Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

JsSandbox: A Framework for Analyzing the Behavior of Malicious JavaScript Code using Internal Function Hooking

Authors
Kim, Hyoung ChunChoi, Young HanLee, Dong Hoon
Issue Date
28-2월-2012
Publisher
KSII-KOR SOC INTERNET INFORMATION
Keywords
Malicious JavaScript code; Sandboxing
Citation
KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, v.6, no.2, pp.766 - 783
Indexed
SCIE
SCOPUS
KCI
OTHER
Journal Title
KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS
Volume
6
Number
2
Start Page
766
End Page
783
URI
https://scholar.korea.ac.kr/handle/2021.sw.korea/105448
DOI
10.3837/tiis.2012.02.019
ISSN
1976-7277
Abstract
Recently, many malicious users have attacked web browsers using JavaScript code that can execute dynamic actions within the browsers. By forcing the browser to execute malicious JavaScript code, the attackers can steal personal information stored in the system, allow malware program downloads in the client's system, and so on. In order to reduce damage, malicious web pages must be located prior to general users accessing the infected pages. In this paper, a novel framework (JsSandbox) that can monitor and analyze the behavior of malicious JavaScript code using internal function hooking (IFH) is proposed. IFH is defined as the hooking of all functions in the modules using the debug information and extracting the parameter values. The use of IFH enables the monitoring of functions that API hooking cannot. JsSandbox was implemented based on a debugger engine, and some features were applied to detect and analyze malicious JavaScript code: detection of obfuscation, deobfuscation of the obfuscated string, detection of URLs related to redirection, and detection of exploit codes. Then, the proposed framework was analyzed for specific features, and the results demonstrate that JsSandbox can be applied to the analysis of the behavior of malicious web pages.
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Lee, Dong Hoon photo

Lee, Dong Hoon
정보보호학과
Read more

Altmetrics

Total Views & Downloads

BROWSE