Back to Search Start Over

Real-world IP and network tracking measurement study of malicious websites with HAZOP

Authors :
Seyed Ebrahim Hashemi
Masood Mansoori
Ian Welch
Roy A. Maxion
Kim-Kwang Raymond Choo
Mansoori, Masood
Welch, Ian
Choo, Kim Kwang Raymond
Maxion, Roy A
Hashemi, Seyed Ebrahim
Publication Year :
2017
Publisher :
US : Taylor and Francis, 2017.

Abstract

IP tracking and cloaking are practices for identifying users which are used legitimately by websites to provide services and content tailored to particular users. However, it is believed that these practices are also used by malicious websites to avoid detection by anti-virus companies crawling the web to find malware. In addition, malicious websites are also believed to use IP tracking in order to deliver targeted malware based upon a history of previous visits by users. In this paper, we empirically investigate these beliefs and collect a large data-set of suspicious URLs in order to identify at what level IP tracking takes place that is at the level of an individual address or at the level of their network provider or organization (network tracking). We perform our experiments using HAZard and OPerability study to control the effects of a large number of other attributes which may affect the result of the analysis. Our results illustrate that IP tracking is used in a small subset of domains within our data-set, while no strong indication of network tracking was observed. Refereed/Peer-reviewed

Details

Language :
English
Database :
OpenAIRE
Accession number :
edsair.doi.dedup.....b0fa17e03dc7c6b574cc9303550d0477