A Cloud-based Protection approach against JavaScript-based attacks to browsers

作者:Hsu Fu Hau; Hwang Yan Ling; Lee Chia Hao*; Lin Chieh Ju; Chang KaiWei; Huang Chen Chia
来源:Computers & Electrical Engineering, 2018, 68: 241-251.
DOI:10.1016/j.compeleceng.2018.03.050

摘要

JavaScript is a standard of client-side scripting languages. Due to its cross-platform property, JavaScript is widely used in web pages. Hence its security problems can seriously influence the security of devices executing code written by it. This paper proposes a Cloud-based Protection approach against JavaScript-based attacks to browsers, called CPJ. CPJ provides timely and effective protection to web browsers to cope with attackers' continuously developing new JavaScript-based attack approaches. CPJ integrates VirusTotal, a cloud-based security analysis service, into a browser. Therefore, with the latest malware signature databases, it can analyze the behavior of a variety of JavaScript files. It allows a browser to block malicious code when the browser is surfing the Internet. We demonstrate its feasibility using Internet experiments, and show its effectiveness on a variety of suspicious targets. According to our experiments, CPJ has rather good sensitivity and performance.