wkr | publications
Journal Publications
"A Multi-model Approach to the Detection of Web-based Attacks"
In the Journal of Computer Networks.

Vol. 48, No. 5, July 2005.

[ Download ]



"Using Alert Verification to Identify Successful Intrusion Attempts"
In the Journal of Practice in Information Processing and Communication (PIK).

Vol. 27, No. 4, October 2004.

[ Download ]



Conference Publications
"Using Generalization and Characterization Techniques in the Anomaly-based Detection of Web Attacks"
In the Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS).

February 2006, San Diego, CA USA.

[ Download ] [ Presentation ]



"Polymorphic Worm Detection Using Structural Information of Executables"
In the Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection (RAID).

September 2005, Seattle, WA USA.

[ Download ]



"Automating Mimicry Attacks Using Static Binary Analysis"
In the Proceedings of the 14th USENIX Security Symposium.

July 2005, Baltimore, MD USA.

[ Download ]



"Reverse Engineering of Network Signatures"
In the Proceedings of the 4th Annual Asia Pacific Information Technology Security Conference (AusCERT).

May 2005, Gold Coast, Australia.

Received Best Paper Award.

[ Download ]



"Detecting Kernel-Level Rootkits Through Binary Analysis"
In the Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC).

December 2004, Tuscon, AZ USA.

[ Download ] [ Presentation ]



"Testing Network-based Intrusion Detection Signatures Using Mutant Exploits"
In the Proceedings of the 11th ACM Conference on Computer and Communications Security (CCS).

October 2004, Washington DC, USA.

[ Download ]



"Static Disassembly of Obfuscated Binaries"
In the Proceedings of the 13th USENIX Security Symposium.

August 2004, San Diego, CA USA.

[ Download ]



"A Stateful Intrusion Detection System for World-Wide Web Servers"
In the Proceedings of the 19th Annual Computer Security Applications Conference (ACSAC).

December 2003, Las Vegas, NV USA.

[ Download ] [ Presentation ]



"Bayesian Event Classification for Intrusion Detection"
In the Proceedings of the 19th Annual Computer Security Applications Conference (ACSAC).

December 2003, Las Vegas, NV USA.

[ Download ]



"Run-time Detection of Heap-based Overflows"
In the Proceedings of the 17th USENIX Large Installation Systems Administration Conference (LISA).

October 2003, San Diego, CA USA.

[ Download ] [ Presentation ]



"Topology-based Detection of Anomalous BGP Messages"
In the Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection (RAID).

September 2003, Pittsburgh, PA USA.

[ Download ]



Workshop Publications
"Alert Verification: Determining the Success of Intrusion Attempts"
In the Proceedings of the 1st Workshop on the Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA).

July 2004, Dortmund, Germany.

[ Download ]