The objective of this Workpackage 4 is to develop techniques to characterize the malicious code that is collected in the previous workpackage. The main idea is to enrich the collected code thanks to metadata that might reveal insights into the origin of the code and the intentions of those that created, released or used it. This deliverable provides a preliminary discussion of possible contextual features of malware, and for each feature, an estimate on its effectiveness and the difficulty to obtain it. Some of these features can be used to analyze potential threats and discriminate collected samples that are mere variations of already known threats.
FP7-ICT-216026-Wombat_WP4-D15_V01_Intermediate-Contextual-features.pdf
FP7-ICT-216026-Wombat_WP4-D15_V01_Intermediate-Contextual-features.pdf