Automatic YARA Rule Generation
Myra Khalid, Maliha Ismail, Mureed Hussain, Muhammad Hanif Durad · 2020
Since 2010, the number of new malware released daily have become so high, that manual analysis is not an option anymore. The purpose of this work is to focus on the increased modern cyber-attacks and malware campaigns. This work devises a framework that automates the process of generating high quality, effective and efficient malware signatures in considerably less amount of time and effort. It also facilitates in the tedious task of malware analysis. The proposed framework presents a generic approach to automatic YARA rule-based signature generation. This approach is based upon cherry-picking the most promising core ideas of the related work. The testing of the prototype shows that it is capable of detecting samples with an average precision of 0.95.