Neha Sharma 0007

dblp:25/9554-7 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0001-5620-4465ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 LeakyDroid: A lightweight method for detecting zero-day leaky Android applications using One-Class Graph Neural Networks
abstract
In the current era of mobile technology, ensuring user data security and privacy is very important, particularly with the rise of malicious Android applications that aim to leak end-user data. Moreover, the popularity of the Android OS is resulting in growing numbers of such malicious Android applications. Hackers make the apps malicious by downloading the source code of Android applications and modifying it. Static analysis techniques have traditionally been used to detect such leaky Android applications. However, these methods cannot simulate runtime behaviours, leading to false positives or negatives. Moreover, obfuscated code is also harder to analyse using this technique. On the other hand, dynamic analysis-based methods are used to overcome these issues because they capture the application’s actual behaviour during runtime. However, dynamic analysis methods have high computational complexity. To fill this gap, we propose LeakyDroid , a static but lightweight method for detecting zero-day leaky Android applications using one-class graph neural networks. LeakyDroid distinguishes between the zero-day malicious and genuine versions of Android applications based on function calls inside various class files of the installable APK files. LeakyDroid generates a control flow graph from function calls from several versions of normal APK files of the same application. The graph is trained using OCGNN, which effectively captures relationships and invocation patterns of normal APK files. While testing an unknown version of the same application’s APK, if a considerable deviation is seen from normal behaviour, the application is detected as malicious. We evaluated the performance of LeakyDroid on three applications, namely WhatsApp, Netflix, and Instagram, each with approximately 25 benign and a few malicious and leaky versions. LeakyDroid successfully detected all the malicious versions of APK with no false positives.
Neha Sharma 0007, Mayank Swarnkar, Shaan Kumar
J. Inf. Secur. Appl.1
2025 DLAZE: Detecting DNS Tunnels Using Lightweight and Accurate Method for Zero-Day Exploits
abstract
Domain Name System (DNS) protocol is highly targeted nowadays for creating tunnels and extracting information from the intended machines. The reason for such exploitation is that DNS is passed unchecked by most firewalls and Intrusion Detection Systems (IDSs) to maintain the network’s quality of service. Most detection methods utilize the signatures of tunneled queries and tools for DNS tunnel detection. However, the new or updated tool versions bypass these signature-based methods. Moreover, DNS generally comprises a significant portion of total network traffic with a skewed distribution of legitimate DNS traffic against DNS tunnels. Thus, checking each DNS packet against signatures is a bottleneck to the efficiency of the network. To resolve this problem, we propose DLAZE, which can efficiently detect known and unknown DNS tunnels in the network traffic without compromising the efficiency of the network. DLAZE consists of a three-layer system. The first layer utilizes our already proposed work OptiTuneD, which filters out nearly all legitimate DNS packets with linear time complexity and solves the problem of the skewed distribution of legitimate vs tunneled DNS. The remaining packets are passed to the second layer, which uses the Bidirectional Encoder Representations from Transformers (BERT) model to identify legitimate DNS packets that remained unidentified at the first layer with the quadratic time complexity. The third layer obtains only unknown or zero-day DNS packets that can be legitimate or tunnels, which are differentiated using the Probing method with constant time complexity. We tested DLAZE using three publicly available datasets. The experimental results show that the average recall, precision, and F1-score obtained on all three datasets are 98.74%, 97.46%, and 97.95%, respectively, with the average processing time for each DNS packet as 473.25 milliseconds.
Neha Sharma 0007, Mayank Swarnkar, Divyanshu
IEEE Trans. Netw. Serv. Manag.1
2024 OptiClass: An Optimized Classifier for Application Layer Protocols Using Bit Level Signatures
abstract
Network traffic classification has many applications, such as security monitoring, quality of service, traffic engineering, and so on. For the aforementioned applications, Deep Packet Inspection (DPI) is a popularly used technique for traffic classification because it scrutinizes the payload and provides comprehensive information for accurate analysis of network traffic. However, DPI-based methods reduce network performance because they are computationally expensive and hinder end-user privacy as they analyze the payload. To overcome these challenges, bit-level signatures are significantly used to perform network traffic classification. However, most of these methods still need to improve performance as they perform one-by-one signature matching of unknown payloads with application signatures for classification. Moreover, these methods become stagnant with the increase in application signatures. Therefore, to fill this gap, we propose OptiClass , an optimized classifier for application protocols using bit-level signatures. OptiClass performs parallel application signature matching with unknown flows, which results in faster, more accurate, and more efficient network traffic classification. OptiClass achieves twofold performance gains compared to the state-of-the-art methods. First, OptiClass generates bit-level signatures of just 32 bits for all the applications. This keeps OptiClass swift and privacy-preserving. Second, OptiClass uses a novel data structure called BiTSPLITTER for signature matching for fast and accurate classification. We evaluated the performance of OptiClass on three datasets consisting of twenty application protocols. Experimental results report that OptiClass has an average recall, precision, and F1-score of 97.36%, 97.38%, and 97.37%, respectively, and an average classification speed of 9.08 times faster than five closely related state-of-the-art methods.
Mayank Swarnkar, Neha Sharma 0007
ACM Trans. Priv. Secur.2