Natalia Stakhanova

dblp:34/2916 · DBLP profile ↗
← Back
52ranked-venue papers
8as first author
25since 2021 · last 2026
0000-0003-1923-319XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 35 · 7 first-author · 13 since 2021Computer networks · 9 · 8 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Security risk assessment of android automotive OS software supply chain using firmware reverse engineering
abstract
As Android Automotive OS (AAOS) becomes the in-vehicle platform of choice for infotainment and domain-controller functions in modern passenger cars, its software supply chain has emerged as a critical security frontier. AAOS spans both infotainment and vehicle-control domains within the automotive electronics architecture by supporting media streaming, over-the-air updates, navigation, and sensor fusion. Its open-source foundations and reliance on third-party libraries introduce risks, from outdated components to malicious modules, that can undermine vehicle functionality and passenger safety. In recognition of these threats, ISO/SAE 21434 and UNECE WP.29 R155 mandate structured security assessments for vehicular systems to prevent software-chain vulnerabilities from compromising safety. In this study, we apply a shift-right security analysis via firmware reverse engineering to AAOS images from four leading OEMs. We unpack each firmware image, extract software bills of materials (SBOMs), map Common Vulnerabilities and Exposures (CVE) to components, and characterize system-level attack surfaces across infotainment and control subsystems. Proof-of-concept exploits were developed for high-risk vulnerabilities. One critical CVE was successfully triggered, while others were mitigated by missing dependencies or built-in protections. Our work delivers a reproducible firmware-analysis workflow for automotive supply-chain risk assessment, a comparative survey of third-party and proprietary component management, and the evidence of inconsistent security postures in AAOS-based vehicular electronics. These vulnerabilities underscore the need for harmonized SBOM practices and targeted hardening in next-generation in-vehicle systems.
Hanbo Yu, Faiyaz Khan, Steven H. H. Ding, Natalia Stakhanova, Benjamin C. M. Fung
Comput. Secur.5
2026 Detecting and Characterizing the Hidden Collaborative Network Supporting Ethereum Scams
abstract
Similar to all other cryptocurrency platforms, Ethereum is constantly confronted with malicious activities. In recent years, research efforts have targeted the detection and mitigation of malicious activities and the associated accounts within the Ethereum ecosystem. Yet, the malicious accounts represent only a small visible part of the substantial collaborative network enabling these activities. In this work, we offer the first analysis of this collaborative network and the corresponding affiliate accounts that often remain hidden from detection. We present enEtherShield, an enhanced framework for detecting affiliate accounts that assist malicious accounts in the related Ethereum scams. Our research findings lay the foundation for the detection of the collaborative network enabling Ethereum scams.
Bofeng Pan, Andrei Natadze, Enrico Branca, Jadyn Kimber, Natalia Stakhanova
ACM Trans. Internet Techn.5
2025 Revealing Unreported OT Vulnerabilities from Public Discussions
Arslane Fawzi Halilou, Natalia Stakhanova
CRiSIS2
2025 More Than You Signed Up For: Exposing Gaps in the Validation of Android's App Signing
Norah Ridley, Enrico Branca, Natalia Stakhanova
DIMVA (2)3
2025 An End to End Analysis of Crypto Scams on Ethereum
abstract
The increasing number of Ethereum scams is causing significant concern within the blockchain community, costing users millions of dollars annually. Yet, our understanding of how these scams operate remains limited. In this study, we present the first end-to-end analysis of crypto scams using a large set of malicious Ethereum accounts as a case study. We examine the tactics these scams employ on social media platforms to deceive users and convince them to transfer funds to malicious accounts. Our analysis explores the full life cycle of these scams, considering both their distribution through social media and their activity on the Ethereum blockchain. We identify several unique aspects of Ethereum phishing scams that have not been documented in prior literature and find that these scams generally persist significantly longer and result in greater financial losses compared to traditional phishing scams studied in earlier research.
Jadyn Kimber, Enrico Branca, Andrei Natadze, Natalia Stakhanova
ACM Trans. Internet Techn.4
2025 Measuring and Characterizing Propagation of Reuse RSA Certificates and Keys Across PKI Ecosystem
abstract
The insecurities of public-key infrastructure on the Internet have been the focus of research for over a decade. The extensive presence of broken, weak, and vulnerable cryptographic keys has been repeatedly emphasized by many studies. Analyzing the security implications of cryptographic keys’ vulnerabilities, several studies noted the presence of public key reuse. While the phenomenon of private key sharing was extensively studied, the prevalence of public key sharing on the Internet remains largely unknown. In this work, we perform a large-scale analysis of public key reuse within the PKI ecosystem. We investigate the presence and distribution of duplicate X.509 certificates and reused RSA public keys across a large collection containing over 314 million certificates and over 13 million SSH keys collected by different sources at different times. We analyze the cryptographic weaknesses of duplicate certificates and reused keys and investigate the reasons and sources of reuse. Our results reveal that certificate and key sharing are common and persistent. Our findings show over 10 million certificates and 17 million public keys are reused across time and shared between our collections. We observe keys with non-compliant cryptographic elements stay available for an extended period of time.
Fatemeh Nezhadian, Enrico Branca, Anna Barzolevskaia, Andrei Natadze, Natalia Stakhanova
IEEE Trans. Netw.5
2024 Decoding Android Permissions: A Study of Developer Challenges and Solutions on Stack Overflow
abstract
Background: The Android permission system is a set of controls to regulate access to sensitive data and platform resources (e.g., cameras). The fast-evolving nature of Android permissions and inadequate documentation result in numerous challenges for third-party developers. Aims: This study investigates the permission-related challenges developers face and the solutions provided to resolve them on the crowdsourcing platform Stack Overflow. Method: We conducted qualitative and quantitative analyses on 3,327 permission-related questions and 3,271 corresponding answers. Results: We found that most questions are related to non-evolving SDK permissions that remain constant across various Android versions, emphasizing the lack of documentation. We also classify developers’ challenges into several categories: Documentation-Related, Problems with Dependencies, Debugging, Conceptual Understanding, and Implementation Issues. Conclusions: Our study indicates the need for clear, consistent documentation to guide the use of permissions and reduce developer misunderstandings, which can lead to potential misuse of Android permissions.
Sahrima Jannat Oishwee, Zadia Codabux, Natalia Stakhanova
ESEM3
2024 Adversarial Analysis of Software Composition Analysis Tools
Ekaterina Ivanova, Natalia Stakhanova, Bahman Sistany
ISC (2)2
2024 Large Language Model vs. Stack Overflow in Addressing Android Permission Related Challenges
abstract
The Android permission system regulates access to sensitive mobile device resources such as camera and location. To access these resources, third-party developers need to request permissions. However, the Android permission system is complex and fast-evolving, presenting developers with numerous challenges surrounding compatibility issues, misuse of permissions, and vulnerabilities related to permissions. Our study aims to explore whether Large Language Models (LLMs) can serve as a reliable tool to assist developers in using Android permissions correctly and securely, thereby reducing the risks of misuse and security vulnerabilities in apps. In our study, we analyzed 1,008 Stack Overflow questions related to Android permissions and their accepted answers. In parallel, we generate answers to these questions using a popular LLM tool, ChatGPT. We focused on how well the ChatGPT's responses align with the accepted answers on Stack Overflow. Our findings show that above 50% of ChatGPT's answers align with Stack Overflow's accepted answers. ChatGPT offers better-aligned responses for challenges related to Documentation and Conceptual Understanding, while it provides less aligned answers for Debugging-related issues. In addition, we found that ChatGPT provides more consistent answers for 73.27% questions. Our study demonstrates the potential for using LLMs such as ChatGPT as a supporting tool to help developers navigate Android permission-related problems.
Sahrima Jannat Oishwee, Natalia Stakhanova, Zadia Codabux
MSR2
2024 Authenticated Range Querying of Historical Blockchain Healthcare Data Using Authenticated Multi-Version Index
abstract
With growing adoption of blockchain in established and emerging applications, there is an increasing need to support efficient ad hoc querying of authenticated historical data. This is especially true in fields such as healthcare to meet the rigorous security and regulatory requirements of ever-expanding digital health platforms. Existing blockchain systems, however, offer little or no support for querying capabilities over historical data. Although a full blockchain archive node can be used to maintain historical records of all executed transactions on the chain, it is not scalable when dealing with large volumes of data. Moreover, such ‘offline’ historical data lack tamper evidence support. To address these issues, we introduce an authenticated index structure called Authenticated Multi-Version Skip List (AMVSL), designed to support a rich set of query features over historical blockchain data. We further present three range queries: SVRK, MVRK, and MVAK, which offer querying over a range of keys and a range of versions. Our experimental evaluation of two healthcare-inspired examples demonstrates that AMVSL efficiently supports these queries and can achieve performance that is several orders of magnitude faster than existing authenticated data structures.
Shlomi Linoy, Suprio Ray, Natalia Stakhanova, Erik J. Scheme
Distributed Ledger Technol. Res. Pract.3
2024 Guest Editorial: Special section on Networks, Systems, and Services Operations and Management Through Intelligence
abstract
Machine Learning (ML) and Artificial Intelligence (AI) can harness the immense amount of operational data from clouds to services, to social and communication networks. In the era of data science and connected devices of all varieties, Intelligence have found ways to improve operations and management of next generation networks, systems, and services. Further research is therefore needed to understand and improve the potential and suitability of ML/AI in the context of network, system, and service operations and management. This will provide deeper understanding and better decision making based on largely collected and available operational and management data. It will also present opportunities for improving ML/AI algorithms on aspects such as reliability, dependability, and scalability, as well as demonstrate the benefits of these methods in control and management systems. Moreover, there is an opportunity to define novel platforms that can harness the vast operational data and advance ML/AI algorithms to drive management decisions in open and highly programmable networks, clouds, and data centers.
Nur Zincir-Heywood, Robert Birke, Elias Bou-Harb, Takeru Inoue, Neeraj Kumar 0001, Hanan Lutfiyya, Deepak Puthal, Abdallah Shami, Natalia Stakhanova
IEEE Trans. Netw. Serv. Manag.9
2024 EtherShield: Time-interval Analysis for Detection of Malicious Behavior on Ethereum
abstract
Advances in blockchain technology have attracted significant attention across the world. The practical blockchain applications emerging in various domains, ranging from finance, healthcare, and entertainment, have quickly become attractive targets for adversaries. The novelty of the technology coupled with the high degree of anonymity it provides made malicious activities even less visible in the blockchain environment. This made their robust detection challenging. This article presents EtherShield, a novel approach for identifying malicious activity on the Ethereum blockchain. By combining temporal transaction information and contract code characteristics, EtherShield can detect various types of threats and provide insight into the behavior of contracts. The time-interval-based analysis used by EtherShield enables expedited detection, achieving comparable accuracy to other approaches with significantly less data. Our validation analysis, which involved over 15,000 Ethereum accounts, demonstrated that EtherShield can significantly expedite the detection of malicious activity while maintaining high accuracy levels (86.52% accuracy with 1 hour of transaction history data and 91.33% accuracy with 1 year of transaction history data).
Bofeng Pan, Natalia Stakhanova, Zhongwen Zhu
ACM Trans. Internet Techn.2
2024 Measuring and Characterizing (Mis)compliance of the Android Permission System
abstract
Within the Android mobile operating system, Android permissions act as a system of safeguards designed to restrict access to potentially sensitive data and privileged components. Multiple research studies indicate flaws and limitations of the Android permission system, prompting Google to implement a more regulated and fine-grained permission model. This newly-introduced complexity creates confusion for developers leading to incorrect permissions and a significant risk to users security and privacy. We present a systematic study of theoretical and practical misuse of permissions. For this analysis we derive the unified permissions and call mappings that represent theoretical requirements of permissions and calls. We develop PChecker, an approach that identifies the discrepancies between the official Android permissions documentation and permission implementation in the Android platform source code based on these mappings. We evaluate four versions of the Android Open Source Project code (major versions 10–13) and shed light on the prevalence of discrepancies between the official Android guidelines for permissions and their implementation in the Android platform source code. We further show that these discrepancies result in miscompliance in third-party Android apps.
Anna Barzolevskaia, Enrico Branca, Natalia Stakhanova
IEEE Trans. Software Eng.3
2023 Exploiting Android Browser
Animesh Kar, Natalia Stakhanova
CANS2
2023 Certificate Reuse in Android Applications
Fatemeh Nezhadian, Enrico Branca, Natalia Stakhanova
ISC3
2023 Learning AI Coding Style for Software Plagiarism Detection
Sri Haritha Ambati, Natalia Stakhanova, Enrico Branca
SecureComm (2)2
2023 Dataset Characteristics for Reliable Code Authorship Attribution
abstract
Code authorship attribution aims to identify the author of software source code according to the author’s unique coding style characteristics. The lack of benchmark data in the field, forced researchers to employ various resources that often did not reflect real programming practices. Throughout the years, research studies have used textbook examples, students’ programming assignments, faculty code samples, code from programming competitions and files retrieved from open-source repositories as research objects. The diversity of the data raised concerns about the feasibility of capturing the appropriate data characteristics to reliably evaluate code attribution. In this paper, we investigate these concerns and analyze the effect of the dataset characteristics and feature elimination techniques on the accuracy of code attribution. Unlike the majority of the work done in this field, which mainly concentrates on designing new features, we explore the nature of the data used in previous studies and assess the factors that influence the attribution task. Within this analysis, we investigate the robustness of three feature sets regarded as reliable benchmarks in the attribution research. Based on our findings, we define a process for deriving a reduced set of features for accurate and predictable attribution and make recommendations on the dataset characteristics.
Farzaneh Abazari, Enrico Branca, Norah Ridley, Natalia Stakhanova, Mila Dalla Preda
IEEE Trans. Dependable Secur. Comput.4
2023 Guest Editorial: Special Section on Machine Learning and Artificial Intelligence for Managing Networks, Systems, and Services - Part II
abstract
Machine learning and artificial intelligence can harness the immense stream of operational data from clouds, to services, to social and communication networks. In the era of big data and connected devices of all varieties, machine learning and artificial intelligence have found ways to improve operations and management of information technology and communications.
Nur Zincir-Heywood, Robert Birke, Elias Bou-Harb, Giuliano Casale, Khalil El-Khatib, Takeru Inoue, Neeraj Kumar 0001, Hanan Lutfiyya, Deepak Puthal, Abdallah Shami, Natalia Stakhanova, Farhana Zulkernine
IEEE Trans. Netw. Serv. Manag.11
2022 Analysis and prediction of web proxies misbehavior
Zahra Nezhadian, Enrico Branca, Natalia Stakhanova
ARES3
2022 AndroClonium: Bytecode-Level Code Clone Detection for Obfuscated Android Apps
Ardalan Foroughipour, Natalia Stakhanova, Farzaneh Abazari, Bahman Sistany
SEC2
2022 HTTPFuzz: Web Server Fingerprinting with HTTP Request Fuzzing
Animesh Kar, Andrei Natadze, Enrico Branca, Natalia Stakhanova
SECRYPT4
2022 Language and Platform Independent Attribution of Heterogeneous Code
Farzaneh Abazari, Enrico Branca, Evgeniya Novikova, Natalia Stakhanova
SecureComm4
2022 Guest Editorial: Special Issue on Machine Learning and Artificial Intelligence for Managing Networks, Systems, and Services - Part I
abstract
Machine learning and artificial intelligence can harness the immense stream of operational data from clouds, to services, to social and communication networks. In the era of big data and connected devices of all varieties, machine learning and artificial intelligence have found ways to improve operations and management of information technology and communications.
Nur Zincir-Heywood, Robert Birke, Elias Bou-Harb, Giuliano Casale, Khalil El-Khatib, Takeru Inoue, Neeraj Kumar 0001, Hanan Lutfiyya, Deepak Puthal, Abdallah Shami, Natalia Stakhanova, Farhana Zulkernine
IEEE Trans. Netw. Serv. Manag.11
2022 Automated Security Assessment Framework for Wearable BLE-enabled Health Monitoring Devices
abstract
The growth of IoT technology, increasing prevalence of embedded devices, and advancements in biomedical technology have led to the emergence of numerous wearable health monitoring devices (WHMDs) in clinical settings and in the community. The majority of these devices are Bluetooth Low Energy (BLE) enabled. Though the advantages offered by BLE-enabled WHMDs in tracking, diagnosing, and intervening with patients are substantial, the risk of cyberattacks on these devices is likely to increase with device complexity and new communication protocols. Furthermore, vendors face risk and financial tradeoffs between speed to market and ensuring device security in all situations. Previous research has explored the security and privacy of such devices by manually testing popular BLE-enabled WHMDs in the market and generally discussed categories of possible attacks, while mostly focused on IP devices. In this work, we propose a new semi-automated framework that can be used to identify and discover both known and unknown vulnerabilities in WHMDs. To demonstrate its implementation, we validate it with a number of commercially available BLE-enabled enabled wearable devices. Our results show that the devices are vulnerable to a number of attacks, including eavesdropping, data manipulation, and denial of service attacks. The proposed framework could therefore be used to evaluate potential devices before adoption into a secure network or, ideally, during the design and implementation of new devices.
Ghazale Amel Zendehdel, Ratinder Kaur, Inderpreet Chopra, Natalia Stakhanova, Erik J. Scheme
ACM Trans. Internet Techn.4
2021 Origin Attribution of RSA Public Keys
Enrico Branca, Farzaneh Abazari, Ronald Rivera Carranza, Natalia Stakhanova
SecureComm (1)4
2019 PoliDOM: Mitigation of DOM-XSS by Detection and Prevention of Unauthorized DOM Tampering
abstract
The current generation of DOM (Document Object Model) Cross-Site Scripting (DOM-XSS) filters are mostly browser-based tools, and do not allow the web developers to control authorized or unauthorized modifications of the web page's DOM. In this work, we propose a policy-based and browser-based protection mechanism to detect and prevent unauthorized tampering of the DOM. To examine the efficiency and feasibility of our approach, we implement the proposed solution in an open source web browser, Chromium. Our proposed approach has little performance overhead and effectively detects malicious modifications of the DOM. We also conduct a thorough analysis of the current state-of-the-art policy-based MutationObserver API and uncover its limitations.
Junaid Iqbal, Ratinder Kaur, Natalia Stakhanova
ARES3
2019 Exploring Ethereum's Blockchain Anonymity Using Smart Contract Code Attribution
abstract
Blockchain users are identified by addresses (public keys), which cannot be easily linked back to them without out-of-network information. This provides pseudo-anonymity, which is amplified when the user generates a new address for each transaction. Since all transaction history is visible to all users in public blockchains, finding affiliation between related addresses can hurt pseudo-anonymity. Such affiliation information can be used to discriminate against addresses that were found to be related to a specific group, or can even lead to the de-anonymization of all addresses in the associated group, if out-of-network information is available on a few addresses in that group. In this work we propose to leverage a stylometry approach on Ethereum's deployed smart contracts' bytecode and high level source code, which is publicly available by third party platforms. We explore the extent to which a deployed smart contract's source code can contribute to the affiliation of addresses. To address this, we prepare a dataset of real-world Ethereum smart contracts data, which we make publicly available; design and implement feature selection, extraction techniques, data refinement heuristics, and examine their effect on attribution accuracy. We further use these techniques to test the classification of real-world scammers data.
Shlomi Linoy, Natalia Stakhanova, Alina Matyukhina
CNSM2
2019 Adversarial Authorship Attribution in Open-Source Projects
abstract
Open-source software is open to anyone by design, whether it is a community of developers, hackers or malicious users. Authors of open-source software typically hide their identity through nicknames and avatars. However, they have no protection against authorship attribution techniques that are able to create software author profiles just by analyzing software characteristics. In this paper we present an author imitation attack that allows to deceive current authorship attribution systems and mimic a coding style of a target developer. Withing this context we explore the potential of the existing attribution techniques to be deceived. Our results show that we are able to imitate the coding style of the developers based on the data collected from the popular source code repository, GitHub. To subvert author imitation attack, we propose a novel author obfuscation approach that allows us to hide the coding style of the author. Unlike existing obfuscation tools, this new obfuscation technique uses transformations that preserve code readability. We assess the effectiveness of our attacks on several datasets produced by actual developers from GitHub, and participants of the GoogleCodeJam competition. Throughout our experiments we show that the author hiding can be achieved by making sensible transformations which significantly reduce the likelihood of identifying the author's style to 0% by current authorship attribution systems.
Alina Matyukhina, Natalia Stakhanova, Mila Dalla Preda, Celine Perley
CODASPY2
2018 Android authorship attribution through string analysis
abstract
With the rising popularity of Android mobile devices, the amount of malicious applications targeting the Android platform has been increasing tremendously. To mitigate the risk of malicious apps, there is a need for an automated system to detect these applications. Current detection techniques rely on the signatures of well-documented malware, and hence may not be able to detect new malware samples. Instead of generating signatures for malware samples themselves, in this work, we propose to develop a lightweight system that can generate signatures of malware writers by leveraging the string components present in their Android binaries. Using these author signatures, we can effectively detect a wide range of existing, as well as any new, malware samples generated by particular authors. The proposed system achieved 98%, 96%, and 71% accuracy over datasets of 1559 benign, 262 malicious, and 96 obfuscated Android applications, respectively. The string-based approach achieved 71% of accuracy compared to only 50% obtained with the existing Ding and Samadzadeh's system.
Vaibhavi Kalgutkar, Natalia Stakhanova, Paul Cook, Alina Matyukhina
ARES2
2018 Authorship Attribution of Android Apps
abstract
Since the first computer virus hit the Advanced Research Projects Agency Network (ARPANET) in the early 1970s, the security community interest revolved around ways to expose the identities of malware writers. Knowledge of the adversarial identities promised additional leverage to security experts in their ongoing battle against those perpetrators. At the dawn of computing era, when malware writers and malicious software were characterized by the lack of experience and relative simplicity, the task of uncovering the identities of virus writers was more or less straightforward. Manual analysis of source code often revealed personal, identifiable information embedded by authors themselves. But these times have long gone. Modern day's malware writers extensively use numerous malware code generators to mass produce new variants and employ advanced obfuscation techniques to hide their identities. As a result the work of security experts trying to uncover the identities of malware writers became significantly more challenging and time consuming.
Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001
CODASPY2
2018 A Security Assessment of HCE-NFC Enabled E-Wallet Banking Android Apps
abstract
E-wallets have started to grow in popularity, reaching a tipping point in some countries. This can be attributed to the worldwide use of payment-enabled devices and ubiquity of e-wallet acceptance by larger and smaller retailers. As more customers adopt e-wallets they may also become a big target of cybercrime. E-wallets facilitates financial transactions via smartphones which is a lucrative opportunity for cybercriminals. This paper presents a security assessment of the Android e-wallet apps provided by the Canada's leading banks.
Ratinder Kaur, Junaid Iqbal, Hugo Gonzalez, Natalia Stakhanova
COMPSAC (2)5
2018 Unmasking Android Obfuscation Tools Using Spatial Analysis
abstract
Android has become one of the most popular mo-bile device operating systems. Indeed, its security issues have attracted a lot of attention. One of the major security concerns is the use of obfuscation strategies to evade anti-malware solutions. Android malware authors are increasingly using code obfuscation tools and techniques to hide malicious code. In this work, we in- troduce a novel fingerprinting approach for Android obfuscation tools based on spatial analysis. We investigate first-order and second-order statistical features to analyze spatial distribution of pixels representing Android binary images. With our approach, we are able to achieve nearly 90% accuracy in fingerprinting several obfuscation tools with specific configuration options.
Ratinder Kaur, Hugo Gonzalez, Natalia Stakhanova
PST4
2017 Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling
Hossein Hadian Jazi, Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001
Comput. Networks3
2016 Detecting Malicious URLs Using Lexical Analysis
Mohammad Saiful Islam Mamun, Mohammad Ahmad Rathore, Arash Habibi Lashkari, Natalia Stakhanova, Ali A. Ghorbani 0001
NSS4
2016 Measuring code reuse in Android apps
abstract
The appearance of the Android platform and its popularity has resulted in a sharp rise in the number of reported vulnerabilities and consequently in the number of mobile threats. Leveraging openness of Android app markets and the lack of security testing, malware authors commonly plagiarize Android applications through code reuse, boosting the amount of malware on the markets and consequently the infection rate. In the last few years the number of studies focused on detection of mobile app code reuse has drastically increased. Ranging from lightweight detection of suspicious signs to more sophisticated and computationally expensive methods assessing apps' similarity, the studies treated the presence of code reuse as a sign of plagiarized apps and maliciousness. In this work, we revisit this assumption and investigate code reuse in legitimate and malicious mobile apps. The main questions that this study aims to answer are what it is that is being reused, what we can learn from this reuse and consequently how we can use this knowledge. To answer these questions we measure code uniqueness and identify common components originating from third-party sources. We further analyze and correlate reused code extracted from over 60,000 apps from ten markets around the world and commonly used app repositories. As our analysis shows, understanding code reuse can shed some light on app origin and evolution.
Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001
PST2
2015 A Performance Evaluation of Hash Functions for IP Reputation Lookup Using Bloom Filters
abstract
IP reputation lookup is one of the traditional methods for recognition of blacklisted IPs, i.e., IP addresses known to be sources of spam and malware-related threats. Its use however has been rapidly increasing beyond its traditional domain reaching various IP filtering tasks. One of the solutions able to provide a necessary scalability is a Bloom filter. Efficient in memory consumption, Bloom filters provide a fast membership check, allowing to confirm a presence of set elements in a data structure with a constant false positive probability. With the increased usage of IP reputation check and an increasing adoption of IPv6 protocol, Bloom filters quickly gained popularity. In spite of their wide application, the question of what hash functions to use in practice remains open. In this work, we investigate a 10 cryptographic and non-cryptographic functions for on their suitability for Bloom filter analysis for IP reputation lookup. Experiments are performed with controlled, randomly generated IP addresses as well as a real dataset containing blacklisted IP addresses. Based on our results we recommend two hash functions for their performance and acceptably low false positive rate.
Marc Antoine Gosselin-Lavigne, Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001
ARES3
2015 An Entropy Based Encrypted Traffic Classifier
Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001, Natalia Stakhanova
ICICS3
2015 Android Botnets: What URLs are Telling Us
Andi Fitriah Abdul Kadir, Natalia Stakhanova, Ali A. Ghorbani 0001
NSS2
2015 Application-layer denial of service attacks: taxonomy and survey
abstract
The recent escalation of application-layer denial of service (DoS) attacks has attracted a significant interest of the security research community. Since application-layer DoS attacks usually do not manifest themselves at the network level, they avoid traditional network-layer-based detection. Therefore, the security community has focused on specialised application-layer DoS attacks detection and mitigation mechanisms. However, the deployment of reliable and efficient defence mechanisms against these attacks requires the comprehensive understanding of the existing application-layer DoS attacks supported by a unified terminology. Thus, in this paper we address this issue and devise a taxonomy of application-layer DoS attacks. By devising the proposed taxonomy, we intend to give researchers a better understanding of these attacks and provide a foundation for organising research efforts within this specific field.
Georgios Mantas, Natalia Stakhanova, Hugo Gonzalez, Hossein Hadian Jazi, Ali A. Ghorbani 0001
Int. J. Inf. Comput. Secur.2
2014 DroidKin: Lightweight Detection of Android Apps Similarity
Hugo Gonzalez, Natalia Stakhanova, Ali A. Ghorbani 0001
SecureComm (1)2
2012 Towards cost-sensitive assessment of intrusion response selection
abstract
In recent years, cost-sensitive intrusion response has gained significant interest mainly due to its emphasis on the balance between potential damage incurred by the intrusion and cost of the response. However, one of the challenges in applying this approach is defining consistent and adaptable measurements of these cost factors on the basis of requirements and policy of the system being protected against intrusions. In this paper we present a framework for the cost-sensitive selection of intrusion response. Specifically, we introduce a set of measurements that characterize potential costs associated with the intrusion handling process and propose evaluation method of intrusion response with respect to the risk of potential intrusion damage, effectiveness of response action and response cost for a system. We provide an implementation of the proposed solution as a plugin tool for Snort IDS and demonstrate its advantages on DARPA data set and real network traffic.
Natalia Stakhanova, Chris Strasburg, Samik Basu 0001, Johnny S. Wong
J. Comput. Secur.1
2010 An Online Adaptive Approach to Alert Correlation
Hanli Ren, Natalia Stakhanova, Ali A. Ghorbani 0001
DIMVA2
2010 Selective Regular Expression Matching
Natalia Stakhanova, Hanli Ren, Ali A. Ghorbani 0001
ISC1
2010 On the symbiosis of specification-based and anomaly-based detection
Natalia Stakhanova, Samik Basu 0001, Johnny S. Wong
Comput. Secur.1
2010 Toward Credible Evaluation of Anomaly-Based Intrusion-Detection Methods
abstract
Since the first introduction of anomaly-based intrusion detection to the research community in 1987, the field has grown tremendously. A variety of methods and techniques introducing new capabilities in detecting novel attacks were developed. Most of these techniques report a high detection rate of 98% at the low false alarm rate of 1%. In spite of the anomaly-based approach's appeal, the industry generally favors signature-based detection for mainstream implementation of intrusion-detection systems. While a variety of anomaly-detection techniques have been proposed, adequate comparison of these methods' strengths and limitations that can lead to potential commercial application is difficult. Since the validity of experimental research in academic computer science, in general, is questionable, it is plausible to assume that research in anomaly detection shares the above problem. The concerns about the validity of these methods may partially explain why anomaly-based intrusion-detection methods are not adopted by industry. To investigate this issue, we review the current state of the experimental practice in the area of anomaly-based intrusion detection and survey 276 studies in this area published during the period of 2000-2008. We summarize our observations and identify the common pitfalls among surveyed works.
Mahbod Tavallaee, Natalia Stakhanova, Ali A. Ghorbani 0001
IEEE Trans. Syst. Man Cybern. Part C2
2009 Intrusion response cost assessment methodology
abstract
In this paper we present a structured methodology for evaluating cost of responses based on three factors: the response operational cost associated with the daily maintenance of the response, the response goodness that measures the applicability of the selected response for a detected intrusion and the response impact on the system that refers to the possible response effect on the system functionality. The proposed approach provides a consistent basis for response evaluation across different systems while incorporating security policy and properties of the specific system environment.
Chris Strasburg, Natalia Stakhanova, Samik Basu 0001, Johnny S. Wong
AsiaCCS2
2008 A Behavioral Model of Ideologically-motivated "Snowball" Attacks
abstract
As our daily life depends more and more on Internet technology, it also becomes increasingly susceptible to new types of cyber threats. These threats often take a form of innovative malicious behavior and commonly emerge in a pace that exceeds the capability of security experts to develop timely solutions to counter such threats. In this context it becomes particularly important to develop a good understanding of the complete cycle of malicious behavior including its evolution and the factors contributing to its spread so that these types of threats are addressed in proactive manner. In this paper we describe and define the new type of recently emerged threat - the ideologically-motivated "snow ball" attack. We develop a conceptual model for explaining the evolution of ideologically motivated attacks and discuss a set of methods that can be used to detect and respond to this type of threat at all stages of its development. Finally, we use the recent case of ideologically motivated attack - the attack on Estonia's cyber infrastructure to evaluate our conceptual model.
Natalia Stakhanova, Oleg Stakhanov, Ali A. Ghorbani 0001
ARES1
2008 On Evaluation of Response Cost for Intrusion Response Systems
Natalia Stakhanova, Chris Strasburg, Samik Basu 0001, Johnny S. Wong
RAID1
2007 A Cost-Sensitive Model for Preemptive Intrusion Response Systems
abstract
The proliferation of complex and fast-spreading intrusions not only requires advances in intrusion detection mechanisms but also demands development of sophisticated and automated intrusion response systems. In this paper we present a novel cost-sensitive model for intrusion response that incorporates preemptive deployment of the response actions. Specifically, our technique relies on comparing the cost of deploying a response against the cost of damage caused by an "'un-attended" intrusion and decides to preemptively deploy a response with maximum benefit. Our technique further allows adaptation of responses to the changing environment through evaluation of success and failure of previously triggered responses. We demonstrate the advantages of the approach and evaluate it using a damage reduction metric.
Natalia Stakhanova, Samik Basu 0001, Johnny S. Wong
AINA1
2007 Software fault tree and coloured Petri net-based specification, design and implementation of agent-based intrusion detection systems
abstract
The integration of Software Fault Tree (SFT), which describes intrusions and Coloured Petri Nets (CPNs) that specifies design, is examined for an Intrusion Detection System (IDS). The IDS under development is a collection of mobile agents that detect, classify, and correlate the system and network activities. SFTs, augmented with nodes that describe trust, temporal and contextual relationships, are used to describe intrusions. CPNs for intrusion detection are built using CPN templates created from the augmented SFTs. Hierarchical CPNs are created to detect critical stages of intrusions. The agentbased implementation of the IDS is then constructed from the CPNs. Examples of intrusions and descriptions of the prototype implementation are used to demonstrate how the CPN approach has been used in the development of the IDS. The main contribution of this paper is an approach to systematic specification, design and implementation of an IDS; Innovations include (1) using stages of intrusions to structure the specification and design of the IDS; (2) augmentation of SFT with trust, temporal and contextual nodes to model intrusions; (3) algorithmic construction of CPNs from augmented SFT; and (4) generation of mobile agents from CPNs.
Guy G. Helmer, Johnny S. Wong, Mark Slagell, Vasant G. Honavar, Leslie L. Miller, Natalia Stakhanova
Int. J. Inf. Comput. Secur.8
2007 A taxonomy of intrusion response systems
abstract
Recent advances in intrusion detection field brought new requirements to intrusion prevention and response. Traditionally, the response to an attack was manually triggered by an administrator. However, increased complexity and speed of the attack-spread during recent years showed acute necessity for complex dynamic response mechanisms. Although intrusion detection systems are being actively developed, research efforts in intrusion response are still isolated. In this work we present taxonomy of intrusion response systems, together with a review of current trends in intrusion response research. We also provide a set of essential fetures as a requirement for an ideal intrusion response system.
Natalia Stakhanova, Samik Basu 0001, Johnny S. Wong
Int. J. Inf. Comput. Secur.1
2006 Automated Caching of Behavioral Patterns for Efficient Run-Time Monitoring
abstract
Run-time monitoring is a powerful approach for dynamically detecting faults or malicious activity of software systems. However, there are often two obstacles to the implementation of this approach in practice: (1) that developing correct and/or faulty behavioral patterns can be a difficult, labor-intensive process, and (2) that use of such pattern-monitoring must provide rapid turn-around or response time. We present a novel data structure, called extended action graph, and associated algorithms to overcome these drawbacks. At its core, our technique relies on effectively identifying and caching specifications from (correct/faulty) patterns learned via machine-learning algorithm. We describe the design and implementation of our technique and show its practical applicability in the domain of security monitoring of sendmail software
Natalia Stakhanova, Samik Basu 0001, Robyn R. Lutz, Johnny S. Wong
DASC1