Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/undo-ransomware/ransomware_detection.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
authorMatthias Held <ilovemilk@wusa.io>2018-09-13 20:20:02 +0300
committerMatthias Held <ilovemilk@wusa.io>2018-09-13 20:20:02 +0300
commit900e31eecdfba9a7bfdaaf0349e293098e149834 (patch)
treeb4b09d4f3b56c4d9eb054c342177dc34d54ec4b9 /lib
parent4a1cff97b588e6047168f6d91de92cc6a0d9534f (diff)
Simplify sequence analysis result color coding
Signed-off-by: Matthias Held <matthias.held@uni-konstanz.de>
Diffstat (limited to 'lib')
-rw-r--r--lib/Analyzer/SequenceAnalyzer.php8
1 files changed, 4 insertions, 4 deletions
diff --git a/lib/Analyzer/SequenceAnalyzer.php b/lib/Analyzer/SequenceAnalyzer.php
index e1b8c6c..190ca7d 100644
--- a/lib/Analyzer/SequenceAnalyzer.php
+++ b/lib/Analyzer/SequenceAnalyzer.php
@@ -71,7 +71,7 @@ class SequenceAnalyzer
* Therefor the suspicions levels are weighted:
* Suspicious - 1
* Maybe suspicious - 0.5
- * Not suspicious - 0.25
+ * Not suspicious - 0
*
* summed up and divided by the sum of all written files. The higher the result,
* the higher is the suspicion of the hole sequence.
@@ -139,10 +139,10 @@ class SequenceAnalyzer
if (sizeof($files['written']) <= $upperBound && sizeof($files['written']) >= sizeof($files['deleted'])) {
if ($this->sequenceSizeAnalyzer->analyze($sequence) === SequenceSizeAnalyzer::EQUAL_SIZE) {
$sequenceResult->setQuantities(2);
- $suspicionScore += 2;
+ $suspicionScore += 1;
} else {
$sequenceResult->setQuantities(1);
- $suspicionScore += 1;
+ $suspicionScore += 0;
}
}
}
@@ -156,7 +156,7 @@ class SequenceAnalyzer
}
// weight the suspicion levels.
- $suspicionSum = (sizeof($files['suspicious']) * 1) + (sizeof($files['maybeSuspicious']) * 0.5) + ((sizeof($files['notSuspicious']) - $numberOfInfoFiles) * 0.25);
+ $suspicionSum = (sizeof($files['suspicious']) * 1) + (sizeof($files['maybeSuspicious']) * 0.5);
// check for division by zero.
if (($numberOfWrittenFiles - $numberOfInfoFiles) > 0) {