10 papers
DroidBreaker: Practical and Functional Problem-Space Attacks on Machine-Learning Android Malware Detectors
Christian Scano, Diego Soi, Angelo Sotgiu +5
Adversarial APKs are Android applications modified in the problem space to evade machine-learning malware detectors. In this work, we first show that, despite claims, existing prob…
Statistical Effort Modelling of Game Resource Localisation Attacks
Alessandro Sanna, Waldo Verstraete, Leonardo Regano +2
Evidence on the effectiveness of Man-At-The-End (MATE) software protections, such as code obfuscation, has mainly come from limited empirical research. Recently, however, an automa…
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
Francesco Pagano, Lorenzo Pisu, Leonardo Regano +3
Code obfuscation is widely adopted in modern software development to protect intellectual property and hinder reverse engineering, but it also provides attackers with a powerful me…
Label-efficient Training Updates for Malware Detection over Time
Luca Minnei, Cristian Manca, Giorgio Piras +6
Machine Learning (ML)-based detectors are becoming essential to counter the proliferation of malware. However, common ML algorithms are not designed to cope with the dynamic nature…
An Analysis of Modern Web Security Vulnerabilities Inside WebAssembly Applications
Lorenzo Corrias, Lorenzo Pisu, Davide Maiorca +1
The growth in the adoption of the WebAssembly (WASM) standard has given rise to a rapidly increasing landscape of binary applications that are natively ported to the environment of…
An Assessment of the Overlooked Dangers of Template Engines
Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto
Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential fo…