arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Aray:用于YARA验证的良性制品的确定性优先合成

Aray: Deterministic-First Synthesis of Benign Artifacts for YARA Validation

Emanuel C. A. Valente, Lourenço A. P. Júnior, Leonardo Gonçalves Chahud, Júlio Cezar Estrella, Marcus Botacin

arXiv 2608.19387首次发表:更新:

AI 中文总结

Aray是确定性优先的YARA解释器和阳性测试用例合成器,可在416条公开规则上实现97.6%的匹配准确率,为YARA验证提供良性替代制品,解决恶意软件样本难以获取的问题。

AI 中文摘要

YARA规则易于分发,但用于展示阳性匹配的恶意软件样本却难以获取,这给存储、持续集成、灾难恢复演练以及可复现的扫描器验证带来了复杂问题。构建替代测试用例不仅需要嵌入字面量,还需满足YARA规则的各类条件,包括替代项、计数、偏移量、整数读取以及可执行容器约束,同时生成的文件不得重现恶意软件行为。阳性验证是存在性的,仅需规则匹配集中的一个文件级成员,而非重建原始样本。本文提出Aray,一种确定性优先的YARA解释器和阳性测试用例合成器。模型可提出建设性归一化或类型化提取回退方案,但不得涉及后端源或二进制结构。常规代码会验证归一化后的规则,推导字符串和整数见证值,并执行提取、路由、冲突检查布局以及ELF、PE或通用序列化。仅剩余的归一化语义会传递给有界模型判断器。我们在416条公开规则条目上评估了Aray,其中归一化在无模型辅助时接受182条,经模型归一化后接受234条;可构建性预检准入406条条目,所有准入的测试用例均匹配其上游原始规则,整体准确率达406/416(97.6%),可构建规则的准确率为406/406,仅存在10次预期的预检处置,无扫描器不匹配或构建失败,不可达端点确认实现过程中未调用模型。原始规则预言机会根据源规则验证生成的测试用例,证明其对所有可能文件的蕴含是独立的更强目标。最终运行前修复了2个锚定正则表达式故障,因此结果为修复后的系统结果,而非保留估计值。

英文摘要

A YARA rule is easy to distribute, but the malware sample used to demonstrate a positive match is not. This complicates storage, continuous integration, disaster-recovery exercises, and reproducible scanner validation. Constructing a replacement fixture requires more than embedding literals: YARA conditions can combine alternatives, counts, offsets, integer reads, and executable-container constraints, while the resulting file should not reproduce malware behavior. Positive validation is existential: it requires one file-level member of a rule's match set, not reconstruction of the originating sample. We present Aray, a deterministic-first YARA interpreter and positive-fixture synthesizer. Models may propose constructive normalizations or typed extraction fallbacks, but never backend source or binary structure. Conventional code validates normalized rules, derives string and integer witnesses, and performs extraction, routing, collision-checked layout, and ELF, PE, or generic serialization. Only residual normalization semantics reach a bounded model judge. We evaluated Aray over 416 public-rule entries. Normalization accepted 182 entries without model assistance and 234 after model normalization. Constructibility preflight admitted 406 entries, and every admitted fixture matched its upstream original rule. This yields 406/416 (97.6%) overall and 406/406 among constructible rules, with ten expected preflight dispositions and no scanner mismatches or construction failures. An unreachable endpoint confirmed zero model invocations during realization. The original-rule oracle validates generated fixtures against their source rules; proving implication for all possible files is a separate, stronger objective. Two anchored-regex failures were repaired before the final run, so these are post-fix systems results, not a held-out estimate.

Comments19 pages, 3 figures, 3 tables. The tool and this work were presented at Black Hat USA 2026 Arsenal. Code: https://github.com/c2dc/aray

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑