MOBIL QURILMALARDA XAVFLI URLʼLARNI KOʻP QATLAMLI SANDBOX TAHLILI

Authors

  • Erkinov Shohjahon Sherali o‘g‘li Author
  • Abdullayev Xushnud Raxmatulla o‘g‘li Author
  • Axmatov Bekzod Nurali o‘g‘li Author
  • Ramazonova Marjona Ikrom qizi Author

Keywords:

URL xavfsizligi, sandbox tahlili, fishing havolalar, threat intelligence, URLhaus, Google Safe Browsing, VirusTotal, homoglyph hujumi, IDN spoofing, URL expander, LRU kesh, mobil xavfsizlik, koʻp qatlamli aniqlash, malware tarqatish.

Abstract

Ushbu maqolada mobil qurilmalarda foydalanuvchiga kelayotgan URL havolalarni avtomatik xavfsizlik bahosi orqali aniqlash uchun koʻp qatlamli sandbox arxitekturasi taklif etilgan. Tizim toʻrt ketma-ket qatlamdan iborat: birinchi qatlam offline evristika asosida URL strukturasini tahlil qiladi (shubhali yuqori darajadagi domenlar, homoglyph hujumlari, IP-manzilli URLʼlar, anormal uzunlik); ikkinchi qatlam URLhaus xavfli URL bazasiga soʻrov yuboradi; uchinchi qatlam Google Safe Browsing API v4 orqali ishlaydi; toʻrtinchi qatlam VirusTotal koʻplab antivirus mexanizmlari orqali tekshirishni faqat “deep scan” rejimida ishlatadi. URLʼlarni tekshirishdan oldin maxsus expander modul qisqartirilgan havolalarni (t.me, bit.ly, tinyurl) haqiqiy manzilga ochib beradi. Yakuniy xavf bali qatlamlar maksimumini kombinatsion bonus bilan birga hisoblaydi, natijalar esa 24 soatlik LRU keshda saqlanadi. Yondashuv mobil qurilmaning chekli resurslari va xizmat kvotalarini hisobga olgan holda, foydalanuvchining xabar mazmunini tashqariga uzatmasdan ishlash imkonini beradi.

References

1. MITRE ATT&CK Framework: Initial Access -- Phishing (T1566). -- The MITRE Corporation, 2024. -- URL: https://attack.mitre.org/techniques/T1566/

2. APWG Phishing Activity Trends Report. -- Anti-Phishing Working Group, 2024. -- URL: https://apwg.org/trendsreports/

3. URLhaus -- abuse.ch threat intelligence platform. -- abuse.ch, 2024. -- URL: https://urlhaus.abuse.ch/

4. Google Safe Browsing API v4 Reference. -- Google Developers, 2024. -- URL: https://developers.google.com/safe-browsing/v4

5. VirusTotal Public API v3 Documentation. -- VirusTotal (Google), 2024. -- URL: https://docs.virustotal.com/

6. Unicode Technical Standard #39: Unicode Security Mechanisms. -- Unicode Consortium, 2023. -- URL: https://www.unicode.org/reports/tr39/

7. Gabrilovich E., Gontmakher A. The homograph attack. // Communications of the ACM. -- 2002. -- Vol. 45, No. 2. -- P. 128.

8. Holgers T., Watson D., Gribble S. Cutting through the confusion: A measurement study of homograph attacks. // USENIX Annual Technical Conference. -- 2006. -- P. 261-266.

9. PhishTank Phishing URL Database. -- Cisco Talos, 2024. -- URL: https://phishtank.org/

10. OpenPhish Phishing Intelligence. -- OpenPhish, 2024. -- URL: https://openphish.com/

11. Pochat V. L., Goethem T., Tajalizadehkhoob S., Korczynski M., Joosen W. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. // Proceedings of NDSS Symposium. -- 2019.

12. Hu T. C., Sengupta S. A least recently used (LRU) cache replacement algorithm. // Performance Evaluation. -- 1990. -- Vol. 11, No. 4. -- P. 245-257.

13. Hoffman P., McManus P. RFC 8484: DNS Queries over HTTPS (DoH). -- IETF, 2018. -- URL: https://datatracker.ietf.org/doc/html/rfc8484

14. Laurie B., Langley A., Kasper E. RFC 6962: Certificate Transparency. -- IETF, 2013. -- URL: https://datatracker.ietf.org/doc/html/rfc6962

15. Nielsen J. Response Times: The 3 Important Limits. // Nielsen Norman Group, 1993. -- URL: https://www.nngroup.com/articles/response-times-3-important-limits/

16. Android CameraX library: Getting Started Guide. -- Google Developers, 2024. -- URL: https://developer.android.com/training/camerax

17. Google ML Kit Barcode Scanning API. -- Google Developers, 2024. -- URL: https://developers.google.com/ml-kit/vision/barcode-scanning

Downloads

Published

2026-06-10