EDBT 2026 Demo / reviewers in the wild / expert
Seyyedeh Atefeh Musavi
dblp:152/1889
· DBLP profile ↗
3ranked-venue papers
3as first author
0since 2021 · last 2019
0000-0002-2726-1484ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Malware analysis · 65% Systems and software security · 22% Hardware security and side channels · 13% | |
| Software engineering, system software, and programming languages
1 paper |
Requirements engineering and software design · 100% |
Topics — the 8 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Requirements engineering and software design
software architecture |
0.4 | 1 | 2019 | An Ontology-Based Method for HW/SW Architecture Reconstruction · IEEE Trans. Computers 2019 |
Requirements engineering and software design › software architecture › software architecture analysis
software architecture recovery |
0.4 | 1 | 2019 | An Ontology-Based Method for HW/SW Architecture Reconstruction · IEEE Trans. Computers 2019 |
Malware analysis › rootkit detection
kernel rootkit detection |
0.2 | 1 | 2014 | Back to Static Analysis for Kernel-Level Rootkit Detection · IEEE Trans. Inf. Forensics Secur. 2014 |
Malware analysis
rootkit detection |
0.2 | 1 | 2014 | Back to Static Analysis for Kernel-Level Rootkit Detection · IEEE Trans. Inf. Forensics Secur. 2014 |
Malware analysis › malware detection
static malware detection |
0.2 | 1 | 2014 | Back to Static Analysis for Kernel-Level Rootkit Detection · IEEE Trans. Inf. Forensics Secur. 2014 |
Systems and software security
vulnerability discovery |
0.2 | 1 | 2014 | Back to Static Analysis for Kernel-Level Rootkit Detection · IEEE Trans. Inf. Forensics Secur. 2014 |
Hardware security and side channels
trusted execution environments |
0.1 | 1 | 2019 | An Ontology-Based Method for HW/SW Architecture Reconstruction · IEEE Trans. Computers 2019 |
Requirements engineering and software design
model-driven engineering |
0.1 | 1 | 2019 | An Ontology-Based Method for HW/SW Architecture Reconstruction · IEEE Trans. Computers 2019 |
Methods — techniques the papers use, named apart from their topics
ontology-based reconstruction · 0.8OntoQA evaluation · 0.8static analysis · 0.2machine learning classification · 0.2feature extraction · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | HPCgnature: a hardware-based application-level intrusion detection systemabstractIn the past decade, commodity software applications have been deployed more than ever in almost every domain. Having the ability to differentiate the original trusted application at run‐time from its compromised, mimic or trojanised versions would mitigate a broad range of intrusion threats to these applications. This has been addressed by application‐level intrusion detection systems, however, such schemes mostly depend on the system software for either monitoring or modelling the application. This is while system software can itself get compromised by kernel‐level rootkit attacks. In this study, the authors have proposed a new hardware‐based app‐IDS, which works independent of the system software of the target system. The proposed method, referred to as HPCgnature , includes a new abstraction corresponding to the repetitious functionalities of programs. Such functionalities generate a distinguishing sequence of periods, referred to in this study as the Operational Periodicity . The method uses monitoring scheme based on external access to the hardware performance counters of CPUs. Implementing a prototype, they have shown how HPCgnature can detect intrusions in 12 complex interactive desktop applications. Evaluation results indicate this model could differentiate applications with 98% accuracy, and can detect even small run‐time code injection attacks by an accuracy of >75% Seyyedeh Atefeh Musavi, Mahmoud Reza Hashemi |
IET Inf. Secur. | 1 |
| 2019 | An Ontology-Based Method for HW/SW Architecture ReconstructionabstractTo address the vast variety of computing requirements in recent ubiquitous computing ecosystem, there is a constant need for more complex computing systems that consist of integrated hardware (HW) and software (SW) systems. Providing an architectural insight into such systems helps in achieving a more efficient usage of system resources, verifying the characteristics of a platform and provisioning of its security and trust. Architecture reconstruction (AR) has been used in software engineering to gain a deeper insight into specific software. Neither software AR nor hardware reverse engineering techniques are sufficient to extract the architecture of a system that incorporates both HW/SW, since they are unable to recover the relationships between the HW and SW components. Inspired by the Symphony software AR framework, we propose a method to reconstruct the architecture of a computing platform as a whole. In order to cover the wide variety of existing HW/SW technologies, our method uses an ontology-based approach. Due to the lack of a comprehensive ontology in literature, we developed PLATOnt, a new ontology that has been shown to be more effective by OntoQA evaluation framework. We used our AR method to reconstruct the architecture of an ARM-based trusted execution environment and a Raspberry Pi platform, widely used in embedded systems and IoT devices. Seyyedeh Atefeh Musavi, Mahmoud Reza Hashemi |
IEEE Trans. Computers | 1 |
| 2014 | Back to Static Analysis for Kernel-Level Rootkit DetectionabstractRootkit's main goal is to hide itself and other modules present in the malware. Their stealthy nature has made their detection further difficult, especially in the case of kernel-level rootkits. There have been many dynamic analysis techniques proposed for detecting kernel-level rootkits, while on the other hand, static analysis has not been popular. This is perhaps due to its poor performance in detecting malware in general, which could be attributed to the level of obfuscation employed in binaries which make static analysis difficult if not impossible. In this paper, we make two important observations, first there is usually little obfuscation used in legitimate kernel-level code, as opposed to the malicious kernel-level code. Second, one of the main approaches to penetrate the Windows operating system is through kernel-level drivers. Therefore, by focusing on detecting malicious kernel drivers employed by the rootkit, one could detect the rootkit while avoiding the issues with current detection technique. Given these two observation, we propose a simple static analysis technique with the aim of detecting malicious driver. We first study the current trends in the implementation of kernel-level rookits. Afterward, we proposed a set of features to quantify the malicious behavior in kernel drivers. These features are then evaluated through a set of experiments on 4420 malicious and legitimate drivers, obtaining an accuracy of 98.15% in distinguishing between these drivers. Seyyedeh Atefeh Musavi, Mehdi Kharrazi |
IEEE Trans. Inf. Forensics Secur. | 1 |