TY - GEN
T1 - Escape from Monkey Island
T2 - 8th Conference on Detection of Intrusions and Malware & Vulnerability Assessment
AU - Kapravelos, Alexandros
AU - Cova, Marco
AU - Kruegel, Christopher
AU - Vigna, Giovanni
PY - 2011/6/30
Y1 - 2011/6/30
N2 - High-interaction honeyclients are the tools of choice to detect malicious web pages that launch drive-by-download attacks. Unfortunately, the approach used by these tools, which, in most cases, is to identify the side-effects of a successful attack rather than the attack itself, leaves open the possibility for malicious pages to perform evasion techniques that allow one to execute an attack without detection or to behave in a benign way when being analyzed. In this paper, we examine the security model that high-interaction honeyclients use and evaluate their weaknesses in practice. We introduce and discuss a number of possible attacks, and we test them against several popular, well-known high-interaction honeyclients. Our attacks evade the detection of these tools, while successfully attacking regular visitors of malicious web pages.
AB - High-interaction honeyclients are the tools of choice to detect malicious web pages that launch drive-by-download attacks. Unfortunately, the approach used by these tools, which, in most cases, is to identify the side-effects of a successful attack rather than the attack itself, leaves open the possibility for malicious pages to perform evasion techniques that allow one to execute an attack without detection or to behave in a benign way when being analyzed. In this paper, we examine the security model that high-interaction honeyclients use and evaluate their weaknesses in practice. We introduce and discuss a number of possible attacks, and we test them against several popular, well-known high-interaction honeyclients. Our attacks evade the detection of these tools, while successfully attacking regular visitors of malicious web pages.
KW - Virtual Machine
KW - Malicious Code
KW - USENIX Security Symposium
KW - Malicious Site
KW - Cache Poisoning Attack
U2 - 10.1007/978-3-642-22424-9_8
DO - 10.1007/978-3-642-22424-9_8
M3 - Conference contribution
SN - 9783642224232
T3 - Lecture Notes in Computer Science
SP - 124
EP - 143
BT - Detection of Intrusions and Malware, and Vulnerability Assessment
A2 - Holz, Thorsten
A2 - Bos, Herbert
PB - Springer
Y2 - 7 July 2011 through 8 July 2011
ER -