| Literature DB >> 25821511 |
Dohoon Kim1, Donghee Choi1, Jonghyun Jin1.
Abstract
Most advanced persistent threat attacks target web users through malicious code within landing (exploit) or distribution sites. There is an urgent need to block the affected websites. Attacks on biomedical information systems are no exception to this issue. In this paper, we present a method for locating malicious websites that attempt to attack biomedical information systems. Our approach uses malicious code crawling to rearrange websites in the order of their risk index by analyzing the centrality between malware sites and proactively eliminates the root of these sites by finding the core-hub node, thereby reducing unnecessary security policies. In particular, we dynamically estimate the risk index of the affected websites by analyzing various centrality measures and converting them into a single quantified vector. On average, the proactive elimination of core malicious websites results in an average improvement in zero-day attack detection of more than 20%.Entities:
Mesh:
Year: 2015 PMID: 25821511 PMCID: PMC4363596 DOI: 10.1155/2015/756842
Source DB: PubMed Journal: Comput Math Methods Med ISSN: 1748-670X Impact factor: 2.238
Figure 1Definition of landing (or exploit)/distribution sites including malicious code.
Figure 2Entire analysis diagram for malicious code landing (or exploit)/distribution site risk estimation.
Figure 3Entire analysis diagram for risk estimation of malicious code exploit/landing/distribution site.
Figure 4Visualization of malware site risk.
MRI estimation result of exploit/landing/distribution sites.
| Node type | URL | MRI | Reliability |
|---|---|---|---|
| Distribution site | http://222.∗∗∗.∗∗∗.∗∗∗/c/h.html | 0.3965 | 91% |
| Distribution site | http://www.∗∗∗∗∗∗∗∗∗.com/New/index.html | 0.3505 | 92% |
| Distribution site | http://a1∗∗∗∗∗∗∗∗∗.com/1/index.html | 0.3058 | 90% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.or.kr/ | 0.3047 | 95% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.co.kr/ | 0.3026 | 94% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.kr/ | 0.3017 | 94% |
| Distribution site | http://a2.∗∗∗∗∗∗∗∗∗.com/2/index.html | 0.3009 | 93% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.re.kr/ | 0.3003 | 92% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.or.kr/ | 0.2993 | 92% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.co.kr/ | 0.2991 | 90% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.co.kr/ | 0.2983 | 91% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.co.kr/ | 0.2982 | 90% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.org/ | 0.2970 | 94% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.or.kr/ | 0.2969 | 96% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.com/ | 0.2968 | 95% |
| Exploit site | http://∗∗∗∗∗∗∗∗∗.co.kr/ | 0.2967 | 95% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.co.kr/ | 0.2966 | 96% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.kr/ | 0.2966 | 94% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.kr/ | 0.2962 | 93% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.com/ | 0.2961 | 93% |
| Exploit site | http://www.∗∗∗∗∗∗∗∗∗.co.kr/ | 0.2960 | 94% |
(“∗∗∗∗∗∗∗∗∗”: the URL information of malware site).
Average detection rate of zero-day attacks for a given day.
| Priority of risk | Malware site group with multipath | Distribution site with single path | Landing (or exploit) site with single path |
|---|---|---|---|
| 1 | 23.3% (15) | 21.5% | 28.2% |
| 2 | 22.6% (9) | 31.6% | 32.4% |
| 3 | 14.7% (8) | 22.8% | 18.1% |
| 4 | 18.4% (10) | 19.7% | 32.3% |
| 5 | 21.2% (12) | 24.2% | 17.6% |
| Average early detection rate | 20.04% | 23.96% | 25.72% |