@article{ART002843637},
author={Hyeong Kyu Choi and Ah Reum Kang},
title={OLE File Analysis and Malware Detection using Machine Learning},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2022},
volume={27},
number={5},
pages={149-156},
doi={10.9708/jksci.2022.27.05.149}
TY - JOUR
AU - Hyeong Kyu Choi
AU - Ah Reum Kang
TI - OLE File Analysis and Malware Detection using Machine Learning
JO - Journal of The Korea Society of Computer and Information
PY - 2022
VL - 27
IS - 5
PB - The Korean Society Of Computer And Information
SP - 149
EP - 156
SN - 1598-849X
AB - Recently, there have been many reports of document-type malicious code injecting malicious code into Microsoft Office files. Document-type malicious code is often hidden by encoding the malicious code in the document. Therefore, document-type malware can easily bypass anti-virus programs. We found that malicious code was inserted into the Visual Basic for Applications (VBA) macro, a function supported by Microsoft Office. Malicious codes such as shellcodes that run external programs and URL-related codes that download files from external URLs were identified. We selected 354 keywords repeatedly appearing in malicious Microsoft Office files and defined the number of times each keyword appears in the body of the document as a feature. We performed machine learning with SVM, naïve Bayes, logistic regression, and random forest algorithms. As a result, each algorithm showed accuracies of 0.994, 0.659, 0.995, and 0.998, respectively.
KW - OLE;malware;Microsoft Office;shellcode;VBA macro;random forest
DO - 10.9708/jksci.2022.27.05.149
ER -
Hyeong Kyu Choi and Ah Reum Kang. (2022). OLE File Analysis and Malware Detection using Machine Learning. Journal of The Korea Society of Computer and Information, 27(5), 149-156.
Hyeong Kyu Choi and Ah Reum Kang. 2022, "OLE File Analysis and Malware Detection using Machine Learning", Journal of The Korea Society of Computer and Information, vol.27, no.5 pp.149-156. Available from: doi:10.9708/jksci.2022.27.05.149
Hyeong Kyu Choi, Ah Reum Kang "OLE File Analysis and Malware Detection using Machine Learning" Journal of The Korea Society of Computer and Information 27.5 pp.149-156 (2022) : 149.
Hyeong Kyu Choi, Ah Reum Kang. OLE File Analysis and Malware Detection using Machine Learning. 2022; 27(5), 149-156. Available from: doi:10.9708/jksci.2022.27.05.149
Hyeong Kyu Choi and Ah Reum Kang. "OLE File Analysis and Malware Detection using Machine Learning" Journal of The Korea Society of Computer and Information 27, no.5 (2022) : 149-156.doi: 10.9708/jksci.2022.27.05.149
Hyeong Kyu Choi; Ah Reum Kang. OLE File Analysis and Malware Detection using Machine Learning. Journal of The Korea Society of Computer and Information, 27(5), 149-156. doi: 10.9708/jksci.2022.27.05.149
Hyeong Kyu Choi; Ah Reum Kang. OLE File Analysis and Malware Detection using Machine Learning. Journal of The Korea Society of Computer and Information. 2022; 27(5) 149-156. doi: 10.9708/jksci.2022.27.05.149
Hyeong Kyu Choi, Ah Reum Kang. OLE File Analysis and Malware Detection using Machine Learning. 2022; 27(5), 149-156. Available from: doi:10.9708/jksci.2022.27.05.149
Hyeong Kyu Choi and Ah Reum Kang. "OLE File Analysis and Malware Detection using Machine Learning" Journal of The Korea Society of Computer and Information 27, no.5 (2022) : 149-156.doi: 10.9708/jksci.2022.27.05.149