EDBT 2026 Demo / reviewers in the wild / expert
Khanh-Huu-The Dam
dblp:198/2407
· DBLP profile ↗
15ranked-venue papers
11as first author
9since 2021 · last 2024
0000-0001-7203-9658ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 8 first-author · 6 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Avoiding "Hot Potato" Problems in Internet Service ProvidersabstractInternet service providers (ISPs) strive to provide the best possible services to their customers. Service outages, or incidents, due to technical failures are inevitable, so the aim of ISPs must be to respond as quickly as possible to error notifications. However, services may rely on thousands of devices and components that are interconnected and managed by different teams (network administrators, technicians, etc.). Identifying the team to which an incident ticket should be assigned becomes a tedious task that slows down recovery time.In this paper we focus on the problem of finding the right team when an incident occurs. We group teams into logical team groups and use machine learning models that we train on previous resolved incidents to predict the most appropriate team group from a failure description. Using a large dataset from a national ISP and telecommunication company, we demonstrate that, even with a small amount of information available at the beginning of the incident, machine learning models can achieve an accuracy of 88.52% and an F1 score of 90.17%. With more complete information about the incident, the accuracy and F1 score increase to 90.52% and 91.7%. Khanh-Huu-The Dam, Gorby Kabasele Ndonda, Axel Legay, Ramin Sadre |
NOMS | 1 |
| 2024 | Analysis of machine learning approaches to packing detection
Charles-Henry Bertrand Van Ouytsel, Khanh-Huu-The Dam, Axel Legay |
Comput. Secur. | 2 |
| 2024 | Feature selection for packer classification based on association rule mining
Rosana Veroneze, Charles-Henry Bertrand Van Ouytsel, Khanh-Huu-The Dam, Axel Legay |
Eng. Appl. Artif. Intell. | 3 |
| 2023 | Mitigate Data Poisoning Attack by Partially Federated LearningabstractAn efficient machine learning model for malware detection requires a large dataset to train. Yet it is not easy to collect such a large dataset without violating or leaving vulnerable to potential violation various aspects of data privacy. Our work proposes a federated learning framework that permits multiple parties to collaborate on learning behavioral graphs for malware detection. Our proposed graph classification framework allows the participating parties to freely decide their preferred classifier model without acknowledging their preferences to the others involved. This mitigates the chance of any data poisoning attacks. In our experiments, our classification model using the partially federated learning achieved the F1-score of 0.97, close to the performance of the centralized data training models. Moreover, the impact of the label flipping attack against our model is less than 0.02. Khanh-Huu-The Dam, Axel Legay |
ARES | 1 |
| 2022 | Symbolic analysis meets federated learning to enhance malware identifierabstractThe manual methods to create detection rules are no longer practical in the anti-malware product since the number of malware threats has been growing over past years. Thus, the turn to machine learning approaches is a promising way to make malware recognition more efficient. The traditional centralized machine learning requires a large amount of data to train a model with excellent performance. To boost the malware detection, the training data might be on various kind of data sources such as data on the host, network, and cloud-based anti-malware components, or even, data from different enterprises. To avoid the expenses of data collection as well as the leakage of private data, we present a federated learning system to identify malware through behavioral graphs, i.e., system call dependency graphs. It is based on a deep learning model including a graph autoencoder and a multiclass classifier module. This model is trained by a secure learning protocol among clients to preserve the private data against inference attacks. Using the model to identify malware, we achieve the accuracy of for homogeneous graph data and for inhomogeneous graph data. Charles-Henry Bertrand Van Ouytsel, Khanh-Huu-The Dam, Axel Legay |
ARES | 2 |
| 2022 | Tool Paper - SEMA: Symbolic Execution Toolchain for Malware Analysis
Charles-Henry Bertrand Van Ouytsel, Christophe Crochet, Khanh-Huu-The Dam, Axel Legay |
CRiSIS | 3 |
| 2022 | Automated Repair of Security Errors in C Programs via Statistical Model Checking: A Proof of Concept
Khanh-Huu-The Dam, Fabien Duchene 0001, Thomas Given-Wilson, Maxime Cordy, Axel Legay |
ISoLA (1) | 1 |
| 2022 | Extracting malicious behavioursabstractIn recent years, the damage cost caused by malwares is huge. Thus, malware detection is a big challenge. The task of specifying malware takes a huge amount of time and engineering effort since it currently requires the manual study of the malicious code. Thus, in order to avoid the tedious manual analysis of malicious codes, this task has to be automatised. To this aim, we propose in this work to represent malicious behaviours using extended API call graphs, where nodes correspond to API function calls, edges specify the execution order between the API functions, and edge labels indicate the dependence relation between API functions parameters. We define new static analysis techniques that allow to extract such graphs from programs, and show how to automatically extract, from a set of malicious and benign programs, an extended API call graph that represents the malicious behaviours. Finally, we show how this graph can be used for malware detection. We implemented our techniques and obtained encouraging results: 95.66% of detection rate with 0% of false alarms. Khanh-Huu-The Dam, Tayssir Touili |
Int. J. Inf. Comput. Secur. | 1 |
| 2021 | MADLIRA: A Tool for Android Malware Detection
Khanh-Huu-The Dam, Tayssir Touili |
ICISSP | 1 |
| 2019 | STAMAD: a STAtic MAlware DetectorabstractOne of the main challenges in malware detection is the discovery of malicious behaviors. This task requires a huge amount of engineering and manual study of the code. To avoid this tedious manual task, we propose in this paper a tool, called STAMAD, that, given a training set of known malwares and benign programs, (1) either automatically extracts malicious behaviors using Information Retrieval techniques, or (2) applies machine learning techniques to automatically learn malwares. Then, in both cases, STAMAD can classify a new given unseen program as malicious or benign. Khanh-Huu-The Dam, Tayssir Touili |
ARES | 1 |
| 2018 | Learning Malware Using Generalized Graph KernelsabstractMachine learning techniques were extensively applied to learn and detect malware. However, these techniques use often rough abstractions of programs. We propose in this work to use a more precise model for programs, namely extended API call graphs, where nodes correspond to API function calls, edges specify the execution order between the API functions, and edge labels indicate the dependence relation between API functions parameters. To learn such graphs, we propose to use Generalized Random Walk Graph Kernels (combined with Support Vector Machines). We implemented our techniques and obtained encouraging results for malware detection: 96.73% of detection rate with 0.73% of false alarms. Khanh-Huu-The Dam, Tayssir Touili |
ARES | 1 |
| 2018 | Precise Extraction of Malicious BehaviorsabstractIn recent years, the damage cost caused by malwares is huge. Thus, malware detection is a big challenge. The task of specifying malware takes a huge amount of time and engineering effort since it currently requires the manual study of the malicious code. Thus, in order to avoid the tedious manual analysis of malicious codes, this task has to be automatized. To this aim, we propose in this work to represent malicious behaviors using extended API call graphs, where nodes correspond to API function calls, edges specify the execution order between the API functions, and edge labels indicate the dependence relation between API functions parameters. We define new static analysis techniques that allow to extract such graphs from programs, and show how to automatically extract, from a set of malicious and benign programs, an extended API call graph that represents the malicious behaviors. Finally, We show how this graph can be used for malware detection. We implemented our techniques and obtained encouraging results: 95.66% of detection rate with 0% of false alarms. Khanh-Huu-The Dam, Tayssir Touili |
COMPSAC (1) | 1 |
| 2017 | Learning Android MalwareabstractThe number of Android malware is increasing every day. Thus Android malware detection is nowadays a big challenge. One of the most tedious tasks in malware detection is the extraction of malicious behaviors. This task is usually done manually and requires a huge effort of engineering. To avoid this step, we propose in this paper to use machine learning techniques for malware detection. Unlike the existing learning based approaches, we propose to use API call graphs to represent the behaviors of Android applications. Then, given a set of malicious applications and a set of benign applications, we apply well-known learning techniques based on Random Walk Graph Kernel (combined with Support Vector Machines). We can achieve a high detection rate with only few false alarms (98.76% for detection rate with 0.24% of false alarms). Khanh-Huu-The Dam, Tayssir Touili |
ARES | 1 |
| 2017 | Malware Detection based on Graph Classification
Khanh-Huu-The Dam, Tayssir Touili |
ICISSP | 1 |
| 2017 | Extracting Android Malicious Behaviors
Khanh-Huu-The Dam, Tayssir Touili |
ICISSP | 1 |