TY - GEN
T1 - Combining static and dynamic analysis for the detection of malicious documents
AU - Tzermias, Zacharias
AU - Sykiotakis, Giorgos
AU - Polychronakis, Michalis
AU - Markatos, Evangelos P.
PY - 2011/4/10
Y1 - 2011/4/10
N2 - The widespread adoption of the PDF format for document exchange has given rise to the use of PDF files as a prime vector for malware propagation. As vulnerabilities in the major PDF viewers keep surfacing, effective detection of malicious PDF documents remains an important issue. In this paper we present MDScan, a standalone malicious document scanner that combines static document analysis and dynamic code execution to detect previously unknown PDF threats. Our evaluation shows that MDScan can detect a broad range of malicious PDF documents, even when they have been extensively obfuscated.
AB - The widespread adoption of the PDF format for document exchange has given rise to the use of PDF files as a prime vector for malware propagation. As vulnerabilities in the major PDF viewers keep surfacing, effective detection of malicious PDF documents remains an important issue. In this paper we present MDScan, a standalone malicious document scanner that combines static document analysis and dynamic code execution to detect previously unknown PDF threats. Our evaluation shows that MDScan can detect a broad range of malicious PDF documents, even when they have been extensively obfuscated.
KW - Attack surface reduction
KW - Kernel hardening
UR - https://www.scopus.com/pages/publications/79957806740
U2 - 10.1145/1972551.1972555
DO - 10.1145/1972551.1972555
M3 - Conference contribution
SN - 9781450306133
T3 - Proceedings of the 4th Workshop on European Workshop on System Security, EUROSEC'11
BT - Proceedings of the 4th Workshop on European Workshop on System Security, EUROSEC'11
PB - Association for Computing Machinery
ER -