6 papers
The CTI Echo Chamber: Fragmentation, Overlap, and Vendor Specificity in Twenty Years of Cyber Threat Reporting
Manuel Suarez-Roman, Francesco Marchiori, Mauro Conti +1
Despite the high volume of open-source Cyber Threat Intelligence (CTI), our understanding of long-term threat actor-victim dynamics remains fragmented due to inconsistent reporting…
Benchmarking Large Language Models for IoC Recovery under Adversarial Code Obfuscation and Encryption
Jaime Morales, Sergio Pastrana, Juan Tapiador
Software obfuscation and encryption present persistent challenges for program comprehension and security analysis, particularly when adversaries conceal Indicators of Compromise (I…
The Infinite Mutation Engine? Measuring Polymorphism in LLM-Generated Offensive Code
Gabriel Hortea, Juan Tapiador
Malware authors have traditionally relied on polymorphic techniques to produce variants in the same malware family, complicating signature-based detection. Integrating generative A…
Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
Gonzalo Roa, Manuel Suarez-Roman, Juan Tapiador
This paper studies the problem of Threat Actor (TA) naming convention inconsistency across leading Cyber Threat Intelligence (CTI) vendors. The current decentralized and proprietar…
Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android
Aniketh Girish, Joel Reardon, Juan Tapiador +2
Mobile apps frequently use Bluetooth Low Energy (BLE) and WiFi scanning permissions to discover nearby devices like peripherals and connect to WiFi Access Points (APs). However, wi…
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
José Miguel Moreno, Narseo Vallina-Rodriguez, Juan Tapiador
The JavaScript programming language, which began as a simple scripting language for the Web, has become ubiquitous, spanning desktop, mobile, and server applications. This increase…