VLDB 2026 Research / reviewers in the wild / expert
Dima Rabadi
dblp:183/1352
· DBLP profile ↗
5ranked-venue papers
4as first author
2since 2021 · last 2025
0000-0001-8067-1995ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | FETA: A systematic and efficient approach for feature engineering on anti-static and anti-dynamic malware analysisabstractMalware detection is a critical but very challenging task in cybersecurity. The eternal competition between malware authors (cyber attackers) and security analysts (detectors) is a never-ending game in which malware evolves rapidly and becomes more sophisticated as cyber attackers constantly evolve their tactics to evade detection. Such competition raises the demand for new automated malware detection techniques to keep pace with malware evolution and address sophisticated malware. This paper presents an empirical study that analyzes the effectiveness of static and dynamic features using machine learning algorithms. We propose FETA, a systematic approach for F eature E ngineering on anti-s T atic and anti-dyn A mic malware analysis. FETA combines static and dynamic features through feature aggregation and model integration techniques to improve detection accuracy and robustness. Extensive experiments on a real-world dataset show that the aggregation of static and dynamic features outperforms individual feature sets, achieving a detection rate of 98.06%. Additionally, we provide insights into feature selection and conduct a deep analysis of misclassified samples. This research contributes to the development of more effective and efficient malware detection techniques for enhanced cybersecurity. Dima Rabadi, Jia Yi Loo, Amudha Narayanan, Sin G. Teo, Tram Truong Huu |
J. Inf. Secur. Appl. | 1 |
| 2023 | Fast and Efficient Malware Detection with Joint Static and Dynamic Features Through Transfer Learning
Mao V. Ngo, Tram Truong Huu, Dima Rabadi, Jia Yi Loo, Sin G. Teo |
ACNS (1) | 3 |
| 2020 | Advanced Windows Methods on Malware Detection and ClassificationabstractApplication Programming Interfaces (APIs) are still considered the standard accessible data source and core wok of the most widely adopted malware detection and classification techniques. API-based malware detectors highly rely on measuring API’s statistical features, such as calculating the frequency counter of calling specific API calls or finding their malicious sequence pattern (i.e., signature-based detectors). Using simple hooking tools, malware authors would help in failing such detectors by interrupting the sequence and shuffling the API calls or deleting/inserting irrelevant calls (i.e., changing the frequency counter). Moreover, relying on API calls (e.g., function names) alone without taking into account their function parameters is insufficient to understand the purpose of the program. For example, the same API call (e.g., writing on a file) would act in two ways if two different arguments are passed (e.g., writing on a system versus user file). However, because of the heterogeneous nature of API arguments, most of the available API-based malicious behavior detectors would consider only the API calls without taking into account their argument information (e.g., function parameters). Alternatively, other detectors try considering the API arguments in their techniques, but they acquire having proficient knowledge about the API arguments or powerful processors to extract them. Such requirements demand a prohibitive cost and complex operations to deal with the arguments. To overcome the above limitations, with the help of machine learning and without any expert knowledge of the arguments, we propose a light-weight API-based dynamic feature extraction technique, and we use it to implement a malware detection and type classification approach. To evaluate our approach, we use reasonable datasets of 7774 benign and 7105 malicious samples belonging to ten distinct malware types. Experimental results show that our type classification module could achieve an accuracy of , where our malware detection module could reach an accuracy of over , and outperforms many state-of-the-art API-based malware detectors. Dima Rabadi, Sin G. Teo |
ACSAC | 1 |
| 2019 | Resilient Clock Synchronization Using Power Grid VoltageabstractMany clock synchronization protocols based on message passing, e.g., the Network Time Protocol (NTP), assume symmetric network delays to estimate the one-way packet transmission time as half of the round-trip time. As a result, asymmetric network delays caused by either network congestion or malicious packet delays can cause significant synchronization errors. This article exploits sinusoidal voltage signals of an alternating current (AC) power grid to limit the impact of the asymmetric network delays on these clock synchronization protocols. Our extensive measurements show that the voltage signals at geographically distributed locations in a city are highly synchronized. Leveraging calibrated voltage phases, we develop a new clock synchronization protocol that we call Grid Time Protocol (GTP), which allows direct measurement of one-way packet transmission times between its slave and master nodes, subject to an analytic condition that can be easily verified in practice. The direct measurements render GTP resilient against asymmetric network delays under this condition. A prototype implementation of GTP maintains sub-millisecond synchronization accuracy for two nodes tens of kilometers apart in the presence of malicious packet delays. The result has been demonstrated for both Singapore and Hangzhou, China. Simulations driven by real network delay measurements between Singapore and Hangzhou under both normal and congested network conditions also show the synchronization accuracy improvement by GTP. We believe that GTP is suitable for grid-connected distributed systems that are currently served by NTP but desire higher resilience against unfavorable network dynamics and packet delay attacks. Dima Rabadi, Rui Tan 0001, David K. Y. Yau, Sreejaya Viswanathan, Peng Cheng 0001 |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2017 | Taming Asymmetric Network Delays for Clock Synchronization Using Power Grid VoltageabstractMany clock synchronization protocols based on message passing, e.g., the Network Time Protocol (NTP), assume symmetric network delays to estimate the one-way packet transmission time as half of the round-trip time. As a result, asymmetric network delays caused by either %natural one-way network congestion or malicious packet delays can cause significant synchronization errors. This paper exploits sinusoidal voltage signals of an alternating current (ac) power grid to tame the asymmetric network delays for robust and resilient clock synchronization. Our extensive measurements show that the voltage signals at geographically distributed locations in a city are highly synchronized. Leveraging calibrated voltage phases, we develop a new clock synchronization protocol, which we call Grid Time Protocol (GTP), that allows direct measurement of one-way packet transmission times between its slave and master nodes, under an analytic condition that can be easily verified in practice. The direct measurements render GTP resilient against asymmetric network delays under this condition. A prototype implementation of GTP, based on readily available ac/ac transformers and PC-grade sound cards as voltage signal sampling devices, maintains sub-ms synchronization accuracy for two nodes 30 km apart, in the presence of malicious packet delays. We believe that GTP is suitable for grid-connected distributed systems that are currently served by NTP but desire higher resilience against network dynamics and packet delay attacks. Dima Rabadi, Rui Tan 0001, David K. Y. Yau, Sreejaya Viswanathan |
AsiaCCS | 1 |