Obfuscated Malicious JavaScript Detection by Machine Learning
Jinkun Pan,Xiaoguang Mao +1 more
- 09 Apr 2016
- pp 805-810
TL;DR: The empirical results demonstrate that the proposed machine-learning based detection approach is able to detect obfuscated malicious JavaScript code both effectively and efficiently.
read more
Abstract: In recent years, malicious JavaScript code has become more and more pervasive and been used by attackers to perform their attacks on the Web. To evade the detection of defense measures, various kinds of obfuscation techniques have been applied by the malicious script, taking advantage of the dynamic nature of JavaScript language. In this paper, we propose a new machine-learning based detection approach aiming at defeating such evasion attempts. Dynamic execution traces are recorded to capture all behaviors performed by the malicious script, including the dynamic generated code. Semantic-based deobfuscation is used to simplify the traces to get more concise and more essential instructions. None-ordered and none-concessive trace patterns are extracted from the deobfuscated traces to represent the intrinsic features for malicious scripts. We evaluated our approach with a large number of dataset collected from the Internet. The empirical results demonstrate that our approach is able to detect obfuscated malicious JavaScript code both effectively and efficiently.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Deobfuscation, unpacking, and decoding of obfuscated malicious JavaScript for machine learning models detection performance improvement
TL;DR: This study performs Deobfuscation, Unpacking, and Decoding (DUD-preprocessing) by function redefinition using a Virtual Machine, a JS code editor, and a python int_to_str() function to facilitate feature learning by the FastText model, which enhances feature learning and provides improved accuracy in the detection of obfuscated malicious JS codes.
References
Prophiler: a fast filter for the large-scale detection of malicious web pages
Davide Canali,Marco Cova,Giovanni Vigna,Christopher Kruegel +3 more
- 28 Mar 2011
TL;DR: The authors' filter, called Prophiler, uses static analysis techniques to quickly examine a web page for malicious content, and automatically derive detection models that use these features using machine-learning techniques applied to labeled datasets.
402
Rozzle: De-cloaking Internet Malware
Clemens Kolbitsch,Benjamin Livshits,Benjamin G. Zorn,Christian Seifert +3 more
- 20 May 2012
TL;DR: Rozzle, a JavaScript multi-execution virtual machine, is proposed as a way to explore multiple execution paths within a single execution so that environment-specific malware will reveal itself, and it is shown that Rozzle triples the effectiveness of online runtime detection.
Efficient and effective realtime prediction of drive-by download attacks
TL;DR: By dynamically monitoring the bytecode stream generated by a web browser during rendering, the approach is able to detect previously unseen drive-by download attacks at runtime, making the approach amenable to in-browser drive- by download detection on resource constrained devices, such as mobile phones.
31
Throwing a monkeywrench into web attackers plans
Armin Büscher,Michael Meier,Ralf Benzmüller +2 more
- 31 May 2010
TL;DR: MonkeyWrench is a low-interaction web-honeyclient allowing automatic identification of malicious web pages by performing static analysis of the HTML-objects in a web page as well as dynamic analysis of scripts by execution in an emulated browser environment and is able to identify the exact vulnerability triggered by a malicious page.
ZDVUE: prioritization of javascript attacks to discover new vulnerabilities
Sandeep Karanth,Srivatsan Laxman,Prasad Naldurg,Ramarathnam Venkatesan,John Lambert,Jinwook Shin +5 more
- 21 Oct 2011
TL;DR: ZDVUE is a tool for automatic prioritization of suspicious JavaScript traces, which can lead to early detection of potential zero-day vulnerabilities, and is used in the organization on a routine basis to automatically filter, analyze, and prioritize thousands of downloaded JavaScript files.