VLDB 2026 Research / reviewers in the wild / expert
P. Vinod 0001
dblp:60/6873-1 · also Vinod P 0001, Vinod P. 0001, Vinod Puthuvath
· DBLP profile ↗
43ranked-venue papers
2as first author
31since 2021 · last 2026
0000-0001-6078-2014ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 1 first-author · 14 since 2021Computer networks · 6 · 4 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Systems, architecture and hardware · 5 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | X-NetIntrospector: A next-generation explainable intelligence framework for secure network introspection in virtualized environment
Preeti Mishra, P. Vinod 0001, Mauro Conti |
Comput. Networks | 3 |
| 2026 | How secure is forgetting? Linking machine unlearning to machine learning attacksabstractAs Machine Learning (ML) continues to evolve, so does the sophistication of security threats targeting data privacy and model integrity. In response, Machine Unlearning (MU) has emerged as a promising paradigm that enables the selective removal of data influence from trained models. By supporting compliance with privacy regulations (such as the GDPR’s right to be forgotten) and facilitating model refinement, MU holds significant practical and legal value. Additionally, MU effective deployment introduces new security concerns. In real-world settings, malicious actors may exploit vulnerabilities in MU mechanisms, such as incomplete or inaccurate data removal, to infer deleted information, reintroduce adversarial behavior, or manipulate model updates. These risks highlight the urgency of understanding how classical ML threats relate to the design and operation of MU systems. However, despite its growing relevance, this intersection remains underexplored. In this article, we present a structured analysis of four major attack classes in ML (Backdoor Attacks, Membership Inference Attacks, Adversarial Attacks, and Inversion Attacks) and examine their implications for MU across multiple dimensions: (i) as direct threats targeting MU mechanisms, (ii) as challenges that MU can potentially mitigate, (iii) as evaluation metrics to measure the effectiveness and performance of MU techniques, and (iv) as verification factors to validate the success and completeness of the Unlearning process. We note that not all attacks exhibit all these perspectives simultaneously; their relevance varies depending on the attack characteristics and MU scenario. We also propose a novel classification that reflects how these attacks are typically employed in this context. Finally, we identify open challenges, including ethical considerations, and highlight promising directions for future research to advance secure and privacy-preserving Machine Unlearning. Muhammed Shafi K. P., Serena Nicolazzo, Antonino Nocera, P. Vinod 0001 |
Neurocomputing | 4 |
| 2026 | Context-aware behavioral authentication and privacy preservation in smartphones: Taxonomy and open research issues
Susmi Jacob, P. Vinod 0001, Sajana T. S. |
Multim. Tools Appl. | 2 |
| 2025 | SeCTIS: A framework to Secure CTI SharingabstractThe rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof. Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, P. Vinod 0001 |
Future Gener. Comput. Syst. | 7 |
| 2025 | SecDefender: Detecting low-quality models in multidomain federated learning systems
K. M. Sameera, Arnaldo Sgueglia, P. Vinod 0001, Rafidha Rehiman K. A., Corrado Aaron Visaggio, Andrea Di Sorbo, Mauro Conti |
Future Gener. Comput. Syst. | 3 |
| 2025 | DroidTTP: Mapping android applications with TTP for Cyber Threat IntelligenceabstractThe widespread use of Android devices for sensitive operations has made them prime targets for sophisticated cyber threats, including Advanced Persistent Threats (APT). Traditional malware detection methods focus primarily on malware classification, often failing to reveal the Tactics, Techniques, and Procedures (TTPs) used by attackers. To address this issue, we propose DroidTTP, a novel system for mapping Android malware to attack behaviors. We curated a dataset linking Android applications to Tactics and Techniques and developed an automated mapping approach using the Problem Transformation Approach and Large Language Models (LLMs). Our pipeline includes dataset construction, feature selection, data augmentation, model training, and explainability via SHAP. Furthermore, we explored the use of LLMs for TTP prediction using both Retrieval Augmented Generation and fine-tuning strategies. The Label Powerset XGBoost model achieved the best performance, with Jaccard Similarity scores of 0.9893 for Tactic classification and 0.9753 for Technique classification. The fine-tuned LLaMa model also performed competitively, achieving 0.9583 for Tactics and 0.9348 for Techniques. Although XGBoost slightly outperformed LLMs, the narrow performance gap highlights the potential of LLM-based approaches for Tactic and Technique prediction. Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Marco Arazzi, Antonino Nocera, Mauro Conti |
J. Inf. Secur. Appl. | 2 |
| 2025 | Through the static: Demystifying malware visualization via explainabilityabstractSecurity researchers face growing challenges in rapidly identifying and classifying malware strains for effective protection. While Convolutional Neural Networks (CNNs) have emerged as powerful visual classifiers for this task, critical issues of robustness and explainability, well-studied in domains like medicine, remain underaddressed in malware analysis. Although these models achieve strong performance without manual feature engineering, their replicability and decision-making processes remain poorly understood. Two technical barriers have limited progress: first, the lack of obvious methods for selecting and evaluating explainability techniques due to their inherent complexity, and second the substantial computational resources required for replicating and tuning these models across diverse environments, which requires extensive computational power and time investments often beyond typical research constraints. Our study addresses these gaps through comprehensive replication of six CNN architectures, evaluating both performance and explainability using Class Activation Maps (CAMs) including GradCAM and HiResCAM. We conduct experiments across standard datasets (MalImg, Big2015) and our new VX-Zoo collection, systematically comparing how different models interpret inputs. Our analysis reveals distinct patterns in malware family identification while providing concrete explanations for CNN decisions. Furthermore, we demonstrate how these interpretability insights can enhance Visual Transformers, achieving F1-score yielding substantial improvements in F1 score, ranging from 2% to 8%, across the datasets compared to benchmark values. • We conducted replicability experiments on BIG2015, Malimg, and VX-Zoo datasets. • We used Class Activation Maps to provide insights into the classifiers’ decisions. • We introduced a novel image masking technique to enhance classifiers performance. • We demonstrated that HiResCAM outperforms GradCAM when applying the masking. Matteo Brosolo, P. Vinod 0001, Mauro Conti |
J. Inf. Secur. Appl. | 2 |
| 2025 | HExNet: Enhancing malware classification through hierarchical CNNs and multi-level feature attributionabstractThe ever-shifting landscape of malware presents a significant threat, as it routinely circumvents traditional defenses. This paper presents HExNet, a Hierarchical Explainable Convolutional Neural Network (CNN) architecture, designed to improve malware analysis and bolster security defenses. Recognizing the growing sophistication of malware, HExNet leverages a dual image representation, converting assembly mnemonics and raw bytecode of malware into visual representations for in-depth pattern recognition. The architecture, optimized for performance and security relevance, integrates multi-level features to enhance detection accuracy. To increase trust and facilitate security audits, HExNet incorporates SHAPley Additive Explanations (SHAP), Class Activation Maps (CAM), and GIST descriptors, providing transparent insights into the model’s classification process. t-SNE visualizations further demonstrate HExNet’s ability to effectively separate malware families, aiding in security intelligence. Evaluated on the Microsoft Malware Classification Challenge (BIG 2015) dataset, HExNet achieves an overall F1-score of 0.9890, with three malware families reaching a perfect F1-score of 1.0 and the remaining six families achieving near-optimal values. To evaluate the generalization capability, we further tested HExNet on a custom dataset consisting 26,401 samples collected from VirusShare, where the proposed model achieved an F1-score of 0.9724, demonstrating generalization performance across diverse malware datasets. Muhammed Shafi K. P., P. Vinod 0001, Rafidha Rehiman K. A., Alejandro Guerra-Manzanares |
J. Inf. Secur. Appl. | 2 |
| 2025 | WeiDetect: Weibull distribution-based defense against poisoning attacks in federated learning for network intrusion detection systems
K. M. Sameera, P. Vinod 0001, Anderson Rocha 0001, Rafidha Rehiman K. A., Mauro Conti |
J. Inf. Secur. Appl. | 2 |
| 2025 | Android malware defense through a hybrid multi-modal approachabstractThe rapid proliferation of Android apps has given rise to a dark side, where increasingly sophisticated malware poses a formidable challenge for detection. To combat this evolving threat, we present an explainable hybrid multi-modal framework. This framework leverages the power of deep learning , with a novel model fusion technique, to illuminate the hidden characteristics of malicious apps . Our approach combines models (leveraging late fusion approach) trained on attributes derived from static and dynamic analysis, hence utilizing the unique strengths of each model. We thoroughly analyze individual feature categories, feature ensembles, and model fusion using traditional machine learning classifiers and deep neural networks across diverse datasets. Our hybrid fused model outperforms others, achieving an F1-score of 99.97% on CICMaldroid2020. We use SHAP (SHapley Additive exPlanations) and t-SNE (t-distributed Stochastic Neighbor Embedding) to further analyze and interpret the best-performing model. We highlight the efficacy of our architectural design through an ablation study, revealing that our approach consistently achieves over 99% detection accuracy across multiple deep learning models . This paves the way groundwork for substantial advancements in security and risk mitigation within interconnected Android OS environments. K. A. Asmitha, P. Vinod 0001, Rafidha Rehiman K. A., Neeraj Raveendran, Mauro Conti |
J. Netw. Comput. Appl. | 2 |
| 2024 | SoK: Visualization-based Malware Detection TechniquesabstractCyber attackers leverage malware to infiltrate systems, steal sensitive data, and extort victims, posing a significant cybersecurity threat. Security experts address this challenge by employing machine learning and deep learning approaches to detect malware precisely, using static, dynamic, or hybrid methodologies. They visualize malware to identify patterns, behaviors, and common features across different malware families. Various methods and tools are used for malware visualization to represent different aspects of malware behavior, characteristics, and relationships. This article evaluates the effectiveness of visualization techniques in detecting and classifying malware. We methodically categorize studies based on their approach to information retrieval, visualization, feature extraction, classification, and evaluation, allowing for an in-depth review of cutting-edge methods. This analysis identifies key challenges in visualization-based techniques and sheds light on the field’s progress and future possibilities. Our thorough analysis can provide valuable insights to researchers, helping them establish optimal practices for selecting suitable visualizations based on the specific characteristics of the analyzed malware. Matteo Brosolo, P. Vinod 0001, Asmitha KA, Rafidha Rehiman K. A., Mauro Conti |
ARES | 2 |
| 2024 | Beyond Words: Stylometric Analysis for Detecting AI Manipulation on Social Media
Sonia Laudanna, P. Vinod 0001, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
ESORICS (1) | 3 |
| 2024 | Relation Extraction Techniques in Cyber Threat Intelligence
Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, Mauro Conti |
NLDB (1) | 2 |
| 2024 | Towards a Malware Family Classification Model Using Static Call Graph Instruction Visualization
Attila Mester, Zalán Bodó, P. Vinod 0001, Mauro Conti |
NSS | 3 |
| 2024 | LFGurad: A Defense against Label Flipping Attack in Federated Learning for Vehicular Network
K. M. Sameera, P. Vinod 0001, Rafidha Rehiman K. A., Mauro Conti |
Comput. Networks | 2 |
| 2024 | Privacy-preserving in Blockchain-based Federated Learning systems
K. M. Sameera, Serena Nicolazzo, Marco Arazzi, Antonino Nocera, Rafidha Rehiman K. A., P. Vinod 0001, Mauro Conti |
Comput. Commun. | 6 |
| 2024 | OSTIS: A novel Organization-Specific Threat Intelligence System
Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, Georgiana Timpau, Mauro Conti |
Comput. Secur. | 2 |
| 2024 | A defensive attention mechanism to detect deepfake content across multiple modalities
Asha S 0001, P. Vinod 0001, Varun G. Menon |
Multim. Syst. | 2 |
| 2024 | D-Fence layer: an ensemble framework for comprehensive deepfake detection
Asha S 0001, P. Vinod 0001, Irene Amerini, Varun G. Menon |
Multim. Tools Appl. | 2 |
| 2023 | Interpretable PDF Malware DetectorabstractThe Portable Document Format (PDF) has gained widespread popularity due to its adaptable structure. As PDF usage continues to grow, so does the potential for it to be exploited as a platform for attacks. Malicious actors seek to compromise users' confidential information and exploit system vulnerabilities by implanting harmful content within PDF files. This paper presents an approach for detecting malicious PDF files by extracting features using the PDFiD tool. Furthermore, we employ explainable AI techniques, including tools like ELI5, SHAP, LIME, Partial Dependency Plot, and Counterfactual explanations. Through the use of explainable AI, we interpret the classifier's predictions and determine the significance of each feature in classifying PDF files as either malicious or benign. Lastly, we assess the robustness of the classification model by generating adversarial attacks to simulate a black-box approach. Sneha Rajagopal, Avanthika Gaur, P. Vinod 0001 |
SIN | 3 |
| 2023 | A smartphone authentication system based on touch gesture dynamicsabstractSummary Different authentication techniques that we use today, are prone to shoulder surfing attacks and mimicry attacks. Thus, keystroke dynamics combined with time and motion‐based typing patterns have been studied for years. In this paper, we introduce and evaluate a touch gesture‐based application to authenticate a user based on their typing behavior in distinct contexts such as lying, sitting, standing, walking, stationary, climbing up and down the stairs, by leveraging different features extracted from multiple built‐in smartphone sensors. We use various attributes including time‐based features such as dwell time and flight time and motion‐based features such as accelerometer, gyroscope, and magnetometer readings. The proposed authentication model distinguishes the legitimate smartphone owner from impostors using hand gestures, touch and keystroke dynamics. We experimented with different design alternatives such as a combination of motion sensor features, time‐based features extracted from multiple devices. In addition, we evaluated the performance using various supervised machine learning algorithms to show how to achieve high authentication accuracy and least equal error rate. A thorough evaluation shows that the system achieves authentication with 99.8% accuracy with a high AUC of 0.99 and EER of 0.11%. Susmi Jacob, P. Vinod 0001, Muralidharan Akarsh, Jackson George, Jewel Joseph, Jigil Joy |
Concurr. Comput. Pract. Exp. | 2 |
| 2023 | Sober: Explores for invasive behaviour of malware
Mohammad Hadi Alaeiyan, Saeed Parsa, P. Vinod 0001 |
J. Inf. Secur. Appl. | 3 |
| 2023 | Affect sensing from smartphones through touch and motion contexts
Susmi Jacob, P. Vinod 0001, Arjun Subramanian, Varun G. Menon |
Multim. Syst. | 2 |
| 2022 | On the Influence of Image Settings in Deep Learning-based Malware Detection
Francesco Mercaldo, Fabio Martinelli, Antonella Santone, P. Vinod 0001 |
ICISSP | 4 |
| 2022 | A few-shot malware classification approach for unknown family recognition using malware feature visualization
Mauro Conti, Shubham Khandhar, P. Vinod 0001 |
Comput. Secur. | 3 |
| 2022 | Cognitive smart cities: Challenges and trending solutionsabstractCognitive smart Varun G. Menon, Reza Khosravi, Alireza Jolfaei, Akshi Kumar 0001, P. Vinod 0001 |
Expert Syst. J. Knowl. Eng. | 5 |
| 2022 | Obfuscation detection in Android applications using deep learning
Mauro Conti, P. Vinod 0001, Alessio Vitella |
J. Inf. Secur. Appl. | 2 |
| 2021 | Downsampling Attack on Automatic Speaker Authentication SystemabstractRecent years have observed an exponential growth in the popularity of audio-based authentication systems. The benefit of a voice-based authentication system is that the person need not be physically present. Voice biometric system provides effective authentication in various domains like remote access control, authentication in mobile applications, customer care centers for call attests. Most of the existing authentication systems that recognize speakers formulate deep learning models for better classification. At the same time, research studies show that deep learning models are highly vulnerable to adversarial inputs. A breach in security on authentication systems are not generally acceptable. This paper exposes the vulnerabilities of audio-based authentication systems. Here, we propose a novel downsampling attack to the speaker recognition system. This attack can effectively trick the speaker recognition framework by causing inaccurate predictions. The proposed threat model achieved remarkable attack effectiveness of 75%. This system employs a custom human voice dataset recorded in real-time conditions to achieve real-time effectiveness during classification. We compare the attack accuracy of the proposed attack against the adversarial audios generated using the CleverHans toolbox. The proposed attack being a black box attack, is transferable to other deep learning systems also. Asha S 0001, P. Vinod 0001, Varun G. Menon, Akka Zemmari |
AICCSA | 2 |
| 2021 | Automatic Classification of Vulnerabilities using Deep Learning and Machine Learning AlgorithmsabstractAs the field of computer science has advanced over the years, there has been a tremendous increase in the software being created, and this increase has been accompanied by an increase in the number of software vulnerabilities. A software vulnerability is a security flaw found in software that can potentially be exploited by attackers to perform cyber attacks. Since automatic approaches for identifying and analyzing vulnerabilities have become a trending topic in research, community, the classification of vulnerability is still an open issue. Developers need to know more about characteristics and types of vulnerabilities in systems to adopt suitable countermeasures in current and next versions. With this paper, we investigate whether vulnerability descriptions alone can be used to identify the type of vulnerability, by comparing five shallow learning models and fourteen deep learning models. The model with the highest F1-score was the Stacking-DNN (98.8%). On performing comprehensive analysis, the experiments demonstrate that both shallow and deep classifiers show comparable performance when trained and tested using the dataset without duplicates, while shallow classifiers showed better performance when trained and tested using the dataset with duplicates. Vishnu Ramesh, Sara Abraham, P. Vinod 0001, Isham Mohamed, Corrado Aaron Visaggio, Sonia Laudanna |
IJCNN | 3 |
| 2021 | Vulnerability Evaluation of Android Malware Detectors against Adversarial ExamplesabstractIn this paper, we evaluate the performance of machine learning classifiers (Logistic Regression, CART, Random Forest) by fabricating adversarial examples (malware samples) statistically identical to goodware. To this end, we demonstrate three scenarios, (a) random attribute injection (b) insertion of prominent attributes from legitimate apps and (c) poisoning of class labels, for creating tainted malware samples, to mislead reduce accuracy of classification models. Experiments were conducted on data-set consisting of 15649 android applications comprising 5373 malicious and 10276 legitimate apps. The outcome of investigations demonstrates significant drop in accuracies in the range of 12-50%. However, in the absence of adversarial examples in the test set, the performance of classifiers was observed between 94.8-97.9%. Ijas Ah, P. Vinod 0001, Akka Zemmari, Harikrishnan D, Godvin Poulose, Don Jose, Francesco Mercaldo, Fabio Martinelli, Antonella Santone |
KES | 2 |
| 2021 | Malware detection employed by visualization and deep neural network
Anson Pinhero, Anupama M. L, P. Vinod 0001, Corrado Aaron Visaggio, Aneesh N, Abhijith S, AnanthaKrishnan S |
Comput. Secur. | 3 |
| 2020 | Detection of Tor Traffic using Deep LearningabstractTor, originally known as The Onion Router, is a free software that allows users to communicate anonymously on the Internet. This makes Tor attractive to cyber criminals, and the anonymity provided can be misused by hackers to enable remote control of victim systems. Indeed, a large volume of Tor traffic is used for malicious purposes such as fast port scans, hacking attempts, ex-filtration of stolen credentials, etc. This makes Tor traffic detection an important component of intrusion detection and prevention systems. Hence, in this paper we present a deep neural network (DNN) based system for the detection and classification of encrypted Tor traffic. The system achieved 99.89% accuracy in the classification of Tor and non-Tor traffic on the UNB-CIC Tor network dataset. Experiments conducted for classifying Tor traffic types demonstrated an accuracy of 95.6%, which is 6.2% higher than previous work on the same dataset. Additionally, the robustness of the proposed DNN classifier is evaluated using adversarial samples generated from a Generative Adversarial Network (GAN). We observed that 100% of the adversarial examples were unidentified by the DNN classifiers. Further retraining of the DNN classifiers with adversarial examples eventually improved their robustness against the adversarial attack. Debmalya Sarkar, P. Vinod 0001, Suleiman Y. Yerima |
AICCSA | 2 |
| 2020 | Detection of algorithmically-generated domains: An adversarial machine learning approach
Mohammad Hadi Alaeiyan, Saeed Parsa, P. Vinod 0001, Mauro Conti |
Comput. Commun. | 3 |
| 2020 | Secure Brain-to-Brain Communication With Edge Computing for Assisting Post-Stroke Paralyzed PatientsabstractStroke affects 33 million individuals worldwide every year and is one of the prime causes of paralysis. Due to partial or full paralysis, most of the patients affected by stroke depend on caregivers for the rest of their lives. Easy and efficient communication from the patient to the caregiver is a vital parameter determining the quality of life during rehabilitation. Several solutions, such as brain-computer interface (BCI) systems and exoskeletons, are proposed for post-stroke rehabilitation. But, most of these devices are expensive, sophisticated, and put an additional burden on the patient. Also, the communication between the patient and the caregiver is insecure. In this article, the brain-to-brain interface technique is integrated with an efficient encryption algorithm to enable secure transmission of information from the patient's brain to the caregiver. When a patient thinks of a word or a number, the thought is transmitted with the help of an electroencephalogram (EEG) headset through a wireless medium to the recipient, who correctly interprets the thoughts conveyed by the sender and types the same alphabet on the keyboard at his/her end. The transmitted message at the edge is encrypted with a lightweight novel tiny symmetric algorithm (NTSA), which can only be decrypted at the edge receiver. The Internet of Things integrated system is also flexible to send signals to multiple caregivers at the same time. The proposed method tested on ten users gave an average effective concentration percentage of 78.9% along with the secure transmission, which is a significant result compared with existing solutions. Sreeja Rajesh, Varghese Paul, Varun G. Menon, Sunil Jacob, P. Vinod 0001 |
IEEE Internet Things J. | 5 |
| 2019 | Identification of Android malware using refined system callsabstractSummary The ever increasing number of Android malware has always been a concern for cybersecurity professionals. Even though plenty of anti‐malware solutions exist, we hypothesize that the performance of existing approaches can be improved by deriving relevant attributes through effective feature selection methods. In this paper, we propose a novel two‐step feature selection approach based on Rough Set and Statistical Test named as RSST to extract refined system calls, which can effectively discriminate malware from benign apps. By refined set of system call, we mean the existence of highly relevant calls that are uniformly distributed thought target classes. Moreover, an optimal attribute set is created, which is devoid of redundant system calls. To address the problem of higher dimensional attribute set, we derived suboptimal system call space by applying the proposed feature selection method to maximize the separability between malware and benign samples. Comprehensive experiments conducted on three datasets resulted in an accuracy of 99.9%, Area Under Curve (AUC) of 1.0, with 1% False Positive Rate (FPR). However, other feature selectors (Information Gain, CFsSubsetEval, ChiSquare, FreqSel, and Symmetric Uncertainty) used in the domain of malware analysis resulted in the accuracy of 95.5% with 8.5% FPR. Moreover, the empirical analysis of RSST derived system calls outperformed other attributes such as permissions, opcodes, API, methods, call graphs, Droidbox attributes, and network traces. Deepa Kundur, Radhamani G, P. Vinod 0001, Mohammad Shojafar, Neeraj Kumar 0001, Mauro Conti |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | A machine learning based approach to detect malicious android apps using discriminant system calls
P. Vinod 0001, Akka Zemmari, Mauro Conti |
Future Gener. Comput. Syst. | 1 |
| 2015 | Machine learning approach for filtering spam emailsabstractAn efficient email spam filtering system by selecting relevant features to reduce the dimensions has become a pivotal aspect in the field of machine learning based spam filtering. To deal with noisy features, TF-IDF-CF is chosen as the feature selection method in this study. The selected relevant feature sets are submitted to LibSVM and MNB classifiers to construct ham and spam models. An accuracy of 98.2612 with F-measure 0.9841 is obtained which depicts the effectiveness of proposed scheme. Princy George, P. Vinod 0001 |
SIN | 2 |
| 2015 | Hartley's test ranked opcodes for Android malware analysisabstractThe popularity and openness of Android platform encourage malware authors to penetrate various market places with malicious applications. As a result, malware detection has become a critical topic in security. Currently signature-based system is able to detect malware only if it is properly documented. This reveals the need to find new malware detection techniques. In our framework, a statistical technique for Android malware detection using opcodes extracted from various applications is proposed. This technique is evaluated against malware apk samples from contagio dataset and benign apk samples from various markets. The prominent features that result in reduced misclassification rates are determined using Hartley's test. Meenu Mary John, P. Vinod 0001, Dhanya K. A. |
SIN | 2 |
| 2015 | Information theoretic method for classification of packed and encoded filesabstractMalware authors make use of some anti-reverse engineering and obfuscation techniques like packing and encoding in-order to conceal their malicious payload. These techniques succeeded in evading the traditional signature based AV scanners. Packed or encoded malware samples are difficult to be analysed directly by the AV scanners. So, such samples must be initially unpacked or decoded for efficient analysis of the malicious code. This paper illustrates a static information theoretic method for the classification of packed and encoded files. The proposed method extracts fragments of fixed size from the files and calculates the entropy scores of the fragments. These entropy scores are then used for computing the Similarity Distance Matrix for fragments in a file-pair. The proposed system classifies all the encoded and packed samples properly, thereby obtaining improved detection. The proposed system is also capable of differentiating the type of packers used for the packing or encoding process. Jithu Raphel, P. Vinod 0001 |
SIN | 2 |
| 2014 | Towards the Detection of Undetectable Metamorphic MalwareabstractOur research developed a non signature based approach, employing feature selection methods such as Categorical Proportional Distance (CPD), Weight of Evidence of Text (WET), Term Frequency - Inverse Document Frequency (TF-IDF), Term Frequency - Inverse Document Frequency - Class Frequency (TF-IDF-CF), Galavotti-Sebastiani-Simi Coefficient (GSS) and Term Significance (TS). Classification model is developed by considering bi--gram features ranked with these feature selection techniques. The proposed feature selection approaches detect unseen malware samples with accuracy in the range of 99% to 100%. Relevance of a feature ranking methods on variable feature length is ascertained using McNemar test. Jikku Kuriakose, P. Vinod 0001 |
SIN | 2 |
| 2014 | Detecting malicious files using non-signature-based methodsabstractMalware or malicious code intends to harm the computer systems without the knowledge of system users. Malware are unknowingly installed by naïve users while browsing the internet. Once installed, the malicious programs perform unintentional activities like: a) steal user name, password; b) install spy software to provide remote access to the attackers; c) flood spam messages; d) perform denial of service attacks, etc. With the emergence of metamorphic malware (that uses complex obfuscation techniques), signature-based detectors fail to identify new variants of malware. In this paper, we investigate non-signature techniques for malware detection and demonstrate methods of feature selection that are best suited for detection purposes. Features are produced using mnemonic n -grams and instruction opcodes (opcodes along with addressing modes). The redundant features are eliminated using class-wise document frequency , scatter criterion and principal component analysis (PCA) . The experiments are conducted on the malware dataset collected from VX Heavens and benign executables (gathered from fresh installation of Windows XP operating system and other utility software’s). The experiments also demonstrate that proposed methods that do not require signatures are effective in identifying and classifying morphed malware. P. Vinod 0001, Vijay Laxmi, Manoj Singh Gaur, Grijesh Chauhan |
Int. J. Inf. Comput. Secur. | 1 |
| 2012 | Mining control flow graph as API call-grams to detect portable executable malwareabstractPresent day malware shows stealthy and dynamic capability and avails administrative rights to control the victim computers. Malware writers depend on evasion techniques like code obfuscation, packing, compression, encryption or polymorphism to avoid detection by Anti-Virus (AV) scanners as AV primarily use syntactic signature to detect a known malware. Our approach is based on semantic aspect of PE exectable that analyses API Call-grams to detect unknown malicious code. As in--exact source code is analysed, the machine is not infected by the executable. Moreover, static analysis covers all the paths of code which is not possible with dynamic behavioural methods as latter does not gurantee the execution of sample being analysed. Modern malicious samples also detect controlled virtual and emulated environments and stop the functioning. Semantic invariant approach is important as signature of known samples are changed by code obfuscation tools. Static analysis is performed by generating an API Call graph from control flow of an executable, then mining the Call graph as API Call-gram to detect malicious files. Parvez Faruki, Vijay Laxmi, Manoj Singh Gaur, P. Vinod 0001 |
SIN | 4 |
| 2012 | ESCAPE: entropy score analysis of packed executableabstractMalware developers hide the malicious payload of malware binary by employing various obfuscation techniques. One such technique commonly applied is packing. Packer transforms the original bytes so it is difficult to recognize the behaviour of any executable. Although the contents of a file is changed, some byte patterns may be preserved across different packed executables. Malware detectors need to apply unpacking mechanism prior to any detection or analysis to every sample under consideration. In this paper, we have proposed a method that discriminate packed binaries from the native files to minimize the processing time of AV scanners. We have used the blockwise entropy score of byte features of the executable. Experimental results show that the proposed method is capable of identifying packed and native executable which are packed using different malware packers. Smita Naval, Vijay Laxmi, Manoj Singh Gaur, P. Vinod 0001 |
SIN | 4 |