Linux antimalware detection via static and behavioral analysis
Micro-VM sandbox, eBPF monitoring and Bayesian scoring.
A Linux malware detection system combining static analysis and behavioral (dynamic) analysis, rather than relying on a single signature-based approach. A multi-layer architecture orchestrates several micro-VMs in parallel to observe how binaries actually execute.
- 90.7%
- Detection rate
- 0%
- False positives
- 10
- Parallel VMs
ENSEEIHT capstone project — supervised by Romain Cayre