4 ms·
Detect if your site is hacked
- undecisive 6y agoThe post's idea: Uptime monitoring with screenshot diffing. As the post points out, this only works if the site's content doesn't change very often, but for static sites this might be worthwhile. Personally, I think that static sites are very easy to make secure, and sites that don't update often tend not to have much traffic, therefore don't make much money, and as such may not want to pay for this extra service (though I admit there are exceptions) That said, if we could mark "expected change zones" and "expected stretch zones" in the images, such that blog posts or news articles would be exempt, then we could tell if it's a site hack or just new content... that might be usable. A second phase (and much research required) might be to detect hack-based content within these zones using some kind of text-based machine learning, comparing usual content and examples of the kinds of things hackers usually add. Of course, this may be made harder in an American election year...
- Akcium 6y agoOh thank you for such a good feedback. Well, as a first step I thought that if we have a site with changing content, like a blog, then the area of blog posts occupies some percentage of the site. So we can correct the threshold, like, if the picture has changed more than 50% then alarm. Regarding static sites: well yes, they are easy to protect, however I guess there are tons of sites on wordpress with 1-2 pages (like company site), which are in fact static but written in php and may use outdated plugin or something. I'm somehow thrilled of this idea because I want to provide something new, while it's pretty hard :) In the end it's kind of possible to do all this stuff like - Select areas which should be checked for changes - Select areas which shouldn't - As you said, text-basic machine learning, though it seems hard for me, but still - Plus, what I also like is Google Vision API which at least can detect adult content. This should be pretty universal, if you know that you shouldn't have this on any condition, even if you have dynamic content changing Hmm..
- undecisive 6y ago> I guess there are tons of sites on wordpress with 1-2 pages (like company site), which are in fact static but written in php and may use outdated plugin or something. Depressingly true :D Text-based machine learning is an interesting one. There are a few mature tools and techniques out there for doing Latent semantic analysis, which might be a relatively low-overhead way to detect unrelated content (though some sites will produce a lot of false positives due to the nature of the sites) I guess the question is how much processing / storage you want to expend for each site in crawling it and building a model for it, so you can evaluate what has changed and whether it's in keeping with the rest of the site. ... and then of course in an election year, when people post an obligatory "go vote" message, suddenly everybody's site is triggering the hack alert. But I guess that's unavoidable whatever you do. I'd be interested to find out what the top ten "hack types" are - I'd guess that directing people to adult sites using adult images probably isn't the most common, but would definitely be in that list, so I could see why that might be useful. That said, I think a big vector for that kind of content would be via advertising networks, which would probably blacklist an uptime monitoring site anyway. Sounds like an interesting adventure though. Good luck with it!