About the Robustness and Looseness of Yara Rules - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2020

About the Robustness and Looseness of Yara Rules

Gerardo Canfora
  • Fonction : Auteur
  • PersonId : 1100066
Mimmo Carapella
  • Fonction : Auteur
  • PersonId : 1100067
Andrea Del Vecchio
  • Fonction : Auteur
  • PersonId : 1100068
Laura Nardi
  • Fonction : Auteur
  • PersonId : 1100069
Antonio Pirozzi
  • Fonction : Auteur
  • PersonId : 1100070
Corrado Aaron Visaggio
  • Fonction : Auteur
  • PersonId : 998094

Résumé

The tremendous and fast growth of malware circulating in the wild urges the community of malware analysts to rapidly and effectively share knowledge about the arising threats. Among the other solutions, Yara is establishing as a de facto standard for describing and exchanging Indicators of Compromise (IOCs). Unfortunately, the community of malware analysts did not agree on a set of guidelines for writing Yara rules: a plethora of very different styles for formalizing IOCs can be observed, indeed. Our thesis is that different styles of Yara rule writing could affect the quality of IOCs. With this paper we provide: (i) the definition of two dimensions of Yara rules quality, namely Robustness and Looseness; (ii) a taxonomy for describing the kinds of IOCs that can be formalized with the Yara grammar, and (iii) a suite of metrics for measuring the quality of an IOC. Finally, we carried out a study on 32,311 Yara rules for examining the different existing styles and to investigate the relationship between the writing styles and the quality of IOCs.
Fichier principal
Vignette du fichier
497758_1_En_7_Chapter.pdf (580.7 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03239822 , version 1 (27-05-2021)

Licence

Paternité

Identifiants

Citer

Gerardo Canfora, Mimmo Carapella, Andrea Del Vecchio, Laura Nardi, Antonio Pirozzi, et al.. About the Robustness and Looseness of Yara Rules. 32th IFIP International Conference on Testing Software and Systems (ICTSS), Dec 2020, Naples, Italy. pp.104-120, ⟨10.1007/978-3-030-64881-7_7⟩. ⟨hal-03239822⟩
47 Consultations
117 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More