Mark Stamp 0001

dblp:80/4529 · also Mark Steven Stamp · DBLP profile ↗
← Back
23ranked-venue papers
1as first author
8since 2021 · last 2026
0000-0002-3803-8368ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 7 since 2021Artificial intelligence and machine learning · 3Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 A Comparison of Selected Image Transformation Techniques for Malware Classification
Rishit Agrawal, Kunal Bhatnagar, Andrew Do, Ronnit Rana, Martin Jurecek, Mark Stamp 0001
ICISSP (2)6
2026 Detecting Concept Drift in Evolving Malware Families Using Rule-Based Classifier Representations
Tomás Kalný, Martin Jurecek, Mark Stamp 0001
SECRYPT (1)3
2023 Darknet traffic classification and adversarial attacks using machine learning
abstract
The anonymous nature of darknets is commonly exploited for illegal activities. Previous research has employed machine learning and deep learning techniques to automate the detection of darknet traffic in an attempt to block these criminal activities. This research aims to improve darknet traffic detection by assessing a wide variety of machine learning and deep learning techniques for the classification of such traffic and for classification of the underlying application types. We find that a Random Forest model outperforms other state-of-the-art machine learning techniques used in prior work with the CIC-Darknet2020 dataset. To evaluate the robustness of our Random Forest classifier, we obfuscate select application type classes to simulate realistic adversarial attack scenarios. We demonstrate that our best-performing classifier can be degraded by such attacks, and we consider ways to effectively deal with such adversarial attacks.
Nhien Rust-Nguyen, Mark Stamp 0001
Comput. Secur.3
2023 An empirical analysis of the shift and scale parameters in BatchNorm
abstract
Batch Normalization (BatchNorm) is a technique that improves the training of deep neural networks, especially Convolutional Neural Networks (CNN). It has been empirically demonstrated that BatchNorm increases performance, stability, and accuracy, although the reasons for such improvements are unclear. BatchNorm includes a normalization step as well as trainable shift and scale parameters. In this paper, we empirically examine the relative contribution to the success of BatchNorm of the normalization step, as compared to the re-parameterization via shifting and scaling. To conduct our experiments, we implement two new optimizers in PyTorch, namely, a version of BatchNorm that we refer to as AffineLayer, which includes the re-parameterization step without normalization, and a version with just the normalization step, that we call BatchNorm-minus. We compare the performance of our AffineLayer and BatchNorm-minus implementations to standard BatchNorm, and we also compare these to the case where no batch normalization is used. We experiment with four ResNet architectures (ResNet18, ResNet34, ResNet50, and ResNet101) over a standard image dataset and multiple batch sizes. Among other findings, we provide empirical evidence that the success of BatchNorm may derive primarily from improved weight initialization.
Yashna Peerthum, Mark Stamp 0001
Inf. Sci.2
2021 Malware Classification using Long Short-term Memory Models
abstract
Signature and anomaly based techniques are the quintessential approaches to malware detection. However, these techniques have become increasingly ineffective as malware has become more sophisticated and complex. Researchers have therefore turned to deep learning to construct better performing model. In this paper, we create four different long-short term memory (LSTM) based models and train each to classify malware samples from 20 families. Our features consist of opcodes extracted from malware executables. We employ techniques used in natural language processing (NLP), including word embedding and bidirection LSTMs (biLSTM), and we also use convolutional neural networks (CNN). We find that a model consisting of word embedding, biLSTMs, and CNN layers performs best in our malware classification experiments.
Dennis Dang, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2021 A New Dataset for Smartphone Gesture-based Authentication
abstract
In this paper, we consider the problem of authentication on a smartphone, based on gestures. Specifically, the gestures consist of users holding a smartphone while writing their initials in the air. Accelerometer data from 80 subjects was collected and we provide a preliminary analysis of this data using machine learning techniques. The machine learning techniques considered include principal component analysis (PCA) and support vector machines (SVM). The results presented here are intended to provide a baseline for additional research based on our dataset.
Elliu Huang, Fabio Di Troia, Mark Stamp 0001, Preethi Sundaravaradhan
ICISSP3
2021 Malware Classification with Word Embedding Features
abstract
Malware classification is an important and challenging problem in information security. Modern malware classification techniques rely on machine learning models that can be trained on features such as opcode sequences, API calls, and byte n-grams, among many others. In this research, we consider opcode features. We implement hybrid machine learning techniques, where we engineer feature vectors by training hidden Markov models—a technique that we refer to as HMM2Vec—and Word2Vec embeddings on these opcode sequences. The resulting HMM2Vec and Word2Vec embedding vectors are then used as features for classification algorithms. Specifically, we consider support vector machine (SVM), k-nearest neighbor (k-NN), random forest (RF), and convolutional neural network (CNN) classifiers. We conduct substantial experiments over a variety of malware families. Our experiments extend well beyond any previous related work in this field.
Aparna Sunil Kale, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2021 Malware Classification with GMM-HMM Models
abstract
Discrete hidden Markov models (HMM) are often applied to malware detection and classification problems. However, the continuous analog of discrete HMMs, that is, Gaussian mixture model-HMMs (GMM-HMM), are rarely considered in the field of cybersecurity. In this paper, we use GMM-HMMs for malware classification and we compare our results to those obtained using discrete HMMs. As features, we consider opcode sequences and entropy-based sequences. For our opcode features, GMM-HMMs produce results that are comparable to those obtained using discrete HMMs, whereas for our entropy-based features, GMM-HMMs generally improve significantly on the classification results that we have achieved with discrete HMMs.
Samanvitha Basole, Mark Stamp 0001
ICISSP3
2020 Detecting malware evolution using support vector machines
Mayuri Wadkar, Fabio Di Troia, Mark Stamp 0001
Expert Syst. Appl.3
2019 Transfer Learning for Image-based Malware Classification
abstract
In this paper, we consider the problem of malware detection and classification based on image analysis. We convert executable files to images and apply image recognition using deep learning (DL) models. To train these models, we employ transfer learning based on existing DL models that have been pre-trained on massive image datasets. We carry out various experiments with this technique and compare its performance to that of an extremely simple machine learning technique, namely, k-nearest neighbors (\kNN). For our k-NN experiments, we use features extracted directly from executables, rather than image analysis. While our image-based DL technique performs well in the experiments, surprisingly, it is outperformed by k-NN. We show that DL models are better able to generalize the data, in the sense that they outperform k-NN in simulated zero-day experiments.
Niket Bhodia, Pratikkumar Prajapati, Fabio Di Troia, Mark Stamp 0001
ICISSP4
2019 A Comparative Analysis of Android Malware
abstract
In this paper, we present a comparative analysis of benign and malicious Android applications, based on static features. In particular, we focus our attention on the permissions requested by an application. We consider both binary classification of malware versus benign, as well as the multiclass problem, where we classify malware samples into their respective families. Our experiments are based on substantial malware datasets and we employ a wide variety of machine learning techniques, including decision trees and random forests, support vector machines, logistic model trees, AdaBoost, and artificial neural networks. We find that permissions are a strong feature and that by careful feature engineering, we can significantly reduce the number of features needed for highly accurate detection and classification.
Neeraj Chavan, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2019 Feature analysis of encrypted malicious traffic
Anish Singh Shekhawat, Fabio Di Troia, Mark Stamp 0001
Expert Syst. Appl.3
2018 Acoustic Gait Analysis using Support Vector Machines
abstract
Gait analysis, defined as the study of human locomotion, can provide valuable information for low-cost analytic and classification applications in security, medical diagnostics, and biomechanics. In comparison to visual-based gait analysis, audio-based gait analysis offers robustness to clothing variations, visibility issues, and angle complications. Current acoustic techniques rely on frequency-based features that are sensitive to changes in footwear and floor surfaces. In this research, we consider an approach to surface-independent acoustic gait analysis based on time differences between consecutive steps. We employ support vector machines (SVMs) for classification. Our approach achieves good classification rates with high discriminative one-vs-all capabilities and we believe that our technique provides a promising avenue for future development.
Jasper Huang, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2018 Autocorrelation Analysis of Financial Botnet Traffic
abstract
A botnet consists of a network of infected computers that can be controlled remotely via a command and control (C&C) server. Typically, a botnet requires frequent communication between a C&C server and the infected nodes. Previous approaches to detecting botnets have included various machine learning techniques based on features extracted from network traffic. In this research, we conduct autocorrelation analysis of traffic generated by financial botnets, and we show that periodicity is a highly distinguishing feature for detecting such botnets.
Prathiba Nagarajan, Fabio Di Troia, Thomas H. Austin, Mark Stamp 0001
ICISSP4
2018 Deep Learning versus Gist Descriptors for Image-based Malware Classification
abstract
Image features known as ``gist descriptors'' have recently been applied to the malware classification problem. In this research, we implement, test, and analyze a malware score based on gist descriptors, and verify that the resulting score yields very strong classification results. We also analyze the robustness of this gist-based scoring technique when applied to obfuscated malware, and we perform feature reduction to determine a minimal set of gist features. Then we compare the effectiveness of a deep learning technique to this gist-based approach. While scoring based on gist descriptors is effective, we show that our deep learning technique performs equally well. A potential advantage of the deep learning approach is that there is no need to extract the gist features when training or scoring.
Sravani Yajamanam, Vikash Raja Samuel Selvin, Fabio Di Troia, Mark Stamp 0001
ICISSP4
2017 Static and Dynamic Analysis of Android Malware
Ankita Kapratwar, Fabio Di Troia, Mark Stamp 0001
ICISSP3
2014 HTTP attack detection using n-gram analysis
Aditya Oza, Kevin Ross, Richard M. Low, Mark Stamp 0001
Comput. Secur.4
2013 Deriving common malware behavior through graph clustering
Younghee Park, Douglas S. Reeves, Mark Stamp 0001
Comput. Secur.3
2011 Masquerade detection using profile hidden Markov models
Mark Stamp 0001
Comput. Secur.2
2008 QuickPay Online Payment Protocol
Mark Stamp 0001
SEKE2
2008 An agent-based privacy-enhancing model
abstract
Purpose The purpose of this paper is to discuss a privacy‐enhancing model, which is designed to help web users protect their private information. The model employs a collection of software agents. Privacy‐related decisions are made based on Platform for Privacy Preferences Project (P3P) information collected by the agents. Design/methodology/approach Based on P3P information collected and user preferences, the software agents play a role in the decision‐making process. This paper presents the design of the agent‐based privacy‐enhancing model and considers the benefits and utility of such an approach. Findings It is argued that the approach is feasible and it provides an effective solution to the usability limitations associated with P3P. Research limitations/implications The paper focuses primarily on usability issues related to P3P. Consequently, some of the ancillary security‐related issues that arise are not covered in detail. Also the paper does not cover the development of an appropriate ontology in significant detail. Practical implications Based on this analysis and extensive testing of the prototype, it is believed that the privacy‐enhancing model presented provides a sound basis for privacy protection on the web. While the emphasis here is on resolving the usability problems associated with P3P, a few straightforward enhancements to the implementation would make it a genuinely practical tool. Originality/value The usability of the P3P framework is generally considered its weak point. The paper provides a practical solution to this usability problem. One is not aware of any comparable work.
Hsu-Hui Lee, Mark Stamp 0001
Inf. Manag. Comput. Secur.2
2007 Solvable problems in enterprise digital rights management
abstract
Purpose Digital rights management (DRM) is often promoted as the technical basis for solutions to enterprise security problems requiring persistent protection. Yet to date, DRM has failed to take hold within the enterprise sphere. This paper aims to examine some possible reasons for the slow adoption of enterprise DRM. Design/methodology/approach It is argued that contrary to the common perception current DRM technology is sufficiently robust for use in enterprise applications. Then three problems that may serve as barriers to enterprise DRM adoption, namely, trustworthy authentication, access policy management and the lack of compelling enterprise applications that require DRM are discussed. Finally, brief examples are presented drawn from the real world that illustrate that the first two barriers can be overcome, and it is argued that regulatory compliance is the “killer app” that will drive enterprise DRM adoption. Findings Finds, amongst other things, that technical weakness in enterprise DRM systems, especially regarding authentication and authorization, can be addressed with relatively simple mechanisms. Originality/value This paper points up the need for more sophisticated enterprise DRM solutions.
E. John Sebes, Mark Stamp 0001
Inf. Manag. Comput. Secur.2
1993 An algorithm for the k-error linear complexity of binary sequences with period 2n
abstract
Certain applications require pseudo-random sequences which are unpredictable in the sense that recovering more of the sequence from a short segment must be computationally infeasible. It is shown that linear complexity is useful in determining such sequences. A generalized linear complexity that has application to the security of stream ciphers is proposed, and an efficient algorithm is given for the case in which the sequence is binary with period 2/sup n/. This algorithm generalizes an algorithm presented by R.A. Games and A.H. Chan (1983).>
Mark Stamp 0001, Clyde Martin
IEEE Trans. Inf. Theory1