网页木马现状分析与监测研究
Investigation and Measurement on Web-based Malware
由于地下经济链的驱动,网络犯罪者已频繁地在中国万维网上构建木马网络,用于攻击普通因特网用户的客户端主机,窃取虚拟资产从而获得非法收入。对中国万维网上的网页木马安全威胁现状进行了深入分析,包括背景、发展历程、驱动根源和技术机理,并构建了基于客户端蜜罐技术和动态行为分析的木马网络监测方法,对国内万维网上最常被访问的网站进行了采样分析,监测结果显示其中1.49%的网站被恶意挂马,进一步对确认挂马网站进行追踪分析揭示了背后复杂而庞大的网页木马网络,并对典型网页木马案例进行了深入剖析和展示。监测结果和案例研究验证了网页木马安全威胁在国内万维网上的泛滥。
riven by the underground economy, cyber criminals are on the rise and use the Web-based Malware networks to exploit innocent Internet users, steal the virtual assets from the exploited computers and sell them for money. We give the overview of the trojan network phenomenon on the Chinese Web, including its background, history, driven root causes and technical mechanisms. Furthermore, we introduce the measurement method based on the client honeypots and dynamic behavior analysis, and we use this method to measure Web-based Malware networks on the Chinese Web, our measurements show that about 1.49% of the examined websites redirect the visitors to Web-based Malware networks. We also perform detailed analysis of the identified malicious websites and reveal the obfuscated and immense Web-based Malware, and we present a representative case study of this specific threat. Our measurement results and detailed case study proofs the prevalence of Web-based Malware on the Chinese Web.
诸葛建伟
安全科学
计算机安全木马网络监测客户端蜜罐恶意代码地下经济
computer securitytrojan network measurementclient honeypotmalwareunderground economy
诸葛建伟.网页木马现状分析与监测研究[EB/OL].(2011-01-14)[2025-08-21].http://www.paper.edu.cn/releasepaper/content/201101-761.点此复制
评论