31 ms·
The paper itself is behind a paywall, or I would have read it to get a better understanding. The article specifies that "Using this technique, researchers clai
by createdapril24 5y ago
The paper itself is behind a paywall, or I would have read it to get a better understanding.
The article specifies that "Using this technique, researchers claims they could record 100,000 measurement traces from IoT devices infected by genuine malware samples, and predicted three generic and one benign malware class with an accuracy as high as 99.82%"
I'm very skeptical of the material practicality of such a system. I am not sure whether they are correctly measuring the accuracy here (or if they are ignored precision and focused entirely on recall). It is hard to tell on the article content alone. But furthermore you would need to run this routinely to catch malware, which means at its very best it's wrong 1 out of every 500 attempts. How long does 100000 traces take? Is it wrong every 500 milliseconds? 500 seconds? To be useful it would have to be wrong every ~500 days, or at least hours.
Based on the title of the paper, I think the technique is specifically looking for certain kinds of machine code obfuscation, and classifying which was used. If this is the case, the application would NOT be to scan for malware but to use such a system after malware is confirmed as an aide to a forensic analyst attempting to understand the malware better. But if that's the case, the article's central claims around the technique "could help companies thwart these threats without needing any software" would appear to be at best wrong if not outright misleading.
Anyone have a link to the paper without a paywall?
- akarmanz 5y ago