A web page malicious code detect approach based on script execution

Zhi Yong Li*, Ran Tao, Zhen He Cai, Hao Zhang

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Citations (Scopus)

Abstract

Web page malicious code detection is a crucial aspect of Internet security. Current web page malicious codes detection work by checking for "signatures", which attempt to capture (syntactic) characteristics of the known malicious codes. This reliance on a syntactic approach makes such detectors vulnerable to code obfuscations, increasingly used by malicious code writers, which alter syntactic prosperities of the malicious code without affecting their execution behavior significantly. This paper takes the position that the key to web page malicious code lies in their execution behavior. It proposes a script execution behavior feature based framework for analyzing propose of malicious codes and proving properties such as soundness and completeness of these malicious codes. Our approach analyses the script and confirms the script which contains malicious code by finding shellcode, overflow behavior and hidden hyper link. As a concrete application of our approach, we show that the script execution behavior based web page malicious code detector can detect many known malicious code but also the newest malicious code.

Original languageEnglish
Title of host publication5th International Conference on Natural Computation, ICNC 2009
Pages308-312
Number of pages5
DOIs
Publication statusPublished - 2009
Event5th International Conference on Natural Computation, ICNC 2009 - Tianjian, China
Duration: 14 Aug 200916 Aug 2009

Publication series

Name5th International Conference on Natural Computation, ICNC 2009
Volume6

Conference

Conference5th International Conference on Natural Computation, ICNC 2009
Country/TerritoryChina
CityTianjian
Period14/08/0916/08/09

Keywords

  • Execution behavior
  • Malicious code
  • Script

Fingerprint

Dive into the research topics of 'A web page malicious code detect approach based on script execution'. Together they form a unique fingerprint.

Cite this