Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pereira, Pedro, Gonçalves, José, Vitorino, João, Maia, Eva, Praça, Isabel
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910970771668992
author Pereira, Pedro
Gonçalves, José
Vitorino, João
Maia, Eva
Praça, Isabel
author_facet Pereira, Pedro
Gonçalves, José
Vitorino, João
Maia, Eva
Praça, Isabel
contents This work addresses JavaScript malware detection to enhance client-side web application security with a behavior-based system. The ability to detect malicious JavaScript execution sequences is a critical problem in modern web security as attack techniques become more sophisticated. This study introduces a new system for detecting JavaScript malware using a Deterministic Finite Automaton (DFA) along with a weighted-behavior system, which we call behavior DFA. This system captures malicious patterns and provides a dynamic mechanism to classify new sequences that exhibit partial similarity to known attacks, differentiating them between benign, partially malicious, and fully malicious behaviors. Experimental evaluation on a dataset of 1,058 sequences captured in a real-world environment demonstrates the capability of the system to detect and classify threats effectively, with the behavior DFA successfully identifying exact matches and partial similarities to known malicious behaviors. The results highlight the adaptability of the system in detecting emerging threats while maintaining transparency in decision making.
format Preprint
id arxiv_https___arxiv_org_abs_2505_21406
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
Pereira, Pedro
Gonçalves, José
Vitorino, João
Maia, Eva
Praça, Isabel
Cryptography and Security
This work addresses JavaScript malware detection to enhance client-side web application security with a behavior-based system. The ability to detect malicious JavaScript execution sequences is a critical problem in modern web security as attack techniques become more sophisticated. This study introduces a new system for detecting JavaScript malware using a Deterministic Finite Automaton (DFA) along with a weighted-behavior system, which we call behavior DFA. This system captures malicious patterns and provides a dynamic mechanism to classify new sequences that exhibit partial similarity to known attacks, differentiating them between benign, partially malicious, and fully malicious behaviors. Experimental evaluation on a dataset of 1,058 sequences captured in a real-world environment demonstrates the capability of the system to detect and classify threats effectively, with the behavior DFA successfully identifying exact matches and partial similarities to known malicious behaviors. The results highlight the adaptability of the system in detecting emerging threats while maintaining transparency in decision making.
title Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
topic Cryptography and Security
url https://arxiv.org/abs/2505.21406