EDBT 2026 Demo / reviewers in the wild / expert
Ilir Gashi
dblp:71/6662
· DBLP profile ↗
22ranked-venue papers
6as first author
4since 2021 · last 2026
0000-0002-8017-3184ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 8 · 2 first-author · 1 since 2021Systems, architecture and hardware · 3 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Statistical Assessment of Bayes-"sub"Optimal Binary Machine Learning Classifier Risk
Abraham Chan, Ilir Gashi, Sathish Gopalakrishnan, Karthik Pattabiraman, Kizito Salako |
SAFECOMP | 2 |
| 2022 | Dynamical analysis of diversity in rule-based open source network intrusion detection systemsabstractAbstract Diverse layers of defence play an important role in the design of defence-in-depth architectures. The use of Intrusion Detection Systems (IDSs) are ubiquitous in this design. But the selection of the “right” IDSs in various configurations is an important decision that the security architects need to make. Additionally, the ability of these IDSs to adapt to the evolving threat-landscape also needs to be investigated. To help with these decisions, we need rigorous quantitative analysis. In this paper, we present a diversity analysis of open-source IDSs, Snort and Suricata, to help security architects tune/deploy these IDSs. We analyse two types of diversities in these IDSs; configurational diversity and functional diversity. In the configurational diversity analysis, we investigate the diversity in the sets of rules and the Blacklisted IP Addresses (BIPAs) these IDSs use in their configurations. The functional diversity analysis investigates the differences in alerting behaviours of these IDSs when they analyse real network traffic, and how these differences evolve. The configurational diversity experiment utilises snapshots of the rules and BIPAs collected over a period of 5 months, from May to October 2017. The snapshots have been collected for three different off-the-shelf default configurations of the Snort IDS and the Emerging Threats (ET) configuration of the Suricata IDS. The functional diversity investigates the alerting behaviour of these two IDSs for a sample of the real network traffic collected in the same time window. Analysing the differences in these systems allows us to get insights into where the diversity in the behaviour of these systems comes from, how does it evolve and whether this has any effect on the alerting behaviour of these IDSs. This analysis gives insight to security architects on how they can combine and layer these systems in a defence-in-depth deployment. Hafiz ul Asad, Ilir Gashi |
Empir. Softw. Eng. | 2 |
| 2022 | Predicting the Discovery Pattern of Publically Known Exploited VulnerabilitiesabstractVulnerabilities with publically known exploits typically form 2-7% of all vulnerabilities reported for a given software version. With a smaller number of known exploited vulnerabilities compared with the total number of vulnerabilities, it is more difficult to model and predict when a vulnerability with a known exploit will be reported. In this paper, we introduce an approach for predicting the discovery pattern of publically known exploited vulnerabilities using all publically known vulnerabilities reported for a given software. Eight commonly used vulnerability discovery models (VDMs) and one neural network model (NNM) were utilized to evaluate the prediction capability of our approach. We compared their predictions results with the scenario when only exploited vulnerabilities were used for prediction. Our results show that, in terms of prediction accuracy, out of eight software we analyzed, our approach led to more accurate results in seven cases. Only in one case, the accuracy of our approach was worse by 1.6%. Yazdan Movahedi, Michel Cukier, Ilir Gashi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Waste not: Using diverse neural networks from hyperparameter search for improved malware detection
Matilda Rhode, Ilir Gashi |
Comput. Secur. | 3 |
| 2020 | Follow the Blue Bird: A Study on Threat Data Published on Twitter
Fernando Alves, Ambrose Andongabo, Ilir Gashi, Pedro M. Ferreira 0001, Alysson Neves Bessani |
ESORICS (1) | 3 |
| 2019 | Vulnerability prediction capability: A comparison between vulnerability discovery models and neural network models
Yazdan Movahedi, Michel Cukier, Ilir Gashi |
Comput. Secur. | 3 |
| 2018 | Detecting Malicious Web Scraping Activity: A Study with Diverse DetectorsabstractWe present results on the use of diverse monitoring tools for the detection of malicious web scraping activity. We have carried out an analysis of a real dataset of Apache HTTP Access logs for an e-commerce application provided by a large multinational IT provider for the global travel and tourism industry. Two tools have been used to detect scraping activities based on the HTTP requests: a commercial tool, and an in-house tool called Arcane. We show the benefits that can be achieved through the use of both systems, in terms of overall sensitivity and specificity, and we discuss the potential sources of diversity between the tool's alert patterns. Zayani Dabbabi, Miruna-Mihaela Mironescu, Olivier Thonnard, Alysson Neves Bessani, Frances V. Buontempo, Ilir Gashi |
PRDC | 7 |
| 2018 | Diversity in Open Source Intrusion Detection Systems
Hafiz ul Asad, Ilir Gashi |
SAFECOMP | 2 |
| 2017 | Diversity with intrusion detection systems: An empirical studyabstractDefence-in-depth is a term often used in security literature to denote architectures in which multiple security protection systems are deployed to defend the valuable assets of an organization (e.g. the data and the services). In this paper we present an approach for analysing defence-in-depth, and illustrate the use of the approach with an empirical study in which we have assessed the detection capabilities of intrusion detection systems when deployed in diverse, two-version, parallel defence-in-depth configurations. The configurations have been assessed in settings that favour detection of attacks (reducing false negatives), as well as settings that favour legitimate traffic (reducing false positives). Areej Algaith, Ivano Alessandro Elia, Ilir Gashi, Marco Vieira |
NCA | 3 |
| 2017 | AVAMAT: AntiVirus and malware analysis toolabstractWe present AVAMAT: AntiVirus and Malware Analysis Tool - a tool for analysing the malware detection capabilities of AntiVirus (AV) products running on different operating system (OS) platforms. Even though similar tools are available, such as VirusTotal and MetaDefender, they have several limitations, which motivated the creation of our own tool. With AVAMAT we are able to analyse not only whether an AV detects a malware, but also at what stage of inspection does it detect it and on what OS. AVAMAT enables experimental campaigns to answer various research questions, ranging from the detection capabilities of AVs on OSs, to optimal ways in which AVs could be combined to improve malware detection capabilities. Pasha Shahegh, Tommy Dietz, Michel Cukier, Areej Algaith, Attila Brozik, Ilir Gashi |
NCA | 6 |
| 2014 | Interoperability between Fingerprint Biometric Systems: An Empirical StudyabstractFingerprints are likely the most widely used biometric in commercial as well as law enforcement applications. With the expected rapid growth of fingerprint authentication in mobile devices their importance justifies increased demands for dependability. An increasing number of new sensors, applications and a diverse user population also intensify concerns about the interoperability in fingerprint authentication. In most applications, fingerprints captured for user enrollment with one device may need to be "matched" with fingerprints captured with another device. We have performed a large-scale study with 494 participants whose fingerprints were captured with 4 different industry-standard optical fingerprint devices. We used two different image quality algorithms to evaluate fingerprint images, and then used three different matching algorithms to calculate match scores. In this paper we present a comprehensive analysis of dependability and interoperability attributes of fingerprint authentication and make empirically-supported recommendations on their deployment strategies. Stephen Mason, Ilir Gashi, Luca Lugini, Emanuela Marasco, Bojan Cukic |
DSN | 2 |
| 2014 | Analysis of operating system diversity for intrusion toleranceabstractOne of the key benefits of using intrusion-tolerant systems is the possibility of ensuring correct behavior in the presence of attacks and intrusions. These security gains are directly dependent on the components exhibiting failure diversity. To what extent failure diversity is observed in practical deployment depends on how diverse are the components that constitute the system. In this paper, we present a study with operating system's (OS's) vulnerability data from the NIST National Vulnerability Database (NVD). We have analyzed the vulnerabilities of 11 different OSs over a period of 18 years, to check how many of these vulnerabilities occur in more than one OS. We found this number to be low for several combinations of OSs. Hence, although there are a few caveats on the use of NVD data to support definitive conclusions, our analysis shows that by selecting appropriate OSs, one can preclude (or reduce substantially) common vulnerabilities from occurring in the replicas of the intrusion-tolerant system. Copyright © 2013 John Wiley & Sons, Ltd. Miguel Garcia 0002, Alysson Neves Bessani, Ilir Gashi, Nuno Neves 0001, Rafael R. Obelheiro |
Softw. Pract. Exp. | 3 |
| 2013 | A study of the relationship between antivirus regressions and label changesabstractAntiVirus (AV) products use multiple components to detect malware. A component which is found in virtually all AVs is the signature-based detection engine: this component assigns a particular signature label to a malware that the AV detects. In previous analysis [1–3], we observed cases of regressions in several different AVs: i.e. cases where on a particular date a given AV detects a given malware but on a later date the same AV fails to detect the same malware. We studied this aspect further by analyzing the only externally observable behaviors from these AVs, namely whether AV engines detect a malware and what labels they assign to the detected malware. In this paper we present the results of the analysis about the relationship between the changing of the labels with which AV vendors recognize malware and the AV regressions. Ilir Gashi, Bertrand Sobesto, Stephen Mason, Vladimir Stankovic 0002, Michel Cukier |
ISSRE | 1 |
| 2013 | Does Malware Detection Improve with Diverse AntiVirus Products? An Empirical Study
Ilir Gashi, Bertrand Sobesto, Vladimir Stankovic 0002, Michel Cukier |
SAFECOMP | 1 |
| 2011 | OS diversity for intrusion tolerance: Myth or reality?abstractOne of the key benefits of using intrusion-tolerant systems is the possibility of ensuring correct behavior in the presence of attacks and intrusions. These security gains are directly dependent on the components exhibiting failure diversity. To what extent failure diversity is observed in practical deployment depends on how diverse are the components that constitute the system. In this paper we present a study with operating systems (OS) vulnerability data from the NIST National Vulnerability Database. We have analyzed the vulnerabilities of 11 different OSes over a period of roughly 15 years, to check how many of these vulnerabilities occur in more than one OS. We found this number to be low for several combinations of OSes. Hence, our analysis provides a strong indication that building a system with diverse OSes may be a useful technique to improve its intrusion tolerance capabilities. Miguel Garcia 0002, Alysson Neves Bessani, Ilir Gashi, Nuno Neves 0001, Rafael R. Obelheiro |
DSN | 3 |
| 2011 | Diversity for Security: A Study with Off-the-Shelf AntiVirus EnginesabstractWe have previously reported [1] the results of an exploratory analysis of the potential gains in detection capability from using diverse AntiVirus products. The analysis was based on 1599 malware samples collected from a distributed honey pot deployment over a period of 178 days. The malware samples were sent to the signature engines of 32 different AntiVirus products hosted by the Virus Total service. The analysis suggested significant gains in detection capability from using more than one AntiVirus product in a one-out-of-two intrusion-tolerant setup. In this paper we present new analysis of this dataset to explore the detection gains that can be achieved from using more diversity (i.e. more than two AntiVirus products), how diversity may help to reduce the "at risk time" of a system and a preliminary model-fitting using the hyper-exponential distribution. Peter Bishop 0001, Robin E. Bloomfield, Ilir Gashi, Vladimir Stankovic 0002 |
ISSRE | 3 |
| 2009 | An Experimental Study of Diversity with Off-the-Shelf AntiVirus EnginesabstractFault tolerance in the form of diverse redundancy is well known to improve the detection rates for both malicious and non-malicious failures. What is of interest to designers of security protection systems are the actual gains in detection rates that they may give. In this paper we provide exploratory analysis of the potential gains in detection capability from using diverse AntiVirus products for the detection of self-propagating malware. The analysis is based on 1599 malware samples collected by the operation of a distributed honeypot deployment over a period of 178 days. We sent these samples to the signature engines of 32 different antivirus products taking advantage of the virus total service. The resulting dataset allowed us to perform analysis of the effects of diversity on the detection capability of these components as well as how their detection capability evolves in time. Ilir Gashi, Vladimir Stankovic 0002, Corrado Leita, Olivier Thonnard |
NCA | 1 |
| 2009 | Uncertainty explicit assessment of off-the-shelf software: A Bayesian approach
Ilir Gashi, Peter T. Popov, Vladimir Stankovic 0002 |
Inf. Softw. Technol. | 1 |
| 2008 | Comparison of Empirical Data from Two Honeynets and a Distributed Honeypot NetworkabstractIn this paper we present empirical results and speculative analysis based on observations collected over a two month period from studies with two high interaction honeynets, deployed in a corporate and an SME (small to medium enterprise) environment, and a distributed honeypots deployment. All three networks contain a mixture of Windows and Linux hosts. We detail the architecture of the deployment and results of comparing the observations from the three environments. We analyze in detail the times between attacks on different hosts, operating systems, networks or geographical location. Even though results from honeynet deployments are reported often in the literature, this paper provides novel results analyzing traffic from three different types of networks and some initial exploratory models. This research aims to contribute to endeavours in the wider security research community to build methods, grounded on strong empirical work, for assessment of the robustness of computer-based systems in hostile environments. Robin E. Bloomfield, Ilir Gashi, Andrey Povyakalo, Vladimir Stankovic 0002 |
ISSRE | 2 |
| 2007 | Reliability Modeling of a 1-Out-Of-2 System: Research with Diverse Off-The-Shelf SQL Database ServersabstractFault tolerance via design diversity is often the only viable way of achieving sufficient dependability levels when using off-the-shelf components. We have reported previously on studies with bug reports of four open-source and commercial off-the-shelf database servers and later release of two of them. The results were very promising for designers of fault-tolerant solutions that wish to employ diverse servers: very few bugs caused failures in more than one server and none caused failure in more than two. In this paper we offer details of two approaches we have studied to construct reliability growth models for a 1-out-of-2 fault-tolerant server which utilize the bug reports. The models presented are of practical significance to system designers wishing to employ diversity with off-the-shelf components since often the bug reports are the only direct dependability evidence available to them. Peter Bishop 0001, Ilir Gashi, Bev Littlewood, David Wright 0001 |
ISSRE | 2 |
| 2007 | Fault Tolerance via Diversity for Off-the-Shelf Products: A Study with SQL Database ServersabstractIf an off-the-shelf software product exhibits poor dependability due to design faults, then software fault tolerance is often the only way available to users and system integrators to alleviate the problem. Thanks to low acquisition costs, even using multiple versions of software in a parallel architecture, which is a scheme formerly reserved for few and highly critical applications, may become viable for many applications. We have studied the potential dependability gains from these solutions for off-the-shelf database servers. We based the study on the bug reports available for four off-the-shelf SQL servers plus later releases of two of them. We found that many of these faults cause systematic noncrash failures, which is a category ignored by most studies and standard implementations of fault tolerance for databases. Our observations suggest that diverse redundancy would be effective for tolerating design faults in this category of products. Only in very few cases would demands that triggered a bug in one server cause failures in another one, and there were no coincident failures in more than two of the servers. Use of different releases of the same product would also tolerate a significant fraction of the faults. We report our results and discuss their implications, the architectural options available for exploiting them, and the difficulties that they may present. Ilir Gashi, Peter T. Popov, Lorenzo Strigini |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2004 | Fault Diversity among Off-The-Shelf SQL Database ServersabstractFault tolerance is often the only viable way of obtaining the required system dependability from systems built out of "off-the-shelf" (OTS) products. We have studied a sample of bug reports from four off-the-shelf SQL servers so as to estimate the possible advantages of software fault tolerance - in the form of modular redundancy with diversity - in complex off-the-shelf software. We checked whether these bugs would cause coincident failures in more than one of the servers. We found that very few bugs affected two of the four servers, and none caused failures in more than two. We also found that only four of these bugs would cause identical, undetectable failures in two servers. Therefore, a fault-tolerant server, built with diverse off-the-shelf servers, seems to have a good chance of delivering improvements in availability and failure rates compared with the individual off-the-shelf servers or their replicated, nondiverse configurations. Ilir Gashi, Peter T. Popov, Lorenzo Strigini |
DSN | 1 |