A Flexible Framework for Malicious Open XML Document Detection based on APT Attacks

被引:0
|
作者
Sun, Hung-Min
Shen, Chi-En
Weng, Chi-Yao
机构
关键词
Open XML; Advanced Persistence Threat; APT; Malicious document;
D O I
10.1109/infcomw.2019.8845281
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The defense against Advanced Persistence Threat (APT) attacks is an important topic in recent years. Many organizations and enterprises even governments have been victims of APT attacks. As APT attacks have a specific objective and are skillfully crafted, motivated, organized and well founded, we should pay more attention on those attacks. Malicious documents have been used with the spear phishing attack in the initial infection phase of an APT attack. The detection of malicious documents is important for an early stage defensive APT attack. The Open XML has a popular document format used in the APT attacks. However, the related malicious document detection research is mostly focused on the PDF file or the traditional OLE Office document format. A specific framework design for malicious Open XML document detection does not exist. This article proposes a framework based on malicious Open XML document detection. This framework is designed under the fundamental principle, such as automatic, flexible and configurable. Our proposed framework can analyze Open XML document job automatically and generate analysis reports with information highlighting. The Scanner Module in this framework can be configured and easily extended by adding customized scanners, is flexible. The Configurable framework makes the APT detection more customizable and suitable for user's demand.
引用
收藏
页码:1005 / 1006
页数:2
相关论文
共 50 条
  • [1] Malicious Document Detection Based on GGE Visualization
    [J]. Sun, Yi (11112072@bjtu.edu.cn), 2025, 82 (01): : 1233 - 1254
  • [2] Classification and Analysis of Malicious Code Detection Techniques Based on the APT Attack
    Lee, Kyungroul
    Lee, Jaehyuk
    Yim, Kangbin
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (05):
  • [3] A Framework of APT Detection Based on Dynamic Analysis
    Su, Yunfei
    Li, Mengjun
    Tang, Chaojing
    Shen, Rongjun
    [J]. PROCEEDINGS OF THE 2015 4TH NATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS AND COMPUTER ENGINEERING ( NCEECE 2015), 2016, 47 : 1047 - 1053
  • [4] Malicious PDF document detection based on mixed feature
    Du, Xuehui
    Lin, Yangdong
    Sun, Yi
    [J]. Tongxin Xuebao/Journal on Communications, 2019, 40 (02): : 118 - 128
  • [5] A flexible structured-based representation for XML document mining
    Vercoustre, Anne-Marie
    Fegas, Mounir
    Gul, Saba
    Lechevallier, Yves
    [J]. ADVANCES IN XML INFORMATION RETRIEVAL AND EVALUATION, 2006, 3977 : 443 - 457
  • [6] Xml-based open framework for system interaction
    Copéré, L
    Fouilleron, M
    Truffinet, C
    Tricot, JC
    El Kamel, A
    [J]. 2003 IEEE SYSTEMS & INFORMATION ENGINEERING DESIGN SYMPOSIUM, 2003, : 101 - 106
  • [7] A Graph Based Framework for Malicious Insider Threat Detection
    Gamachchi, Anagi
    Sun, Li
    Boztas, Serdar
    [J]. PROCEEDINGS OF THE 50TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2017, : 2638 - 2647
  • [8] A new framework for APT attack detection based on network traffic
    Hoa Cuong Nguyen
    Cho Do Xuan
    Long Thanh Nguyen
    Hoa Dinh Nguyen
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (03) : 3459 - 3474
  • [9] XML schemas based flexible distributed code generation framework
    Govindaraju, Madhusudhan
    [J]. 2007 IEEE International Conference on Web Services, Proceedings, 2007, : 1212 - 1213
  • [10] Impact Evaluation and Detection of Malicious Spoofing Attacks on BLE Based Occupancy Detection Systems
    Oliff, William
    Filippoupolitis, Avgoustinos
    Loukas, George
    [J]. PROCEEDINGS OF THE 1ST INTERNATIONAL CONFERENCE ON INTERNET OF THINGS AND MACHINE LEARNING (IML'17), 2017,