{"id":"W3114105288","doi":"10.1109/isncc49221.2020.9297272","title":"P-Code Based Classification to Detect Malicious VBA Macro","year":2020,"lang":"en","type":"article","venue":"","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":10,"is_retracted":false,"has_abstract":true,"ca_institutions":"École de Technologie Supérieure","funders":"","keywords":"Malware; Computer science; Opcode; Macro; Code (set theory); Heuristics; Obfuscation; Artificial intelligence; Visual Basic for Applications; Machine learning; Preprocessor; Source code; Data mining; Computer security; Programming language; Operating system","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0005309881,0.001057612,0.0005711818,0.006155004,0.0006537458,0.001010592,0.0008546138,0.0009511748,0.001586341],"category_scores_gemma":[0.00327633,0.0001586373,0.0007288025,0.002608362,0.0004185694,0.001334512,0.0008172577,0.001137593,0.002656121],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008056213,"about_ca_system_score_gemma":0.001008804,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.008379887,"about_ca_topic_score_gemma":0.01022099,"domain_scores_codex":[0.999119,0.00005200829,0.00007865227,0.0002322609,0.000393765,0.0001244266],"domain_scores_gemma":[0.997421,0.000697085,0.000300183,0.0002846115,0.001134159,0.0001628848],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0007530175,0.0006780099,0.1259101,0.0005920696,0.0001489748,0.0009472572,0.0002309734,0.01768673,0.02508675,0.002575499,0.0730198,0.7523709],"study_design_scores_gemma":[0.00005014906,0.0003823353,0.06890691,0.0001530007,0.0001154711,0.002000355,0.0004117624,0.80957,0.06129734,0.005507181,0.0515126,0.00009291231],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.7597647,0.003340112,0.1527482,0.00122741,0.0006873936,0.001132659,0.03530997,0.02479596,0.02099356],"genre_scores_gemma":[0.7919789,0.0008798782,0.145866,0.0002371948,0.0001969686,0.000453869,0.04928465,0.0006106723,0.01049191],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.008379887,"threshold_uncertainty_score":0.01666218,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03830866726439872,"score_gpt":0.2844805363594726,"score_spread":0.2461718690950739,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}