Skip to main content
  • Home
  • About
  • Faculty Experts
  • For The Media
  • Videos
  • Topics
    • Alumni
    • Events
    • Faculty
    • Library
    • Research
    • Students
    • All Topics
  • Contact
  • Submit
STEM
  • All News
  • Arts & Culture
  • Business & Economy
  • Campus & Community
  • Health & Society
  • Media, Law & Policy
  • STEM
  • Veterans
  • |
  • Alumni
  • The Peel
  • Athletics
Sections
  • All News
  • Arts & Culture
  • Business & Economy
  • Campus & Community
  • Health & Society
  • Media, Law & Policy
  • STEM
  • Veterans
  • |
  • Alumni
  • The Peel
  • Athletics
  • Home
  • About
  • Faculty Experts
  • For The Media
  • Videos
  • Topics
    • Alumni
    • Events
    • Faculty
    • Library
    • Research
    • Students
    • All Topics
  • Contact
  • Submit
STEM

Faculty to Present Research at Cybersecurity Conference

Thursday, October 30, 2014, By Matt Wheeler
Share
College of Engineering and Computer Science

The College of Engineering and Computer Science has had three papers accepted by the Association for Computing Machinery’s Conference on Computer and Communications Security, a prestigious security conference that will take place this November in Scottsdale, Ariz. It is a notable achievement to have three research papers accepted from the same institution at such a well-regarded cybersecurity conference. Students and faculty will travel to the conference and present their work to an audience of computing professionals and researchers.

engineersIn their paper, “Code Injection Attacks on HTML5-based Mobile Apps: Characterization, Detection and Mitigation,” Professors Wenliang (Kevin) Du and Heng Yin address the security concerns that arise as smartphone applications begin to rely more and more on HTML5. Unfortunately, the web technology used by HTML5-based mobile apps has a dangerous feature, which allows data and code to be mixed together, making code injection attacks possible.

Du and Yin conducted a systematic study on such apps and found a new form of code injection attack, which inherits the fundamental cause of cross-site scripting attack (XSS), but uses many more channels to inject code than XSS.  These channels, unique to mobile devices, include Contact, SMS, Barcode and MP3 files. To assess the prevalence of this, they developed a vulnerability detection tool and analyzed apps found in Google Play. Out of 15,510 apps, 478 apps were found to be vulnerable. Click here for more details.

In another paper, “Semantics-Aware Android Malware Classification Using Weighted Contextual API Dependency Graphs,” Yin highlights how the drastic increase of Android malware has necessitated automation of the malware analysis process. Existing automated detection and classification can be easily evaded In this paper, Yin proposes a semantic-based approach that classifies malware via dependency graphs. Using these, he and his team have developed methods to battle transformation attacks, malware variants and zero-day malware. They have also implemented a prototype system that can correctly label 93 percent of malware instances. Click here for more details.

Finally, in “Beware, Your Hands Reveal Your Secrets,” Professor Vir V. Phoha reveals his research that introduces a new way for adversaries to learn a smartphone user’s PIN. Instead of watching over a person’s shoulder, this method relies entirely on the spatio-temporal dynamics of a person’s hands as they enter their PIN. Essentially, that means that adversaries can determine your PIN without even being able to see your screen. Click here for more details.

 

  • Author
  • Faculty Experts

Matt Wheeler

  • Vir V. Phoha

  • Recent
  • Data Privacy Day 2021: Is Your Personal Information Safe?
    Monday, January 25, 2021, By Daryl Lovell
  • Spring 2021 Office of Research Events Focus on Research Success
    Monday, January 25, 2021, By News Staff
  • A&S Speech Disorders Professor: Poet Amanda Gorman’s Story Shares Important Lesson
    Monday, January 25, 2021, By Daryl Lovell
  • Syracuse University Names Four as “Unsung Heroes” in Honor of Rev. Dr. Martin Luther King Jr.
    Monday, January 25, 2021, By News Staff
  • WAER Will Transition to the Newhouse School This Summer
    Monday, January 25, 2021, By Wendy S. Loughlin

More In STEM

Data Privacy Day 2021: Is Your Personal Information Safe?

Jan. 28 is Data Privacy Day, an annual event to create and raise awareness about how personal information is collected, secured and shared in the growing digital world. A 2019 Pew Research Center report found a majority of Americans were…

Professor Rahman Awarded Google Grant to Engage Underrepresented Students in Computing Research

Electrical engineering and computer science (EECS) Professor Farzana Rahman received a 2020 Google exploreCSR award to fund the development of an undergraduate student engagement workshop program, Research Exposure in Socially Relevant Computing (RESORC). The RESORC program will provide research opportunities…

Arts and Sciences Welcomes New Director of Forensics Kathleen Corrado

After 25 years working in the field of forensic science and over two decades of executive experience as a laboratory director, Kathleen Corrado has been named director of the Forensic and National Security Science Institute (FNSSI) in the College of…

Hehnly Lab Awarded $1.2M NIH Grant to Research Critical Tissue Formation

A key process during the development of an embryo is tissue morphogenesis, where the number of cells in an organism increase through cell division and tissues begins to take shape. Heidi Hehnly, assistant professor of biology, has been awarded a…

The Role of Digital Forensics and Tracking Down US Capitol Riot Criminals

With just under a week left before President-elect Joe Biden’s inauguration ceremony, investigators and law enforcement agencies across the country are working speedily to identify as many of the Jan. 6 U.S. Capitol riot offenders as they can. Knowing exactly…

Subscribe to SU Today

If you need help with your subscription, contact sunews@syr.edu.

Connect With Us

  • Twitter
  • Facebook
  • Instagram
  • Youtube
  • LinkedIn
Social Media Directory

For the Media

Find an Expert Follow @SyracuseUNews
  • Facebook
  • Instagram
  • Youtube
  • LinkedIn
  • @SyracuseU
  • @SyracuseUNews
  • @SUCampus
  • Social Media Directory
  • Accessibility
  • Privacy
  • Campus Status
  • Syracuse.edu
© 2021 Syracuse University News. All Rights Reserved.