/SEMA

SEMA is based on angr, a symbolic execution engine used to extract API calls. Especially, we extend ANGR with strategies to create representative signatures based on System Call Dependency graph (SCDG). Those SCDGs can be exploited in machine learning modules to do classification/detection.

Primary LanguagePythonBSD 2-Clause "Simplified" LicenseBSD-2-Clause

Stargazers