Conference item
Malicons: detecting payload in favicons
- Abstract:
- A recent version of the “Vawtrak” malware used steganography to hide the addresses of the command and control channels in favicons: small images automatically downloaded by the web browser. Since almost all research in steganalysis focuses on natural images, we study how well these methods can detect secret messages in favicons. The study is performed on a large corpus of favicons downloaded from the internet and applies a number of state-of-art steganalysis techniques, as well as proposing very simple novel features that exploit flat areas in favicons. The ultimate question is whether we can detect Vawtrak’s steganographic favicons with a sufficiently low false positive rate.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, pdf, 386.4KB, Terms of use)
-
- Publisher copy:
- 10.2352/ISSN.2470-1173.2016.8.MWSF-079
Authors
- Publisher:
- Ingentaconnect
- Host title:
- Electronic Imaging: Media Watermarking, Security, and Forensics 2016
- Journal:
- Electronic Imaging: Media Watermarking, Security, and Forensics 2016 More from this journal
- Issue:
- 2016
- Pages:
- 1-9
- Publication date:
- 2016-02-14
- DOI:
- Pubs id:
-
pubs:602187
- UUID:
-
uuid:895a0272-412f-4a64-ba07-70c2c497dd88
- Local pid:
-
pubs:602187
- Source identifiers:
-
602187
- Deposit date:
-
2016-02-13
- ARK identifier:
Terms of use
- Copyright holder:
- Society for Imaging Science and Technology
- Copyright date:
- 2016
- Notes:
- © 2016 Society for Imaging Science and Technology. This is the accepted manuscript version of the article.The final version is available from Ingenta Connect at: https://doi.org/10.2352/ISSN.2470-1173.2016.8.MWSF-079
If you are the owner of this record, you can report an update to it here: Report update to this record