{"id":"W4293192140","doi":"10.5220/0010908200003120","title":"Detecting Obfuscated Malware using Memory Feature Engineering","year":2022,"lang":"en","type":"article","venue":"","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":147,"is_retracted":false,"has_abstract":false,"ca_institutions":"University of New Brunswick","funders":"","keywords":"Computer science; Malware; Feature (linguistics); Feature engineering; Artificial intelligence; Obfuscation; Pattern recognition (psychology); Operating system; Computer security; Deep learning","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0002151928,0.0006637954,0.0003840425,0.001483347,0.0003253874,0.0007380343,0.0005037224,0.0004868265,0.001244357],"category_scores_gemma":[0.001895453,0.0002374994,0.000439029,0.0005487506,0.0003223554,0.001369493,0.0006035906,0.00051944,0.000479962],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0002450057,"about_ca_system_score_gemma":0.0003803451,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0005041187,"about_ca_topic_score_gemma":0.00115347,"domain_scores_codex":[0.9996386,0.0000297508,0.00001891571,0.00007504338,0.0001738584,0.00006381355],"domain_scores_gemma":[0.9987925,0.0003799931,0.0002981291,0.0002581737,0.0002422608,0.0000288729],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.00032682,0.0002906792,0.01918754,0.0002304896,0.00009098786,0.0005518816,0.0001798067,0.01398808,0.282872,0.004982584,0.002735237,0.6745639],"study_design_scores_gemma":[0.00002693281,0.0007182847,0.01120426,0.00007004946,0.0001615605,0.001866647,0.0001878836,0.4579793,0.5065705,0.01368532,0.007473083,0.00005615705],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.5682936,0.001261641,0.4153167,0.0003519693,0.0001607195,0.0001505249,0.0002998061,0.008416513,0.005748569],"genre_scores_gemma":[0.9157516,0.0002545084,0.08078412,0.00010791,0.00003436689,0.00003606067,0.0002280504,0.0001829269,0.002620439],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.001483347,"threshold_uncertainty_score":0.004162848,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01154745839125784,"score_gpt":0.2286258534574822,"score_spread":0.2170783950662244,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}