EDBT 2026 Demo / reviewers in the wild / expert
Duy-Phuc Pham
dblp:232/0241
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2022
0000-0003-3149-0957ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | ULTRA: Ultimate Rootkit Detection over the AirabstractRootkits are the most challenging malware threats against server and desktop systems. They are created by highly skilled actors and are deployed in advanced persistent threat attacks. Lately and even in the future, rootkits will become a real threat to billions of IoT devices. Existing malware detection techniques based on static or dynamic analysis face major shortcomings, which become more apparent when it is necessary to detect threats on IoT devices. Duy-Phuc Pham, Damien Marion 0001, Annelie Heuser |
RAID | 1 |
| 2021 | Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware ClassificationabstractThe Internet of Things (IoT) is constituted of devices that are exponentially growing in number and in complexity. They use numerous customized firmware and hardware, without taking into consideration security issues, which make them a target for cybercriminals, especially malware authors. Duy-Phuc Pham, Damien Marion 0001, Matthieu Mastio, Annelie Heuser |
ACSAC | 1 |
| 2021 | Poster: Obfuscation Revealed - Using Electromagnetic Emanation to Identify and Classify MalwareabstractIn this poster we present a novel approach of using side channel information to identify the kinds of malware threats that are targeting IoT devices. Although in the presence of obfuscation techniques that can prevent static or symbolic binary analysis, a malware researcher may obtain detailed information about malware type and identification using our method by leveraging side channel by electromagnetism rather than software-layer malware analysis. By capturing 100,000 measurement traces from an IoT system infected with different malware samples, we can obtain this information without altering the actual hardware. As a result, it can be implemented without any overhead, regardless of the resources available. Furthermore, our method has the advantage of non-trivial for malware authors to avoid. We were able to distinguish malware families based on side-channel knowledge without being able to see what exact hardware was involved. We were able to predict three generic malware forms (and one benign class) with a 99.89% percent accuracy in our tests. Furthermore, our results show that we are able to classify altered malware samples with unseen obfuscation techniques during the training phase, and to determine what kind of obfuscations, which makes our approach particularly useful for malware analysts. Duy-Phuc Pham, Damien Marion 0001, Annelie Heuser |
EuroS&P | 1 |