Return
Optimizing symbolic execution for malware behavior classification
DOI:10.1016/j.cose.2020.101775.png)
Abstract
En 中文
Increasingly software correctness, reliability, and security is being analyzed using tools that combine various formal and heuristic approaches. Often such analysis becomes expensive in terms of time and at the cost of high quality results. In this experience report we explore the tuning and optimization of the tools underlying binary malware detection and classification. We identify heuristics and SMT solver tactics for the effective symbolic execution of binary files. We combine these with effective heuristics for the construction of behavioral signatures of programs that can be used for a supervised learning multi-class malware classifier. Further, a set of experiments following the full-factorial design allowed us to identify the correlations between heuristics and the overall performance of the classifier. (C) 2020 Elsevier Ltd. All rights reserved.
Keywords:
Malware classification
Empirical studies
SMT solving
Behavior graphs
Symbolic execution
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
C
IF:
5.4
Papers:
4.6K
Citations:
1.4W
Organization
Cited Papers
A set of robust fluorescent peptide probes for quantification of Cu(ii) binding affinities in the micromolar to femtomolar range
Metallomics
IF0

