• Title/Summary/Keyword: YARA Rules

Search Result 1, Processing Time 0.014 seconds

The Study on YARA Rules and Detection Tool for HWP Document-Type Malware (HWP 문서형 악성코드 탐지를 위한 YARA규칙 및 탐지도구에 관한 연구)

  • Joongjin Kook;Heechan Won;Sungwoo Kim;Dohee Kim;Junghoon Lee
    • Journal of the Semiconductor & Display Technology
    • /
    • v.23 no.3
    • /
    • pp.108-114
    • /
    • 2024
  • This study details the development of YARA rules and a detection program specifically designed to identify malware in HWP documents, a common target in cyber-attacks within South Korea. By thoroughly analyzing the unique structural features of HWP files, we developed precise YARA rules that were subsequently integrated into a custom detection tool. The program was rigorously tested on a dataset of benign and malicious HWP documents, demonstrating high detection accuracy and a low false-positive rate. This research offers a robust and practical solution for enhancing cybersecurity in environments where HWP files are frequently used, contributing valuable tools for the targeted detection of document-based malware.

  • PDF