|
| This Article | ||
| ||
| Share | ||
| Bibliographic References | ||
| Add to: | ||
| | ||
| Search | ||
| ||
2012 IEEE Symposium on Security and Privacy
Rozzle: De-cloaking Internet Malware
San Francisco, California USA
May 20-May 23
ISBN: 978-0-7695-4681-0
| ASCII Text | x | ||
| C. Seifert, B. Zorn, B. Livshits, C. Kolbitsch, "Rozzle: De-cloaking Internet Malware," Security and Privacy, IEEE Symposium on, pp. 443-457, 2012 IEEE Symposium on Security and Privacy, 2012. | |||
| BibTex | x | ||
| @article{ 10.1109/SP.2012.48, author = {C. Seifert and B. Zorn and B. Livshits and C. Kolbitsch}, title = {Rozzle: De-cloaking Internet Malware}, journal ={Security and Privacy, IEEE Symposium on}, volume = {0}, year = {2012}, issn = {1081-6011}, pages = {443-457}, doi = {http://doi.ieeecomputersociety.org/10.1109/SP.2012.48}, publisher = {IEEE Computer Society}, address = {Los Alamitos, CA, USA}, } | |||
| RefWorks Procite/RefMan/Endnote | x | ||
| TY - CONF JO - Security and Privacy, IEEE Symposium on TI - Rozzle: De-cloaking Internet Malware SN - 1081-6011 SP443 EP457 A1 - C. Seifert, A1 - B. Zorn, A1 - B. Livshits, A1 - C. Kolbitsch, PY - 2012 KW - virtual machines KW - Internet KW - invasive software KW - Java KW - JavaScript multiexecution virtual machine KW - Rozzle KW - decloaking Internet malware KW - JavaScript based malware attacks KW - signicant threat KW - desktop computers KW - smartphones KW - tablets KW - runtime methods KW - static methods KW - malware detection KW - just-in-time in-browser detection KW - crawler based malware discovery KW - fingerprinting techniques KW - browser configurations KW - malware scanners KW - Malware KW - Browsers KW - Runtime KW - Navigation KW - Detectors KW - Reactive power KW - Fingerprint recognition KW - JavaScript KW - malware KW - cloaking VL - 0 JA - Security and Privacy, IEEE Symposium on ER - | |||
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/SP.2012.48
JavaScript-based malware attacks have increased in recent years and currently represent a signicant threat to the use of desktop computers, smartphones, and tablets. While static and runtime methods for malware detection have been proposed in the literature, both on the client side, for just-in-time in-browser detection, as well as offline, crawler-based malware discovery, these approaches encounter the same fundamental limitation. Web-based malware tends to be environment-specific, targeting a particular browser, often attacking specic versions of installed plugins. This targeting occurs because the malware exploits vulnerabilities in specific plugins and fails otherwise. As a result, a fundamental limitation for detecting a piece of malware is that malware is triggered infrequently, only showing itself when the right environment is present. We observe that, using fingerprinting techniques that capture and exploit unique properties of browser configurations, almost all existing malware can be made virtually impssible for malware scanners to detect. This paper proposes Rozzle, a JavaScript multi-execution virtual machine, as a way to explore multiple execution paths within a single execution so that environment-specific malware will reveal itself. Using large-scale experiments, we show that Rozzle increases the detection rate for offline runtime detection by almost seven times. In addition, Rozzle triples the effectiveness of online runtime detection. We show that Rozzle incurs virtually no runtime overhead and allows us to replace multiple VMs running different browser configurations with a single Rozzle-enabled browser, reducing the hardware requirements, network bandwidth, and power consumption.
Index Terms:
virtual machines,Internet,invasive software,Java,JavaScript multiexecution virtual machine,Rozzle,decloaking Internet malware,JavaScript based malware attacks,signicant threat,desktop computers,smartphones,tablets,runtime methods,static methods,malware detection,just-in-time in-browser detection,crawler based malware discovery,fingerprinting techniques,browser configurations,malware scanners,Malware,Browsers,Runtime,Navigation,Detectors,Reactive power,Fingerprint recognition,JavaScript,malware,cloaking
Citation:
C. Seifert, B. Zorn, B. Livshits, C. Kolbitsch, "Rozzle: De-cloaking Internet Malware," sp, pp.443-457, 2012 IEEE Symposium on Security and Privacy, 2012
Usage of this product signifies your acceptance of the Terms of Use.
