GenRex: Leveraging Regular Expressions for Dynamic Malware Detection
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26230%2F23%3APU149338" target="_blank" >RIV/00216305:26230/23:PU149338 - isvavai.cz</a>
Result on the web
<a href="https://ieeexplore.ieee.org/document/10538538" target="_blank" >https://ieeexplore.ieee.org/document/10538538</a>
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
GenRex: Leveraging Regular Expressions for Dynamic Malware Detection
Original language description
GenRex is a unique tool for detecting similarities in artifacts (extracted data) from executable files and for generating regular expressions from them. It implements an advanced algorithm to create regular expressions, improves state-of-the-art algorithms, and includes domain-specific optimizations and pattern detections for optimal results. Generated regular expressions can be used for malware detections, for example, with YARA or any other pattern-matching tool. In this paper, we present the benefits of using this tool, the key features of GenRex that other existing solutions are missing, the algorithm for the automatic generation of YARA rules, and the benefits of using behavioral data for malware detection in general. We also tested GenRex on publicly available behavioral reports and achieved a high True Positive Rate of 92.34% and a low False Positive Rate of 0.01%.
Czech name
—
Czech description
—
Classification
Type
O - Miscellaneous
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2023
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů