Arrow Research search

Author name cluster

Gil Tahan

Possible papers associated with this exact author name in Arrow. This page groups case-insensitive exact name matches and is not a full identity disambiguation profile.

2 papers
1 author row

Possible papers

2

JMLR Journal 2012 Journal Article

Mal-ID: Automatic Malware Detection Using Common Segment Analysis and Meta-Features

  • Gil Tahan
  • Lior Rokach
  • Yuval Shahar

This paper proposes several novel methods, based on machine learning, to detect malware in executable files without any need for preprocessing, such as unpacking or disassembling. The basic method (Mal-ID) is a new static (form-based) analysis methodology that uses common segment analysis in order to detect malware files. By using common segment analysis, Mal-ID is able to discard malware parts that originate from benign code. In addition, Mal-ID uses a new kind of feature, termed meta-feature, to better capture the properties of the analyzed segments. Rather than using the entire file, as is usually the case with machine learning based techniques, the new approach detects malware on the segment level. This study also introduces two Mal-ID extensions that improve the Mal-ID basic method in various aspects. We rigorously evaluated Mal-ID and its two extensions with more than ten performance measures, and compared them to the highly rated boosted decision tree method under identical settings. The evaluation demonstrated that Mal-ID and the two Mal-ID extensions outperformed the boosted decision tree method in almost all respects. In addition, the results indicated that by extracting meaningful features, it is sufficient to employ one simple detection rule for classifying executable files. [abs] [ pdf ][ bib ] &copy JMLR 2012. ( edit, beta )

AIIM Journal 2006 Journal Article

Distributed, intelligent, interactive visualization and exploration of time-oriented clinical data and their abstractions

  • Yuval Shahar
  • Dina Goren-Bar
  • David Boaz
  • Gil Tahan

Objectives We present KNAVE-II, an intelligent interface to a distributed architecture specific to the tasks of query, knowledge-based interpretation, summarization, visualization, interactive exploration of large numbers of distributed time-oriented clinical data, and dynamic sensitivity analysis of these data. KNAVE-II main contributions to the fields of temporal reasoning and intelligent user interfaces are: (1) the capability for interactive computation and visualization of domain specific temporal abstractions, supported by ALMA – a computational engine that applies the domain knowledge base to the clinical time-oriented database. (2) Semantic (ontology-based) navigation and exploration of the data, knowledge, and temporal abstractions, supported by the IDAN mediator, a distributed architecture that enables runtime access to domain-specific knowledge bases that are maintained by expert physicians. Methods and materials KNAVE-II was designed according to 12 requirements that were defined through iterative cycles of design and user-centered evaluation. The complete architecture has been implemented and evaluated in a cross-over study design that compared the KNAVE-II module versus two existing methods: paper charts and an Excel electronic spreadsheet. A small group of clinicians answered the same queries, using the domain of oncology and a set of 1000 patients followed after bone-marrow transplantation. Results The results show that users are able to perform medium to hard difficulty level queries faster and more accurately by using KNAVE-II than paper charts and Excel. Moreover, KNAVE-II was ranked first in preference by all users, along all usability dimensions. Conclusions Initial evaluation of KNAVE-II and its supporting knowledge based temporal-mediation architecture, by applying it to a large data base of patients monitored several years after bone marrow transplantation (BMT), has produced highly encouraging results.

v2026.09.13