Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

문서 구조 및 스트림 오브젝트 분석을 통한 문서형 악성코드 탐지

Full metadata record
DC Field Value Language
dc.contributor.author강아름-
dc.contributor.author정영섭-
dc.contributor.author김세령-
dc.contributor.author김종현-
dc.contributor.author우지영-
dc.contributor.author최선오-
dc.date.accessioned2021-08-11T13:23:30Z-
dc.date.available2021-08-11T13:23:30Z-
dc.date.created2021-06-17-
dc.date.issued2018-
dc.identifier.issn1598-849X-
dc.identifier.urihttps://scholarworks.bwise.kr/sch/handle/2021.sw.sch/6466-
dc.description.abstractIn recent years, there has been an increasing number of ways to distribute document-based malicious code using vulnerabilities in document files. Because document type malware is not an executable file itself, it is easy to bypass existing security programs, so research on a model to detect it is necessary. In this study, we extract main features from the document structure and the JavaScript contained in the stream object In addition, when JavaScript is inserted, keywords with high occurrence frequency in malicious code such as function name, reserved word and the readable string in the script are extracted. Then, we generate a machine learning model that can distinguish between normal and malicious. In order to make it difficult to bypass, we try to achieve good performance in a black box type algorithm. For an experiment, a large amount of documents compared to previous studies is analyzed. Experimental results show 98.9% detection rate from three different type algorithms. SVM, which is a black box type algorithm and makes obfuscation difficult, shows much higher performance than in previous studies.-
dc.language한국어-
dc.language.isoko-
dc.publisher한국컴퓨터정보학회-
dc.title문서 구조 및 스트림 오브젝트 분석을 통한 문서형 악성코드 탐지-
dc.title.alternativeDetection of Malicious PDF based on Document Structure Features and Stream Object-
dc.typeArticle-
dc.contributor.affiliatedAuthor강아름-
dc.contributor.affiliatedAuthor정영섭-
dc.contributor.affiliatedAuthor우지영-
dc.identifier.doi10.9708/jksci.2018.23.11.085-
dc.identifier.bibliographicCitation한국컴퓨터정보학회논문지, v.23, no.11, pp.85 - 93-
dc.relation.isPartOf한국컴퓨터정보학회논문지-
dc.citation.title한국컴퓨터정보학회논문지-
dc.citation.volume23-
dc.citation.number11-
dc.citation.startPage85-
dc.citation.endPage93-
dc.type.rimsART-
dc.identifier.kciidART002406766-
dc.description.journalClass2-
dc.description.journalRegisteredClasskci-
dc.subject.keywordAuthormalware-
dc.subject.keywordAuthorPDF-
dc.subject.keywordAuthormachine learning-
dc.subject.keywordAuthorjava script-
dc.subject.keywordAuthordetection-
Files in This Item
There are no files associated with this item.
Appears in
Collections
SCH Media Labs > Department of Big Data Engineering > 1. Journal Articles
SCH Media Labs > SCH미디어랩스_SCH융합과학연구소 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Woo, Ji young photo

Woo, Ji young
College of Software Convergence (AI·빅데이터학과)
Read more

Altmetrics

Total Views & Downloads

BROWSE