Detecting Modern Maldocs: An Analytical Study of PDF Feature Importance Using KDD Cup 99 as the Process Framework
Open AccessCybersecurity researchers continually adapt their strategies to combat evolving threats. This praxis focuses on enhancing malicious document (maldoc) detection, particularly in the realm of PDF files, a common vector for cyberattacks. The absence of a standardized dataset for maldoc intrusion detection in PDFs necessitated innovative approaches. Leveraging the Knowledge Discovery in Databases (KDD) process employed to develop the famous KDD Cup 99 dataset, the same KDD process was adapted for PDF maldoc research. Critical to this endeavor was the identification and collection of real-world PDF files, representing both malicious and benign documents. This temporal aspect was crucial, recognizing that outdated files might not reflect modern maldoc attributes. The researcher introduces the iqMuT toolbelt, an amalgamation of PDF parsing tools, such as PDF(i)d, (q)pdf, (Mu)PDF, and Apache (T)ika. These tools were meticulously chosen based on their sustainability and compatibility, thus supporting a repeatable data pipeline. The research also involved feature engineering to develop modern attributes, specifically those that cannot be artificially produced. In conclusion, this research bridges the gap in maldoc intrusion detection for PDF files, presenting the iqMuT toolbelt as a promising solution. By adhering to the KDD process and integrating cutting-edge tools, this study advances our understanding of maldoc detection and offers valuable insights into improving cybersecurity in an ever-evolving threat landscape.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.