activity
20172020
most citedLearning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning

182 citations · 212 across the 5 of their papers we have counts for

collaborators

6 papers

stat.ML2020

Classifying Sequences of Extreme Length with Constant Memory Applied to Malware Detection

Edward Raff, William Fleshman, Richard Zak +3

Recent works within machine learning have been tackling inputs of ever-increasing size, with cybersecurity presenting sequence classification problems of particularly extreme lengt…

cs.LG2020

Getting Passive Aggressive About False Positives: Patching Deployed Malware Detectors

Edward Raff, Bobby Filar, James Holt

False positives (FPs) have been an issue of extreme importance for anti-virus (AV) systems for decades. As more security vendors turn to machine learning, alert deluge has hit crit…

cs.CR202027 cited

Automatic Yara Rule Generation Using Biclustering

Edward Raff, Richard Zak, Gary Lopez Munoz +5

Yara rules are a ubiquitous tool among cybersecurity practitioners and analysts. Developing high-quality Yara rules to detect a malware family of interest can be labor- and time-in…

cs.CR2020

ProblemChild: Discovering Anomalous Patterns based on Parent-Child Process Relationships

Bobby Filar, David French

It is becoming more common that adversary attacks consist of more than a standalone executable or script. Often, evidence of an attack includes conspicuous process heritage that ma…

cs.CR2018182 cited

Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning

Hyrum S. Anderson, Anant Kharkar, Bobby Filar +2

Machine learning is a popular approach to signatureless malware detection because it can generalize to never-before-seen malware families and polymorphic strains. This has resulted…

cs.HC20173 cited

Ask Me Anything: A Conversational Interface to Augment Information Security Workers

Bobby Filar, Richard J. Seymour, Matthew Park

Security products often create more problems than they solve, drowning users in alerts without providing the context required to remediate threats. This challenge is compounded by…