VLDB 2026 Research / reviewers in the wild / expert
Nedim Srndic
dblp:50/10639
· DBLP profile ↗
7ranked-venue papers
3as first author
2since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | WoRMA '22: 1st Workshop on Robust Malware AnalysisabstractMalware is a term used for computer software created for malicious purposes. The rise of malware has closely followed the rise of computers in the society, and in~2022 it represents a ubiquitous threat in the digital world, impacting individuals, organizations and governments. As a reaction to the emergence of malware, the new research direction malware analysis was established. Unlike most other domains of computer science, malware analysis operates in an actively adversarial environment, where the potential reward for attackers is very high, and their maneuvering space is ample. Under such conditions, an arms race has arisen between attackers and defenders. A crucial condition necessary to prevail in this race is the research of robust methods and solutions. The goal of this workshop is to bring together leading researchers in the field in a joint forum for advancing the robustness of malware analysis. Fabio Pierazzi, Nedim Srndic |
AsiaCCS | 2 |
| 2021 | Detection of illicit cryptomining using network metadataabstractAbstract Illicit cryptocurrency mining has become one of the prevalent methods for monetization of computer security incidents. In this attack, victims’ computing resources are abused to mine cryptocurrency for the benefit of attackers. The most popular illicitly mined digital coin is Monero as it provides strong anonymity and is efficiently mined on CPUs.Illicit mining crucially relies on communication between compromised systems and remote mining pools using the de facto standard protocol Stratum. While prior research primarily focused on endpoint-based detection of in-browser mining, in this paper, we address network-based detection of cryptomining malware in general. We propose XMR-Ray, a machine learning detector using novel features based on reconstructing the Stratum protocol from raw NetFlow records. Our detector is trained offline using only mining traffic and does not require privacy-sensitive normal network traffic, which facilitates its adoption and integration.In our experiments, XMR-Ray attained 98.94% detection rate at 0.05% false alarm rate, outperforming the closest competitor. Our evaluation furthermore demonstrates that it reliably detects previously unseen mining pools, is robust against common obfuscation techniques such as encryption and proxies, and is applicable to mining in the browser or by compiled binaries. Finally, by deploying our detector in a large university network, we show its effectiveness in protecting real-world systems. Michele Russo, Nedim Srndic, Pavel Laskov |
EURASIP J. Inf. Secur. | 2 |
| 2016 | Hidost: a static machine-learning-based detector of malicious filesabstractMalicious software, i.e., malware, has been a persistent threat in the information security landscape since the early days of personal computing. The recent targeted attacks extensively use non-executable malware as a stealthy attack vector. There exists a substantial body of previous work on the detection of non-executable malware, including static, dynamic, and combined methods. While static methods perform orders of magnitude faster, their applicability has been hitherto limited to specific file formats. This paper introduces Hidost, the first static machine-learning-based malware detection system designed to operate on multiple file formats . Extending a previously published, highly effective method, it combines the logical structure of files with their content for even better detection accuracy. Our system has been implemented and evaluated on two formats, PDF and SWF (Flash). Thanks to its modular design and general feature set, it is extensible to other formats whose logical structure is organized as a hierarchy. Evaluated in realistic experiments on timestamped datasets comprising 440,000 PDF and 40,000 SWF files collected during several months, Hidost outperformed all antivirus engines deployed by the website VirusTotal to detect the highest number of malicious PDF files and ranked among the best on SWF malware. Nedim Srndic, Pavel Laskov |
EURASIP J. Inf. Secur. | 1 |
| 2014 | Practical Evasion of a Learning-Based Classifier: A Case StudyabstractLearning-based classifiers are increasingly used for detection of various forms of malicious data. However, if they are deployed online, an attacker may attempt to evade them by manipulating the data. Examples of such attacks have been previously studied under the assumption that an attacker has full knowledge about the deployed classifier. In practice, such assumptions rarely hold, especially for systems deployed online. A significant amount of information about a deployed classifier system can be obtained from various sources. In this paper, we experimentally investigate the effectiveness of classifier evasion using a real, deployed system, PDFrate, as a test case. We develop a taxonomy for practical evasion strategies and adapt known evasion algorithms to implement specific scenarios in our taxonomy. Our experimental results reveal a substantial drop of PDFrate's classification scores and detection accuracy after it is exposed even to simple attacks. We further study potential defense mechanisms against classifier evasion. Our experiments reveal that the original technique proposed for PDFrate is only effective if the executed attack exactly matches the anticipated one. In the discussion of the findings of our study, we analyze some potential techniques for increasing robustness of learning-based systems against adversarial manipulation of data. Nedim Srndic, Pavel Laskov |
IEEE Symposium on Security and Privacy | 1 |
| 2013 | Detection of Malicious PDF Files Based on Hierarchical Document Structure
Nedim Srndic, Pavel Laskov |
NDSS | 1 |
| 2013 | Evasion Attacks against Machine Learning at Test Time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndic, Pavel Laskov, Giorgio Giacinto, Fabio Roli |
ECML/PKDD (3) | 5 |
| 2011 | Static detection of malicious JavaScript-bearing PDF documentsabstractDespite the recent security improvements in Adobe's PDF viewer, its underlying code base remains vulnerable to novel exploits. A steady flow of rapidly evolving PDF malware observed in the wild substantiates the need for novel protection instruments beyond the classical signature-based scanners. In this contribution we present a technique for detection of JavaScript-bearing malicious PDF documents based on static analysis of extracted JavaScript code. Compared to previous work, mostly based on dynamic analysis, our method incurs an order of magnitude lower run-time overhead and does not require special instrumentation. Due to its efficiency we were able to evaluate it on an extremely large real-life dataset obtained from the VirusTotal malware upload portal. Our method has proved to be effective against both known and unknown malware and suitable for large-scale batch processing. Pavel Laskov, Nedim Srndic |
ACSAC | 2 |