错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Utilizing DNS and VirusTotal for Automated Ad-Malware Detection

  • Florian Nettersheim,
  • Stephan Arlt,
  • Michael Rademacher

摘要

In this paper, we present a novel approach to the automated detection of ad-malware. We efficiently crawl a vast set of websites and extensively fetch all HTTP requests embedded in these websites.Then we query these requests both against filtered DNS resolvers and VirusTotal. The idea is to evaluate, how much content is labeled as a potential threat. The results show that up to 8.8% of the domains found in our approach are labeled as suspicious. Moreover, up to 3.2% of these domains are categorized as ad-malware. However, the overall responses from the used services paint a divergent picture: Both DNS resolvers and VirusTotal have different understandings to the definition of suspicious content.