arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

表征与编码恶意软件复杂性

Characterizing and Codifying Malware Sophistication

Angelo Porcella, Zachary Wadhams, Clemente Izurieta, Jonathan Crussell, Ann Marie Reinhold

arXiv 2610.00098首次发表:更新:

发表机构

Montana State University; Sandia National Laboratories(蒙大拿州立大学; 桑迪亚国家实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文系统化现有静态二进制分析方法,基于ISO/IEC 25010质量标准定义恶意软件复杂性,为源代码缺失时评估其威胁潜力奠定基础。

AI 中文摘要

“复杂”一词被广泛用于描述恶意软件,但在学术文献中缺乏一致的定义。虽然现有的软件质量和复杂性度量标准能对恶意软件结构提供一定洞察,但它们未能捕捉到促成现实世界威胁潜力的更广泛的对抗性和操作性特征。本文对使用静态二进制分析评估恶意软件质量的现有方法进行了系统化梳理。我们通过质量聚焦的视角来定义恶意软件复杂性,即重新诠释ISO/IEC 25010软件质量标准中的选定特性,包括可靠性、可维护性、灵活性和安全性,并评估其对恶意软件二进制的适用性。我们识别出哪些特性既与恶意软件相关,又可通过静态分析进行度量,这为未来在源代码不可用或动态执行不可行时,一致评估恶意软件复杂性的框架奠定了基础。

英文摘要

'Sophisticated' is widely used to describe malware, yet it lacks a consistent definition within academic literature. While existing software quality and complexity metrics offer some insight into malware structure, they do not capture the broader adversarial and operational traits that contribute to real-world threat potential. This paper presents a systematization of existing approaches for assessing malware quality using static binary analysis. We define malware sophistication through a quality-focused lens by reinterpreting select characteristics from the ISO/IEC 25010 software quality standard, including reliability, maintainability, flexibility, and security, and evaluating their applicability to malware binaries. We identify which characteristics are both relevant to malware and measurable through static analysis, forming the basis for future frameworks that consistently assess malware sophistication when source code is unavailable or dynamic execution is infeasible.

Comments7 pages, 2 tables, published at 2026 Intermountain Engineering, Technology and Computing (IETC)

Journal ref2026 Intermountain Engineering, Technology and Computing (IETC), Provo, UT, USA, 2026, pp. 1-6

DOI:10.1109/IETC69527.2026.11568673

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑