arrow
Return

Research on Malicious JavaScript Detection Technology Based on LSTM

delete2018-01-01
delete27
delete
OA
AI
方勇 (Yong Fang)
C
Cheng Huang *
L
Liang Liu
M
Min Xue
DOI:10.1109/ACCESS.2018.2874098delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The attacker injects malicious JavaScript into web pages to achieve the purpose of implanting Trojan horses, spreading viruses, phishing, and obtaining secret information. By analyzing the existing researches on malicious JavaScript detection, a malicious JavaScript detection model based on LSTM (Long Short-Term Memory) is proposed. Features are extracted from the semantic level of bytecode, and the method of word vector is optimized. It can distinguish malicious JavaScript code and combat obfuscated code effectively. Experiments showed that the accuracy of detection model based on LSTM is 99.51%, and the F1-score is 98.37%, which is better than the existing model based on Random Forest and SVM algorithm.
Keywords:
JavaScript
malicious code detection
bytecode
word vector
LSTM

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

S
sichuan university
Scholars:
11.9W
Papers: 7.7W
Citations: 100