Aiming at the traditional abstract syntax tree detection method ignoring the data dependency relationship, node attrib ute information and other related problems, a JavaScript malicious code detection method based on graph-level heterogeneous graph attention network is proposed. A heterogeneous graph extraction framework based on abstract syntax tree is constructed to model and characterize the spatial structure and complex data dependencies of JS malicious code, obtain JS text semantic information, and enrich the attribute features of heterogeneous graph nodes; a node attribute combination module is constructed to fuse multiple attribute features of nodes to enrich the semantic expression; finally, the structure of the heterogeneous graph attention network is improved, and a global summation pooling layer is added to enhance the characterization of the whole graph. capability. The experimental results show that the proposed method in this paper has an accuracy of more than 99.2% on the real JS dataset, and all other detection indexes are significantly improved.
GuptaS, GuptaB B. XSS-SAFE: a server-side approach to detect and mitigate cross-site scripting (xss) attacks in javascript code[J]. Arabian Journal for Science & Engineering, 2016, 41(3): 897-920.
ZhangLu-yu. Exploration and research on XSS vulnerabilities based on web penetration testing[J]. Network Security Technology and Application, 2024(4):5-8.
YangYu-xing. Research and implementation of JavaScript malicious code detection technology based on deep learning[D]. Beijing: School of Computer Science and Technology, Beijing University of Posts and Telecommunications, 2019.
[10]
SongX, ChenC, CuiB, et al. Malicious javascript detection based on bidirectional LSTM model[J]. Applied Sciences, 2020, 10: 10103440
[11]
RoziM F, KimS, OzawaS. Deep neural networks for malicious javascript detection using bytecode sequences[C]∥International Joint Conference on Neural Networks, Glasgow, UK, 2020: 1-8.
ChenPeng, HanBin, HongHua-jun. A JavaScript malicious code detection system based on deep learning and blockchain[J]. Computer System Applications, 2021, 30(5): 99-106.
[16]
RoziM F, BanT, OzawaS, et al. JStrack: enriching malicious javascript detection based on ast graph analysis and attention mechanism[C]∥Neural Information Processing, Springer, Cham, 2021: 669-680.
HuangQing. Malware detection based on heterogeneous graph embedding[J]. Electronic Design Engineering,2024,32(7):92-96.
[23]
GuanW L, JiaoF K, SongX M, et al. Personalized fashion compatibility modeling via metapath-guided heterogeneous graph learning[C]∥Proceedings of the Proceedings of the 45th International ACM SIGIR Conference on Research and Devel opment in Information Retrieval, New York, USA, 2022: 482-491.
ZhongYu-le, HanPu, XuXin. A study on joint extraction of adverse drug reaction entity relations based on heterogeneous graph attention network [J]. Modern Intelligence, 2024, 44(9): 71-81.
[26]
ZhuX, GhahramaniZ, LaffertyJ D. Semi-supervised learning using gaussian fields and harmonic functions[C]∥Proceedings of the Twentieth International Conference, Washington, USA, 2003: 912-919.
[27]
ZhouK, DongY, WangK. Understanding and resolving performance degradation in graph convolutional networks[J]. Arxive Print, 2006, 7: 071070.
MengXiang-fu, WenJing, LiZi-han, et al. A heterogeneous graph embedding method guided by multiple attention[J]. Journal of Intelligent Systems, 2023,18(4): 688-698.
[30]
JinD, HuoC Y, LiangC D, et al. Heterogeneous graph neural network via attribute completion[C]∥Proceedings of the Web Conference, New York, USA, 2021: 391-400.
[31]
ChenY, QinB, MaC, et al. Malware classification based on heterogeneous information network representation learning[C]∥International Conference on Big Data, Artificial Intelligence and Internet of Things Engineering, Fuzhou, China, 2020: 202000018.
JiYu-qing, FangYan-hong, TanShun-hua, et al. Detection of malicious JavaScript code based on Bi-LSTM model[J]. Computer Applications and Software, 2024, 41(9): 357-362.