An ontology of suspicious software behavior

Andre Ricardo Abed Gregio, Rodrigo Bonacin, Antonio Carlos de Marchi, Olga Fernanda Nabuco, Paulo Lício de Geus · Applied Ontology · 2016

Malicious programs have been the main actors in complex, sophisticated attacks against nations, governments, diplomatic agencies, private institutions and people. Knowledge about malicious program behavior forms the basis for constructing more secure information systems. In this article, we introdu ce MBO, a Malicious Behavior Ontology that represents complex behaviors of suspicious executions, and through inference rules calculates their associated threat level for analytical proposals. We evaluate MBO using over two thousand unique known malware and 385 unique known benign software. Results highlight the representativeness of the MBO for expressing typical malicious activities.

Read the paper · More papers on PaperTik