Academic Journal
JSCoherence: detecting obfuscated malicious JavaScript via data-dependent statement pairs.
| Τίτλος: | JSCoherence: detecting obfuscated malicious JavaScript via data-dependent statement pairs. |
|---|---|
| Συγγραφείς: | Chen, Zixian, Wang, Weiping, Gu, Zesong, Song, Hong |
| Πηγή: | Cybersecurity (2523-3246); 9/8/2026, Vol. 9 Issue 1, p1-19, 19p |
| Θεματικοί όροι: | JavaScript programming language, Malware, Encoding, Internet security, Source code, Computer software security, Data flow computing |
| Περίληψη: | As a crucial component of websites, JavaScript is one of the most common attack payloads on malicious websites. Although many methods for detecting malicious JavaScript have been proposed, obfuscation techniques make it difficult for previous approaches to detect disguised malicious JavaScript effectively. To address this problem, we observe that malicious JavaScript often uses obfuscation to fragment key attack semantics and conceal them within data-dependent statements involving variable propagation. This observation suggests that data dependencies between variables can be leveraged to extract potentially malicious functional statements. Therefore, this paper proposes JSCoherence, a novel static detection method for obfuscated malicious JavaScript. Its core principle is to mine statement pairs with data dependencies through data-flow analysis, thereby reconnecting fragmented semantics and recovering locally coherent malicious behavior. Experiments show that JSCoherence achieves an F1 score of 99.77% on public datasets. On the Jfogs, JSObfu, and JavaScript-obfuscator obfuscated datasets, its F1 score consistently exceeds 95%, representing an improvement over the current advanced methods. In addition, JSCoherence provides interpretability by analyzing the semantics of representative data-dependent statement pairs, offering clear explanatory evidence for its detection decisions. [ABSTRACT FROM AUTHOR] |
| Copyright of Cybersecurity (2523-3246) is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Βάση Δεδομένων: | Complementary Index |
| FullText | Text: Availability: 0 CustomLinks: – Url: https://dx.doi.org/doi:10.1186/s42400-026-00645-9 Name: EDS - Springer Nature Journals (s7799221) Category: fullText Text: View record at Springer – Url: https://resolver.ebsco.com/c/fiv2js/result?sid=EBSCO:edb&genre=article&issn=25233246&ISBN=&volume=9&issue=1&date=20260908&spage=1&pages=1-19&title=Cybersecurity (2523-3246)&atitle=JSCoherence%3A%20detecting%20obfuscated%20malicious%20JavaScript%20via%20data-dependent%20statement%20pairs.&aulast=Chen%2C%20Zixian&id=DOI:10.1186/s42400-026-00645-9 Name: Full Text Finder (for New FTF UI) (ns324271) Category: fullText Text: Full Text Finder MouseOverText: Full Text Finder |
|---|---|
| Header | DbId: edb DbLabel: Complementary Index An: 196860034 RelevancyScore: 1082 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 1082.427734375 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: JSCoherence: detecting obfuscated malicious JavaScript via data-dependent statement pairs. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Chen%2C+Zixian%22">Chen, Zixian</searchLink><br /><searchLink fieldCode="AR" term="%22Wang%2C+Weiping%22">Wang, Weiping</searchLink><br /><searchLink fieldCode="AR" term="%22Gu%2C+Zesong%22">Gu, Zesong</searchLink><br /><searchLink fieldCode="AR" term="%22Song%2C+Hong%22">Song, Hong</searchLink> – Name: TitleSource Label: Source Group: Src Data: Cybersecurity (2523-3246); 9/8/2026, Vol. 9 Issue 1, p1-19, 19p – Name: Subject Label: Subject Terms Group: Su Data: <searchLink fieldCode="DE" term="%22JavaScript+programming+language%22">JavaScript programming language</searchLink><br /><searchLink fieldCode="DE" term="%22Malware%22">Malware</searchLink><br /><searchLink fieldCode="DE" term="%22Encoding%22">Encoding</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22Source+code%22">Source code</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+software+security%22">Computer software security</searchLink><br /><searchLink fieldCode="DE" term="%22Data+flow+computing%22">Data flow computing</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: As a crucial component of websites, JavaScript is one of the most common attack payloads on malicious websites. Although many methods for detecting malicious JavaScript have been proposed, obfuscation techniques make it difficult for previous approaches to detect disguised malicious JavaScript effectively. To address this problem, we observe that malicious JavaScript often uses obfuscation to fragment key attack semantics and conceal them within data-dependent statements involving variable propagation. This observation suggests that data dependencies between variables can be leveraged to extract potentially malicious functional statements. Therefore, this paper proposes JSCoherence, a novel static detection method for obfuscated malicious JavaScript. Its core principle is to mine statement pairs with data dependencies through data-flow analysis, thereby reconnecting fragmented semantics and recovering locally coherent malicious behavior. Experiments show that JSCoherence achieves an F1 score of 99.77% on public datasets. On the Jfogs, JSObfu, and JavaScript-obfuscator obfuscated datasets, its F1 score consistently exceeds 95%, representing an improvement over the current advanced methods. In addition, JSCoherence provides interpretability by analyzing the semantics of representative data-dependent statement pairs, offering clear explanatory evidence for its detection decisions. [ABSTRACT FROM AUTHOR] – Name: Abstract Label: Group: Ab Data: <i>Copyright of Cybersecurity (2523-3246) is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=196860034 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1186/s42400-026-00645-9 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 19 StartPage: 1 Subjects: – SubjectFull: JavaScript programming language Type: general – SubjectFull: Malware Type: general – SubjectFull: Encoding Type: general – SubjectFull: Internet security Type: general – SubjectFull: Source code Type: general – SubjectFull: Computer software security Type: general – SubjectFull: Data flow computing Type: general Titles: – TitleFull: JSCoherence: detecting obfuscated malicious JavaScript via data-dependent statement pairs. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Chen, Zixian – PersonEntity: Name: NameFull: Wang, Weiping – PersonEntity: Name: NameFull: Gu, Zesong – PersonEntity: Name: NameFull: Song, Hong IsPartOfRelationships: – BibEntity: Dates: – D: 08 M: 09 Text: 9/8/2026 Type: published Y: 2026 Identifiers: – Type: issn-print Value: 25233246 Numbering: – Type: volume Value: 9 – Type: issue Value: 1 Titles: – TitleFull: Cybersecurity (2523-3246) Type: main |
| ResultId | 1 |