EGAMA-RC:用于鲁棒且可解释的内存取证分类的风险校准、证据门控自适应恶意软件分析
EGAMA-RC: Risk-Calibrated Evidence-Gated Adaptive Malware Analysis for Robust and Interpretable Memory-Forensic Triage
- School of Information Technology, University of Cincinnati(辛辛那提大学信息技术学院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
EGAMA-RC是用于内存取证分类的风险校准证据门控框架,结合多维度评估与路由,在三个恶意软件数据集上实现高接受准确率与低误接受率,为可靠恶意软件分析提供方案。
AI中文摘要:
机器学习恶意软件检测器通常在干净数据上实现高精度,但实际分类还需要关于不确定性、新颖性、鲁棒性、可解释性、延迟和审查成本的证据。本文提出EGAMA-RC,这是一种用于内存取证恶意软件分类的风险校准、证据门控框架,基于SHAP引导的特征优化,结合特定数据集优化、模型池评估、对抗性和开放家族测试、新颖性评分、解释条件证据以及运行时感知路由。低风险样本被自动接受,而不确定、高风险或潜在新颖的案例被路由至审查、升级或新颖性感知处理。在三个恶意软件数据集和冻结多种子协议下,所选混合门接受93.12%的池样本,接受准确率为99.86%,误接受率为0.136%。新颖性校准减少过度严格的审查行为,同时保持低不安全接受率。XGBoost提供轻量级快速路径推理,每个样本的p50/p95延迟为0.0054/0.0059毫秒。结果表明,可靠的恶意软件分析需要风险校准路由、新颖性感知和受控分析师审查,而非仅分类准确率。
英文摘要:
Machine-learning malware detectors often achieve high clean-data accuracy, but operational triage also requires evidence about uncertainty, novelty, robustness, interpretability, latency, and review cost. This paper presents EGAMA-RC, a risk-calibrated evidence-gated framework for memory-forensic malware triage. Building on SHAP-guided feature refinement, EGAMA-RC combines dataset-specific refinement, model-pool evaluation, adversarial and open-family testing, novelty scoring, explanation-conditioned evidence, and runtime-aware routing. Low-risk samples are accepted automatically, while uncertain, high-risk, or potentially novel cases are routed to review, escalation, or novelty-aware handling. Across three malware datasets and a frozen multi-seed protocol, the selected hybrid gate accepts 93.12% of pooled samples with 99.86% accepted accuracy and a 0.136% false-accept rate. Novelty calibration reduces over-restrictive review behavior while preserving a low unsafe-accept profile. XGBoost provides lightweight fast-path inference with p50/p95 latency of 0.0054/0.0059 ms per sample. The results show that dependable malware analysis requires risk-calibrated routing, novelty awareness, and controlled analyst review, not classification accuracy alone.