André Ricardo Abed Grégio

dblp:115/4570 · also Andre Gregio, André Grégio · DBLP profile ↗
← Back
32ranked-venue papers
5as first author
13since 2021 · last 2023
0000-0003-1766-5757ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 1 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Computer networks · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorSystems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2023 Efficient Prequential AUC-PR Computation
abstract
When dealing with classification problems for data streams, we often need to compute the classification metrics in a prequential manner. The Area Under the Precision-Recall Curve (AUC-PR) metric is extensively used in imbalanced classification scenarios, where the negative class outnumbers the positive one. Despite its advantages, it may be computationally expensive to recompute that metric every time a new test instance becomes available. In this work, we present an efficient algorithm to compute the AUC-PR in a prequential way. Our proposed algorithm uses a self-balancing binary search tree to avoid the need to reorder the data when updating the AUC-PR value with the most recent data. Our experiments take into consideration six well-known, publicly available stream-based datasets. Our experiments show that our approach can be up to 13 times faster and use 12 times less energy than the traditional batch approach when considering a window of size 1,000.
David L. Pereira Gomes, André Ricardo Abed Grégio, Marco A. Z. Alves, Paulo R. L. Almeida
ICMLA2
2023 Fast & Furious: On the modelling of malware detection as an evolving data stream
abstract
Malware is a major threat to computer systems and imposes many challenges to cyber security. Targeted threats, such as ransomware, cause millions of dollars in losses every year. The constant increase of malware infections has been motivating popular antiviruses (AVs) to develop dedicated detection strategies, which include meticulously crafted machine learning (ML) pipelines. However, malware developers unceasingly change their samples' features to bypass detection. This constant evolution of malware samples causes changes to the data distribution (i.e., concept drifts) that directly affect ML model detection rates, something not considered in the majority of the literature work. In this work, we evaluate the impact of concept drift on malware classifiers for two Android datasets: DREBIN (about 130K apps) and a subset of AndroZoo (about 285K apps). We used these datasets to train an Adaptive Random Forest (ARF) classifier, as well as a Stochastic Gradient Descent (SGD) classifier. We also ordered all datasets samples using their VirusTotal submission timestamp and then extracted features from their textual attributes using two algorithms (Word2Vec and TF-IDF). Then, we conducted experiments comparing both feature extractors, classifiers, as well as four drift detectors (DDM, EDDM, ADWIN, and KSWIN) to determine the best approach for real environments. Finally, we compare some possible approaches to mitigate concept drift and propose a novel data stream pipeline that updates both the classifier and the feature extractor. To do so, we conducted a longitudinal evaluation by (i) classifying malware samples collected over nine years (2009-2018), (ii) reviewing concept drift detection algorithms to attest its pervasiveness, (iii) comparing distinct ML approaches to mitigate the issue, and (iv) proposing an ML data stream pipeline that outperformed literature approaches.
Fabricio Ceschin, Marcus Botacin, Heitor Murilo Gomes, Felipe Azevedo Pinage, Luiz Eduardo Soares de Oliveira, André Ricardo Abed Grégio
Expert Syst. Appl.6
2022 On Metadata Privacy in Instant Messaging
abstract
Users metadata collection is a concerning issue related to Instant Messaging (IM) due to the potential of privacy violation. Even with messages' content encryption, metadata such as relationships and other communication patterns are exchanged in clear text, incurring in information leakage. In this paper, we investigate popular IM solutions to identify existing metadata, propose a broader nomenclature encompassing similar information, and assess the impact of metadata leakage on users' privacy. We also present a hierarchy of metadata based on our proposed nomenclature to allow for fair comparison among related work and easy gathering of privacy needs of users.
Marlon Cordeiro Domenech, André Ricardo Abed Grégio, Luis C. E. Bona
ISCC2
2022 Dissecting Applications Uninstallers and Removers: Are They Effective?
Marcus Botacin, André Ricardo Abed Grégio
ISC2
2022 Why We Need a Theory of Maliciousness: Hardware Performance Counters in Security
Marcus Botacin, André Ricardo Abed Grégio
ISC2
2022 AntiViruses under the microscope: A hands-on perspective
Marcus Botacin, Felipe Duarte Domingues, Fabricio Ceschin, Raphael Machnicki, Marco A. Z. Alves, Paulo Lício de Geus, André Ricardo Abed Grégio
Comput. Secur.7
2022 HEAVEN: A Hardware-Enhanced AntiVirus ENgine to accelerate real-time, signature-based malware detection
Marcus Botacin, Marco A. Z. Alves, Daniela Oliveira 0001, André Ricardo Abed Grégio
Expert Syst. Appl.4
2022 A Praise for Defensive Programming: Leveraging Uncertainty for Effective Malware Mitigation
abstract
A promising avenue for improving the effectiveness of behavioral-based malware detectors is to leverage two-phase detection mechanisms. Existing problem in two-phase detection is that after the first phase produces borderline decision, suspicious behaviors are not well contained before the second phase completes. This article improvesChameleon, a framework to realize the uncertain environment.Chameleonoffers two environments: standard—for software identified as benign by the first phase, and uncertain—for software received borderline classification from the first phase. The uncertain environment adds obstacles to software execution through random perturbations applied probabilistically. We introduce a dynamic perturbation threshold that can target malware disproportionately more than benign software. We analyzed the effects of the uncertain environment by manually studying 113 software and 100 malware, and found that 92 percent malware and 10 percent benign software disrupted during execution. The results were then corroborated by an extended dataset (5,679 Linux malware samples) on a newer system. Finally, a careful inspection of the benign software crashes revealed some software bugs, highlightingChameleon's potential as a practical complementary anti-malware solution.
Ruimin Sun, Marcus Botacin, Nikolaos Sapountzis, Xiaoyong Yuan, Matt Bishop, Donald E. Porter, Xiaolin Li 0001, André Ricardo Abed Grégio, Daniela Oliveira 0001
IEEE Trans. Dependable Secur. Comput.8
2022 Terminator: A Secure Coprocessor to Accelerate Real-Time AntiViruses Using Inspection Breakpoints
abstract
AntiViruses (AVs) are essential to face the myriad of malware threatening Internet users. AVs operate in two modes: on-demand checks and real-time verification. Software-based real-time AVs intercept system and function calls to execute AV’s inspection routines, resulting in significant performance penalties as the monitoring code runs among the suspicious code. Simultaneously, dark silicon problems push the industry to add more specialized accelerators inside the processor to mitigate these integration problems. In this article, we propose Terminator , an AV-specific coprocessor to assist software AVs by outsourcing their matching procedures to the hardware, thus saving CPU cycles and mitigating performance degradation. We designed Terminator to be flexible and compatible with existing AVs by using YARA and ClamAV rules. Our experiments show that our approach can save up to 70 million CPU cycles per rule when outsourcing on-demand checks for matching typical, unmodified YARA rules against a dataset of 30 thousand in-the-wild malware samples. Our proposal eliminates the AV’s need for blocking the CPU to perform full system checks, which can now occur in parallel. We also designed a new inspection breakpoint mechanism that signals to the coprocessor the beginning of a monitored region, allowing it to scan the regions in parallel with their execution. Overall, our mechanism mitigated up to 44% of the overhead imposed to execute and monitor the SPEC benchmark applications in the most challenging scenario.
Marcus Botacin, Francis B. Moreira 0001, Philippe Olivier Alexandre Navaux, André Ricardo Abed Grégio, Marco A. Z. Alves
ACM Trans. Priv. Secur.4
2022 Learning Fast and Slow: Propedeutica for Real-Time Malware Detection
abstract
Existing malware detectors on safety-critical devices have difficulties in runtime detection due to the performance overhead. In this article, we introduce Propedeutica, a framework for efficient and effective real-time malware detection, leveraging the best of conventional machine learning (ML) and deep learning (DL) techniques. In Propedeutica, all software start executions are considered as benign and monitored by a conventional ML classifier for fast detection. If the software receives a borderline classification from the ML detector (e.g., the software is 50% likely to be benign and 50% likely to be malicious), the software will be transferred to a more accurate, yet performance demanding DL detector. To address spatial-temporal dynamics and software execution heterogeneity, we introduce a novel DL architecture (DeepMalware) for Propedeutica with multistream inputs. We evaluated Propedeutica with 9115 malware samples and 1338 benign software from various categories for the Windows OS. With a borderline interval of [30%, 70%], Propedeutica achieves an accuracy of 94.34% and a false-positive rate of 8.75%, with 41.45% of the samples moved for DeepMalwareanalysis. Even using only CPU, Propedeutica can detect malware within less than 0.1 s.
Ruimin Sun, Xiaoyong Yuan, Pan He, Qile Zhu, Aokun Chen, André Ricardo Abed Grégio, Daniela Oliveira 0001, Xiaolin Li 0001
IEEE Trans. Neural Networks Learn. Syst.6
2021 Family Matters: On the Investigation of [Malicious] Mobile Apps Clustering
Thalita Scharr Rodrigues Pimenta, Rafael Duarte Coelho dos Santos, André Ricardo Abed Grégio
ICCSA (3)3
2021 Challenges and pitfalls in malware research
Marcus Botacin, Fabricio Ceschin, Ruimin Sun, Daniela Oliveira 0001, André Ricardo Abed Grégio
Comput. Secur.5
2021 One Size Does Not Fit All: A Longitudinal Analysis of Brazilian Financial Malware
abstract
Malware analysis is an essential task to understand infection campaigns, the behavior of malicious codes, and possible ways to mitigate threats. Malware analysis also allows better assessment of attackers’ capabilities, techniques, and processes. Although a substantial amount of previous work provided a comprehensive analysis of the international malware ecosystem, research on regionalized, country-, and population-specific malware campaigns have been scarce. Moving towards addressing this gap, we conducted a longitudinal (2012-2020) and comprehensive (encompassing an entire population of online banking users) study of MS Windows desktop malware that actually infected Brazilian banks’ users. We found that the Brazilian financial desktop malware has been evolving quickly: it started to make use of a variety of file formats instead of typical PE binaries, relied on native system resources, and abused obfuscation techniques to bypass detection mechanisms. Our study on the threats targeting a significant population on the ecosystem of the largest and most populous country in Latin America can provide invaluable insights that may be applied to other countries’ user populations, especially those in the developing world that might face cultural peculiarities similar to Brazil’s. With this evaluation, we expect to motivate the security community/industry to seriously consider a deeper level of customization during the development of next-generation anti-malware solutions, as well as to raise awareness towards regionalized and targeted Internet threats.
Marcus Botacin, Hojjat Aghakhani, Stefano Ortolani, Christopher Krügel, Giovanni Vigna, Daniela Oliveira 0001, Paulo Lício de Geus, André Ricardo Abed Grégio
ACM Trans. Priv. Secur.8
2020 On the Security of Application Installers and Online Software Repositories
Marcus Botacin, Giovanni Bertão, Paulo Lício de Geus, André Ricardo Abed Grégio, Christopher Krügel, Giovanni Vigna
DIMVA4
2020 A Systematic Literature Mapping of Artificial Intelligence Planning in Software Testing
Luis F. de Lima, Letícia M. Peres, André Ricardo Abed Grégio, Fabiano Silva
ICSOFT3
2020 On the Challenges of Automated Testing of Web Vulnerabilities
abstract
Pentesting is an important process to reduce the risks associated with attacks in Web applications. However, testers may find some difficulties while conducting this process. This paper aims to discuss the main challenges founded while performing pentesting. For this, an exploratory study was conducted with five pentesting tools and seven Web applications. We analyzed and executed these tools and applications, and identified and evaluated some of their characteristics and functionalities. Preliminary results showed that one of the major challenges relates to pentesting tools execution in Web applications is the poor standardization of input parameters in the authentication process.
Luis F. de Lima, Matheus C. Horstmann, David N. Neto, André Ricardo Abed Grégio, Fabiano Silva, Letícia M. Peres
WETICE4
2020 We need to talk about antiviruses: challenges & pitfalls of AV evaluations
Marcus Botacin, Fabricio Ceschin, Paulo Lício de Geus, André Ricardo Abed Grégio
Comput. Secur.4
2020 ControlChain: A new stage on the IoT access control authorization
abstract
Summary The IoT is changing the way we interact with the world. Very soon, almost all of our daily tasks will be made through self intelligent systems embedded in devices scattered all around us. Their mission is to turn our cities, transportation systems, buildings, homes, and bodies in smart environments. These environments will bring us more comfort, improve our performance, increase our profits, and take away time‐consuming tasks. However, besides its great benefits, the IoT is also a big source of concerns, mainly because a good part of its devices will handle private and confidential information. Recently, cases of successful IoT invasions only worsen this scenario and show us that the today's adopted access control systems need to be replaced by more efficiently and secure ones. To overcome these access control problems, in this work, we present the ControlChain. The ControlChain is an access control authorization architecture that is heavily based on Blockchain technology. We also demonstrate the viability of the ControlChain through the E‐ControlChain, a proof‐of‐concept developed to run over the Ethereum network. Our proposals follows the IoT tendency requirements and are user‐transparent, user‐friendly, fully decentralized, scalable, fault tolerant, and compatible with a wide range of today's access control models already used in the IoT. Finally, we also make a cost and a performance analysis of E‐ControlChain, using a Raspberry Pi as an IoT device.
Otto Julio Ahlert Pinno, André Ricardo Abed Grégio, Luis C. E. Bona
Concurr. Comput. Pract. Exp.2
2019 The Internet Banking [in]Security Spiral: Past, Present, and Future of Online Banking Protection Mechanisms based on a Brazilian case study
abstract
Internet Banking have become the primary way of accessing banking services for most customers, but its security is still a constant concern, since million dollars are still lost every year due to frauds. Over time, banks and customers overcome the initial technology distrust and learned how to secure their operations. However, there are still many lessons to learn, mainly when looking to the upcoming technological developments. To understand the lessons learned over time and also to help shedding light on possible future developments, we review the past and the present of internet banking implementations in Brazil, a country widely adopting this type of service and an early adopter of new banking technologies, thus targeted by many threats. We show how Internet banking evolved from desktop software to mobile apps and how attackers also evolved from phishing mails to complete phishing applications to target Brazilian users. We also performed a detailed security analysis of Brazilian banking apps available in the Android app store and identified that developers still fail to follow secure development practices, thus causing banking apps to leak user's sensitive data. Moreover, we also looked to the future to present new attacks which can threat users in a short-term. In particular, we demonstrate an attack against a Whatsapp-based transaction mechanism implemented by some Brazilian banks
Marcus Botacin, Anatoli Kalysch, André Ricardo Abed Grégio
ARES3
2019 L(a)ying in (Test)Bed - How Biased Datasets Produce Impractical Results for Actual Malware Families' Classification
Tamy Beppler, Marcus Botacin, Fabricio Ceschin, Luiz Eduardo Soares de Oliveira, André Ricardo Abed Grégio
ISC5
2018 Lumus: Dynamically Uncovering Evasive Android Applications
Vitor Monte Afonso, Anatoli Kalysch, Tilo Müller, Daniela Oliveira 0001, André Ricardo Abed Grégio, Paulo Lício de Geus
ISC5
2018 Leveraging ontologies and machine-learning techniques for malware analysis into Android permissions ecosystems
Luiz C. Navarro, Alexandre K. W. Navarro, André Ricardo Abed Grégio, Anderson Rocha 0001, Ricardo Dahab
Comput. Secur.3
2018 Enhancing Branch Monitoring for Security Purposes: From Control Flow Integrity to Malware Analysis and Debugging
abstract
Malware and code-reuse attacks are the most significant threats to current systems operation. Solutions developed to countermeasure them have their weaknesses exploited by attackers through sandbox evasion and antidebug crafting. To address such weaknesses, we propose a framework that relies on the modern processors’ branch monitor feature to allow us to analyze malware while reducing evasion effects. The use of hardware assistance aids in increasing stealthiness, a key feature for debuggers, as modern software (malicious or benign) may be antianalysis armored. We achieve stealthier code execution control by using the branch monitor hardware’s inherent interrupt capabilities, keeping the code under execution intact. Previous works on branch monitoring have already addressed the ROP attack problem but require code injection and/or are limited in their capture window size. Therefore, we also propose a ROP detector without these limitations.
Marcus Botacin, Paulo Lício de Geus, André Ricardo Abed Grégio
ACM Trans. Priv. Secur.3
2017 ControlChain: Blockchain as a Central Enabler for Access Control Authorizations in the IoT
abstract
The IoT is pervading our daily activities and lives with devices scattered all over our cities, transport systems, buildings, homes and bodies. This invasion of devices with sensors and communication capabilities brings big concerns, mainly about the privacy and confidentiality of the collected information. These concerns hinder the wide adoption of the IoT. To overcome them, in this work, we present an Blockchain-based architecture for IoT access authorizations. Following the IoT tendency requirements, our architecture is user transparent, user friendly, fully decentralized, scalable, fault tolerant and compatible with a wide range of today's access control models used in the IoT. Finally, our architecture also has a secure way to establish relationships between users, devices and group of both, allowing the assignment of attributes for these relationships and their use in the access control authorization.
Otto Julio Ahlert Pinno, André Ricardo Abed Grégio, Luis C. E. Bona
GLOBECOM2
2017 Enhancing the Creation of Detection Rules for Malicious Software through Ontologies and Crowdsourcing
abstract
The analysis of malicious software (malware) is one of the hardest open problems in computer security, since there is a huge and varied number of samples produced daily. In addition,modern malicious programs have automatic mutation capabilities. Through behavior analysis of existing malware, we are able to understand new variants and develop new protection methods. Ontologies can be used to model those behaviors, enabling experts to define classes and rules that represent complex behaviors. In this paper, we used an ontology and architecture built during our previous studies as a starting point to inspire the development of a crowdsource-based framework and platform. The objective of this work is to explore crowdsourcing mechanisms to collaboratively evolve ontologies, in which users can propose new classes and rules that increasingly identify potential malicious programs. With a user-friendly platform, we expect to leverage a model that could be used in other malware analysis systems, as well as to quickly respond to new malware variants. Eight domain experts evaluated this platform with the goal of validating and identifying the platforms potentials and limitations.
Antonio Carlos de Marchi, André Ricardo Abed Grégio, Rodrigo Bonacin
WETICE2
2015 Toward a Taxonomy of Malware Behaviors
abstract
Malicious code attacks pose a serious threat to the security of information systems, as malware evolved from innocuous conceptual software to advanced and destructive cyber weapons. However, there is still the lack of a comprehensive and useful taxonomy to classify malware according to their behavior, since commonly used names are obsolete and unable to handle the complex and multipurpose currently observed samples. In this article, we present a brief survey on available malware taxonomies, discuss about issues on existing naming schemes and introduce an extensible taxonomy consisting of an initial set of behaviors usually exhibited by malware during an infection. The main goal of our proposed taxonomy is to address the menace of potentially malicious programs based on their observed behaviors, thus aiding in incident response procedures. Finally, we present a case study to evaluate our behavior-centric taxonomy, in which we apply identification patterns extracted from the proposed taxonomy to over 12 thousand known malware samples. The leveraged results show that it is possible to screen malicious programs that exhibit suspicious behaviors, even when they remain undetected by antivirus tools.
André Ricardo Abed Grégio, Vitor Monte Afonso, Dario Simões Fernandes Filho, Paulo Lício de Geus, Mário Jino
Comput. J.1
2014 Ontology for Malware Behavior: A Core Model Proposal
abstract
The ubiquity of Internet-connected devices motivates attackers to create malicious programs (malware) to exploit users and their systems. Malware detection requires a deep understanding of their possible behaviors, one that is detailed enough to tell apart suspicious programs from benign, legitimate ones. A step to effectively address the malware problem leans toward the development of an ontology. Current efforts are based on an obsolete hierarchy of malware classes that defines a malware family by one single prevalent behavior (e.g., viruses infect other files, worms spread and exploit remote systems autonomously, Trojan horses disguise themselves as benign programs, and so on). In order to address the detection of modern, complex malware families whose infections involve sets of multiple exploit methods, we need an ontology broader enough to deal with these suspicious activities performed on the victim's system. In this paper, we propose a core model for a novel malware ontology that is based on their exhibited behavior, filling a gap in the field.
André Ricardo Abed Grégio, Rodrigo Bonacin, Olga Nabuco, Vitor Monte Afonso, Paulo Lício de Geus, Mário Jino
WETICE1
2012 Tracking Memory Writes for Malware Classification and Code Reuse Identification
André Ricardo Abed Grégio, Paulo Lício de Geus, Christopher Krügel, Giovanni Vigna
DIMVA1
2012 A hybrid framework to analyze web and OS malware
abstract
Malicious programs (malware) cause serious security issues to home users and even to highly secured enterprise systems. The main infection vector currently used by attackers is the Internet. To improve the detection rate and to develop protection mechanisms, it is very important to analyze and study these threats. To this end, several systems were developed to perform malware analysis, which support operating system (OS) programs or Web codes, but they all suffer from limitations. Also, the existing systems focus only on one type of malware, those that target the OS or that require a Web browser. In this article, we propose a framework that is able to analyze Web and OS-based malware, which provides better detection rates and a broader range of malware types analysis. We have also evaluated and compared our analysis results to the state-of-the-art systems, presenting the advantages of the developed framework over them when regarding Web and OS-based malware.
Vitor Monte Afonso, Dario Simões Fernandes Filho, André Ricardo Abed Grégio, Paulo Lício de Geus, Mário Jino
ICC3
2012 Pinpointing Malicious Activities through Network and System-Level Malware Execution Behavior
André Ricardo Abed Grégio, Vitor Monte Afonso, Dario Simões Fernandes Filho, Paulo Lício de Geus, Mário Jino, Rafael Duarte Coelho dos Santos
ICCSA (4)1
2012 Interactive, Visual-Aided Tools to Analyze Malware Behavior
André Ricardo Abed Grégio, Alexandre Or Cansian Baruque, Vitor Monte Afonso, Dario Simões Fernandes Filho, Paulo Lício de Geus, Mário Jino, Rafael Duarte Coelho dos Santos
ICCSA (4)1
2012 A Malware Detection System Inspired on the Human Immune System
Isabela L. Oliveira, André Ricardo Abed Grégio, Adriano Mauro Cansian
ICCSA (4)2