{"id":"W3107757457","doi":"10.1007/s40747-020-00233-5","title":"Embedded YARA rules: strengthening YARA rules utilising fuzzy hashing and fuzzy rules for malware analysis","year":2020,"lang":"en","type":"article","venue":"Complex & Intelligent Systems","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":31,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Computer science; Malware; Data mining; Fuzzy logic; Malware analysis; Ransomware; Hash function; Probabilistic logic; Machine learning; Artificial intelligence; Computer security","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.003247882,0.0005943603,0.0008462394,0.002475299,0.0007638661,0.002414817,0.001735679,0.001035036,0.001936616],"category_scores_gemma":[0.01446965,0.0004171656,0.0009312783,0.001236943,0.001288267,0.002546941,0.001166969,0.001173542,0.001425328],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0005468094,"about_ca_system_score_gemma":0.00109213,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002739291,"about_ca_topic_score_gemma":0.002951326,"domain_scores_codex":[0.9956166,0.0007284349,0.0005613799,0.0009105267,0.001989771,0.000193269],"domain_scores_gemma":[0.9822882,0.008037539,0.00174092,0.003121616,0.004561847,0.0002498217],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0009125896,0.0005103473,0.01806136,0.0006109921,0.0002985078,0.0008805073,0.001185685,0.07327923,0.07515286,0.0123572,0.003587878,0.8131629],"study_design_scores_gemma":[0.00006337818,0.0006846045,0.01192803,0.0002226631,0.0002119869,0.001734546,0.0005712251,0.8091712,0.1443923,0.01571787,0.01509858,0.0002037078],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.1833995,0.0006286803,0.8028091,0.0002896192,0.0001840594,0.0005306447,0.0005604149,0.005503129,0.006094872],"genre_scores_gemma":[0.5315196,0.0002054306,0.4643833,0.00016337,0.00005275783,0.0001517509,0.0005612367,0.0001340687,0.002828531],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.003247882,"threshold_uncertainty_score":0.01717669,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.07404297900241157,"score_gpt":0.307322885469279,"score_spread":0.2332799064668674,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}