• Home
  • Search
  • JsSandbox: A Framework for Analyzing the Behavior of Malicious JavaScript Code using Internal Function Hooking
  • Cite Icon15
  • https://doi.org/10.3837/tiis.2012.02.019Copy DOI Icon

JsSandbox: A Framework for Analyzing the Behavior of Malicious JavaScript Code using Internal Function Hooking

  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Recently, many malicious users have attacked web browsers using JavaScript code that can execute dynamic actions within the browsers.By forcing the browser to execute malicious JavaScript code, the attackers can steal personal information stored in the system, allow malware program downloads in the client's system, and so on.In order to reduce damage, malicious web pages must be located prior to general users accessing the infected pages.In this paper, a novel framework (JsSandbox) that can monitor and analyze the behavior of malicious JavaScript code using internal function hooking (IFH) is proposed.IFH is defined as the hooking of all functions in the modules using the debug information and extracting the parameter values.The use of IFH enables the monitoring of functions that API hooking cannot.JsSandbox was implemented based on a debugger engine, and some features were applied to detect and analyze malicious JavaScript code: detection of obfuscation, deobfuscation of the obfuscated string, detection of URLs related to redirection, and detection of exploit codes.Then, the proposed framework was analyzed for specific features, and the results demonstrate that JsSandbox can be applied to the analysis of the behavior of malicious web pages.

Similar Papers
  • Conference Article
  • Citations33

Early detection of malicious behavior in JavaScript code

  • Oct 19, 2012
  • Kristof Schütt +3
  • Conference Article
  • Citations27

A Machine Learning Approach to Malicious JavaScript Detection using Fixed Length Vector Representation

  • Jul 01, 2018
  • Samuel Ndichu +3
  • Book Chapter
  • Citations3

Clustering Client Honeypot Data to Support Malware Analysis

  • Jan 01, 2010
  • Yaser Alosefer +1
  • Conference Article
  • Citations20

Detecting Obfuscated JavaScript Malware Using Sequences of Internal Function Calls

  • Mar 28, 2014
  • Alireza Gorji +1
  • Conference Article
  • Citations31

Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssembly

  • May 01, 2022
  • Alan Romano +3
  • Research Article
  • Citations10

Intelligent Defense against Malicious JavaScript Code

  • Apr 01, 2012
  • PIK - Praxis der Informationsverarbeitung und Kommunikation
  • Tammo Krueger +1
  • Book Chapter
  • Citations14

Measurement Study on Malicious Web Servers in the .nz Domain

  • Jan 01, 2009
  • Christian Seifert +4
  • Book Chapter
  • Citations7

Defending the OSN-Based Web Applications from XSS Attacks Using Dynamic JavaScript Code and Content Isolation

  • Oct 04, 2017
  • Pooja Chaudhary +2
  • Conference Article
  • Citations6

Research on Prevention Solution of Advanced Persistent Threat

  • Jan 01, 2014
  • Xiaomei Liu
  • PDF
  • Research Article
  • Citations2

Malicious and benign websites classification using machine learning methods

  • Aug 06, 2020
  • Theoretical and Applied Cybersecurity
  • M Lavreniuk +1
  • Conference Article
  • Citations14

Malicious Webpage Classification Based on Web Content Features using Machine Learning and Deep Learning

  • Oct 26, 2022
  • A Saleem Raja +3
  • Book Chapter

Cardinal Correlated Oversampling for Detection of Malicious Web Links Using Machine Learning

  • Sep 14, 2021
  • M Shyamala Devi +4
  • Conference Article
  • Citations6

An efficient visitation algorithm to improve the detection speed of high-interaction client honeypots

  • Nov 02, 2011
  • Hong-Geun Kim +4
  • Research Article
  • Citations1

Improving Malicious Web Code Classification with Sequence by Machine Learning

  • Oct 31, 2014
  • IEIE Transactions on Smart Processing and Computing
  • Incheon Paik
  • Conference Article
  • Citations68

A lexical approach for classifying malicious URLs

  • Jul 01, 2015
  • Michael Darling +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.