Siru Yang

dblp:282/6239 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 91% Program analysis · 9%
Network and information security
1 paper
Malware analysis · 100%
Databases, data mining, and information retrieval
1 paper
Data mining · 50% Web and social media mining · 50%

Topics — the 7 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis › mobile malware detection
android malware detection
0.512021
IntDroid: Android Malware Detection Based on API Intimacy Analysis · ACM Trans. Softw. Eng. Methodol. 2021
Software maintenance and evolution
code clone detection
0.412020
SCDetector: Software Functional Clone Detection Based on Semantic Tokens Analysis · ASE 2020
Software maintenance and evolution › code clone detection
semantic code clone detection
0.412020
SCDetector: Software Functional Clone Detection Based on Semantic Tokens Analysis · ASE 2020
Software maintenance and evolution › code clone detection
token-based clone detection
0.412020
SCDetector: Software Functional Clone Detection Based on Semantic Tokens Analysis · ASE 2020
Data mining › structured data mining
graph mining
0.112021
IntDroid: Android Malware Detection Based on API Intimacy Analysis · ACM Trans. Softw. Eng. Methodol. 2021
Web and social media mining
social network analysis
0.112021
IntDroid: Android Malware Detection Based on API Intimacy Analysis · ACM Trans. Softw. Eng. Methodol. 2021
Program analysis › static analysis
semantics-based program analysis
0.112020
SCDetector: Software Functional Clone Detection Based on Semantic Tokens Analysis · ASE 2020

Methods — techniques the papers use, named apart from their topics

social network centrality analysis · 1.0call graph analysis · 1.0semantic token analysis · 0.4graph matching · 0.4
YearPublicationVenuePosition
2021 IntDroid: Android Malware Detection Based on API Intimacy Analysis
abstract
Android, the most popular mobile operating system, has attracted millions of users around the world. Meanwhile, the number of new Android malware instances has grown exponentially in recent years. On the one hand, existing Android malware detection systems have shown that distilling the program semantics into a graph representation and detecting malicious programs by conducting graph matching are able to achieve high accuracy on detecting Android malware. However, these traditional graph-based approaches always perform expensive program analysis and suffer from low scalability on malware detection. On the other hand, because of the high scalability of social network analysis, it has been applied to complete large-scale malware detection. However, the social-network-analysis-based method only considers simple semantic information (i.e., centrality) for achieving market-wide mobile malware scanning, which may limit the detection effectiveness when benign apps show some similar behaviors as malware. In this article, we aim to combine the high accuracy of traditional graph-based method with the high scalability of social-network-analysis--based method for Android malware detection. Instead of using traditional heavyweight static analysis, we treat function call graphs of apps as complex social networks and apply social-network--based centrality analysis to unearth the central nodes within call graphs. After obtaining the central nodes, the average intimacies between sensitive API calls and central nodes are computed to represent the semantic features of the graphs. We implement our approach in a tool called IntDroid and evaluate it on a dataset of 3,988 benign samples and 4,265 malicious samples. Experimental results show that IntDroid is capable of detecting Android malware with an F-measure of 97.1% while maintaining a True-positive Rate of 99.1%. Although the scalability is not as fast as a social-network-analysis--based method (i.e., MalScan ), compared to a traditional graph-based method, IntDroid is more than six times faster than MaMaDroid . Moreover, in a corpus of apps collected from GooglePlay market, IntDroid is able to identify 28 zero-day malware that can evade detection of existing tools, one of which has been downloaded and installed by more than ten million users. This app has also been flagged as malware by six anti-virus scanners in VirusTotal, one of which is Symantec Mobile Insight .
Deqing Zou, Yueming Wu 0001, Siru Yang, Anki Chauhan, Wei Yang 0013, Jiangying Zhong, Shihan Dou, Hai Jin 0001
ACM Trans. Softw. Eng. Methodol.3
2020 SCDetector: Software Functional Clone Detection Based on Semantic Tokens Analysis
abstract
Code clone detection is to find out code fragments with similar functionalities, which has been more and more important in software engineering. Many approaches have been proposed to detect code clones, in which token-based methods are the most scalable but cannot handle semantic clones because of the lack of consideration of program semantics. To address the issue, researchers conduct program analysis to distill the program semantics into a graph representation and detect clones by matching the graphs. However, such approaches suffer from low scalability since graph matching is typically time-consuming.
Yueming Wu 0001, Deqing Zou, Shihan Dou, Siru Yang, Wei Yang 0013, Hai Jin 0001
ASE4