Obfuscated malicious JavaScript detection by Causal Relations Finding
Ismail Adel AL-Taharwa, Ching-Hao Mao, Hsin-Kuo Pao, Kuo-Ping Wu, Christos Faloutsos, Hahn-Ming Lee, Shyi‐Ming Chen, Albert B. Jeng · International Conference on Advanced Communication Technology · 2011
JavaScript code is often obfuscated; given such code, can we tell whether if it is malicious or benign? We propose Obfuscating Causal Relations Finding (OCRF), which addresses this problem. The contributions are the following: (1) careful feature extraction, using domain knowledge (2) no need for de-obfuscation, since our method can be applied to the obfuscated script directly, (3) combined obfuscation detection, with malicious obfuscated code detection (4) improved detection accuracy and significantly reduced false positives (while the average false positive rate of competitors is between 0.18 and 0.30. Our method decreases it between 0.03 and 0.1). Moreover, our method is easy to be implemented as a plug-in for Web browsers.