Rule Creation in a Knowledge-assisted Visual Analytics Prototype for Malware Analysis
نویسندگان
چکیده
The increasing number of malicious software (malware) requires domain experts to shift their analysis process towards more individualized approaches to acquire more information about unknown malware samples. KAMAS is a knowledgeassisted visual analytics prototype for behavioral malware analysis. It allows IT-security experts to categorize and store potentially harmful system call sequences (rules) in a knowledge database. To meet the increasing demand for individualization of analysis processes, analysts should be able to create individual rules. This paper is a visualization design study, which describes the design and implementation of a Rule Creation Area (RCA) into KAMAS and its evaluation by domain experts. It became clear that continuous integration of experts in interaction processes improves the knowledge generation mechanism of KAMAS. Additionally, the outcome of the evaluation revealed that there is a demand for adjustment and re-usage of already stored rules in the RCA.
منابع مشابه
Supporting Knowledge-assisted Rule Creation in a Behavior-based Malware Analysis Prototype
The ever increasing number of malicious software (malware) requires domain experts to shift their analysis process towards more individualized approaches to acquire more information about presently unknown malware samples. KAMAS is a knowledge-assisted visual analytics prototype for behavioral malware analysis, which allows IT-security experts to categorize and store potentially harmful system ...
متن کاملKnowledge-Assisted Rule Building for Malware Analysis 103, Recent Advances in Multimedia Processing, Organization and Visualization beyond Domains and Disciplines
Due to the increasing threat from malicious software (malware), the monitoring of vulnerable systems is becoming increasingly important, which includes the need to log and analyze activity ranging from networks, individual computers, to mobile devices. Currently available tools in behavior-based malware analysis do not meet all experts’ needs, such as selecting different rules, categorizing the...
متن کاملBiG2-KAMAS: Supporting Knowledge-Assisted Malware Analysis with Bi-Gram Based Valuation
Malicious software, short malware, refers to software programs that are designed to cause damage or to perform unwanted actions on the infected computer system. The behavior-based analysis of malware typically utilizes tools that produce lengthy traces of observed events, which have to be analyzed manually or by means of individual scripts. Due to the growing amount of data extracted from malwa...
متن کاملA knowledge-assisted visual malware analysis system: Design, validation, and reflection of KAMAS
IT-security experts engage in behavior-based malware analysis in order to learn about previously unknown samples of malicious software (malware) or malware families. For this, they need to find and categorize suspicious patterns from large collections of execution traces. Currently available systems do not meet the analysts’ needs which are described as: visual access suitable for complex data ...
متن کاملThe Role of Explicit Knowledge: A Conceptual Model of Knowledge-Assisted Visual Analytics Supplement Material to Formalize the Model
Figure 1: Conceptual Model of Knowledge-Assisted Visual Analytics. The model is divided into two spaces (machine and human) and describes knowledge generation, conversion, and exploitation within the Visual Analytics (VA) process, in terms of artifacts: explicit knowledge Kε , data D , specification S , image I and tacit knowledge Kτ ; and processes: analysis A , visualization V , externalizati...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2017