SPARSE: A Hybrid System to Detect Malcode-Bearing Documents
نویسندگان
چکیده
Embedding malcode within documents provides a convenient means of penetrating systems which may be unreachable by network-level service attacks. Such attacks can be very targeted and difficult to detect compared to the typical network worm threat due to the multitude of document-exchange vectors. Detecting malcode embedded in a document is difficult owing to the complexity of modern document formats that provide ample opportunity to embed code in a myriad of ways. We focus on Microsoft Word documents as malcode carriers as a case study in this paper. We introduce a hybrid system that integrates static and dynamic techniques to detect the presence and location of malware embedded in documents. The system is designed to automatically update its detection models to improve accuracy over time. The overall hybrid detection system with a learning feedback loop is demonstrated to achieve a 99.27% detection rate and 3.16% false positive rate on a corpus of 6228 Word documents.
منابع مشابه
Thwarting Attacks in Malcode-Bearing Documents by Altering Data Sector Values
Embedding malcode within documents provides a convenient means of attacking systems. Such attacks can be very targeted and difficult to detect to stop due to the multitude of document-exchange vectors and the vulnerabilities in modern document processing applications. Detecting malcode embedded in a document is difficult owing to the complexity of modern document formats that provide ample oppo...
متن کاملData-Driven Detection of Malicious Document PhD Thesis Proposal
Malcode hidden in otherwise normal appearing public documents provide both convenient and stealthy means for attackers to penetrate systems. By exploiting the ubiquitous and object-oriented approach of modern document applications and formats, malcode can reach third-party applications that may harbor exploitable vulnerabilities otherwise unreachable by network-level service attacks: by clickin...
متن کاملA Study of Malcode-Bearing Documents
By exploiting the object-oriented dynamic composability of modern document applications and formats, malcode hidden in otherwise inconspicuous documents can reach third-party applications that may harbor exploitable vulnerabilities that are otherwise unreachable by network-level service attacks. Such attacks can be very selective and difficult to detect compared to the typical network worm thre...
متن کاملFileprint analysis for Malware Detection
June 19, 2005 1 Review Draft Fileprint analysis for Malware Detection Salvatore J. Stolfo, Ke Wang, Wei-Jen Li Columbia University Abstract Malcode can be easily hidden in document files and embedded in application executables. We demonstrate this opportunity of stealthy malcode insertion in several experiments using a standard COTS Anti-Virus (AV) scanner. In the case of zero-day malicious exp...
متن کاملTowards Stealthy Malware Detection1
Malcode can be easily hidden in document files and go undetected by standard technology. We demonstrate this opportunity of stealthy malcode insertion in several experiments using a standard COTS Anti-Virus (AV) scanner. Furthermore, in the case of zero-day malicious exploit code, signature-based AV scanners would fail to detect such malcode even if the scanner knew where to look. We propose th...
متن کامل