DocumentCode :
595557
Title :
The power of obfuscation techniques in malicious JavaScript code: A measurement study
Author :
Wei Xu ; Fangfang Zhang ; Sencun Zhu
Author_Institution :
Dept. of Comput. Sci. & Eng., Pennsylvania State Univ., University Park, PA, USA
fYear :
2012
fDate :
16-18 Oct. 2012
Firstpage :
9
Lastpage :
16
Abstract :
JavaScript based attacks have been reported as the top Internet security threats in recent years. Since most of the Internet users rely on anti-virus software to protect themselves from malicious JavaScript code, attackers exploit JavaScript obfuscation techniques to evade the detection of anti-virus software. To better understand the obfuscation techniques adopted by malicious JavaScript code, we conduct a measurement study. We first categorize observed JavaScript obfuscation techniques. Then we conduct a statistic analysis on the usage of different categories of obfuscation techniques in real-world malicious JavaScript samples. We also study the detection effectiveness of 20 most popular anti-virus software against obfuscation techniques. Based on the results, we analyze the cause of the popularity of obfuscation in malicious JavaScript code; the reason behind the choice of obfuscation techniques and the difference between benign obfuscation and malicious obfuscation. Moreover, we also provide suggestions for designing effective obfuscation detection approaches in future.
Keywords :
Internet; Java; invasive software; statistical analysis; Internet security threats; JavaScript based attacks; JavaScript obfuscation techniques; antivirus software; benign obfuscation; malicious JavaScript code; malicious obfuscation; obfuscation detection approaches; real-world malicious JavaScript samples; statistic analysis; Abstracts; Electronic mail; Software;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Malicious and Unwanted Software (MALWARE), 2012 7th International Conference on
Conference_Location :
Fajardo, PR
Print_ISBN :
978-1-4673-4880-5
Type :
conf
DOI :
10.1109/MALWARE.2012.6461002
Filename :
6461002
Link To Document :
بازگشت