Approach using Transforming Structural Data into Image for Detection of Malicious MS-DOC Files based on Deep Learning Models
Shaojie Yang, Wenbo Chen, Shanxi Li, Qingxiang Xu · 2019
Malicious MS-DOC file has a long history in cybersecurity and has rapid growth with tremendous appearance of advanced persistent threat (APT) attacks. Due to its obfuscation and complexities, regular detection methods are not ideal, and the specific detection methods are limited, either. This paper presents a new approach for malware detection of MS-DOC files. Inspired by analysis of MS-DOC files and tremendous success made by convolutional neural network (CNN) in the field of feature identification, especially image identification, a new approach including data extraction and conversion is designed to identify MS-DOC malicious files and benign files. Based on three CNN models, experiment results show that the accuracy rate of detection for test dataset reaches 94.09%, and in simulated zero-day malware detection experiment, the average accuracy rate reaches 94.70%. The approach proves the feasibility of MS-DOC malicious file detection based on convolutional neural network and proposes a new idea to detect zero-day MS-DOC malware.