Cargando…

Method for Detecting Core Malware Sites Related to Biomedical Information Systems

Most advanced persistent threat attacks target web users through malicious code within landing (exploit) or distribution sites. There is an urgent need to block the affected websites. Attacks on biomedical information systems are no exception to this issue. In this paper, we present a method for loc...

Descripción completa

Detalles Bibliográficos
Autores principales: Kim, Dohoon, Choi, Donghee, Jin, Jonghyun
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Hindawi Publishing Corporation 2015
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4363596/
https://www.ncbi.nlm.nih.gov/pubmed/25821511
http://dx.doi.org/10.1155/2015/756842
_version_ 1782361939153780736
author Kim, Dohoon
Choi, Donghee
Jin, Jonghyun
author_facet Kim, Dohoon
Choi, Donghee
Jin, Jonghyun
author_sort Kim, Dohoon
collection PubMed
description Most advanced persistent threat attacks target web users through malicious code within landing (exploit) or distribution sites. There is an urgent need to block the affected websites. Attacks on biomedical information systems are no exception to this issue. In this paper, we present a method for locating malicious websites that attempt to attack biomedical information systems. Our approach uses malicious code crawling to rearrange websites in the order of their risk index by analyzing the centrality between malware sites and proactively eliminates the root of these sites by finding the core-hub node, thereby reducing unnecessary security policies. In particular, we dynamically estimate the risk index of the affected websites by analyzing various centrality measures and converting them into a single quantified vector. On average, the proactive elimination of core malicious websites results in an average improvement in zero-day attack detection of more than 20%.
format Online
Article
Text
id pubmed-4363596
institution National Center for Biotechnology Information
language English
publishDate 2015
publisher Hindawi Publishing Corporation
record_format MEDLINE/PubMed
spelling pubmed-43635962015-03-29 Method for Detecting Core Malware Sites Related to Biomedical Information Systems Kim, Dohoon Choi, Donghee Jin, Jonghyun Comput Math Methods Med Research Article Most advanced persistent threat attacks target web users through malicious code within landing (exploit) or distribution sites. There is an urgent need to block the affected websites. Attacks on biomedical information systems are no exception to this issue. In this paper, we present a method for locating malicious websites that attempt to attack biomedical information systems. Our approach uses malicious code crawling to rearrange websites in the order of their risk index by analyzing the centrality between malware sites and proactively eliminates the root of these sites by finding the core-hub node, thereby reducing unnecessary security policies. In particular, we dynamically estimate the risk index of the affected websites by analyzing various centrality measures and converting them into a single quantified vector. On average, the proactive elimination of core malicious websites results in an average improvement in zero-day attack detection of more than 20%. Hindawi Publishing Corporation 2015 2015-03-03 /pmc/articles/PMC4363596/ /pubmed/25821511 http://dx.doi.org/10.1155/2015/756842 Text en Copyright © 2015 Dohoon Kim et al. https://creativecommons.org/licenses/by/3.0/ This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Research Article
Kim, Dohoon
Choi, Donghee
Jin, Jonghyun
Method for Detecting Core Malware Sites Related to Biomedical Information Systems
title Method for Detecting Core Malware Sites Related to Biomedical Information Systems
title_full Method for Detecting Core Malware Sites Related to Biomedical Information Systems
title_fullStr Method for Detecting Core Malware Sites Related to Biomedical Information Systems
title_full_unstemmed Method for Detecting Core Malware Sites Related to Biomedical Information Systems
title_short Method for Detecting Core Malware Sites Related to Biomedical Information Systems
title_sort method for detecting core malware sites related to biomedical information systems
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4363596/
https://www.ncbi.nlm.nih.gov/pubmed/25821511
http://dx.doi.org/10.1155/2015/756842
work_keys_str_mv AT kimdohoon methodfordetectingcoremalwaresitesrelatedtobiomedicalinformationsystems
AT choidonghee methodfordetectingcoremalwaresitesrelatedtobiomedicalinformationsystems
AT jinjonghyun methodfordetectingcoremalwaresitesrelatedtobiomedicalinformationsystems