Development of a Statistical Analyzer to Identify Malicious Code in Information Systems

Aung Kyaw Myo, Evgeni Mikhailovich Portnov, Alexey R. Fedorov · 2025

Currently, the search for malicious code in information systems is relevant. The analysis showed that existing static analyzers detect vulnerabilities in the code, but not malicious code, as a result of which it was decided to create a new static analyzer with zero false positives, which will not only search for malicious code, but also indicate its location. A formalized representation of the task of detecting malicious code based on static analysis using set theory based on the introduction of a function that matches each element with a maliciousness factor is proposed. A technique for detecting malicious code in the source code based on lexical, semantic and static analysis has been developed. An experimental study has shown that the accuracy of detecting malicious code has increased by three percent, and the F1 measure - by five percent, compared to the best similar tool, which indicates a more effective performance of the task of detecting malicious code by the developed algorithm compared to analogs.

Read the paper · More papers on PaperTik