Malicious websites which employ cloaking use operating system, network and browser information of visiting clients to estimate their geographical location and target them using a combination of social engineering and geolocation-specific content. This makes the malicious websites detection process challenging as a detection system has to simulate the client in a specific geographical location on top of setting all operating system, network, and browser attributes accurately to trigger an attack. An Adversarial Information Retrieval (AIR) system must therefore retrieve the content from multiple locations to be able to adequately identify a geolocation attack which makes the detection per website costly and inefficient. In this paper, we propose the design of an AIR system and determine the effectiveness of compression, minification and sanitisation on resource utilisation (i.e. traffic) and detection rate of our prototype AIR system. Experiments on a real-world dataset achieved a 61% rate of compression and reduction in traffic utilisation. In case of minification and sanitisation, 13 and 69% size reduction in resource utilisation and an average of 99 and 55% detection rate were observed in a controlled dataset of malicious websites, respectively. Compression and minification therefore proved to be viable approaches in the design of AIR systems that require multiple retrieval for analysis with limited impact on the detection rate.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Cost-Effective AIR System for Browser-Based Geolocation and Cloaking Attacks

  • Masood Mansoori,
  • Junaid Haseeb,
  • Ian Welch

摘要

Malicious websites which employ cloaking use operating system, network and browser information of visiting clients to estimate their geographical location and target them using a combination of social engineering and geolocation-specific content. This makes the malicious websites detection process challenging as a detection system has to simulate the client in a specific geographical location on top of setting all operating system, network, and browser attributes accurately to trigger an attack. An Adversarial Information Retrieval (AIR) system must therefore retrieve the content from multiple locations to be able to adequately identify a geolocation attack which makes the detection per website costly and inefficient. In this paper, we propose the design of an AIR system and determine the effectiveness of compression, minification and sanitisation on resource utilisation (i.e. traffic) and detection rate of our prototype AIR system. Experiments on a real-world dataset achieved a 61% rate of compression and reduction in traffic utilisation. In case of minification and sanitisation, 13 and 69% size reduction in resource utilisation and an average of 99 and 55% detection rate were observed in a controlled dataset of malicious websites, respectively. Compression and minification therefore proved to be viable approaches in the design of AIR systems that require multiple retrieval for analysis with limited impact on the detection rate.