|国家预印本平台
首页|恶意网页检测系统的研究与实现

恶意网页检测系统的研究与实现

Research and implementation of detecting system for malicious web pages

中文摘要英文摘要

当今世界越来越离不开互联网,但是各种恶意网页层出不穷,带来的经济损失一直日益增加。而目前的检测方法存在着各种各样的缺陷,例如耗费时间过长、对被混淆内容检测正确率底下等等。为了能够快速并且准确的分辨恶意网页,本文设计实现了一个系统,它可以日常采集互联网网站的恶意网址和安全网址建立自己的黑白名单列表,通过一个无界面浏览器去运行指定页面,获得其中实际的内容,而不仅仅是源文件的文本。这样即使恶意网页采用了混淆技术也无所遁形,通过分析其实际运行时的行为判断其中是否有暗链、恶意链接等内容,从而较为准确快速的分析页面。经过以上的动态处理后,进一步采取静态扫描来分析去混淆页面的威胁值,相比直接静态分析原文本可以获取页面的真实特征,做出精准的判定。

In today's world the Internetis more and more important, but all kinds of malicious web pages emerge in endlessly, the economic loss has been increasing .But the current detection method, there are all kinds of defects including taking too much time and the Low accuracy on crypted content.In order to be able to accurately identify malicious web pages, this paper implements a system. It can collect daily Internet site to build own database of black and white list,.It also can access to the real content and by an open source browser, not just the source text, even the page use confusion technology . In this process,the sysyem detect safety of the page upon its action. Finally,it take static analysis on decrypted pages to get their threat degree,so it can make more accurate decision than anslyzing promiscuous pages.

皇甫群泽、辛阳

计算技术、计算机技术自动化技术、自动化技术设备安全科学

信息安全恶意网页动态检测静态检测

Information securityMalicious web pagesynamic detectionStatic detection

皇甫群泽,辛阳.恶意网页检测系统的研究与实现[EB/OL].(2017-09-05)[2025-08-28].http://www.paper.edu.cn/releasepaper/content/201709-26.点此复制

评论