ADSandbox: sandboxing JavaScript to fight malicious websites

ADSandbox: sandboxing JavaScript to fight malicious websites
复制标题

ADSandbox:沙箱 JavaScript 以对抗恶意网站

DOI:
10.1145/1774088.1774482
复制
发表时间:
2010
期刊:
Proceedings of the 14th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
F. Freiling
F. Freiling
中科院分区:
--
文献类型:
--
作者:
Andreas Dewald;Thorsten Holz;F. Freiling

文献摘要

被引文献

相似文献

我们提出了ADSandbox,恶意网站的分析系统,专注于检测通过JavaScript的攻击。由于与Java不同,JavaScript没有任何内置的沙箱概念,因此其想法是在隔离的环境中执行任何嵌入式JavaScript并记录每个关键操作。通过对这些日志进行分析,ADSandbox可以判断该网站是否是恶意的。与以前的工作相比,这种方法结合了通用性和可用性,因为该系统是直接在客户端上运行Web浏览器的网页显示之前执行。我们表明,我们可以实现假阳性率接近0%,假阴性率低于15%,只有几秒钟的性能开销,这是一个有点高的真实的时间应用程序,但假设我们的工具的未来版本的巨大潜力。
We present ADSandbox, an analysis system for malicious websites that focusses on detecting attacks through JavaScript. Since, in contrast to Java, JavaScript does not have any built-in sandbox concept, the idea is to execute any embedded JavaScript within an isolated environment and log every critical action. Using heuristics on these logs, ADSandbox decides whether the site is malicious or not. In contrast to previous work, this approach combines generality with usability, since the system is executed directly on the client running the web browser before the web page is displayed. We show that we can achieve false positive rates close to 0% and false negative rates below 15% with a performance overhead of only a few seconds, what is a bit high for real time application, but supposes a great potential for future versions of our tool.