כתבה
arXiv cs.AI ·
A TTP by TTP Approach: Precise Malware Detection via Malicious TTP Recognition
תקציר מקורי באנגליתarXiv:2609.06579v1 Announce Type: cross Abstract: Machine learning methods, and especially neural networks, are now routinely used for malware detection in network traffic. Though very effective, systems based on such methods often (i) are purely data-driven, ignoring the substantial body of available knowledge about the tactics, techniques, and procedures (TTPs) possibly used, and, consequently (ii) are not precise, since they either cannot correlate malicious activity with TTP usage, or if they do, they are unable to explain which TTP has been maliciously used. In this paper we demonstrate that it is possible to precisely detect malware by (i) providing the neural network model with information about the TTPs used by any given sample, and (ii) teaching the neural network to detect not ju
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית