ADSandbox: sandboxing JavaScript to fight malicious websites
ADSandbox: sandboxing JavaScript to fight malicious websites
复制标题
ADSandbox:沙箱 JavaScript 以对抗恶意网站
DOI:
10.1145/1774088.1774482
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
F. Freiling
中科院分区:
文献类型:
--
作者:
Andreas Dewald;Thorsten Holz;F. Freiling
We present ADSandbox, an analysis system for malicious websites that focusses on detecting attacks through JavaScript. Since, in contrast to Java, JavaScript does not have any built-in sandbox concept, the idea is to execute any embedded JavaScript within an isolated environment and log every critical action. Using heuristics on these logs, ADSandbox decides whether the site is malicious or not. In contrast to previous work, this approach combines generality with usability, since the system is executed directly on the client running the web browser before the web page is displayed. We show that we can achieve false positive rates close to 0% and false negative rates below 15% with a performance overhead of only a few seconds, what is a bit high for real time application, but supposes a great potential for future versions of our tool.