Skip to content
Open access

JSCoherence: detecting obfuscated malicious JavaScript via data-dependent statement pairs

Sep 2026 · Cybersecurity · Vol 9 · 0 citations · 42 references

Abstract

As a crucial component of websites, JavaScript is one of the most common attack payloads on malicious websites. Although many methods for detecting malicious JavaScript have been proposed, obfuscation techniques make it difficult for previous approaches to detect disguised malicious JavaScript effectively. To address this problem, we observe that malicious JavaScript often uses obfuscation to fragment key attack semantics and conceal them within data-dependent statements involving variable propagation. This observation suggests that data dependencies between variables can be leveraged to extract potentially malicious functional statements. Therefore, this paper proposes JSCoherence, a novel static detection method for obfuscated malicious JavaScript. Its core principle is to mine statement pairs with data dependencies through data-flow analysis, thereby reconnecting fragmented semantics and recovering locally coherent malicious behavior. Experiments show that JSCoherence achieves an F1 score of 99.77% on public datasets. On the Jfogs, JSObfu, and JavaScript-obfuscator obfuscated datasets, its F1 score consistently exceeds 95%, representing an improvement over the current advanced methods. In addition, JSCoherence provides interpretability by analyzing the semantics of representative data-dependent statement pairs, offering clear explanatory evidence for its detection decisions.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.