activity
20242026
collaborators

6 papers

cs.CR2026

The CTI Echo Chamber: Fragmentation, Overlap, and Vendor Specificity in Twenty Years of Cyber Threat Reporting

Manuel Suarez-Roman, Francesco Marchiori, Mauro Conti +1

Despite the high volume of open-source Cyber Threat Intelligence (CTI), our understanding of long-term threat actor-victim dynamics remains fragmented due to inconsistent reporting…

cs.CR2026

Benchmarking Large Language Models for IoC Recovery under Adversarial Code Obfuscation and Encryption

Jaime Morales, Sergio Pastrana, Juan Tapiador

Software obfuscation and encryption present persistent challenges for program comprehension and security analysis, particularly when adversaries conceal Indicators of Compromise (I…

cs.CR2026

The Infinite Mutation Engine? Measuring Polymorphism in LLM-Generated Offensive Code

Gabriel Hortea, Juan Tapiador

Malware authors have traditionally relied on polymorphic techniques to produce variants in the same malware family, complicating signature-based detection. Integrating generative A…

cs.CR2025

Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale

Gonzalo Roa, Manuel Suarez-Roman, Juan Tapiador

This paper studies the problem of Threat Actor (TA) naming convention inconsistency across leading Cyber Threat Intelligence (CTI) vendors. The current decentralized and proprietar…

cs.CR2025

Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android

Aniketh Girish, Joel Reardon, Juan Tapiador +2

Mobile apps frequently use Bluetooth Low Energy (BLE) and WiFi scanning permissions to discover nearby devices like peripherals and connect to WiFi Access Points (APs). However, wi…

cs.CR2024

Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis

José Miguel Moreno, Narseo Vallina-Rodriguez, Juan Tapiador

The JavaScript programming language, which began as a simple scripting language for the Web, has become ubiquitous, spanning desktop, mobile, and server applications. This increase…