TY - GEN
T1 - Server-side code injection attacks
T2 - 16th International Symposium on Research in Attacks, Intrusions, and Defenses, RAID 2013
AU - Fritz, Jakob
AU - Leita, Corrado
AU - Polychronakis, Michalis
PY - 2013
Y1 - 2013
N2 - Server-side code injection attacks used to be one of the main culprits for the spread of malware. A vast amount of research has been devoted to the problem of effectively detecting and analyzing these attacks. Common belief seems to be that these attacks are now a marginal threat compared to other attack vectors such as drive-by download and targeted emails. However, information on the complexity and the evolution of the threat landscape in recent years is mostly conjectural. This paper builds upon five years of data collected by a honeypot deployment that provides a unique, long-term perspective obtained by traffic monitoring at the premises of different organizations and networks. Our contributions are twofold: first, we look at the characteristics of the threat landscape and at the major changes that have happened in the last five years; second, we observe the impact of these characteristics on the insights provided by various approaches proposed in previous research. The analysis underlines important findings that are instrumental at driving best practices and future research directions.
AB - Server-side code injection attacks used to be one of the main culprits for the spread of malware. A vast amount of research has been devoted to the problem of effectively detecting and analyzing these attacks. Common belief seems to be that these attacks are now a marginal threat compared to other attack vectors such as drive-by download and targeted emails. However, information on the complexity and the evolution of the threat landscape in recent years is mostly conjectural. This paper builds upon five years of data collected by a honeypot deployment that provides a unique, long-term perspective obtained by traffic monitoring at the premises of different organizations and networks. Our contributions are twofold: first, we look at the characteristics of the threat landscape and at the major changes that have happened in the last five years; second, we observe the impact of these characteristics on the insights provided by various approaches proposed in previous research. The analysis underlines important findings that are instrumental at driving best practices and future research directions.
UR - https://www.scopus.com/pages/publications/84888390980
U2 - 10.1007/978-3-642-41284-4_3
DO - 10.1007/978-3-642-41284-4_3
M3 - Conference contribution
AN - SCOPUS:84888390980
SN - 9783642412837
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 41
EP - 61
BT - Research in Attacks, Intrusions, and Defenses - 16th International Symposium, RAID 2013, Proceedings
PB - Springer Verlag
Y2 - 23 October 2013 through 25 October 2013
ER -