首页> 外文会议>IEEE International Conference on Intelligent Computer Communication and Processing >Semi-automated verdicts assignment for potentially malicious programs
【24h】

Semi-automated verdicts assignment for potentially malicious programs

机译:半自动判决潜在恶意计划的分配

获取原文

摘要

Deciding if a given program is malicious or not is a recurring problem in anti-malware research, giving the fact that it is generally undecidable. Although field experts are able to perform correct classifications, the amount of both clean and malicious samples that appear every day is too high for relying only on manual analysis. In practice, the files collections are clustered and intensive analysis is performed only on a couple of representatives for each cluster. Some insights about each file can also be provided by automated analysis tools but they are less reliable than human experts. Based on the assumption that similar programs are likely to share the same verdict, we propose an algorithm for verdicts inference that is able to auto-correct wrong verdicts or request further manual analysis if auto-correction is not possible. The algorithm considers all the available sources of information together with their reliability and assigns verdicts to all the samples in the cluster. The system was tested on a collection of more than 200000 clusters built using the single linkage approach on a collection of over 20 million samples.
机译:决定如果给定的程序是恶意的,则是反恶意软件研究中的重复问题,给出了它通常不可判定的事实。虽然现场专家能够进行正确的分类,但每天出现的清洁和恶意样本的数量太高,只依赖于手动分析。在实践中,文件集群是集群的,并且密集分析仅在每个群集的几个代表上执行。关于每个文件的一些见解也可以通过自动分析工具提供,但它们比人类专家更可靠。基于类似程序可能分享相同判决的假设,我们提出了一种判断判决推理,可以自动纠正错误的验证或者如果不可能进行自动校正,则可以进一步进行手动分析。该算法将所有可用的信息源与其可靠性一起,并将符号分配给群集中的所有样本。在使用超过2000万个样本的集合上建造了超过200000年集群的集合中测试了该系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号