GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Rubikoid (rubikoid@social.rubikoid.ru)'s status on Saturday, 16-Mar-2024 08:21:56 JSTRubikoidRubikoid
    in reply to
    • :umu: :umu:

    @a1ba I work at sandbox+malware-related department in one ru big infosec company.

    We don’t have AV in their original form (even we have some of EDR products, which replaces AV as well), but i think i can say a few words about a problem.

    About the ML for AVs: it’s cursed.
    Most of AVs can work in two general ways: signature analysis and behaviour analysis.

    I have not seen any AV, that uses ML in behaviour analysis - and this is the only thing where ML works enough good.

    For signature analysis, it is hard to make really good models for malware detection, I think.

    For example, if for hand-written signatures you can run some false-positive tests and don’t release bad signatures, for ML model this action performs even more slower and harder.
    Also, ML models are more harder to fix and retrain.

    Why ML models used? I think, it’s cheaper than department of specialists, who knows how to write good signatures.
    Aaaand in 1% cases it can really be better than human.

    In your case, i *magically guess* this can be happen due to usage of some weird functions imports, or you accidentally wrote code snippet, which seems _like_ packer or something.

    In conversationSaturday, 16-Mar-2024 08:21:56 JST from gnusocial.jppermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://human.In/
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.