77118bedc4767cdc81ccd6063076a1f4.ppt
- Количество слайдов: 6
A CRAWLER BASED STUDY OF SPYWARE ON THE WEB Vijay Savanth The University of Auckland Computer Science Department vijaysavanth@gmail. com A. Moshchuk, T. Bragin, S. D. Gribble, H. M. Levy, “A Crawler-based Study of Spyware on the Web”, in Proceedings of the 13 th Annual Network and Distributed Systems Security Symposium (NDSS 2006), The Internet Society, 2006.
SUMMARY • The paper aims at analyzing the effect spyware has on the internet, by conducting a study to address the following issues, F Determining the amount of spyware on the internet - Its distribution over a variety of sites, (game sites, adult sites, music sites, etc. ) - The damage spyware can do - The types of spyware attacks, i. e. via executables or drive-by downloads F The rate of change of spyware over time
C APPRECIATION • Commendable effort spent in creating performance, automated system that: a high ü Crawls the web, and downloads executables ü Automatically installs executables within a Virtual Machine that contained Windows XP ü Analyzes if the installation caused spyware infection ü Uses trigger conditions to detect drive by downloads ü Rolls back to a clean state
D CRITICISIM • Test environment contradicts aim – “In this paper we change perspective, examining the nature of the spyware threat not on the desktop but from an internet point of view” û Windows XP was the only Operating System considered. û Internet Explorer was the main browser used, (Firefox gets a brief mention). û What about websites/programs in a language other than English? û Tends to be desktop oriented rather than internet oriented.
D CRITICISIM (contd. ) • What is the author trying to convey? û Is spyware increasing or decreasing? û How is the distribution or rate of change of spyware affecting the internet? û Raw results provided without much analysis.
QUESTION ? ? ? Spyware is quite common on the internet, but will the extent or distribution of spyware affect user browsing behavior in a given environment?
77118bedc4767cdc81ccd6063076a1f4.ppt