用AI提升恶意软件分析效率,显著提速降本。
Malware analysis assisted by AI with R2AI
- 结合Radare2与Claude 3.5/3.7 Sonnet进行智能反汇编分析
- 分析速度大幅提升,质量接近或优于人工,误差可控
- 适合安全研究员在真实环境中辅助研判复杂物联网恶意样本
本研究探讨人工智能辅助恶意软件分析在质量、速度和成本方面的表现。聚焦2024-2025年间的Linux与物联网(IoT)恶意软件,采用Radare2的AI扩展r2ai。实验表明,使用Claude 3.5和3.7 Sonnet可获得优异结果,尽管存在少量误判,整体分析质量与人工相当或更优。高质量结果需经验丰富的分析师持续引导AI,避免其陷入无效循环。即使计入理解AI幻觉、夸大与遗漏的时间,速度仍明显提升;成本通常远低于专业分析师薪资,但需实时监控以防止无进展循环。
原文摘要 · Abstract (English)
This research studies the quality, speed and cost of malware analysis assisted by artificial intelligence. It focuses on Linux and IoT malware of 2024-2025, and uses r2ai, the AI extension of Radare2's disassembler. Not all malware and not all LLMs are equivalent but the study shows excellent results with Claude 3.5 and 3.7 Sonnet. Despite a few errors, the quality of analysis is overall equal or better than without AI assistance. For good results, the AI cannot operate alone and must constantly be guided by an experienced analyst. The gain of speed is largely visible with AI assistance, even when taking account the time to understand AI's hallucinations, exaggerations and omissions. The cost is usually noticeably lower than the salary of a malware analyst, but attention and guidance is needed to keep it under control in cases where the AI would naturally loop without showing progress.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。