Invoice #31415 attached: Automated analysis of malicious Microsoft Office documents. Issue 114 (March 2022)
- Record Type:
- Journal Article
- Title:
- Invoice #31415 attached: Automated analysis of malicious Microsoft Office documents. Issue 114 (March 2022)
- Main Title:
- Invoice #31415 attached: Automated analysis of malicious Microsoft Office documents
- Authors:
- Koutsokostas, Vasilios
Lykousas, Nikolaos
Apostolopoulos, Theodoros
Orazi, Gabriele
Ghosal, Amrita
Casino, Fran
Conti, Mauro
Patsakis, Constantinos - Abstract:
- Abstract: Microsoft Office may be by far the most widely used suite for processing documents, spreadsheets, and presentations. Due to its popularity, it is continuously utilised to carry out malicious campaigns. Threat actors, exploiting the platform's dynamic features, use it to launch their attacks and penetrate millions of hosts in their campaigns. This work explores the modern landscape of malicious Microsoft Office documents, exposing the means that malware authors use. We leverage a taxonomy of the tools used to weaponise Microsoft Office documents and explore the modus operandi of malicious actors. Moreover, we generated and publicly shared a specially crafted dataset, which relies on incorporating benign and malicious documents containing many dynamic features such as VBA macros and DDE. The latter is crucial for a fair and realistic analysis, an open issue in the current state of the art. This allows us to draw safe conclusions on the malicious features and behaviour. More precisely, we extract the necessary features with an automated analysis pipeline to efficiently and accurately classify a document as benign or malicious using machine learning with an F 1 score above 0.98, outperforming the current state of the art detection algorithms.
- Is Part Of:
- Computers & security. Issue 114(2022)
- Journal:
- Computers & security
- Issue:
- Issue 114(2022)
- Issue Display:
- Volume 114, Issue 114 (2022)
- Year:
- 2022
- Volume:
- 114
- Issue:
- 114
- Issue Sort Value:
- 2022-0114-0114-0000
- Page Start:
- Page End:
- Publication Date:
- 2022-03
- Subjects:
- Malware -- Office documents -- Macro malware -- Powershell -- LOLBAS
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102582 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 25262.xml