Skip to content
Open access

BSM: A Browser-Resident Framework for Real-Time Detection of JavaScript API Abuse and Prompt Injection Attacks

2026 · IEEE Access · Vol 14, pp. 108287-108311 · 0 citations · 52 references
Computer Science

TL;DR

Browser Security Monitor (BSM), a browser-resident framework that instruments sensitive window object APIs to intercept and analyze dynamic JavaScript execution in real time, is presented, a precision-first, low-overhead client-side filter that complements rather than replaces server-side and model-internal defenses.

Abstract

As web applications embed both dynamic JavaScript and AI services, they expose browser APIs to two runtime threats that are rarely addressed together: JavaScript code injection and prompt injection. This paper presents Browser Security Monitor (BSM), a browser-resident framework that instruments sensitive window object APIs to intercept and analyze dynamic JavaScript execution in real time. BSM integrates weighted behavioral pattern matching using Deterministic Finite Automata (DFA) with empirically derived risk scores and a lightweight keyword and linguistic feature filter for direct prompt injection. We evaluate BSM across production deployment, static malware analysis, and prompt injection detection. Field deployment across 47 production websites monitored 50,732 API events (6,559 fetch and 44,173 eval() invocations) with zero false positives. Static evaluation on 1,109 samples (1,061 malicious from the Petrak collection and 48 benign production libraries) reports 98.4% precision, 59.6% recall, and 79.2% specificity at the browser-deployment threshold $T=40$ , with an AUROC of 0.60 reflecting a discrete weighted scoring design that trades ranking quality for sub-millisecond latency; a Random Forest baseline on the same features reaches AUC-ROC 0.98 but a 52.0% false-positive rate unusable for browser deployment. Applied to the static evaluation, a SHA-256 content-hash access list over canonical CDN library versions raises specificity to 100.0% with no measurable change in malicious-sample recall. On 1,695 labeled prompts, the prompt injection module yields 45.9% recall, 92.5% precision, 96.8% specificity, and F1 = 0.614, while detecting 0 of 20 paraphrased attacks, an explicit keyword evasion boundary. An adversarial robustness evaluation across five transformation families shows 90% evasion once the literal eval() token is stripped, quantifying the rule-based detection ceiling. BSM does not address indirect prompt injection, binary-payload malware, or polymorphic JavaScript outside the nine-pattern set. Detection latency stays within 0.3 to 0.8 ms and memory within 25 to 35 MB. BSM’s contribution is integrative rather than algorithmic: no individual technique is novel in isolation, and the value lies in combining JavaScript API-abuse detection and direct prompt injection detection in a single browser-resident, sub-millisecond, low-memory extension validated on 47 live production sites. BSM is a precision-first, low-overhead client-side filter that complements rather than replaces server-side and model-internal defenses.

Read PDF

Similar papers

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Unknown authors · 1 citation
#small language model Book Oct 2026

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Wen-Yu Xu, Anders Møller · 0 citations
Review Sep 2026

An Empirical Analysis of CodeQL False Positives and Query Refinements for Java Vulnerabilities

Static application security testing (SAST) tools help developers find vulnerabilities before deployment, but false positives create substantial triage effort. We study whether CodeQL false positives in Java security analysis form recurring, explainable patterns that can be reduced by refining the analysis. We run CodeQ...

Amirali Sajadi, Saikat Dutta, Preetha Chatterjee · 0 citations
Conference Jul 2026

Commit-Message-Augmented Static Analysis of Cross-Site Scripting Fixes in Java Web Applications

Cross-Site Scripting (XSS) remains a common and high-impact web vulnerability. Detecting XSS with high precision is difficult because exploitability depends on end-to-end data flow (sources, sanitizers, and sinks), framework-specific rendering semantics, and the correctness of context-aware output encoding. Although se...

Abu Alam, Qka Mirza · 0 citations
#artificial intelligence Preprint Sep 2026

Beyond Static Guarantees: Measuring the Static-Pass Dynamic-Fail Gap in Security-Sensitive and LLM-Generated Python Code

Advances in large language models (LLMs) fuel the quest for scalable methods to assess the security of generated and security-sensitive software. Static analysis is widely adopted as a scalable, reproducible, and inexpensive security gate, but cannot directly observe runtime exploit behaviour. Vulnerabilities dependent...

Jessica Pourleyli, Maitreyee Das Urmi, Glaucia Melo · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.