Malicious PDF Detection Using Support Vector Machine
1 Department of Computer Science, University of Ilorin, Ilorin, Nigeria
* Corresponding author: balogun.gb@unilorin.edu.ng
* Corresponding author: balogun.gb@unilorin.edu.ng
Abstract
The aim of this study is to develop a system that can detect
and classify the Portable Document Format (PDF) as malware
or benign document based on its features, using the Support
Vector Machine (SVM) as an underlying model. Based on
feature extraction and the Support Vector Machine technique, a
method is proposed for efficiently detecting PDFs with harmful
payloads. It was proved in this study that by extracting a
wide range of feature sets, a robust PDF malware classifier can
be produced. By employing data sets with a total of 10,000
harmful and 10,000 benign documents, the classification rate
can reach up to 99 percent while retaining low false positive
rates of 0.2 percent or less for various classification parameters.
Keywords
Malware
Benign
JavaScript
Code
Support Vector Machine
How to Cite
Balogun, G. B., Adinoyi, P. F., Awotunde, J. B., Abdulraheem, M., & Oladipo, I. D. (2022). Malicious PDF Detection Using Support Vector Machine. Nigerian Journal of Mathematics and Applications, 32(1), 117-135. https://doi.org/10.67897/njma.2022.4rcm0i4v
G. B. Balogun, P. F. Adinoyi, J. B. Awotunde, M. Abdulraheem, and I. D. Oladipo, "Malicious PDF Detection Using Support Vector Machine," Nigerian Journal of Mathematics and Applications, vol. 32, no. 1, pp. 117-135, June 2022. doi: 10.67897/njma.2022.4rcm0i4v