Dear All,
We submitted 2 new papers related to Sparta/Safair.
1.
Title: The effects of data balancing procedures on surrogate explainability
methods in network cybersecurity-related streamed difficult data
By: Szczepanski, Komisarek, Pawlicki, Kozik, Choras.
Venue: IJCNN 2021 conference
Abstract:
Handling the data imbalance problem is one of the crucial steps in a
machine learning pipeline. The research community is well aware of the
effects of data imbalance on machine learning algorithms. At the same
time, there is a rising need for explainability of AI, especially in
difficult, high-stakes domains like network intrusion detection. In this
paper, the effects of data balancing procedures on two explainability
procedures implemented to explain a neural network used for network
intrusion detection are evaluated. The discrepancies between the two
methods are highlighted and important conclusions are drawn.
2.
Title:Is the COVID-19 pandemic helping to bridge the digital skill and
cybersecurity awareness-related gender gap?
By: A. Pawlicka, R. Tomaszewska, E. Krause, D. Jaroszewska-Choras,
M.Pawlicki, M.Choras ́
Venue: IEEE Security and Privacy
Abstract:
Women tend to possess lower digital competence than men. This may lead to
them being socially excluded and vulnerable to cybersecurity threats. This
study concerned the digital literacy and the cybersecurity awareness of
Polish women who have been forced to work online due to the COVID-19
pandemic.
If accepted we plan to acknowledge SPARTA.
Kind Regards,
Prof. Michal Choras
Dear all,
We are submitting a paper to the "IFIP SEC" conference this year. If it
is accepted, we acknowledge SPARTA.
Title: Hybroid: Toward Android Malware Detection and Categorization with
Program Code and Network Traffic
Abstract: Android malicious applications have become so sophisticated
that they can bypass endpoint protection measures. Therefore, it is safe
to admit that traditional anti-malware techniques have become
cumbersome, thereby raising the need to develop efficient ways to detect
Android malware. In this paper, we present Hybroid, a hybrid Android
malware detection and categorization solution that utilizes program code
structures as static behavioral features and network traffic as dynamic
behavioral features for detection (binary classification) and
categorization (multi-label classification). For static analysis, we
introduce a natural language processing-inspired technique based on
function call graph embeddings and design a graph neural network-based
approach to convert the whole graph structure of an Android app to a
vector. In dynamic analysis, we extract network flow features from the
raw network traffic by capturing each application's network flow.
Finally, Hybroid utilizes the network flow features combined with the
graphs' vectors to detect and categorize the malware. Our solution gets
99.6% accuracy on average for malware detection and 97.6% accuracy for
malware categorization.
Best regards,
Mohammad Norouzian
--
Mohammad Reza Norouzian
Lehrstuhl für Sicherheit in der Informatik I20
Institut für Informatik TU München
Boltzmannstr. 3
85748 Garching
Tel. +49 89 289 18584
Fax +49 89 289 18579
e-mail: norouzian(a)sec.in.tum.de
http://www.sec.in.tum.de
Dear all,
If the dissemination committee raises no objections, we would like to acknowledge the SPARTA project on the following three accepted papers.
These papers are related to our research activities performed in WP5 Cape.
(The camera ready versions are not yet ready)
Timothé Riom, Arthur D. Sawadogo, Kevin Allix, Alexandre Bartel, Tegawendé F. Bissyandé, Naouel Moha and Jacques Klein, Revisiting the VCCFinder Approach for the Identification of Vulnerability-Contributing Commits, Empirical Software Engineering, journal first, Springer, Accepted for publication on Jan. 22, 2021
(Rank A)
Jordan Samhi, Kevin Allix, Tegawendé F. Bissyandé, Jacques Klein, A First Look at Android Applications in Google Play related to Covid-19, Empirical Software Engineering, journal first, Springer, Accepted for publication on Jan. 15, 2021
(Rank A)
Yanjie Zhao, Li Li, Haoyu Wang, Haipeng Cai, Tegawendé F. Bissyandé, Jacques Klein, John Grundy, On the Impact of Sample Duplication in Machine Learning based Android Malware Detection, ACM Transactions on Software Engineering and Methodology (TOSEM), journal first, ACM, Accepted for publication on Jan. 07, 2021
(Rank A*)
All the best,
Jacques
--
Prof. Jacques Klein
Chief Scientist
University of Luxembourg - SnT
00352 46 66 44 56 00 / Gsm: 0033 6 06 47 62 54
https://jacquesklein2302.github.io/
Dear all,
we plan to submit the paper “Privacy ABCs: Now Ready for Your Wallets!”
to Workshop on Privacy in the Electronic Society which is held in
conjunction with the ACM CCS conference.
Please find the manuscript version in the attachment. The paper is in
line with WP6 - Task 6.5 Privacy-by-Design and does not contain any
sensitive information.
If the paper will be accepted and no objections will be raised by diss.
committee, we would like to acknowledge to SPARTA.
Thank you.
Best regards,
Lukas Malina
--
doc. Ing. Lukáš Malina, Ph.D.
E-mail: malina(a)feec.vutbr.cz
Brno University of Technology
Faculty of Electrical Engineering and Communication
Department of Telecommunications
Technicka 12
616 00 Brno
Czech Republic
Dear all,
If the dissemination committee raises no objections, we would like to acknowledge the SPARTA project on the attached paper (preprint version).
This paper has been recently accepted for publication at the ICSE conference (rank A*).
This paper is related to our research activities performed in WP5 Cape.
Jordan Samhi, Alexandre Bartel, Tegawendé F. Bissyandé, Jacques Klein, RAICC: Revealing Atypical Inter-Component Communication in Android Apps, 43rd International Conference on Software Engineering (ICSE), IEEE/ACM, May 2021, To appear, Madrid, Spain (Virtual Conference)
All the best,
Jacques
--
Prof. Jacques Klein
Chief Scientist
University of Luxembourg - SnT
00352 46 66 44 56 00 / Gsm: 0033 6 06 47 62 54
https://jacquesklein2302.github.io/
Dear all,
I would like to announce a recent publication by fortiss. Our paper has
been accepted for publication at VNC 2020. It acknowledges the SPARTA
project. Our paper is related to our research activities performed in
T5.2 (Convergence of security and safety).
Title:
A Formal Security Assessment Framework for Cooperative Adaptive Cruise
Control
Authors:
Yuri Gil Dantas (fortiss, Germany), Vivek Nigam (fortiss, Germany),
Carolyn Talcott (SRI International, USA)
Conference:
2020 IEEE Vehicular Networking Conference (VNC)
The paper is attached.
Cheers,
Yuri
--
fortiss · Landesforschungsinstitut des Freistaats Bayern
An-Institut Technische Universität München
Guerickestraße 25
80805 München
Germany
Tel.: +49 (89) 3603522 193
Fax: +49 (89) 3603522 50 E-Mail: dantas(a)fortiss.org
https://www.fortiss.org/
Amtsgericht München: HRB: 176633
USt-IdNr.: DE263907002, Steuer-Nr.: 143/237/25900
Rechtsform: gemeinnützige GmbH
Sitz der Gesellschaft: München
Geschäftsführer: Dr. Harald Rueß, Thomas Vallon
Vorsitzender des Aufsichtsrats: Dr. Manfred Wolter
Dear all,
If the dissemination committee raises no objections, we would like to acknowledge the SPARTA project on the attached paper (not yet the camera ready version).
This paper has been recently accepted for publication in the ACM Transactions on Software Engineering and Methodology (TOSEM) journal.
This paper is related to our research activities performed in WP5 Cape.
Xiaoyu Sun, Li Li, Tegawendé F. Bissyandé, Jacques Klein, Damien Octeau, John Grundy , Taming Reflection: An Essential Step Towards Whole-Program Analysis of Android Apps, ACM Transactions on Software Engineering and Methodology (TOSEM), ACM, Accepted for publication on Nov. 29, 2020
All the best,
Jacques
--
Prof. Jacques Klein
Chief Scientist
University of Luxembourg - SnT
00352 46 66 44 56 00 / Gsm: 0033 6 06 47 62 54
https://jacquesklein2302.github.io/
Dear All
I would like to let you know that we have a paper under evaluation of
"Computers & Security" acknowledging SPARTA. The title and abstract are
the following (the pre-print is attached):
Title: Optimisation of cyber insurance coverage with selection of cost
effective security controls.
Abstract: Nowadays, cyber threats are considered among the most
dangerous risks by top
management of enterprises. One way to deal with these risks is to insure
them,
but cyber insurance is still quite expensive. The insurance fee can be
reduced if
organisations improve their cyber security protection, i.e., reducing
the insured
risk. In other words, organisations need an investment strategy to
decide the
optimal amount of investments into cyber insurance and self-protection.
In this work, we propose an approach to help a risk-averse organisation to
distribute its cyber security investments in a cost-efficient way. What
makes
our approach unique is that next to defining the amount of investments in
cyber insurance and self-protection, our proposal also explicitly
defines how
these investments should be spent by selecting the most cost-ecffiient
security
controls. Moreover, we provide an exact algorithm for the control selection
problem considering several threats at the same time and compare this
algorithm
with other approximate algorithmic solutions.
--
___________
best regard,
Artsiom Yautsiukhin
Dear SPARTA Dissemination Committee,
I would like to report that the paper "Never Trust Your Victim: Weaponizing
Vulnerabilities in Security Scanners" by Andrea Valenza, Gabriele Costa,
and Alessandro Armando, was recently accepted at the 23rd International
Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020).
More information here:
- https://raid2020.org/accepted-papers/
- https://www.usenix.org/conference/raid2020/presentation/valenza
Thank you for your consideration,
Andrea Valenza
Dear colleagues,
We (IST) recently had four papers accepted with acknowledgment to SPARTA:
Luis Dias, Simão Valente and Miguel Correia. Go With the Flow: Clustering Dynamically-Defined NetFlow Features for Network Intrusion Detection with DYNIDS. In Proceedings of the 19th IEEE International Symposium on Network Computing and Applications (NCA), Nov. 2020.
Arnaldo Gouveia and Miguel Correia. Towards Quantum-Enhanced Machine Learning for Network Intrusion Detection. In Proceedings of the 19th IEEE International Symposium on Network Computing and Applications (NCA), Nov. 2020.
Gilberto Gomes, Luis Dias and Miguel Correia. CryingJackpot: Network Flows and Performance Counters against Cryptojacking. In Proceedings of the 19th IEEE International Symposium on Network Computing and Applications (NCA), Nov. 2020.
Tiago Fernandes, Luis Dias and Miguel Correia. C2BID: Cluster Change-Based Intrusion Detection. In Proceedings of Trustcom 2020, December 2020.
Best regards,
Miguel Correia
------------------------------
Miguel P. Correia
Instituto Superior Técnico / Universidade de Lisboa
INESC-ID
URL: http://www.gsd.inesc-id.pt/~mpc/ <http://www.gsd.inesc-id.pt/~mpc/>
Rua Alves Redol, 9
1000-029 Lisboa
Portugal
Tel.: +351 213 100 278
Email: miguel.p.correia(a)tecnico.ulisboa.pt <mailto:miguel.p.correia@tecnico.ulisboa.pt>
------------------------------