English

Using HTML5 to Prevent Detection of Drive-by-Download Web Malware

Cryptography and Security 2015-07-14 v1

Abstract

The web is experiencing an explosive growth in the last years. New technologies are introduced at a very fast-pace with the aim of narrowing the gap between web-based applications and traditional desktop applications. The results are web applications that look and feel almost like desktop applications while retaining the advantages of being originated from the web. However, these advancements come at a price. The same technologies used to build responsive, pleasant and fully-featured web applications, can also be used to write web malware able to escape detection systems. In this article we present new obfuscation techniques, based on some of the features of the upcoming HTML5 standard, which can be used to deceive malware detection systems. The proposed techniques have been experimented on a reference set of obfuscated malware. Our results show that the malware rewritten using our obfuscation techniques go undetected while being analyzed by a large number of detection systems. The same detection systems were able to correctly identify the same malware in its original unobfuscated form. We also provide some hints about how the existing malware detection systems can be modified in order to cope with these new techniques.

Keywords

Cite

@article{arxiv.1507.03467,
  title  = {Using HTML5 to Prevent Detection of Drive-by-Download Web Malware},
  author = {Alfredo De Santis and Giancarlo De Maio and Umberto Ferraro Petrillo},
  journal= {arXiv preprint arXiv:1507.03467},
  year   = {2015}
}

Comments

This is the pre-peer reviewed version of the article: \emph{Using HTML5 to Prevent Detection of Drive-by-Download Web Malware}, which has been published in final form at \url{http://dx.doi.org/10.1002/sec.1077}. This article may be used for non-commercial purposes in accordance with Wiley Terms and Conditions for Self-Archiving

R2 v1 2026-06-22T10:10:47.990Z