3 papers
cs.CR2025
An Analysis of Malicious Packages in Open-Source Software in the Wild
Xiaoyan Zhou, Ying Zhang, Wenjia Niu +3
The open-source software (OSS) ecosystem suffers from security threats caused by malware.However, OSS malware research has three limitations: a lack of high-quality datasets, a lac…
cs.CR2024
Tactics, Techniques, and Procedures (TTPs) in Interpreted Malware: A Zero-Shot Generation with Large Language Models
Ying Zhang, Xiaoyan Zhou, Hui Wen +4
Nowadays, the open-source software (OSS) ecosystem suffers from security threats of software supply chain (SSC) attacks. Interpreted OSS malware plays a vital role in SSC attacks,…
cs.CR2024
AutoFirm: Automatically Identifying Reused Libraries inside IoT Firmware at Large-Scale
YongLe Chen, Feng Ma, Ying Zhang +3
The Internet of Things (IoT) has become indispensable to our daily lives and work. Unfortunately, developers often reuse software libraries in the IoT firmware, leading to a major…