返回
New deep learning method to detect code injection attacks on hybrid applications
DOI:10.1016/j.jss.2017.11.001.png)
摘要
En 中文
Mobile phones are becoming increasingly pervasive. Among them, HTML5-based hybrid applications are more and more popular because of their portability on different systems. However these applications suffer from code injection attacks. In this paper, we construct a-novel deep learning network, Hybrid Deep Learning Network (HDLN), and use it to detect these attacks. At first, based on our previous work, we extract more features from Abstract Syntax Tree (AST) of JavaScript and employ three methods to select key features. Then we get the feature vectors and train HDLN to distinguish vulnerable applications from normal ones. Finally thorough experiments are done to validate our methods. The results show our detection approach with HDLN achieves 97.55% in accuracy and 97.60% in AUC, which outperforms those with other traditional classifiers and gets higher average precision than other detection methods. (C) 2017 Elsevier Inc. All rights reserved.
Keyword:
Code injection
Hybrid application
Abstract syntax tree
Deep learning
期刊
IF:
4.1
论文数:
5.5K
被引数:
8.4K
机构
引用论文
Software architectural principles in contemporary mobile software: from conception to practice当代移动软件中的软件架构原则: 从概念到实践
Gradient-based learning applied to document recognition基于梯度的学习在文档识别中的应用
PROCEEDINGS OF THE IEEE
IF25.9
Toward Efficient Multi-Keyword Fuzzy Search Over Encrypted Outsourced Data With Accuracy Improvement在加密的外包数据上实现高效的多关键字模糊搜索,并提高准确性

