@article{ART002467562},
author={Hweerang Park and Sang-Il Cho and JungKyu Park and Youngho Cho},
title={A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2019},
volume={24},
number={5},
pages={27-33},
doi={10.9708/jksci.2019.24.05.027}
TY - JOUR
AU - Hweerang Park
AU - Sang-Il Cho
AU - JungKyu Park
AU - Youngho Cho
TI - A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files
JO - Journal of The Korea Society of Computer and Information
PY - 2019
VL - 24
IS - 5
PB - The Korean Society Of Computer And Information
SP - 27
EP - 33
SN - 1598-849X
AB - One of serious security threats is a botnet-based attack. A botnet in general consists of numerous bots, which are computing devices with networking function, such as personal computers, smartphones, or tiny IoT sensor devices compromised by malicious codes or attackers. Such botnets can launch various serious cyber-attacks like DDoS attacks, propagating mal-wares, and spreading spam e-mails over the network. To establish a botnet, attackers usually inject malicious URLs into web source codes stealthily by using data hiding methods like Javascript obfuscation techniques to avoid being discovered by traditional security systems such as Firewall, IPS(Intrusion Prevention System) or IDS(Intrusion Detection System). Meanwhile, it is non-trivial work in practice for software developers to manually find such malicious URLs which are hidden in numerous web source codes stored in web servers. In this paper, we propose a security defense system to discover such suspicious, malicious URLs hidden in web source codes, and present experiment results that show its discovery performance. In particular, based on our experiment results, our proposed system discovered 100% of URLs hidden by Javascript encoding obfuscation within sample web source files.
KW - Hidden URL Discovery;Web Defacement Attack;Javascript Obfuscation;Network Security
DO - 10.9708/jksci.2019.24.05.027
ER -
Hweerang Park, Sang-Il Cho, JungKyu Park and Youngho Cho. (2019). A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files. Journal of The Korea Society of Computer and Information, 24(5), 27-33.
Hweerang Park, Sang-Il Cho, JungKyu Park and Youngho Cho. 2019, "A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files", Journal of The Korea Society of Computer and Information, vol.24, no.5 pp.27-33. Available from: doi:10.9708/jksci.2019.24.05.027
Hweerang Park, Sang-Il Cho, JungKyu Park, Youngho Cho "A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files" Journal of The Korea Society of Computer and Information 24.5 pp.27-33 (2019) : 27.
Hweerang Park, Sang-Il Cho, JungKyu Park, Youngho Cho. A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files. 2019; 24(5), 27-33. Available from: doi:10.9708/jksci.2019.24.05.027
Hweerang Park, Sang-Il Cho, JungKyu Park and Youngho Cho. "A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files" Journal of The Korea Society of Computer and Information 24, no.5 (2019) : 27-33.doi: 10.9708/jksci.2019.24.05.027
Hweerang Park; Sang-Il Cho; JungKyu Park; Youngho Cho. A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files. Journal of The Korea Society of Computer and Information, 24(5), 27-33. doi: 10.9708/jksci.2019.24.05.027
Hweerang Park; Sang-Il Cho; JungKyu Park; Youngho Cho. A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files. Journal of The Korea Society of Computer and Information. 2019; 24(5) 27-33. doi: 10.9708/jksci.2019.24.05.027
Hweerang Park, Sang-Il Cho, JungKyu Park, Youngho Cho. A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files. 2019; 24(5), 27-33. Available from: doi:10.9708/jksci.2019.24.05.027
Hweerang Park, Sang-Il Cho, JungKyu Park and Youngho Cho. "A Discovery System of Malicious Javascript URLs hidden in Web Source Code Files" Journal of The Korea Society of Computer and Information 24, no.5 (2019) : 27-33.doi: 10.9708/jksci.2019.24.05.027