New Deep Learning Method to Detect Code Injection Attacks on Hybrid Applications.

Ruibo Yan,Xi Xiao,Guangwu Hu,Sancheng Peng,Yong Jiang
DOI: https://doi.org/10.1016/j.jss.2017.11.001
IF: 3.5
2017-01-01
Journal of Systems and Software
Abstract:Mobile phones are becoming increasingly pervasive. Among them, HTML5-based hybrid applications are more and more popular because of their portability on different systems. However these applications suffer from code injection attacks. In this paper, we construct a-novel deep learning network, Hybrid Deep Learning Network (HDLN), and use it to detect these attacks. At first, based on our previous work, we extract more features from Abstract Syntax Tree (AST) of JavaScript and employ three methods to select key features. Then we get the feature vectors and train HDLN to distinguish vulnerable applications from normal ones. Finally thorough experiments are done to validate our methods. The results show our detection approach with HDLN achieves 97.55% in accuracy and 97.60% in AUC, which outperforms those with other traditional classifiers and gets higher average precision than other detection methods. (C) 2017 Elsevier Inc. All rights reserved.
What problem does this paper attempt to address?