Xabier Ugarte-Pedrero

dblp:86/9728 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
2since 2021 · last 2022
0009-0004-3950-9880ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 6 first-author · 2 since 2021Databases, data management, data science and information retrieval · 4Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2022 How Machine Learning Is Solving the Binary Function Similarity Problem
Andrea Marcelli, Mariano Graziano, Xabier Ugarte-Pedrero, Yanick Fratantonio, Mohamad Mansouri, Davide Balzarotti
USENIX Security Symposium3
2021 Survivalism: Systematic Analysis of Windows Malware Living-Off-The-Land
abstract
As malware detection algorithms and methods become more sophisticated, malware authors adopt equally sophisticated evasion mechanisms to defeat them. Anecdotal evidence claims Living-Off-The-Land (LotL) techniques are one of the major evasion techniques used in many malware attacks. These techniques leverage binaries already present in the system to conduct malicious actions. We present the first large-scale systematic investigation of the use of these techniques by malware on Windows systems.In this paper, we analyse how common the use of these native system binaries is across several malware datasets, containing a total of 31,805,549 samples. We identify an average 9.41% prevalence. Our results show that the use of LotL techniques is prolific, particularly in Advanced Persistent Threat (APT) malware samples where the prevalence is 26.26%, over twice that of commodity malware.To illustrate the evasive potential of LotL techniques, we test the usage of LotL techniques against several fully patched Windows systems in a local sandboxed environment and show that there is a generalised detection gap in 10 of the most popular anti-virus products.
Frederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor, Ivan Martinovic
SP2
2020 Prevalence and Impact of Low-Entropy Packing Schemes in the Malware Ecosystem
Alessandro Mantovani, Simone Aonzo, Xabier Ugarte-Pedrero, Alessio Merlo, Davide Balzarotti
NDSS3
2019 A Close Look at a Daily Dataset of Malware Samples
abstract
The number of unique malware samples is growing out of control. Over the years, security companies have designed and deployed complex infrastructures to collect and analyze this overwhelming number of samples. As a result, a security company can collect more than 1M unique files per day only from its different feeds. These are automatically stored and processed to extract actionable information derived from static and dynamic analysis. However, only a tiny amount of this data is interesting for security researchers and attracts the interest of a human expert. To the best of our knowledge, nobody has systematically dissected these datasets to precisely understand what they really contain. The security community generally discards the problem because of the alleged prevalence of uninteresting samples. In this article, we guide the reader through a step-by-step analysis of the hundreds of thousands Windows executables collected in one day from these feeds. Our goal is to show how a company can employ existing state-of-the-art techniques to automatically process these samples and then perform manual experiments to understand and document what is the real content of this gigantic dataset. We present the filtering steps, and we discuss in detail how samples can be grouped together according to their behavior to support manual verification. Finally, we use the results of this measurement experiment to provide a rough estimate of both the human and computer resources that are required to get to the bottom of the catch of the day .
Xabier Ugarte-Pedrero, Mariano Graziano, Davide Balzarotti
ACM Trans. Priv. Secur.1
2016 RAMBO: Run-Time Packer Analysis with Multiple Branch Observation
Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo García Bringas
DIMVA1
2015 SoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time Packers
abstract
Run-time packers are often used by malware-writers to obfuscate their code and hinder static analysis. The packer problem has been widely studied, and several solutions have been proposed in order to generically unpack protected binaries. Nevertheless, these solutions commonly rely on a number of assumptions that may not necessarily reflect the reality of the packers used in the wild. Moreover, previous solutions fail to provide useful information about the structure of the packer or its complexity. In this paper, we describe a framework for packer analysis and we propose a taxonomy to measure the runtime complexity of packers. We evaluated our dynamic analysis system on two datasets, composed of both off-the-shelf packers and custom packed binaries. Based on the results of our experiments, we present several statistics about the packers complexity and their evolution over time.
Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo García Bringas
IEEE Symposium on Security and Privacy1
2014 On the adoption of anomaly detection for packed executable filtering
Xabier Ugarte-Pedrero, Igor Santos, Iván García-Ferreira, Sergio Huerta, Borja Sanz 0001, Pablo García Bringas
Comput. Secur.1
2014 Study on the effectiveness of anomaly detection for spam filtering
Carlos Laorden, Xabier Ugarte-Pedrero, Igor Santos, Borja Sanz 0001, Javier Nieves, Pablo García Bringas
Inf. Sci.2
2013 Instance-based Anomaly Method for Android Malware Detection
Borja Sanz 0001, Igor Santos, Xabier Ugarte-Pedrero, Carlos Laorden, Javier Nieves, Pablo García Bringas
SECRYPT3
2013 Mama: manifest Analysis for Malware Detection in Android
abstract
The use of mobile phones has increased because they offer nearly the same functionality as a personal computer. In addition, the number of applications available for Android-based mobile devices has increased. Google offers programmers the opportunity to upload and sell applications in the Android Market, but malware writers upload their malicious code there. In light of this background, we present here manifest analysis for malware detection in Android (MAMA), a new method that extracts several features from the Android manifest of the applications to build machine learning classifiers and detect malware.
Borja Sanz 0001, Igor Santos, Carlos Laorden, Xabier Ugarte-Pedrero, Javier Nieves, Pablo García Bringas, Gonzalo Álvarez
Cybern. Syst.4
2013 Opcode sequences as representation of executables for data-mining-based unknown malware detection
Igor Santos, Felix Brezo, Xabier Ugarte-Pedrero, Pablo García Bringas
Inf. Sci.3
2012 On the study of anomaly-based spam filtering using spam as representation of normality
abstract
In previous work, we presented the first spam filtering method based on anomaly detection that reduces the necessity of labelling spam messages and only employs the representation of legitimate e-mails. This method achieved high accuracy rates detecting spam while maintaining a low false positive rate and reducing the effort produced by labelling spam. In this paper, we study the performance of our previous method when using spam messages to represent normality.
Carlos Laorden, Xabier Ugarte-Pedrero, Igor Santos, Borja Sanz 0001, Javier Nieves, Pablo García Bringas
CCNC2
2012 On the automatic categorisation of android applications
abstract
The presence of mobile devices has increased in our lives offering almost the same functionality as a personal computer. Android devices have appeared lately and, since then, the number of applications available for this operating system have increased exponentially. Google already has its Android Market where applications are offered and, as happens with every popular media, is prone to misuse. A malware writer may insert a malicious application into this market without being noticed. Indeed, there are already several cases of Android malware within the Android Market. Therefore, an approach that can automatically characterise the different types of applications can be helpful for both organising the Android Market and detecting fraudulent or malicious applications. In this paper, we propose a new method for categorising Android applications through machine-learning techniques. To represent each application, our method extracts different feature sets: (i) the frequency of occurrence of the printable strings, (ii) the different permissions of the application itself and (iii) the permissions of the application extracted from the Android Market. We evaluate this approach of automatically categorisation of Android applications and show that achieves a high performance.
Borja Sanz 0001, Igor Santos, Carlos Laorden, Xabier Ugarte-Pedrero, Pablo García Bringas
CCNC4
2012 Countering entropy measure attacks on packed software detection
abstract
Malware writers usually employ several techniques to evade detection. For the last years, the number of variants detected each day has increased significantly. Traditional approaches such as signature scanning, one of the most common techniques employed by anti-virus companies, are becoming inefficient for the high amount of samples found in the wild. In order to bypass this kind of filters, malware writers usually obfuscate and transform the code of their creations. One of the methods employed is executable packing, which consists in compressing or ciphering the real malicious code, and injecting a decryption routine into the executable that will load and decompress it at run-time. Entropy is a common heuristic for the detection of packed executables. High entropy values indicate a random distribution of the bytes that compose the executable, a property very common in compressed and ciphered data. Unfortunately, this entropy measure can be altered by different techniques that modify randomness. In this paper, we detail various attacks found on real Zeus family samples, one of the most powerful and spread malware families at this moment, which are protected by custom made packers. In addition, we describe a method for obtaining an alternative entropy measure more resilient to these techniques, and evaluate it for the classification of packed/not-packed executables, obtaining satisfactory detection and false positive rates.
Xabier Ugarte-Pedrero, Igor Santos, Borja Sanz 0001, Carlos Laorden, Pablo García Bringas
CCNC1
2012 Supervised classification of packets coming from a HTTP botnet
abstract
The posibilities that the management of a vast amount of computers and/or networks offer, is attracting an increasing number of malware writers. In this document, the authors propose a methodology thought to detect malicious botnet traffic, based on the analysis of the packets flow that circulate in the network. This objective is achieved by means of the parametrization of the static characteristics of packets, which are lately analysed using supervised machine learning techniques focused on traffic labelling so as to face proactively to the huge volume of information nowadays filters work with.
Felix Brezo, José Gaviria de la Puerta, Xabier Ugarte-Pedrero, Igor Santos, Pablo García Bringas, David Barroso
CLEI3
2011 Boosting Scalability in Anomaly-Based Packed Executable Filtering
Xabier Ugarte-Pedrero, Igor Santos, Pablo García Bringas
Inscrypt1
2011 Anomaly Detection for the Prediction of Ultimate Tensile Strength in Iron Casting Production
Igor Santos, Javier Nieves, Xabier Ugarte-Pedrero, Pablo García Bringas
DEXA (2)3
2011 Semi-supervised learning for packed executable detection
abstract
The term malware is coined to name any software with malicious intentions. One of the methods malware writers use for hiding their creations is executable packing. Packing consists of encrypting or hiding the real code of the executable in such a way that it is decrypted or unhidden in its execution. Widespread solutions to this issue first try to identify the packer used and next apply the corresponding unpacking routine for each packing algorithm. As it happens with malware obfuscations, this approach fails to detect new and custom packers. Generic unpacking is a technique that has been proposed to solve this issue. These methods usually execute the binary in a contained environment or sandbox to retrieve the real code of the packed executable. Because these approaches incur in a high performance overhead, a filter step is required to determine whether an executable is packed or not. Supervised machine-learning approaches have been proposed to handle this filtering step. However, the usefulness of supervised learning is far to be complete because it requires a high amount of packed and not packed executables to be identified and labelled previously. In this paper, we propose a new method for packed executable detection that adopts a well-known semi-supervised learning approach to reduce the labelling requirements of completely supervised approaches. We performed an empirical validation demonstrating that the labelling efforts are lower than when supervised learning is used while the system maintains high accuracy rates.
Xabier Ugarte-Pedrero, Igor Santos, Pablo García Bringas, Mikel Gastesi, José Miguel Esparza
NSS1
2011 Anomaly-based Spam Filtering
Igor Santos, Carlos Laorden, Xabier Ugarte-Pedrero, Borja Sanz 0001, Pablo García Bringas
SECRYPT3