Inline Detection Of Evil JavaScript
ID: ed6ffdaa-3808-5e26-b73e-fd828eb49895
STIX ID: report--ed6ffdaa-3808-5e26-b73e-fd828eb49895
Feed Name: Zscaler Security Research Blog
This report analyzes how exploit kits and injected obfuscated JavaScript evade detection and proposes two scalable inline heuristics—Shannon entropy scoring and JavaScript "density" scoring—to flag potentially malicious scripts for further inspection; tests showed benign pages typically have entropy around 5–6 and low density, while many exploit pages deviate from that range and exhibit much higher density, making these metrics useful filters to reduce the subset of JS requiring deobfuscation or blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
