Logo image
A Flexible Framework for Malicious Open XML Document Detection against APT Attacks
Thesis

A Flexible Framework for Malicious Open XML Document Detection against APT Attacks

Shen, Chi-En
Masters, 國立清華大學, 資訊系統與應用研究所
2013

Abstract

進階持續性滲透攻擊 惡意文件偵測 Open XML Advanced Persistence Threat APT Malicious document
The defense against Advanced Persistence Threat (APT) attacks is a hot issue in recent years. Many organizations and enterprises even governments have been victims of APT attacks. Since APT attacks have a specific objective and are skillfully crafted, motivated, organized and well founded, they should not be ignored. Malicious documents have always been used with the spear phishing attack in the initial infection phase of an APT attack. The detection of malicious documents is important for an early stage defensive APT attack. In recent years, Open XML has become a popular document format used in the APT attacks. However, the related malicious document detection research is mostly focused on the PDF file or the traditional OLE Office document format. A specific framework design for malicious Open XML document detection does not exist. In this thesis, we propose a malicious Open XML document detection framework. This framework is designed under the principle of: Automatic, Flexible and Configurable. This framework can analyze Open XML document job automatically and generate analysis reports with information highlighting. Also, this framework is flexible since the “Scanner Module” can be configured and it is easy to extend this farmework by adding customized scanners. The “Configurable” framework makes the detection more customizable and can be adjusted to fit different scanning on demand. This framework can not only be used to do the detection work but it can also be used for research purposes.

Metrics

1 Record Views

Details

Logo image