{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T22:42:53Z","timestamp":1760395373850,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030883805"},{"type":"electronic","value":"9783030883812"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-88381-2_7","type":"book-chapter","created":{"date-parts":[[2021,10,14]],"date-time":"2021-10-14T14:42:13Z","timestamp":1634222533000},"page":"135-155","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["DETECTING MALICIOUS PDF DOCUMENTS USING SEMI-SUPERVISED MACHINE LEARNING"],"prefix":"10.1007","author":[{"given":"Jianguo","family":"Jiang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nan","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Min","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kam-Pui","family":"Chow","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiqing","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,10,15]]},"reference":[{"key":"7_CR1","unstructured":"Adobe Systems, Document Management \u2013 Portable Document Format \u2013 Part 1: PDF 1.7, First Edition 2008-7-1, PDF 32000-1:2008, First Edition 2008-7-1, San Jose, California, 2008."},{"key":"7_CR2","unstructured":"A. Blonce, E. Filiol and L. Frayssignes, Portable Document Format (PDF) security analysis and malware threats, presented at the Black Hat Europe Conference, 2008."},{"key":"7_CR3","doi-asserted-by":"crossref","unstructured":"G. Canfora, F. Mercaldo and C. Visaggio, An HMM and structural entropy based detector for Android malware: An empirical study, Computers and Security, vol. 61, pp. 1\u201318, 2016.","DOI":"10.1016\/j.cose.2016.04.009"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"A. Cohen, N. Nissim, L. Rokach and Y. Elovici, SFEM: Structural feature extraction methodology for the detection of malicious office documents using machine learning methods, Expert Systems with Applications, vol. 63, pp 324\u2013343, 2016.","DOI":"10.1016\/j.eswa.2016.07.010"},{"key":"7_CR5","unstructured":"Contaigo, 16,800 Clean and 11,960 Malicious Files for Signature Testing and Research (contagiodump.blogspot.com\/2013\/03\/16800-clean-and-11960-malicious-files.html), March 24, 2013."},{"key":"7_CR6","unstructured":"FireEye, Advanced Persistent Threat Groups, Milipitas, California (www.fireeye.com\/current-threats\/apt-groups.html), 2020."},{"key":"7_CR7","doi-asserted-by":"crossref","unstructured":"D. Gibert, C. Mateu, J. Planes and R. Vicens, Classification of malware by using structural entropy on convolutional neural networks, Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence, Thirtieth AAAI Conference on Innovative Applications of Artificial Intelligence and Eighth AAAI Symposium on Educational Advances in Artificial Intelligence, pp. 7759\u20137764, 2018.","DOI":"10.1609\/aaai.v32i1.11409"},{"key":"7_CR8","doi-asserted-by":"crossref","unstructured":"A. Kaboutari, J. Bagherzadeh and F. Kheradmand, An evaluation of two-step techniques for positive-unlabeled learning in text classification, International Journal of Computer Applications Technology and Research, vol. 3(9), pp. 592\u2013594, 2014.","DOI":"10.7753\/IJCATR0309.1012"},{"key":"7_CR9","doi-asserted-by":"crossref","unstructured":"M. Li, Y. Liu, M. Yu, G. Li, Y. Wang and C. Liu, FEPDF: A robust feature extractor for malicious PDF detection, Proceedings of the IEEE International Conference on Trust, Security and Privacy in Computing and Communications, pp. 218\u2013224, 2017.","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.240"},{"key":"7_CR10","doi-asserted-by":"crossref","unstructured":"J. Lin and H. Pao, Multi-view malicious document detection, Proceedings of the Conference on Technologies and Applications of Artificial Intelligence, pp. 170\u2013175, 2013.","DOI":"10.1109\/TAAI.2013.43"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"L. Liu, X. He, L. Liu, L. Qing, Y. Fang and J. Liu, Capturing the symptoms of malicious code in electronic documents by file entropy signals combined with machine learning, Applied Soft Computing, vol. 82, article no. 105598, 2019.","DOI":"10.1016\/j.asoc.2019.105598"},{"key":"7_CR12","doi-asserted-by":"crossref","unstructured":"X. Lu, F. Wang and Z. Shu, Malicious Word document detection based on multi-view feature learning, Proceedings of the Twenty-Eighth International Conference on Computer Communications and Networks, 2019.","DOI":"10.1109\/ICCCN.2019.8846940"},{"key":"7_CR13","doi-asserted-by":"crossref","unstructured":"D. Maiorca, D. Ariu, I. Corona and G. Giacinto, A structural and content-based approach for precise and robust detection of malicious PDF files, Proceedings of the International Conference on Information Systems Security and Privacy, pp. 27\u201336, 2015.","DOI":"10.5220\/0005264400270036"},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"D. Maiorca, G. Giacinto and I. Corona, A pattern recognition system for malicious PDF file detection, Proceedings of the Eighth International Conference on Machine Learning and Data Mining in Pattern Recognition, pp. 510\u2013524, 2012.","DOI":"10.1007\/978-3-642-31537-4_40"},{"key":"7_CR15","doi-asserted-by":"crossref","unstructured":"F. Mordelet and J. Vert, A bagging SVM to learn from positive and unlabeled examples, Pattern Recognition Letters, vol. 37, pp. 201\u2013209, 2014.","DOI":"10.1016\/j.patrec.2013.06.010"},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"J. Muller, F. Ising, V. Mladenov, C. Mainka, S. Schinzel and J. Schwenk, Practical decryption exfiltration: Breaking PDF encryption, Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, pp. 15\u201329, 2019.","DOI":"10.1145\/3319535.3354214"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"C. Smutz and A. Stavrou, Malicious PDF detection using metadata and structural features, Proceedings of the Twenty-Eighth Annual Computer Security Applications Conference, pp. 239\u2013248, 2012.","DOI":"10.1145\/2420950.2420987"},{"key":"7_CR18","unstructured":"N. Srndic and P. Laskov, Detection of malicious PDF files based on hierarchical document structure, Proceedings of the Twentieth Annual Network and Distributed System Security Symposium, 2013."},{"key":"7_CR19","doi-asserted-by":"crossref","unstructured":"N. Srndic and P. Laskov, Hidost: A static machine-learning-based detector of malicious files, EURASIP Journal on Information Security, vol. 2016(1), article no. 45, 2016.","DOI":"10.1186\/s13635-016-0045-0"},{"key":"7_CR20","doi-asserted-by":"crossref","unstructured":"J. Torres and S. De Los Santos, Malicious PDF document detection using machine learning techniques, Proceedings of the Fourth International Conference on Information Systems Security and Privacy, pp. 337\u2013344, 2018.","DOI":"10.5220\/0006609503370344"},{"key":"7_CR21","doi-asserted-by":"crossref","unstructured":"Z. Tzermias, G. Sykiotakis, M. Polychronakis and E. Markatos, Combining static and dynamic analysis for the detection of malicious documents, Proceedings of the Fourth European Workshop on System Security, article no. 4, 2011.","DOI":"10.1145\/1972551.1972555"},{"key":"7_CR22","unstructured":"VirusShare, Home (www.virusshare.com), 2020."},{"key":"7_CR23","unstructured":"VirusTotal, GUI (www.virustotal.com\/gui), 2020."},{"key":"7_CR24","unstructured":"M. Xu and T. Kim, PlatPal: Detecting malicious documents with platform diversity, Proceedings of the Twenty-Sixth USENIX Security Symposium, pp. 271\u2013287, 2017."},{"key":"7_CR25","doi-asserted-by":"crossref","unstructured":"W. Xu, Y. Qi and D. Evans, Automatically evading classifiers: A case study on PDF malware classifiers, Proceedings of the Twenty-Third Annual Network and Distributed Systems Security Symposium, 2016.","DOI":"10.14722\/ndss.2016.23115"},{"key":"7_CR26","doi-asserted-by":"crossref","unstructured":"M. Yu, J. Jiang, G. Li, C. Lou, Y. Liu, C. Liu and W. Huang, Malicious document detection for business process management based on a multi-layer abstract model, Future Generation Computer Systems, vol. 99, pp. 517\u2013526, 2019.","DOI":"10.1016\/j.future.2019.04.012"},{"key":"7_CR27","unstructured":"J. Zhang, MLPdf: An effective machine learning based approach for PDF malware detection, presented at Black Hat USA, 2018."}],"container-title":["IFIP Advances in Information and Communication Technology","Advances in Digital Forensics XVII"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-88381-2_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T22:03:41Z","timestamp":1760393021000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-88381-2_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030883805","9783030883812"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-88381-2_7","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"15 October 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DigitalForensics","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Digital Forensics","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 February 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 February 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"digitalforensics2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ifip119.org\/Conferences\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}