Characterizing and Codifying Malware Sophistication Publication

Systematizes static binary analysis approaches for assessing malware quality, reinterpreting ISO/IEC 25010 characteristics (reliability, maintainability, flexibility, security) to define and measure malware sophistication when source code or dynamic execution is unavailable.

Andarwin: Scalable detection of android application clones based on semantics Publication

Journal article presenting AnDarwin’s scalable semantic analysis approach that detected 4,295 cloned and 36,106 rebranded apps from 265,359 applications across 17 markets including Google Play, with automatic library code removal.

Andarwin: Scalable detection of semantically similar android applications Publication

Introduces AnDarwin, a scalable tool that analyzed 265,359 apps from 17 markets to detect 4,295 clones and 36,106 rebranded apps, discovering 88 new malware variants by comparing semantic information without pairwise comparison.

Attack of the clones: Detecting cloned applications on android markets Publication

Presents DNADroid, a tool that detects Android application cloning by comparing program dependency graphs, identifying at least 141 cloned apps including cases of malware injection and ad revenue redirection.

AndroidLeaks: Automatically Detecting Potential Privacy Leaks in Android Applications on a Large Scale Publication

Presents AndroidLeaks, which analyzed 24,350 Android apps in 30 hours and found 2,342 apps leaking private data including phone info, GPS location, WiFi data, and audio from 57,299 potential privacy leaks detected.