PDF Malicious Indicators Extraction Technique Based on Improved Symbolic Execution

The malicious PDF document is a common attack method used by APT organizations.Analyzing extracted indicators of embedded JavaScript code is an important means to determine the maliciousness of the documents.However, attackers can adopt high obfuscation, sandbox detection and other escape methods to...

Full description

Saved in:
Bibliographic Details
Published in:Ji suan ji ke xue Vol. 51; no. 7; pp. 389 - 396
Main Authors: Song, Enzhou, Hu, Tao, Yi, Peng, Wang, Wenbo
Format: Journal Article
Language:Chinese
Published: Chongqing Guojia Kexue Jishu Bu 01.07.2024
Editorial office of Computer Science
Subjects:
ISSN:1002-137X
Online Access:Get full text
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:The malicious PDF document is a common attack method used by APT organizations.Analyzing extracted indicators of embedded JavaScript code is an important means to determine the maliciousness of the documents.However, attackers can adopt high obfuscation, sandbox detection and other escape methods to interfere with analysis.Therefore, this paper innovatively applies symbolic execution method to PDF indicator extraction.We propose a PDF malicious indicator extraction technique based on improved symbolic execution and implement SYMBPDF,an indicator extraction system consisting of three modules: code parsing, symbolic execution and indicator extraction.In the code parsing module, we implement extraction and reorganization of inline Javascript code.In the symbolic execution module, we design the code rewriting method to force branch shifting, resulting in improving the code coverage of symbolic execution.We also design a concurrency strategy and two constraint solving optimization methods to improve the efficiency
Bibliography:ObjectType-Article-1
SourceType-Scholarly Journals-1
ObjectType-Feature-2
content type line 14
ISSN:1002-137X
DOI:10.11896/jsjkx.230300117