Justin Del Vecchio

dblp:174/1970 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Malware analysis · 72% Systems and software security · 22% Web and mobile security · 5%
Software engineering, system software, and programming languages
2 papers
Program analysis · 100%

Topics — the 9 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis
mobile malware detection
0.722019
Android Malware Detection Using Complex-Flows · IEEE Trans. Mob. Comput. 2019
Poster: Android Malware Detection using Multi-Flows and API Patterns · MobiSys 2017
Malware analysis › mobile malware detection
android malware detection
0.412019
Android Malware Detection Using Complex-Flows · IEEE Trans. Mob. Comput. 2019
Program analysis › static analysis
information flow analysis
0.412019
Android Malware Detection Using Complex-Flows · IEEE Trans. Mob. Comput. 2019
Systems and software security › information flow control
information flow analysis
0.312017
Poster: Android Malware Detection using Multi-Flows and API Patterns · MobiSys 2017
Program analysis › static analysis
interprocedural analysis
0.212015
String Analysis of Android Applications (N) · ASE 2015
Program analysis
static analysis
0.212015
String Analysis of Android Applications (N) · ASE 2015
Program analysis › data flow analysis › value analysis
string analysis
0.212015
String Analysis of Android Applications (N) · ASE 2015
Malware analysis › malware detection
behavior-based malware detection
0.112019
Android Malware Detection Using Complex-Flows · IEEE Trans. Mob. Comput. 2019
Web and mobile security › mobile security
android security
0.112017
Poster: Android Malware Detection using Multi-Flows and API Patterns · MobiSys 2017

Methods — techniques the papers use, named apart from their topics

n-gram analysis · 1.0control flow analysis · 0.8string disambiguation · 0.4information flow analysis · 0.3
YearPublicationVenuePosition
2019 Android Malware Detection Using Complex-Flows
abstract
This paper proposes a new technique to detect mobile malware based on information flow analysis. Our approach examines the structure of information flows to identify patterns of behavior present in them and which flows are related, those that share partial computation paths. We call such flows Complex-Flows, as their structure, patterns, and relations accurately capture the complex behavior exhibited by both recent malware and benign applications. N-gram analysis is used to identify unique and common behavioral patterns present in Complex-Flows. The N-gram analysis is performed on sequences of API calls that occur along Complex-Flows' control flow paths. We show the precision of our technique by applying it to four different data sets totaling 8,598 apps. These data sets consist of both recent and older generation benign and malicious apps to demonstrate the effectiveness of our approach across different generations of apps.
Justin Del Vecchio, David Mohaisen, Steven Y. Ko, Lukasz Ziarek
IEEE Trans. Mob. Comput.2
2017 Android Malware Detection Using Complex-Flows
abstract
This paper proposes a new technique to detect mobile malware based on information flow analysis. Our approach examines the structure of information flows to identify patterns of behavior present in them and which flows are related, those that share partial computation paths. We call such flows Complex-Flows, as their structure, patterns, and relations accurately capture the complex behavior exhibited by both recent malware and benign applications. N-gram analysis is used to identify unique and common behavioral patterns present in Complex-Flows. The N-gram analysis is performed on sequences of API calls that occur along Complex-Flows' control flow paths. We show the precision of our technique by applying it to different data sets totaling 7,798 apps. These data sets consist of both recent and older generation benign and malicious apps to demonstrate the effectiveness of our approach across different generations of apps.
Justin Del Vecchio, David Mohaisen, Steven Y. Ko, Lukasz Ziarek
ICDCS2
2017 Poster: Android Malware Detection using Multi-Flows and API Patterns
abstract
This paper proposes a new technique for detecting mobile malware based on information flow analysis. Our approach focuses on the structure of information flows we gather in our analysis, and the patterns of behavior present in information flows. Our analysis not only gathers simple flows that have a single source and a single sink, but also Multi-Flows that either start from a single source and flow to multiple sinks, or start from multiple sources and flow to a single sink. This analysis captures more complex behavior that both recent malware and recent benign applications exhibit. We leverage N-gram analysis to understand both unique and common behavioral patterns present in Multi-Flows. Our tool leverages N-gram analysis over sequences of API calls that occur along control flow paths in Multi-Flows to precisely analyze Multi-Flows with respect to app behavior.
Justin Del Vecchio, David Mohaisen, Steven Y. Ko, Lukasz Ziarek
MobiSys2
2015 String Analysis of Android Applications (N)
abstract
The desire to understand mobile applications has resulted in researchers adapting classical static analysis techniques to the mobile domain. Examination of data and control flows in Android apps is now a common practice to classify them. Important to these analyses is a fine-grained examination and understanding of strings, since in Android they are heavily used in intents, URLs, reflection, and content providers. Rigorous analysis of string creation, usage, and value characteristics offers additional information to increase precision of app classification. This paper shows that inter-procedural static analysis that specifically targets string construction and usage can be used to reveal valuable insights for classifying Android apps. To this end, we first present case studies to illustrate typical uses of strings in Android apps. We then present the results of our analysis on real-world malicious and benign apps. Our analysis examines how strings are created and used for URL objects, Java reflection, and Android intents, and infers the actual string values used as much as possible. Our results demonstrate that string disambiguation based on creation, usage, and value indeed provides additional information that may be used to improve precision of classifying application behaviors.
Justin Del Vecchio, Kenny M. Yee, Steven Y. Ko, Lukasz Ziarek
ASE1