Academia.eduAcademia.edu

PER-FAMILY CLASSIFIER PRECISION, RECALL, AND F SCORES FOR THE MALWARE FAMILIES WITH THE HIGHEST AND LOWEST F SCORES  Generally, the best performing families were those from narrowly defined malware categories, such as viruses, worms, and backdoors. Conversely, the worst performing families were those from more broadly defined categories, particularly Tro- jans. Furthermore, some of the poorly performing families are also broadly defined. For example, Gandlo!gmb, Ircbrute!gmb, and Sisron!gmb are all generically-defined Trojans. In contrast, the highest performing families are typically very narrowly defined. For example, Klez and MyDoom, are well studied families whose samples perform specific functions and have a shared heritage.

Table 2 PER-FAMILY CLASSIFIER PRECISION, RECALL, AND F SCORES FOR THE MALWARE FAMILIES WITH THE HIGHEST AND LOWEST F SCORES Generally, the best performing families were those from narrowly defined malware categories, such as viruses, worms, and backdoors. Conversely, the worst performing families were those from more broadly defined categories, particularly Tro- jans. Furthermore, some of the poorly performing families are also broadly defined. For example, Gandlo!gmb, Ircbrute!gmb, and Sisron!gmb are all generically-defined Trojans. In contrast, the highest performing families are typically very narrowly defined. For example, Klez and MyDoom, are well studied families whose samples perform specific functions and have a shared heritage.