Security

Classifying malware and detecting vulnerabilities, from both machine learning and stochastic modelling.

Information security is a precondition for any information system that serves as social infrastructure. Operating a network safely and reliably demands high dependability, yet unauthorised access and malware grow more sophisticated every year, and countermeasures struggle to keep pace with new threats.

We approach the problem from two directions. On the machine learning side we work on malware classification that analyses API call sequences with recurrent neural networks, detection of vulnerable code with graph neural networks, and classification using transformers.

On the stochastic modelling side we describe the vulnerability discovery process with non-homogeneous Poisson processes and related models, and use it to derive the optimal timing for releasing a security patch, or to forecast how many vulnerabilities an operating system will reveal. Availability analysis of intrusion-tolerant systems belongs to the same line of work.

Research highlights in this area