From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhou, Dongchao, Ying, Lingyun, Chai, Huajun, Wang, Dongbin
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909965003784192
author Zhou, Dongchao
Ying, Lingyun
Chai, Huajun
Wang, Dongbin
author_facet Zhou, Dongchao
Ying, Lingyun
Chai, Huajun
Wang, Dongbin
contents JavaScript's widespread adoption has made it an attractive target for malicious attackers who employ sophisticated obfuscation techniques to conceal harmful code. Current deobfuscation tools suffer from critical limitations that severely restrict their practical effectiveness. Existing tools struggle with diverse input formats, address only specific obfuscation types, and produce cryptic output that impedes human analysis. To address these challenges, we present JSIMPLIFIER, a comprehensive deobfuscation tool using a multi-stage pipeline with preprocessing, abstract syntax tree-based static analysis, dynamic execution tracing, and Large Language Model (LLM)-enhanced identifier renaming. We also introduce multi-dimensional evaluation metrics that integrate control/data flow analysis, code simplification assessment, entropy measures and LLM-based readability assessments. We construct and release the largest real-world obfuscated JavaScript dataset with 44,421 samples (23,212 wild malicious + 21,209 benign samples). Evaluation shows JSIMPLIFIER outperforms existing tools with 100% processing capability across 20 obfuscation techniques, 100% correctness on evaluation subsets, 88.2% code complexity reduction, and over 4-fold readability improvement validated by multiple LLMs. Our results advance benchmarks for JavaScript deobfuscation research and practical security applications.
format Preprint
id arxiv_https___arxiv_org_abs_2512_14070
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
Zhou, Dongchao
Ying, Lingyun
Chai, Huajun
Wang, Dongbin
Cryptography and Security
Software Engineering
JavaScript's widespread adoption has made it an attractive target for malicious attackers who employ sophisticated obfuscation techniques to conceal harmful code. Current deobfuscation tools suffer from critical limitations that severely restrict their practical effectiveness. Existing tools struggle with diverse input formats, address only specific obfuscation types, and produce cryptic output that impedes human analysis. To address these challenges, we present JSIMPLIFIER, a comprehensive deobfuscation tool using a multi-stage pipeline with preprocessing, abstract syntax tree-based static analysis, dynamic execution tracing, and Large Language Model (LLM)-enhanced identifier renaming. We also introduce multi-dimensional evaluation metrics that integrate control/data flow analysis, code simplification assessment, entropy measures and LLM-based readability assessments. We construct and release the largest real-world obfuscated JavaScript dataset with 44,421 samples (23,212 wild malicious + 21,209 benign samples). Evaluation shows JSIMPLIFIER outperforms existing tools with 100% processing capability across 20 obfuscation techniques, 100% correctness on evaluation subsets, 88.2% code complexity reduction, and over 4-fold readability improvement validated by multiple LLMs. Our results advance benchmarks for JavaScript deobfuscation research and practical security applications.
title From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2512.14070