Comparing the utility of user-level and kernel-level data for dynamic malware analysis