EDBT 2026 Demo / reviewers in the wild / expert
Paulo Lício de Geus
dblp:79/4220 · also Paulo L. de Geus
· DBLP profile ↗
23ranked-venue papers
0as first author
3since 2021 · last 2023
0000-0002-6540-8686ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4Artificial intelligence and machine learning · 3 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Static Analysis for Malware Classification Using Machine and Deep LearningabstractMalware, or malicious software, is a general term to describe any program or code that can be harmful to systems. This hostile, intrusive, and intentionally harmful code makes use of a variety of techniques to protect and evade detection and removal through code obfuscation, polymorphism, metamorphism, encryption, encrypted communication, and more. Current state-of-the-art research focuses on the application of artificial intelligence techniques for the detection and classification of malware. In this context, this paper proposes a new malware classification through static analysis using seven machine learning algorithms (LightGBM, XGBoost, Logistic Regression, KNN, SVM, Naive Bayes, and Random Forest) and deep learning finetuning. These models make use of the SelectKBest technique within data engineering, allowing the selection of the 893 most relevant characteristics for the classification of 10868 malware in 9 families, reducing overfitting and training time. The results show that the application of Gradient Boosting algorithms such as LightGBM with hyperparameter optimization exceeds the reference results in competitions such as Kaggle, with a logarithmic loss 0.00118, an accuracy close to 100%, and prediction times less than 2.3ms. Fast enough to be applied to systems in real time to classify malware. Marcelo Invert Palma Salas, Paulo Lício de Geus |
CLEI | 2 |
| 2022 | AntiViruses under the microscope: A hands-on perspective
Marcus Botacin, Felipe Duarte Domingues, Fabricio Ceschin, Raphael Machnicki, Marco A. Z. Alves, Paulo Lício de Geus, André Ricardo Abed Grégio |
Comput. Secur. | 6 |
| 2021 | One Size Does Not Fit All: A Longitudinal Analysis of Brazilian Financial MalwareabstractMalware analysis is an essential task to understand infection campaigns, the behavior of malicious codes, and possible ways to mitigate threats. Malware analysis also allows better assessment of attackers’ capabilities, techniques, and processes. Although a substantial amount of previous work provided a comprehensive analysis of the international malware ecosystem, research on regionalized, country-, and population-specific malware campaigns have been scarce. Moving towards addressing this gap, we conducted a longitudinal (2012-2020) and comprehensive (encompassing an entire population of online banking users) study of MS Windows desktop malware that actually infected Brazilian banks’ users. We found that the Brazilian financial desktop malware has been evolving quickly: it started to make use of a variety of file formats instead of typical PE binaries, relied on native system resources, and abused obfuscation techniques to bypass detection mechanisms. Our study on the threats targeting a significant population on the ecosystem of the largest and most populous country in Latin America can provide invaluable insights that may be applied to other countries’ user populations, especially those in the developing world that might face cultural peculiarities similar to Brazil’s. With this evaluation, we expect to motivate the security community/industry to seriously consider a deeper level of customization during the development of next-generation anti-malware solutions, as well as to raise awareness towards regionalized and targeted Internet threats. Marcus Botacin, Hojjat Aghakhani, Stefano Ortolani, Christopher Krügel, Giovanni Vigna, Daniela Oliveira 0001, Paulo Lício de Geus, André Ricardo Abed Grégio |
ACM Trans. Priv. Secur. | 7 |
| 2020 | On the Security of Application Installers and Online Software Repositories
Marcus Botacin, Giovanni Bertão, Paulo Lício de Geus, André Ricardo Abed Grégio, Christopher Krügel, Giovanni Vigna |
DIMVA | 3 |
| 2020 | We need to talk about antiviruses: challenges & pitfalls of AV evaluations
Marcus Botacin, Fabricio Ceschin, Paulo Lício de Geus, André Ricardo Abed Grégio |
Comput. Secur. | 3 |
| 2018 | Lumus: Dynamically Uncovering Evasive Android Applications
Vitor Monte Afonso, Anatoli Kalysch, Tilo Müller, Daniela Oliveira 0001, André Ricardo Abed Grégio, Paulo Lício de Geus |
ISC | 6 |
| 2018 | Enhancing Branch Monitoring for Security Purposes: From Control Flow Integrity to Malware Analysis and DebuggingabstractMalware and code-reuse attacks are the most significant threats to current systems operation. Solutions developed to countermeasure them have their weaknesses exploited by attackers through sandbox evasion and antidebug crafting. To address such weaknesses, we propose a framework that relies on the modern processors’ branch monitor feature to allow us to analyze malware while reducing evasion effects. The use of hardware assistance aids in increasing stealthiness, a key feature for debuggers, as modern software (malicious or benign) may be antianalysis armored. We achieve stealthier code execution control by using the branch monitor hardware’s inherent interrupt capabilities, keeping the code under execution intact. Previous works on branch monitoring have already addressed the ROP attack problem but require code injection and/or are limited in their capture window size. Therefore, we also propose a ROP detector without these limitations. Marcus Botacin, Paulo Lício de Geus, André Ricardo Abed Grégio |
ACM Trans. Priv. Secur. | 2 |
| 2017 | Malicious Software Classification Using Transfer Learning of ResNet-50 Deep Neural NetworkabstractMalicious software (malware) has been extensively used for illegal activity and new malware variants are discovered at an alarmingly high rate. The ability to group malware variants into families with similar characteristics makes possible to create mitigation strategies that work for a whole class of programs. In this paper, we present a malware family classification approach using a deep neural network based on the ResNet-50 architecture. Malware samples are represented as byteplot grayscale images and a deep neural network is trained freezing the convolutional layers of ResNet-50 pre-trained on the ImageNet dataset and adapting the last layer to malware family classification. The experimental results on a dataset comprising 9,339 samples from 25 different families showed that our approach can effectively be used to classify malware families with an accuracy of 98.62%. Edmar R. S. De Rezende, Guilherme C. S. Ruppert, Tiago J. Carvalho, Fabio Ramos 0001, Paulo Lício de Geus |
ICMLA | 5 |
| 2016 | Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing Policy
Vitor Monte Afonso, Paulo Lício de Geus, Antonio Bianchi, Yanick Fratantonio, Christopher Krügel, Giovanni Vigna, Adam Doupé, Mario Polino |
NDSS | 2 |
| 2015 | Return on security investment for cloud computing: a customer perspectiveabstractCloud Computing has introduced a variety of models of service delivery and deployment for public clouds, hybrid and private, that changed enterprise computing. Several providers provide these services, and each uses different models and pricing solutions. One of the most complex tasks for IT governance team is to calculate the total cost of an IT service in relation to its potential return, and needs to consider the tangible and intangible benefits (security) with views over the short, medium and long term as well as contract termination costs. To evaluate the Return On Security Investment (ROSI) in Cloud Computing, this paper presents a new qualitative and quantitative approach for calculating the ROSI. Carlos Alberto da Silva, Paulo Lício de Geus |
MEDES | 2 |
| 2015 | Security Testing Methodology for Evaluation of Web Services Robustness - Case: XML InjectionabstractA Web Service is a software system designed to support interoperable machine-to-machine interaction over a network, it also provides a standard means of interoperating between different software applications. However, Web Services have raised new challenges on information security, this technology is susceptible to XML Injection attacks, which would allow an attacker to collect and manipulate information to insert malicious code in either server-side or client-side, being one of the most employed attack against web applications according to the OWASP Top 10. Different studies have shown that the current testing techniques -- penetration testing and fuzzy scanning -- generate several false positives and negatives. However, the fault injection technique improve the robustness of web applications, through the greater flexibility to modify the test cases and to find software bugs. This work describes a fault injection technique for the evaluation of Web Services robustness with WS-Security (Username Token) and the development of a set of rules for vulnerability analysis, resulting on the improvement of the vulnerability detector accuracy. Our results show that 82% of web Services tested were vulnerable to XML Injection attacks. Marcelo Invert Palma Salas, Paulo Lício de Geus, Eliane Martins |
SERVICES | 2 |
| 2015 | Toward a Taxonomy of Malware BehaviorsabstractMalicious code attacks pose a serious threat to the security of information systems, as malware evolved from innocuous conceptual software to advanced and destructive cyber weapons. However, there is still the lack of a comprehensive and useful taxonomy to classify malware according to their behavior, since commonly used names are obsolete and unable to handle the complex and multipurpose currently observed samples. In this article, we present a brief survey on available malware taxonomies, discuss about issues on existing naming schemes and introduce an extensible taxonomy consisting of an initial set of behaviors usually exhibited by malware during an infection. The main goal of our proposed taxonomy is to address the menace of potentially malicious programs based on their observed behaviors, thus aiding in incident response procedures. Finally, we present a case study to evaluate our behavior-centric taxonomy, in which we apply identification patterns extracted from the proposed taxonomy to over 12 thousand known malware samples. The leveraged results show that it is possible to screen malicious programs that exhibit suspicious behaviors, even when they remain undetected by antivirus tools. André Ricardo Abed Grégio, Vitor Monte Afonso, Dario Simões Fernandes Filho, Paulo Lício de Geus, Mário Jino |
Comput. J. | 4 |
| 2014 | Ontology for Malware Behavior: A Core Model ProposalabstractThe ubiquity of Internet-connected devices motivates attackers to create malicious programs (malware) to exploit users and their systems. Malware detection requires a deep understanding of their possible behaviors, one that is detailed enough to tell apart suspicious programs from benign, legitimate ones. A step to effectively address the malware problem leans toward the development of an ontology. Current efforts are based on an obsolete hierarchy of malware classes that defines a malware family by one single prevalent behavior (e.g., viruses infect other files, worms spread and exploit remote systems autonomously, Trojan horses disguise themselves as benign programs, and so on). In order to address the detection of modern, complex malware families whose infections involve sets of multiple exploit methods, we need an ontology broader enough to deal with these suspicious activities performed on the victim's system. In this paper, we propose a core model for a novel malware ontology that is based on their exhibited behavior, filling a gap in the field. André Ricardo Abed Grégio, Rodrigo Bonacin, Olga Nabuco, Vitor Monte Afonso, Paulo Lício de Geus, Mário Jino |
WETICE | 5 |
| 2012 | Tracking Memory Writes for Malware Classification and Code Reuse Identification
André Ricardo Abed Grégio, Paulo Lício de Geus, Christopher Krügel, Giovanni Vigna |
DIMVA | 2 |
| 2012 | A hybrid framework to analyze web and OS malwareabstractMalicious programs (malware) cause serious security issues to home users and even to highly secured enterprise systems. The main infection vector currently used by attackers is the Internet. To improve the detection rate and to develop protection mechanisms, it is very important to analyze and study these threats. To this end, several systems were developed to perform malware analysis, which support operating system (OS) programs or Web codes, but they all suffer from limitations. Also, the existing systems focus only on one type of malware, those that target the OS or that require a Web browser. In this article, we propose a framework that is able to analyze Web and OS-based malware, which provides better detection rates and a broader range of malware types analysis. We have also evaluated and compared our analysis results to the state-of-the-art systems, presenting the advantages of the developed framework over them when regarding Web and OS-based malware. Vitor Monte Afonso, Dario Simões Fernandes Filho, André Ricardo Abed Grégio, Paulo Lício de Geus, Mário Jino |
ICC | 4 |
| 2012 | Interactive Analysis of Computer Scenarios through Parallel Coordinates Graphics
Gabriel D. Cavalcante, Sébastien Tricaud, Cleber P. Souza, Paulo Lício de Geus |
ICCSA (4) | 4 |
| 2012 | Pinpointing Malicious Activities through Network and System-Level Malware Execution Behavior
André Ricardo Abed Grégio, Vitor Monte Afonso, Dario Simões Fernandes Filho, Paulo Lício de Geus, Mário Jino, Rafael Duarte Coelho dos Santos |
ICCSA (4) | 4 |
| 2012 | Interactive, Visual-Aided Tools to Analyze Malware Behavior
André Ricardo Abed Grégio, Alexandre Or Cansian Baruque, Vitor Monte Afonso, Dario Simões Fernandes Filho, Paulo Lício de Geus, Mário Jino, Rafael Duarte Coelho dos Santos |
ICCSA (4) | 5 |
| 2011 | Scalable model-based configuration management of security services in complex enterprise networksabstractAbstract Security administrators face the challenge of designing, deploying and maintaining a variety of configuration files related to security systems, especially in large‐scale networks. These files have heterogeneous syntaxes and follow differing semantic concepts. Nevertheless, they are interdependent due to security services having to cooperate and their configuration to be consistent with each other, so that global security policies are completely and correctly enforced. To tackle this problem, our approach supports a comfortable definition of an abstract high‐level security policy and provides an automated derivation of the desired configuration files. It is an extension of policy‐based management and policy hierarchies, combining model‐based management (MBM) with system modularization. MBM employs an object‐oriented model of the managed system to obtain the details needed for automated policy refinement. The modularization into abstract subsystems (ASs) segment the system—and the model—into units which more closely encapsulate related system components and provide focused abstract views. As a result, scalability is achieved and even comprehensive IT systems can be modelled in a unified manner. The associated tool MoBaSeC (Model‐Based‐Service‐Configuration) supports interactive graphical modelling, automated model analysis and policy refinement with the derivation of configuration files. We describe the MBM and AS approaches, outline the tool functions and exemplify their applications and results obtained. Copyright © 2010 John Wiley & Sons, Ltd. João Porto de Albuquerque, Heiko Krumm, Paulo Lício de Geus, René Jeruschkat |
Softw. Pract. Exp. | 3 |
| 2008 | Model-based management of security services in complex network environmentsabstractThe security mechanisms employed in current networked environments are increasingly complex, and their configuration management has an important role for the protection of these environments. Especially in large scale networks, security administrators are faced with the challenge of designing, deploying, maintaining and monitoring a huge number of mechanisms, most of which have complicated and heterogeneous configuration syntaxes. Consequently, configuration errors are nowadays a frequent cause of security vulnerabilities. This paper summarizes results from a doctoral thesis that offers an approach to the configuration management of network security systems specially suited to the needs of the complex environments of today's organizations. The approach relies upon policy-based management and model-based management, extending these approaches with a modeling framework that allows the design of security systems to be performed in a modular fashion. The model is segmented into logical units (so-called Abstract Subsystems) that enclose a group of security mechanisms and other relevant system entities, offering a more abstract representation of them. In this manner, the administrator is able to design a security system-including its different mechanism types and their mutual relations-by means of an abstract and uniform modeling technique. A software tool supports the approach, offering a diagram editor for models. After the model is complete, the tool performs an automated policy refinement, deriving configuration parameters for each security mechanism in the system. João Porto de Albuquerque, Heiko Krumm, Paulo Lício de Geus |
NOMS | 3 |
| 2007 | A Policy-Based Framework for Interoperable Digital Content ManagementabstractThrough the past years, several digital rights man- agement (DRM) solutions for controlled dissemination of dig- ital information have been developed using cryptography and other technologies. Within so many different solutions, however, interoperability problems arise, which increase the interest on integrated design and management of these technologies. Pursu- ing these goals, this paper presents a framework which aims at promoting interoperability among DRM systems, using a service- oriented architecture (SOA) and a high-level policy modeling approach. Fernando Marques Figueira Filho, João Porto de Albuquerque, Paulo Lício de Geus, Heiko Krumm |
CCNC | 3 |
| 2005 | On Scalability and Modularisation in the Modelling of Network Security Systems
João Porto de Albuquerque, Heiko Krumm, Paulo Lício de Geus |
ESORICS | 3 |
| 2004 | An intrusion detection system using ideas from the immune systemabstractThis paper proposes an intrusion detection framework and presents a prototype for an intrusion detection system based on it. This framework takes architectural inspiration from the human immune system and brings desirable features to intrusion detection systems, such as automated intrusion recovery, attack signature extraction, and potential to improve behavior-based detection. These features are enabled through intrusion evidence detection. The prototype, called ADENOIDS, is designed to deal with application attacks, extracting signature for remote buffer overflow attacks. The framework and ADENOIDS are described and experimental results are presented. Fabricio Sergio de Paula, Leandro Nunes de Castro, Paulo Lício de Geus |
IEEE Congress on Evolutionary Computation | 3 |