• DocumentCode
    595557
  • Title

    The power of obfuscation techniques in malicious JavaScript code: A measurement study

  • Author

    Wei Xu ; Fangfang Zhang ; Sencun Zhu

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Pennsylvania State Univ., University Park, PA, USA
  • fYear
    2012
  • fDate
    16-18 Oct. 2012
  • Firstpage
    9
  • Lastpage
    16
  • Abstract
    JavaScript based attacks have been reported as the top Internet security threats in recent years. Since most of the Internet users rely on anti-virus software to protect themselves from malicious JavaScript code, attackers exploit JavaScript obfuscation techniques to evade the detection of anti-virus software. To better understand the obfuscation techniques adopted by malicious JavaScript code, we conduct a measurement study. We first categorize observed JavaScript obfuscation techniques. Then we conduct a statistic analysis on the usage of different categories of obfuscation techniques in real-world malicious JavaScript samples. We also study the detection effectiveness of 20 most popular anti-virus software against obfuscation techniques. Based on the results, we analyze the cause of the popularity of obfuscation in malicious JavaScript code; the reason behind the choice of obfuscation techniques and the difference between benign obfuscation and malicious obfuscation. Moreover, we also provide suggestions for designing effective obfuscation detection approaches in future.
  • Keywords
    Internet; Java; invasive software; statistical analysis; Internet security threats; JavaScript based attacks; JavaScript obfuscation techniques; antivirus software; benign obfuscation; malicious JavaScript code; malicious obfuscation; obfuscation detection approaches; real-world malicious JavaScript samples; statistic analysis; Abstracts; Electronic mail; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Malicious and Unwanted Software (MALWARE), 2012 7th International Conference on
  • Conference_Location
    Fajardo, PR
  • Print_ISBN
    978-1-4673-4880-5
  • Type

    conf

  • DOI
    10.1109/MALWARE.2012.6461002
  • Filename
    6461002