<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/CINECAstyle.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-21T06:50:48Z</responseDate><request verb="GetRecord" identifier="oai:iris.unica.it:11584/266872" metadataPrefix="oai_dc">https://iris.unica.it/oai/request</request><GetRecord><record><header><identifier>oai:iris.unica.it:11584/266872</identifier><datestamp>2022-10-20T09:32:26Z</datestamp><setSpec>com_11584_207615</setSpec><setSpec>com_11584_111066</setSpec><setSpec>col_11584_265854</setSpec></header><metadata><oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:doc="http://www.lyncode.com/xoai" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
<dc:title>Design and implementation of robust systems for secure malware detection</dc:title>
<dc:creator>MAIORCA, DAVIDE</dc:creator>
<dc:subject>Android</dc:subject>
<dc:subject>Machine Learning</dc:subject>
<dc:subject>antivirus</dc:subject>
<dc:subject>evasion</dc:subject>
<dc:subject>fingerprinting</dc:subject>
<dc:subject>malware</dc:subject>
<dc:subject>security</dc:subject>
<dc:subject>Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni</dc:subject>
<dc:description>Malicious software (malware) have significantly increased in terms of number and effectiveness&#xd;
during the past years. Until 2006, such software were mostly used to disrupt&#xd;
network infrastructures or to show coders’ skills. Nowadays, malware constitute a very&#xd;
important source of economical profit, and are very difficult to detect. Thousands of&#xd;
novel variants are released every day, and modern obfuscation techniques are used to&#xd;
ensure that signature-based anti-malware systems are not able to detect such threats.&#xd;
This tendency has also appeared on mobile devices, with Android being the most targeted&#xd;
platform. To counteract this phenomenon, a lot of approaches have been developed&#xd;
by the scientific community that attempt to increase the resilience of anti-malware systems.&#xd;
Most of these approaches rely on machine learning, and have become very popular&#xd;
also in commercial applications. However, attackers are now knowledgeable about these&#xd;
systems, and have started preparing their countermeasures. This has lead to an arms&#xd;
race between attackers and developers. Novel systems are progressively built to tackle&#xd;
the attacks that get more and more sophisticated. For this reason, a necessity grows&#xd;
for the developers to anticipate the attackers’ moves. This means that defense systems&#xd;
should be built proactively, i.e., by introducing some security design principles in their&#xd;
development. The main goal of this work is showing that such proactive approach can&#xd;
be employed on a number of case studies. To do so, I adopted a global methodology that&#xd;
can be divided in two steps. First, understanding what are the vulnerabilities of current&#xd;
state-of-the-art systems (this anticipates the attacker’s moves). Then, developing novel&#xd;
systems that are robust to these attacks, or suggesting research guidelines with which&#xd;
current systems can be improved. This work presents two main case studies, concerning&#xd;
the detection of PDF and Android malware. The idea is showing that a proactive approach&#xd;
can be applied both on the X86 and mobile world. The contributions provided on&#xd;
this two case studies are multifolded. With respect to PDF files, I first develop novel attacks&#xd;
that can empirically and optimally evade current state-of-the-art detectors. Then,&#xd;
I propose possible solutions with which it is possible to increase the robustness of such&#xd;
detectors against known and novel attacks. With respect to the Android case study,&#xd;
I first show how current signature-based tools and academically developed systems are&#xd;
weak against empirical obfuscation attacks, which can be easily employed without particular&#xd;
knowledge of the targeted systems. Then, I examine a possible strategy to build a&#xd;
machine learning detector that is robust against both empirical obfuscation and optimal&#xd;
attacks. Finally, I will show how proactive approaches can be also employed to develop&#xd;
systems that are not aimed at detecting malware, such as mobile fingerprinting systems.&#xd;
In particular, I propose a methodology to build a powerful mobile fingerprinting system,&#xd;
and examine possible attacks with which users might be able to evade it, thus preserving&#xd;
their privacy. To provide the aforementioned contributions, I co-developed (with the cooperation&#xd;
of the researchers at PRALab and Ruhr-Universität Bochum) various systems:&#xd;
a library to perform optimal attacks against machine learning systems (AdversariaLib),&#xd;
a framework for automatically obfuscating Android applications, a system to the robust&#xd;
detection of Javascript malware inside PDF files (LuxOR), a robust machine learning system&#xd;
to the detection of Android malware, and a system to fingerprint mobile devices. I&#xd;
also contributed to develop Android PRAGuard, a dataset containing a lot of empirical&#xd;
obfuscation attacks against the Android platform. Finally, I entirely developed Slayer&#xd;
NEO, an evolution of a previous system to the detection of PDF malware. The results&#xd;
attained by using the aforementioned tools show that it is possible to proactively build&#xd;
systems that predict possible evasion attacks. This suggests that a proactive approach&#xd;
is crucial to build systems that provide concrete security against general and evasion&#xd;
attacks.</dc:description>
<dc:date>2016-03-04</dc:date>
<dc:type>info:eu-repo/semantics/doctoralThesis</dc:type>
<dc:identifier>http://hdl.handle.net/11584/266872</dc:identifier>
<dc:language>eng</dc:language>
<dc:relation>numberofpages:188</dc:relation>
<dc:rights>info:eu-repo/semantics/openAccess</dc:rights>
<dc:publisher>Università degli Studi di Cagliari</dc:publisher>
<dc:rights>license:Non specificato</dc:rights>
</oai_dc:dc></metadata></record></GetRecord></OAI-PMH>