跳到主要导航 跳到搜索 跳到主要内容

UFADF: A Unified Feature Analysis and Detection Framework for Malicious Office Documents

  • Southwest University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Malicious Office documents have become common mediums in network attacks, which support embedding multi-class attack techniques with strong concealment. Existing detecting methods mainly focus on specific types of malicious attacks or document categories. It is lack of universal detection method for multi-version documents and multi-class malicious attacks. To address the issue, this paper proposes a Unified Feature Analyzing and Detecting Framework UFADF for multi-class malicious Office document detection. It is implemented with three-fold interesting ideas: a) analyzing 20,000 latest real-world Office document samples and extracting the key features of various malicious categories, which innovatively design five mainstream malicious feature extraction methods with eight new features or embedding locations; b) calculating the information gain of all the extracted malicious key features, then choosing the most 64 prominent malicious features to construct the feature list with a newly proposed feature fusion algorithm; c) detecting the fused malicious features with an adaptive classifier, which classifies Office documents with various versions and formats into five malicious categories and benign documents. Through the experiments on 20,000 latest real-world Office document samples, it is demonstrated that the proposed framework UFADF achieve high-precision unified feature detection, including detecting 185 malicious samples with accurate classifications which undetected by antivirus software.

源语言英语
主期刊名Proceedings - 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom/BigDataSE/CSE/EUC/iSCI 2023
编辑Jia Hu, Geyong Min, Guojun Wang
出版商Institute of Electrical and Electronics Engineers Inc.
881-888
页数8
ISBN(电子版)9798350381993
DOI
出版状态已出版 - 2023
活动22nd IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2023 - Exeter, 英国
期限: 1 11月 20233 11月 2023

出版系列

姓名Proceedings - 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom/BigDataSE/CSE/EUC/iSCI 2023

会议

会议22nd IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2023
国家/地区英国
Exeter
时期1/11/233/11/23

指纹

探究 'UFADF: A Unified Feature Analysis and Detection Framework for Malicious Office Documents' 的科研主题。它们共同构成独一无二的指纹。

引用此