Measurement of IP and network tracking behaviour of malicious websites

Abstract

IP tracking and cloaking are practices for identifying users which are used legitimately by websites to provide services and content tailored to particular users. However, it is believed that these practices are also used by malicious websites to avoid detection by anti-virus companies crawling the web to find malware. In addition, malicious websites are also believed to use IP tracking in order to deliver targeted malware based upon a history of previous visits by users. In this paper we empirically investigate these beliefs and collect a large dataset of suspicious URLs in order to identify at what level IP tracking takes place that is at the level of an individual address or at the level of their network provider or organisation (Network tracking). Our results illustrate that IP tracking is used in a small subset of domains within our dataset while no strong indication of network tracking was observed.

DOI: 10.1145/2843043.2843358

Extracted Key Phrases

11 Figures and Tables

Cite this paper

@inproceedings{Mansoori2016MeasurementOI, title={Measurement of IP and network tracking behaviour of malicious websites}, author={Masood Mansoori and Ian Welch and Seyed Ebrahim Hashemi}, booktitle={ACSW}, year={2016} }