Detection of malicious URLs in a web page
    8.
    发明授权
    Detection of malicious URLs in a web page 有权
    检测网页中的恶意URL

    公开(公告)号:US08505094B1

    公开(公告)日:2013-08-06

    申请号:US12686458

    申请日:2010-01-13

    摘要: Detection of malicious URLs in a Web page retrieved by a computer user is based in a backend security service or upon the user's computer. The HTML code download by the user is first scanned to detect any embedded links such as URLs found in frames or scripts. Features related to the layout of such a URL (position, visibility) are identified. Features related to the referring nature of the URL (page rank of parent, page rank of child) are identified. Features indicating the relevancy between the content of the parent Web page and the content of the Web page identified by the embedded URL identified. Each set of features is transformed into a binary vector and these vectors are fed into a decision engine such as a classifier algorithm. The classifier algorithm outputs a score indicating whether or not the suspect URL (and the Web page to which it links) is malicious or not. The user may be warned by a display message.

    摘要翻译: 由计算机用户检索的网页中的恶意URL的检测基于后端安全服务或用户的计算机。 首先扫描用户下载的HTML代码,以检测任何嵌入的链接,例如在帧或脚本中找到的URL。 识别与这样的URL(位置,可见性)的布局相关的特征。 识别与URL的参考性质相关的特征(父级的页面排名,小孩的页面排名)。 表明父网页的内容与所识别的嵌入式网页所标识的网页的内容之间的相关性。 每组特征被转换成二进制向量,并且这些向量被馈送到诸如分类器算法的决策引擎中。 分类器算法输出一个分数,表示可疑URL(和链接到的网页)是否是恶意的。 用户可能会受到显示消息的警告。