본문 바로가기
  • Home

An Improved Detecting Scheme of Malicious Codes using HTTP Outbound Traffic

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2009, 14(9), pp.47-54
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science

최병하 1 Kyungsan CHO 1

1단국대학교

Accredited

ABSTRACT

Malicious codes, which are spread through WWW, are now evolved with various hacking technologies. However, detecting technologies for them are seemingly not able to keep up with the improvement of hacking and newly generated malicious codes. In this paper, we define the requirements of detecting systems based on the analysis of malicious codes and their spreading characteristics, and propose an improved detection scheme which monitors HTTP Outbound traffic and detects spreading malicious codes in real time. Our proposed scheme sets up signatures in IDS with confirmed HTML tags and Java scripts which spread malicious codes. Through the verification analysis under the real-attacked environment, we show that our scheme is superior to the existing schemes in satisfying the defined requirements and has a higher detection rate for malicious codes.

Citation status

* References for papers published after 2023 are currently being built.