<p>With the increasing popularity of browser extensions, there is a growing concern about malicious actors exploiting this software to distribute malware. Existing solutions rely on manual review processes or traditional methods like static, dynamic or hybrid analysis, which are insufficient in detecting complex and evolving threats. In this study, we investigate the potential of Natural Language Processing (NLP) for automatically classifying users’ comments in the Chrome Web Store, the public repository where extensions are stored and distributed, to identify malicious extensions. We propose a novel framework called CoTH that leverages NLP techniques to analyse the textual feedback provided by users and detect patterns indicative of malicious activity. We evaluate the accuracy of our model using a dataset of user reviews and demonstrate its effectiveness in identifying malicious extensions. Our findings suggest that NLP-based comment analysis can be a valuable addition to existing security measures, providing an opportunity for more accurate and efficient detection of malware in the Chrome Web Store.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

From comments to threats: leveraging NLP to detect malicious browser extensions

  • Adam Flemark,
  • Axel Paulander,
  • Pablo Picazo-Sanchez

摘要

With the increasing popularity of browser extensions, there is a growing concern about malicious actors exploiting this software to distribute malware. Existing solutions rely on manual review processes or traditional methods like static, dynamic or hybrid analysis, which are insufficient in detecting complex and evolving threats. In this study, we investigate the potential of Natural Language Processing (NLP) for automatically classifying users’ comments in the Chrome Web Store, the public repository where extensions are stored and distributed, to identify malicious extensions. We propose a novel framework called CoTH that leverages NLP techniques to analyse the textual feedback provided by users and detect patterns indicative of malicious activity. We evaluate the accuracy of our model using a dataset of user reviews and demonstrate its effectiveness in identifying malicious extensions. Our findings suggest that NLP-based comment analysis can be a valuable addition to existing security measures, providing an opportunity for more accurate and efficient detection of malware in the Chrome Web Store.