AMA: Static Code Analysis of Web Page For The Detection of Malicious Scripts

被引:21
|
作者
Seshagiri, Prabhu [1 ]
Vazhayil, Anu [2 ]
Sriram, Padmamala [2 ]
机构
[1] Amrita Vishwa Vidyapeetham, Amrita Ctr Cybersecur Syst & Networks, Amritapuri Campus, Kollam, Kerala, India
[2] Amrita Vishwa Vidyapeetham, Comp Sci & Engn, Amritapuri Campus, Kollam, Kerala, India
来源
PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING AND COMMUNICATIONS | 2016年 / 93卷
关键词
Obfuscation; Static Detection; Probable Plaintext attack;
D O I
10.1016/j.procs.2016.07.291
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
JavaScript language, through its dynamic feature, provides user interactivity with websites. It also pose serious security threats to both user and website. On top of this, obfuscation is widely used to hide its malicious purpose and to evade the detection of antivirus software. Malware embedded in web pages is regularly used as part of targeted attacks. To hinder detection by antivirus scanners, the malicious code is usually obfuscated, often with encodings like hexadecimal, unicode, base64, escaped characters and rarely with substitution ciphers like Vigenere, Caesar and Atbash. The malicious iframes are injected to the websites using JavaScript and are also made hidden from the users perspective in-order to prevent detection. To defend against obfuscated malicious JavaScript code, we propose a mostly static approach called, AMA, Amrita Malware Analyzer, a framework capable of detecting the presence of malicious code through static code analysis of web page. To this end, the framework performs probable plaintext attack using strings likely contained in malicious web pages. But this approach targets only few among many possible obfuscation strategies. The evaluation based on the links provided in the Malware domain list demonstrates high level accuracy (C) 2016 The Authors. Published by Elsevier B.V.
引用
收藏
页码:768 / 773
页数:6
相关论文
共 50 条
  • [1] UTANSA: Static Approach for Multi-language Malicious Web Scripts Detection
    Huang, Weiqing
    Jia, Chenggang
    Yu, Min
    Li, Gang
    Liu, Chao
    Jiang, Jianguo
    26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [2] Mechanism analysis and prevention of overflow-type web page malicious code
    Li, Zhi-Yong
    Tao, Ran
    Wang, Yue
    Zhang, Hao
    Binggong Xuebao/Acta Armamentarii, 2010, 31 (06): : 832 - 836
  • [3] A WEB PAGE MALICIOUS SCRIPT DETECTION SYSTEM
    Zhang, Siyue
    Wang, Weiguang
    Chen, Zhao
    Gu, Heng
    Liu, Jianyi
    Wang, Cong
    2014 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND INTELLIGENCE SYSTEMS (CCIS), 2014, : 394 - 399
  • [4] Detection Method of WEB Malicious Code based on Link Analysis
    Lu Zhiyong
    Sui Sai
    Huang Chengdong
    Wang Xueyu
    2016 INTERNATIONAL SYMPOSIUM ON COMPUTER, CONSUMER AND CONTROL (IS3C), 2016, : 511 - 514
  • [5] Malicious Web Page Detection Based on Feature Classification
    Phakoontod, Chanachai
    Limthanmaphon, Benchaphon
    2012 7TH INTERNATIONAL CONFERENCE ON COMPUTING AND CONVERGENCE TECHNOLOGY (ICCCT2012), 2012, : 66 - 71
  • [6] Static detection of application backdoorsDetecting both malicious software behavior and malicious indicators from the static analysis of executable code
    Chris Wysopal
    Chris Eng
    Tyler Shields
    Datenschutz und Datensicherheit - DuD, 2010, 34 (3) : 149 - 155
  • [7] Feature optimization and hybrid classification for malicious web page detection
    Deng, Weiping
    Peng, Yan
    Yang, Fan
    Song, Jun
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (16):
  • [8] SoK: Static Configuration Analysis in Infrastructure as Code Scripts
    Konala, Pandu Ranga Reddy
    Kumar, Vimal
    Bainbridge, David
    2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 281 - 288
  • [9] Static Code Analysis and Detection of Multiple Malicious Java']Java Applets using SVM
    Salunkhe, Sapana Y.
    Pattewar, Tareek M.
    2015 International Conference on Green Computing and Internet of Things (ICGCIoT), 2015, : 1538 - 1542
  • [10] Static Detection of Malicious Code in Programs Using Semantic Techniques
    Navid, Syed Zami-Ul-Haque
    Dey, Protik
    Hasan, Shamiul
    Ali, Muhammad Masroor
    PROCEEDINGS OF 2020 11TH INTERNATIONAL CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (ICECE), 2020, : 327 - 330