【24h】

About the Robustness and Looseness of Yara Rules

机译:关于雅拉规则的鲁棒性和松散

获取原文

摘要

The tremendous and fast growth of malware circulating in the wild urges the community of malware analysts to rapidly and effectively share knowledge about the arising threats. Among the other solutions, Yara is establishing as a de facto standard for describing and exchanging Indicators of Compromise (IOCs). Unfortunately, the community of malware analysts did not agree on a set of guidelines for writing Yara rules: a plethora of very different styles for formalizing IOCs can be observed, indeed. Our thesis is that different styles of Yara rule writing could affect the quality of IOCs. With this paper we provide: (i) the definition of two dimensions of Yara rules quality, namely Robustness and Looseness; (ii) a taxonomy for describing the kinds of IOCs that can be formalized with the Yara grammar, and (iii) a suite of metrics for measuring the quality of an IOC. Finally, we carried out a study on 32,311 Yara rules for examining the different existing styles and to investigate the relationship between the writing styles and the quality of IOCs.
机译:在野外流通的恶意软件的巨大和快速增长促使恶意软件分析师社区迅速有效地分享有关引起的威胁的知识。在其他解决方案中,雅拉正作为描述和交换妥协指标(IOC)的事实标准。不幸的是,恶意软件分析师社区并不达成一套写作雅拉规则的指导方针:确实可以观察到正式化IOC的夸张非常不同的风格。我们的论文是,不同风格的雅拉规则写作可能会影响IOC的质量。用本文提供:(i)雅拉规则质量的两个维度的定义,即鲁棒性和松散; (ii)用于描述可以用雅拉语法形式化的IOC种类的分类法,以及(iii)一套测量IOC质量的指标套件。最后,我们对32,311张雅拉法规进行了研究,以研究不同现有风格,并调查写作风格与IOC质量之间的关系。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号