|
ABSTRACT
Web-based malware attacks are more insidious than ever. What can be done to stem the tide?
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Barth, A., Jackson, C., Reis, C. 2008. The security architecture of the Chromium browser; http:// crypto.stanford.edu/websec/chromium/ chromium-security-architecture.pdf.
|
| |
2
|
Brumley, D., Hartwig, C., Kang, M., Liang, Z., Newsome, J., Song, D., Yin, H. 2007. BitScope: Automatically dissecting malicious binaries. Technical Report CMU-CS-07-133. School of Computer Science, Carnegie Mellon University (March).
|
| |
3
|
Federal Trade Commission. 2008. Court halts bogus computer scans (December); www.ftc.gov/ opa/2008/12/winsoftware.shtm.
|
| |
4
|
|
| |
5
|
Krebs, B. 2007. Internet Explorer unsafe for 284 days in 2006. Washington Post Online blog (January).
|
| |
6
|
Krebs, B. 2009. Blogfight: IE vs. Firefox security. Washington Post Online blog (January).
|
| |
7
|
Microsoft Security Advisory (935423). 2007. Vulnerability in Windows animated cursor handling; http://www.microsoft.com/TechNet/security/ advisory/935423.mspx.
|
| |
8
|
Microsoft Security Bulletin MS06-014. 2006. Vulnerability in the Microsoft Data Access Components (MDAC) function could allow code execution; http:// www.microsoft.com/technet/security/Bulletin/ ms06-014.mspx.
|
| |
9
|
|
| |
10
|
|
| |
11
|
Provos, N. 2008. Using htaccess to distribute malware (December); www.provos.org/index.php?/archives/ 55-Using-htaccess-To-Distribute-Malware.html.
|
| |
12
|
Niels Provos , Panayiotis Mavrommatis , Moheeb Abu Rajab , Fabian Monrose, All your iFRAMEs point to Us, Proceedings of the 17th conference on Security symposium, p.1-15, July 28-August 01, 2008, San Jose, CA
|
| |
13
|
Raz, R. 2008. Asprox silent defacement. Chapters in Web Security (December); http:// chaptersinWebsecurity.blogspot.com/ 2008/07/asprox-silent-defacement.html.
|
| |
14
|
Sam Small , Joshua Mason , Fabian Monrose , Niels Provos , Adam Stubblefield, To catch a predator: a natural language approach for eliciting malicious payloads, Proceedings of the 17th conference on Security symposium, p.171-183, July 28-August 01, 2008, San Jose, CA
|
| |
15
|
Stewart, J. 2008. Danmec/Asprox SQL injection attack tool analysis. Secure Works Online (May); www. secureworks.com/research/threats/danmecasprox.
|
|