Mark Vella

dblp:11/6290 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0002-6483-9054ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2026 Detecting Attack Patterns in Windows Registry Using CTI: A BERT-Based Approach
Leanne Briffa, Claudia Borg, Mark Vella
ICISSP (1)3
2023 Using Infrastructure-Based Agents to Enhance Forensic Logging of Third-Party Applications
Jennifer Bellizzi, Mark Vella, Christian Colombo 0001, Julio César Hernández Castro
ICISSP2
2022 D-Cloud-Collector: Admissible Forensic Evidence from Mobile Cloud Storage
abstract
Abstract Difficulties with accessing device content or even the device itself can seriously hamper smartphone forensics. Mobile cloud storage, which extends on-device capacity, provides an avenue for a forensic collection process that does not require physical access to the device. Rather, it is possible to remotely retrieve credentials from a device of interest through undercover operations, followed by live cloud forensics. While technologically appealing, this approach raises concerns with evidence preservation, ranging from the use of malware-like operations, to linking the collected evidence with the physically absent smartphone, and possible mass surveillance accusations. In this paper, we propose a solution to ease these concerns by employing hardware security modules to provide for controlled live cloud forensics and tamper-evident access logs. A Google Drive-based proof of concept, using the SEcube hardware security module, demonstrates that D-Cloud-Collector is feasible whenever the performance penalty incurred is affordable.
Mark Vella, Christian Colombo 0001
SEC1
2021 Responding to Living-Off-the-Land Tactics using Just-In-Time Memory Forensics (JIT-MF) for Android
Jennifer Bellizzi, Mark Vella, Christian Colombo 0001, Julio César Hernández Castro
SECRYPT2
2021 EtherClue: Digital investigation of attacks on Ethereum smart contracts
abstract
Programming errors in Ethereum smart contracts can result in catastrophic financial losses from stolen cryptocurrency. While vulnerability detectors can prevent vulnerable contracts from being deployed, this does not mean that such contracts will not be deployed. Once a vulnerable contract is instantiated on the blockchain and becomes the target of attacks, the identification of exploit transactions becomes indispensable in assessing whether it has been actually exploited and identifying which malicious or subverted accounts were involved. In this work, we study the problem of post-factum investigation of Ethereum attacks using Indicators of Compromise (IoC) specially crafted for use in the blockchain. IoC definitions need to capture the side-effects of successful exploitation in the context of the Ethereum blockchain. Therefore, we define a model for smart contract execution, comprising multiple abstraction levels that mirror the multiple views of code execution on a blockchain. Subsequently, we compare IoCs defined across the different levels in terms of their effectiveness and practicality through EtherClue, a prototype tool for investigating Ethereum security incidents. Our results illustrate that coarse-grained IoCs defined over blocks of transactions can detect exploit transactions with less computation. However, they are contract-specific and suffer from false negatives. On the other hand, fine-grained IoCs defined over virtual machine instructions can avoid these pitfalls at the expense of increased computation, which is nevertheless applicable for practical use.
Simon Joseph Aquilina, Fran Casino, Mark Vella, Joshua Ellul, Constantinos Patsakis
Blockchain Res. Appl.3
2020 Towards a Comprehensive Solution for Secure Cryptographic Protocol Execution based on Runtime Verification
Christian Colombo 0001, Mark Vella
ICISSP2
2020 SpotCheck: On-Device Anomaly Detection for Android
abstract
In recent years the PC has been replaced by mobile devices for many security sensitive operations, both from a privacy and a financial standpoint. While security mechanisms are deployed at various levels, these are frequently put under strain by previously unseen malware. An additional protection layer capable of novelty detection is therefore needed. In this work we propose SpotCheck, an anomaly detector intended to run on Android devices. It samples app executions and submits suspicious apps to more thorough processing by malware sandboxes. We compare Kernel Principal Component Analysis (KPCA) and Variational Autoencoders (VAE) on app execution representations based on the well-known system call traces, as well as a novel approach based on memory dumps. Results show that when using VAE, SpotCheck attains a level of effectiveness comparable to what has been previously achieved for network anomaly detection. Interestingly this is also true for the memory dump approach, relinquishing the need for continuous app monitoring.
Mark Vella, Christian Colombo 0001
SIN1
2018 Enhancing Virtual Machine Introspection-Based Memory Analysis with Event Triggers
abstract
Virtual Machine Introspection (VMI) has the potential to provide secure cloud monitoring, but its hardware level monitoring gives rise to the 'semantic gap', where software-level behaviour loses its meaning. Memory forensics tools can offer a deployment-ready solution as compared to automated semantics derivation techniques, in the form of an integrated VMI-memory forensics architecture. A pending issue concerns the appropriate points in time at which to execute memory analysis routines. Analysis is required to execute in a manner not to overwhelm virtual machines but neither to lose out on short-lived in-memory data structures. This paper presents an on-going study to address what we call the 'event semantic gap', or rather the lost semantics of software-level events associated with the monitored behaviour. As opposed to deriving these events directly from the hardware level, we argue that translating them at the software level to recognizable events at the hardware level is more pragmatic, thus providing a fully integrated VMI-memory forensics architecture. Dynamic binary instrumentation (DBI) is a key enabler and promising results are demonstrated for the Xen hypervisor.
Matthew Muscat, Mark Vella
CloudCom2
2018 Volatile memory-centric investigation of SMS-hijacked phones: a Pushbullet case study
abstract
Cloak-and-Dagger attacks targeting Android devices can completely hijack the UI feedback loop, with one possible consequence being that of hijacking SMS functionality for cybercrime purposes.What is of particular concern is that attackers can decouple stealth activities from SMS hijacking.Consequently the latter could be pulled off using completely legitimate apps that normally would allow users to manage text messages from their personal computers (SMSonPC), but this time all hidden away under attacker control.This work proposes a digital investigation process aiming to uncover SMS-hijacked devices.It uses bytecode instrumentation in order to force the dumping of volatile memory areas where evidence for the hijack can be located.Eventually both the malware that conceals the SMS-hijacking and the compromised or smuggled SMSonPC app can be identified.Preliminary results are presented using a case study based on the popular SMSonPC app: Pushbullet.
Mark Vella, Vishwas Rudramurthy
FedCSIS1
2017 Memory Forensics of Insecure Android Inter-app Communications
Mark Vella, Rachel Cilia
ICISSP1
2017 AndroNeo: Hardening Android Malware Sandboxes by Predicting Evasion Heuristics
Yonas Leguesse, Mark Vella, Joshua Ellul
WISTP2
2015 WeXpose: Towards on-Line Dynamic Analysis of Web Attack Payloads using Just-In-Time Binary Modification
abstract
Web applications constitute a prime target for attacks. A subset of these inject code into their targets, posing a threat to the entire hosting infrastructure rather than just to the compromised application. Existing web intrusion detection systems (IDS) are easily evaded when code payloads are obfuscated. Dynamic analysis in the form of instruction set emulation is a well-known answer to this problem, which however is a solution for off-line settings rather than the on-line IDS setting and cannot be used for all types of web attacks payloads. Host-based approaches provide an alternative, yet all of them impose runtime overheads. This work proposes just-in-time (JIT) binary modification complemented with payload-based heuristics for the provision of obfuscation-resistant web IDS at the network level. A number of case studies conducted with WeXpose, a prototype implementation of the technique, shows that JIT binary modification fits the on-line setting due to native instruction execution, while also isolating harmful attack side-effects that consequentially become of concern. Avoidance of emulation makes the approach relevant to all types of payloads, while payload-based heuristics provide practicality.
Jennifer Bellizzi, Mark Vella
SECRYPT2
2012 Distress Detection (Poster Abstract)
Mark Vella, Sotirios Terzis, Marc Roper
RAID1