Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssembly
Alan Romano, Daniel Lehmann, Michael Pradel, Weihang Wang
摘要
To protect web users from malicious JavaScript code, various malware detectors have been proposed, which analyze and classify code as malicious or benign. State-of-the-art detectors focus on JavaScript as the only target language. However, WebAssembly provides attackers a new and so far unexplored opportunity for evading malware detectors. This paper presents Wobfuscator, the first technique for evading static JavaScript malware detection by moving parts of the computation into WebAssembly. The core of the technique is a set of code transformations that translate carefully selected parts of behavior implemented in JavaScript into WebAssembly. The approach is opportunistic in the sense that it uses WebAssembly where it helps to evade malware detection without compromising the correctness of the code. Evaluating our approach with a dataset of 43,499 malicious and 149,677 benign JavaScript files, as well as six popular JavaScript libraries reveals that our approach is effective at evading state-of-the-art, learning-based static malware detectors; the obfuscation is semantic-preserving; and our approach has small overhead, making it practical for use in real-world programs. By pinpointing limitations of current malware detectors, our work motivates future efforts on detecting multi-language malware in the web.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Large Language Models for Code Analysis: Do LLMs Really Do Their Job?Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu 等USENIX Security 2024 · 被引用 110 次
- Finding the dwarf: recovering precise types from WebAssembly binariesDaniel Lehmann, Michael PradelPLDI 2022 · 被引用 29 次
- That's a Tough Call: Studying the Challenges of Call Graph Construction for WebAssemblyDaniel Lehmann, Michelle Thalakottur, Frank Tip, Michael PradelISSTA 2023 · 被引用 11 次
- An Empirical Study on the Effects of Obfuscation on Static Machine Learning-Based Malicious JavaScript DetectorsKunlun Ren, Weizhong Qiang, Yueming Wu, Yi Zhou 等ISSTA 2023 · 被引用 11 次
- Wasm-R3: Record-Reduce-Replay for Realistic and Standalone WebAssembly BenchmarksDoehyun Baek, Jakob Getz, Yusung Sim, Daniel Lehmann 等OOPSLA 2024 · 被引用 6 次
它引用的顶会 Paper7
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer 等CCS 2018 · 被引用 162 次
- How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldGeng Hong, Zhemin Yang, Sen Yang, Lei Zhang 等CCS 2018 · 被引用 120 次
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 被引用 114 次
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 被引用 78 次
相关 Paper
- WasmGuard: Enhancing Web Security through Robust Raw-Binary Detection of WebAssembly MalwareYuxia Sun, Huihong Chen, Zhixiao Fu, Wenjian Lv 等WWW 2025 · 被引用 2 次
- An Empirical Study of WebAssembly Usage in Node.jsMichelle Thalakottur, Maxwell Bernstein, Daniel Lehmann, Michael Pradel 等ICSE 2026
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- An Empirical Study of Bugs in WebAssembly CompilersAlan Romano, Xinyue Liu, Yonghwi Kwon, Weihang WangASE 2021 · 被引用 43 次
- WAMO: Toward Secure Browser Inference via Web Model Obfuscation in WebAssemblyYitong Wang, Pengfei Yu, Hao Han, Jingjing Gu 等WWW 2026
