• Home
  • Search
  • Clustering Client Honeypot Data to Support Malware Analysis
  • Cite Icon3
  • https://doi.org/10.1007/978-3-642-15384-6_59Copy DOI Icon

Clustering Client Honeypot Data to Support Malware Analysis

  • Jan 1, 2010
  • Yaser Alosefer +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Client honeypots visit and interact with suspect web sites in order to detect and collect information about malware. Malicious websites may cause a number of activities to be performed on a victim's system; each activity is performed in different stages. We use a state machine to represent the activities performed by the malicious web page into pre-defined states. These states can be used to summarise interactions with malicious web pages using the same state machine structure. The states are then passed to a clustering algorithm to group similar malicious web page exploits in order to better understand how software can be developed to better respond to such attacks. The outputs of the clustering algorithm are categorized to build up groups of similar states that represent the malicious activities performed on the victim's system. The benefit of using this process is to build families of malicious web pages with similar behaviours (behaviour families) leading to the development of common approaches to deal with such exploits.

Similar Papers
  • Book Chapter
  • Citations14

Measurement Study on Malicious Web Servers in the .nz Domain

  • Jan 01, 2009
  • Christian Seifert +4
  • Conference Article
  • Citations6

Research on Prevention Solution of Advanced Persistent Threat

  • Jan 01, 2014
  • Xiaomei Liu
  • PDF
  • Research Article
  • Citations2

Malicious and benign websites classification using machine learning methods

  • Aug 06, 2020
  • Theoretical and Applied Cybersecurity
  • M Lavreniuk +1
  • Conference Article
  • Citations14

Malicious Webpage Classification Based on Web Content Features using Machine Learning and Deep Learning

  • Oct 26, 2022
  • A Saleem Raja +3
  • Research Article
  • Citations15

JsSandbox: A Framework for Analyzing the Behavior of Malicious JavaScript Code using Internal Function Hooking

  • Jan 01, 2012
  • KSII Transactions on Internet and Information Systems
  • Hyoung Chun Kim
  • Conference Article
  • Citations68

A lexical approach for classifying malicious URLs

  • Jul 01, 2015
  • Michael Darling +4
  • Book Chapter

Cardinal Correlated Oversampling for Detection of Malicious Web Links Using Machine Learning

  • Sep 14, 2021
  • M Shyamala Devi +4
  • Conference Article
  • Citations1

Detection of Malicious Webpages Using Deep Learning

  • Dec 15, 2021
  • A K Singh +1
  • Conference Article
  • Citations6

An efficient visitation algorithm to improve the detection speed of high-interaction client honeypots

  • Nov 02, 2011
  • Hong-Geun Kim +4
  • Conference Article
  • Citations10

The legal firing sequence problem of Petri nets with state machine structure

  • May 12, 1996
  • K Morita +1
  • Dissertation
  • Citations1

Localisation of Attacks, Combating Browser-Based Geo-Information and IP Tracking Attacks

  • Jan 01, 2017
  • Masood Mansoori
  • Conference Article
  • Citations2

POSTER

  • Oct 12, 2015
  • Toshiki Shibahara +4
  • Research Article
  • Citations8

Malicious web pages: What if hosting providers could actually do something…

  • Jun 19, 2015
  • Computer Law & Security Review
  • Huw Fryer +2
  • Research Article
  • Citations17

A drift aware adaptive method based on minimum uncertainty for anomaly detection in social networking

  • Aug 19, 2020
  • Expert Systems with Applications
  • Emad Mahmodi +2
  • Book Chapter
  • Citations5

Identification of Malicious Web Pages by Inductive Learning

  • Jan 01, 2009
  • Peishun Liu +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.