JSgraph: Enabling Reconstruction of Web Attacks via Efficient Tracking of Live In-Browser JavaScript Executions
Bo Li, Phani Vadrevu, Kyu Hyung Lee, Roberto Perdisci
Abstract
In this paper, we propose JSgraph, a forensic engine that is able to efficiently record fine-grained details pertaining to the execution of JavaScript (JS) programs within the browser, with particular focus on JS-driven DOM modifications. JSgraph's main goal is to enable a detailed, post-mortem reconstruction of ephemeral JS-based web attacks experienced by real network users. In particular, we aim to enable the reconstruction of social engineering attacks that result in the download of malicious executable files or browser extensions, among other attacks. We implement JSgraph by instrumenting Chromium's code base at the interface between Blink and V8, the rendering and JavaScript engines. We design JSgraph to be lightweight, highly portable, and to require low storage capacity for its fine-grained audit logs. Using a variety of both in-the-wild and lab-reproduced web attacks, we demonstrate how JSgraph can aid the forensic investigation process. We then show that JSgraph introduces acceptable overhead, with a median overhead on popular website page loads between 3.2% and 3.9%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 76924f84-e8bd-4f90-9e1e-65d3b0f3e5beCited by top-tier papers18
- WebSocket Adoption and the Landscape of the Real-Time WebPaul Murley, Zane Ma, Joshua Mason, Michael D. Bailey et al.WWW 2021 · 40 citations
- Detecting Filter List Evasion with Event-Loop-Turn Granularity JavaScript SignaturesQuan Chen, Peter Snyder, Ben Livshits, Alexandros KapravelosS&P 2021 · 33 citations
- WTAGRAPH: Web Tracking and Advertising Detection using Graph Neural NetworksZhiju Yang, Weiping Pei, Monchu Chen, Chuan YueS&P 2022 · 29 citations
- TrackSign: Guided Web Tracking DiscoveryIsmael Castell-Uroz, Josep Solé-Pareta, Pere Barlet-RosINFOCOM 2021 · 18 citations
- FV8: A Forced Execution JavaScript Engine for Detecting Evasive TechniquesNikolaos Pantelaios, Alexandros KapravelosUSENIX Security 2024 · 6 citations
Builds on4
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
- MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution PartitioningShiqing Ma, Juan Zhai, Fei Wang, Kyu Hyung Lee et al.USENIX Security 2017 · 136 citations
- Towards Measuring and Mitigating Social Engineering Software Download AttacksTerry Nelms, Roberto Perdisci, Manos Antonakakis, Mustaque AhamadUSENIX Security 2016 · 70 citations
- Enabling Reconstruction of Attacks on Users via Efficient Browsing SnapshotsPhani Vadrevu, Jienan Liu, Bo Li, Babak Rahbarinia et al.NDSS 2017 · 22 citations
Related papers
- WEBRR: A Forensic System for Replaying and Investigating Web-Based Attacks in The Modern WebJoey Allen, Zheng Yang, Feng Xiao, Matthew Landen et al.USENIX Security 2024 · 2 citations
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits et al.S&P 2020 · 112 citations
- C^2SR: Cybercrime Scene Reconstruction for Post-mortem Forensic AnalysisYonghwi Kwon, Weihang Wang, Jinho Jung, Kyu Hyung Lee et al.NDSS 2021
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 88 citations
- Extraction and Mutation at a High Level: Template-Based Fuzzing for JavaScript EnginesWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Yiteng Peng et al.OOPSLA 2025 · 4 citations
