The Role of Web Hosting Providers in Detecting Compromised Websites - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

The Role of Web Hosting Providers in Detecting Compromised Websites

Davide Canali
  • Fonction : Auteur
  • PersonId : 937916
Davide Balzarotti
Aurélien Francillon

Résumé

Compromised websites are often used by attackers to deliver ma- licious content or to host phishing pages designed to steal private information from their victims. Unfortunately, most of the targeted websites are managed by users with little security background - often unable to detect this kind of threats or to afford an external professional security service. In this paper we test the ability of web hosting providers to detect compromised websites and react to user complaints. We also test six specialized services that provide security monitoring of web pages for a small fee. During a period of 30 days, we hosted our own vulnerable web- sites on 22 shared hosting providers, including 12 of the most pop- ular ones. We repeatedly ran five different attacks against each of them. Our tests included a bot-like infection, a drive-by download, the upload of malicious files, an SQL injection stealing credit card numbers, and a phishing kit for a famous American bank. In ad- dition, we also generated traffic from seemingly valid victims of phishing and drive-by download sites. We show that most of these attacks could have been detected by free network or file analysis tools. After 25 days, if no malicious activity was detected, we started to file abuse complaints to the providers. This allowed us to study the reaction of the web hosting providers to both real and bogus complaints. The general picture we drew from our study is quite alarming. The vast majority of the providers, or "add-on" security monitoring services, are unable to detect the most simple signs of malicious activity on hosted websites.

Domaines

Informatique
Fichier principal
Vignette du fichier
canali-providers.pdf (136.04 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-00856722 , version 1 (02-09-2013)

Identifiants

  • HAL Id : hal-00856722 , version 1

Citer

Davide Canali, Davide Balzarotti, Aurélien Francillon. The Role of Web Hosting Providers in Detecting Compromised Websites. WWW '13 Proceedings of the 22nd international conference on World Wide Web, May 2013, Rio de Janeiro, Brazil. pp.177-188. ⟨hal-00856722⟩

Collections

EURECOM
685 Consultations
3472 Téléchargements

Partager

Gmail Facebook X LinkedIn More