Skip to main navigation Skip to search Skip to main content

Combining static and dynamic analysis for the detection of malicious documents

  • Foundation for Research and Technology-Hellas
  • University of Crete

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

100 Scopus citations

Abstract

The widespread adoption of the PDF format for document exchange has given rise to the use of PDF files as a prime vector for malware propagation. As vulnerabilities in the major PDF viewers keep surfacing, effective detection of malicious PDF documents remains an important issue. In this paper we present MDScan, a standalone malicious document scanner that combines static document analysis and dynamic code execution to detect previously unknown PDF threats. Our evaluation shows that MDScan can detect a broad range of malicious PDF documents, even when they have been extensively obfuscated.

Original languageEnglish
Title of host publicationProceedings of the 4th Workshop on European Workshop on System Security, EUROSEC'11
PublisherAssociation for Computing Machinery
ISBN (Print)9781450306133
DOIs
StatePublished - Apr 10 2011

Publication series

NameProceedings of the 4th Workshop on European Workshop on System Security, EUROSEC'11

Keywords

  • Attack surface reduction
  • Kernel hardening

Fingerprint

Dive into the research topics of 'Combining static and dynamic analysis for the detection of malicious documents'. Together they form a unique fingerprint.

Cite this