{"id":"W4293791248","doi":"10.48550/arxiv.2208.12836","title":"Living-off-the-Land Abuse Detection Using Natural Language Processing and Supervised Learning","year":2022,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":5,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Guelph","funders":"","keywords":"Computer science; Security token; Encoding (memory); Evasion (ethics); Semaphore; Computer virus; Machine learning; Software; Artificial intelligence; Natural language; Computer security; Programming language","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001393318,0.0009850763,0.0006119125,0.001582496,0.0005010919,0.001045246,0.001124649,0.0008019743,0.000618174],"category_scores_gemma":[0.0046873,0.0003008214,0.0008421242,0.0008194623,0.0009998183,0.001726076,0.0007465066,0.001489723,0.0004878504],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008871847,"about_ca_system_score_gemma":0.00125307,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003761874,"about_ca_topic_score_gemma":0.004959792,"domain_scores_codex":[0.9985951,0.0004844085,0.0001041423,0.0003764223,0.000343258,0.00009657368],"domain_scores_gemma":[0.9947705,0.003215701,0.0007144936,0.0004320904,0.0007764265,0.00009083108],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0003758197,0.001068155,0.01414949,0.0002457014,0.0001613814,0.0007074412,0.0004365203,0.221296,0.03086766,0.005875234,0.006426526,0.71839],"study_design_scores_gemma":[0.000006289496,0.00006128501,0.000858906,0.000009022752,0.0000109227,0.00007672991,0.00003841142,0.9864172,0.0090007,0.002995753,0.0005130519,0.00001178287],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1664059,0.000280136,0.8239112,0.0005628872,0.00007042608,0.0002756065,0.0003908318,0.006099432,0.002003653],"genre_scores_gemma":[0.6366754,0.000153889,0.3594212,0.0002113811,0.00006139288,0.0002257836,0.001036364,0.0001462195,0.002068468],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003761874,"threshold_uncertainty_score":0.007479966,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03287329196300334,"score_gpt":0.2029692709386579,"score_spread":0.1700959789756545,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}