期刊文献+

针对JavaScript攻击的恶意PDF文档检测技术研究 被引量:4

Research on Malicious PDF Documents Detection Technology Based on JavaScript Attack
下载PDF
导出
摘要 当今社会,便携式文档(PDF)已经成为恶意代码传播的主要载体,而90%的恶意PDF样本都是基于Java Script攻击的。因此针对Java Script攻击的恶意样本检测是非常有必要的。介绍PDF的结构,以及常见的嵌入Java Script的恶意PDF文档攻击手段,在此基础上,提出一种基于Java Script攻击的恶意PDF文档检测方法,并实现基于该方法的检测系统,主要包括PDF文档格式深入解析模块、Java Script代码定位与提取模块、恶意特征提取模块。实验表明该系统能有效检测PDF恶意文档。 In today's society, portable document(PDF) has become the main carrier of the spread of malicious code, while 90% of the malicious PDF sample are based on JavaScript attacks. So it is necessary to detect the malicious sample based on JavaScript attack. Introduces the struc- ture of PDF files and attack method based on JavaScript code. Based on this research, proposes a malicious PDF document detection method based on JavaScript attack and realizes the detection system ,which mainly includes the parsing module of PDF file format, JavaScript code location and extraction module, malicious feature extraction module. Experiments show that this system can effectively detect malicious PDF document.
作者 胡江 周安民
出处 《现代计算机》 2016年第1期36-40,共5页 Modern Computer
关键词 恶意PDF文档 JAVASCRIPT代码 静态检测 特征提取 Malicious PDF Documets JavaScript Code Static Detection Feature Extraction
  • 相关文献

参考文献6

  • 1Lu Xun,Zhuge Jianwei,Wang Ruoyu,Cao Yinzhi,Yan Chen. De-Obfuscation and Detection of Malicious PDF Files with High Accuracy [J]. System Science(HICSS),2013( 1 ) : 1530-1605.
  • 2Tzermias Z, Sykiotakis G, Polychronakis M, et al. Combining Static and Dynamic Analysis for the Detection of Malicious Docu- ments Proceedings of the Fourth European Workshop on System Security. ACM, 2011: 4.
  • 3Laskov P, rndi N. Static Detection of Malicious JavaScript-bearing PDF Documents Proceedings of the 27th Annual Com- puter Security Applications Conference. ACM, 2011: 373-382.
  • 4武学峰.恶意PDF文档的分析.山东:山东大学,2012.
  • 5Securelist, http://www.securelist.com/en/.
  • 6Virustotal, https://www.virustotal.com.

同被引文献23

引证文献4

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部