VLDB 2026 Research / reviewers in the wild / expert
Michael Sandborn
dblp:316/4140
· DBLP profile ↗
1ranked-venue papers
1as first author
1since 2021 · last 2024
0000-0001-8592-6758ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Malware analysis · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Operating systems · 100% |
Topics — the 2 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Malware analysis
automated malware analysis |
0.8 | 1 | 2024 | Reducing Malware Analysis Overhead With Coverings · IEEE Trans. Dependable Secur. Comput. 2024 |
Operating systems › virtualization
virtual machine introspection |
0.2 | 1 | 2024 | Reducing Malware Analysis Overhead With Coverings · IEEE Trans. Dependable Secur. Comput. 2024 |
Methods — techniques the papers use, named apart from their topics
covering configuration selection · 1.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Reducing Malware Analysis Overhead With CoveringsabstractThere is a substantial and growing body of malware samples that evade automated analysis and detection tools. Malware may measure fingerprints (“artifacts”) of the underlying analysis tool or environment, and change their behavior when such artifacts are detected. While analysis tools can mitigate artifacts to reduce exposure, such concealment is expensive and limits scalable automated malware analysis. However, not every sample checks for every type of artifact—analysis efficiency can be improved by mitigating only those artifacts most likely to be used by a sample. Using that insight, we proposeMimosa, a system that identifies a small set of “covering” configurations that collectively and efficiently defeat most malware samples in a corpus.Mimosaidentifies a set of configurations that maximize analysis throughput and detection accuracy while minimizing manual effort, enabling scalable automation for analyzing stealthy malware. We evaluate our approach against a benchmark of 1535 meticulously labeled stealthy malware samples. We further test our approach on an additional set of 1221 stealthy malware samples and successfully analyze nearly 99% of them using only 2 VM backends.Mimosaprovides a practical, tunable method for efficiently deploying malware analysis resources. Michael Sandborn, Zach Stoebner, Westley Weimer, Stephanie Forrest, Ryan E. Dougherty, Jules White, Kevin Leach |
IEEE Trans. Dependable Secur. Comput. | 1 |