Loading...
Please wait, while we are loading the content...
Similar Documents
Portable Document Format (PDF) Security Analysis and Malware Threats
| Content Provider | Semantic Scholar |
|---|---|
| Author | Blonce, Alexandre Frayssignes, Laurent |
| Copyright Year | 2008 |
| Abstract | Alexandre Blonce and Laurent Frayssignes are from the French Navy as IT-Security Officers and stayed at the Virology and Cryptology Laboratory in Rennes for this study. Abstract Adobe Portable Document Format has become the most widespread and used document description format throughout the world. It is also a true programming language of its own, strongly dedicated to document creation and manipulation which has accumulated a lot of powerful programming features from version to version. Until now, no real, exploratory security analysis of the PDF and of its programming power with respect to malware attacks has been conducted. Only a very few cases of attacks are known, which exploit vulnerabilities in the management of external programming languages (Javacript, VBS). This paper presents an in-depth security analysis of the PDF programming features and capabilities, independently from any vulnerability. The aim is to exhaustively explore and evaluate the risk attached to PDF language-based malware which could successfully subvert some of PDF primitives in order to conduct malware based attacks. Along with a dedicated PDF document analysis and manipulation tool we have designed, this paper presents two proof-of-concepts on an algorithmic point of view, which clearly demonstrate the existence of such a risk. We also suggest some security measures at the users'level to reduce this risk. |
| File Format | PDF HTM / HTML |
| Alternate Webpage(s) | http://www.blackhat.com/presentations/bh-europe-08/Filiol/Presentation/bh-eu-08-filiol.pdf |
| Alternate Webpage(s) | https://www.blackhat.com/presentations/bh-europe-08/Filiol/Presentation/bh-eu-08-filiol.pdf |
| Language | English |
| Access Restriction | Open |
| Content Type | Text |
| Resource Type | Article |