%0 Conference Proceedings %T About the Robustness and Looseness of Yara Rules %+ University of Sannio [Benevento] %A Canfora, Gerardo %A Carapella, Mimmo %A Vecchio, Andrea, Del %A Nardi, Laura %A Pirozzi, Antonio %A Visaggio, Corrado, Aaron %Z Part 2: Security Testing %< avec comité de lecture %( Lecture Notes in Computer Science %B 32th IFIP International Conference on Testing Software and Systems (ICTSS) %C Naples, Italy %Y Valentina Casola %Y Alessandra De Benedictis %Y Massimiliano Rak %I Springer International Publishing %3 Testing Software and Systems %V LNCS-12543 %P 104-120 %8 2020-12-09 %D 2020 %R 10.1007/978-3-030-64881-7_7 %K Yara %K Malware classification %K Threat intelligence %K Threat hunting %Z Computer Science [cs] %Z Computer Science [cs]/Networking and Internet Architecture [cs.NI]Conference papers %X The tremendous and fast growth of malware circulating in the wild urges the community of malware analysts to rapidly and effectively share knowledge about the arising threats. Among the other solutions, Yara is establishing as a de facto standard for describing and exchanging Indicators of Compromise (IOCs). Unfortunately, the community of malware analysts did not agree on a set of guidelines for writing Yara rules: a plethora of very different styles for formalizing IOCs can be observed, indeed. Our thesis is that different styles of Yara rule writing could affect the quality of IOCs. With this paper we provide: (i) the definition of two dimensions of Yara rules quality, namely Robustness and Looseness; (ii) a taxonomy for describing the kinds of IOCs that can be formalized with the Yara grammar, and (iii) a suite of metrics for measuring the quality of an IOC. Finally, we carried out a study on 32,311 Yara rules for examining the different existing styles and to investigate the relationship between the writing styles and the quality of IOCs. %G English %Z TC 6 %Z WG 6.1 %2 https://inria.hal.science/hal-03239822/document %2 https://inria.hal.science/hal-03239822/file/497758_1_En_7_Chapter.pdf %L hal-03239822 %U https://inria.hal.science/hal-03239822 %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC6 %~ IFIP-WG6-1 %~ IFIP-ICTSS %~ IFIP-LNCS-12543