• Home
  • Search
  • Understanding Evasion Techniques that Abuse Differences Among JavaScript Implementations
  • Cite Icon2
  • https://doi.org/10.1007/978-3-319-68786-5_22Copy DOI Icon

Understanding Evasion Techniques that Abuse Differences Among JavaScript Implementations

  • Jan 1, 2017
  • Yuta Takata +4 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

There is a common approach to detecting drive-by downloads using a classifier based on the static and dynamic features of malicious websites collected using a honeyclient. However, attackers detect the honeyclient and evade analysis using sophisticated JavaScript code. The evasive code indirectly identifies clients by abusing the differences among JavaScript implementations. Attackers deliver malware only to targeted clients on the basis of the evasion results while avoiding honeyclient analysis. Therefore, we are faced with a problem in that honeyclients cannot extract features from malicious websites and the subsequent classifier does not work. Nevertheless, we can observe the evasion nature, i.e., the results in accessing malicious websites by using targeted clients are different from those by using honeyclients. In this paper, we propose a method of extracting evasive code by leveraging the above differences to investigate current evasion techniques and to use them for analyzing malicious websites. Our method analyzes HTTP transactions of the same website obtained using two types of clients, a real browser as a targeted client and a browser emulator as a honeyclient. As a result of evaluating our method with 8,467 JavaScript samples executed in 20,272 malicious websites, we discovered unknown evasion techniques that abuse the differences among JavaScript implementations. These findings will contribute to improving the analysis capabilities of conventional honeyclients.

Similar Papers
  • Conference Article
  • Citations25

An Intelligent Behavior-Based Ransomware Detection System For Android Platform

  • Dec 01, 2019
  • Abdulrahman Alzahrani +3
  • Research Article
  • Citations35

A Malicious Mining Code Detection Method Based on Multi-Features Fusion

  • Sep 01, 2023
  • IEEE Transactions on Network Science and Engineering
  • Shudong Li +5
  • Conference Article
  • Citations16

Detecting Malicious Websites by Integrating Malicious, Benign, and Compromised Redirection Subgraph Similarities

  • Jul 01, 2017
  • Toshiki Shibahara +4
  • Research Article
  • Citations1

Detection of metamorphic malicious mobile code on android-based smartphones

  • Jan 01, 2017
  • International Journal of Advanced Media and Communication
  • Jeong Nyeo Kim +3
  • Research Article

Detection of metamorphic malicious mobile code on android-based smartphones

  • Jan 01, 2017
  • International Journal of Advanced Media and Communication
  • Sangdon Kim +3
  • Conference Article
  • Citations4

Efficient Method for Analyzing Malicious Websites by Using Multi-Environment Analysis System

  • Aug 01, 2017
  • Masanori Hirotomo +5
  • PDF
  • Research Article
  • Citations38

Clustering Algorithm-Based Data Fusion Scheme for Robust Cooperative Spectrum Sensing

  • Jan 01, 2020
  • IEEE Access
  • Shunchao Zhang +5
  • Conference Article
  • Citations28

Taxonomy on malware evasion countermeasures techniques

  • Feb 01, 2018
  • Chandra Sekar Veerappan +3
  • Book Chapter
  • Citations6

Website Forensic Investigation to Identify Evidence and Impact of Compromise

  • Jan 01, 2017
  • Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
  • Yuta Takata +4
  • Discussion

Rucas over privacy of domain name registration

  • Apr 01, 2001
  • Computer Fraud & Security
  • Conference Article
  • Citations4

An implementation of Botnet dataset to predict accuracy based on network flow model

  • Sep 01, 2017
  • Yesta Medya Mahardhika +2
  • Book Chapter
  • Citations7

Defending the OSN-Based Web Applications from XSS Attacks Using Dynamic JavaScript Code and Content Isolation

  • Oct 04, 2017
  • Pooja Chaudhary +2
  • Conference Article
  • Citations58

RansHunt: A support vector machines based ransomware analysis framework with integrated feature set

  • Dec 01, 2017
  • Md Mahbub Hasan +1
  • Supplementary Content

Antivirus evasion methods

  • Mar 17, 2021
  • Dione (University of Piraeus)
  • Ιωάννης Παναγόπουλος +1
  • Research Article

Dual stage ensemble technique for intrusion detection in cloud computing

  • Mar 22, 2023
  • Web Intelligence
  • P Neelakantan +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.