This paper investigates the potential causes of the vulnerabilities of free content websites to address risks and maliciousness. Assembling more than 1,500 websites with free and premium content, we identify their content management system (CMS) and malicious attributes. We use frequency analysis at both the aggregate and per category of content (books, games, movies, music, and software), utilizing the unpatched vulnerabilities, total vulnerabilities, malicious count, and percentiles to uncover trends and affinities of usage and maliciousness of CMS{'s} and their contribution to those websites. Moreover, we find that, despite the significant number of custom code websites, the use of CMS{'s} is pervasive, with varying trends across types and categories. Finally, we find that even a small number of unpatched vulnerabilities in popular CMS{'s} could be a potential cause for significant maliciousness.
翻译:本文调查了自由内容网站在应对风险和恶意方面的脆弱性的潜在原因。 我们聚集了1,500多个免费和有溢价内容的网站,确定了其内容管理系统(CMS)和恶意属性。我们使用总内容和每类内容(书籍、游戏、电影、音乐和软件)的频率分析,利用未流出的脆弱性、全部脆弱性、恶意计数和百分数来发现CMS{} 及其在使用和恶意方面的趋势和关联性及其对这些网站的贡献。此外,我们发现,尽管有相当多的定制代码网站,但CMS{}的使用是普遍的,其类型和类别不同。最后,我们发现即使流行的CMS{}中少量未流出的脆弱性也可能是重大恶意行为的潜在原因。