VLDB 2026 Research / reviewers in the wild / expert
Asma Razgallah
dblp:285/5211
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Comparing the Effectiveness of Static, Dynamic and Hybrid Malware Detection on a Common DatasetabstractThe detection of malicious Android applications is a major security challenge. A number of machine learning-based techniques have been put forth, and some of them have attained great accuracy. However, the diversity of apps and frequency at which new malware families are found means that the issue remains unresolved. In this paper, we use both static, dynamic and hybrid analysis to automatically classify Android apps as benign or infected. We compare all three approaches on a common dataset — the TwinDroid dataset which contains over 15,000 system call traces from over 9,000 benign and infected app. This method allows comparison on equal footing. We make further contributions on the topic of feature selection and trace abstraction. Asma Razgallah, Raphaël Khoury, Kobra Khanmohammadi, Christophe Pere |
SMC | 1 |
| 2022 | TwinDroid: A Dataset of Android app System call traces and Trace Generation PipelineabstractSystem call traces are an invaluable source of information about a program's runtime behavior and be particularly useful for malware detection in Android apps. However, the paucity of publicly available high-quality datasets hinders the development of the field. In this paper, we introduce TwinDroid, a dataset of over 1000 system calls traces, from both benign and infected Android apps. A large part of the apps used to create the dataset is from benign-malicious app pairs, identical apart from the inclusion of malware in the latter. This makes TwinDroid an ideal basis for security research, and an earlier version of TwinDroid has already been used for this purpose. In addition to a dataset of traces, TwinDroid includes a fully automated traces generation pipeline, which allows users to generate new traces in a standardized manner seamlessly. This pipeline will enable the dataset to remain up-to-date and relevant despite the rapid pace of change that characterizes Android security. Asma Razgallah, Raphaël Khoury, Jean-Baptiste Poulet |
MSR | 1 |
| 2021 | Behavioral classification of Android applications using system callsabstractThe exponential growth in the number of Android applications on the market has been matching with a corresponding growth in malicious application. Of particular concern is the risk of application repackaging, a process by which cy-bercriminals downloads, modifies and republishes an application that already exists on the store with the addition of malicious code. Dynamic detection in system call traces, based on machine learning models has emerged as a promising solution. In this paper, we introduce a novel abstraction process, and demonstrate that it improves the classification process by replicating multiples malware detection techniques from the literature. We further propose a novel classification method, based on our observation that malware triggers specific system calls at different points than benign programs. We further make our dataset available for future researchers. Asma Razgallah, Raphaël Khoury |
APSEC | 1 |