返回
Optimizing symbolic execution for malware behavior classification
DOI:10.1016/j.cose.2020.101775.png)
摘要
En 中文
Increasingly software correctness, reliability, and security is being analyzed using tools that combine various formal and heuristic approaches. Often such analysis becomes expensive in terms of time and at the cost of high quality results. In this experience report we explore the tuning and optimization of the tools underlying binary malware detection and classification. We identify heuristics and SMT solver tactics for the effective symbolic execution of binary files. We combine these with effective heuristics for the construction of behavioral signatures of programs that can be used for a supervised learning multi-class malware classifier. Further, a set of experiments following the full-factorial design allowed us to identify the correlations between heuristics and the overall performance of the classifier. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Malware classification
Empirical studies
SMT solving
Behavior graphs
Symbolic execution
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
A malware detection method based on family behavior graph一种基于家族行为图的恶意软件检测方法
COMPUTERS & SECURITY
IF5.4
A set of robust fluorescent peptide probes for quantification of Cu(ii) binding affinities in the micromolar to femtomolar range
Metallomics
IF0
Guidelines for conducting and reporting case study research in software engineering在软件工程中进行和报告案例研究的指南

