Rule Creation in a Knowledge-assisted Visual Analytics Prototype for Malware Analysis

نویسندگان

  • Johannes Schick
  • Markus Wagner
  • Niklas Thür
  • Christina Niederer
  • Gernot Rottermanner
  • Paul Tavolato
  • Wolfgang Aigner
چکیده

The increasing number of malicious software (malware) requires domain experts to shift their analysis process towards more individualized approaches to acquire more information about unknown malware samples. KAMAS is a knowledgeassisted visual analytics prototype for behavioral malware analysis. It allows IT-security experts to categorize and store potentially harmful system call sequences (rules) in a knowledge database. To meet the increasing demand for individualization of analysis processes, analysts should be able to create individual rules. This paper is a visualization design study, which describes the design and implementation of a Rule Creation Area (RCA) into KAMAS and its evaluation by domain experts. It became clear that continuous integration of experts in interaction processes improves the knowledge generation mechanism of KAMAS. Additionally, the outcome of the evaluation revealed that there is a demand for adjustment and re-usage of already stored rules in the RCA.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Supporting Knowledge-assisted Rule Creation in a Behavior-based Malware Analysis Prototype

The ever increasing number of malicious software (malware) requires domain experts to shift their analysis process towards more individualized approaches to acquire more information about presently unknown malware samples. KAMAS is a knowledge-assisted visual analytics prototype for behavioral malware analysis, which allows IT-security experts to categorize and store potentially harmful system ...

متن کامل

Knowledge-Assisted Rule Building for Malware Analysis 103, Recent Advances in Multimedia Processing, Organization and Visualization beyond Domains and Disciplines

Due to the increasing threat from malicious software (malware), the monitoring of vulnerable systems is becoming increasingly important, which includes the need to log and analyze activity ranging from networks, individual computers, to mobile devices. Currently available tools in behavior-based malware analysis do not meet all experts’ needs, such as selecting different rules, categorizing the...

متن کامل

BiG2-KAMAS: Supporting Knowledge-Assisted Malware Analysis with Bi-Gram Based Valuation

Malicious software, short malware, refers to software programs that are designed to cause damage or to perform unwanted actions on the infected computer system. The behavior-based analysis of malware typically utilizes tools that produce lengthy traces of observed events, which have to be analyzed manually or by means of individual scripts. Due to the growing amount of data extracted from malwa...

متن کامل

A knowledge-assisted visual malware analysis system: Design, validation, and reflection of KAMAS

IT-security experts engage in behavior-based malware analysis in order to learn about previously unknown samples of malicious software (malware) or malware families. For this, they need to find and categorize suspicious patterns from large collections of execution traces. Currently available systems do not meet the analysts’ needs which are described as: visual access suitable for complex data ...

متن کامل

The Role of Explicit Knowledge: A Conceptual Model of Knowledge-Assisted Visual Analytics Supplement Material to Formalize the Model

Figure 1: Conceptual Model of Knowledge-Assisted Visual Analytics. The model is divided into two spaces (machine and human) and describes knowledge generation, conversion, and exploitation within the Visual Analytics (VA) process, in terms of artifacts: explicit knowledge Kε , data D , specification S , image I and tacit knowledge Kτ ; and processes: analysis A , visualization V , externalizati...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017