MAECProject / schemas

MAEC Schemas and Schema Development
80 stars 18 forks source link

Add/Remove Malware Labels #62

Open dzbeck opened 10 years ago

dzbeck commented 10 years ago

consider adding the following labels to MalwareLabelEnum:

joke program: programs that interfere with the normal behavior of your computer, creating a nuisance

scareware: programs that report false or significantly misleading information on the presence of security risks, threats, or system issues on the target computer

parental control: programs for monitoring or limiting computer usage. They can run undetected and transmit monitoring information to another computer

security assessment tool: programs that can be used to gather information for unauthorized access to computer systems.

trackware: programs that trace a user's path on the Internet and send information to third parties (this differs from 'spyware' which monitors system activity to detect passwords and other confidential info that is relayed to a third party)

Consider removing the "malcode" label, which is very broad and not very useful.

ikiril01 commented 9 years ago

We could potentially mine malware advisories/reports for other labels, e.g. "proxy tool", "lightweight backdoor", from https://www.us-cert.gov/ncas/alerts/TA14-353A

cystek commented 4 years ago

You might consider adding "exploit" and/or "exploit-kit" as well.