Finding rules for heuristic detection of malicious PDFs: with analysis of embedded exploit code

Paul Baccas Sophos

The use of PDFs as a vector for the installation of malicious content has been on the rise over the last few years. This has been for numerous reasons, some of which are the ubiquity of the file format (not browser or platform dependent); the update mechanisms for Adobe; and also the many and various exploit kits.

Methods for detection and classification of malware have been focused on EXE, MS Office and HTML analysis and the lack of research in PDF is telling. In this paper we show some tips and tricks to help classification and detection of malicious PDFs. This will be achieved by both static and dynamic analysis of malicious files and Internet-derived corpuses of, potentially, clean files.

As well as communicating these results, the presentation will augment them with analysis of current threats and case studies of whole attacks.

 del.icio.us  digg this! digg this

Quick Links

Poll
Should software vendors extend support for their products on Windows XP beyond the end-of-life of the operating system?
Yes - it keeps their users secure
No - it encourages users to continue to use a less secure OS
I don't know
Leave a comment
View 23 comments

Jobs Recruit Sidebar

Jobs
In Virus Bulletin's jobs pages among others:

Virus Bulletin currently has 231,294 registered users.