Fabio Di Troia

dblp:177/3021 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
5since 2021 · last 2022
0000-0003-2355-7146ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 5 since 2021Artificial intelligence and machine learning · 2
YearPublicationVenuePosition
2022 Profile Hidden Markov Model Malware Detection and API Call Obfuscation
Monem Hamid, Jacob Jasser, Joachim Lerman, Samod Shetty, Fabio Di Troia
ICISSP6
2022 NLP-based User Authentication through Mouse Dynamics
Hoseong Asher Lee, Nikhil Prathapani, Rajesh Paturi, Sarp Parmaksiz, Fabio Di Troia
ICISSP5
2021 Malware Classification using Long Short-term Memory Models
abstract
Signature and anomaly based techniques are the quintessential approaches to malware detection. However, these techniques have become increasingly ineffective as malware has become more sophisticated and complex. Researchers have therefore turned to deep learning to construct better performing model. In this paper, we create four different long-short term memory (LSTM) based models and train each to classify malware samples from 20 families. Our features consist of opcodes extracted from malware executables. We employ techniques used in natural language processing (NLP), including word embedding and bidirection LSTMs (biLSTM), and we also use convolutional neural networks (CNN). We find that a model consisting of word embedding, biLSTMs, and CNN layers performs best in our malware classification experiments.
Dennis Dang, Fabio Di Troia, Mark Stamp 0001
ICISSP2
2021 A New Dataset for Smartphone Gesture-based Authentication
abstract
In this paper, we consider the problem of authentication on a smartphone, based on gestures. Specifically, the gestures consist of users holding a smartphone while writing their initials in the air. Accelerometer data from 80 subjects was collected and we provide a preliminary analysis of this data using machine learning techniques. The machine learning techniques considered include principal component analysis (PCA) and support vector machines (SVM). The results presented here are intended to provide a baseline for additional research based on our dataset.
Elliu Huang, Fabio Di Troia, Mark Stamp 0001, Preethi Sundaravaradhan
ICISSP2
2021 Malware Classification with Word Embedding Features
abstract
Malware classification is an important and challenging problem in information security. Modern malware classification techniques rely on machine learning models that can be trained on features such as opcode sequences, API calls, and byte n-grams, among many others. In this research, we consider opcode features. We implement hybrid machine learning techniques, where we engineer feature vectors by training hidden Markov models—a technique that we refer to as HMM2Vec—and Word2Vec embeddings on these opcode sequences. The resulting HMM2Vec and Word2Vec embedding vectors are then used as features for classification algorithms. Specifically, we consider support vector machine (SVM), k-nearest neighbor (k-NN), random forest (RF), and convolutional neural network (CNN) classifiers. We conduct substantial experiments over a variety of malware families. Our experiments extend well beyond any previous related work in this field.
Aparna Sunil Kale, Fabio Di Troia, Mark Stamp 0001
ICISSP2
2020 Detecting malware evolution using support vector machines
Mayuri Wadkar, Fabio Di Troia, Mark Stamp 0001
Expert Syst. Appl.2
2019 Transfer Learning for Image-based Malware Classification
abstract
In this paper, we consider the problem of malware detection and classification based on image analysis. We convert executable files to images and apply image recognition using deep learning (DL) models. To train these models, we employ transfer learning based on existing DL models that have been pre-trained on massive image datasets. We carry out various experiments with this technique and compare its performance to that of an extremely simple machine learning technique, namely, k-nearest neighbors (\kNN). For our k-NN experiments, we use features extracted directly from executables, rather than image analysis. While our image-based DL technique performs well in the experiments, surprisingly, it is outperformed by k-NN. We show that DL models are better able to generalize the data, in the sense that they outperform k-NN in simulated zero-day experiments.
Niket Bhodia, Pratikkumar Prajapati, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2019 A Comparative Analysis of Android Malware
abstract
In this paper, we present a comparative analysis of benign and malicious Android applications, based on static features. In particular, we focus our attention on the permissions requested by an application. We consider both binary classification of malware versus benign, as well as the multiclass problem, where we classify malware samples into their respective families. Our experiments are based on substantial malware datasets and we employ a wide variety of machine learning techniques, including decision trees and random forests, support vector machines, logistic model trees, AdaBoost, and artificial neural networks. We find that permissions are a strong feature and that by careful feature engineering, we can significantly reduce the number of features needed for highly accurate detection and classification.
Neeraj Chavan, Fabio Di Troia, Mark Stamp 0001
ICISSP2
2019 Feature analysis of encrypted malicious traffic
Anish Singh Shekhawat, Fabio Di Troia, Mark Stamp 0001
Expert Syst. Appl.2
2018 Acoustic Gait Analysis using Support Vector Machines
abstract
Gait analysis, defined as the study of human locomotion, can provide valuable information for low-cost analytic and classification applications in security, medical diagnostics, and biomechanics. In comparison to visual-based gait analysis, audio-based gait analysis offers robustness to clothing variations, visibility issues, and angle complications. Current acoustic techniques rely on frequency-based features that are sensitive to changes in footwear and floor surfaces. In this research, we consider an approach to surface-independent acoustic gait analysis based on time differences between consecutive steps. We employ support vector machines (SVMs) for classification. Our approach achieves good classification rates with high discriminative one-vs-all capabilities and we believe that our technique provides a promising avenue for future development.
Jasper Huang, Fabio Di Troia, Mark Stamp 0001
ICISSP2
2018 Autocorrelation Analysis of Financial Botnet Traffic
abstract
A botnet consists of a network of infected computers that can be controlled remotely via a command and control (C&C) server. Typically, a botnet requires frequent communication between a C&C server and the infected nodes. Previous approaches to detecting botnets have included various machine learning techniques based on features extracted from network traffic. In this research, we conduct autocorrelation analysis of traffic generated by financial botnets, and we show that periodicity is a highly distinguishing feature for detecting such botnets.
Prathiba Nagarajan, Fabio Di Troia, Thomas H. Austin, Mark Stamp 0001
ICISSP2
2018 Deep Learning versus Gist Descriptors for Image-based Malware Classification
abstract
Image features known as ``gist descriptors'' have recently been applied to the malware classification problem. In this research, we implement, test, and analyze a malware score based on gist descriptors, and verify that the resulting score yields very strong classification results. We also analyze the robustness of this gist-based scoring technique when applied to obfuscated malware, and we perform feature reduction to determine a minimal set of gist features. Then we compare the effectiveness of a deep learning technique to this gist-based approach. While scoring based on gist descriptors is effective, we show that our deep learning technique performs equally well. A potential advantage of the deep learning approach is that there is no need to extract the gist features when training or scoring.
Sravani Yajamanam, Vikash Raja Samuel Selvin, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2017 Static and Dynamic Analysis of Android Malware
Ankita Kapratwar, Fabio Di Troia, Mark Stamp 0001
ICISSP2