{"id":"W3008617927","doi":"10.1109/ssci44817.2019.9002773","title":"Augmented YARA Rules Fused With Fuzzy Hashing in Ransomware Triaging","year":2019,"lang":"en","type":"article","venue":"","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":18,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Ransomware; Malware; Computer science; Hash function; Data mining; Malware analysis; Fuzzy logic; Artificial intelligence; Computer security","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001424518,0.0007973816,0.001158981,0.001336112,0.00059659,0.001582617,0.001043852,0.0009514473,0.001355126],"category_scores_gemma":[0.005045306,0.000351864,0.000896422,0.0007150764,0.000729955,0.001471841,0.0007639112,0.0008162067,0.0009871348],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0004108074,"about_ca_system_score_gemma":0.0006806186,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.00283982,"about_ca_topic_score_gemma":0.002268819,"domain_scores_codex":[0.9980211,0.0002666613,0.0002516966,0.0004218576,0.0008637419,0.0001748866],"domain_scores_gemma":[0.997234,0.0008258735,0.000487174,0.0004468853,0.0009233445,0.0000827086],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0008923379,0.0002491665,0.008925132,0.0003115603,0.0002166876,0.0008285226,0.0005464863,0.1626991,0.07201963,0.007541414,0.002121902,0.743648],"study_design_scores_gemma":[0.00002587561,0.0004544702,0.004134572,0.00006567957,0.0001281415,0.001120925,0.0002046349,0.9214089,0.06392623,0.003961254,0.004468674,0.0001007647],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1113483,0.001034566,0.8816925,0.0001359308,0.0001948982,0.0001725083,0.0001302801,0.001751827,0.003539251],"genre_scores_gemma":[0.7774702,0.0004455695,0.2183169,0.0001304644,0.00007105025,0.0001020959,0.0002415111,0.00006844145,0.003153794],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.00283982,"threshold_uncertainty_score":0.007533669,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.006762589529553787,"score_gpt":0.2236066504061207,"score_spread":0.2168440608765669,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}