发明名称 JavaScript obfuscation by hooking automatically decrypted and how to detect malicious Web sites
摘要 PURPOSE: Methods for automatically decrypting obfuscated java scripts based on a hooking scheme and for detecting malicious web sites are provided to increase detection rate and to reduce the generation of error. CONSTITUTION: Hypertext markup language(HTML) documents containing obfuscated java script codes are input(S100). An inline hooking scheme is applied to the evaluation function of jscript.dll and the element.appendChild function and the element.appendChild function of mshtml.dll(S110). The existence of a Hidden Iframe code is confirmed on a hooking result(S120). A web server with the HTML documents is detected as a malicious code waypoint(S130). The source address of the Hidden Iframe code is executed on a browser based on CoCreateInstance functional hooking scheme(S140). The generation of Active X objects is confirmed(S150).
申请公布号 KR101181843(B1) 申请公布日期 2012.09.11
申请号 KR20100131403 申请日期 2010.12.21
申请人 发明人
分类号 G06F21/56;G06F11/30 主分类号 G06F21/56
代理机构 代理人
主权项
地址