Team Ai
Apppublic

sholokhov007/malware-triage-env

sourceHugging Facemitupdated 6mo agoView on Hugging Face
0likes
App README

๐Ÿฆ  Malware Triage Agent โ€” OpenEnv Environment

A real-world cybersecurity environment where an AI agent acts as a malware analyst, triaging synthetic malware reports through progressively harder tasks.

![OpenEnv](https://openenv.dev) ![HuggingFace](https://huggingface.co/spaces) ![Python](https://python.org)


๐ŸŽฏ Environment Description & Motivation

Security Operations Centers (SOCs) are overwhelmed. Analysts spend hours manually triaging malware alerts, classifying threats, and deciding containment actions. A significant portion of this work is pattern-matching against known threat intelligence โ€” exactly the kind of reasoning a capable LLM agent can learn to do.

This environment simulates the malware triage workflow:

  1. 1.The agent receives a synthetic malware analysis report (static indicators, behavioral patterns, API calls, network IOCs)
  2. 2.The agent must classify the threat, identify its family, and recommend containment actions
  3. 3.The environment scores the analysis with partial credit for each dimension

All malware reports are entirely synthetic โ€” no real malware, no real IOCs.


๐Ÿ“‹ Observation Space

Each observation is a MalwareObservation object:

FieldTypeDescription
sample_idstrUnique sample identifier
file_namestrName of the suspicious file
task_typestreasy / medium / hard
task_descriptionstrNatural language task instructions
reportdictFull malware analysis report (see below)
step_numberintCurrent step in the episode
max_stepsintMaximum steps per episode (3)
previous_feedbackstrFeedback from last step (None on first step)

Easy report fields: file_name, file_size_kb, file_type, md5, strings_of_interest, api_calls, network_activity, registry_changes, analyst_note

Medium report fields: file_name, behavioral_profile, api_calls, network_iocs, mutex, pdb_path, analyst_note, known_families (list to choose from)

Hard report fields: file_name, file_type, submission_source, static_analysis, behavioral_analysis, network_iocs, similarity_scores, affected_assets, analyst_note


โšก Action Space

Each action is a MalwareAction object:

FieldTypeRequiredDescription
malware_typestrAlwaysransomware / trojan / worm / spyware / adware / rootkit / dropper / unknown
danger_scorefloat [0,1]AlwaysSeverity score
confidencefloat [0,1]AlwaysAgent's confidence
family_namestrMedium + HardMalware family name
danger_levelstrMediumlow / medium / high / critical
is_zero_dayboolHardTrue if novel/zero-day
cvss_scorefloat [0,10]HardEstimated CVSS score
recommended_actionslist[str]HardContainment actions
reasoningstrHardBrief analysis explanation

๐Ÿ† Tasks & Difficulty

Task 1: classify-malware-type (Easy)

Objective: Given a static analysis report, classify the malware type and estimate danger.

Grading:

  • โ€”50% โ€” Correct malware type classification
  • โ€”35% โ€” Danger score within ยฑ0.15 of ground truth
  • โ€”15% โ€” Attempted reasoning

Example: File with CryptEncrypt API calls + .locked extension + ransom note strings โ†’ ransomware, danger_score 0.95


Task 2: identify-malware-family (Medium)

Objective: Given behavioral indicators, identify the malware family from a provided list and assess danger level.

Grading:

  • โ€”50% โ€” Correct family identification (CobaltStrike / Emotet / Trickbot / AgentTesla)
  • โ€”25% โ€” Correct danger level (low/medium/high/critical)
  • โ€”15% โ€” Correct malware type inference
  • โ€”10% โ€” Reasoning quality

Example: Process hollowing + HTTPS beaconing every 60s + mutex Global\FakeMutexCobalt โ†’ CobaltStrike, critical


Task 3: zero-day-assessment (Hard)

Objective: Full assessment of a novel or variant sample โ€” determine if it's a zero-day, estimate CVSS, and recommend a complete containment plan.

Grading:

  • โ€”25% โ€” Correct zero-day vs. known-variant determination
  • โ€”20% โ€” Closest known family identification
  • โ€”20% โ€” CVSS score within correct range
  • โ€”25% โ€” Correct containment actions (partial credit per action)
  • โ€”10% โ€” Quality of reasoning

Example: Kernel driver + SSDT hooks + BYOVD + DNS tunneling with 41% similarity to Lazarus loader โ†’ novel_variant_or_zeroday, CVSS 9.2, isolate + preserve forensics + reset credentials


๐Ÿ” Reward Function

Rewards are shaped for partial progress:

  • โ€”Scores are always in [0.0, 1.0]
  • โ€”Each task dimension provides partial credit โ€” wrong family but right danger level still earns points
  • โ€”Reward decays across steps (agent is incentivized to get it right early)
  • โ€”done=True when: perfect score (โ‰ฅ0.85), max steps reached, or episode complete

๐Ÿš€ Setup & Usage

Prerequisites

bash
pip install -r requirements.txt
pip install openenv-core   # for validation

Run locally

bash
python server.py
# Server starts at http://localhost:7860

Test with curl

bash
# Reset (easy task)
curl -X POST http://localhost:7860/reset \
  -H "Content-Type: application/json" \
  -d '{"task": "easy", "sample_index": 0}'

# Submit action
curl -X POST http://localhost:7860/step \
  -H "Content-Type: application/json" \
  -d '{
    "task": "easy",
    "sample_index": 0,
    "action": {
      "malware_type": "ransomware",
      "danger_score": 0.95,
      "confidence": 0.9
    }
  }'

# Get state
curl http://localhost:7860/state?task=easy

Run with Docker

bash
docker build -t malware-triage-env .
docker run -p 7860:7860 malware-triage-env

Run inference script

bash
export HF_TOKEN=your_hf_token
export MALWARE_TASK=easy       # easy | medium | hard
export MALWARE_SAMPLE_IDX=0
export SPACE_URL=http://localhost:7860

python inference.py

Run graders

bash
python graders/grader.py

๐Ÿ“Š Baseline Scores

TaskDifficultyOracle ScoreBaseline LLM Score
classify-malware-typeEasy1.00~0.72
identify-malware-familyMedium0.95~0.55
zero-day-assessmentHard0.88~0.38

Baseline scores obtained with Qwen2.5-72B-Instruct via HuggingFace Router.


๐Ÿ“ Project Structure

malware-triage-env/
โ”œโ”€โ”€ server.py           # FastAPI server (OpenEnv HTTP interface)
โ”œโ”€โ”€ environment.py      # Core environment: reset/step/state + reward logic
โ”œโ”€โ”€ inference.py        # Baseline inference script (LLM agent)
โ”œโ”€โ”€ openenv.yaml        # OpenEnv metadata
โ”œโ”€โ”€ Dockerfile          # Container definition
โ”œโ”€โ”€ requirements.txt    # Python dependencies
โ”œโ”€โ”€ data/
โ”‚   โ””โ”€โ”€ samples.py      # Synthetic malware report dataset
โ”œโ”€โ”€ graders/
โ”‚   โ””โ”€โ”€ grader.py       # Deterministic graders for all 3 tasks
โ”œโ”€โ”€ tasks/              # Task definitions (referenced in openenv.yaml)
โ””โ”€โ”€ tests/              # Unit tests

โš ๏ธ Infra Constraints

  • โ€”Runtime per episode: < 60 seconds
  • โ€”Total inference script runtime: < 20 minutes
  • โ€”Machine requirements: vCPU=2, memory=8GB compatible
  • โ€”No external APIs required (all data is synthetic and self-contained)

๐Ÿท๏ธ Tags

openenv cybersecurity malware-analysis soc threat-intelligence agent-evaluation