中国科大学位与研究生教育
课程名称: 教师:
当前位置:
 >> 
 >> 
Measuring and Modeling the Label Dynamics of Online Anti-Malware Engines
Measuring and Modeling the Label Dynamics of Online Anti-Malware Engines
教师介绍

本讲教师:Linhai Song
所属学科:理科
人  气:1327

课程介绍
报告摘要:VirusTotal provides malware labels from a large set of antimalware engines, and is heavily used by researchers for malware annotation and system evaluation. Since different engines often disagree with each other, researchers have used various methods to aggregate their labels. In this talk, I wil discuss our recent research project on categorizing, reasoning, and validating common labeling methods used by researchers. We first survey 115 academie papers that use VirusTotal, and identify common methodologies. Then we collect the daily snapshots of VirusTotal labels for more than 14,000 files (including a subset of manually verified ground-truth) from 65 VirusTotal engines over a year. Our analysis validates the benefits of threshold-based label aggregation in staillizing fles' labels, and also points out the impact of poorty-chosen thresholds. We show that hand-picked "trusted" engines do not always perform well, and certain groups of engines are strongly correlated and should not be treated independently. Finally, we empirically show certain engines fail to perform in-depth analysis on submitted fles and can easily produce false posives.Based on our findings. we offer suggestions for future usage of Virus Total for data annotation. This work was published in Usenix Security'2020. 报告人简介:Linhai Song is an Assistant Professor at the PennsyIvania State University. Linhai has published more than ten research papers on top-tier conferences, including ASPLOS, PLDI and USENIX Security Linhai won the MICRO' 2014 Best Paper Runner Up and the ACM SIGPLAN Research Highights Award in 2011. Linhai got his Ph.D degree from University of Wisconsin-Madison in 2015. His research interests include systems, programming languages and security.
致谢:本课件的制作和发布均为公益目的,免费提供给公众学习和研究。对于本课件制作传播过程中可能涉及的作品或作品部分内容的著作权人以及相关权利人谨致谢意!
课件总访问人次:29186176
中国科学技术大学研究生网络课堂试运行版,版权属于中国科学技术大学研究生院。
本网站所有内容属于中国科学技术大学,未经允许不得下载传播。
地址:安徽省合肥市金寨路96号;邮编:230026。TEL:+86-551-63602929;E-mail:wlkt@ustc.edu.cn。

扫一扫,手机版