RISS 학술연구정보서비스

검색
다국어 입력

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

변환된 중국어를 복사하여 사용하시면 됩니다.

예시)
  • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
  • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
닫기
    인기검색어 순위 펼치기

    RISS 인기검색어

      κ-Depth Mimicry Attack to Secretly Embed Shellcode into PDF Files and the Evaluation and the Countermeasure

      한글로보기

      https://www.riss.kr/link?id=T14574732

      • 0

        상세조회
      • 0

        다운로드
      서지정보 열기
      • 내보내기
      • 내책장담기
      • 공유하기
      • 오류접수

      부가정보

      다국어 초록 (Multilingual Abstract)

      This paper revisits the shellcode embedding problem for PDF files. We found that a popularly used shellcode embedding technique called reverse mimicry attack has not been shown to be effective against well-trained state-of-the-art detectors. To overco...

      This paper revisits the shellcode embedding problem for PDF files. We found that a popularly used shellcode embedding technique called reverse mimicry attack has not been shown to be effective against well-trained state-of-the-art detectors. To overcome the limitation of the reverse mimicry method against existing shellcode detectors, we extend the idea of reverse mimicry attack to a more generalized one by applying the ��-depth mimicry method to PDF files. We implement a proof-of-concept tool for the ��-depth mimicry attack and show its feasibility by generating shellcode-embedded PDF files to evade the best known shellcode detector (PDFrate) with three classifiers. The experimental results show that all tested classifiers failed to effectively detect the shellcode embedded by the ��-depth mimicry method when �� ≧ 20. As the countermeasure of our ��-depth mimicry attack, we propose a novel PDF parser toolkit to approach a suspicious PDF document files from different aspects, functioning object-by-object analysis. We implement the toolkit named ‘PDF Antagonist’ as the result, and demonstrate the effectiveness.

      더보기

      목차 (Table of Contents)

      • ABSTRACT
      • 1 Introduction
      • 1-1 Overview
      • 1-2 Contributions
      • ABSTRACT
      • 1 Introduction
      • 1-1 Overview
      • 1-2 Contributions
      • 1-3 Organization of the Paper
      • 2 Background
      • 2-1 Object, categorized by Types
      • 2-2 File Structure
      • 2-3 Document Structure
      • 2-4 Common Shellcode Types
      • 3 Related Work
      • 3-1 Malicious PDF Detection Techniques
      • 3-2 Evasion of Malicious PDF Detection Techniques
      • 4 K-Depth Mimicry Attack
      • 5 Experiments
      • 5-1 Evaluation of ��-depth Mimicry based on Commonplace Object Dictionary
      • 5-2 Evaluation of ��-depth Mimicry based on Self-built Objects Dictionary
      • 5-3 Comparison to Evaluation Result
      • 6 Countermeasure
      • 7 Conclusion
      • References
      • 논문요약(국문초록)
      더보기

      분석정보

      View

      상세정보조회

      0

      Usage

      원문다운로드

      0

      대출신청

      0

      복사신청

      0

      EDDS신청

      0

      동일 주제 내 활용도 TOP

      더보기

      주제

      연도별 연구동향

      연도별 활용동향

      연관논문

      연구자 네트워크맵

      공동연구자 (7)

      유사연구자 (20) 활용도상위20명

      이 자료와 함께 이용한 RISS 자료

      나만을 위한 추천자료

      해외이동버튼