On the Robustness of Language Model-based Ransomware Detectors for API Sequence Analysis under Semantic-Preserving Mutations
Ngày được chấp nhận: -
-
Tra cứu các công bố khoa học theo năm, loại công trình, tác giả và từ khóa.
Nhấp vào tiêu đề để xem nội dung chi tiết hoặc sử dụng DOI/PDF khi dữ liệu được cung cấp.
-
Web 3.0 technologies present fundamental challenges to established theories of platform strategy and organizational design, yet the organizational forms enabling decentralized innovation remain theoretically underexamined. This paper reconceptualizes cross-chain bridges, which enable value and message transfer across independent blockchain networks, not as…
-
-
-
Despite the dominance of Transformer-based models in software vulnerability detection, the extent to which their learned security logic generalizes across different programming languages remains a critical open question. To address this, we propose a comprehensive evaluation framework organized into three phases spanning…
Security testing of REST APIs remains difficult because real-world OpenAPI specifications are often incomplete, many security flaws are inherently stateful, and prevailing stateful fuzzers still optimize primarily for structural exploration rather than OWASP-aligned risk categories. Based on this gap, this paper presents…
Network Intrusion Detection Systems (NIDS) based on machine learning must evolve after deployment to detect emerging threats very soon with a few labeled samples, while without catastrophic forgetting or degrading due to concept drift. Existing methods address these issues in isolation, lacking…
-
-
In the rapidly evolving cybersecurity landscape, Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) have become essential for detecting sophisticated threats, yet they are increasingly vulnerable to adversarial evasion attacks and concept drift caused by adaptive attackers. Existing ensemble-based defenses optimize for…
With the widespread adoption of IoT and edge computing, federated learning (FL)-based intrusion detection systems (IDSs), which enable privacy-preserving, cost-effective training by fusing knowledge extracted from collaborators without centralizing the sensitive data, have become essential. Specifically, decentralized FL (DFL)-based IDSs are increasingly…
Swarm Learning (SL) integrates federated learning and blockchain to support decentralized privacy-preserving learning for smart healthcare. However, the resilience of its learning and aggregation process against malicious data injection remains underexplored. This study presents a vulnerability analysis of SL against data-level poisoning,…
Android malware is increasingly becoming a serious security threat to users as the popularity of mobile phones continues to rise. The application of machine learning models for classifying Android malware has been widely used in related studies. However, machine learning models can…
-
MAF-LLM: A Multi-Agent Framework Based on Large Language Models for Automated Ransomware Memory Forensics
Federated learning (FL) enables collaborative Intrusion Detection Systems (IDS) across distributed Internet of Things (IoT) networks without sharing raw data. However, its openness exposes it to model poisoning and backdoor attacks, where malicious clients manipulate updates to corrupt the global model. Detecting…
Web Application Firewalls (WAFs) are crucial in mitigating web-based threats such as SQLi and XSS, yet the evolving complexity of WAF detection mechanisms poses significant challenges for penetration testing (pentest) tools. Existing ML- and RL-based fuzzers often suffer from three main limitations:…
-
-
-
With the continuous evolution of the Windows operating system, malware-especially those based on Portable Executable (PE) files-has become increasingly sophisticated. Recent studies have widely adopted artificial intelligence (AI), particularly deep learning (DL) models, for malware detection. Among these, approaches focusing on API…
-
-
To keep pace with the rapid advancements in both the quality and complexity of malware, recent research has extensively employed machine learning (ML) and deep learning (DL) models to detect malicious software, particularly in the widely used Windows system. Despite demonstrating promising…
Malware continues to evolve, exposing weaknesses in conventional detectors and motivating realistic adversarial evaluations. Prior RL-based evasion methods often rely on partial model access or feature-level perturbations, limiting realism under strict black-box constraints. We propose xPriMES, a dual-environment reinforcement learning framework that…
The Android platform is the dominant mobile operating system, making it a prime target for malware attacks. The increasing complexity of Android malware necessitates advanced detection methods that integrate modern machine learning techniques with security analysis. This study aims to enhance Android…
Honeypot allocation has emerged as a pivotal strategy in cyber deception. However, existing approaches often face scalability issues, limited coordination, and inadequate consideration of intrusion stages, which constrain their effectiveness in complex attack environments. To address these challenges, this study introduces Hawkeyes,…
The growing fragmentation of the blockchain ecosystem has intensified the demand for secure and scalable interoperability protocols. Existing cross-chain solutions face an ‘interoperability trilemma’, struggling to simultaneously achieve decentralization, security, and scalability amidst a fragmented blockchain ecosystem. This paper introduces Acheron, a…
Smart contracts secure over $287 billion in total value locked, yet vulnerabilities caused $3.8 billion in losses during 2023. Traditional detection approaches require complete code disclosure, raising intellectual property concerns for enterprises. We present FedVuln, a privacy-preserving federated graph learning framework enabling…
Web application firewalls (WAFs) are critical for detecting and blocking malicious activities, offering essential protection for web applications. However, to defend against the complexity of modern attacks, penetration testers must regularly evaluate WAFs to identify potential weaknesses. A key aspect of this…
Leveraging LLM Agents for Autonomous Web Penetration Testing Targeting SQL Injection Vulnerability
-
HelioSearch: A Multimodal Video Retrieval Framework with LLM-Driven Query Expansion and Hybrid Filtering
Investigating Deep Learning-based Binary Code Similarity Detection Using Graph Representation For Cross-dataset Analysis Context
-
-
-
-
-
-
-
Generating evasive payloads for assessing Web Application Firewalls with Reinforcement Learning and Pre-trained Language Models
-
-
-
-
ChainFLIP: A Unified Framework Integrating Blockchain, Federated Learning, and IPFS for Secure Supply Chain Management
A Multi-Source Feature Fusion-Based Knowledge Graph Construction from Cyber Threat Intelligence to Facilitate APT Attribution in IDS
-
Honeypots play a critical role in cyber defense by emulating systems that attract and deceive attackers, allowing defenders to monitor malicious behavior in a controlled environment. However, building and maintaining realistic and diverse honeypot environments remains a labor-intensive and technically demanding task,…
-
-
-
-
-
Multimodal Windows Malware Detection via Hybrid Analysis and Enriched Graphs: Effectiveness and Explainability
The increasing number of smart contracts has gained significant attention to the urgency of robust and scalable vulnerability detection techniques to mitigate substantial financial risks associated with their immutable nature on blockchain platforms. This paper introduces structured reasoning prompts using agent-role chaining…
-
-
-
Malware threatens cybersecurity by enabling data theft, unauthorized access, and extortion. Traditional malware detection systems (MDS) struggle with the increasing volume and complexity of malware. While machine learning (ML) and deep learning (DL) offer promising solutions, they remain vulnerable to adversarial attacks…
-
-
The advancement of software vulnerability detection tools has accelerated in recent years, yet the prevalence and severity of vulnerabilities continue to escalate, posing significant threats to computer security and information safety. To address this, numerous detection methodologies have been proposed, with machine…
Detecting malware on Android remains a major challenge because malicious apps use sophisticated evasion techniques. This study presents RAX-ClaMal, a novel approach leveraging dynamic analysis of RAX (Register a Extended) register values for Android malware detection. By extracting and examining the RAX…
The cybersecurity landscape is witnessing an increasing prevalence of threats and malicious programs, posing formidable challenges to conventional detection techniques. Although machine learning (ML) and deep learning (DL) have demonstrated effectiveness in malware detection, their susceptibility to adversarial attacks has led to…
The application of machine learning and deep learning to intrusion detection systems (IDSs) enhances their ability to detect and respond to sophisticated cyber threats efficiently and effectively, providing a robust defense mechanism in the ever-evolving landscape of cybersecurity. However, many environments where…
-
-
-
-
-
-
The rise of security concerns in conventional centralized learning has driven the adoption of federated learning. However, the risks posed by poisoning attacks from internal adversaries against federated systems necessitate robust anti-poisoning frameworks. While previous defensive mechanisms relied on outlier detection, recent…
-
-
-
-
-
-
-
-
-
-
-
-
To discover threats to a network system, investigating the behaviors of attackers after successful exploitation is an important phase, called post-exploitation. Although various efficient tools support post-exploitation implementation, the crucial factor in completing this process remains experienced human experts, known as penetration…
The complex and rapidly evolving nature of modern software landscapes introduces challenges such as increasingly sophisticated cyber threats, the diversity in programming languages and coding styles, and the need to identify subtle patterns indicative of vulnerabilities. These hurdles underscore the necessity for…
Recent advancements in Artificial Intelligence (AI) have greatly impacted cybersecurity, particularly in detecting phishing websites. Traditional methods struggle to address evolving vulnerabilities, but research shows that Machine Learning (ML), Ensemble Learning (EL), and Deep Learning (DL) are effective in developing defenses. However,…
-
The proliferation of connectivity through modern telecommunications has led to increased unwanted and disruptive calls. Such communications negatively impact user experience and trust in platforms. Currently, call filtering relies on centralized architectures that aggregate vast troves of sensitive user data within single…
-
Fuzzing is a popular and effective software testing technique that automatically generates or modifies inputs to test the stability and vulnerabilities of a software system, which has been widely applied and improved by security researchers and experts. The goal of fuzzing is…
-
The diverse landscape of network models, including Software-Defined Networking (SDN), Cloud Computing (C2), and Internet of Things (IoT), is evolving to meet the demands of flexibility and performance. However, these environments face numerous security challenges due to cyber-attack complexity. Traditional defense mechanisms…
As data driven-based Windows malware detectors become increasingly prevalent, the need for robust evaluation and enhancement of adversarial malware generation techniques also becomes imperative, as malicious actors will adapt and enhance their malware to evade detection. There are numerous works that introduce…
The abuse of prescription medications has become a severe public health crisis fueled by limited coordination and oversight across healthcare systems. Current frameworks lack interoperability between doctors, pharmacies, and regulators, enabling abusive practices like doctor shopping and pharmacy hopping. To address these…
-
Across various industries, credential verification stands as a critical requirement, yet traditional approaches face limitations in security, privacy, and interoperability. Although recent blockchain innovations promise decentralization, deploying them independently in institutions creates data isolation. While there are theoretical frameworks, lack of practical…
-
-
The emergence of Blockchain technology has inaugurated a transformative era by its multifaceted advantages and wide-ranging applications across diverse industries. Nevertheless, while holding great promise, Blockchain encounters a significant challenge in achieving interoperability within the complex landscape of multi-blockchain ecosystems. The imperative…
DoppelSearch: A Novel Approach to Content-Based Video Retrieval for AI Challenge HCMC 2023
BlazeSearch: A multimomal semantic search engine for retrieving in-video information for AI Challenge HCMC 2023
-
-
Binary Representation Embedding and Deep Learning For Binary Code Similarity Detection in Software Security Domain
-
-
In the development of the Industrial Internet of Things (IIoT), cyber threats and attacks have become major issues and concerns in Industry 4.0 due to the negative impacts on the infrastructures and services across organizations. Nevertheless, due to the issues in preserving…
-
In recent times, there has been a growing utilization of Machine Learning (ML) in the realm of malware detection. The Adversarial Example (AE) attack, which is widely acknowledged for undermining ML in diverse contexts, has demonstrated its effectiveness in evading or deceiving…
-
With the continuous growth of the internet and web applications, billions of websites built and available at our fingertips today lead more and more sophisticated and malicious attacks and pose requirements to build more precise and modern Web Attack Detection (WAD) system.…
In recent years, the advancements in the Internet of Medical Things (IoMT) or smart devices have enabled the automatic monitoring of human health. Using smart healthcare devices can not only reduce the burden on hospitals but also save costs, travel time, and…
-
An increasing number of devices are connecting to the Internet via Wi-Fi networks, ranging from mobile phones to Internet of Things (IoT) devices. Moreover, Wi-Fi technology has undergone gradual development, with various standards and implementations. In a Wi-Fi network, a Wi-Fi client…
Nowadays, in the realm of blockchain technology, a pressing challenge lies in the current lack of interoperability, which significantly limits its potential for innovation and advancement. However, the attainment of cross-chain interoperability is undeniable of utmost importance, as it holds the key…
-
The recent explosion in the number and advancement of cyberattacks induces the deployment of machine learning (ML)-based network intrusion detection systems (NIDS) in the network infrastructure of each corporation. However, there are plenty of difficulties for enterprise organization in training a conventional…
Advanced persistent threats (APT) are increasingly sophisticated and pose a significant threat to organizations' cybersecurity. Detecting APT attacks in a timely manner is crucial to prevent significant damage. However, hunting for APT attacks requires access to large amounts of sensitive data, which…
Recently, the application of machine learning (ML) in the field of cybersecurity, particularly in the detection and prevention of malware, has received significant attention and interest. Numerous research works on malware analysis have been proposed, showing promising results for practical applications. In…
With the growth and expansion of the internet, web attacks have become more powerful and pose a significant threat in the cyber world. In response to this, this paper presents a deceptive approach for gathering malicious behavior to understand the strategies used…
The increasing proliferation of phishing and scamming websites has become a significant threat to the safety and security of internet users. Accurately detecting such websites is crucial in mitigating their negative impact. While various techniques for detecting phishing and scamming websites exist,…
Recently, Software Defined Networking (SDN) has emerged as the key technology in programming and orchestrating security policy in the security operations centers (SOCs) for heterogeneous networks. Typically, machine learning-based intrusion detection systems (ML-IDS) have been deployed and associated with SDN to leverage…
Penetration testing is one of the most common methods for assessing the security of a system, application, or network. Although there are different support tools with great efficiency in this field, penetration testing is done mostly manually and relies heavily on the…
Software-defined networking (SDN) is a potential approach for modern network architecture, which has received great attention recently. SDN-based networks also face security issues, and they can become targets of cyberattacks. Cyber threat hunting is one of the security solutions proposed for early…
In large-scale networks like the Industrial Internet of Things (IIoT), it is more important to monitor and enforce the security policy within an appropriate time due to the continuous widespread of cyberattacks. This is a tough challenge in traditional network architecture; thus,…
The rising development of machine learning (ML) techniques has become the motivation for research in applying their outstanding features to facilitate intelligent intrusion detection systems (IDSs). However, ML-based solutions also have drawbacks of high false positive rates and vulnerability to sophisticated attacks…
Sharing medical data can help doctors to give a more rapid and accurate diagnosis of a patient's health problems. However, electronic healthcare records (EHRs) are also considered sensitive data, whose sharing may raise issues of security and privacy. Most current healthcare systems…
The Android operating systems is becoming more popular. Security analysis on Android devices is necessary. We can perform security assessment on difference components of Android operating system such as pre-installed applications component, application framework component, or Linux kernel (Android kernel) component. Most…
Today, Android mobile phones have shown their popularity with more than two billion users worldwide. Through the use of the application, the user’s personal data will be stored on the Android device. These data are especially important in digital investigation. The logical…
-
To build an effective malware detector, it is required to collect a diversity of malware samples and their evolution, since malware authors always try to evade detectors through strategies of malware mutation. So, this paper explores the ability to craft mutants of…
Recently, the development in both quantity and complication of malware has raised a need of powerful malware detection solution. The outstanding characteristics of machine learning (ML) and deep learning (DL) techniques has been leveraged in the fight against malware. However, they are…
Nowadays, the amount of data generated from Internet of Things (IoT) devices is increasing, paving the way for the development of artificial intelligence (AI) applications. However, with the traditional AI approach, users sharing their raw data causes many concerns in terms of…
Phishing is a major cybersecurity threat that is increasingly dangerous and complicated, especially during a global pandemic when there is a great need for remote work and communication between Internet users. Moreover, the challenge is even greater when the crime of using…
As one of the defensive solutions against cyberattacks, Intrusion Detection System (IDS) plays an important role in observing the network state, alerting suspicious actions that can break down the system. There are many attempts of adopting Machine Learning (ML) in IDS to…
Cloud infrastructure enables individuals, organizations, and enterprises to offer scalable and elastic resources to support business operations remotely. The demand for digital transformation encourages communities and technical professionals to adopt cloud computing and automation platforms for facilitating their resource capacity, including operating…
Emerging with outstanding features in network management, Software Defined Networking (SDN) is considered as a flexible and efficient paradigm in the context of smart city including a massive number of heterogeneous devices. In the vision of Metaverse towards, SDN plays important roles…
The adoption of deception technology constructed to throw off stealthy attackers from real assets and gather intelligence about how they operate is gaining ground in the network system. Also, some static honeypots are deployed in the network system to attract adversaries for…
Threat hunting is the action of seeking harmful actors lurking in the network or the system in the early stage with the assumption of attackers already broke the cy-ber defense solution. This defense solution requires collecting more knowledge inside and outside to…
Federated learning has become the promising approach for building collaborative intrusion detection systems (IDS) as providing privacy guaranteeing among data holders. Nevertheless, the non-independent and identically distributed (Non-IID) data in real-world scenarios negatively impacts the performance of aggregated models from training client…
Virtual cybersecurity training platforms play an important role in developing the knowledge and practice skills for students in educational institution and universities. It helps learners can access to virtual laboratory through web-interface without any geolocation restriction, especially in the Covid-19 pandemic. Furthermore,…
Although Software-defined networking (SDN) is a promising architecture that simplifies network management and control, it also faces security problems that may affect the whole network. Hence, protecting strategies, such as intrusion detection and prevention system (IDPS), are in need in the SDN…
-
-
-
-
-
-
Forensics Analysis of FacePlay Application to Seek Digital Artifacts on Data Ownership and Privacy
ALID-GAN: Phương pháp hỗ trợ học chủ động cho hệ thống phát hiện xâm nhập dựa trên mạng sinh đối kháng
-
-
-
With the spread of the number of smart devices in the context of Smart City, Software Defined Networking (SDN) is considered as a vital principle to manage a large-scale heterogeneous network within centralized controller. To deal with cyberattacks against such networks, intrusion…
Showing a great potential in various domains, machine learning techniques are more and more used in the task of malicious network traffic detection to significantly enhance the ability of intrusion detection system (IDS). When associating with Software-Defined Networks (SDN), the deployment of…
Revolutionizing operation model of traditional network in programmability, scalability, and orchestration, Software-Defined Networking (SDN) has considered as a novel network management approach for a massive network with heterogeneous devices. However, it is also highly susceptible to security attacks like conventional network. Inspired…
-
In recent years, the Internet has witnessed a significant increase in phishing attacks. These attacks are not merely deceiving Internet users to get their sensitive information, but phishing attacks are developing more and more sophisticated, using many new techniques to try to…
-
Fruits classification by using machine learning - An experiment using popular approaches on local data
The demand for personal healthcare record (PHR) exchange among electronic medical record (EMR) systems and patients is growing along with remarkable efforts to improve the quality, safety, privacy- preserving, and efficiency of healthcare information delivery. Currently, in EMR systems, there are problems…
With the emergence of deep learning, recent years have witnessed a booming of artificial intelligence (AI) applications and services in many fields of modern society, ranging from face recognition to video surveillance to many recommendation systems. In addition, there is a tremendous…
With the development of social networks in the age of information technology explosion, the classification of social news plays an important role in detecting the hot topics being discussed on social networks over a period of time. In this paper, we present…
Trình phát hiện xâm nhập mạng (Network IDS) được xây dựng để phát hiện và cảnh báo khi hệ thống bị tấn công, từ đó có thể đưa ra các phản ứng phù hợp. Với sự bùng nổ của dữ liệu, các…
Deceive Intrusion Detection System with GAN and Function-Preserving on Adversarial Samples in SDN-enabled networks (*selected as an Excellent Young Research Award at VANJ 2020 conference) (abstract only)
Smart Grid is one of the critical technologies that provide essential services to sustain social and economic developments. There are various cyber attacks on the Smart Grid system in recent years, which resulted in various negative repercussions. Therefore, understanding the characteristics and…
Wi-Fi technology has become popular in our lives with various Wi-Fi capable products such as laptops, mobile phones, etc. Moreover, in Wi-Fi networks, a device communicates typically with a server using Transmission Control Protocol (TCP) for most applications. In such a context,…
Emerging with highlight features as a global phenomenon, TikTok - the international version of Douyin application in China market, is a social media video app for creating and sharing short lip-syncing. This social video platform has seen astounding growth by reaching 1.5…
-
Despite bringing many benefits of global network configuration and control, Software Defined Networking (SDN) also presents potential challenges for both digital forensics and cybersecurity. In fact, there are various attacks targeting a range of vulnerabilities on vital elements of this paradigm such…
Recently, low latency has become one of the most critical requirements in Wi-Fi networks (e.g., for Internet access). Many factors and events such as bufferbloat, which unexpectedly happen, can affect the delay of Wi-Fi networks. Hence, the delay requirement leads to the…
In Software-Defined Networking (SDN), Northbound Interface provides APIs, which allow network applications to communicate with SDN controllers. However, a malicious application can access to SDN controller and perform illegal activities via these APIs. Although some studies proposed AAA (Authentication, Authorization, Accounting) systems…
Controller is a key component in the three layers of Software - Defined Networking (SDN), which is to process a huge number of flow requests from network devices. As a result, it puts a flow rule into flow table in switch according…
Android operating system always occupies the highest market share in mobile operating systems. Security analysis on Android operating systems often focuses on analyzing applications (APK files) when installed on the phone. There are few studies analyzing Android firmware, especially customized Android firmware.…
Emerging with unprecedented features of programmable network management at a centralized controller for network technology in recent years, Software-Defined Networking (SDN) has promptly received much attention from both industry and academic research. However, to provide security and scalability of network, a single…
In modern networks, bufferbloat is currently a rising problem where network equipment with the oversized buffer can produce undesired latency in packet transmission. Wi-Fi network is not an exception, for example, in the case of having an incorrect configuration on access points.…
Software Defined Networking (SDN) – a new rising terminology of network is recently gained more and more interest in both academic and industrial field. Not only decoupling of its control plane and data plane, SDN also provides the whole view of entire…
Android sensitive information leakage datasets studies are still limited. Specifically, DroidBench dataset contains 120 case studies of which only 3 case studies are used for analyzing inter-application data flow. Therefore, increasing the number of case study of Android sensitive information leakage datasets…
-
-
Abstract— The modern society, economy and industry have been changed remarkably by many cutting-edge technologies over the last years, and many more are in development and early implementation that will in turn led even wider spread of adoptions and greater alteration. Blockchain…
In the "Industry 4.0" era, blockchain as well as related distributed ledger technologies has been an unmissable trend for both academy and industry recently. Blockchain technology has become famous as the innovative technology that underlies cryptocurrencies such as Bitcoin and Ethereum platform.…
There is a transformation of the traditional network into Software Defined Networking (SDN) which is an outstanding developing area recently. Among the most exciting features of SDN are the remarkable control over network infrastructure and decoupling of control and data plane. Although…
Leaking personal information on mobile devices is a serious problem. Work on information leak detection for mobile devices, until now, mostly focus on action within a single application, while the coordinated action of several applications for the malicious purpose is becoming popular.…
-
-
In recent years, mobile malware has grown to be significant types of behaviors, including stealing personal information of users, hijacking and surveilling user devices. Every year, it caused financial loss for infected enterprises, also more and more concerned about seriously secure data…
There are many custom Android firmware (custom ROMs) which are shared on the Internet. Several recent studies aim their efforts at analyzing pre-installed applications in these firmware. However, they analyzed separate pre-installed applications. In this study we propose a system, uitXROM, to…
One approach of Android security is the analysis for detecting potential information leaks. The current technical analyses (as static analysis, dynamic analysis, hybrid of static and dynamic analysis) only focus on action within a single application, while the coordinated action of several…
In this study, we present the uitHyDroid system, which allows the detection of sensitive data leakage via multi-applications using hybrid analysis. uitHyDroid uses static analysis to collect user interface elements that must interact to illuminate possible sensitive data flows. In addition, dynamic…
-
There is a large share market of Android operating system and the number of new malware on Android has a significantly upward trend in recent. The current studies identified a behavior that is dangerous or not by only analyzing each single application.…
-
-
-
-
-
-
-
-
-
Hãy thay đổi từ khóa hoặc bộ lọc.