USENIX Security2021Top-tier venue
YARIX: Scalable YARA-based Malware Intelligence
Michael Brengel, Christian Rossow
Abstract
YARA is the industry standard to search for patterns in malware data sets. Malware analysts heavily rely on YARA rules to identify specific threats, e.g., by scanning unknown malware samples for patterns that are characteristic for a certain malware strain. While YARA is tremendously useful to inspect individual files, its run time grows linearly with the number of input files, resulting in prohibitive performance penalties in large malware corpora. We present YARIX, a methodology to efficiently reveal files matching arbitrary YARA rules. In order to scale to large malware corpora, YARIX uses an inverted n-gram index that maps fixed-length byte sequences to lists of files in which they appear. To efficiently query such corpora, YARIX optimizes YARA searches by transforming YARA rules into index lookups to obtain a set of candidate files that potentially match the rule. Given the storage demands that arise when indexing binary files, YARIX compresses the disk footprint with variable byte delta encoding, abstracts from file offsets, and leverages a novel grouping-based compression methodology. This completeness-preserving approximation will then be scanned using YARA to get the actual set of matching files. Using 32M malware samples and 1 404 YARA rules, we show that YARIX scales in both disk footprint and search performance. The index requires just ≈74% of the space required for storing the malware samples. Querying YARIX with a YARA rule in our test setup is five orders of magnitude faster than using standard sequential YARA scans.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f1e9a514-bbb6-45d5-9a99-b40f31eea530Cited by top-tier papers5
- PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer DetectionShijia Li, Jiang Ming, Pengda Qiu, Qiyuan Chen et al.CCS 2023 · 10 citations
- BinAug: Enhancing Binary Similarity Analysis with Low-Cost Input RepairingWai Kin Wong, Huaijin Wang, Zongjie Li, Shuai WangICSE 2024 · 4 citations
- Limits of I/O Based Ransomware Detection: An Imitation Based AttackChijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma et al.S&P 2023
- ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content AnalysisLingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan et al.NDSS 2025
- Understanding Miniapp Malware: Identification, Dissection, and CharacterizationYuqing Yang, Yue Zhang, Zhiqiang LinNDSS 2025
Builds on3
- FeatureSmith: Automatically Engineering Features for Malware Detection by Mining the Security LiteratureZiyun Zhu, Tudor DumitrasCCS 2016 · 114 citations
- Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance BoostBinlin Cheng, Jiang Ming, Jianming Fu, Guojun Peng et al.CCS 2018 · 68 citations
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
Related papers
- A New Burrows Wheeler Transform Markov DistanceEdward Raff, Charles Nicholas, Mark McLeanAAAI 2020 · 13 citations
- An Evaluation of N-Gram Selection Strategies for Regular Expression Indexing in Contemporary Text Analysis TasksLing Zhang, Shaleen Deep, Jignesh M. Patel, Karthikeyan SankaralingamVLDB 2025 · 2 citations
- Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyKhaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew SmithS&P 2016 · 128 citations
- Regular Expression Indexing for Log AnalysisLing Zhang, Shaleen Deep, Jignesh M. Patel, Karthikeyan SankaralingamSIGMOD 2026
- Collapsing the Hierarchy of Compressed Data Structures: Suffix Arrays in Optimal Compressed SpaceDominik Kempa, Tomasz KociumakaFOCS 2023 · 20 citations
