Pavel Gladyshev

dblp:g/PavelGladyshev · DBLP profile ↗
← Back
21ranked-venue papers
2as first author
2since 2021 · last 2022
0000-0002-7449-4475ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1
YearPublicationVenuePosition
2022 Automating the Flow of Data Between Digital Forensic Tools Using Apache NiFi
Francis N. Nwebonyi, Pavel Gladyshev
ICDF2C3
2022 Crime and Incident Watch for Smart Cities: A Sensor-Based Approach
Francis N. Nwebonyi, Pavel Gladyshev
ICDF2C3
2020 Remote Air-Gap Live Forensics
Tom Van der Mussele, Babak Habibnia, Pavel Gladyshev
ICDF2C3
2015 Development and Initial User Evaluation of a Virtual Crime Scene Simulator Including Digital Evidence
Alleyn Conway, Joshua James, Pavel Gladyshev
ICDF2C3
2015 A Survey of International Cooperation in Digital Investigations
Joshua James, Pavel Gladyshev
ICDF2C2
2015 Forensic analysis of instagram and path on an iPhone 5s mobile device
abstract
Social networking applications are a treasure trove for forensic examiners. The amount of potential evidence that they hold could sway the course of any investigation. However, the large number of mobile operating systems, their continuous updates, and the constant emergence of new social networking applications in the market, create challenges for forensic practitioners today. This paper hopes to alleviate some of those challenges by conducting a forensic analysis on two popular social networking applications; Instagram and Path on an iPhone 5s mobile device. The analysis process consisted of installing both applications on the device, performing common user activities via these applications, obtaining a forensically sound logical image of the device, and finally conducting manual- and automatic (for result verification)-forensic analysis on the acquired image. The ultimate goal of the analysis was to determine whether the activities conducted through these applications are stored on the mobile device's internal memory or not. The test results show that a portion of the activities is indeed stored in the internal memory. Therefore, the significance, extent, and locations of the stored information were all determined and documented in this paper.
Reema Al Mushcab, Pavel Gladyshev
ISCC2
2013 An Automated Link Analysis Solution Applied to Digital Forensic Investigations
Fergal Brennan, Martins Udris, Pavel Gladyshev
ICDF2C3
2013 Measuring Accuracy of Automated Parsing and Categorization Tools and Processes in Digital Investigations
Joshua James, Alejandra Lopez-Fernandez, Pavel Gladyshev
ICDF2C3
2013 Determining Training Needs for Cloud Infrastructure Investigations Using I-STRIDE
Joshua James, Ahmed F. Shosha, Pavel Gladyshev
ICDF2C3
2012 Evasion-resistant malware signature based on profiling kernel data structure objects
abstract
Malware authors attempt in an endless effort to find new methods to evade the malware detection engines. A popular method is the use of obfuscation technologies that change the syntax of malicious code while preserving the execution semantics. This leads to the evasion of signatures that are built based on the code syntax. In this paper, we propose a novel approach to develop an evasion-resistant malware signature. This signature is based on the malware's execution profiles extracted from kernel data structure objects and neither uses malicious code syntax specific information code execution flow information. Thus, proposed signature is more resistant to obfuscation methods and resilient in detecting malicious code variants. To evaluate the effectiveness of the proposed approach, a prototype signature generation tool called SigGENE is developed. The effectiveness of signatures generated by SigGENE evaluated using an experimental root kit-simulation tool that employs techniques commonly found in rootkits. This simulationtool is obfuscated using several different methods. In further experiments, real-world malware samples that have different variants with the same behavior used to verify the real-world applicability of the approach. The experiments show that the proposed approach is effective, not only in generating a signature that detects the malware and its variants and defeats different obfuscation methods, but also, in producing an execution profiles that can be used to characterize different malicious attacks.
Ahmed F. Shosha, Chen-Ching Liu, Pavel Gladyshev, Marcus Matten
CRiSIS3
2012 BREDOLAB: Shopping in the Cybercrime Underworld
Daan de Graaf, Ahmed F. Shosha, Pavel Gladyshev
ICDF2C3
2012 Investigating File Encrypted Material Using NTFS $logfile
Niall McGrath, Pavel Gladyshev
ICDF2C2
2012 Towards Automated Malware Behavioral Analysis and Profiling for Digital Forensic Investigation Purposes
Ahmed F. Shosha, Joshua James, Alan Hannaway, Chen-Ching Liu, Pavel Gladyshev
ICDF2C5
2012 Towards Automated Forensic Event Reconstruction of Malicious Code (Poster Abstract)
Ahmed F. Shosha, Joshua James, Chen-Ching Liu, Pavel Gladyshev
RAID4
2011 A Novel Methodology for Malware Intrusion Attack Path Reconstruction
Ahmed F. Shosha, Joshua James, Pavel Gladyshev
ICDF2C3
2010 Reliable Acquisition of RAM Dumps from Intel-Based Apple Mac Computers over FireWire
Pavel Gladyshev, Afrah Almansoori
ICDF2C1
2010 Signature Based Detection of User Events for Post-mortem Forensic Analysis
Joshua James, Pavel Gladyshev, Yuandong Zhu
ICDF2C2
2010 A Consistency Study of the Windows Registry
Yuandong Zhu, Joshua James, Pavel Gladyshev
IFIP Int. Conf. Digital Forensics3
2009 Analysis of Evidence Using Formal Event Reconstruction
Joshua James, Pavel Gladyshev, Mohd Taufik Abdullah, Yuandong Zhu
ICDF2C2
2009 Temporal Analysis of Windows MRU Registry Keys
Yuandong Zhu, Pavel Gladyshev, Joshua James
IFIP Int. Conf. Digital Forensics2
1998 Cracking RC5 with Java applets
abstract
The paper describes a distributed brute-force attack on RC5 cipher using Java applets. It introduces a novel model for long-term parallel computing based on the abstraction of solvers with limited lifetime. The associated problems and scheduling policy are discussed. The paper comments on the inherent performance problems of the Java Virtual Machine and presents performance measurements of the cipher breaking applet for several computing platforms. © 1998 John Wiley & Sons, Ltd.
Pavel Gladyshev, Ahmed Patel, Donal O'Mahony
Concurr. Pract. Exp.1