Detailed Information

Cited 3 time in webofscience Cited 3 time in scopus
Metadata Downloads

Lightweight detection method of obfuscated landing sites based on the AST structure and tokens

Authors
Han, K.H.Hwang, S.O.
Issue Date
Sep-2020
Publisher
MDPI AG
Keywords
Abstract syntax tree; Malicious JavaScript; Obfuscation detection; Redirection detection; Static analysis
Citation
Applied Sciences (Switzerland), v.10, no.17
Journal Title
Applied Sciences (Switzerland)
Volume
10
Number
17
URI
https://scholarworks.bwise.kr/gachon/handle/2020.sw.gachon/78455
DOI
10.3390/app10176116
ISSN
2076-3417
Abstract
Attackers use a variety of techniques to insert redirection JavaScript that leads a user to a malicious webpage, where a drive-by-download attack is executed. In particular, the redirection JavaScript in the landing site is obfuscated to avoid detection systems. In this paper, we propose a lightweight detection system based on static analysis to classify the obfuscation type and to promptly detect the obfuscated redirection JavaScript. The proposed model detects the obfuscated redirection JavaScript by converting the JavaScript into an abstract syntax tree (AST). Then, the structure and token information are extracted. Specifically, we propose a lightweight AST to identify the obfuscation type and the revised term frequency-inverse document frequency to efficiently detect the malicious redirection JavaScript. This approach enables rapid identification of the obfuscated redirection JavaScript and proactive blocking of the webpages that are used in drive-by-download attacks. © 2020 by the authors.
Files in This Item
There are no files associated with this item.
Appears in
Collections
IT융합대학 > 컴퓨터공학과 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Hwang, Seong Oun photo

Hwang, Seong Oun
College of IT Convergence (컴퓨터공학부(컴퓨터공학전공))
Read more

Altmetrics

Total Views & Downloads

BROWSE