VLDB 2026 Research / reviewers in the wild / expert
Denis Petrov 0001
dblp:79/400-1
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0000-7131-6844ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata SequencesabstractAbstract For a few years, malware with tunneling (or: covert channel) capabilities has been on the rise. While malware research led to several methods and innovations, the detection and differentiation of malware solely based on its DNS tunneling features is still in its infancy. Moreover, no work so far has used the DNS tunneling traffic to gain knowledge over the current actions taken by the malware. In this paper, we present , an approach to detect and differentiate state-of-the-art malware and DNS tunneling tools without relying on trivial (but quickly altered) features such as “magic bytes” that are embedded into subdomains. Instead, we apply an analysis of sequential patterns to identify specific types of malware. We evaluate our approach with 7 real-world malware samples and tunneling tools and can identify the particular malware based on its DNS traffic. We further infer the rough behavior of the particular malware through its DNS tunneling artifacts. Finally, we compare our with related methods. Denis Petrov 0001, Pascal Ruffing, Sebastian Zillien, Steffen Wendzel |
ARES (1) | 1 |
| 2024 | A Comprehensive Pattern-based Overview of StegomalwareabstractIn recent years, malware increasingly applies steganography methods to remain undetected as long as possible. Such malware is called stegomalware. Stegomalware not only covers its tracks on the infected system, but also hides its communication with adversary infrastructure. This paper reviews 106 stegomalware cases on the basis of 133 reports, including digital media (audio, video, images), text, and network steganography. For this purpose, the steganography methods used by the malware are categorized and introduced using a pattern-based approach. Our survey reveals that solely a small set of patterns are employed by known malware samples. We also analyzed the commonalities of media-, text-, and network-based stegomalware. We show that only a small variation of network protocols, media types and hiding methods are utilized by stegomalware. For this reason, research may focus on these to counter malicious activities covered by steganography. Fabian Strachanski, Denis Petrov 0001, Tobias Schmidbauer, Steffen Wendzel |
ARES | 2 |
| 2024 | A Development Framework for TCP/IP Network Steganography Malware DetectionabstractStegomalware poses a rising threat in the security landscape as more and more malware samples use steganography to disguise their network traffic, rendering traditional detection approaches less and less useful. To detect such advanced threats, it is important to identify and focus on unique characteristics of stegomalware. We present a new malware detection framework tailored for stegomalware nested in TCP/IP protocols. With the framework, we are able to observe real malware in a secure environment, use the gained insights to create realistic simulations, extract relevant characteristics and perform detection based on the gained data. The goal of the framework is to enable and streamline the process of developing new detection methods. Sebastian Zillien, Denis Petrov 0001, Pascal Ruffing, Friedrich Gross |
IH&MMSec | 2 |