Malicious Script Blocking Detection Technology Using a Local Proxy

SangHwan Oh, Hanchul Bae, Soojin Yoon, Hwankuk Kim, YoungTae Cha · 2016

The key feature of HTML5, the next-generation web standard announced in W3 in October 2015, might be the enhancement of JavaScript functions. While the previous generation HTML required non-standard plug-ins such as Silverlight or Active X for media play and web socket communication, HTML5 provides the functions via new APIs including JavaScript audio and video, which are powerful features that can replace non-standard technologies like Active-X. Like this, web browser developers are rushing to make their browsers HTML5 compatible and a number of projects for converting into the HTML5 environment are ongoing all over the world. But along with this trend, there are increasing threats of new types of cyberattacks using Java script, which is the core function of HTML5. Unlike a traditional attack using malicious code, existing security technologies have limits in detecting new types of attacks as connecting to web pages with malscript causes malicious behavior without any infection to the user PC. So this paper suggests methods to detect and block malscript and obfuscated malicious script by collecting and analyzing HTTP traffic via local proxy.

Read the paper · More papers on PaperTik