Skip to main navigation Skip to search Skip to main content

Facing the challenge of leveraging untrained humans in malware analysis

Benjamin Zi Hao Zhao*, Hassan Jameel Asghar, Muhammad Ikram, Mohamed Ali Kaafar, Sean Lamont, Daniel Coscia

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

Software binary analysis, tools and machine learning aid security analysts in interpreting data, by automated means that filter, prioritize, and arrange pertinent information for skilled analysts. In this work, we revisit cooperative human-machine teams and evaluate the possibility of enabling untrained humans to assist machines and skilled analysts in their analysis of software binaries. Specifically, we propose a pipeline to transform a complex input domain into facial images on which untrained individuals make similarity decisions. Our faces include realistic human, animal, artistic, and anime faces that preserve inherent distances between data points of the input domain. Our approach is evaluated through a human study, where untrained respondents with minimal training successfully flag machine misclassifications. The untrained human does not replace the machine or skilled analyst, instead, utilized in a triage setting, to identify samples without historical precedence, deferring the decision to the skilled analyst for deeper inspection.

Original languageEnglish
Title of host publicationICT Systems Security and Privacy Protection
Subtitle of host publication40th IFIP International Conference, SEC 2025, Maribor, Slovenia, May 21-23, 2025, proceedings, part I
EditorsLili Nemec Zlatolas, Kai Rannenberg, Tatjana Welzer, Joaquin Garcia-Alfaro
Place of PublicationCham, Switzerland
PublisherSpringer, Springer Nature
Pages61-75
Number of pages15
ISBN (Electronic)9783031928826
ISBN (Print)9783031928819, 9783031928840
DOIs
Publication statusPublished - 2025
Event40th IFIP International Conference on ICT Systems Security and Privacy Protection, SEC 2025 - Maribor, Spain
Duration: 20 May 202523 May 2025

Publication series

NameIFIP Advances in Information and Communication Technology
PublisherSpringer
Volume745
ISSN (Print)1868-4238
ISSN (Electronic)1868-422X

Conference

Conference40th IFIP International Conference on ICT Systems Security and Privacy Protection, SEC 2025
Country/TerritorySpain
CityMaribor
Period20/05/2523/05/25

Keywords

  • Malware
  • Binaries
  • Data Visualization
  • Human
  • Faces
  • Rapid
  • Triage

Fingerprint

Dive into the research topics of 'Facing the challenge of leveraging untrained humans in malware analysis'. Together they form a unique fingerprint.

Cite this