Preprints‎ > ‎

Malicious JavaScript Detection by Features Extraction by Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio

pubblicato 5 gen 2015, 13:38 da Gerardo Canfora
In recent years, JavaScript-based attacks have become one of the most common and successful types of attack. Existing techniques for detecting malicious JavaScripts could fail for different reasons. Some techniques are tailored on specific kinds of attacks, and are ineffective for others. Some other techniques require costly computational resources to be implemented. Other techniques could be circumvented with evasion methods. This paper proposes a method for detecting malicious JavaScript code based on five features that capture different characteristics of a script: execution time, external referenced domains and calls to JavaScript functions. Mixing different types of features could result in a more effective detection technique, and overcome the limitations of existing tools created for identifying malicious JavaScript. The experimentation carried out suggests that a combination of these features is able to successfully detect malicious JavaScript code (in the best cases we obtained a precision of 0.979 and a recall of 0.978).
e-Informatica Software Engineering Journal, Volume 8, Issue 1, 2014, pages: 65–78, DOI 10.5277/e-Inf140105