Work item: X.1546 (ex X.maec)
Status: Approved on 2014-01-24 [Issued from previous study period]
Approval process: TAP
Type of work item: Recommendation
Version: New
Provisional name: X.maec
Equivalent number: -
Timing: -
Liaison: -
Subject/title: Malware attribute enumeration and characterization
Summary: The malware attribute enumeration and characterization (MAEC) language includes enumerations of malware attributes and behaviour that provide a common vocabulary. These enumerations are at different levels of abstraction: low-level observables, mid-level behaviours and high-level taxonomies. Recommendation ITU-T 1546, which is the initial version of MAEC, focuses on the creation of the enumeration of low-level malware attributes, and leverages the few instances of similar work already done in this area. Thus it will initially be capable of characterizing the most common malware types, including Trojans, worms, and rootkits, but will ultimately be applicable to more esoteric malware types.
Comment: -
Base text(s):
ITU-T A.5 reference(s):
First registration in the WP: 2010-05-31 11:04:02
Last update: 2014-02-03 15:11:23