Looking at the bag is not enough to find the bomb: an evasion of structural methods for malicious PDF files detection

MAIORCA, DAVIDE;CORONA, IGINO;GIACINTO, GIORGIO
2013-01-01

Abstract

PDF files have proved to be excellent malicious-code bearing vectors. Thanks to their flexible logical structure, an attack can be hidden in several ways, and easily deceive protection mechanisms based on file-type filtering. Recent work showed that malicious PDF files can be accurately detected by analyzing their logical structure, with excellent results. In this paper, we present and practically demonstrate a novel evasion technique, called reverse mimicry, that can easily defeat such kind of analysis. We implement it using real samples and validate our approach by testing it against various PDF malware detectors proposed so far. Finally, we highlight the importance of developing systems robust to adversarial attacks and propose a framework to strengthen PDF malware detection against evasion.
2013
ASIA CCS'13. Proceedings of the 8th ACM Symposium on Information, Computer and Communications Security
978-1-4503-1767-2
ACM
New York
119
129
11
http://dl.acm.org/citation.cfm?doid=2484313.2484327
8th ACM SIGSAC Symposium on Information, Computer and Communications Security, ASIA CCS 2013
contributo
Esperti anonimi
8-10 May 2013
Hangzhou, China
internazionale
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Maiorca, Davide; Corona, Igino; Giacinto, Giorgio
273
3
4.1 Contributo in Atti di convegno
none
info:eu-repo/semantics/conferenceObject
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Questionario e social

Condividi su:
Impostazioni cookie