Detail výsledku

GenRex: Leveraging Regular Expressions for Dynamic Malware Detection

REGÉCIOVÁ, D.; KOLÁŘ, D. GenRex: Leveraging Regular Expressions for Dynamic Malware Detection. IEEE Xplore. Exeter: Institute of Electrical and Electronics Engineers, 2023. p. 857-864. ISBN: 979-8-3503-8199-3.
Typ
článek ve sborníku konference
Jazyk
anglicky
Autoři
Abstrakt

GenRex is a unique tool for detecting similarities in artifacts (extracted data) from executable files and for generating regular expressions from them. It implements an advanced algorithm to create regular expressions, improves state-of-the-art algorithms, and includes domain-specific optimizations and pattern detections for optimal results.

Generated regular expressions can be used for malware detections, for example, with YARA or any other pattern-matching tool. In this paper, we present the benefits of using this tool, the key features of GenRex that other existing solutions are missing, the algorithm for the automatic generation of YARA rules, and the benefits of using behavioral data for malware detection in general. We also tested GenRex on publicly available behavioral reports and achieved a high True Positive Rate of 92.34% and a low False Positive Rate of 0.01%.

Klíčová slova

Malware detection, dynamic analysis, pattern generation algorithm, regular expressions, rules generation algorithm, YARA, GenRex

URL
Rok
2023
Strany
857–864
Sborník
IEEE Xplore
Konference
22nd IEEE International Conference on Trust, Security and Privacy in Computing and Communications
ISBN
979-8-3503-8199-3
Vydavatel
Institute of Electrical and Electronics Engineers
Místo
Exeter
DOI
BibTeX
@inproceedings{BUT185111,
  author="Dominika {Regéciová} and Dušan {Kolář}",
  title="GenRex: Leveraging Regular Expressions for Dynamic Malware Detection",
  booktitle="IEEE Xplore",
  year="2023",
  pages="857--864",
  publisher="Institute of Electrical and Electronics Engineers",
  address="Exeter",
  doi="10.1109/TrustCom60117.2023.00123",
  isbn="979-8-3503-8199-3",
  url="https://ieeexplore.ieee.org/document/10538538"
}
Projekty
Chytré informační technologie pro odolnou společnost, VUT, Vnitřní projekty VUT, FIT-S-23-8209, zahájení: 2023-03-01, ukončení: 2026-02-28, řešení
Výzkumné skupiny
Pracoviště
Nahoru