Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Zozzle: Low-overhead Mostly Static JavaScript Malware Detection

Go down

Zozzle: Low-overhead Mostly Static JavaScript Malware Detection Empty Zozzle: Low-overhead Mostly Static JavaScript Malware Detection

Post  andry Fri Jan 07, 2011 5:47 am

JavaScript malware-based attacks account for a largefraction of successful mass-scale exploitation ning today.From the standpoint of the attacker,the attraction is that these drive-by attacks that can be mounted agains an unsuspecting user visiting a seemingly innocent web page.While several techniques for addressing these types of exploits have been proposed,in-browser adoption has been slow,in part because of the performance overhead these methods tend to incur.In this paper,we propose ZOZZLE,a low-overhead solution for detecting and preventing JavaScript malware that can be deployed in the browser.Our approach uses Bayesian classification of hierarchical features of the JavaScript abstract syntax tree to identify syntax elements that are highly predictive of malware.Our extensive experimental evaluation shows that ZOZZLE is able to effectively detect JavaScript malware through mostly static code analysis with very low false positive rates (fractions of 1%),and with a typical overhead of only 2-5 milliseconds per JavaScript file.Our experience also suggests that ZOZZLE may be used as a lightweight filter for a more costly detection technique or for standalone offline malware detection.happe

Download: PDF
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum