<efrbr:recordSet xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:efrbr="http://vfrbr.info/efrbr/1.1" xmlns:efrbr-work="http://vfrbr.info/efrbr/1.1/work" xmlns:efrbr-expression="http://vfrbr.info/efrbr/1.1/expression" xmlns:efrbr-manifestation="http://vfrbr.info/efrbr/1.1/manifestation" xmlns:efrbr-person="http://vfrbr.info/efrbr/1.1/person" xmlns:efrbr-corporateBody="http://vfrbr.info/efrbr/1.1/corporateBody" xmlns:efrbr-concept="http://vfrbr.info/efrbr/1.1/concept" xmlns:efrbr-structure="http://vfrbr.info/efrbr/1.1/structure" xmlns:efrbr-responsible="http://vfrbr.info/efrbr/1.1/responsible" xmlns:efrbr-subject="http://vfrbr.info/efrbr/1.1/subject" xmlns:efrbr-other="http://vfrbr.info/efrbr/1.1/other" xsi:schemaLocation="http://vfrbr.info/efrbr/1.1 http://vfrbr.info/schemas/1.1/efrbr.xsd"><efrbr:entities><efrbr-work:work identifier="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08"><efrbr-work:titleOfTheWork>Bayesian active malware analysis</efrbr-work:titleOfTheWork></efrbr-work:work><efrbr-expression:expression identifier="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08"><efrbr-expression:titleOfTheExpression>Bayesian active malware analysis</efrbr-expression:titleOfTheExpression><efrbr-expression:formOfExpression vocabulary="DIAS:TYPES">
            Πλήρης Δημοσίευση σε Συνέδριο
            Conference Full Paper
         </efrbr-expression:formOfExpression><efrbr-expression:dateOfExpression type="issued">2022-07-26</efrbr-expression:dateOfExpression><efrbr-expression:dateOfExpression type="published">2020</efrbr-expression:dateOfExpression><efrbr-expression:languageOfExpression vocabulary="iso639-1">en</efrbr-expression:languageOfExpression><efrbr-expression:otherDistinguishingCharacteristic>The research reported in this publication has been partially supported by the project “Dipartimenti di Eccellenza 2018-2022” funded by the Italian Ministry of Education, University and Research (MIUR).</efrbr-expression:otherDistinguishingCharacteristic><efrbr-expression:summarizationOfContent>We propose a novel technique for Active Malware Analysis (AMA) formalized as a Bayesian game between an analyzer agent and a malware agent, focusing on the decision making strategy for the analyzer. In our model, the analyzer performs an action on the system to trigger the malware into showing a malicious behavior, i.e., by activating its payload. The formalization is built upon the link between malware families and the notion of types in Bayesian games. A key point is the design of the utility function, which reflects the amount of uncertainty on the type of the adversary after the execution of an analyzer action. This allows us to devise an algorithm to play the game with the aim of minimizing the entropy of the analyzer’s belief at every stage of the game in a myopic fashion. Empirical evaluation indicates that our approach results in a significant improvement both in terms of learning speed and classification score when compared to other state-of-the-art AMA techniques.</efrbr-expression:summarizationOfContent><efrbr-expression:useRestrictionsOnTheExpression type="creative-commons">http://creativecommons.org/licenses/by/4.0/</efrbr-expression:useRestrictionsOnTheExpression><efrbr-expression:note type="page range">1206 - 1214</efrbr-expression:note><efrbr-expression:note type="conference name">19th International Conference on Autonomous Agents and Multiagent Systems</efrbr-expression:note><efrbr-expression:note type="proceedings title">Proceedings of the 19th International Conference on Autonomous Agents and Multiagent Systems</efrbr-expression:note></efrbr-expression:expression><efrbr-person:person identifier="0B96E9C5-FACF-422D-AD54-AA85EFDEF86F"><efrbr-person:nameOfPerson vocabulary="">
            Sartea Riccardo
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-person:person identifier="http://users.isc.tuc.gr/~gchalkiadakis"><efrbr-person:nameOfPerson vocabulary="TUC:LDAP">
            Chalkiadakis Georgios
            Χαλκιαδακης Γεωργιος
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-person:person identifier="1C5D69D0-AC62-4D94-ABAA-755E934AEE98"><efrbr-person:nameOfPerson vocabulary="">
            Farinelli Alessandro
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-person:person identifier="4CE2B936-0245-40F3-9D81-4FB3F1550B13"><efrbr-person:nameOfPerson vocabulary="">
            Murari Matteo
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-corporateBody:corporateBody identifier="13E766F3-72E6-472E-9286-F535B8A7D7AC"><efrbr-corporateBody:nameOfTheCorporateBody vocabulary="">
            International Foundation for Autonomous Agents and Multiagent Systems (IFAAMAS)
         </efrbr-corporateBody:nameOfTheCorporateBody></efrbr-corporateBody:corporateBody><efrbr-concept:concept identifier="809A59B9-950F-4E0B-91E3-A40927114C66"><efrbr-concept:termForTheConcept>
            Malware
         </efrbr-concept:termForTheConcept></efrbr-concept:concept><efrbr-concept:concept identifier="82F2CFF5-5D02-4796-AC7D-BE75B732EF54"><efrbr-concept:termForTheConcept>
            Autonomous agents
         </efrbr-concept:termForTheConcept></efrbr-concept:concept><efrbr-concept:concept identifier="53947C54-2876-4FA5-9588-2DBDA5A9FF39"><efrbr-concept:termForTheConcept>
            Multi agent systems
         </efrbr-concept:termForTheConcept></efrbr-concept:concept><efrbr-concept:concept identifier="FE161A58-C4E3-4817-ADE8-CDDBE47EBD17"><efrbr-concept:termForTheConcept>
            Decision making
         </efrbr-concept:termForTheConcept></efrbr-concept:concept></efrbr:entities><efrbr:relationships><efrbr-structure:structureRelations><efrbr-structure:realizedThrough sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="expression" targetURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08"/></efrbr-structure:structureRelations><efrbr-responsible:responsibleRelations><efrbr-responsible:createdBy sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="person" targetURI="0B96E9C5-FACF-422D-AD54-AA85EFDEF86F"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="person" targetURI="0B96E9C5-FACF-422D-AD54-AA85EFDEF86F" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="person" targetURI="http://users.isc.tuc.gr/~gchalkiadakis" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="person" targetURI="1C5D69D0-AC62-4D94-ABAA-755E934AEE98" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="person" targetURI="4CE2B936-0245-40F3-9D81-4FB3F1550B13" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="person" targetURI="13E766F3-72E6-472E-9286-F535B8A7D7AC" role="publisher"/></efrbr-responsible:responsibleRelations><efrbr-subject:subjectRelations><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="concept" targetURI="809A59B9-950F-4E0B-91E3-A40927114C66"/><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="concept" targetURI="82F2CFF5-5D02-4796-AC7D-BE75B732EF54"/><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="concept" targetURI="53947C54-2876-4FA5-9588-2DBDA5A9FF39"/><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/C261F0BB-A07D-45B8-8B7F-7DFD52339A08" targetEntity="concept" targetURI="FE161A58-C4E3-4817-ADE8-CDDBE47EBD17"/></efrbr-subject:subjectRelations><efrbr-other:otherRelations/></efrbr:relationships></efrbr:recordSet>