About the Robustness and Looseness of Yara Rules - Testing Software and Systems Access content directly
Conference Papers Year : 2020

About the Robustness and Looseness of Yara Rules

Gerardo Canfora
  • Function : Author
  • PersonId : 1100066
Mimmo Carapella
  • Function : Author
  • PersonId : 1100067
Andrea Del Vecchio
  • Function : Author
  • PersonId : 1100068
Laura Nardi
  • Function : Author
  • PersonId : 1100069
Antonio Pirozzi
  • Function : Author
  • PersonId : 1100070
Corrado Aaron Visaggio
  • Function : Author
  • PersonId : 998094

Abstract

The tremendous and fast growth of malware circulating in the wild urges the community of malware analysts to rapidly and effectively share knowledge about the arising threats. Among the other solutions, Yara is establishing as a de facto standard for describing and exchanging Indicators of Compromise (IOCs). Unfortunately, the community of malware analysts did not agree on a set of guidelines for writing Yara rules: a plethora of very different styles for formalizing IOCs can be observed, indeed. Our thesis is that different styles of Yara rule writing could affect the quality of IOCs. With this paper we provide: (i) the definition of two dimensions of Yara rules quality, namely Robustness and Looseness; (ii) a taxonomy for describing the kinds of IOCs that can be formalized with the Yara grammar, and (iii) a suite of metrics for measuring the quality of an IOC. Finally, we carried out a study on 32,311 Yara rules for examining the different existing styles and to investigate the relationship between the writing styles and the quality of IOCs.
Fichier principal
Vignette du fichier
497758_1_En_7_Chapter.pdf (580.7 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-03239822 , version 1 (27-05-2021)

Licence

Attribution

Identifiers

Cite

Gerardo Canfora, Mimmo Carapella, Andrea Del Vecchio, Laura Nardi, Antonio Pirozzi, et al.. About the Robustness and Looseness of Yara Rules. 32th IFIP International Conference on Testing Software and Systems (ICTSS), Dec 2020, Naples, Italy. pp.104-120, ⟨10.1007/978-3-030-64881-7_7⟩. ⟨hal-03239822⟩
48 View
124 Download

Altmetric

Share

Gmail Facebook X LinkedIn More