Malicious Web Page Detection Based on Anomaly Semantics

碩士 === 國立中山大學 === 資訊工程學系研究所 === 97 === Web services are becoming the dominant way to provide access to on-line information. Web services have a lot of applications, like e-mail, web search engine, auction network and internet banking. On the web services, web application technology and dynamic webpa...

Full description

Bibliographic Details
Main Authors: Jing-Siang Luo, 羅敬翔
Other Authors: D. J. Guan
Format: Others
Language:zh-TW
Published: 2009
Online Access:http://ndltd.ncl.edu.tw/handle/qg3z7q
id ndltd-TW-097NSYS5392054
record_format oai_dc
spelling ndltd-TW-097NSYS53920542019-05-29T03:42:54Z http://ndltd.ncl.edu.tw/handle/qg3z7q Malicious Web Page Detection Based on Anomaly Semantics 以異常語意為基礎的惡意網頁偵測 Jing-Siang Luo 羅敬翔 碩士 國立中山大學 資訊工程學系研究所 97 Web services are becoming the dominant way to provide access to on-line information. Web services have a lot of applications, like e-mail, web search engine, auction network and internet banking. On the web services, web application technology and dynamic webpage technology are very important, but hackers take advantage of web application vulnerabilities and dynamic webpage technology to inject malicious codes into webpages. However, a part of the web sites have neglected the issue of security. In this paper, we propose a novel approach for detecting malicious webpages by URL features, anomaly semantics, potential dangerous tags and tag attributes. This research proposed approach mainly consists of three parts: (1) scripting language and automatic link filter. (2) malicious feature. (3) scoring mechanism. By first part, this step can filter out normal webpages to increae detection speed. Second part can identify some known malicious attacks. Third part can search some unknown malicious webpages by scoring. Our experimental results show that the proposed approach achieves low false positive rate and low false negative rate. D. J. Guan 官大智 2009 學位論文 ; thesis 68 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立中山大學 === 資訊工程學系研究所 === 97 === Web services are becoming the dominant way to provide access to on-line information. Web services have a lot of applications, like e-mail, web search engine, auction network and internet banking. On the web services, web application technology and dynamic webpage technology are very important, but hackers take advantage of web application vulnerabilities and dynamic webpage technology to inject malicious codes into webpages. However, a part of the web sites have neglected the issue of security. In this paper, we propose a novel approach for detecting malicious webpages by URL features, anomaly semantics, potential dangerous tags and tag attributes. This research proposed approach mainly consists of three parts: (1) scripting language and automatic link filter. (2) malicious feature. (3) scoring mechanism. By first part, this step can filter out normal webpages to increae detection speed. Second part can identify some known malicious attacks. Third part can search some unknown malicious webpages by scoring. Our experimental results show that the proposed approach achieves low false positive rate and low false negative rate.
author2 D. J. Guan
author_facet D. J. Guan
Jing-Siang Luo
羅敬翔
author Jing-Siang Luo
羅敬翔
spellingShingle Jing-Siang Luo
羅敬翔
Malicious Web Page Detection Based on Anomaly Semantics
author_sort Jing-Siang Luo
title Malicious Web Page Detection Based on Anomaly Semantics
title_short Malicious Web Page Detection Based on Anomaly Semantics
title_full Malicious Web Page Detection Based on Anomaly Semantics
title_fullStr Malicious Web Page Detection Based on Anomaly Semantics
title_full_unstemmed Malicious Web Page Detection Based on Anomaly Semantics
title_sort malicious web page detection based on anomaly semantics
publishDate 2009
url http://ndltd.ncl.edu.tw/handle/qg3z7q
work_keys_str_mv AT jingsiangluo maliciouswebpagedetectionbasedonanomalysemantics
AT luójìngxiáng maliciouswebpagedetectionbasedonanomalysemantics
AT jingsiangluo yǐyìchángyǔyìwèijīchǔdeèyìwǎngyèzhēncè
AT luójìngxiáng yǐyìchángyǔyìwèijīchǔdeèyìwǎngyèzhēncè
_version_ 1719193010307072000