EDBT 2026 Demo / reviewers in the wild / expert
Stanislav Dashevskyi
dblp:150/5429
· DBLP profile ↗
9ranked-venue papers
4as first author
1since 2021 · last 2024
0000-0003-1095-3035ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 5 · 2 first-authorSecurity and privacy · 4 · 2 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
4 papers |
Software testing · 79% Software maintenance and evolution · 11% Program analysis · 10% | |
| Network and information security
3 papers |
Malware analysis · 49% Web and mobile security · 33% Systems and software security · 19% |
Topics — the 14 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software testing › test coverage
code coverage |
0.8 | 2 | 2020 | Fine-grained Code Coverage Measurement in Automated Black-box Android Testing · ACM Trans. Softw. Eng. Methodol. 2020 An Effective Android Code Coverage Tool · CCS 2018 |
Malware analysis
malware classification |
0.8 | 1 | 2024 | Poster: A Multi-step Approach for Classification of Malware Samples · CCS 2024 |
Software testing › mobile application testing
android app testing |
0.5 | 2 | 2020 | Fine-grained Code Coverage Measurement in Automated Black-box Android Testing · ACM Trans. Softw. Eng. Methodol. 2020 The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018 |
Software testing › test coverage
coverage-based testing |
0.4 | 2 | 2018 | The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018 An Effective Android Code Coverage Tool · CCS 2018 |
Systems and software security
vulnerability discovery |
0.4 | 1 | 2019 | A Screening Test for Disclosed Vulnerabilities in FOSS Components · IEEE Trans. Software Eng. 2019 |
Software maintenance and evolution
software ecosystems |
0.4 | 1 | 2019 | A Screening Test for Disclosed Vulnerabilities in FOSS Components · IEEE Trans. Software Eng. 2019 |
Web and mobile security › mobile security
android security |
0.3 | 1 | 2018 | An Effective Android Code Coverage Tool · CCS 2018 |
Web and mobile security
mobile security |
0.3 | 1 | 2018 | An Effective Android Code Coverage Tool · CCS 2018 |
Software testing › test generation
automated test generation |
0.3 | 1 | 2018 | The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018 |
Software testing › test coverage
coverage metrics |
0.3 | 1 | 2018 | The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018 |
Program analysis
dynamic analysis |
0.3 | 1 | 2018 | An Effective Android Code Coverage Tool · CCS 2018 |
Malware analysis
malware detection |
0.2 | 1 | 2024 | Poster: A Multi-step Approach for Classification of Malware Samples · CCS 2024 |
Software testing › test generation › search-based test generation
evolutionary testing |
0.1 | 1 | 2020 | Fine-grained Code Coverage Measurement in Automated Black-box Android Testing · ACM Trans. Softw. Eng. Methodol. 2020 |
Software testing
mobile application testing |
0.1 | 1 | 2018 | The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018 |
Methods — techniques the papers use, named apart from their topics
instrumentation · 1.1third-party services · 0.8thin slicing · 0.8static analysis · 0.8machine learning · 0.8smali bytecode analysis · 0.7dynamic analysis · 0.4coverage metric combination · 0.3automated test design · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Poster: A Multi-step Approach for Classification of Malware SamplesabstractThe rapid spread of unknown malware has prompted many companies and researchers to improve their detection and classification systems. Cyber security companies must deal with the newest malware samples captured by their honeypots, aiming to analyze and classify them to develop several countermeasures. This process could only be feasible with a strong ground truth baseline; companies could only securely store the samples, waiting for further developments. This paper proposes a multi-step approach to support the classification process of unknown malware samples. Specifically, our approach first leverages well-known classification techniques and third-party services to collect as much information as possible about the samples and combines them with Machine Learning (ML)-based techniques to classify the remaining samples. Our case study, conducted on industrial data, shows how the combination offers superior performance than using each method individually. Arnaldo Sgueglia, Rocco Addabbo, Andrea Di Sorbo, Stanislav Dashevskyi, Daniel Ricardo dos Santos, Corrado Aaron Visaggio |
CCS | 4 |
| 2020 | Dissecting Android Cryptocurrency MinersabstractCryptojacking applications pose a serious threat to mobile devices. Due to the extensive computations, they deplete the battery fast and can even damage the device. In this work we make a step towards combating this threat. We collected and manually verified a large dataset of Android mining apps. In this paper, we analyze the gathered miners and identify how they work, what are the most popular libraries and APIs used to facilitate their development, and what static features are typical for this class of applications. Further, we analyzed our dataset using VirusTotal. The majority of our samples is considered malicious by at least one VirusTotal scanner, but 16 apps are not detected by any engine; and at least 5 apks were not seen previously by the service. Mining code could be obfuscated or fetched at runtime, and there are many confusing miner-related apps that actually do not mine. Thus, static features alone are not sufficient for miner detection. We have collected a feature set of dynamic metrics both for miners and unrelated benign apps, and built a machine learning-based tool for dynamic detection. Our BrenntDroid tool is able to detect miners with 95% of accuracy on our dataset. Stanislav Dashevskyi, Yury Zhauniarovich, Olga Gadyatskaya, Aleksandr Pilgun, Hamza Ouhssain |
CODASPY | 1 |
| 2020 | Fine-grained Code Coverage Measurement in Automated Black-box Android TestingabstractToday, there are millions of third-party Android applications. Some of them are buggy or even malicious. To identify such applications, novel frameworks for automated black-box testing and dynamic analysis are being developed by the Android community. Code coverage is one of the most common metrics for evaluating effectiveness of these frameworks. Furthermore, code coverage is used as a fitness function for guiding evolutionary and fuzzy testing techniques. However, there are no reliable tools for measuring fine-grained code coverage in black-box Android app testing. We present the Android Code coVerage Tool, ACVTool for short, that instruments Android apps and measures code coverage in the black-box setting at class, method and instruction granularity. ACVTool has successfully instrumented 96.9% of apps in our experiments. It introduces a negligible instrumentation time overhead, and its runtime overhead is acceptable for automated testing tools. We demonstrate practical value of ACVTool in a large-scale experiment with Sapienz, a state-of-the-art automated testing tool. Using ACVTool on the same cohort of apps, we have compared different coverage granularities applied by Sapienz in terms of the found amount of crashes. Our results show that none of the applied coverage granularities clearly outperforms others in this aspect. Aleksandr Pilgun, Olga Gadyatskaya, Yury Zhauniarovich, Stanislav Dashevskyi, Artsiom Kushniarou, Sjouke Mauw |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2019 | TestREx: a framework for repeatable exploits
Stanislav Dashevskyi, Daniel Ricardo dos Santos, Fabio Massacci, Antonino Sabetta |
Int. J. Softw. Tools Technol. Transf. | 1 |
| 2019 | A Screening Test for Disclosed Vulnerabilities in FOSS ComponentsabstractFree and Open Source Software (FOSS) components are ubiquitous in both proprietary and open source applications. Each time a vulnerability is disclosed in a FOSS component, a software vendor using this component in an application must decide whether to update the FOSS component, patch the application itself, or just do nothing as the vulnerability is not applicable to the older version of the FOSS component used. This is particularly challenging for enterprise software vendors that consume thousands of FOSS components and offer more than a decade of support and security fixes for their applications. Moreover, customers expect vendors to react quickly on disclosed vulnerabilities-in case of widely discussed vulnerabilities such as Heartbleed, within hours. To address this challenge, we propose a screening test: a novel, automatic method based on thin slicing, for estimating quickly whether a given vulnerability is present in a consumed FOSS component by looking across its entire repository. We show that our screening test scales to large open source projects (e.g., Apache Tomcat, Spring Framework, Jenkins) that are routinely used by large software vendors, scanning thousands of commits and hundred thousands lines of code in a matter of minutes. Further, we provide insights on the empirical probability that, on the above mentioned projects, a potentially vulnerable component might not actually be vulnerable after all. Stanislav Dashevskyi, Achim D. Brucker, Fabio Massacci |
IEEE Trans. Software Eng. | 1 |
| 2018 | The Influence of Code Coverage Metrics on Automated Testing Efficiency in AndroidabstractCode coverage is an important metric that is used by automated Android testing and security analysis tools to guide the exploration of applications and to assess efficacy. Yet, there are many different variants of this metric and there is no agreement within the Android community on which are the best to work with. In this paper, we report on our preliminary study using the state-of-the-art automated test design tool Sapienz. Our results suggest a viable hypothesis that combining different granularities of code coverage metrics can be beneficial for achieving better results in automated testing of Android applications. Stanislav Dashevskyi, Olga Gadyatskaya, Aleksandr Pilgun, Yury Zhauniarovich |
CCS | 1 |
| 2018 | An Effective Android Code Coverage ToolabstractThe deluge of Android apps from third-party developers calls for sophisticated security testing and analysis techniques to inspect suspicious apps without accessing their source code. Code coverage is an important metric used in these techniques to evaluate their effectiveness, and even as a fitness function to help achieving better results in evolutionary and fuzzy approaches. Yet, so far there are no reliable tools for measuring fine-grained bytecode coverage of Android apps. In this work we present ACVTool that instruments Android apps and measures the smali code coverage at the level of classes, methods, and instructions. Tool repository: https://github.com/pilgun/acvtool Aleksandr Pilgun, Olga Gadyatskaya, Stanislav Dashevskyi, Yury Zhauniarovich, Artsiom Kushniarou |
CCS | 3 |
| 2017 | Delta-Bench: Differential Benchmark for Static Analysis Security Testing ToolsabstractBackground: Static analysis security testing (SAST) tools may be evaluated using synthetic micro benchmarks and benchmarks based on real-world software. Aims: The aim of this study is to address the limitations of the existing SAST tool benchmarks: lack of vulnerability realism, uncertain ground truth, and large amount of findings not related to analyzed vulnerability. Method: We propose Delta-Bench - a novel approach for the automatic construction of benchmarks for SAST tools based on differencing vulnerable and fixed versions in Free and Open Source (FOSS) repositories. To test our approach, we used 7 state of the art SAST tools against 70 revisions of four major versions of Apache Tomcat spanning 62 distinct Common Vulnerabilities and Exposures (CVE) fixes and vulnerable files totalling over 100K lines of code as the source of ground truth vulnerabilities. Results: Our experiment allows us to draw interesting conclusions (e.g., tools perform differently due to the selected benchmark). Conclusions: Delta-Bench allows SAST tools to be automatically evaluated on the real-world historical vulnerabilities using only the findings that a tool produced for the analysed vulnerability. Ivan Pashchenko, Stanislav Dashevskyi, Fabio Massacci |
ESEM | 2 |
| 2016 | An automatic method for assessing the versions affected by a vulnerability
Stanislav Dashevskyi, Fabio Massacci |
Empir. Softw. Eng. | 2 |