ZOZZLE: Fast and Precise In-Browser JavaScript Malware Detection

ZOZZLE: Fast and Precise In-Browser JavaScript Malware Detection
复制标题

DOI:
--
复制
发表时间:
2011-08
期刊:
--
影响因子:
--
通讯作者:
Charlie Curtsinger;B. Livshits;B. Zorn;C. Seifert
Charlie Curtsinger;B. Livshits;B. Zorn;C. Seifert
中科院分区:
其他
文献类型:
--
作者:
Charlie Curtsinger;B. Livshits;B. Zorn;C. Seifert

文献摘要

被引文献

相似文献

基于JavaScript恶意软件的攻击占今天大规模成功攻击的很大一部分。攻击者喜欢基于javascript的攻击,因为它们可以装载到一个毫无戒心的用户访问一个看似无辜的网页。虽然已经提出了几种解决这类漏洞的技术,但在浏览器内采用的速度很慢,部分原因是这些方法带来的性能开销。在本文中,我们提出了ZOZZLE,这是一个低开销的解决方案,用于检测和防止JavaScript恶意软件,速度足够快,可以部署在浏览器中。我们的方法使用JavaScript抽象语法树的层次特征的贝叶斯分类来识别高度预测恶意软件的语法元素。我们的实验评估表明,ZOZZLE能够通过大多数静态代码分析有效地检测JavaScript恶意软件。ZOZZLE的假阳性率极低,为0.0003%,不到25万分之一。尽管准确率很高,但ZOZZLE分类器速度很快,每秒处理JavaScript代码的吞吐量超过1兆字节。
JavaScript malware-based attacks account for a large fraction of successful mass-scale exploitation happening today. Attackers like JavaScript-based attacks because they can be mounted against an unsuspecting user visiting a seemingly innocent web page. While several techniques for addressing these types of exploits have been proposed, in-browser adoption has been slow, in part because of the performance overhead these methods incur. In this paper, we propose ZOZZLE, a low-overhead solution for detecting and preventing JavaScript malware that is fast enough to be deployed in the browser. Our approach uses Bayesian classification of hierarchical features of the JavaScript abstract syntax tree to identify syntax elements that are highly predictive of malware. Our experimental evaluation shows that ZOZZLE is able to detect JavaScript malware through mostly static code analysis effectively. ZOZZLE has an extremely low false positive rate of 0.0003%, which is less than one in a quarter million. Despite this high accuracy, the ZOZZLE classifier is fast, with a throughput of over one megabyte of JavaScript code per second.