EDBT 2026 Demo / reviewers in the wild / expert
Tobias Wüchner
dblp:84/9824
· DBLP profile ↗
7ranked-venue papers
7as first author
0since 2021 · last 2019
0000-0002-7524-5550ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Databases, data mining, and information retrieval
1 paper |
Data mining · 100% | |
| Network and information security
1 paper |
Malware analysis · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Data mining › structured data mining
graph mining |
0.4 | 1 | 2019 | Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection · IEEE Trans. Dependable Secur. Comput. 2019 |
Data mining
pattern mining |
0.4 | 1 | 2019 | Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection · IEEE Trans. Dependable Secur. Comput. 2019 |
Malware analysis › malware detection
behavior-based malware detection |
0.4 | 1 | 2019 | Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection · IEEE Trans. Dependable Secur. Comput. 2019 |
Malware analysis › mobile malware detection › android malware detection
graph-based malware detection |
0.4 | 1 | 2019 | Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection · IEEE Trans. Dependable Secur. Comput. 2019 |
Methods — techniques the papers use, named apart from their topics
quantitative data flow graph · 0.8compression-based mining · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Leveraging Compression-Based Graph Mining for Behavior-Based Malware DetectionabstractBehavior-based detection approaches commonly address the threat of statically obfuscated malware. Such approaches often use graphs to represent process or system behavior and typically employ frequency-based graph mining techniques to extract characteristic patterns from collections of malware graphs. Recent studies in the molecule mining domain suggest that frequency-based graph mining algorithms often perform sub-optimally in finding highly discriminating patterns. We propose a novel malware detection approach that uses so-called compression-based mining on quantitative data flow graphs to derive highly accurate detection models. Our evaluation on a large and diverse malware set shows that our approach outperforms frequency-based detection models in terms of detection effectiveness by more than 600 percent. Tobias Wüchner, Aleksander Cislak, Martín Ochoa, Alexander Pretschner |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Generating behavior-based malware detection models with genetic programmingabstractMalware remains a major IT security threat and current detection approaches struggle to cope with a professionalized malware development industry. We propose the use of genetic programming to generate effective and robust malware detection models which we call FrankenMods. These are sets of graph metrics that capture characteristic malware behavior. Evolution of FrankenMods with good detection capabilities yields continuously improved detection effectiveness. FrankenMods are operationalized by evaluating them on quantitative data flow graphs that model malware behavior as data flows between system resources caused by issued system calls. We show that FrankenMods are substantially more robust and effective than a state-of-the-art graph metric-based detection approach. Tobias Wüchner, Martín Ochoa, Enrico Lovat, Alexander Pretschner |
PST | 1 |
| 2015 | Robust and Effective Malware Detection Through Quantitative Data Flow Graph Metrics
Tobias Wüchner, Martín Ochoa, Alexander Pretschner |
DIMVA | 1 |
| 2014 | Malware detection with quantitative data flow graphsabstractWe propose a novel behavioral malware detection approach based on a generic system-wide quantitative data flow model. We base our data flow analysis on the incremental construction of aggregated quantitative data flow graphs. These graphs represent communication between different system entities such as processes, sockets, files or system registries. We demonstrate the feasibility of our approach through a prototypical instantiation and implementation for the Windows operating system. Our experiments yield encouraging results: in our data set of samples from common malware families and popular non-malicious applications, our approach has a detection rate of 96% and a false positive rate of less than 1.6%. In comparison with closely related data flow based approaches, we achieve similar detection effectiveness with considerably better performance: an average full system analysis takes less than one second. Tobias Wüchner, Martín Ochoa, Alexander Pretschner |
AsiaCCS | 1 |
| 2014 | DAVAST: data-centric system level activity visualizationabstractHost-based intrusion detection systems need to be complemented by analysis tools that help understand if malware or attackers have indeed intruded, what they have done, and what the consequences are. We present a tool that visualizes system activities as data flow graphs: nodes are operating system entities such as processes, files, and sockets; edges are data flows between the nodes. Pattern matching identifies structures that correspond to (suspected) malicious and (suspected) normal behaviors. Matches are highlighted in slices of the data flow graph. As a proof of concept, we show how email worm attacks, drive-by downloads, and data leakage are detected, visualized, and analyzed. Tobias Wüchner, Alexander Pretschner, Martín Ochoa |
VizSEC | 1 |
| 2013 | Compliance-Preserving Cloud Storage Federation Based on Data-Driven Usage ControlabstractCloud storage federation improves service availability and reduces vendor lock-in risks of single-provider cloud storage solutions. Federation therefore distributes and replicates data among different cloud storage providers. Missing controls on data location and distribution however introduce security and compliance issues. This paper proposes a novel approach of using data-driven usage control to preserve compliance constraints in cloud storage federation. Based on common compliance regulations and laws we provide a brief categorization of compliance problems into spatial, temporal, and qualitative requirements. In addition, we show how usage control policies can be employed to constrain federation according to these categories. To demonstrate the feasibility of our approach we evaluate security and performance of our prototypical implementation. Tobias Wüchner, Steffen Müller 0002, Robin Fischer |
CloudCom (2) | 1 |
| 2012 | Data Loss Prevention Based on Data-Driven Usage ControlabstractInadvertent data disclosure by insiders is considered as one of the biggest threats for corporate information security. Data loss prevention systems typically try to cope with this problem by monitoring access to confidential data and preventing their leakage or improper handling. Current solutions in this area, however, often provide limited means to enforce more complex security policies that for instance specify temporal or cardinal constraints on the execution of events. This paper presents UC4Win, a data loss prevention solution for Microsoft Windows operating systems that is based on the concept of data-driven usage control to allow such a fine-grained policy-based protection. UC4Win is capable of detecting and controlling data-loss related events at the level of individual function calls. This is done with function call interposition techniques to intercept application calls to the Windows API in combination with methods to track the flows of confidential data through the system. Tobias Wüchner, Alexander Pretschner |
ISSRE | 1 |