{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T21:38:58Z","timestamp":1784237938751,"version":"3.55.0"},"reference-count":30,"publisher":"Springer Science and Business Media LLC","issue":"28","license":[{"start":{"date-parts":[[2022,5,17]],"date-time":"2022-05-17T00:00:00Z","timestamp":1652745600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,5,17]],"date-time":"2022-05-17T00:00:00Z","timestamp":1652745600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001778","name":"Deakin University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001778","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"published-print":{"date-parts":[[2022,11]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>In this paper, we perform an in-depth analysis of a large corpus of PDF maldocs to identify the key set of significantly important features and help in maldoc detection. Existing industry-based tools for the detection are inefficient and cannot prevent PDF maldocs because they are generic and depend primarily on a signature-based approach. Besides, several other methods developed by academics suffer heavily from reduced effectiveness. The feature-set using machine learning classifiers is prone to various known attacks, such as mimicry and parser confusion. Also, <jats:italic>we discover that increasingly more malicious files i) contain evasive and obfuscated JavaScript code, ii) include hidden contents (mostly outside the objects), iii) have a corrupted document structure, and iv) usually contain short JavaScript code blocks<\/jats:italic>. We utilise maldoc attacks\u2019 evolution over a decade to highlight the essential features (e.g., concept drifts) that impact detectors and classifiers.<\/jats:p>","DOI":"10.1007\/s11042-022-11960-x","type":"journal-article","created":{"date-parts":[[2022,5,17]],"date-time":"2022-05-17T03:47:50Z","timestamp":1652759270000},"page":"41103-41130","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Towards enhanced PDF maldocs detection with feature engineering: design challenges"],"prefix":"10.1007","volume":"81","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6359-8570","authenticated-orcid":false,"given":"Ahmed","family":"Falah","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiva Raj","family":"Pokhrel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lei","family":"Pan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anthony","family":"de Souza-Daw","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,5,17]]},"reference":[{"key":"11960_CR1","unstructured":"Adobe Systems Incorporated (2007) JavascriptTM for acrobat\u00ae; api reference, available online at https:\/\/www.adobe.com\/content\/dam\/acom\/en\/devnet\/acrobat\/pdfs\/js_api_reference.pdf. Accessed Sep 2019"},{"key":"11960_CR2","doi-asserted-by":"publisher","first-page":"138","DOI":"10.1016\/j.cose.2019.04.018","volume":"85","author":"D Carlin","year":"2019","unstructured":"Carlin D, O\u2019Kane P, Sezer S (2019) A cost analysis of machine learning using dynamic runtime opcodes for malware detection. Comput Secur 85:138\u2013155","journal-title":"Comput Secur"},{"key":"11960_CR3","doi-asserted-by":"crossref","unstructured":"Carmony C, Hu X, Yin H, Bhaskar AV, Zhang M (2016) Extract Me If You Can: Abusing PDF Parsers in Malware Detectors. In: NDSS, pp 1\u201315","DOI":"10.14722\/ndss.2016.23483"},{"key":"11960_CR4","doi-asserted-by":"crossref","unstructured":"Dang H, Huang Y, Chang E-C (2017) Evading Classifiers by Morphing in the Dark. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. Dallas, Texas, USA: ACM, pp 119\u2013133","DOI":"10.1145\/3133956.3133978"},{"key":"11960_CR5","doi-asserted-by":"crossref","unstructured":"Ding Y, Wu R, Zhang X (2019) Ontology-based knowledge representation for malware individuals and families, Computers & Security, p 101574","DOI":"10.1016\/j.cose.2019.101574"},{"key":"11960_CR6","unstructured":"Ehteshamifar S, Barresi A, Gross TR, Pradel M (2019) Easy to fool? testing the anti-evasion capabilities of pdf malware scanners. arXiv:1901.05674"},{"key":"11960_CR7","doi-asserted-by":"crossref","unstructured":"Endignoux G, Levillain O, Migeon J-Y (2016) Caradoc: A pragmatic approach to pdf parsing and validation. In: Security and Privacy Workshops (SPW). IEEE, pp 126\u2013139","DOI":"10.1109\/SPW.2016.39"},{"key":"11960_CR8","doi-asserted-by":"crossref","unstructured":"Falah A, Pan L, Abdelrazek M, Doss R (2018) Identifying drawbacks in malicious pdf detectors. In: International conference on future network systems and security. Springer, pp 128\u2013139","DOI":"10.1007\/978-3-319-94421-0_10"},{"key":"11960_CR9","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1016\/j.future.2020.09.015","volume":"115","author":"A Falah","year":"2021","unstructured":"Falah A, Pan L, Huda S, Pokhrel SR, Anwar A (2021) Improving malicious pdf classifier with feature engineering: a data-driven approach. Futur Gener Comput Syst 115:314\u2013326","journal-title":"Futur Gener Comput Syst"},{"key":"11960_CR10","unstructured":"Hinton GE, Roweis ST (2003) Stochastic neighbor embedding. In: Advances in neural information processing systems, pp 857\u2013864"},{"key":"11960_CR11","unstructured":"Jordan A, Gauthier F, Hassanshahi B, Zhao D (2018) Safe-pdf: Robust detection of javascript pdf malware using abstract interpretation. arXiv:1810.12490"},{"key":"11960_CR12","doi-asserted-by":"crossref","unstructured":"Li M, Liu Y, Yu M, Li G, Wang Y, Liu C (2017) Fepdf: A robust feature extractor for malicious pdf detection. In: 2017 IEEE Trustcom\/BigDataSE\/ICESS, pp 218\u2013224","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.240"},{"key":"11960_CR13","doi-asserted-by":"crossref","unstructured":"Liu D, Wang H, Stavrou A (2014) Detecting malicious javascript in pdf through document instrumentation. In: Dependable Systems and Networks (DSN), 2014 44th Annual IEEE\/IFIP International conference on. IEEE, pp 100\u2013111","DOI":"10.1109\/DSN.2014.92"},{"key":"11960_CR14","unstructured":"Maiorca D, Ariu D, Corona I, Giacinto G (2015) A structural and content-based approach for a precise and robust detection of malicious pdf files. In: Information systems security and privacy (ICISSP), 2015 International conference on. IEEE, pp 27\u201336"},{"key":"11960_CR15","doi-asserted-by":"crossref","unstructured":"Maiorca D, Corona I, Giacinto G (2013) Looking at the bag is not enough to find the bomb: an evasion of structural methods for malicious pdf files detection. In: Proceedings of the 8th ACM SIGSAC Symposium on Information, Computer and Communications Security. ACM, pp 119\u2013130","DOI":"10.1145\/2484313.2484327"},{"key":"11960_CR16","unstructured":"Metasploit (2013) Cool pdf image stream - remote buffer overflow, available online at https:\/\/www.exploit-db.com\/exploits\/24876. Accessed Sep 2019"},{"key":"11960_CR17","doi-asserted-by":"crossref","unstructured":"Nath HV, Mehtre BM (2015) Ensemble learning for detection of malicious content embedded in pdf documents. In: 2015 IEEE International conference on signal processing, informatics, communication and energy systems (SPICES), pp 1\u20135","DOI":"10.1109\/SPICES.2015.7091371"},{"key":"11960_CR18","doi-asserted-by":"publisher","first-page":"246","DOI":"10.1016\/j.cose.2014.10.014","volume":"48","author":"N Nissim","year":"2015","unstructured":"Nissim N, Cohen A, Glezer C, Elovici Y (2015) Detection of malicious pdf files and directions for enhancements: a state-of-the art survey. Comput Secur 48:246\u2013266","journal-title":"Comput Secur"},{"issue":"1","key":"11960_CR19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13388-016-0026-3","volume":"5","author":"N Nissim","year":"2016","unstructured":"Nissim N, Cohen A, Moskovitch R, Shabtai A, Edri M, BarAd O, Elovici Y (2016) Keeping pace with the creation of new malicious pdf files using an active-learning based detection framework. Secur Inf 5(1):1","journal-title":"Secur Inf"},{"key":"11960_CR20","doi-asserted-by":"crossref","unstructured":"Park J, Kim H (2017) k-depth mimicry attack to secretly embed shellcode into pdf files. In: International conference on information science and applications. Springer, pp 388\u2013395","DOI":"10.1007\/978-981-10-4154-9_45"},{"key":"11960_CR21","unstructured":"Pontiroli SM, Martinez FR (2015) The tao of.net and powershell malware analysis. In: Virus bulletin conference, pp 1\u201326"},{"key":"11960_CR22","doi-asserted-by":"crossref","unstructured":"Scofield D, Miles C, Kuhn S (2017) Fast model learning for the detection of malicious digital documents. In: Proceedings of the 7th Software Security, Protection, and Reverse Engineering \/ Software Security and Protection Workshop, ser. SSPREW-7. New York, NY, USA: ACM, pp 3:1\u20133:8","DOI":"10.1145\/3151137.3151142"},{"issue":"3","key":"11960_CR23","first-page":"134","volume":"29","author":"P Singh","year":"2020","unstructured":"Singh P, Tapaswi S, Gupta S (2020) Malware detection in PDF and office documents: a survey. Inf Secur J: A Glob Perspect 29(3):134\u2013153","journal-title":"Inf Secur J: A Glob Perspect"},{"key":"11960_CR24","doi-asserted-by":"crossref","unstructured":"Smutz C, Stavrou A (2012) Malicious PDF detection using metadata and structural features. In: Proceedings of the 28th annual computer security applications conference. Accessed Aug 2019. ACM, pp 239\u2013248","DOI":"10.1145\/2420950.2420987"},{"key":"11960_CR25","doi-asserted-by":"crossref","unstructured":"Smutz C, Stavrou A (2016) When a tree falls: using diversity in ensemble classifiers to identify evasion in Malware detectors. In: NDSS, pp 1\u201315","DOI":"10.14722\/ndss.2016.23078"},{"key":"11960_CR26","doi-asserted-by":"crossref","unstructured":"\u0160rndi\u0107 N, Laskov P (2014) Practical evasion of a learning-based classifier: a case study. In: Security and Privacy (SP), 2014 IEEE Symposium on. Accessed Aug 2019. IEEE, pp 197\u2013211","DOI":"10.1109\/SP.2014.20"},{"issue":"1","key":"11960_CR27","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1186\/s13635-016-0045-0","volume":"2016","author":"N \u0160rndi\u0107","year":"2016","unstructured":"\u0160rndi\u0107 N, Laskov P (2016) Hidost: a static machine-learning-based detector of malicious files. EURASIP J Inf Secur 2016(1):22","journal-title":"EURASIP J Inf Secur"},{"key":"11960_CR28","doi-asserted-by":"publisher","first-page":"S75","DOI":"10.1016\/j.diin.2017.01.009","volume":"20","author":"K W\u00fcst","year":"2017","unstructured":"W\u00fcst K, Tsankov P, Radomirovi\u0107 S, Dashti MT (2017) Force open: Lightweight black box file repair. Digit Investig 20:S75\u2013S82","journal-title":"Digit Investig"},{"key":"11960_CR29","unstructured":"Xu M, Kim T (2017) PlatPal: Detecting Malicious Documents with Platform Diversity. In: USENIX Security Symposium, pp 271\u2013287"},{"key":"11960_CR30","unstructured":"Xu W, Qi Y, Evans D (2016) Automatically evading classifiers. In: NDSS, pp 21\u201324"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-022-11960-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-022-11960-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-022-11960-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,25]],"date-time":"2022-10-25T10:00:36Z","timestamp":1666692036000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-022-11960-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,17]]},"references-count":30,"journal-issue":{"issue":"28","published-print":{"date-parts":[[2022,11]]}},"alternative-id":["11960"],"URL":"https:\/\/doi.org\/10.1007\/s11042-022-11960-x","relation":{},"ISSN":["1380-7501","1573-7721"],"issn-type":[{"value":"1380-7501","type":"print"},{"value":"1573-7721","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,5,17]]},"assertion":[{"value":"18 April 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 March 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 January 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 May 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}