返回
JStrong: Malicious JavaScript detection based on code semantic representation and graph neural network
DOI:10.1016/j.cose.2022.102715.png)
摘要
En 中文
Web development technology has experienced significant progress. The creation of JavaScript has highly enriched the interactive ability of the client. However, the attacker uses the dynamic characteristics of the JavaScript language to embed malicious code into web pages to achieve the purpose of smuggling, redirection, and so on. Traditional methods based on static feature detection are therefore difficult to detect malicious code after confusion, and the method based on dynamic analysis is inefficient. To meet these challenges, this paper proposes a static detection model JStrong based on graph neural network. The model first generates an abstract syntax tree from the JavaScript source code, and then adds data flow and control flow information into the program dependency graph. In addition, we embed the nodes and edges of the graph into the feature vector and fully learn the features of the whole graph through the graph neural network. We take advantage of a real-world dataset collected from the top website and GitHub to evaluate JStrong and compare it to the state-of-the-art method. Experimental results show that JStrong achieves near-perfect classification performance and is superior to the state-of-the-art method.(c) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Malicious JavaScript
Code representation
Graph neural network
Program dependency graph
Scripts detection
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Late Bronze Age climate change and the destruction of the Mycenaean Palace of Nestor at Pylos青铜时代晚期的气候变化和皮洛斯内斯特迈锡尼宫的破坏
PLOS ONE
IF0
JSContana: Malicious JavaScript detection using adaptable context analysis and key feature extraction
COMPUTERS & SECURITY
IF5.4
Removal and recovery of mercury from chlor-alkali petrochemical wastes using γ-Fe2O3 nanoparticles使用 γ-Fe2O3纳米颗粒从氯碱石化废物中去除和回收汞
没有更多内容

