Proceedings of the Fourth European Workshop on System Security 2011
DOI: 10.1145/1972551.1972555
|View full text |Cite
|
Sign up to set email alerts
|

Combining static and dynamic analysis for the detection of malicious documents

Abstract: The widespread adoption of the PDF format for document exchange has given rise to the use of PDF files as a prime vector for malware propagation. As vulnerabilities in the major PDF viewers keep surfacing, effective detection of malicious PDF documents remains an important issue. In this paper we present MDScan, a standalone malicious document scanner that combines static document analysis and dynamic code execution to detect previously unknown PDF threats. Our evaluation shows that MDScan can detect a broad r… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
69
0
1

Year Published

2014
2014
2022
2022

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 96 publications
(70 citation statements)
references
References 9 publications
0
69
0
1
Order By: Relevance
“…Tzermias et al [9] proposed MDScan, which extracts Javascript from documents and executes it in instrumented SpiderMonkey and Nemu [19]. However, such a method suffers several limitations.…”
Section: Related Workmentioning
confidence: 99%
See 4 more Smart Citations
“…Tzermias et al [9] proposed MDScan, which extracts Javascript from documents and executes it in instrumented SpiderMonkey and Nemu [19]. However, such a method suffers several limitations.…”
Section: Related Workmentioning
confidence: 99%
“…These features characterize the obfuscation techniques frequently used in malicious PDF. The combination of static and runtime features will be more effective and robust than existing methods, which are either fully static [5] [4] [6] or fully dynamic [9] [13]. A more thorough comparison between our method and others is presented in Table I.…”
Section: Introductionmentioning
confidence: 99%
See 3 more Smart Citations