A. Moshchuk, T. Bragin, S. D. Gribble, H. M. Levy, "A Crawler-based Study of Spyware on the Web", in Proceedings of the 13th Annual Network and Distributed Systems Security Symposium (NDSS 2006), The Internet Society, 2006. Abstract. Malicious spyware poses a significant threat to desktop security and integrity. This paper examines that threat from an Internet perspective. Using a crawler, we performed a large-scale, longitudinal study of the Web, sampling both executables and conventional Web pages for malicious objects. Our results show the extent of spyware content. For example, in a May 2005 crawl of 18 million URLs, we found spyware in 13.4% of the 21,200 executables we identified. At the same time, we found scripted “drive-by download” attacks in 5.9% of the Web pages we processed. Our analysis quantifies the density of spyware, the types of of threats, and the most dangerous Web zones in which spyware is likely to be encountered. We also show the frequency with which specific spyware programs were found in the content we crawled. Finally, we measured changes in the density of spyware over time; e.g., our October 2005 crawl saw a substantial reduction in the presence of drive-by download attacks, compared with those we detected in May. @inproceedings{DBLP:conf/ndss/MoshchukBGL06, author = {Alex Moshchuk and Tanya Bragin and Steven D. Gribble and Henry M. Levy}, title = {A Crawler-based Study of Spyware in the Web}, booktitle = {NDSS}, year = {2006}, ee = {http://www.isoc.org/isoc/conferences/ndss/06/proceedings/html/2006/papers/spycrawler.pdf}, crossref = {DBLP:conf/ndss/2006}, bibsource = {DBLP, http://dblp.uni-trier.de} } @proceedings{DBLP:conf/ndss/2006, title = {Proceedings of the Network and Distributed System Security Symposium, NDSS 2006, San Diego, California, USA}, booktitle = {NDSS}, publisher = {The Internet Society}, year = {2006}, isbn = {1-891562-22-3, 1-891562-21-5}, bibsource = {DBLP, http://dblp.uni-trier.de} }