Detail aplikovaného výsledku

GenRex: Generator of Regular Expressions

KOLÁŘ, D.; MILKOVIČ, M.; REGÉCIOVÁ, D.

Original Title

GenRex: Generator of Regular Expressions

English Title

GenRex: Generator of Regular Expressions

Type

Software

Abstract

GenRex is a unique tool for detecting similarities in artifacts (extracted data) from executable files and for generating regular expressions from them. It implements an advanced algorithm to create regular expressions, improves state-of-the-art algorithms, and includes domain-specific optimizations and pattern detections for optimal results.

Generated regular expressions can be used for malware detections, for example, with YARA or any other pattern-matching tool. We also tested GenRex on publicly available behavioral reports and achieved a high True Positive Rate of 92.34% and a low False Positive Rate of 0.01%.

Abstrakt aglicky

GenRex is a unique tool for detecting similarities in artifacts (extracted data) from executable files and for generating regular expressions from them. It implements an advanced algorithm to create regular expressions, improves state-of-the-art algorithms, and includes domain-specific optimizations and pattern detections for optimal results.

Generated regular expressions can be used for malware detections, for example, with YARA or any other pattern-matching tool. We also tested GenRex on publicly available behavioral reports and achieved a high True Positive Rate of 92.34% and a low False Positive Rate of 0.01%.

Keywords

Malware detection, dynamic analysis, pattern generation algorithm, regular expressions, rules generation algorithm, YARA, GenRex

Key words in English

Malware detection, dynamic analysis, pattern generation algorithm, regular expressions, rules generation algorithm, YARA, GenRex

Location

https://github.com/avast/genrex

Licence fee

In order to use the result by another entity, it is always necessary to acquire a license

www