Treffer: 실시간으로 악성 스크립트를 탐지하는 기술.

Title:
실시간으로 악성 스크립트를 탐지하는 기술.
Alternate Title:
The Real-Time Detection of the Malicious JavaScript.
Authors:
추현록1 hlchu@kisa.or.kr, 정종훈1 jjh2640@kisa.or.kr, 김환국1 rinyfeel@kisa.or.kr
Source:
Journal of Internet Computing & Services. Aug2015, Vol. 16 Issue 4, p51-59. 9p.
Database:
Business Source Elite

Weitere Informationen

JavaScript is a popular technique for activating static HTML. JavaScript has drawn more attention following the introduction of HTML5 Standard. In proportion to JavaScript's growing importance, attacks (ex. DDos, Information leak using its function) become more dangerous. Since these attacks do not create a trail, whether the JavaScript code is malicious or not must be decided. The real attack action is completed while the browser runs the JavaScript code. For these reasons, there is a need for a real-time classification and determination technique for malicious JavaScript. This paper proposes the Analysis Engine for detecting malicious JavaScript by adopting the requirements above. The analysis engine performs static analysis using signature-based detection and dynamic analysis using behavior-based detection. Static analysis can detect malicious JavaScript code, whereas dynamic analysis can detect the action of the JavaScript code. [ABSTRACT FROM AUTHOR]

Copyright of Journal of Internet Computing & Services is the property of Korean Society for Internet Information and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)