|
ABSTRACT
Web-based malware attacks are more insidious than ever. What can be done to stem the tide?
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Barth, A., Jackson, C., and Reis, C. The Security Architecture of the Chromium Browser; http://crypto.stanford.edu/websec/chromium/chromium-security-architecture.odf.
|
| |
2
|
Brumley, D., Hartwig, C., Kang, M., Liang, Z., Newsome, J., Song, D., and Yin, H. BitScope: Automatically dissecting malicious binaries. Technical Report Technical Report CMU-CS-07-133, School of Computer Science, Carnegie Mellon University, March 2007.
|
| |
3
|
Court halts bogus computer scans (Dec. 2008); www.ftc.gov/opa/2008/12/winsoftware.shtm.
|
| |
4
|
|
| |
5
|
Krebs, B. Internet Explorer unsafe for 284 days in 2006. Washington Post Online Blog, Jan. 2007.
|
| |
6
|
Krebs, B. Blogfight: IE vs. Firefox security. Washington Post Online Blog, Jan. 2009.
|
| |
7
|
Microsoft. Microsoft Security Bulletin MS06-014: Vulnerability in the Microsoft Data Access Components (MDACS) Function Could Allow Code Execution. May 2006.
|
| |
8
|
Microsoft. Microsoft Security Advisory (935423): Vulnerability in Windows Animated Cursor Handling, Mar. 2007.
|
| |
9
|
|
| |
10
|
|
| |
11
|
Provos, N. Using htaccess To Distribute Malware. Dec. 2008; www.provos.org/index.php?/archives/55-Using-htaccess-To-Distribute-Malware.html.
|
| |
12
|
Niels Provos , Panayiotis Mavrommatis , Moheeb Abu Rajab , Fabian Monrose, All your iFRAMEs point to Us, Proceedings of the 17th conference on Security symposium, p.1-15, July 28-August 01, 2008, San Jose, CA
|
| |
13
|
Raz, R. Asprox silent defacement. Chapters in Web Security, Dec. 2008; http://chaptersinWebsecurityblogspot.com/2008/07/asprox-silent-defacement.html.
|
| |
14
|
Sam Small , Joshua Mason , Fabian Monrose , Niels Provos , Adam Stubblefield, To catch a predator: a natural language approach for eliciting malicious payloads, Proceedings of the 17th conference on Security symposium, p.171-183, July 28-August 01, 2008, San Jose, CA
|
| |
15
|
Stewart, J. Danmec/Asprox SQL injection attack tool analysis. Secure Works Online, May 2008; www.secureworks.com/research/threats/danmecasprox.
|
|