HoneyAgent: Detecting Malicious Java']Java Applets by Using Dynamic Analysis

被引:0
|
作者
Gassen, Jan [1 ]
Chapman, Jonathan P. [1 ]
机构
[1] Fraunhofer FKIE, Friedrich Ebert Allee 144, D-53113 Bonn, Germany
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Malicious Java applets are widely used to deliver malicious software to remote systems. In this work, we present HoneyAgent which allows for the dynamic analysis of Java applets, bypassing common obfuscation techniques. This enables security researchers to quickly comprehend the functionality of an examined applet and to unveil malicious behavior. In order to trace the behavior of a sample as far as possible, HoneyAgent is further able to simulate various vulnerabilities allowing analysts for example to identify the malware that should finally be installed by the applet. In our evaluation, we show that HoneyAgent is able to reliably detect malicious applets used by common exploit kits with no false positives. By using a combination of heuristics as well as signatures applied to observed method invocations, HoneyAgent is further able to identify exploited common vulnerabilities and exposures in many cases.
引用
收藏
页码:109 / 117
页数:9
相关论文
共 50 条
  • [41] Geospatial metadata querying and visualization on the WWW using Java']Java(TM) applets
    Alper, N
    Stein, C
    IEEE SYMPOSIUM ON INFORMATION VISUALIZATION '96, PROCEEDINGS, 1996, : 77 - +
  • [42] Developing Java']Java entertainment applets - Withers,J
    Gillespie, T
    LIBRARY JOURNAL, 1997, 122 (06) : 118 - 118
  • [43] Cracking RC5 with Java']Java applets
    Gladychev, P
    Patel, A
    O'Mahony, D
    CONCURRENCY-PRACTICE AND EXPERIENCE, 1998, 10 (11-13): : 1165 - 1171
  • [44] Educational Java']Java applets for visualizing MOS memory
    Yuan, Z
    Wie, CR
    2001 INTERNATIONAL CONFERENCE ON MICROELECTRONIC SYSTEMS EDUCATION, PROCEEDINGS: DESIGNING MICROSYSTEMS IN THE NEW MILLENNIUM, 2001, : 67 - 68
  • [46] Managing the life cycle of Java']Java Card applets in other Java']Java virtual machines
    Roland, Michael
    Langer, Josef
    Mayrhofer, Rene
    INTERNATIONAL JOURNAL OF PERVASIVE COMPUTING AND COMMUNICATIONS, 2014, 10 (03) : 291 - +
  • [47] Interactive graphics toolkit for java']java applications and web applets
    Denbo, DW
    17TH INTERNATIONAL CONFERENCE ON INTERACTIVE INFORMATION AND PROCESSING SYSTEMS (IIPS) FOR METEOROLOGY, OCEANOGRAPHY, AND HYDROLOGY, 2001, : 372 - 375
  • [48] EUROMED-JAVA']JAVA: Trusted Third Party Services for securing medical Java']Java applets
    Varvitsiotis, A
    Polemi, D
    Marsh, A
    COMPUTER SECURITY - ESORICS 98, 1998, 1485 : 209 - 220
  • [49] Anomalous intrusion detection system for hostile Java']Java applets
    Helmer, G
    Wong, J
    Madaka, S
    JOURNAL OF SYSTEMS AND SOFTWARE, 2001, 55 (03) : 273 - 286
  • [50] Overview of Java']Java™ components and applets in SAS/IntrNet™ software
    Walters, B
    Chapman, D
    PROCEEDINGS OF THE TWENTY-THIRD ANNUAL SAS USERS GROUP INTERNATIONAL CONFERENCE, 1998, : 871 - 877