GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Rubikoid (rubikoid@social.rubikoid.ru)

  1. Embed this notice
    Rubikoid (rubikoid@social.rubikoid.ru)'s status on Saturday, 16-Mar-2024 08:21:56 JST Rubikoid Rubikoid
    in reply to
    • :umu: :umu:

    @a1ba I work at sandbox+malware-related department in one ru big infosec company.

    We don’t have AV in their original form (even we have some of EDR products, which replaces AV as well), but i think i can say a few words about a problem.

    About the ML for AVs: it’s cursed.
    Most of AVs can work in two general ways: signature analysis and behaviour analysis.

    I have not seen any AV, that uses ML in behaviour analysis - and this is the only thing where ML works enough good.

    For signature analysis, it is hard to make really good models for malware detection, I think.

    For example, if for hand-written signatures you can run some false-positive tests and don’t release bad signatures, for ML model this action performs even more slower and harder.
    Also, ML models are more harder to fix and retrain.

    Why ML models used? I think, it’s cheaper than department of specialists, who knows how to write good signatures.
    Aaaand in 1% cases it can really be better than human.

    In your case, i *magically guess* this can be happen due to usage of some weird functions imports, or you accidentally wrote code snippet, which seems _like_ packer or something.

    In conversation about a year ago from gnusocial.jp permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://human.In/
  2. Embed this notice
    Rubikoid (rubikoid@social.rubikoid.ru)'s status on Wednesday, 20-Dec-2023 21:08:47 JST Rubikoid Rubikoid
    in reply to
    • Houl :blobfoxfloof:
    • Meko #nowar
    • AkhIL
    • Lost Edges
    • Libre Fox
    • Kir4ik52 :blobfoxsanta:

    @akhil @kir4ik52 @libre_fox @yura @edges @Houl а может лучше WSL?)

    In conversation Wednesday, 20-Dec-2023 21:08:47 JST from social.rubikoid.ru permalink

User actions

    Rubikoid

    Rubikoid

    Yet another infosec cube.Python, DevOps/Sysadm, Reverse-engineeringSpeaks en, ru (native).

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          224915
          Member since
          20 Dec 2023
          Notices
          2
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.