Unlock instant, AI-driven research and patent intelligence for your innovation.

Detection method for malicious PDF document containing JavaScript, and electronic equipment

A detection method and document technology, applied in the computer field, can solve problems such as confusion and encryption that are difficult to detect, and achieve the effect of improving accuracy

Active Publication Date: 2021-02-05
PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU
View PDF9 Cites 4 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Generally speaking, the disadvantage of static features is that it is difficult to detect obfuscation and encryption and hide deep malicious codes, while the acquisition of dynamic features requires the construction of a large number of heterogeneous operating environments, which require a lot of resource overhead and are easy to pass time delays, interactive manipulation and other techniques to circumvent

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Detection method for malicious PDF document containing JavaScript, and electronic equipment
  • Detection method for malicious PDF document containing JavaScript, and electronic equipment
  • Detection method for malicious PDF document containing JavaScript, and electronic equipment

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0043] In order to further explain the technical means and functions adopted by the present invention to achieve the intended purpose, the present invention will be described in detail below in conjunction with the accompanying drawings and preferred embodiments.

[0044] Such as figure 1 As shown, according to the detection method for malicious PDF documents containing JavaScript according to the embodiment of the present invention, including:

[0045] S101: Extract JavaScript code;

[0046] It should be noted that the PDF document may contain JavaScript code, and the JavaScript code extracted from the PDF document may refer to the complete JavaScript code. thus. It is convenient for feature extraction and classification analysis of JavaScript code. The realization of the malicious function of the malicious PDF document to be identified by the present invention is caused by the included malicious JavaScript code.

[0047]S102: Perform feature extraction on the JavaScript ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides a detection method for a malicious PDF (Portable Document Format) document containing JavaScript. The detection method for the malicious PDF document containing the JavaScript comprises the following steps of extracting a JavaScript code; carrying out feature extraction on the JavaScript code to obtain feature data; inputting the feature data into a pre-constructed trainingclassification model for processing to obtain a classification result; and obtaining a detection result of the PDF document based on the classification result. According to the detection method for the malicious PDF document containing the JavaScript, the JavaScript code in the PDF document is extracted, feature extraction is carried out on the JavaScript code, and the feature data is input into the pre-constructed training classification model to be processed to obtain the classification result, so the malicious JavaScript code can be effectively extracted; therefore, whether the PDF documentis benign or malicious can be accurately and reliably judged according to the classification result, and malicious PDF document detection accuracy is improved.

Description

technical field [0001] The invention relates to the field of computer technology, in particular to a method for detecting malicious PDF documents containing JavaScript. Background technique [0002] Since the Portable Document Format (PDF) is widely used for document exchange due to its high efficiency and stability, PDF files have become an important vector of cyber attacks. A typical scenario is phishing attacks using emails targeting governments and large corporations. Since most mail servers block executable files attached to emails for security reasons, PDF files have played an increasing role in recent cyberattacks. Regular users consider non-executable files safer than executable files, making them less suspicious of receiving files by email. However, PDF files are just as dangerous as executable files, and attackers can exploit vulnerabilities in the document format to gain illegal access to the host. [0003] An important reason why PDF files are insecure comes f...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): G06F21/56G06K9/62G06N3/04G06F40/205G06F40/279
CPCG06F21/562G06N3/045G06F18/23G06F18/241Y02D10/00
Inventor 刘龙祝跃飞何康芦斌林伟陈岩费金龙舒辉李红帅
Owner PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More