摘要
随着互联网的迅猛发展,网页已经成为人们日常发布和获取信息的重要途径,给人们带来了极大的便利。然而,安全挑战也随之而来,层出不穷的网页入侵手段严重影响着互联网的长远应用和发展,尤其是网页挂马是一个十分泛滥的攻击方式,严重威胁着用户安全。针对此问题,本文提出了一种基于沙箱技术的检测系统,能够动态地检测和抵御网页木马攻击。在安全性上,所提系统通过高交互蜜罐中多个沙箱技术,动态地模拟网页木马攻击过程,进而能够分析和抵御应用层、系统层和内核层的恶意行为,实现了多层检测。在效率上,所提系统采用了轻量级的沙箱技术,在内核层涉及较少调用,着重在应用层HOOK相关API实现检测,提高了效率表现。实验评估分析表明,所提系统能够获得较好的性能。
With the rapid development of the Internet,webpage has become an important way to make people get daily information,which brings great convenience.However,security issues are becoming challenging.Kinds of webpage intrusion have affected the network and terminal securities. Especially,webpage trojan is well known as an effective attack way.This paper proposes a new detection system based on sandbox technologies to dynamically detect webpage trojan.For the security,by employing multi-sandbox technologies in the high-interaction honeypot,the proposed system can simulate the attack process of Webpage Trojan.Then,malicious behaviors can be analyzed and detected at the application layer,the system layer and the kernel layer, which realizes multi level detection.For the efficiency,the proposed system uses a lightweight technology to focus on the HOOK operations at the application layer,which can avoid the time-consuming operations at the kernel layer. The experimental evaluation results show that comparing with the existing schemes,the proposed system can achieve better performance.
出处
《电子测试》
2014年第11X期87-92,共6页
Electronic Test
基金
信息网络边界安全隔离及主动防御技术研究及应用EPRIXXKJ[2013]2868
关键词
网页木马
蜜罐
沙箱
动态检测
Webpage Trojan
Honeypot
Sandboxing
Dynamic Behavior