Concepedia

Publication | Closed Access

The ghost in the browser analysis of web-based malware

422

Citations

5

References

2007

Year

TLDR

The increasing prevalence of internet use has fueled an underground economy that infects users’ computers with malware or adware, enabling attackers to exploit vulnerabilities, gain full system control, exfiltrate data, and remotely manipulate hosts—behaviors akin to botnets but driven by pull‑based, loosely coupled web‑based infections. This study aims to map the current landscape of web‑based malware by identifying and illustrating four main injection mechanisms—web‑server security flaws, user‑contributed content, advertising, and third‑party widgets—to highlight the growing threat. The authors provide concrete examples of abuse for each of these four injection vectors, demonstrating how they are exploited across popular websites.

Abstract

As more users are connected to the Internet and conduct their daily activities electronically, computer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected web site enables the attacker to detect vulnerabilities in the user's applications and force the download a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host. We believe that such behavior is similar to our traditional understanding of botnets. However, the main difference is that web-based malware infections are pull-based and that the resulting command feedback loop is looser. To characterize the nature of this rising thread, we identify the four prevalent mechanisms used to inject malicious content on popular web sites: web server security, user contributed content, advertising and third-party widgets. For each of these areas, we present examples of abuse found on the Internet. Our aim is to present the state of malware on the Web and emphasize the importance of this rising threat.

References

YearCitations

Page 1