Anti-html Evasion in Intrusion Prevention System
Feng Dong, Jia Liu, Liang Gu, Min Ma · 2020
As evasion techniques are widely used to evade intrusion prevention system (IPS), anti-evasion is becoming more and more important. Due to the flexibility of the scripting language and the obfuscation, detecting html attacks disguised by obfuscation has been a challenge. State-of-the-art approaches in the literature adopt runtime analysis to restore the obfuscated JavaScript, but the performance penalty incurred by runtime analysis prevents it from being applied to IPS real-time detection. Others use machine learning to detect obfuscation, cannot accurately distinguish malicious obfuscation from benign obfuscation, resulting in a high false positive rate. In this work, we propose, AHE, a novel hybrid approach to anti-html evasion in IPS. AHE combines machine learning and anomaly detection to detect malicious obfuscated JavaScript. It first adopts machine learning techniques using features extracted from html to identify the obfuscated JavaScript, and then identify malicious obfuscated JavaScript through anomaly detection. AHE achieved a precision rate of 96.18% on real-world malicious and benign samples, indicating that AHE is capable of anti-html evasion in IPS.