logoalt Hacker News

Provably unmasking malicious behavior through execution traces

16 pointsby PaulHouleyesterday at 10:18 PM3 commentsview on HN

Comments

thethirdonetoday at 12:30 AM

Based on Table 1: This method is actually worse than generating a random number (0-100%)(independent of the program) and testing if it is less than 98.8%. That would achieve a better detection rate without increasing the false positive rate.

It doesn't seem worth it to try to follow the math to see if there is something interesting.

causalmodelsyesterday at 10:55 PM

Interesting direction but the 98.8% FPR in Table 1 seems like a dealbreaker. Anyone understand what's going on with the contradictory results between the text and tables?

show 1 reply