182 citations · 212 across the 5 of their papers we have counts for
6 papers
Classifying Sequences of Extreme Length with Constant Memory Applied to Malware Detection
Edward Raff, William Fleshman, Richard Zak +3
Recent works within machine learning have been tackling inputs of ever-increasing size, with cybersecurity presenting sequence classification problems of particularly extreme lengt…
Getting Passive Aggressive About False Positives: Patching Deployed Malware Detectors
Edward Raff, Bobby Filar, James Holt
False positives (FPs) have been an issue of extreme importance for anti-virus (AV) systems for decades. As more security vendors turn to machine learning, alert deluge has hit crit…
Automatic Yara Rule Generation Using Biclustering
Edward Raff, Richard Zak, Gary Lopez Munoz +5
Yara rules are a ubiquitous tool among cybersecurity practitioners and analysts. Developing high-quality Yara rules to detect a malware family of interest can be labor- and time-in…
ProblemChild: Discovering Anomalous Patterns based on Parent-Child Process Relationships
Bobby Filar, David French
It is becoming more common that adversary attacks consist of more than a standalone executable or script. Often, evidence of an attack includes conspicuous process heritage that ma…
Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
Hyrum S. Anderson, Anant Kharkar, Bobby Filar +2
Machine learning is a popular approach to signatureless malware detection because it can generalize to never-before-seen malware families and polymorphic strains. This has resulted…
Ask Me Anything: A Conversational Interface to Augment Information Security Workers
Bobby Filar, Richard J. Seymour, Matthew Park
Security products often create more problems than they solve, drowning users in alerts without providing the context required to remediate threats. This challenge is compounded by…