Neural Classification of Malicious Scripts: A study with JavaScript and VBScript

05/15/2018
by   Jack W. Stokes, et al.
0

Malicious scripts are an important computer infection threat vector. Our analysis reveals that the two most prevalent types of malicious scripts include JavaScript and VBScript. The percentage of detected JavaScript attacks are on the rise. To address these threats, we investigate two deep recurrent models, LaMP (LSTM and Max Pooling) and CPoLS (Convoluted Partitioning of Long Sequences), which process JavaScript and VBScript as byte sequences. Lower layers capture the sequential nature of these byte sequences while higher layers classify the resulting embedding as malicious or benign. Unlike previously proposed solutions, our models are trained in an end-to-end fashion allowing discriminative training even for the sequential processing layers. Evaluating these models on a large corpus of 296,274 JavaScript files indicates that the best performing LaMP model has a 65.9 false positive rate (FPR) of 1.0 45.3 respectively, at an FPR of 1.0

READ FULL TEXT

page 2

page 7

research
04/01/2019

ScriptNet: Neural Static Analysis for Malicious JavaScript Detection

Malicious scripts are an important computer infection threat vector in t...
research
06/28/2018

Robust Neural Malware Detection Models for Emulation Sequence Learning

Malicious software, or malware, presents a continuously evolving challen...
research
05/23/2022

CELEST: Federated Learning for Globally Coordinated Threat Detection

The cyber-threat landscape has evolved tremendously in recent years, wit...
research
02/10/2021

DANTE: Predicting Insider Threat using LSTM on system logs

Insider threat is one of the most pernicious threat vectors to informati...
research
03/02/2020

Graphing Website Relationships for Risk Prediction: Identifying Derived Threats to Users Based on Known Indicators

The hypothesis for the study was that the relationship based on referrer...
research
02/26/2019

Design of intentional backdoors in sequential models

Recent work has demonstrated robust mechanisms by which attacks can be o...
research
10/02/2018

PromID: human promoter prediction by deep learning

Computational identification of promoters is notoriously difficult as hu...

Please sign up or login with your details

Forgot password? Click here to reset