Duy-Phuc Pham

dblp:232/0241 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2022
0000-0003-3149-0957ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2022 ULTRA: Ultimate Rootkit Detection over the Air
abstract
Rootkits are the most challenging malware threats against server and desktop systems. They are created by highly skilled actors and are deployed in advanced persistent threat attacks. Lately and even in the future, rootkits will become a real threat to billions of IoT devices. Existing malware detection techniques based on static or dynamic analysis face major shortcomings, which become more apparent when it is necessary to detect threats on IoT devices.
Duy-Phuc Pham, Damien Marion 0001, Annelie Heuser
RAID1
2021 Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware Classification
abstract
The Internet of Things (IoT) is constituted of devices that are exponentially growing in number and in complexity. They use numerous customized firmware and hardware, without taking into consideration security issues, which make them a target for cybercriminals, especially malware authors.
Duy-Phuc Pham, Damien Marion 0001, Matthieu Mastio, Annelie Heuser
ACSAC1
2021 Poster: Obfuscation Revealed - Using Electromagnetic Emanation to Identify and Classify Malware
abstract
In this poster we present a novel approach of using side channel information to identify the kinds of malware threats that are targeting IoT devices. Although in the presence of obfuscation techniques that can prevent static or symbolic binary analysis, a malware researcher may obtain detailed information about malware type and identification using our method by leveraging side channel by electromagnetism rather than software-layer malware analysis. By capturing 100,000 measurement traces from an IoT system infected with different malware samples, we can obtain this information without altering the actual hardware. As a result, it can be implemented without any overhead, regardless of the resources available. Furthermore, our method has the advantage of non-trivial for malware authors to avoid. We were able to distinguish malware families based on side-channel knowledge without being able to see what exact hardware was involved. We were able to predict three generic malware forms (and one benign class) with a 99.89% percent accuracy in our tests. Furthermore, our results show that we are able to classify altered malware samples with unseen obfuscation techniques during the training phase, and to determine what kind of obfuscations, which makes our approach particularly useful for malware analysts.
Duy-Phuc Pham, Damien Marion 0001, Annelie Heuser
EuroS&P1