Publications

233 refereed publications, listed by type and then in reverse chronological order. See also my Google Scholar profile and DBLP record.

Download all citations

Articles in Refereed Journals

  1. Carter Yagemann, Simon Pak Ho Chung, Erkam Uzun, Sai Ragam, Brendan Saltaformaggio, and Wenke Lee. Modeling Large-Scale Manipulation in Open Stock Markets. IEEE Security & Privacy, 19(6), 2021.
    BibTeX
    @article{yagemann2021modeling, title={Modeling Large-Scale Manipulation in Open Stock Markets}, volume={19}, ISSN={1558-4046}, url={http://dx.doi.org/10.1109/msec.2021.3076717}, DOI={10.1109/msec.2021.3076717}, number={6}, journal={IEEE Security \& Privacy}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Yagemann, Carter and Chung, Pak Ho and Uzun, Erkam and Ragam, Sai and Saltaformaggio, Brendan and Lee, Wenke}, year={2021}, month=Nov, pages={58--65} }
  2. Matthew Lau, Ismaïla Seck, Athanasios P. Meliopoulos, Wenke Lee, and Eugène Ndiaye. Revisiting Non-separable Binary Classification and its Applications in Anomaly Detection. Transactions on Machine Learning Research. Vol 2024.
    BibTeX
    @article{lau2024revisiting,
      author  = {Matthew Lau and Ismaïla Seck and Athanasios P. Meliopoulos and Wenke Lee and Eugène Ndiaye},
      title   = {Revisiting Non-separable Binary Classification and its Applications in Anomaly Detection},
      journal = {Transactions on Machine Learning Research},
      year    = {2024}
    }
  3. Dinuka Sahabandu, Shana Moothedath, Joey Allen, Linda Bushnell, Wenke Lee, and Radha Poovendran. RL-ARNE: A Reinforcement Learning Algorithm for Computing Average Reward Nash Equilibrium of Nonzero-Sum Stochastic Games. IEEE Transactions on Automatic Control. Vol 69(11), 2024.
    BibTeX
    @article{sahabandu2024rl, title={RL-ARNE: A Reinforcement Learning Algorithm for Computing Average Reward Nash Equilibrium of Nonzero-Sum Stochastic Games}, volume={69}, ISSN={2334-3303}, url={http://dx.doi.org/10.1109/tac.2024.3403693}, DOI={10.1109/tac.2024.3403693}, number={11}, journal={IEEE Transactions on Automatic Control}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Sahabandu, Dinuka and Moothedath, Shana and Allen, Joey and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2024}, month=Nov, pages={7824--7831} }
  4. Shana Moothedath, Dinuka Sahabandu, Joey Allen, Andrew Clark, Linda Bushnell, Wenke Lee, and Radha Poovendran. Dynamic Information Flow Tracking for Detection of Advanced Persistent Threats: A Stochastic Game Approach. IEEE Transactions on Automatic Control. Vol 69(10), 2024.
    BibTeX
    @article{moothedath2024dynamic, title={Dynamic Information Flow Tracking for Detection of Advanced Persistent Threats: A Stochastic Game Approach}, volume={69}, ISSN={2334-3303}, url={http://dx.doi.org/10.1109/tac.2024.3403675}, DOI={10.1109/tac.2024.3403675}, number={10}, journal={IEEE Transactions on Automatic Control}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Moothedath, Shana and Sahabandu, Dinuka and Allen, Joey and Clark, Andrew and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2024}, month=Oct, pages={6684--6699} }
  5. Shana Moothedath, Dinuka Sahabandu, Joey Allen, Linda Bushnell, Wenke Lee, and Radha Poovendran. Stochastic Dynamic Information Flow Tracking game using supervised learning for detecting advanced persistent threats. Automatica. Vol 159, 2024.
    BibTeX
    @article{moothedath2024stochastic, title={Stochastic Dynamic Information Flow Tracking game using supervised learning for detecting advanced persistent threats}, volume={159}, ISSN={0005-1098}, url={http://dx.doi.org/10.1016/j.automatica.2023.111353}, DOI={10.1016/j.automatica.2023.111353}, journal={Automatica}, publisher={Elsevier BV}, author={Moothedath, Shana and Sahabandu, Dinuka and Allen, Joey and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2024}, month=Jan, pages={111353} }
  6. Yisroel Mirsky, Ambra Demontis, Jaidip Kotak, Ram Shankar, Gelei Deng, Liu Yang, Xiangyu Zhang, Maura Pintor, Wenke Lee, Yuval Elovici, and Battista Biggio. The Threat of Offensive AI to Organizations. Computer Security. Vol 124, 2023.
    BibTeX
    @article{mirsky2023threat, title={The Threat of Offensive AI to Organizations}, volume={124}, ISSN={0167-4048}, url={http://dx.doi.org/10.1016/j.cose.2022.103006}, DOI={10.1016/j.cose.2022.103006}, journal={Computers \& Security}, publisher={Elsevier BV}, author={Mirsky, Yisroel and Demontis, Ambra and Kotak, Jaidip and Shankar, Ram and Gelei, Deng and Yang, Liu and Zhang, Xiangyu and Pintor, Maura and Lee, Wenke and Elovici, Yuval and Biggio, Battista}, year={2023}, month=Jan, pages={103006} }
  7. Yisroel Mirsky and Wenke Lee. The Creation and Detection of Deepfakes: A Survey. ACM Computing Surveys. 54(1), 2022.
    BibTeX
    @article{mirsky2022creation,
      author  = {Yisroel Mirsky and Wenke Lee},
      title   = {The Creation and Detection of Deepfakes: A Survey},
      journal = {ACM Computing Surveys},
      volume  = {54},
      number  = {1},
      year    = {2022}
    }
  8. Kangjie Lu, Meng Xu, Chengyu Song, Taesoo Kim, and Wenke Lee. Stopping Memory Disclosures via Diversification and Replicated Execution. IEEE Transactions on Dependable and Secure Computing (TDSC). 18(1), 2021.
    BibTeX
    @article{lu2021stopping, title={Stopping Memory Disclosures via Diversification and Replicated Execution}, volume={18}, ISSN={2160-9209}, url={http://dx.doi.org/10.1109/tdsc.2018.2878234}, DOI={10.1109/tdsc.2018.2878234}, number={1}, journal={IEEE Transactions on Dependable and Secure Computing}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Lu, Kangjie and Xu, Meng and Song, Chengyu and Kim, Taesoo and Lee, Wenke}, year={2021}, month=Jan, pages={160--173} }
  9. Shana Moothedath, Dinuka Sahabandu, Joey Allen, Andrew Clark, Linda Bushnell, Wenke Lee, and Radha Poovendran. A Game-Theoretic Approach for Dynamic Information Flow Tracking to Detect Multistage Advanced Persistent Threats. IEEE Transactions on Automatic Control. 65(12): 5248-5263, 2020.
    BibTeX
    @article{moothedath2020game, title={A Game-Theoretic Approach for Dynamic Information Flow Tracking to Detect Multistage Advanced Persistent Threats}, volume={65}, ISSN={2334-3303}, url={http://dx.doi.org/10.1109/tac.2020.2976040}, DOI={10.1109/tac.2020.2976040}, number={12}, journal={IEEE Transactions on Automatic Control}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Moothedath, Shana and Sahabandu, Dinuka and Allen, Joey and Clark, Andrew and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2020}, month=Dec, pages={5248--5263} }
  10. Junjie Zhang, Roberto Perdisci, Wenke Lee, Unum Sarfraz, and Xiapu Luo. Building a Scalable System for Stealthy P2P-Botnet Detection. IEEE Transactions on Information Forensics and Security, 9(1), January 2014.
    BibTeX
    @article{zhang2014building, title={Building a Scalable System for Stealthy P2P-Botnet Detection}, volume={9}, ISSN={1556-6021}, url={http://dx.doi.org/10.1109/tifs.2013.2290197}, DOI={10.1109/tifs.2013.2290197}, number={1}, journal={IEEE Transactions on Information Forensics and Security}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Zhang, Junjie and Perdisci, Roberto and Lee, Wenke and Luo, Xiapu and Sarfraz, Unum}, year={2014}, month=Jan, pages={27--38} }
  11. Roberto Perdisci, Davide Ariu, Prahlad Fogla, Giorgio Giacinto, and Wenke Lee. McPAD: A Multiple Classifier System for Accurate Payload-Based Anomaly Detection. Computer Networks, 53(6), 2009.
    BibTeX
    @article{perdisci2009mcpad, title={McPAD: A multiple classifier system for accurate payload-based anomaly detection}, volume={53}, ISSN={1389-1286}, url={http://dx.doi.org/10.1016/j.comnet.2008.11.011}, DOI={10.1016/j.comnet.2008.11.011}, number={6}, journal={Computer Networks}, publisher={Elsevier BV}, author={Perdisci, Roberto and Ariu, Davide and Fogla, Prahlad and Giacinto, Giorgio and Lee, Wenke}, year={2009}, month=Apr, pages={864--881} }
  12. Roberto Perdisci, Andrea Lanzi, and Wenke Lee. Classification of Packed Executables for Accurate Computer Virus Detection. Pattern Recognition Letters, 29(14), October 2008.
    BibTeX
    @article{perdisci2008classification, title={Classification of packed executables for accurate computer virus detection}, volume={29}, ISSN={0167-8655}, url={http://dx.doi.org/10.1016/j.patrec.2008.06.016}, DOI={10.1016/j.patrec.2008.06.016}, number={14}, journal={Pattern Recognition Letters}, publisher={Elsevier BV}, author={Perdisci, Roberto and Lanzi, Andrea and Lee, Wenke}, year={2008}, month=Oct, pages={1941--1946} }
  13. Prahlad Fogla and Wenke Lee. q-Gram Matching Using Tree Models. IEEE Transactions on Knowledge and Data Engineering, 18(4), April 2006.
    BibTeX
    @article{fogla2006q,
      author  = {Prahlad Fogla and Wenke Lee},
      title   = {{q-Gram} Matching Using Tree Models},
      journal = {IEEE Transactions on Knowledge and Data Engineering},
      volume  = {18},
      number  = {4},
      month   = {apr},
      year    = {2006},
      doi     = {10.1109/tkde.2006.66}
    }
  14. W. Fan, M. Miller, S. Stolfo, W. Lee, and P. Chan. Using Artificial Anomalies to Detect Unknown and Known Network Intrusions. Knowledge and Information Systems, Springer, 6(5), September 2004.
    BibTeX
    @article{fan2004using, title={Using artificial anomalies to detect unknown and known network intrusions}, volume={6}, ISSN={0219-3116}, url={http://dx.doi.org/10.1007/s10115-003-0132-7}, DOI={10.1007/s10115-003-0132-7}, number={5}, journal={Knowledge and Information Systems}, publisher={Springer Science and Business Media LLC}, author={Fan, W. and Miller, M. and Stolfo, S. and Lee, W. and Chan, P.}, year={2004}, month=Apr, pages={507--527} }
  15. Yongguang Zhang, Wenke Lee, and Yian Huang. Intrusion Detection Techniques for Mobile Wireless Networks. ACM/Kluwer Wireless Networks Journal (ACM WINET), 9(5), September 2003.
    BibTeX
    @article{zhang2003intrusion,
      author  = {Yongguang Zhang and Wenke Lee and Yian Huang},
      title   = {Intrusion Detection Techniques for Mobile Wireless Networks},
      journal = {ACM/Kluwer Wireless Networks Journal (ACM WINET)},
      volume  = {9},
      number  = {5},
      month   = {sep},
      year    = {2003}
    }
  16. Joao B. D. Cabrera, Lundy Lewis, Xinzhou Qin, Wenke Lee, and Raman K. Mehra. Proactive Intrusion Detection and Distributed Denial of Service Attacks - A Case Study in Security Management. Journal of Network and Systems Management, 10(2), June 2002.
    BibTeX
    @article{cabrera2002proactive, title={Proactive Intrusion Detection and Distributed Denial of Service Attacks—A Case Study in Security Management}, volume={10}, ISSN={1573-7705}, url={http://dx.doi.org/10.1023/a:1015910917349}, DOI={10.1023/a:1015910917349}, number={2}, journal={Journal of Network and Systems Management}, publisher={Springer Science and Business Media LLC}, author={Cabrera, João B. D. and Lewis, Lundy and Qin, Xinzhou and Lee, Wenke and Mehra, Raman K.}, year={2002}, month=June, pages={225--254} }
  17. Wenke Lee, Wei Fan, Matt Miller, Sal Stolfo, and Erez Zadok. Toward Cost-Sensitive Modeling for Intrusion Detection and Response. Journal of Computer Security, 10(1,2), 2002.
    BibTeX
    @article{lee2002cost,
      author  = {Wenke Lee and Wei Fan and Matt Miller and Sal Stolfo and Erez Zadok},
      title   = {Toward {Cost-Sensitive} Modeling for Intrusion Detection and Response},
      journal = {Journal of Computer Security},
      year    = {2002}
    }
  18. Wenke Lee and Sal Stolfo. A Framework for Constructing Features and Models for Intrusion Detection Systems. ACM Transactions on Information and System Security, 3(4), November 2000.
    BibTeX
    @article{lee2000framework,
      author  = {Wenke Lee and Sal Stolfo},
      title   = {A Framework for Constructing Features and Models for Intrusion Detection Systems},
      journal = {ACM Transactions on Information and System Security},
      volume  = {3},
      number  = {4},
      month   = {nov},
      year    = {2000}
    }
  19. Wenke Lee, Sal Stolfo, and Kui Mok. Adaptive Intrusion Detection: A Data Mining Approach. Artificial Intelligence Review, Kluwer Academic Publishers, 14(6):533-567, December 2000.
    BibTeX
    @article{lee2000adaptive,
      author  = {Wenke Lee and Sal Stolfo and Kui Mok},
      title   = {Adaptive Intrusion Detection: A Data Mining Approach},
      journal = {Artificial Intelligence Review},
      volume  = {14},
      number  = {6},
      pages   = {533--567},
      month   = {dec},
      year    = {2000}
    }
  20. Wenke Lee and Gail E. Kaiser. Interfacing Oz with the PCTE OMS: A Case Study of Integrating a Legacy System with a Standard Object Management System. Journal of Systems Integration, Kluwer Academic Publishers, 9(4):329-358, December 1999.
    BibTeX
    @article{lee1999interfacing,
      author  = {Wenke Lee and Gail E. Kaiser},
      title   = {Interfacing Oz with the {PCTE} {OMS}: A Case Study of Integrating a Legacy System with a Standard Object Management System},
      journal = {Journal of Systems Integration},
      volume  = {9},
      number  = {4},
      pages   = {329--358},
      month   = {dec},
      year    = {1999}
    }

Refereed Book Chapters

  1. Xinzhou Qin and Wenke Lee. Discovering Novel Attack Strategies from INFOSEC Alerts. Data Warehousing and Data Mining Techniques for Cyber Security. Anoop Singhal (eds), Springer, 2007.
    BibTeX
    @incollection{qin2007discovering,
      author    = {Xinzhou Qin and Wenke Lee},
      title     = {Discovering Novel Attack Strategies from {INFOSEC} Alerts},
      booktitle = {Data Warehousing and Data Mining Techniques for Cyber Security},
      year      = {2007}
    }
  2. Yongguang Zhang and Wenke Lee. Security in Mobile Ad-Hoc Networks. Ad Hoc Networks: Technologies and Protocols. P. Mohapatra and S. Krishnamurthy (eds), Springer, 2004.
    BibTeX
    @inbook{zhang2004security, title={Security in Mobile Ad-Hoc Networks}, ISBN={9780387226903}, url={http://dx.doi.org/10.1007/0-387-22690-7_9}, DOI={10.1007/0-387-22690-7_9}, booktitle={Ad Hoc Networks}, publisher={Springer US}, author={Zhang, Yongguang and Lee, Wenke}, year={2005}, pages={249--268} }
  3. Xinzhou Qin, Wenke Lee, Lundy Lewis, Joao B. Cabrera. Using MIB II Variables for Network Intrusion Detection. Applications of Data Mining in Computer Security. D. Barbara and S. Jajodia (eds), Kluwer Academic Publishers, May 2002.
    BibTeX
    @inbook{qin2002using, title={Using MIB II Variables for Network Intrusion Detection}, ISBN={9781461509530}, ISSN={1568-2633}, url={http://dx.doi.org/10.1007/978-1-4615-0953-0_6}, DOI={10.1007/978-1-4615-0953-0_6}, booktitle={Applications of Data Mining in Computer Security}, publisher={Springer US}, author={Qin, Xinzhou and Lee, Wenke and Lewis, Lundy and Cabrera, João B. D.}, year={2002}, pages={123--151} }
  4. Joao B.D. Cabrera, Lundy Lewis, Xinzhou Qin, Wenke Lee, Raman K. Mehra. Proactive Intrusion Detection - A Study on Temporal Data Mining. Applications of Data Mining in Computer Security. D. Barbara and S. Jajodia (eds), Kluwer Academic Publishers, May 2002
    BibTeX
    @inbook{cabrera2002proactivea, title={Proactive Intrusion Detection: A Study on Temporal Data Mining}, ISBN={9781461509530}, ISSN={1568-2633}, url={http://dx.doi.org/10.1007/978-1-4615-0953-0_8}, DOI={10.1007/978-1-4615-0953-0_8}, booktitle={Applications of Data Mining in Computer Security}, publisher={Springer US}, author={Cabrera, João B. D. and Lewis, Lundy and Qin, Xinzhou and Lee, Wenke and Mehra, Raman K.}, year={2002}, pages={195--227} }
  5. Wenke Lee, Sal Stolfo, and Kui Mok. Algorithms for Mining System Audit Data. Data Mining, Rough Sets, and Granular Computing, T. Y. Lin Y. Y. Yao, and L. A. Zadeh (eds), Physica-Verlag, 2002.
    BibTeX
    @incollection{lee2002algorithms,
      author    = {Wenke Lee and Sal Stolfo and Kui Mok},
      title     = {Algorithms for Mining System Audit Data},
      booktitle = {Data Mining},
      year      = {2002}
    }
  6. Wenke Lee and Naser Barghouti. Jadve: An Extensible Data Visualization Environment. Object-Oriented Applications Frameworks, M. Fayad, D. Schmidt, and R. Johnson (eds), John Wiley & Sons, 1999.
    BibTeX
    @incollection{lee1999jadve,
      author    = {Wenke Lee and Naser Barghouti},
      title     = {Jadve: An Extensible Data Visualization Environment},
      booktitle = {Object-Oriented Applications Frameworks},
      year      = {1999}
    }

Edited Proceedings

  1. Proceedings of the Second ACM Conference on Wireless Network Security (WISEC 2009), David A. Basin, Srdjan Capkun, Wenke Lee (Eds.), Zurich, Switzerland, March 16-19, 2009, ACM, 2009.
  2. Botnet Detection: Countering the Largest Security Threat (Advances in Information Security), Wenke Lee, Cliff Wang, and David Dagon (Eds.), Springer, 2007.
  3. Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID 2001), Wenke Lee, Ludovic Me, and Andreas Wespi (Eds.), Lecture Notes in Computer Science, Vol. 2212, Springer, 2001.

Papers in Refereed Conferences

  1. Xiangchi Yuan, Dachuan Shi, Chunhui Zhang, Zheyuan Liu, Shenglong Yao, Soroush Vosoughi, and Wenke Lee. Behavior Knowledge Merge in Reinforced Agentic Models. In Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (ACL). 2026.
    BibTeX
    @inproceedings{yuan2026behavior, title={Behavior Knowledge Merge in Reinforced Agentic Models}, url={http://dx.doi.org/10.18653/v1/2026.acl-long.1524}, DOI={10.18653/v1/2026.acl-long.1524}, booktitle={Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)}, publisher={Association for Computational Linguistics}, author={Yuan, Xiangchi and Shi, Dachuan and Zhang, Chunhui and Liu, Zheyuan and Yao, Shenglong and Vosoughi, Soroush and Lee, Wenke}, year={2026}, pages={33007--33028} }
  2. Mansi Phute, Matthew Hull, Haoran Wang, Alec Helbling, Sheng-Yun Peng, Willian T. Lunardi, Martin Andreoni, Wenke Lee, and Duen Horng Chau. Differentiable Rendering Powered End-to-End Adversarial Attack Evaluation. In Proceedings of the Pacific-Asia Conference on Knowledge Discovery and Data Mining (PAKDD). 2026.
    BibTeX
    @inbook{phute2026differentiable, title={Differentiable Rendering Powered End-to-End Adversarial Attack Evaluation}, ISBN={9789819214655}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-981-92-1465-5_9}, DOI={10.1007/978-981-92-1465-5_9}, booktitle={Advances in Knowledge Discovery and Data Mining}, publisher={Springer Nature Singapore}, author={Phute, Mansi and Hull, Matthew and Wang, Haoran and Helbling, Alec and Peng, ShengYun and Lunardi, Willian and Andreoni, Martin and Lee, Wenke and Chau, Duen Horng}, year={2026}, pages={107--120} }
  3. Yupeng Yang, Shenglong Yao, Jizhou Chen, and Wenke Lee. Hybrid Language Processor Fuzzing via LLM-Based Constraint Solving. In Proceedings of the 34th USENIX Security Symposium (USENIX). 2025.
    BibTeX
    @inproceedings{yang2025hybrid,
      author    = {Yupeng Yang and Shenglong Yao and Jizhou Chen and Wenke Lee},
      title     = {Hybrid Language Processor Fuzzing via {LLM-Based} Constraint Solving},
      booktitle = {Proceedings of the 34th USENIX Security Symposium (USENIX)},
      year      = {2025}
    }
  4. Zheng Yang, Simon P. Chung, Jizhou Chen, Runze Zhang, Brendan Saltaformaggio, and Wenke Lee. CoinDef: A Comprehensive Code Injection Defense for the Electron Framework. In Proceedings of the 46th IEEE Symposium on Security and Privacy. 2025.
    BibTeX
    @inproceedings{yang2025coindef, title={CoinDef: A Comprehensive Code Injection Defense for the Electron Framework}, url={http://dx.doi.org/10.1109/sp61157.2025.00195}, DOI={10.1109/sp61157.2025.00195}, booktitle={2025 IEEE Symposium on Security and Privacy (SP)}, publisher={IEEE}, author={Yang, Zheng and Chung, Simon P. and Chen, Jizhou and Zhang, Runze and Saltaformaggio, Brendan and Lee, Wenke}, year={2025}, month=May, pages={3127--3144} }
  5. Haoran Wang, Zheng Yang, Sangdon Park, Yibin Yang, Seulbae Kim, Willian T. Lunardi, Martin Andreoni, Taesoo Kim, and Wenke Lee. SoundBoost: Effective RCA and Attack Detection for UAV via Acoustic Side-Channel. In Proceedings of the 55th IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). 2025.
    BibTeX
    @inproceedings{wang2025soundboost, title={SoundBoost: Effective RCA and Attack Detection for UAV via Acoustic Side-Channel}, url={http://dx.doi.org/10.1109/dsn64029.2025.00039}, DOI={10.1109/dsn64029.2025.00039}, booktitle={2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)}, publisher={IEEE}, author={Wang, Haoran and Yang, Zheng and Park, Sangdon and Yang, Yibin and Kim, Seulbae and Lunardi, Willian and Andreoni, Martin and Kim, Taesoo and Lee, Wenke}, year={2025}, month=June, pages={289--302} }
  6. Moses Ike, Keaton Sadoski, Romuald Valme, Burak Sahin, Saman A. Zonouz, and Wenke Lee. Your Control Host Intrusion Left Some Physical Breadcrumbs: Physical Evidence-Guided Post-Mortem Triage of SCADA Attacks. In Proceedings of the ACM ASIA Conference on Computer and Communications Security (AsiaCCS). 2025.
    BibTeX
    @inproceedings{ike2025your, series={ASIA CCS ’25}, title={Your Control Host Intrusion Left Some Physical Breadcrumbs: Physical Evidence-Guided Post-Mortem Triage of SCADA Attacks}, url={http://dx.doi.org/10.1145/3708821.3710817}, DOI={10.1145/3708821.3710817}, booktitle={Proceedings of the 20th ACM Asia Conference on Computer and Communications Security}, publisher={ACM}, author={Ike, Moses and Sadoski, Keaton and Valme, Romuald and Sahin, Burak and Zonouz, Saman and Lee, Wenke}, year={2025}, month=Aug, pages={1016--1031}, collection={ASIA CCS ’25} }
  7. Leyan Pan, Vijay Ganesh, Jacob D. Abernethy, Chris Esposo, and Wenke Lee. Can Transformers Reason Logically? A Study in SAT Solving. In Proceedings of the 42nd International Conference on Machine Learning (ICML). 2025.
    BibTeX
    @inproceedings{pan2025can,
      author    = {Leyan Pan and Vijay Ganesh and Jacob D. Abernethy and Chris Esposo and Wenke Lee},
      title     = {Can Transformers Reason Logically? A Study in {SAT} Solving},
      booktitle = {Proceedings of the 42nd International Conference on Machine Learning (ICML)},
      year      = {2025}
    }
  8. Matthew Hull, Haoran Wang, Matthew Lau, Alec Helbling, Mansi Phute, Chao Zhang, Zsolt Kira, Willian T. Lunardi, Martin Andreoni, Wenke Lee, and Duen Horng Chau. RenderBender: A Survey on Adversarial Attacks Using Differentiable Rendering. In Proceedings of the 34th International Joint Conference on Artificial Intelligence (IJCAI). 2025.
    BibTeX
    @inproceedings{hull2025renderbender, series={IJCAI-2024}, title={RenderBender: A Survey on Adversarial Attacks Using Differentiable Rendering}, url={http://dx.doi.org/10.24963/ijcai.2024/1163}, DOI={10.24963/ijcai.2024/1163}, booktitle={Proceedings of the Thirty-ThirdInternational Joint Conference on Artificial Intelligence}, publisher={International Joint Conferences on Artificial Intelligence Organization}, author={Hull, Matthew and Wang, Haoran and Lau, Matthew and Helbling, Alec and Phute, Mansi and Zhang, Chao and Kira, Zsolt and Lunardi, Willian and Andreoni, Martin and Lee, Wenke and Chau, Duen Horng}, year={2024}, month=Aug, pages={10473--10480}, collection={IJCAI-2024} }
  9. Xiangchi Yuan, Chunhui Zhang, Zheyuan Liu, Dachuan Shi, Leyan Pan, Soroush Vosoughi, and Wenke Lee. Superficial Self-Improved Reasoners Benefit from Model Merging. In Proceedings of the Conference on Empirical Methods in Natural Language Processing (EMNLP). 2025.
    BibTeX
    @inproceedings{yuan2025superficial, title={Superficial Self-Improved Reasoners Benefit from Model Merging}, url={http://dx.doi.org/10.18653/v1/2025.emnlp-main.301}, DOI={10.18653/v1/2025.emnlp-main.301}, booktitle={Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing}, publisher={Association for Computational Linguistics}, author={Yuan, Xiangchi and Zhang, Chunhui and Liu, Zheyuan and Shi, Dachuan and Pan, Leyan and Vosoughi, Soroush and Lee, Wenke}, year={2025}, pages={5912--5932} }
  10. Feng Xiao, Zhongfu Su, Guangliang Yang, and Wenke Lee. Jasmine: Scale up JavaScript Static Security Analysis with Computation-based Semantic Explanation. In Proceedings of the IEEE Symposium on Security and Privacy. 2024.
    BibTeX
    @inproceedings{xiao2024jasmine, title={Jasmine: Scale up JavaScript Static Security Analysis with Computation-based Semantic Explanation}, url={http://dx.doi.org/10.1109/sp54263.2024.00183}, DOI={10.1109/sp54263.2024.00183}, booktitle={2024 IEEE Symposium on Security and Privacy (SP)}, publisher={IEEE}, author={Xiao, Feng and Su, Zhongfu and Yang, Guangliang and Lee, Wenke}, year={2024}, month=May, pages={296--311} }
  11. Joey Allen, Zheng Yang, Feng Xiao, Matthew Landen, Roberto Perdisci, and Wenke Lee. WEBRR: A Forensic System for Replaying and Investigating Web-Based Attacks in The Modern Web. In Proceedings of the 33rd USENIX Security Symposium (USENIX). 2024.
    BibTeX
    @inproceedings{allen2024webrr,
      author    = {Joey Allen and Zheng Yang and Feng Xiao and Matthew Landen and Roberto Perdisci and Wenke Lee},
      title     = {{WEBRR}: A Forensic System for Replaying and Investigating {Web-Based} Attacks in The Modern Web},
      booktitle = {Proceedings of the 33rd USENIX Security Symposium (USENIX)},
      year      = {2024}
    }
  12. Yupeng Yang, Yongheng Chen, Rui Zhong, Jizhou Chen, and Wenke Lee. Towards Generic Database Management System Fuzzing. In Proceedings of the 33rd USENIX Security Symposium (USENIX). 2024.
    BibTeX
    @inproceedings{yang2024generic,
      author    = {Yupeng Yang and Yongheng Chen and Rui Zhong and Jizhou Chen and Wenke Lee},
      title     = {Towards Generic Database Management System Fuzzing},
      booktitle = {Proceedings of the 33rd USENIX Security Symposium (USENIX)},
      year      = {2024}
    }
  13. Matthew Lau, Leyan Pan, Stefan Davidov, Athanasios P. Meliopoulos, and Wenke Lee. Geometric Implications of Classification on Reducing Open Space Risk. Tiny Papers @ The Twelfth International Conference on Learning Representations (ICLR). 2024.
    BibTeX
    @inproceedings{lau2024geometric,
      author    = {Matthew Lau and Leyan Pan and Stefan Davidov and Athanasios P. Meliopoulos and Wenke Lee},
      title     = {Geometric Implications of Classification on Reducing Open Space Risk},
      booktitle = {Tiny Papers @ The Twelfth International Conference on Learning Representations (ICLR)},
      year      = {2024}
    }
  14. Matthew Lau, Fahad Alsaeed, Kayla Thames, Nano Suresettakul, Saman A. Zonouz, Wenke Lee, and Athanasios P. Meliopoulos. Physics-Assisted Explainable Anomaly Detection in Power Systems. In Proceedings of the European Conference on Artificial Intelligence. 2024.
    BibTeX
    @inbook{lau2024physics, title={Physics-Assisted Explainable Anomaly Detection in Power Systems}, ISBN={9781643685489}, ISSN={1879-8314}, url={http://dx.doi.org/10.3233/faia241073}, DOI={10.3233/faia241073}, booktitle={ECAI 2024}, publisher={IOS Press}, author={Lau, Matthew and Alsaeed, Fahad and Thames, Kayla and Suresettakul, Nano and Zonouz, Saman and Lee, Wenke and Meliopoulos, Athanasios P}, year={2024}, month=Oct }
  15. Zheng Yang, Joey Allen, Matthew Landen, Roberto Perdisci, and Wenke Lee. TRIDENT: Towards Detecting and Mitigating Web-based Social Engineering Attacks. In Proceedings of the 32nd USENIX Security Symposium (USENIX). Anaheim, California. 2023.
    BibTeX
    @inproceedings{yang2023trident,
      author    = {Zheng Yang and Joey Allen and Matthew Landen and Roberto Perdisci and Wenke Lee},
      title     = {{TRIDENT}: Towards Detecting and Mitigating Web-based Social Engineering Attacks},
      booktitle = {Proceedings of the 32nd USENIX Security Symposium (USENIX)},
      year      = {2023}
    }
  16. Yisroel Mirsky, George Macon, Michael D. Brown, Carter Yagemann, Matthew Pruett, Evan Downing, J. Sukarno Mertoguno, and Wenke Lee. VulChecker: Graph-based Vulnerability Localization in Source Code. In Proceedings of the 32nd USENIX Security Symposium (USENIX). Anaheim, California. 2023.
    BibTeX
    @inproceedings{mirsky2023vulchecker,
      author    = {Yisroel Mirsky and George Macon and Michael D. Brown and Carter Yagemann and Matthew Pruett and Evan Downing and J. Sukarno Mertoguno and Wenke Lee},
      title     = {{VulChecker}: Graph-based Vulnerability Localization in Source Code},
      booktitle = {Proceedings of the 32nd USENIX Security Symposium (USENIX)},
      year      = {2023}
    }
  17. Carter Yagemann, Simon Chung, Brendan Saltaformaggio, and Wenke Lee. PUMM: Preventing Use-After-Free Using Execution Unit Partitioning. In Proceedings of the 32nd USENIX Security Symposium (USENIX). Anaheim, California. 2023.
    BibTeX
    @inproceedings{yagemann2023pumm,
      author    = {Carter Yagemann and Simon Chung and Brendan Saltaformaggio and Wenke Lee},
      title     = {{PUMM}: Preventing {Use-After-Free} Using Execution Unit Partitioning},
      booktitle = {Proceedings of the 32nd USENIX Security Symposium (USENIX)},
      year      = {2023}
    }
  18. Yongheng Chen, Rui Zhong, Yupeng Yang, Hong Hu, Dinghao Wu, and Wenke Lee. µFUZZ: Redesign of Parallel Fuzzing using Microservice Architecture. In Proceedings of the 32nd USENIX Security Symposium (USENIX). Anaheim, California. 2023.
    BibTeX
    @inproceedings{chen2023fuzz,
      author    = {Yongheng Chen and Rui Zhong and Yupeng Yang and Hong Hu and Dinghao Wu and Wenke Lee},
      title     = {{µFUZZ}: Redesign of Parallel Fuzzing using Microservice Architecture},
      booktitle = {Proceedings of the 32nd USENIX Security Symposium (USENIX)},
      year      = {2023}
    }
  19. Moses Ike, Kandy Phan, Keaton Sadoski, Romuald Valme, and Wenke Lee. SCAPHY: Detecting Modern ICS Attacks by Correlating Behaviors in SCADA and PHYsical. In Proceedings of the 2023 IEEE Symposium on Security and Privacy. San Francisco, California. 2023.
    BibTeX
    @inproceedings{ike2023scaphy, title={Scaphy: Detecting Modern ICS Attacks by Correlating Behaviors in SCADA and PHYsical}, url={http://dx.doi.org/10.1109/sp46215.2023.10179411}, DOI={10.1109/sp46215.2023.10179411}, booktitle={2023 IEEE Symposium on Security and Privacy (SP)}, publisher={IEEE}, author={Ike, Moses and Phan, Kandy and Sadoski, Keaton and Valme, Romuald and Lee, Wenke}, year={2023}, month=May, pages={20--37} }
  20. Matthew Landen, Keywhan Chung, Moses Ike, Sarah Mackay, Jean-Paul Watson, and Wenke Lee. DRAGON: Deep Reinforcement Learning for Autonomous Grid Operation and Attack Detection. In Proceedings of the Annual Computer Security Applications Conference (ACSAC). 2022.
    BibTeX
    @inproceedings{landen2022dragon, series={ACSAC}, title={DRAGON: Deep Reinforcement Learning for Autonomous Grid Operation and Attack Detection}, url={http://dx.doi.org/10.1145/3564625.3567969}, DOI={10.1145/3564625.3567969}, booktitle={Proceedings of the 38th Annual Computer Security Applications Conference}, publisher={ACM}, author={Landen, Matthew and Chung, Keywhan and Ike, Moses and Mackay, Sarah and Watson, Jean-Paul and Lee, Wenke}, year={2022}, month=Dec, pages={13--27}, collection={ACSAC} }
  21. ChangSeok Oh, Sangho Lee, Chenxiong Qian, Hyungjoon Koo, and Wenke Lee. DeView: Confining Progressive Web Applications by Debloating Web APIs. In Proceedings of the Annual Computer Security Applications Conference (ACSAC). 2022.
    BibTeX
    @inproceedings{oh2022deview, series={ACSAC}, title={DeView: Confining Progressive Web Applications by Debloating Web APIs}, url={http://dx.doi.org/10.1145/3564625.3567987}, DOI={10.1145/3564625.3567987}, booktitle={Proceedings of the 38th Annual Computer Security Applications Conference}, publisher={ACM}, author={Oh, ChangSeok and Lee, Sangho and Qian, Chenxiong and Koo, Hyungjoon and Lee, Wenke}, year={2022}, month=Dec, pages={881--895}, collection={ACSAC} }
  22. Feng Xiao, Zheng Yang, Joey Allen, Guangliang Yang, Grant Williams, and Wenke Lee. Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform Ecosystem. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2022.
    BibTeX
    @inproceedings{xiao2022understanding, series={CCS ’22}, title={Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform Ecosystem}, url={http://dx.doi.org/10.1145/3548606.3559340}, DOI={10.1145/3548606.3559340}, booktitle={Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Xiao, Feng and Yang, Zheng and Allen, Joey and Yang, Guangliang and Williams, Grant and Lee, Wenke}, year={2022}, month=Nov, pages={2975--2988}, collection={CCS ’22} }
  23. Carter Yagemann, Simon Chung, Brendan Saltaformaggio, and Wenke Lee. Automated Bug Hunting With Data-Driven Symbolic Root Cause Analysis. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2021.
    BibTeX
    @inproceedings{yagemann2021automated, series={CCS ’21}, title={Automated Bug Hunting With Data-Driven Symbolic Root Cause Analysis}, url={http://dx.doi.org/10.1145/3460120.3485363}, DOI={10.1145/3460120.3485363}, booktitle={Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Yagemann, Carter and Chung, Simon P. and Saltaformaggio, Brendan and Lee, Wenke}, year={2021}, month=Nov, pages={320--336}, collection={CCS ’21} }
  24. Carter Yagemann, Mohammad Noureddine, Wajih Hassan, Simon Chung, Adam Bates, and Wenke Lee. Validating the Integrity of Audit Logs Against Execution Repartitioning Attacks. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2021.
    BibTeX
    @inproceedings{yagemann2021validating, series={CCS ’21}, title={Validating the Integrity of Audit Logs Against Execution Repartitioning Attacks}, url={http://dx.doi.org/10.1145/3460120.3484551}, DOI={10.1145/3460120.3484551}, booktitle={Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Yagemann, Carter and Noureddine, Mohammad A. and Hassan, Wajih Ul and Chung, Simon and Bates, Adam and Lee, Wenke}, year={2021}, month=Nov, pages={3337--3351}, collection={CCS ’21} }
  25. Erkam Uzun, Simon P. Chung, Vladimir Kolesnikov, Alexandra Boldyreva, and Wenke Lee. Fuzzy Labeled Private Set Intersection with Applications to Private Real-Time Biometric Search. In Proceedings of the 2021 USENIX Security Symposium. 2021.
    BibTeX
    @inproceedings{uzun2021fuzzy,
      author    = {Erkam Uzun and Simon P. Chung and Vladimir Kolesnikov and Alexandra Boldyreva and Wenke Lee},
      title     = {Fuzzy Labeled Private Set Intersection with Applications to Private {Real-Time} Biometric Search},
      booktitle = {Proceedings of the 2021 USENIX Security Symposium},
      year      = {2021}
    }
  26. Evan Downing, Yisroel Mirsky, Kyuhong Park, and Wenke Lee. DeepReflect: Discovering Malicious Functionality through Binary Reconstruction. In Proceedings of the 2021 USENIX Security Symposium. 2021.
    BibTeX
    @inproceedings{downing2021deepreflect,
      author    = {Evan Downing and Yisroel Mirsky and Kyuhong Park and Wenke Lee},
      title     = {{DeepReflect}: Discovering Malicious Functionality through Binary Reconstruction},
      booktitle = {Proceedings of the 2021 USENIX Security Symposium},
      year      = {2021}
    }
  27. Carter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick, Brendan Saltaformaggio, and Wenke Lee. ARCUS: Symbolic Root Cause Analysis of Exploits in Production Systems. In Proceedings of the 2021 USENIX Security Symposium. 2021.
    BibTeX
    @inproceedings{yagemann2021arcus,
      author    = {Carter Yagemann and Matthew Pruett and Simon P. Chung and Kennon Bittick and Brendan Saltaformaggio and Wenke Lee},
      title     = {{ARCUS}: Symbolic Root Cause Analysis of Exploits in Production Systems},
      booktitle = {Proceedings of the 2021 USENIX Security Symposium},
      year      = {2021}
    }
  28. Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu, and Wenke Lee. Abusing Hidden Properties to Attack the Node.js Ecosystem. In Proceedings of the 2021 USENIX Security Symposium. 2021.
    BibTeX
    @inproceedings{xiao2021abusing,
      author    = {Feng Xiao and Jianwei Huang and Yichang Xiong and Guangliang Yang and Hong Hu and Guofei Gu and Wenke Lee},
      title     = {Abusing Hidden Properties to Attack the Node.js Ecosystem},
      booktitle = {Proceedings of the 2021 USENIX Security Symposium},
      year      = {2021}
    }
  29. Kyuhong Park, Burak Sahin, Yongheng Chen, Jisheng Zhao, Evan Downing, Hong Hu, and Wenke Lee. Identifying Behavior Dispatchers for Malware Analysis. In Proceedings of the 16th ACM ASIA Conference on Computer and Communications Security (ACM AsiaCCS 2021).
    BibTeX
    @inproceedings{park2021identifying, series={ASIA CCS ’21}, title={Identifying Behavior Dispatchers for Malware Analysis}, url={http://dx.doi.org/10.1145/3433210.3457894}, DOI={10.1145/3433210.3457894}, booktitle={Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security}, publisher={ACM}, author={Park, Kyuhong and Sahin, Burak and Chen, Yongheng and Zhao, Jisheng and Downing, Evan and Hu, Hong and Lee, Wenke}, year={2021}, month=May, pages={759--773}, collection={ASIA CCS ’21} }
  30. Erkam Uzun, Carter Yagemann, Simon P. Chung, Vladimir Kolesnikov, and Wenke Lee. Cryptographic Key Derivation from Biometric Inferences for Remote Authentication. In Proceedings of the 16th ACM ASIA Conference on Computer and Communications Security (ACM AsiaCCS 2021).
    BibTeX
    @inproceedings{uzun2021cryptographic, series={ASIA CCS ’21}, title={Cryptographic Key Derivation from Biometric Inferences for Remote Authentication}, url={http://dx.doi.org/10.1145/3433210.3437512}, DOI={10.1145/3433210.3437512}, booktitle={Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security}, publisher={ACM}, author={Uzun, Erkam and Yagemann, Carter and Chung, Simon and Kolesnikov, Vladimir and Lee, Wenke}, year={2021}, month=May, pages={629--643}, collection={ASIA CCS ’21} }
  31. Dongsong Yu, Guangliang Yang, Guozhu Meng, Xiaorui Gong, Xiu Zhang, Xiaobo Xiang, Xiaoyu Wang, Yue Jiang, Kai Chen, Wei Zou, Wenke Lee, and Wenchang Shi. SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customization. In Proceedings of The Web Conference 2021 (WWW 2021).
    BibTeX
    @inproceedings{yu2021sepal, series={WWW ’21}, title={SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customization}, url={http://dx.doi.org/10.1145/3442381.3450007}, DOI={10.1145/3442381.3450007}, booktitle={Proceedings of the Web Conference 2021}, publisher={ACM}, author={Yu, Dongsong and Yang, Guangliang and Meng, Guozhu and Gong, Xiaorui and Zhang, Xiu and Xiang, Xiaobo and Wang, Xiaoyu and Jiang, Yue and Chen, Kai and Zou, Wei and Lee, Wenke and Shi, Wenchang}, year={2021}, month=Apr, pages={2733--2744}, collection={WWW ’21} }
  32. Yongheng Chen, Rui Zhong, Hong Hu, Hangfan Zhang, Yupeng Yang, Dinghao Wu, and Wenke Lee. One Engine to Fuzz 'em All: Generic Language Processor Testing with Semantic Validation. In Proceedings of the 41st IEEE Symposium on Security and Privacy (Oakland). 2021.
    BibTeX
    @inproceedings{chen2021one, title={One Engine to Fuzz ’em All: Generic Language Processor Testing with Semantic Validation}, url={http://dx.doi.org/10.1109/sp40001.2021.00071}, DOI={10.1109/sp40001.2021.00071}, booktitle={2021 IEEE Symposium on Security and Privacy (SP)}, publisher={IEEE}, author={Chen, Yongheng and Zhong, Rui and Hu, Hong and Zhang, Hangfan and Yang, Yupeng and Wu, Dinghao and Lee, Wenke}, year={2021}, month=May, pages={642--658} }
  33. Ruian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder, Brendan Saltaformaggio, and Wenke Lee. Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages. In Proceedings of the Network and Distributed System Security Symposium (NDSS). 2021.
    BibTeX
    @inproceedings{duan2021measuring, series={NDSS 2021}, title={Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages}, url={http://dx.doi.org/10.14722/ndss.2021.23055}, DOI={10.14722/ndss.2021.23055}, booktitle={Proceedings 2021 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Duan, Ruian and Alrawi, Omar and Kasturi, Ranjita Pai and Elder, Ryan and Saltaformaggio, Brendan and Lee, Wenke}, year={2021}, collection={NDSS 2021} }
  34. Carter Yagemann, Simon P. Chung, Erkam Uzun, Sai Ragam, Brendan Saltaformaggio, and Wenke Lee. On the Feasibility of Automating Stock Market Manipulation. In Proceedings of the Annual Computer Security Applications Conference (ACSAC). 2020.
    BibTeX
    @inproceedings{yagemann2020feasibility, series={ACSAC ’20}, title={On the Feasibility of Automating Stock Market Manipulation}, url={http://dx.doi.org/10.1145/3427228.3427241}, DOI={10.1145/3427228.3427241}, booktitle={Annual Computer Security Applications Conference}, publisher={ACM}, author={Yagemann, Carter and Chung, Simon P. and Uzun, Erkam and Ragam, Sai and Saltaformaggio, Brendan and Lee, Wenke}, year={2020}, month=Dec, pages={277--290}, collection={ACSAC ’20} }
  35. Chenxiong Qian, Hyungjoon Koo, ChangSeok Oh, Taesoo Kim, and Wenke Lee. Slimium: Debloating the Chromium Browser with Feature Subsetting. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2020.
    BibTeX
    @inproceedings{qian2020slimium, series={CCS ’20}, title={Slimium: Debloating the Chromium Browser with Feature Subsetting}, url={http://dx.doi.org/10.1145/3372297.3417866}, DOI={10.1145/3372297.3417866}, booktitle={Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Qian, Chenxiong and Koo, Hyungjoon and Oh, ChangSeok and Kim, Taesoo and Lee, Wenke}, year={2020}, month=Oct, pages={461--476}, collection={CCS ’20} }
  36. Joey Allen, Zheng Yang, Matthew Landen, Raghav Bhat, Harsh Grover, Andrew Chang, Yang Ji, Roberto Perdisci, and Wenke Lee. Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation System. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2020.
    BibTeX
    @inproceedings{allen2020mnemosyne, series={CCS ’20}, title={Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation System}, url={http://dx.doi.org/10.1145/3372297.3423355}, DOI={10.1145/3372297.3423355}, booktitle={Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Allen, Joey and Yang, Zheng and Landen, Matthew and Bhat, Raghav and Grover, Harsh and Chang, Andrew and Ji, Yang and Perdisci, Roberto and Lee, Wenke}, year={2020}, month=Oct, pages={787--802}, collection={CCS ’20} }
  37. Rui Zhong, Yongheng Chen, Hong Hu, Hangfan Zhang, Wenke Lee, and Dinghao Wu. SQUIRREL: Testing Database Management Systems with Language Validity and Coverage Feedback. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2020.
    BibTeX
    @inproceedings{zhong2020squirrel, series={CCS ’20}, title={SQUIRREL: Testing Database Management Systems with Language Validity and Coverage Feedback}, url={http://dx.doi.org/10.1145/3372297.3417260}, DOI={10.1145/3372297.3417260}, booktitle={Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Zhong, Rui and Chen, Yongheng and Hu, Hong and Zhang, Hangfan and Lee, Wenke and Wu, Dinghao}, year={2020}, month=Oct, pages={955--970}, collection={CCS ’20} }
  38. Dinuka Sahabandu, Joey Allen, Shana Moothedath, Linda Bushnell, Wenke Lee, and Radha Poovendran. Quickest Detection of Advanced Persistent Threats: A Semi-Markov Game Approach. In Proceedings of the ACM/IEEE International Conference on Cyber-Physical Systems (ICCPS). 2020.
    BibTeX
    @inproceedings{sahabandu2020quickest, title={Quickest Detection of Advanced Persistent Threats: A Semi-Markov Game Approach}, url={http://dx.doi.org/10.1109/iccps48487.2020.00009}, DOI={10.1109/iccps48487.2020.00009}, booktitle={2020 ACM/IEEE 11th International Conference on Cyber-Physical Systems (ICCPS)}, publisher={IEEE}, author={Sahabandu, Dinuka and Allen, Joey and Moothedath, Shana and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2020}, month=Apr, pages={9--19} }
  39. D. Sahabandu, S. Moothedath, J. Allen, A. Clark, L. Bushnell, Wenke Lee, and R. Poovendran. Dynamic Information Flow Tracking Games for Simultaneous Detection of Multiple Attackers. In Proceedings of the IEEE Conference on Decision and Control (CDC). Nice, France, December 2019.
    BibTeX
    @inproceedings{sahabandu2019dynamic, title={Dynamic Information Flow Tracking Games for Simultaneous Detection of Multiple Attackers}, url={http://dx.doi.org/10.1109/cdc40024.2019.9029836}, DOI={10.1109/cdc40024.2019.9029836}, booktitle={2019 IEEE 58th Conference on Decision and Control (CDC)}, publisher={IEEE}, author={Sahabandu, Dinuka and Moothedath, Shana and Allen, Joey and Clark, Andrew and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2019}, month=Dec, pages={567--574} }
  40. S. Misra, S. Moothedath, H. Hosseini, J. Allen, L. Bushnell, Wenke Lee, and R. Poovendran. Learning Equilibria in Stochastic Information Flow Tracking Games with Partial Knowledge. In Proceedings of the IEEE Conference on Decision and Control (CDC). Nice, France, December 2019.
    BibTeX
    @inproceedings{misra2019learning, title={Learning Equilibria in Stochastic Information Flow Tracking Games with Partial Knowledge}, url={http://dx.doi.org/10.1109/cdc40024.2019.9029404}, DOI={10.1109/cdc40024.2019.9029404}, booktitle={2019 IEEE 58th Conference on Decision and Control (CDC)}, publisher={IEEE}, author={Misra, Shruti and Moothedath, Shana and Hosseini, Hossein and Allen, Joey and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2019}, month=Dec, pages={4053--4060} }
  41. Dinuka Sahabandu, Shana Moothedath, Joey Allen, Linda Bushnell, Wenke Lee, and Radha Poovendran. Stochastic Dynamic Information Flow Tracking Game with Reinforcement Learning. In Proceedings of the 2019 Conference on Decision and Game Theory for Security. Stockholm, Sweden, October 2019.
    BibTeX
    @inbook{sahabandu2019stochastic, title={Stochastic Dynamic Information Flow Tracking Game with Reinforcement Learning}, ISBN={9783030324308}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-030-32430-8_25}, DOI={10.1007/978-3-030-32430-8_25}, booktitle={Decision and Game Theory for Security}, publisher={Springer International Publishing}, author={Sahabandu, Dinuka and Moothedath, Shana and Allen, Joey and Bushnell, Linda and Lee, Wenke and Poovendran, Radha}, year={2019}, pages={417--438} }
  42. Chenxiong Qian, Hong Hu, Mansour Alharthi, Pak Ho Chung, Taesoo Kim, and Wenke Lee. RAZOR: A Framework for Post-deployment Software Debloating. In Proceedings of the 28th USENIX Security Symposium. Santa Clara, CA, August 2019.
    BibTeX
    @inproceedings{qian2019razor,
      author    = {Chenxiong Qian and Hong Hu and Mansour Alharthi and Pak Ho Chung and Taesoo Kim and Wenke Lee},
      title     = {{RAZOR}: A Framework for Post-deployment Software Debloating},
      booktitle = {Proceedings of the 28th USENIX Security Symposium},
      month     = {aug},
      year      = {2019}
    }
  43. Dinuka Sahabandu, Shana Moothedath, Linda Bushnell, Radha Poovendran, Joey Allen, Wenke Lee, and Andrew Clark. A Game Theoretic Approach for Dynamic Information Flow Tracking with Conditional Branching. In Proceedings of the 2019 American Control Conference (ACC). Philadelphia, PA, July 2019.
    BibTeX
    @inproceedings{sahabandu2019game, title={A Game Theoretic Approach for Dynamic Information Flow Tracking with Conditional Branching}, url={http://dx.doi.org/10.23919/acc.2019.8814596}, DOI={10.23919/acc.2019.8814596}, booktitle={2019 American Control Conference (ACC)}, publisher={IEEE}, author={Sahabandu, Dinuka and Moothedath, Shana and Bushnell, Linda and Poovendran, Radha and Aller, Joey and Lee, Wenke and Clark, Andrew}, year={2019}, month=July, pages={2289--2296} }
  44. Carter Yagemann, Salmin Sultana, Li Chen, and Wenke Lee. Barnum: Detecting Document Malware via Control Flow Anomalies in Hardware Traces. In Proceedings of the International Conference on Information Security (ISC). 2019.
    BibTeX
    @inbook{yagemann2019barnum, title={Barnum: Detecting Document Malware via Control Flow Anomalies in Hardware Traces}, ISBN={9783030302153}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-030-30215-3_17}, DOI={10.1007/978-3-030-30215-3_17}, booktitle={Information Security}, publisher={Springer International Publishing}, author={Yagemann, Carter and Sultana, Salmin and Chen, Li and Lee, Wenke}, year={2019}, pages={341--359} }
  45. Ruian Duan, Ashish Bijlani, Yang Ji, Omar Alrawi, Yiyuan Xiong, Moses Ike, Brendan Saltaformaggio, and Wenke Lee. Automating Patching of Vulnerable Open-Source Software Versions in Application Binaries. In Proceedings of the 2019 Network and Distributed System Security Symposium (NDSS). San Diego, CA, February 2019.
    BibTeX
    @inproceedings{duan2019automating, series={NDSS 2019}, title={Automating Patching of Vulnerable Open-Source Software Versions in Application Binaries}, url={http://dx.doi.org/10.14722/ndss.2019.23126}, DOI={10.14722/ndss.2019.23126}, booktitle={Proceedings 2019 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Duan, Ruian and Bijlani, Ashish and Ji, Yang and Alrawi, Omar and Xiong, Yiyuan and Ike, Moses and Saltaformaggio, Brendan and Lee, Wenke}, year={2019}, collection={NDSS 2019} }
  46. Joey Allen, Matthew Landen, Sanya Chaba, Yang Ji, Simon Pak Ho Chung, and Wenke Lee. Improving Accuracy of Android Malware Detection with Lightweight Contextual Awareness. In Proceedings of the 34th Annual Computer Security Applications Conference (ACSAC). December, 2018.
    BibTeX
    @inproceedings{allen2018improving, series={ACSAC ’18}, title={Improving Accuracy of Android Malware Detection with Lightweight Contextual Awareness}, url={http://dx.doi.org/10.1145/3274694.3274744}, DOI={10.1145/3274694.3274744}, booktitle={Proceedings of the 34th Annual Computer Security Applications Conference}, publisher={ACM}, author={Allen, Joey and Landen, Matthew and Chaba, Sanya and Ji, Yang and Chung, Simon Pak Ho and Lee, Wenke}, year={2018}, month=Dec, pages={210--221}, collection={ACSAC ’18} }
  47. Dinuka Sahabandu, Baicen Xiao, Andrew Clark, Sangho Lee, Wenke Lee, and Radha Poovendran. DIFT Games: Dynamic Information Flow Tracking Games for Advanced Persistent Threats. In Proceedings of The 57th IEEE Conference on Decision and Control (CDC). Miami Beach, FL, December 2018.
    BibTeX
    @inproceedings{sahabandu2018dift, title={DIFT Games: Dynamic Information Flow Tracking Games for Advanced Persistent Threats}, url={http://dx.doi.org/10.1109/cdc.2018.8619416}, DOI={10.1109/cdc.2018.8619416}, booktitle={2018 IEEE Conference on Decision and Control (CDC)}, publisher={IEEE}, author={Sahabandu, Dinuka and Xiao, Baicen and Clark, Andrew and Lee, Sangho and Lee, Wenke and Poovendran, Radha}, year={2018}, month=Dec, pages={1136--1143} }
  48. Shana Moothedath, Dinuka Sahabandu, Andrew Clark, Sangho Lee, Wenke Lee, and Radha Poovendran. Multi-Stage Dynamic Information Flow Tracking Game. In Proceedings of The 9th Conference on Decision and Game Theory for Security (GameSec). Seattle, WA, October 2018.
    BibTeX
    @inbook{moothedath2018multi, title={Multi-stage Dynamic Information Flow Tracking Game}, ISBN={9783030015541}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-030-01554-1_5}, DOI={10.1007/978-3-030-01554-1_5}, booktitle={Decision and Game Theory for Security}, publisher={Springer International Publishing}, author={Moothedath, Shana and Sahabandu, Dinuka and Clark, Andrew and Lee, Sangho and Lee, Wenke and Poovendran, Radha}, year={2018}, pages={80--101} }
  49. Hong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung, Bill Harris, Taesoo Kim, and Wenke Lee. Enforcing Unique Code Target Property for Control-Flow Integrity. In Proceedings of The 25th ACM Conference on Computer and Communications Security (CCS 2018). Toronto, Canada, October 2018.
    BibTeX
    @inproceedings{hu2018enforcing, series={CCS ’18}, title={Enforcing Unique Code Target Property for Control-Flow Integrity}, url={http://dx.doi.org/10.1145/3243734.3243797}, DOI={10.1145/3243734.3243797}, booktitle={Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Hu, Hong and Qian, Chenxiong and Yagemann, Carter and Chung, Simon Pak Ho and Harris, William R. and Kim, Taesoo and Lee, Wenke}, year={2018}, month=Oct, pages={1470--1486}, collection={CCS ’18} }
  50. Andrea Possemato, Andrea Lanzi, Simon Pak Ho Chung, Wenke Lee, and Yanick Fratantonio. ClickShield: Are You Hiding Something? Towards Eradicating Clickjacking on Android. In Proceedings of The 25th ACM Conference on Computer and Communications Security (CCS 2018). Toronto, Canada, October 2018.
    BibTeX
    @inproceedings{possemato2018clickshield, series={CCS ’18}, title={ClickShield: Are You Hiding Something? Towards Eradicating Clickjacking on Android}, url={http://dx.doi.org/10.1145/3243734.3243785}, DOI={10.1145/3243734.3243785}, booktitle={Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Possemato, Andrea and Lanzi, Andrea and Chung, Simon Pak Ho and Lee, Wenke and Fratantonio, Yanick}, year={2018}, month=Oct, pages={1120--1136}, collection={CCS ’18} }
  51. Yang Ji, Sangho Lee, Mattia Fazzini, Joey Allen, Evan Downing, Taesoo Kim, Alessandro Orso, and Wenke Lee. Enabling Refinable Cross-Host Attack Investigation with Efficient Data Flow Tagging and Tracking. In Proceedings of the 27th USENIX Security Symposium. Baltimore, MD, August 2018
    BibTeX
    @inproceedings{ji2018enabling,
      author    = {Yang Ji and Sangho Lee and Mattia Fazzini and Joey Allen and Evan Downing and Taesoo Kim and Alessandro Orso and Wenke Lee},
      title     = {Enabling Refinable {Cross-Host} Attack Investigation with Efficient Data Flow Tagging and Tracking},
      booktitle = {Proceedings of the 27th USENIX Security Symposium},
      month     = {aug},
      year      = {2018}
    }
  52. Wei Meng, Chenxiong Qian, Shuang Hao, Kevin Borgolte, Giovanni Vigna, and Christopher Kruegel, and Wenke Lee. Rampart: Protecting Web Applications from CPU-Exhaustion Denial-of-Service Attacks. In Proceedings of the 27th USENIX Security Symposium. Baltimore, MD, August 2018
    BibTeX
    @inproceedings{meng2018rampart,
      author    = {Wei Meng and Chenxiong Qian and Shuang Hao and Kevin Borgolte and Giovanni Vigna and Christopher Kruegel and Wenke Lee},
      title     = {Rampart: Protecting Web Applications from {CPU-Exhaustion} {Denial-of-Service} Attacks},
      booktitle = {Proceedings of the 27th USENIX Security Symposium},
      month     = {aug},
      year      = {2018}
    }
  53. Erkam Uzun, Simon Pak Ho Chung, Irfan Essa, and Wenke Lee. rtCaptcha: A Real-Time CAPTCHA Based Liveness Detection System. In Proceedings of The 2018 Network and Distributed System Security Symposium (NDSS). San Diego, CA, February 2018.
    BibTeX
    @inproceedings{uzun2018rtcaptcha, series={NDSS 2018}, title={rtCaptcha: A Real-Time CAPTCHA Based Liveness Detection System}, url={http://dx.doi.org/10.14722/ndss.2018.23253}, DOI={10.14722/ndss.2018.23253}, booktitle={Proceedings 2018 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Uzun, Erkam and Chung, Simon Pak Ho and Essa, Irfan and Lee, Wenke}, year={2018}, collection={NDSS 2018} }
  54. Antonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel, Giovanni Vigna, Simon Pak Ho Chung, and Wenke Lee. Broken Fingers: On the Usage of the Fingerprint API in Android. In Proceedings of The 2018 Network and Distributed System Security Symposium (NDSS). San Diego, CA, February 2018.
    BibTeX
    @inproceedings{bianchi2018broken, series={NDSS 2018}, title={Broken Fingers: On the Usage of the Fingerprint API in Android}, url={http://dx.doi.org/10.14722/ndss.2018.23079}, DOI={10.14722/ndss.2018.23079}, booktitle={Proceedings 2018 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Bianchi, Antonio and Fratantonio, Yanick and Machiry, Aravind and Kruegel, Christopher and Vigna, Giovanni and Chung, Simon Pak Ho and Lee, Wenke}, year={2018}, collection={NDSS 2018} }
  55. Ruian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim, and Wenke Lee. Identifying Open-Source License Violation and 1-day Security Risk at Large Scale. In Proceedings of The 24th ACM Conference on Computer and Communications Security (CCS 2017). Dallas, Texas, October 2017.
    BibTeX
    @inproceedings{duan2017identifying, series={CCS ’17}, title={Identifying Open-Source License Violation and 1-day Security Risk at Large Scale}, url={http://dx.doi.org/10.1145/3133956.3134048}, DOI={10.1145/3133956.3134048}, booktitle={Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Duan, Ruian and Bijlani, Ashish and Xu, Meng and Kim, Taesoo and Lee, Wenke}, year={2017}, month=Oct, pages={2169--2185}, collection={CCS ’17} }
  56. Yang Ji, Sangho Lee, Evan Downing, Weiren Wang, Mattia Fazzini, Taesoo Kim, Alessandro Orso, and Wenke Lee. RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow Tracking. In Proceedings of The 24th ACM Conference on Computer and Communications Security (CCS 2017). Dallas, Texas, October 2017.
    BibTeX
    @inproceedings{ji2017rain, series={CCS ’17}, title={RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow Tracking}, url={http://dx.doi.org/10.1145/3133956.3134045}, DOI={10.1145/3133956.3134045}, booktitle={Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Ji, Yang and Lee, Sangho and Downing, Evan and Wang, Weiren and Fazzini, Mattia and Kim, Taesoo and Orso, Alessandro and Lee, Wenke}, year={2017}, month=Oct, pages={377--390}, collection={CCS ’17} }
  57. Ren Ding, Chenxiong Qian, Chengyu Song, Bill Harris, Taesoo Kim, and Wenke Lee. Efficient Protection of Path-Sensitive Control Security. In Proceedings of the 26th USENIX Security Symposium. Vancouver, BC, Canada, August 2017.
    BibTeX
    @inproceedings{ding2017efficient,
      author    = {Ren Ding and Chenxiong Qian and Chengyu Song and Bill Harris and Taesoo Kim and Wenke Lee},
      title     = {Efficient Protection of {Path-Sensitive} Control Security},
      booktitle = {Proceedings of the 26th USENIX Security Symposium},
      month     = {aug},
      year      = {2017}
    }
  58. Meng Xu, Kangjie Lu, Taesoo Kim, and Wenke Lee. Bunshin: Compositing Security Mechanisms through Diversification. In Proceedings of the 2017 USENIX Annual Technical Conference. Santa Clara, CA, July 2017.
    BibTeX
    @inproceedings{xu2017bunshin,
      author    = {Meng Xu and Kangjie Lu and Taesoo Kim and Wenke Lee},
      title     = {Bunshin: Compositing Security Mechanisms through Diversification},
      booktitle = {Proceedings of the 2017 USENIX Annual Technical Conference},
      month     = {jul},
      year      = {2017}
    }
  59. Yanick Fratantonio, Chenxiong Qian, Pak Chung, and Wenke Lee. Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback Loop. In Proceedings of The 2017 IEEE Symposium on Security and Privacy. San Jose, CA, May 2017 (Distinguished Practical Paper Award).
    BibTeX
    @inproceedings{fratantonio2017cloak, title={Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback Loop}, url={http://dx.doi.org/10.1109/sp.2017.39}, DOI={10.1109/sp.2017.39}, booktitle={2017 IEEE Symposium on Security and Privacy (SP)}, publisher={IEEE}, author={Fratantonio, Yanick and Qian, Chenxiong and Chung, Simon P. and Lee, Wenke}, year={2017}, month=May, pages={1041--1057} }
  60. Kangjie Lu, Marie-Therese Walter, David Pfaff, Stefan Nuernberger, Wenke Lee, and Michael Backes. Unleashing Use-Before-Initialization Vulnerabilities in the Linux Kernel Using Targeted Stack Spraying. In Proceedings of The 2017 Network and Distributed System Security Symposium (NDSS). San Diego, CA, February 2017.
    BibTeX
    @inproceedings{lu2017unleashing, series={NDSS 2017}, title={Unleashing Use-Before-Initialization Vulnerabilities in the Linux Kernel Using Targeted Stack Spraying}, url={http://dx.doi.org/10.14722/ndss.2017.23387}, DOI={10.14722/ndss.2017.23387}, booktitle={Proceedings 2017 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Lu, Kangjie and Walter, Marie-Therese and Pfaff, David and Nuernberger, Stefan and Lee, Wenke and Backes, Michael}, year={2017}, collection={NDSS 2017} }
  61. Le Guan, Jun Xu, Shuai Wang, Xinyu Xing, Lin Lin, Heqing Huang, Peng Liu, and Wenke Lee. From Physical to Cyber: Escalating Protection for Personalized Auto Insurance. In Proceedings of The 14th ACM Conference on Embedded Networked Sensor Systems (SenSys 2016). Stanford, CA, November 2016.
    BibTeX
    @inproceedings{guan2016physical,
      author    = {Le Guan and Jun Xu and Shuai Wang and Xinyu Xing and Lin Lin and Heqing Huang and Peng Liu and Wenke Lee},
      title     = {From Physical to Cyber: Escalating Protection for Personalized Auto Insurance},
      booktitle = {Proceedings of The 14th ACM Conference on Embedded Networked Sensor Systems (SenSys 2016)},
      month     = {nov},
      year      = {2016}
    }
  62. Kangjie Lu, Chengyu Song, Taesoo Kim, and Wenke Lee. UniSan: Proactive Kernel Memory Initialization to Eliminate Data Leakages. In Proceedings of The 23rd ACM Conference on Computer and Communications Security (CCS 2016). Vienna, Austria, October 2016.
    BibTeX
    @inproceedings{lu2016unisan, series={CCS′16}, title={UniSan: Proactive Kernel Memory Initialization to Eliminate Data Leakages}, url={http://dx.doi.org/10.1145/2976749.2978366}, DOI={10.1145/2976749.2978366}, booktitle={Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Lu, Kangjie and Song, Chengyu and Kim, Taesoo and Lee, Wenke}, year={2016}, month=Oct, pages={920--932}, collection={CCS′16} }
  63. Yang Ji, Sangho Lee, and Wenke Lee. RecProv: Towards Provenance-Aware User Space Record and Replay. In Proceedings of the 6th International Provenance and Annotation Workshop (IPAW). 2016.
    BibTeX
    @inbook{ji2016recprov, title={RecProv: Towards Provenance-Aware User Space Record and Replay}, ISBN={9783319405933}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-319-40593-3_1}, DOI={10.1007/978-3-319-40593-3_1}, booktitle={Provenance and Annotation of Data and Processes}, publisher={Springer International Publishing}, author={Ji, Yang and Lee, Sangho and Lee, Wenke}, year={2016}, pages={3--15} }
  64. Yizheng Chen, Panagiotis Kintis, Manos Antonakakis, Yacin Nadji, David Dagon, Wenke Lee, and Michael Farrell. Financial Lower Bounds of Online Advertising Abuse - A Four Year Case Study of the TDSS/TDL4 Botnet. In Proceedings of The 13th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA 2016). Sebastian, Spain, July 2016.
    BibTeX
    @inbook{chen2016financial, title={Financial Lower Bounds of Online Advertising Abuse: A Four Year Case Study of the TDSS/TDL4 Botnet}, ISBN={9783319406671}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-319-40667-1_12}, DOI={10.1007/978-3-319-40667-1_12}, booktitle={Detection of Intrusions and Malware, and Vulnerability Assessment}, publisher={Springer International Publishing}, author={Chen, Yizheng and Kintis, Panagiotis and Antonakakis, Manos and Nadji, Yacin and Dagon, David and Lee, Wenke and Farrell, Michael}, year={2016}, pages={231--254} }
  65. Chengyu Song, Hyungon Moon, Monjur Alam, Insu Yun, Byoungyoung Lee, Taesoo Kim, Wenke Lee, and Yunheung Paek. HDFI: Hardware-Assisted Data-flow Isolation. In Proceedings of The 37th IEEE Symposium on Security and Privacy, San Jose, CA, May 2016. (to appear)
    BibTeX
    @inproceedings{song2016hdfi, title={HDFI: Hardware-Assisted Data-Flow Isolation}, url={http://dx.doi.org/10.1109/sp.2016.9}, DOI={10.1109/sp.2016.9}, booktitle={2016 IEEE Symposium on Security and Privacy (SP)}, publisher={IEEE}, author={Song, Chengyu and Moon, Hyungon and Alam, Monjur and Yun, Insu and Lee, Byoungyoung and Kim, Taesoo and Lee, Wenke and Paek, Yunheung}, year={2016}, month=May, pages={1--17} }
  66. Wei Meng, Byoungyoung Lee, Xinyu Xing, and Wenke Lee. TrackMeOrNot: Enabling Flexible Control on Web Tracking. In Proceedings of The 25th International World Wide Web Conference (WWW), Montreal, Canada, April 2016. (to appear)
    BibTeX
    @inproceedings{meng2016trackmeornot, series={WWW ’16}, title={TrackMeOrNot: Enabling Flexible Control on Web Tracking}, url={http://dx.doi.org/10.1145/2872427.2883034}, DOI={10.1145/2872427.2883034}, booktitle={Proceedings of the 25th International Conference on World Wide Web}, publisher={International World Wide Web Conferences Steering Committee}, author={Meng, Wei and Lee, Byoungyoung and Xing, Xinyu and Lee, Wenke}, year={2016}, month=Apr, pages={99--109}, collection={WWW ’16} }
  67. Wei Meng, Ren Ding, Simon P. Chung, Steven Han, and Wenke Lee. The Price of Free: Privacy Leakage in Personalized Mobile In-Apps Ads. In Proceedings of The 2016 Network and Distributed System Security Symposium (NDSS), San Diego, CA, February, 2016.
    BibTeX
    @inproceedings{meng2016price, series={NDSS 2016}, title={The Price of Free: Privacy Leakage in Personalized Mobile In-App Ads}, url={http://dx.doi.org/10.14722/ndss.2016.23353}, DOI={10.14722/ndss.2016.23353}, booktitle={Proceedings 2016 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Meng, Wei and Ding, Ren and Chung, Simon P. and Han, Steven and Lee, Wenke}, year={2016}, collection={NDSS 2016} }
  68. Kangjie Lu, Wenke Lee, Stefan Nurnberger, and Michael Backes. How to Make ASLR Win the Clone Wars: Runtime Re-Randomization. In Proceedings of The 2016 Network and Distributed System Security Symposium (NDSS), San Diego, CA, February, 2016.
    BibTeX
    @inproceedings{lu2016how, series={NDSS 2016}, title={How to Make ASLR Win the Clone Wars: Runtime Re-Randomization}, url={http://dx.doi.org/10.14722/ndss.2016.23173}, DOI={10.14722/ndss.2016.23173}, booktitle={Proceedings 2016 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Lu, Kangjie and Nürnberger, Stefan and Backes, Michael and Lee, Wenke}, year={2016}, collection={NDSS 2016} }
  69. Chengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris, Taesoo Kim and Wenke Lee. Enforcing Kernel Security Invariants with Data Flow Integrity. In Proceedings of The 2016 Network and Distributed System Security Symposium (NDSS), San Diego, CA, February, 2016.
    BibTeX
    @inproceedings{song2016enforcing, series={NDSS 2016}, title={Enforcing Kernel Security Invariants with Data Flow Integrity}, url={http://dx.doi.org/10.14722/ndss.2016.23218}, DOI={10.14722/ndss.2016.23218}, booktitle={Proceedings 2016 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Song, Chengyu and Lee, Byoungyoung and Lu, Kangjie and Harris, William and Kim, Taesoo and Lee, Wenke}, year={2016}, collection={NDSS 2016} }
  70. Meng Xu, Yeongjin Jang, Xinyu Xing, Taesoo Kim, and Wenke Lee. UCognito: Private Browsing without Tears. In Proceedings of The 22nd ACM Conference on Computer and Communications Security (CCS), Denver, CO, October 2015.
    BibTeX
    @inproceedings{xu2015ucognito, series={CCS′15}, title={UCognito: Private Browsing without Tears}, url={http://dx.doi.org/10.1145/2810103.2813716}, DOI={10.1145/2810103.2813716}, booktitle={Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Xu, Meng and Jang, Yeongjin and Xing, Xinyu and Kim, Taesoo and Lee, Wenke}, year={2015}, month=Oct, pages={438--449}, collection={CCS′15} }
  71. Kangjie Lu, Chengyu Song, Byoungyoung Lee, Simon P. Chung, Taesoo Kim, and Wenke Lee. ASLR-Guard: Stopping Address Space Leakage for Code Reuse Attacks. In Proceedings of The 22nd ACM Conference on Computer and Communications Security (CCS), Denver, CO, October 2015.
    BibTeX
    @inproceedings{lu2015aslr, series={CCS′15}, title={ASLR-Guard: Stopping Address Space Leakage for Code Reuse Attacks}, url={http://dx.doi.org/10.1145/2810103.2813694}, DOI={10.1145/2810103.2813694}, booktitle={Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Lu, Kangjie and Song, Chengyu and Lee, Byoungyoung and Chung, Simon P. and Kim, Taesoo and Lee, Wenke}, year={2015}, month=Oct, pages={280--291}, collection={CCS′15} }
  72. Byoungyoung Lee, Chengyu Song, Taesoo Kim, and Wenke Lee. Type Casting Verification: Stopping an Emerging Attack Vector. In Proceedings of The 24th USENIX Security Symposium, Washington, D.C., August 2015. (Awarded the Internet Defense Prize by Facebook and USENIX)
    BibTeX
    @inproceedings{lee2015type,
      author    = {Byoungyoung Lee and Chengyu Song and Taesoo Kim and Wenke Lee},
      title     = {Type Casting Verification: Stopping an Emerging Attack Vector},
      booktitle = {Proceedings of The 24th USENIX Security Symposium},
      month     = {aug},
      year      = {2015}
    }
  73. Xinyu Xing, Wei Meng, Byoungyoung Lee, Udi Weinsberg, Anmol Sheth, Roberto Perdisci, and Wenke Lee. Understanding Malvertising Through Ad-Injecting Browser Extensions. In Proceedings of The 24th International World Wide Web Conference (WWW), Florence, Italy, May 2015.
    BibTeX
    @inproceedings{xing2015understanding, series={WWW ’15}, title={Understanding Malvertising Through Ad-Injecting Browser Extensions}, url={http://dx.doi.org/10.1145/2736277.2741630}, DOI={10.1145/2736277.2741630}, booktitle={Proceedings of the 24th International Conference on World Wide Web}, publisher={International World Wide Web Conferences Steering Committee}, author={Xing, Xinyu and Meng, Wei and Lee, Byoungyoung and Weinsberg, Udi and Sheth, Anmol and Perdisci, Roberto and Lee, Wenke}, year={2015}, month=May, pages={1286--1295}, collection={WWW ’15} }
  74. Chengyu Song, Chao Zhang, Tielei Wang, Wenke Lee, and David Melski. Exploiting and Protecting Dynamic Code Generation. In Proceedings of The 2015 Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2015.
    BibTeX
    @inproceedings{song2015exploiting, series={NDSS 2015}, title={Exploiting and Protecting Dynamic Code Generation}, url={http://dx.doi.org/10.14722/ndss.2015.23233}, DOI={10.14722/ndss.2015.23233}, booktitle={Proceedings 2015 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Song, Chengyu and Zhang, Chao and Wang, Tielei and Lee, Wenke and Melski, David}, year={2015}, collection={NDSS 2015} }
  75. Byoungyoung Lee, Chengyu Song, Yeongjin Jang, Tielei Wang, Taesoo Kim, Long Lu, and Wenke Lee. Preventing Use-after-free with Dangling Pointers Nullification. In Proceedings of The 2015 Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2015.
    BibTeX
    @inproceedings{lee2015preventing, series={NDSS 2015}, title={Preventing Use-after-free with Dangling Pointers Nullification}, url={http://dx.doi.org/10.14722/ndss.2015.23238}, DOI={10.14722/ndss.2015.23238}, booktitle={Proceedings 2015 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Lee, Byoungyoung and Song, Chengyu and Jang, Yeongjin and Wang, Tielei and Kim, Taesoo and Lu, Long and Lee, Wenke}, year={2015}, collection={NDSS 2015} }
  76. Kangjie Lu, Zhichun Li, Vasileios P. Kemerlis, Zhenyu Wu, Long Lu, Cong Zheng, Zhiyun Qian, Wenke Lee, and Guofei Jiang. Checking More and Alerting Less: Detecting Privacy Leakages via Enhanced Data-flow Analysis and Peer Voting. In Proceedings of The 2015 Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2015.
    BibTeX
    @inproceedings{lu2015checking, series={NDSS 2015}, title={Checking More and Alerting Less: Detecting Privacy Leakages via Enhanced Data-flow Analysis and Peer Voting}, url={http://dx.doi.org/10.14722/ndss.2015.23287}, DOI={10.14722/ndss.2015.23287}, booktitle={Proceedings 2015 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Lu, Kangjie and Li, Zhichun and Kemerlis, Vasileios P. and Wu, Zhenyu and Lu, Long and Zheng, Cong and Qian, Zhiyun and Lee, Wenke and Jiang, Guofei}, year={2015}, collection={NDSS 2015} }
  77. Yeongjin Jang, Chengyu Song, Simon P. Chung, Tielei Wang, and Wenke Lee. A11y Attacks: Exploiting Accessibility in Operating Systems. In Proceedings of The 21st ACM Conference on Computer and Communications Security (CCS), Scottsdale, Arizona, November 2014.
    BibTeX
    @inproceedings{jang2014y, series={CCS′14}, title={A11y Attacks: Exploiting Accessibility in Operating Systems}, url={http://dx.doi.org/10.1145/2660267.2660295}, DOI={10.1145/2660267.2660295}, booktitle={Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Jang, Yeongjin and Song, Chengyu and Chung, Simon P. and Wang, Tielei and Lee, Wenke}, year={2014}, month=Nov, pages={103--115}, collection={CCS′14} }
  78. Wei Meng, Xinyu Xing, Anmol Sheth, Udi Weinsberg, and Wenke Lee. Your Online Interests - Pwned! A Pollution Attack Against Targeted Advertising. In Proceedings of The 21st ACM Conference on Computer and Communications Security (CCS), Scottsdale, Arizona, November 2014.
    BibTeX
    @inproceedings{meng2014your, series={CCS′14}, title={Your Online Interests: Pwned! A Pollution Attack Against Targeted Advertising}, url={http://dx.doi.org/10.1145/2660267.2687258}, DOI={10.1145/2660267.2687258}, booktitle={Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Meng, Wei and Xing, Xinyu and Sheth, Anmol and Weinsberg, Udi and Lee, Wenke}, year={2014}, month=Nov, pages={129--140}, collection={CCS′14} }
  79. Billy Lau, Pak Ho Chung, Chengyu Song, Yeongjin Jang, Wenke Lee, and Alexandra Boldyreva. Mimesis Aegis: A Mimicry Privacy Shield - A System's Approach to Data Privacy on Public Cloud. In Proceedings of The 23rd USENIX Security Symposium, San Diego, CA, August 2014.
    BibTeX
    @inproceedings{lau2014mimesis,
      author    = {Billy Lau and Pak Ho Chung and Chengyu Song and Yeongjin Jang and Wenke Lee and Alexandra Boldyreva},
      title     = {Mimesis Aegis: A Mimicry Privacy Shield - A System's Approach to Data Privacy on Public Cloud},
      booktitle = {Proceedings of The 23rd USENIX Security Symposium},
      month     = {aug},
      year      = {2014}
    }
  80. Tielei Wang, Yeongjin Jang, Yizheng Chen, Pak Ho Chung, Billy Lau, and Wenke Lee. On the Feasibility of Large-Scale Infections of iOS Devices. In Proceedings of The 23rd USENIX Security Symposium, San Diego, CA, August 2014.
    BibTeX
    @inproceedings{wang2014feasibility,
      author    = {Tielei Wang and Yeongjin Jang and Yizheng Chen and Pak Ho Chung and Billy Lau and Wenke Lee},
      title     = {On the Feasibility of {Large-Scale} Infections of {iOS} Devices},
      booktitle = {Proceedings of The 23rd USENIX Security Symposium},
      month     = {aug},
      year      = {2014}
    }
  81. Tielei Wang, Chengyu Song, and Wenke Lee. Diagnosis and Emergency Patch Generation for Integer Overflow Exploits. In Proceedings of The 11th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA 2014), Egham, UK, July 2014.
    BibTeX
    @inbook{wang2014diagnosis, title={Diagnosis and Emergency Patch Generation for Integer Overflow Exploits}, ISBN={9783319085098}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-319-08509-8_14}, DOI={10.1007/978-3-319-08509-8_14}, booktitle={Detection of Intrusions and Malware, and Vulnerability Assessment}, publisher={Springer International Publishing}, author={Wang, Tielei and Song, Chengyu and Lee, Wenke}, year={2014}, pages={255--275} }
  82. Yizheng Chen, Manos Antonakakis, Roberto Perdisci, Yacin Nadji, David Dagon, and Wenke Lee. DNS Noise: Measuring the Pervasiveness of Disposable Domains in Modern DNS Traffic. In Proceedings of The 44th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2014), Atlanta, GA, June 2014.
    BibTeX
    @inproceedings{chen2014dns, title={DNS Noise: Measuring the Pervasiveness of Disposable Domains in Modern DNS Traffic}, url={http://dx.doi.org/10.1109/dsn.2014.61}, DOI={10.1109/dsn.2014.61}, booktitle={2014 44th Annual IEEE/IFIP International Conference on Dependable Systems and Networks}, publisher={IEEE}, author={Chen, Yizheng and Antonakakis, Manos and Perdisci, Roberto and Nadji, Yacin and Dagon, David and Lee, Wenke}, year={2014}, month=June, pages={598--609} }
  83. Byoungyoung Lee, Long Lu, Tielei Wang, Taesoo Kim, and Wenke Lee. From Zygote to Morula: Fortifying Weakened ASLR on Android. In Proceedings of The 2014 IEEE Symposium on Security and Privacy, San Jose, CA, May 2014.
    BibTeX
    @inproceedings{lee2014zygote, title={From Zygote to Morula: Fortifying Weakened ASLR on Android}, url={http://dx.doi.org/10.1109/sp.2014.34}, DOI={10.1109/sp.2014.34}, booktitle={2014 IEEE Symposium on Security and Privacy}, publisher={IEEE}, author={Lee, Byoungyoung and Lu, Long and Wang, Tielei and Kim, Taesoo and Lee, Wenke}, year={2014}, month=May, pages={424--439} }
  84. Xinyu Xing, Wei Meng, Dan Doozan, Nick Feamster, Wenke Lee, and Alex C. Snoeren. Exposing Inconsistent Web Search Results with Bobble. In Proceedings of The 2014 Passive and Active Measurement Conference (PAM), Los Angeles, CA, March 2014.
    BibTeX
    @inbook{xing2014exposing, title={Exposing Inconsistent Web Search Results with Bobble}, ISBN={9783319049182}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-319-04918-2_13}, DOI={10.1007/978-3-319-04918-2_13}, booktitle={Passive and Active Measurement}, publisher={Springer International Publishing}, author={Xing, Xinyu and Meng, Wei and Doozan, Dan and Feamster, Nick and Lee, Wenke and Snoeren, Alex C.}, year={2014}, pages={131--140} }
  85. Yeongjin Jang, Simon P. Chung, Bryan D. Payne, and Wenke Lee. Gyrus: A Framework for User-Intent Monitoring of Text-Based Networked Applications. In Proceedings of The 21st Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2014.
    BibTeX
    @inproceedings{jang2014gyrus, series={NDSS 2014}, title={Gyrus: A Framework for User-Intent Monitoring of Text-Based Networked Applications}, url={http://dx.doi.org/10.14722/ndss.2014.23076}, DOI={10.14722/ndss.2014.23076}, booktitle={Proceedings 2014 Network and Distributed System Security Symposium}, publisher={Internet Society}, author={Jang, Yeongjin and Chung, Simon P. and Payne, Bryan D. and Lee, Wenke}, year={2014}, collection={NDSS 2014} }
  86. Yacin Nadji, Manos Antonakakis, Roberto Perdisci, David Dagon, and Wenke Lee. Beheading Hydras: Performing Effective Botnet Takedowns. In Proceedings of the 20th ACM Conference on Computer and Communications Security (CCS), Berlin, Germany, November 2013.
    BibTeX
    @inproceedings{nadji2013beheading, series={CCS ’13}, title={Beheading hydras: performing effective botnet takedowns}, url={http://dx.doi.org/10.1145/2508859.2516749}, DOI={10.1145/2508859.2516749}, booktitle={Proceedings of the 2013 ACM SIGSAC conference on Computer \& communications security - CCS ’13}, publisher={ACM Press}, author={Nadji, Yacin and Antonakakis, Manos and Perdisci, Roberto and Dagon, David and Lee, Wenke}, year={2013}, pages={121--132}, collection={CCS ’13} }
  87. Brendan Dolan-Gavitt, Tim Leek, Josh Hodosh, and Wenke Lee. Tappan Zee (North) Bridge: Mining Memory Accesses for Introspection. In Proceedings of the 20th ACM Conference on Computer and Communications Security (CCS), Berlin, Germany, November 2013.
    BibTeX
    @inproceedings{dolangavitt2013tappan, series={CCS ’13}, title={Tappan Zee (north) bridge: mining memory accesses for introspection}, url={http://dx.doi.org/10.1145/2508859.2516697}, DOI={10.1145/2508859.2516697}, booktitle={Proceedings of the 2013 ACM SIGSAC conference on Computer \& communications security - CCS ’13}, publisher={ACM Press}, author={Dolan-Gavitt, Brendan and Leek, Tim and Hodosh, Josh and Lee, Wenke}, year={2013}, pages={839--850}, collection={CCS ’13} }
  88. Yacin Nadji, Manos Antonakakis, Roberto Perdisci, and Wenke Lee. Connected Colors: Unveiling the Structure of Criminal Networks. In Proceedings of the 16th International Symposium on Research in Attacks, Intrusions and Defenses (RAID), St. Lucia, October 2013.
    BibTeX
    @inbook{nadji2013connected, title={Connected Colors: Unveiling the Structure of Criminal Networks}, ISBN={9783642412844}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-642-41284-4_20}, DOI={10.1007/978-3-642-41284-4_20}, booktitle={Research in Attacks, Intrusions, and Defenses}, publisher={Springer Berlin Heidelberg}, author={Nadji, Yacin and Antonakakis, Manos and Perdisci, Roberto and Lee, Wenke}, year={2013}, pages={390--410} }
  89. Xinyu Xing, Wei Meng, Dan Doozan, Alex C. Snoeren, Nick Feamster, and Wenke Lee. Take this Personally: Pollution Attacks on Personalized Services. In Proceedings of the 22nd USENIX Security Symposium, Washington, D.C., August 2013.
    BibTeX
    @inproceedings{xing2013take,
      author    = {Xinyu Xing and Wei Meng and Dan Doozan and Alex C. Snoeren and Nick Feamster and Wenke Lee},
      title     = {Take this Personally: Pollution Attacks on Personalized Services},
      booktitle = {Proceedings of the 22nd USENIX Security Symposium},
      month     = {aug},
      year      = {2013}
    }
  90. Tielei Wang, Kangjie Lu, Long Lu, Simon Chung, and Wenke Lee. Jekyll on iOS: When Benign Apps Become Evil. In Proceedings of the 22nd USENIX Security Symposium, Washington, D.C., August 2013.
    BibTeX
    @inproceedings{wang2013jekyll,
      author    = {Tielei Wang and Kangjie Lu and Long Lu and Simon Chung and Wenke Lee},
      title     = {Jekyll on {iOS}: When Benign Apps Become Evil},
      booktitle = {Proceedings of the 22nd USENIX Security Symposium},
      month     = {aug},
      year      = {2013}
    }
  91. Junjie Zhang, Yinglian Xie, Fang Yu, David Soukal, and Wenke Lee. Intention and Origination: An Inside Look at Large-Scale Bot Queries. In Proceedings of The 20th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2013.
    BibTeX
    @inproceedings{zhang2013intention,
      author    = {Junjie Zhang and Yinglian Xie and Fang Yu and David Soukal and Wenke Lee},
      title     = {Intention and Origination: An Inside Look at {Large-Scale} Bot Queries},
      booktitle = {Proceedings of The 20th Annual Network and Distributed System Security Symposium (NDSS)},
      month     = {feb},
      year      = {2013}
    }
  92. Charles Lever, Manos Antonakakis, Bradley Reaves, Patrick Traynor and Wenke Lee. The Core of the Matter: Analyzing Malicious Traffic in Cellular Carriers. In Proceedings of The 20th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2013.
    BibTeX
    @inproceedings{lever2013core,
      author    = {Charles Lever and Manos Antonakakis and Bradley Reaves and Patrick Traynor and Wenke Lee},
      title     = {The Core of the Matter: Analyzing Malicious Traffic in Cellular Carriers},
      booktitle = {Proceedings of The 20th Annual Network and Distributed System Security Symposium (NDSS)},
      month     = {feb},
      year      = {2013}
    }
  93. Long Lu, Zhichun Li, Zhenyu Wu, Wenke Lee, and Guofei Jiang. CHEX: Statically Vetting Android Apps for Component Hijacking Vulnerabilities. In Proceedings of The 19th ACM Conference on Computer and Communications Security (CCS), Raleigh, NC. October 2012.
    BibTeX
    @inproceedings{lu2012chex, series={CCS′12}, title={CHEX: statically vetting Android apps for component hijacking vulnerabilities}, url={http://dx.doi.org/10.1145/2382196.2382223}, DOI={10.1145/2382196.2382223}, booktitle={Proceedings of the 2012 ACM conference on Computer and communications security}, publisher={ACM}, author={Lu, Long and Li, Zhichun and Wu, Zhenyu and Lee, Wenke and Jiang, Guofei}, year={2012}, month=Oct, pages={229--240}, collection={CCS′12} }
  94. Martim Carbone, Matthew Conover, Bruce Montague, and Wenke Lee. Secure and Robust Monitoring of Virtual Machines through Guest-Assisted Introspection. In Proceedings of The 15th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID). Amsterdam, The Netherlands. September, 2012.
    BibTeX
    @inbook{carbone2012secure, title={Secure and Robust Monitoring of Virtual Machines through Guest-Assisted Introspection}, ISBN={9783642333385}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-642-33338-5_2}, DOI={10.1007/978-3-642-33338-5_2}, booktitle={Research in Attacks, Intrusions, and Defenses}, publisher={Springer Berlin Heidelberg}, author={Carbone, Martim and Conover, Matthew and Montague, Bruce and Lee, Wenke}, year={2012}, pages={22--41} }
  95. Manos Antonakakis, Roberto Perdisci, Yacin Nadji, Nikolaos Vasiloglou, Saeed Abu-Nimeh, Wenke Lee, and David Dagon. From Throw-Away Traffic to Bots: Detecting the Rise of DGA-Based Malware. In Proceedings of The 21st USENIX Security Symposium. Bellevue, WA. August 2012.
    BibTeX
    @inproceedings{antonakakis2012throw,
      author    = {Manos Antonakakis and Roberto Perdisci and Yacin Nadji and Nikolaos Vasiloglou and Saeed Abu-Nimeh and Wenke Lee and David Dagon},
      title     = {From {Throw-Away} Traffic to Bots: Detecting the Rise of {DGA-Based} Malware},
      booktitle = {Proceedings of The 21st USENIX Security Symposium},
      month     = {aug},
      year      = {2012}
    }
  96. Kapil Singh, Helen Wang, Alexander Moshchuk, Collin Jackson, and Wenke Lee. Practical End-to-End Web Content Integrity. In Proceedings of The 21st International World Wide Web Conference (WWW), Lyon, France, April 2012.
    BibTeX
    @inproceedings{singh2012practical, series={WWW 2012}, title={Practical end-to-end web content integrity}, url={http://dx.doi.org/10.1145/2187836.2187926}, DOI={10.1145/2187836.2187926}, booktitle={Proceedings of the 21st international conference on World Wide Web}, publisher={ACM}, author={Singh, Kapil and Wang, Helen J. and Moshchuk, Alexander and Jackson, Collin and Lee, Wenke}, year={2012}, month=Apr, pages={659--668}, collection={WWW 2012} }
  97. Xiapu Luo, Peng Zhou, Junjie Zhang, Roberto Perdisci, Wenke Lee, and Rocky K.C. Chang. Exposing Invisible Timing-Based Traffic Watermarks with BACKLIT. In Proceedings of The 27th Annual Computer Security Applications Conference (ACSAC 2011), Orlando, FL, December 2011.
    BibTeX
    @inproceedings{luo2011exposing, series={ACSAC ’11}, title={Exposing invisible timing-based traffic watermarks with BACKLIT}, url={http://dx.doi.org/10.1145/2076732.2076760}, DOI={10.1145/2076732.2076760}, booktitle={Proceedings of the 27th Annual Computer Security Applications Conference}, publisher={ACM}, author={Luo, Xiapu and Zhou, Peng and Zhang, Junjie and Perdisci, Roberto and Lee, Wenke and Chang, Rocky K. C.}, year={2011}, month=Dec, pages={197--206}, collection={ACSAC ’11} }
  98. Yacin Nadji, Manos Antonakakis, Roberto Perdisci, and Wenke Lee. Understanding the Prevalence and Use of Alternative Plans in Malware with Network Games. In Proceedings of The 27th Annual Computer Security Applications Conference (ACSAC 2011), Orlando, FL, December 2011.
    BibTeX
    @inproceedings{nadji2011understanding, series={ACSAC ’11}, title={Understanding the prevalence and use of alternative plans in malware with network games}, url={http://dx.doi.org/10.1145/2076732.2076734}, DOI={10.1145/2076732.2076734}, booktitle={Proceedings of the 27th Annual Computer Security Applications Conference}, publisher={ACM}, author={Nadji, Yacin and Antonakakis, Manos and Perdisci, Roberto and Lee, Wenke}, year={2011}, month=Dec, pages={1--10}, collection={ACSAC ’11} }
  99. Long Lu, Roberto Perdisci, and Wenke Lee. SURF: Detecting and Measuring Search Poisoning. In Proceedings of The 18th ACM Conference on Computer and Communications Security (CCS). Chicago, IL, October 2011.
    BibTeX
    @inproceedings{lu2011surf, series={CCS′11}, title={SURF: detecting and measuring search poisoning}, url={http://dx.doi.org/10.1145/2046707.2046762}, DOI={10.1145/2046707.2046762}, booktitle={Proceedings of the 18th ACM conference on Computer and communications security}, publisher={ACM}, author={Lu, Long and Perdisci, Roberto and Lee, Wenke}, year={2011}, month=Oct, pages={467--476}, collection={CCS′11} }
  100. Manos Antonakakis, Roberto Perdisci, Wenke Lee, Nikolaos Vasiloglou II, and David Dagon. Detecting Malware Domains at the Upper DNS Hierarchy. In Proceedings of The 20th USENIX Security Symposium. San Francisco, August 2011.
    BibTeX
    @inproceedings{antonakakis2011detecting,
      author    = {Manos Antonakakis and Roberto Perdisci and Wenke Lee and Nikolaos Vasiloglou II and David Dagon},
      title     = {Detecting Malware Domains at the Upper {DNS} Hierarchy},
      booktitle = {Proceedings of The 20th USENIX Security Symposium},
      month     = {aug},
      year      = {2011}
    }
  101. Xiapu Luo, Peng Zhou, Edmond W. W. Chan, Rocky K. C. Chang, and Wenke Lee. A Combinatorial Approach to Network Covert Communications with Applications in Web Leaks. In Proceedings of The 41st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). Hong Kong, China, June 2011.
    BibTeX
    @inproceedings{luo2011combinatorial, title={A combinatorial approach to network covert communications with applications in Web Leaks}, url={http://dx.doi.org/10.1109/dsn.2011.5958260}, DOI={10.1109/dsn.2011.5958260}, booktitle={2011 IEEE/IFIP 41st International Conference on Dependable Systems \& Networks (DSN)}, publisher={IEEE}, author={Luo, Xiapu and Zhou, Peng and Chan, Edmond W. W. and Chang, Rocky K. C. and Lee, Wenke}, year={2011}, month=June, pages={474--485} }
  102. Junjie Zhang, Roberto Perdisci, Wenke Lee, Unum Sarfraz, and Xiapu Luo. Detecting Stealthy P2P Botnets Using Statistical Traffic Fingerprints. In Proceedings of The 41st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). Hong Kong, China, June 2011.
    BibTeX
    @inproceedings{zhang2011detecting, title={Detecting stealthy P2P botnets using statistical traffic fingerprints}, url={http://dx.doi.org/10.1109/dsn.2011.5958212}, DOI={10.1109/dsn.2011.5958212}, booktitle={2011 IEEE/IFIP 41st International Conference on Dependable Systems \& Networks (DSN)}, publisher={IEEE}, author={Zhang, Junjie and Perdisci, Roberto and Lee, Wenke and Sarfraz, Unum and Luo, Xiapu}, year={2011}, month=June, pages={121--132} }
  103. Brendan Dolan-Gavitt, Tim Leek, Michael Zhivich, Jonathon Giffin, and Wenke Lee. Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection. In Proceedings of The 2011 IEEE Symposium on Security and Privacy. Oakland, CA, May 2011.
    BibTeX
    @inproceedings{dolangavitt2011virtuoso, title={Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection}, url={http://dx.doi.org/10.1109/sp.2011.11}, DOI={10.1109/sp.2011.11}, booktitle={2011 IEEE Symposium on Security and Privacy}, publisher={IEEE}, author={Dolan-Gavitt, Brendan and Leek, Tim and Zhivich, Michael and Giffin, Jonathon and Lee, Wenke}, year={2011}, month=May, pages={297--312} }
  104. Junjie Zhang, Jay Stokes, Christian Seifert, and Wenke Lee. ARROW: Generating Signatures to Detect Drive-By Downloads. In Proceedings of The 20th International World Wide Web Conference (WWW), Hyderabad, India, March 2011.
    BibTeX
    @inproceedings{zhang2011arrow, series={WWW ’11}, title={ARROW: GenerAting SignatuRes to Detect DRive-By DOWnloads}, url={http://dx.doi.org/10.1145/1963405.1963435}, DOI={10.1145/1963405.1963435}, booktitle={Proceedings of the 20th international conference on World wide web}, publisher={ACM}, author={Zhang, Junjie and Seifert, Christian and Stokes, Jack W. and Lee, Wenke}, year={2011}, month=Mar, pages={187--196}, collection={WWW ’11} }
  105. Junjie Zhang, Xiapu Luo, Roberto Perdisci, Guofei Gu, Wenke Lee, and Nick Feamster. Boosting the Scalability of Botnet Detection Using Adaptive Traffic Sampling. In Proceedings of The 6th ACM Symposium on Information, Computer and Communications Security (ASIACCS), Hong Kong, March 2011.
    BibTeX
    @inproceedings{zhang2011boosting, series={ASIA CCS ’11}, title={Boosting the scalability of botnet detection using adaptive traffic sampling}, url={http://dx.doi.org/10.1145/1966913.1966930}, DOI={10.1145/1966913.1966930}, booktitle={Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security}, publisher={ACM}, author={Zhang, Junjie and Luo, Xiapu and Perdisci, Roberto and Gu, Guofei and Lee, Wenke and Feamster, Nick}, year={2011}, month=Mar, pages={124--134}, collection={ASIA CCS ’11} }
  106. Xiapu Luo, Peng Zhou, Edmond W.W. Chan, Wenke Lee, Rocky K. C. Chang, and Roberto Perdisci. HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows. In Proceedings of The 18th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2011.
    BibTeX
    @inproceedings{luo2011httpos,
      author    = {Xiapu Luo and Peng Zhou and Edmond W.W. Chan and Wenke Lee and Rocky K. C. Chang and Roberto Perdisci},
      title     = {{HTTPOS}: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows},
      booktitle = {Proceedings of The 18th Annual Network and Distributed System Security Symposium (NDSS)},
      month     = {feb},
      year      = {2011}
    }
  107. Qing Hui, Xiapu Luo, and Wenke Lee. Control of Low-Rate Denial-of-Service Attacks on Web Servers and TCP Flows. In Proceedings of The 49th IEEE Conference on Decision and Control (CDC), Atlanta, GA, December 2010.
    BibTeX
    @inproceedings{hui2010control, title={Control of low-rate denial-of-service attacks on web servers and TCP flows}, url={http://dx.doi.org/10.1109/cdc.2010.5717825}, DOI={10.1109/cdc.2010.5717825}, booktitle={49th IEEE Conference on Decision and Control (CDC)}, publisher={IEEE}, author={Hui, Qing and Luo, Xiapu and Lee, Wenke}, year={2010}, month=Dec, pages={4186--4191} }
  108. Xiapu Luo, Junjie Zhang, Roberto Perdisci, and Wenke Lee. On the Secrecy of Spread-Spectrum Flow Watermarks. In Proceedings of The 15th European Symposium on Research in Computer Security (ESORICS), Athens, Greece, September 2010.
    BibTeX
    @inbook{luo2010secrecy, title={On the Secrecy of Spread-Spectrum Flow Watermarks}, ISBN={9783642154973}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-642-15497-3_15}, DOI={10.1007/978-3-642-15497-3_15}, booktitle={Computer Security – ESORICS 2010}, publisher={Springer Berlin Heidelberg}, author={Luo, Xiapu and Zhang, Junjie and Perdisci, Roberto and Lee, Wenke}, year={2010}, pages={232--248} }
  109. Manos Antonakakis, David Dagon, Xiapu Luo, Roberto Perdisci, and Wenke Lee. A Centralized Monitoring Infrastructure for Improving DNS Security. In Proceedings of The 13th International Symposium on Recent Advances in Intrusion Detection (RAID), Ottawa, Ontario, Canada, September 2010.
    BibTeX
    @inbook{antonakakis2010centralized, title={A Centralized Monitoring Infrastructure for Improving DNS Security}, ISBN={9783642155123}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-642-15512-3_2}, DOI={10.1007/978-3-642-15512-3_2}, booktitle={Recent Advances in Intrusion Detection}, publisher={Springer Berlin Heidelberg}, author={Antonakakis, Manos and Dagon, David and Luo, Xiapu and Perdisci, Roberto and Lee, Wenke and Bellmor, Justin}, year={2010}, pages={18--37} }
  110. Long Lu, Vinod Yegneswaran, Phil Porras, and Wenke Lee. BLADE: An Attack-Agnostic Approach for Preventing Drive-By Malware Infections. In Proceedings of The 17th ACM Conference on Computer and Communications Security (CCS), Chicago, IL, October 2010.
    BibTeX
    @inproceedings{lu2010blade, series={CCS ’10}, title={BLADE: an attack-agnostic approach for preventing drive-by malware infections}, url={http://dx.doi.org/10.1145/1866307.1866356}, DOI={10.1145/1866307.1866356}, booktitle={Proceedings of the 17th ACM conference on Computer and communications security}, publisher={ACM}, author={Lu, Long and Yegneswaran, Vinod and Porras, Phillip and Lee, Wenke}, year={2010}, month=Oct, pages={440--450}, collection={CCS ’10} }
  111. Manos Antonakakis, Roberto Perdisci, David Dagon, Wenke Lee, and Nick Feamster. Building a Dynamic Reputation System for DNS. In Proceedings of The 19th USENIX Security Symposium, Washington, DC, August 2010.
    BibTeX
    @inproceedings{antonakakis2010building,
      author    = {Manos Antonakakis and Roberto Perdisci and David Dagon and Wenke Lee and Nick Feamster},
      title     = {Building a Dynamic Reputation System for {DNS}},
      booktitle = {Proceedings of The 19th USENIX Security Symposium},
      month     = {aug},
      year      = {2010}
    }
  112. Kapil Singh, Samrit Sangal, Nehil Jain, Patrick Traynor, and Wenke Lee. Evaluating Bluetooth as a Medium for Botnet Command and Control. In Proceedings of The 7th Conference on Detection of Intrusions and Malware Vulnerability Assessment (DIMVA), Bonn, Germany, July 2010.
    BibTeX
    @inbook{singh2010evaluating, title={Evaluating Bluetooth as a Medium for Botnet Command and Control}, ISBN={9783642142154}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-642-14215-4_4}, DOI={10.1007/978-3-642-14215-4_4}, booktitle={Detection of Intrusions and Malware, and Vulnerability Assessment}, publisher={Springer Berlin Heidelberg}, author={Singh, Kapil and Sangal, Samrit and Jain, Nehil and Traynor, Patrick and Lee, Wenke}, year={2010}, pages={61--80} }
  113. Kapil Singh, Alexander Moshchuk, Helen J. Wang, and Wenke Lee. On the Incoherencies in Web Browser Access Control Policies. In Proceedings of The 2010 IEEE Symposium on Security and Privacy, Oakland, CA, May 2010.
    BibTeX
    @inproceedings{singh2010incoherencies, title={On the Incoherencies in Web Browser Access Control Policies}, url={http://dx.doi.org/10.1109/sp.2010.35}, DOI={10.1109/sp.2010.35}, booktitle={2010 IEEE Symposium on Security and Privacy}, publisher={IEEE}, author={Singh, Kapil and Moshchuk, Alexander and Wang, Helen J. and Lee, Wenke}, year={2010}, pages={463--478} }
  114. Roberto Perdisci, Wenke Lee, and Nick Feamster. Behavioral Clustering of HTTP-based Malware and Signature Generation using Malicious Network Traces. In Proceedings of The 7th USENIX Symposium on Networked Systems Design and Implementation (NSDI), San Jose, CA, April 2010.
    BibTeX
    @inproceedings{perdisci2010behavioral,
      author    = {Roberto Perdisci and Wenke Lee and Nick Feamster},
      title     = {Behavioral Clustering of {HTTP-based} Malware and Signature Generation using Malicious Network Traces},
      booktitle = {Proceedings of The 7th USENIX Symposium on Networked Systems Design and Implementation (NSDI)},
      month     = {apr},
      year      = {2010},
      doi       = {10.5555/1855711.1855737}
    }
  115. Roberto Perdisci, Igino Corona, David Dagon, and Wenke Lee. Detecting Malicious Flux Service Networks through Passive Analysis of Recursive DNS Traces. In Proceedings of The 25th Annual Computer Security Applications Conference (ACSAC 2009), Honolulu, HI, December 2009.
    BibTeX
    @inproceedings{perdisci2009detecting, title={Detecting Malicious Flux Service Networks through Passive Analysis of Recursive DNS Traces}, url={http://dx.doi.org/10.1109/acsac.2009.36}, DOI={10.1109/acsac.2009.36}, booktitle={2009 Annual Computer Security Applications Conference}, publisher={IEEE}, author={Perdisci, Roberto and Corona, Igino and Dagon, David and Lee, Wenke}, year={2009}, month=Dec, pages={311--320} }
  116. Guofei Gu, Vinod Yegneswaran, Phillip Porras, Jennifer Stoll, and Wenke Lee. Active Botnet Probing to Identify Obscure Command and Control Channels. In Proceedings of The 25th Annual Computer Security Applications Conference (ACSAC 2009), Honolulu, HI, December 2009.
    BibTeX
    @inproceedings{gu2009active, title={Active Botnet Probing to Identify Obscure Command and Control Channels}, url={http://dx.doi.org/10.1109/acsac.2009.30}, DOI={10.1109/acsac.2009.30}, booktitle={2009 Annual Computer Security Applications Conference}, publisher={IEEE}, author={Gu, Guofei and Yegneswaran, Vinod and Porras, Phillip and Stoll, Jennifer and Lee, Wenke}, year={2009}, month=Dec, pages={241--253} }
  117. Monirul Sharif, Wenke Lee, Weidong Cui, and Andrea Lanzi. Secure In-VM Monitoring Using Hardware Virtualization. In Proceedings of The 16th ACM Conference on Computer and Communications Security (CCS 2009), Chicago, IL, November, 2009.
    BibTeX
    @inproceedings{sharif2009secure, series={CCS ’09}, title={Secure in-VM monitoring using hardware virtualization}, url={http://dx.doi.org/10.1145/1653662.1653720}, DOI={10.1145/1653662.1653720}, booktitle={Proceedings of the 16th ACM conference on Computer and communications security}, publisher={ACM}, author={Sharif, Monirul I. and Lee, Wenke and Cui, Weidong and Lanzi, Andrea}, year={2009}, month=Nov, pages={477--487}, collection={CCS ’09} }
  118. Martim Carbone, Weidong Cui, Long Lu, Wenke Lee, Marcus Peinado, and Xuxian Jiang. Mapping Kernel Objects to Enable Systematic Integrity Checking. In Proceedings of The 16th ACM Conference on Computer and Communications Security (CCS 2009), Chicago, IL, November, 2009.
    BibTeX
    @inproceedings{carbone2009mapping, series={CCS ’09}, title={Mapping kernel objects to enable systematic integrity checking}, url={http://dx.doi.org/10.1145/1653662.1653729}, DOI={10.1145/1653662.1653729}, booktitle={Proceedings of the 16th ACM conference on Computer and communications security}, publisher={ACM}, author={Carbone, Martim and Cui, Weidong and Lu, Long and Lee, Wenke and Peinado, Marcus and Jiang, Xuxian}, year={2009}, month=Nov, pages={555--565}, collection={CCS ’09} }
  119. Kapil Singh, Sumeer Bhola, and Wenke Lee. xBook: Redesigning Privacy Control in Social Networking Platforms. In Proceedings of The 18th USENIX Security Symposium, Montreal, Canada, August, 2009.
    BibTeX
    @inproceedings{singh2009xbook,
      author    = {Kapil Singh and Sumeer Bhola and Wenke Lee},
      title     = {{xBook}: Redesigning Privacy Control in Social Networking Platforms},
      booktitle = {Proceedings of The 18th USENIX Security Symposium},
      month     = {aug},
      year      = {2009}
    }
  120. Roberto Perdisci, Manos Antonakakis, Xiapu Luo, and Wenke Lee. WSEC DNS: Protecting Recursive DNS Resolvers from Poisoning Attacks. In Proceedings of The 39th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2009), Lisbon, Portugal, June 2009.
    BibTeX
    @inproceedings{perdisci2009wsec, title={WSEC DNS: Protecting recursive DNS resolvers from poisoning attacks}, url={http://dx.doi.org/10.1109/dsn.2009.5270363}, DOI={10.1109/dsn.2009.5270363}, booktitle={2009 IEEE/IFIP International Conference on Dependable Systems \& Networks}, publisher={IEEE}, author={Perdisci, Roberto and Antonakakis, Manos and Luo, Xiapu and Lee, Wenke}, year={2009}, month=June, pages={3--12} }
  121. Monirul Sharif, Andrea Lanzi, Jon Giffin, and Wenke Lee. Automatic Reverse Engineering of Malware Emulators. In Proceedings of The 2009 IEEE Symposium on Security and Privacy, Oakland, CA, May 2009. (Best Student Paper Award)
    BibTeX
    @inproceedings{sharif2009automatic, title={Automatic Reverse Engineering of Malware Emulators}, url={http://dx.doi.org/10.1109/sp.2009.27}, DOI={10.1109/sp.2009.27}, booktitle={2009 30th IEEE Symposium on Security and Privacy}, publisher={IEEE}, author={Sharif, Monirul and Lanzi, Andrea and Giffin, Jonathon and Lee, Wenke}, year={2009}, month=May, pages={94--109} }
  122. Andrea Lanzi, Monirul Sharif, and Wenke Lee. K-Tracer: A System for Extracting Kernel Malware Behavior. In Proceedings of The 16th Annual Network and Distributed System Security Symposium (NDSS 2009), San Diego, CA, February 2009.
    BibTeX
    @inproceedings{lanzi2009k,
      author    = {Andrea Lanzi and Monirul Sharif and Wenke Lee},
      title     = {{K-Tracer}: A System for Extracting Kernel Malware Behavior},
      booktitle = {Proceedings of The 16th Annual Network and Distributed System Security Symposium (NDSS 2009)},
      month     = {feb},
      year      = {2009}
    }
  123. David Dagon, Manos Antonakakis, Kevin Day, Xiapu Luo, Christopher P. Lee, and Wenke Lee. Recursive DNS Architectures and Vulnerability Implications. In Proceedings of The 16th Annual Network and Distributed System Security Symposium (NDSS 2009), San Diego, CA, February 2009.
    BibTeX
    @inproceedings{dagon2009recursive,
      author    = {David Dagon and Manos Antonakakis and Kevin Day and Xiapu Luo and Christopher P. Lee and Wenke Lee},
      title     = {Recursive {DNS} Architectures and Vulnerability Implications},
      booktitle = {Proceedings of The 16th Annual Network and Distributed System Security Symposium (NDSS 2009)},
      month     = {feb},
      year      = {2009}
    }
  124. Roberto Perdisci, Andrea Lanzi, and Wenke Lee. McBoost: Boosting Scalability in Malware Collection and Analysis Using Statistical Classification of Executables. In Proceedings of The 24th Annual Computer Security Applications Conference (ACSAC 2008), Anaheim, CA, December 2008.
    BibTeX
    @inproceedings{perdisci2008mcboost, title={McBoost: Boosting Scalability in Malware Collection and Analysis Using Statistical Classification of Executables}, url={http://dx.doi.org/10.1109/acsac.2008.22}, DOI={10.1109/acsac.2008.22}, booktitle={2008 Annual Computer Security Applications Conference (ACSAC)}, publisher={IEEE}, author={Perdisci, Roberto and Lanzi, Andrea and Lee, Wenke}, year={2008}, month=Dec, pages={301--310} }
  125. Artem Dinaburg, Paul Royal, Monirul Sharif, and Wenke Lee. Ether: Malware Analysis via Hardware Virtualization Extensions. In Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS 2008), Alexandria, VA, October 2008.
    BibTeX
    @inproceedings{dinaburg2008ether, series={CCS08}, title={Ether: malware analysis via hardware virtualization extensions}, url={http://dx.doi.org/10.1145/1455770.1455779}, DOI={10.1145/1455770.1455779}, booktitle={Proceedings of the 15th ACM conference on Computer and communications security}, publisher={ACM}, author={Dinaburg, Artem and Royal, Paul and Sharif, Monirul and Lee, Wenke}, year={2008}, month=Oct, pages={51--62}, collection={CCS08} }
  126. David Dagon, Manos Antonakakis, Paul Vixie, Tatuya Jinmei, and Wenke Lee. Increased DNS Forgery Resistance Through 0x20-Bit Encoding. In Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS 2008), Alexandria, VA, October 2008.
    BibTeX
    @inproceedings{dagon2008increased, series={CCS08}, title={Increased DNS forgery resistance through 0x20-bit encoding: security via leet queries}, url={http://dx.doi.org/10.1145/1455770.1455798}, DOI={10.1145/1455770.1455798}, booktitle={Proceedings of the 15th ACM conference on Computer and communications security}, publisher={ACM}, author={Dagon, David and Antonakakis, Manos and Vixie, Paul and Jinmei, Tatuya and Lee, Wenke}, year={2008}, month=Oct, pages={211--222}, collection={CCS08} }
  127. Monirul Sharif, Vinod Yegneswaran, Hassen Saidi, Phillip Porras, and Wenke Lee. Eureka: A Framework for Enabling Static Malware Analysis. In Proceedings of the 13th European Symposium on Research in Computer Security (ESORICS), Malaga, Spain, October 2008.
    BibTeX
    @inbook{sharif2008eureka, title={Eureka: A Framework for Enabling Static Malware Analysis}, ISBN={9783540883135}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-540-88313-5_31}, DOI={10.1007/978-3-540-88313-5_31}, booktitle={Computer Security - ESORICS 2008}, publisher={Springer Berlin Heidelberg}, author={Sharif, Monirul and Yegneswaran, Vinod and Saidi, Hassen and Porras, Phillip and Lee, Wenke}, year={2008}, pages={481--500} }
  128. Guofei Gu, Roberto Perdisci, Junjie Zhang, and Wenke Lee. BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnet Detection. In Proceedings of The 17th USENIX Security Symposium (Security'08), San Jose, CA, July 2008.
    BibTeX
    @inproceedings{gu2008botminer,
      author    = {Guofei Gu and Roberto Perdisci and Junjie Zhang and Wenke Lee},
      title     = {{BotMiner}: Clustering Analysis of Network Traffic for Protocol- and {Structure-Independent} Botnet Detection},
      booktitle = {Proceedings of The 17th USENIX Security Symposium (Security'08)},
      month     = {jul},
      year      = {2008}
    }
  129. Kapil Singh, Abhinav Srivastava, Jon Giffin, and Wenke Lee. Evaluating Email's Feasibility for Botnet Command and Control. In Proceedings of the 38th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2008), Anchorage, Alaska, June 2008.
    BibTeX
    @inproceedings{singh2008evaluating, title={Evaluating email’s feasibility for botnet command and control}, url={http://dx.doi.org/10.1109/dsn.2008.4630106}, DOI={10.1109/dsn.2008.4630106}, booktitle={2008 IEEE International Conference on Dependable Systems and Networks With FTCS and DCC (DSN)}, publisher={IEEE}, author={Singh, Kapil and Srivastava, Abhinav and Giffin, Jonathon and Lee, Wenke}, year={2008}, month=June, pages={376--385} }
  130. Bryan D. Payne, Martim Carbone, Monirul Sharif, and Wenke Lee. Lares: An Architecture for Secure Active Monitoring Using Virtualization. In Proceedings of the 2008 IEEE Symposium on Security and Privacy, Oakland, CA, May 2008.
    BibTeX
    @inproceedings{payne2008lares, title={Lares: An Architecture for Secure Active Monitoring Using Virtualization}, ISSN={1081-6011}, url={http://dx.doi.org/10.1109/sp.2008.24}, DOI={10.1109/sp.2008.24}, booktitle={2008 IEEE Symposium on Security and Privacy (sp 2008)}, publisher={IEEE}, author={Payne, Bryan D. and Carbone, Martim and Sharif, Monirul and Lee, Wenke}, year={2008}, month=May, pages={233--247} }
  131. Guofei Gu, Alvaro A. Cardenas, and Wenke Lee. Principled Reasoning and Practical Applications of Alert Fusion in Intrusion Detection Systems. In Proceedings of the ACM Symposium on InformAction, Computer and Communications Security (ASIACCS'08), Tokyo, Japan, March 2008.
    BibTeX
    @inproceedings{gu2008principled, series={Asia CCS ’08}, title={Principled reasoning and practical applications of alert fusion in intrusion detection systems}, url={http://dx.doi.org/10.1145/1368310.1368332}, DOI={10.1145/1368310.1368332}, booktitle={Proceedings of the 2008 ACM symposium on Information, computer and communications security}, publisher={ACM}, author={Gu, Guofei and Cárdenas, Alvaro A. and Lee, Wenke}, year={2008}, month=Mar, pages={136--147}, collection={Asia CCS ’08} }
  132. David Dagon, Niels Provos, Chris Lee, and Wenke Lee. Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority. In Proceedings of The 15th Annual Network and Distributed System Security Symposium (NDSS 2008), San Diego, CA, February 2008.
    BibTeX
    @inproceedings{dagon2008corrupted,
      author    = {David Dagon and Niels Provos and Chris Lee and Wenke Lee},
      title     = {Corrupted {DNS} Resolution Paths: The Rise of a Malicious Resolution Authority},
      booktitle = {Proceedings of The 15th Annual Network and Distributed System Security Symposium (NDSS 2008)},
      month     = {feb},
      year      = {2008}
    }
  133. Guofei Gu, Junjie Zhang, and Wenke Lee. BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In Proceedings of The 15th Annual Network and Distributed System Security Symposium (NDSS 2008), San Diego, CA, February 2008.
    BibTeX
    @inproceedings{gu2008botsniffer,
      author    = {Guofei Gu and Junjie Zhang and Wenke Lee},
      title     = {{BotSniffer}: Detecting Botnet Command and Control Channels in Network Traffic},
      booktitle = {Proceedings of The 15th Annual Network and Distributed System Security Symposium (NDSS 2008)},
      month     = {feb},
      year      = {2008}
    }
  134. Monirul Sharif, Andrea Lanzi, Jonathon Giffin, and Wenke Lee. Impeding Malware Analysis using Conditional Code Obfuscation. In Proceedings of The 15th Annual Network and Distributed System Security Symposium (NDSS 2008), San Diego, CA, February 2008.
    BibTeX
    @inproceedings{sharif2008impeding,
      author    = {Monirul Sharif and Andrea Lanzi and Jonathon Giffin and Wenke Lee},
      title     = {Impeding Malware Analysis using Conditional Code Obfuscation},
      booktitle = {Proceedings of The 15th Annual Network and Distributed System Security Symposium (NDSS 2008)},
      month     = {feb},
      year      = {2008}
    }
  135. Bryan D. Payne, Martim Carbone, and Wenke Lee. Secure and Flexible Monitoring of Virtual Machines. In Proceedings of The 23rd Annual Computer Security Applications Conference (ACSAC 2007), Miami Beach, FL, December 2007.
    BibTeX
    @inproceedings{payne2007secure,
      author    = {Bryan D. Payne and Martim Carbone and Wenke Lee},
      title     = {Secure and Flexible Monitoring of Virtual Machines},
      booktitle = {Proceedings of The 23rd Annual Computer Security Applications Conference (ACSAC 2007)},
      month     = {dec},
      year      = {2007},
      doi       = {10.1109/acsac.2007.4413005}
    }
  136. David Dagon, Guofei Gu, Chris Lee and Wenke Lee. A Taxonomy of Botnet Structures. In Proceedings of The 23rd Annual Computer Security Applications Conference (ACSAC 2007), Miami Beach, FL, December 2007.
    BibTeX
    @inbook{dagon2007taxonomy, title={A Taxonomy of Botnet Structures}, ISBN={9780387687667}, url={http://dx.doi.org/10.1007/978-0-387-68768-1_8}, DOI={10.1007/978-0-387-68768-1_8}, booktitle={Botnet Detection}, publisher={Springer US}, author={Dagon, David and Gu, Guofei and Lee, Christopher P.}, pages={143--164}, year={2007} }
  137. Guofei Gu, Zesheng Chen, Phillip Porras and Wenke Lee. Misleading and Defeating Importance-Scanning Malware Propagation. In Proceedings of The 3rd International Conference on Security and Privacy in Communication Networks (SecureComm'07), Nice, France, September 2007.
    BibTeX
    @inproceedings{gu2007misleading, title={Misleading and defeating importance-scanning malware propagation}, url={http://dx.doi.org/10.1109/seccom.2007.4550340}, DOI={10.1109/seccom.2007.4550340}, booktitle={2007 Third International Conference on Security and Privacy in Communications Networks and the Workshops - SecureComm 2007}, publisher={IEEE}, author={Guofei Gu and Zesheng Chen and Porras, Phillip and Lee, Wenke}, year={2007}, pages={250--259} }
  138. Takehiro Takahashi and Wenke Lee. An Assessment of VoIP Covert Channel Threats. In Proceedings of The 3rd International Conference on Security and Privacy in Communication Networks (SecureComm'07), Nice, France, September 2007.
    BibTeX
    @inproceedings{takahashi2007assessment, title={An assessment of VoIP covert channel threats}, url={http://dx.doi.org/10.1109/seccom.2007.4550357}, DOI={10.1109/seccom.2007.4550357}, booktitle={2007 Third International Conference on Security and Privacy in Communications Networks and the Workshops - SecureComm 2007}, publisher={IEEE}, author={Takahashi, Takehiro and Lee, Wenke}, year={2007}, pages={371--380} }
  139. Monirul Sharif, Kapil Singh, Jonathon Giffin and Wenke Lee. Understanding Precision in Host Based Intrusion Detection: Formal Analysis and Practical Models. In Proceedings of The 10th International Symposium on Recent Advances in Intrusion Detection (RAID), Surfers Paradise, Australia, September 2007.
    BibTeX
    @inproceedings{sharif2007understanding,
      author    = {Monirul Sharif and Kapil Singh and Jonathon Giffin and Wenke Lee},
      title     = {Understanding Precision in Host Based Intrusion Detection: Formal Analysis and Practical Models},
      booktitle = {Proceedings of The 10th International Symposium on Recent Advances in Intrusion Detection (RAID)},
      month     = {sep},
      year      = {2007}
    }
  140. Guofei Gu, Phillip Porras, Vinod Yegneswaran, Martin Fong, Wenke Lee. BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation. In Proceedings of The 16th USENIX Security Symposium (Security'07), Boston, MA, August 2007.
    BibTeX
    @inproceedings{gu2007bothunter,
      author    = {Guofei Gu and Phillip Porras and Vinod Yegneswaran and Martin Fong and Wenke Lee},
      title     = {{BotHunter}: Detecting Malware Infection Through {IDS-Driven} Dialog Correlation},
      booktitle = {Proceedings of The 16th USENIX Security Symposium (Security'07)},
      month     = {aug},
      year      = {2007}
    }
  141. David Cash, Yan Zong Ding, Yevgeniy Dodis, Wenke Lee, Richard Lipton, and Shabsi Walfish. Intrusion-Resilient Key Exchange in the Bounded Retrieval Model. In Proceedings of The Fourth IACR Theory of Cryptography Conference (TCC 2007), Amsterdam, The Netherlands, February 2007.
    BibTeX
    @inbook{cash2007intrusion, title={Intrusion-Resilient Key Exchange in the Bounded Retrieval Model}, ISBN={9783540709367}, url={http://dx.doi.org/10.1007/978-3-540-70936-7_26}, DOI={10.1007/978-3-540-70936-7_26}, booktitle={Theory of Cryptography}, publisher={Springer Berlin Heidelberg}, author={Cash, David and Ding, Yan Zong and Dodis, Yevgeniy and Lee, Wenke and Lipton, Richard and Walfish, Shabsi}, pages={479--498}, year={2007} }
  142. Roberto Perdisci, Guofei Gu, and Wenke Lee. Using an Ensemble of One-Class SVM Classifiers to Harden Payload-based Anomaly Detection Systems. In Proceedings of The 2006 IEEE International Conference on Data Mining (ICDM '06), Hong Kong, China, December 2006.
    BibTeX
    @inproceedings{perdisci2006using, title={Using an Ensemble of One-Class SVM Classifiers to Harden Payload-based Anomaly Detection Systems}, ISSN={1550-4786}, url={http://dx.doi.org/10.1109/icdm.2006.165}, DOI={10.1109/icdm.2006.165}, booktitle={Sixth International Conference on Data Mining (ICDM′06)}, publisher={IEEE}, author={Perdisci, Roberto and Gu, Guofei and Lee, Wenke}, year={2006}, month=Dec, pages={488--498} }
  143. Paul Royal, Mitch Halpin, David Dagon, Robert Edmonds, and Wenke Lee. PolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware. In Proceedings of The 22nd Annual Computer Security Applications Conference (ACSAC 2006), Miami Beach, FL, December 2006.
    BibTeX
    @inproceedings{royal2006polyunpack, title={PolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware}, url={http://dx.doi.org/10.1109/acsac.2006.38}, DOI={10.1109/acsac.2006.38}, booktitle={2006 22nd Annual Computer Security Applications Conference (ACSAC′06)}, publisher={IEEE}, author={Royal, Paul and Halpin, Mitch and Dagon, David and Edmonds, Robert and Lee, Wenke}, year={2006}, month=Dec, pages={289--300} }
  144. Prahlad Fogla and Wenke Lee. Evading Network Anomaly Detection Systems: Formal Reasoning and Practical Techniques. In Proceedings of The 13th ACM Conference on Computer and Communications Security (CCS 2006), Alexandria, VA, October 2006.
    BibTeX
    @inproceedings{fogla2006evading, series={CCS06}, title={Evading network anomaly detection systems: formal reasoning and practical techniques}, url={http://dx.doi.org/10.1145/1180405.1180414}, DOI={10.1145/1180405.1180414}, booktitle={Proceedings of the 13th ACM conference on Computer and communications security}, publisher={ACM}, author={Fogla, Prahlad and Lee, Wenke}, year={2006}, month=Oct, pages={59--68}, collection={CCS06} }
  145. Guofei Gu, Prahlad Fogla, David Dagon, Wenke Lee, and Boris Skoric. Towards an Information-Theoretic Framework for Analyzing Intrusion Detection Systems. In Proceedings of The 11th European Symposium Research Computer Security (ESORICS 2006), Hamburg, Germany, September 2006.
    BibTeX
    @inbook{gu2006information, title={Towards an Information-Theoretic Framework for Analyzing Intrusion Detection Systems}, ISBN={9783540446057}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/11863908_32}, DOI={10.1007/11863908_32}, booktitle={Computer Security – ESORICS 2006}, publisher={Springer Berlin Heidelberg}, author={Gu, Guofei and Fogla, Prahlad and Dagon, David and Lee, Wenke and Skoric, Boris}, year={2006}, pages={527--546} }
  146. Prahlad Fogla, Monirul Sharif, Roberto Perdisci, Oleg Kolesnikov, and Wenke Lee. Polymorphic Blending Attacks. In Proceedings of The 15th USENIX Security Symposium (SECURITY '06), Vancouver, B.C., Canada, August 2006.
    BibTeX
    @inproceedings{fogla2006polymorphic,
      author    = {Prahlad Fogla and Monirul Sharif and Roberto Perdisci and Oleg Kolesnikov and Wenke Lee},
      title     = {Polymorphic Blending Attacks},
      booktitle = {Proceedings of The 15th USENIX Security Symposium (SECURITY '06)},
      month     = {aug},
      year      = {2006}
    }
  147. Collin Mulliner, Giovanni Vigna, David Dagon, and Wenke Lee. Using Labeling to Prevent Cross-Service Attacks Against Smart Phones. In Proceedings of The 3rd Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA 2006), Berlin, Germany, July 2006.
    BibTeX
    @inbook{mulliner2006using, title={Using Labeling to Prevent Cross-Service Attacks Against Smart Phones}, ISBN={9783540360179}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/11790754_6}, DOI={10.1007/11790754_6}, booktitle={Detection of Intrusions and Malware \& Vulnerability Assessment}, publisher={Springer Berlin Heidelberg}, author={Mulliner, Collin and Vigna, Giovanni and Dagon, David and Lee, Wenke}, year={2006}, pages={91--108} }
  148. Hongmei Deng, Roger Xu, Jason H. Li, Frank Zhang, Renato Levy, and Wenke Lee. Agent-Based Cooperative Anomaly Detection for Wireless Ad Hoc Networks. In Proceedings of The 12th International Conference on Parallel and Distributed Systems (ICPADS 2006), Minneapolis, Minnesota, July 2006.
    BibTeX
    @inproceedings{deng2006agent, title={Agent-based cooperative anomaly detection for wireless ad hoc networks}, url={http://dx.doi.org/10.1109/icpads.2006.23}, DOI={10.1109/icpads.2006.23}, booktitle={12th International Conference on Parallel and Distributed Systems - (ICPADS′06)}, publisher={IEEE}, author={Hongmei Deng and Xu, R. and Li, J. and Zhang, F. and Levy, R. and Wenke Lee}, year={2006}, pages={8 pp.} }
  149. Guofei Gu, Prahlad Fogla, Wenke Lee, and Douglas Blough. DSO: Dependable Signing Overlay. In Proceedings of The 4th International Conference on Applied Cryptography and Network Security (ACNS '06), Singapore, June 2006.
    BibTeX
    @inbook{gu2006dso, title={DSO: Dependable Signing Overlay}, ISBN={9783540354383}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/11767480_3}, DOI={10.1007/11767480_3}, booktitle={RoboCup 2005: Robot Soccer World Cup IX}, publisher={Springer Berlin Heidelberg}, author={Gu, Guofei and Fogla, Prahlad and Lee, Wenke and Blough, Douglas}, year={2006}, pages={33--49} }
  150. Roberto Perdisci, David Dagon, Wenke Lee, Prahlad Fogla, and Monirul Sharif. Misleading Worm Signature Generators Using Deliberate Noise Injection (full paper). In Proceedings of the 2006 IEEE Symposium on Security and Privacy, Oakland, CA, May 2006.
    BibTeX
    @inproceedings{perdisci2006misleading, title={Misleading worm signature generators using deliberate noise injection}, url={http://dx.doi.org/10.1109/sp.2006.26}, DOI={10.1109/sp.2006.26}, booktitle={2006 IEEE Symposium on Security and Privacy (S\&P′06)}, publisher={IEEE}, author={Perdisci, R. and Dagon, D. and Wenke Lee and Fogla, P. and Sharif, M.}, year={2006} }
  151. Guofei Gu, Prahlad Fogla, David Dagon, Wenke Lee, and Boris Skoric. Measuring Intrusion Detection Capability: An Information-Theoretic Approach. In Proceedings of ACM Symposium on InformAction, Computer and Communications Security (ASIACCS '06), Taipei, Taiwan, March 2006.
    BibTeX
    @inproceedings{gu2006measuring, series={Asia CCS06}, title={Measuring intrusion detection capability: an information-theoretic approach}, url={http://dx.doi.org/10.1145/1128817.1128834}, DOI={10.1145/1128817.1128834}, booktitle={Proceedings of the 2006 ACM Symposium on Information, computer and communications security}, publisher={ACM}, author={Gu, Guofei and Fogla, Prahlad and Dagon, David and Lee, Wenke and Skorić, Boris}, year={2006}, month=Mar, pages={90--101}, collection={Asia CCS06} }
  152. David Dagon, Cliff Zou, and Wenke Lee. Modeling Botnet Propagation Using Time Zones. In Proceedings of The 13th Annual Network and Distributed System Security Symposium (NDSS 2006), San Diego, CA, February 2006.
    BibTeX
    @inproceedings{dagon2006modeling,
      author    = {David Dagon and Cliff Zou and Wenke Lee},
      title     = {Modeling Botnet Propagation Using Time Zones},
      booktitle = {Proceedings of The 13th Annual Network and Distributed System Security Symposium (NDSS 2006)},
      month     = {feb},
      year      = {2006}
    }
  153. Yongguang Zhang, Yi-an Huang, and Wenke Lee. An Extensible Environment for Evaluating Secure MANET. In Proceedings of The 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks (SecureComm 2005), Athens, Greece, September 2005.
    BibTeX
    @inproceedings{zhang2005extensible,
      author    = {Yongguang Zhang and Yi-an Huang and Wenke Lee},
      title     = {An Extensible Environment for Evaluating Secure {MANET}},
      booktitle = {Proceedings of The 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks (SecureComm 2005)},
      month     = {sep},
      year      = {2005}
    }
  154. Tao Zhang, Xiaotong Zhuang, Santosh Pande, and Wenke Lee. Anomalous Path Detection with Hardware Support. In Proceedings of The 2005 International Conference on Compilers, Architecture, and Synthesis for Embedded Systems (CASES 2005), San Francisco, CA, September 2005.
    BibTeX
    @inproceedings{zhang2005anomalous, series={CASES05}, title={Anomalous path detection with hardware support}, url={http://dx.doi.org/10.1145/1086297.1086305}, DOI={10.1145/1086297.1086305}, booktitle={Proceedings of the 2005 international conference on Compilers, architectures and synthesis for embedded systems}, publisher={ACM}, author={Zhang, Tao and Zhuang, Xiaotong and Pande, Santosh and Lee, Wenke}, year={2005}, month=Sept, pages={43--54}, collection={CASES05} }
  155. Jonathon T. Giffin, David Dagon, Somesh Jha, Wenke Lee, and Barton P. Miller. Environment-Sensitive Intrusion Detection. In Proceedings of The 8th International Symposium on Recent Advances in Intrusion Detection (RAID 2005), Seattle, WA, September 2005.
    BibTeX
    @inproceedings{giffin2005environment,
      author    = {Jonathon T. Giffin and David Dagon and Somesh Jha and Wenke Lee and Barton P. Miller},
      title     = {{Environment-Sensitive} Intrusion Detection},
      booktitle = {Proceedings of The 8th International Symposium on Recent Advances in Intrusion Detection (RAID 2005)},
      month     = {sep},
      year      = {2005}
    }
  156. David Dagon, Wenke Lee, and Richard Lipton. Protecting Secret Data from Insider Attacks. In Proceedings of Ninth International Conference on Financial Cryptography and Data Security, Roseau, Dominica, Feb. 2005.
    BibTeX
    @inbook{dagon2005protecting, title={Protecting Secret Data from Insider Attacks}, ISBN={9783540316800}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/11507840_2}, DOI={10.1007/11507840_2}, booktitle={Financial Cryptography and Data Security}, publisher={Springer Berlin Heidelberg}, author={Dagon, David and Lee, Wenke and Lipton, Richard}, year={2005}, pages={16--30} }
  157. Guofei Gu, David Dagon, Xinzhou Qin, Monirul I. Sharif, Wenke Lee, and George F. Riley. Worm Detection, Early Warning, and Response Based on Local Victim Information. In Proceedings of The 20th Annual Computer Security Applications Conference (ACSAC 2004), Tucson, Arizona, December 2004.
    BibTeX
    @inproceedings{gu2004worm,
      author    = {Guofei Gu and David Dagon and Xinzhou Qin and Monirul I. Sharif and Wenke Lee and George F. Riley},
      title     = {Worm Detection, Early Warning, and Response Based on Local Victim Information},
      booktitle = {Proceedings of The 20th Annual Computer Security Applications Conference (ACSAC 2004)},
      month     = {dec},
      year      = {2004}
    }
  158. Xinzhou Qin and Wenke Lee. Attack Plan Recognition and Prediction Using Causal Networks. In Proceedings of The 20th Annual Computer Security Applications Conference (ACSAC 2004), Tucson, Arizona, December 2004.
    BibTeX
    @inproceedings{qin2004attack,
      author    = {Xinzhou Qin and Wenke Lee},
      title     = {Attack Plan Recognition and Prediction Using Causal Networks},
      booktitle = {Proceedings of The 20th Annual Computer Security Applications Conference (ACSAC 2004)},
      month     = {dec},
      year      = {2004}
    }
  159. Joao B.D. Cabrera, Jaykumar Gosar, Wenke Lee, and Raman K. Mehra. On the Statistical Distribution of Processing Times in Network Intrusion Detection. In Proceedings of The 43rd IEEE Conference on Decision and Control (CDC 2004), Bahamas, December 2004.
    BibTeX
    @inproceedings{cabrera2004statistical,
      author    = {Joao B.D. Cabrera and Jaykumar Gosar and Wenke Lee and Raman K. Mehra},
      title     = {On the Statistical Distribution of Processing Times in Network Intrusion Detection},
      booktitle = {Proceedings of The 43rd IEEE Conference on Decision and Control (CDC 2004)},
      month     = {dec},
      year      = {2004}
    }
  160. George F. Riley, Monirul I. Sharif, and Wenke Lee. Simulating Internet Worms. In Proceedings of The 12th Annual Meeting of the IEEE/ACM International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems (MASCOTS), Volendam, The Netherlands, October 2004.
    BibTeX
    @inproceedings{riley2004simulating,
      author    = {George F. Riley and Monirul I. Sharif and Wenke Lee},
      title     = {Simulating Internet Worms},
      booktitle = {Proceedings of The 12th Annual Meeting of the IEEE/ACM International Symposium on Modeling},
      month     = {oct},
      year      = {2004}
    }
  161. Yian Huang and Wenke Lee. Attack Analysis and Detection for Ad Hoc Routing Protocols. Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID 2004), Sophia Antipolis, France, September 2004.
    BibTeX
    @inproceedings{huang2004attack,
      author    = {Yian Huang and Wenke Lee},
      title     = {Attack Analysis and Detection for Ad Hoc Routing Protocols},
      booktitle = {Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID 2004)},
      month     = {sep},
      year      = {2004}
    }
  162. David Dagon, Xinzhou Qin, Guofei Gu, Wenke Lee, Julian Grizzard, John Levin, and Henry Owen. HoneyStat: Local Worm Detection Using Honeypots. Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID 2004), Sophia Antipolis, France, September 2004.
    BibTeX
    @inproceedings{dagon2004honeystat,
      author    = {David Dagon and Xinzhou Qin and Guofei Gu and Wenke Lee and Julian Grizzard and John Levin and Henry Owen},
      title     = {{HoneyStat}: Local Worm Detection Using Honeypots},
      booktitle = {Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID 2004)},
      month     = {sep},
      year      = {2004}
    }
  163. Xinzhou Qin and Wenke Lee. Discovering Novel Attack Strategies from INFOSEC Alerts. Proceedings of the 9th European Symposium on Research in Computer Security (ESORICS 2004) , Sophia Antipolis, France, September 2004.
    BibTeX
    @inbook{qin2004discovering, title={Discovering Novel Attack Strategies from INFOSEC Alerts}, ISBN={9783540301080}, ISSN={1611-3349}, url={http://dx.doi.org/10.1007/978-3-540-30108-0_27}, DOI={10.1007/978-3-540-30108-0_27}, booktitle={Computer Security – ESORICS 2004}, publisher={Springer Berlin Heidelberg}, author={Qin, Xinzhou and Lee, Wenke}, year={2004}, pages={439--456} }
  164. Henry H. Feng, Jonathon T. Giffin, Yong Huang, Somesh Jha, Wenke Lee, and Barton P. Miller. Formalizing Sensitivity in Static Analysis for Intrusion Detection. In Proceedings of the 2004 IEEE Symposium on Security and Privacy, Oakland, CA, May 2004.
    BibTeX
    @inproceedings{feng2004formalizing,
      author    = {Henry H. Feng and Jonathon T. Giffin and Yong Huang and Somesh Jha and Wenke Lee and Barton P. Miller},
      title     = {Formalizing Sensitivity in Static Analysis for Intrusion Detection},
      booktitle = {Proceedings of the 2004 IEEE Symposium on Security and Privacy},
      month     = {may},
      year      = {2004}
    }
  165. Xinzhou Qin and Wenke Lee. Statistical Causality Analysis of INFOSEC Alert Data. In Proceedings of The 6th International Symposium on Recent Advances in Intrusion Detection (RAID 2003), Pittsburgh, PA, September 2003.
    BibTeX
    @inproceedings{qin2003statistical,
      author    = {Xinzhou Qin and Wenke Lee},
      title     = {Statistical Causality Analysis of {INFOSEC} Alert Data},
      booktitle = {Proceedings of The 6th International Symposium on Recent Advances in Intrusion Detection (RAID 2003)},
      month     = {sep},
      year      = {2003}
    }
  166. Henry H. Feng, Oleg Kolesnikov, Prahlad Fogla, Wenke Lee, and Weibo Gong. Anomaly Detection Using Call Stack Information. In Proceedings of the 2003 IEEE Symposium on Security and Privacy, Oakland, CA, May 2003.
    BibTeX
    @inproceedings{feng2003anomaly,
      author    = {Henry H. Feng and Oleg Kolesnikov and Prahlad Fogla and Wenke Lee and Weibo Gong},
      title     = {Anomaly Detection Using Call Stack Information},
      booktitle = {Proceedings of the 2003 IEEE Symposium on Security and Privacy},
      month     = {may},
      year      = {2003}
    }
  167. Yi-an Huang, Wei Fan, Wenke Lee, and Philip S. Yu. Cross-Feature Analysis for Detecting Ad-Hoc Routing Anomalies. In Proceedings of the 23rd International Conference on Distributed Computing Systems (ICDCS), Providence, RI, May 2003.
    BibTeX
    @inproceedings{huang2003cross,
      author    = {Yi-an Huang and Wei Fan and Wenke Lee and Philip S. Yu},
      title     = {{Cross-Feature} Analysis for Detecting {Ad-Hoc} Routing Anomalies},
      booktitle = {Proceedings of the 23rd International Conference on Distributed Computing Systems (ICDCS)},
      month     = {may},
      year      = {2003}
    }
  168. Wenke Lee, Joao B. D. Cabrera, Ashley Thomas, Niranjan Balwalli, Sunmeet Saluja, and Yi Zhang. Performance Adaptation in Real-Time Intrusion Detection Systems. In Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID 2002), Zurich, Switzerland, October 2002.
    BibTeX
    @inproceedings{lee2002performance,
      author    = {Wenke Lee and Joao B. D. Cabrera and Ashley Thomas and Niranjan Balwalli and Sunmeet Saluja and Yi Zhang},
      title     = {Performance Adaptation in {Real-Time} Intrusion Detection Systems},
      booktitle = {Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID 2002)},
      month     = {oct},
      year      = {2002}
    }
  169. Xinzhou Qin, Wenke Lee, Lundy Lewis, and Joao B. D. Cabrera. Integrating Intrusion Detection and Network Management. In Proceedings of the IEEE/IFIP Network Operations and Management Symposium (NOMS 2002), Florence, Italy, May 2002.
    BibTeX
    @inproceedings{qin2002integrating, series={NOMS-02}, title={Integrating intrusion detection and network management}, url={http://dx.doi.org/10.1109/noms.2002.1015591}, DOI={10.1109/noms.2002.1015591}, booktitle={NOMS 2002. IEEE/IFIP Network Operations and Management Symposium. ′ Management Solutions for the New Communications World’(Cat. No.02CH37327)}, publisher={IEEE}, author={Xinzhou Qin and Wenke Lee and Lewis, L. and Cabrera, J.B.D.}, pages={329--344}, collection={NOMS-02}, year={2002} }
  170. Wei Fan, Matt Miller, Sal Stolfo, Wenke Lee, and Phil Chan. Using Artificial Anomalies to Detect Unknown and Known Network Intrusions. In Proceedings of The First IEEE International Conference on Data Mining, San Jose, CA, November 2001.
    BibTeX
    @inproceedings{fan2001using,
      author    = {Wei Fan and Matt Miller and Sal Stolfo and Wenke Lee and Phil Chan},
      title     = {Using Artificial Anomalies to Detect Unknown and Known Network Intrusions},
      booktitle = {Proceedings of The First IEEE International Conference on Data Mining},
      month     = {nov},
      year      = {2001}
    }
  171. Yongguang Zhang, Harrick Vin, Lorenzo Alvisi, Wenke Lee, and Son K. Dao. Heterogeneous Networking: A New Survivability Paradigm. In Proceedings of the 2001 New Security Paradigms Workshop, Cloudcroft, New Mexico, September 2001.
    BibTeX
    @inproceedings{zhang2001heterogeneous,
      author    = {Yongguang Zhang and Harrick Vin and Lorenzo Alvisi and Wenke Lee and Son K. Dao},
      title     = {Heterogeneous Networking: A New Survivability Paradigm},
      booktitle = {Proceedings of the 2001 New Security Paradigms Workshop},
      month     = {sep},
      year      = {2001}
    }
  172. Wenke Lee, Sal Stolfo, Phil Chan, Eleazar Eskin, Wei Fan, Matt Miller, Shlomo Hershkop, and Junxin Zhang. Real Time Data Mining-based Intrusion Detection. In Proceedings of the 2001 DARPA Information Survivability Conference and Exposition (DISCEX II) (selected for presentation), Anaheim, CA, June 2001.
    BibTeX
    @inproceedings{lee2001real,
      author    = {Wenke Lee and Sal Stolfo and Phil Chan and Eleazar Eskin and Wei Fan and Matt Miller and Shlomo Hershkop and Junxin Zhang},
      title     = {Real Time Data Mining-based Intrusion Detection},
      booktitle = {Proceedings of the 2001 DARPA Information Survivability Conference and Exposition (DISCEX II) (selected for presentation)},
      month     = {jun},
      year      = {2001}
    }
  173. Wenke Lee and Dong Xiang. Information-Theoretic Measures for Anomaly Detection. In Proceedings of The 2001 IEEE Symposium on Security and Privacy, Oakland, CA, May 2001.
    BibTeX
    @inproceedings{lee2001information,
      author    = {Wenke Lee and Dong Xiang},
      title     = {{Information-Theoretic} Measures for Anomaly Detection},
      booktitle = {Proceedings of The 2001 IEEE Symposium on Security and Privacy},
      month     = {may},
      year      = {2001}
    }
  174. J. B. D. Cabrera, L. Lewis, X. Qin, Wenke Lee, Ravi Prasanth, B. Ravichandran, and Raman Mehra. Proactive Detection of Distributed Denial of Service Attacks Using MIB Traffic Variables - A Feasibility Study. In Proceedings of The Seventh IFIP/IEEE International Symposium on Integrated Network Management (IM 2001), Seattle, WA, May 2001.
    BibTeX
    @inproceedings{cabrera2001proactive,
      author    = {J. B. D. Cabrera and L. Lewis and X. Qin and Wenke Lee and Ravi Prasanth and B. Ravichandran and Raman Mehra},
      title     = {Proactive Detection of Distributed Denial of Service Attacks Using {MIB} Traffic Variables - A Feasibility Study},
      booktitle = {Proceedings of The Seventh IFIP/IEEE International Symposium on Integrated Network Management (IM 2001)},
      month     = {may},
      year      = {2001}
    }
  175. Yongguang Zhang and Wenke Lee. Intrusion Detection in Wireless Ad-Hoc Networks. Proceedings of The Sixth International Conference on Mobile Computing and Networking (MobiCom 2000), Boston, MA, August 2000.
    BibTeX
    @inproceedings{zhang2000intrusion,
      author    = {Yongguang Zhang and Wenke Lee},
      title     = {Intrusion Detection in Wireless {Ad-Hoc} Networks},
      booktitle = {Proceedings of The Sixth International Conference on Mobile Computing and Networking (MobiCom 2000)},
      month     = {aug},
      year      = {2000}
    }
  176. Wei Fan, Wenke Lee, Sal Stolfo, and Matt Miller. A Multiple Model Cost-Sensitive Approach for Intrusion Detection. Proceedings of The Eleventh European Conference on Machine Learning (ECML 2000), LNAI 1810, Barcelona, Spain, May 2000.
    BibTeX
    @inproceedings{fan2000multiple,
      author    = {Wei Fan and Wenke Lee and Sal Stolfo and Matt Miller},
      title     = {A Multiple Model {Cost-Sensitive} Approach for Intrusion Detection},
      booktitle = {Proceedings of The Eleventh European Conference on Machine Learning (ECML 2000)},
      month     = {may},
      year      = {2000}
    }
  177. Sal Stolfo, Wei Fan, Wenke Lee, Andreas Prodromidis, and Phil Chan. Cost-based Modeling for Fraud and Intrusion Detection: Results from the JAM Project. Proceedings of the 2000 DARPA Information Survivability Conference and Exposition (DISCEX '00) (selected for presentation), Hilton Head, SC, January 2000.
    BibTeX
    @inproceedings{stolfo2000cost,
      author    = {Sal Stolfo and Wei Fan and Wenke Lee and Andreas Prodromidis and Phil Chan},
      title     = {Cost-based Modeling for Fraud and Intrusion Detection: Results from the {JAM} Project},
      booktitle = {Proceedings of the 2000 DARPA Information Survivability Conference and Exposition (DISCEX '00) (selected for presentation)},
      month     = {jan},
      year      = {2000}
    }
  178. Wenke Lee, Sal Stolfo, and Kui Mok. Mining in a Data-flow Environment: Experience in Network Intrusion Detection (Best Paper Award in Applied Research Category). Proceedings of the 5th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD '99), San Diego, CA, August 1999.
    BibTeX
    @inproceedings{lee1999mining,
      author    = {Wenke Lee and Sal Stolfo and Kui Mok},
      title     = {Mining in a Data-flow Environment: Experience in Network Intrusion Detection (Best Paper Award in Applied Research Category)},
      booktitle = {Proceedings of the 5th ACM SIGKDD International Conference on Knowledge Discovery \& Data Mining (KDD '99)},
      month     = {aug},
      year      = {1999}
    }
  179. Wenke Lee, Sal Stolfo, and Kui Mok. A Data Mining Framework for Building Intrusion Detection Models. Proceedings of the 1999 IEEE Symposium on Security and Privacy, Oakland, CA, May 1999.
    BibTeX
    @inproceedings{lee1999data,
      author    = {Wenke Lee and Sal Stolfo and Kui Mok},
      title     = {A Data Mining Framework for Building Intrusion Detection Models},
      booktitle = {Proceedings of the 1999 IEEE Symposium on Security and Privacy},
      month     = {may},
      year      = {1999}
    }
  180. Wenke Lee, Sal Stolfo, and Kui Mok. Mining Audit Data to Build Intrusion Detection Models (Honorable mention (runner-up) for Best Paper Award in Applied Research Category). Proceedings of the Fourth International Conference on Knowledge Discovery and Data Mining (KDD '98), New York, NY, August 1998.
    BibTeX
    @inproceedings{lee1998mining,
      author    = {Wenke Lee and Sal Stolfo and Kui Mok},
      title     = {Mining Audit Data to Build Intrusion Detection Models (Honorable mention (runner-up) for Best Paper Award in Applied Research Category)},
      booktitle = {Proceedings of the Fourth International Conference on Knowledge Discovery and Data Mining (KDD '98)},
      month     = {aug},
      year      = {1998}
    }
  181. Wenke Lee and Sal Stolfo. Data Mining Approaches for Intrusion Detection. Proceedings of the Seventh USENIX Security Symposium (SECURITY '98), San Antonio, TX, January 1998.
    BibTeX
    @inproceedings{lee1998data,
      author    = {Wenke Lee and Sal Stolfo},
      title     = {Data Mining Approaches for Intrusion Detection},
      booktitle = {Proceedings of the Seventh USENIX Security Symposium (SECURITY '98)},
      month     = {jan},
      year      = {1998}
    }
  182. Sal Stolfo, Andreas Prodromidis, Shelley Tselepis, Wenke Lee, Wei Fan, and Phil Chan. JAM: Java Agents for Meta-learning over Distributed Databases (Honorable mention (runner-up) for Best Paper Award in Applied Research Category). Proceedings of the Third International Conference on Knowledge Discovery and Data Mining (KDD '97), Newport Beach, CA, August 1997.
    BibTeX
    @inproceedings{stolfo1997jam,
      author    = {Sal Stolfo and Andreas Prodromidis and Shelley Tselepis and Wenke Lee and Wei Fan and Phil Chan},
      title     = {{JAM}: Java Agents for Meta-learning over Distributed Databases (Honorable mention (runner-up) for Best Paper Award in Applied Research Category)},
      booktitle = {Proceedings of the Third International Conference on Knowledge Discovery and Data Mining (KDD '97)},
      month     = {aug},
      year      = {1997}
    }
  183. Naser S. Barghouti, John Mocenigo, and Wenke Lee. Grappa: A GRAPh PAckage in Java. Proceedings of the Fifth Annual Symposium on Graph Drawing (Graph Drawing '97), Rome, Italy, September 1997.
    BibTeX
    @inproceedings{barghouti1997grappa,
      author    = {Naser S. Barghouti and John Mocenigo and Wenke Lee},
      title     = {Grappa: A {GRAPh} {PAckage} in Java},
      booktitle = {Proceedings of the Fifth Annual Symposium on Graph Drawing (Graph Drawing '97)},
      month     = {sep},
      year      = {1997}
    }
  184. Wenke Lee, Gail Kaiser, Paul Clayton, and Eric Sherman. OzCare: A Workflow Automation System for Care Plans. Proceedings of the American Medical Informatics Association Annual Fall Symposium, Washington DC, October 1996.
    BibTeX
    @inproceedings{lee1996ozcare,
      author    = {Wenke Lee and Gail Kaiser and Paul Clayton and Eric Sherman},
      title     = {{OzCare}: A Workflow Automation System for Care Plans},
      booktitle = {Proceedings of the American Medical Informatics Association Annual Fall Symposium},
      month     = {oct},
      year      = {1996}
    }

Papers in Workshops

  1. Yi-an Huang and Wenke Lee. Hotspot-Based Traceback for Mobile Ad Hoc Networks. In Proceedings of The ACM Workshop on Wireless Security (WiSe 2005), Cologne, Germany, September 2005.
    BibTeX
    @inproceedings{huang2005hotspot,
      author    = {Yi-an Huang and Wenke Lee},
      title     = {{Hotspot-Based} Traceback for Mobile Ad Hoc Networks},
      booktitle = {Proceedings of The ACM Workshop on Wireless Security (WiSe 2005)},
      month     = {sep},
      year      = {2005}
    }
  2. Monirul Sharif, George Riley, and Wenke Lee. Comparative Study between Analytical Models and Packet-Level Worm Simulations. In Proceedings of The 19th Workshop on Parallel and Distributed Simulation (PADS 2005), Monterey, CA, June 2005.
    BibTeX
    @inproceedings{sharif2005comparative, title={Comparative Study between Analytical Models and Packet-Level Worm Simulations}, url={http://dx.doi.org/10.1109/pads.2005.5}, DOI={10.1109/pads.2005.5}, booktitle={Workshop on Principles of Advanced and Distributed Simulation (PADS′05)}, publisher={IEEE}, author={Sharif, M.I. and Riley, G.F. and Wenke Lee}, pages={88--98}, year={2005} }
  3. Chris Clark, Wenke Lee, David Schimmel, Didier Contis, Mohamed Kone, Ashley Thomas, and Craig Wampler. A Hardware Platform for Network Intrusion Detection and Prevention. In Proceedings of The 3rd Workshop on Network Processors and Applications (NP3), Madrid, Spain, February 2004.
    BibTeX
    @inproceedings{clark2004hardware,
      author    = {Chris Clark and Wenke Lee and David Schimmel and Didier Contis and Mohamed Kone and Ashley Thomas and Craig Wampler},
      title     = {A Hardware Platform for Network Intrusion Detection and Prevention},
      booktitle = {Proceedings of The 3rd Workshop on Network Processors and Applications (NP3)},
      month     = {feb},
      year      = {2004}
    }
  4. Yian Huang and Wenke Lee. A Cooperative Intrusion Detection System for Ad Hoc Networks. In Proceedings of the ACM Workshop on Security of Ad Hoc and Sensor Networks (SASN '03), Fairfax VA, October 2003.
    BibTeX
    @inproceedings{huang2003cooperative,
      author    = {Yian Huang and Wenke Lee},
      title     = {A Cooperative Intrusion Detection System for Ad Hoc Networks},
      booktitle = {Proceedings of the ACM Workshop on Security of Ad Hoc and Sensor Networks (SASN '03)},
      month     = {oct},
      year      = {2003}
    }
  5. Mustaque Ahamad, Wenke Lee, Ling Liu, Leo Mark, Edward Omicienski, Calton Pu, and Andre dos Santos. Guarding the Next Internet Frontier: Countering Denial of Information Attacks. Proceedings of the 2002 New Security Paradigms Workshop, Virginia Beach, Virginia, September 2002.
    BibTeX
    @inproceedings{ahamad2002guarding, series={NSPW02}, title={Guarding the next Internet frontier: countering denial of information attacks}, url={http://dx.doi.org/10.1145/844102.844126}, DOI={10.1145/844102.844126}, booktitle={Proceedings of the 2002 workshop on New security paradigms}, publisher={ACM}, author={Ahamad, Mustaque and Mark, Leo and Lee, Wenke and Omicienski, Edward and Santos, Andre dos and Liu, Ling and Pu, Calton}, year={2002}, month=Sept, pages={136--143}, collection={NSPW02} }
  6. Xinzhou Qin, Wenke Lee, Lundy Lewis, and Joao B. D. Cabrera. Using MIB II Variables for Network Anomaly Detection - A Feasibility Study. ACM Workshop on Data Mining for Security Applications, Philadelphia, PA, November 2001.
    BibTeX
    @inproceedings{qin2001using,
      author    = {Xinzhou Qin and Wenke Lee and Lundy Lewis and Joao B. D. Cabrera},
      title     = {Using {MIB} {II} Variables for Network Anomaly Detection - A Feasibility Study},
      booktitle = {ACM Workshop on Data Mining for Security Applications},
      month     = {nov},
      year      = {2001}
    }
  7. Wenke Lee, Rahul Nimbalkar, Kam Yee, Sunil Patil, Pragnesh Desai, Thuan Tran, and Sal Stolfo. A Data Mining and CIDF Based Approach for Detecting Novel and Distributed Intrusions. Proceedings of The Third International Workshop on Recent Advances in Intrusion Detection (RAID 2000), LNCS 1907, Toulouse, France, October 2000.
    BibTeX
    @inproceedings{lee2000data,
      author    = {Wenke Lee and Rahul Nimbalkar and Kam Yee and Sunil Patil and Pragnesh Desai and Thuan Tran and Sal Stolfo},
      title     = {A Data Mining and {CIDF} Based Approach for Detecting Novel and Distributed Intrusions},
      booktitle = {Proceedings of The Third International Workshop on Recent Advances in Intrusion Detection (RAID 2000)},
      month     = {oct},
      year      = {2000}
    }
  8. Wenke Lee, Wei Fan, Matt Miller, Sal Stolfo, and Erez Zadok. Toward Cost-Sensitive Modeling for Intrusion Detection and Response. ACM Workshop on Intrusion Detection Systems, Athens, Greece, November 2000.
    BibTeX
    @inproceedings{lee2000cost,
      author    = {Wenke Lee and Wei Fan and Matt Miller and Sal Stolfo and Erez Zadok},
      title     = {Toward {Cost-Sensitive} Modeling for Intrusion Detection and Response},
      booktitle = {ACM Workshop on Intrusion Detection Systems},
      month     = {nov},
      year      = {2000}
    }
  9. Wenke Lee, Chris Park, and Sal Stolfo. Towards Automatic Intrusion Detection using NFR. 1st USENIX Workshop on Intrusion Detection and Network Monitoring, April 1999.
    BibTeX
    @inproceedings{lee1999automatic,
      author    = {Wenke Lee and Chris Park and Sal Stolfo},
      title     = {Towards Automatic Intrusion Detection using {NFR}},
      booktitle = {1st USENIX Workshop on Intrusion Detection and Network Monitoring},
      month     = {apr},
      year      = {1999}
    }
  10. Wenke Lee, Sal Stolfo, and Phil Chan. Learning Patterns from Unix Process Execution Traces for Intrusion Detection. AAAI Workshop: AI Approaches to Fraud Detection and Risk Management, July 1997.
    BibTeX
    @inproceedings{lee1997learning,
      author    = {Wenke Lee and Sal Stolfo and Phil Chan},
      title     = {Learning Patterns from Unix Process Execution Traces for Intrusion Detection},
      booktitle = {AAAI Workshop: AI Approaches to Fraud Detection and Risk Management},
      month     = {jul},
      year      = {1997}
    }
  11. Sal Stolfo, Wei Fan, Wenke Lee, Andreas Prodromidis, and Phil Chan. Credit Card Fraud Detection Using Meta-Learning: Issues and Initial Results. AAAI Workshop: AI Approaches to Fraud Detection and Risk Management, July 1997.
    BibTeX
    @inproceedings{stolfo1997credit,
      author    = {Sal Stolfo and Wei Fan and Wenke Lee and Andreas Prodromidis and Phil Chan},
      title     = {Credit Card Fraud Detection Using {Meta-Learning}: Issues and Initial Results},
      booktitle = {AAAI Workshop: AI Approaches to Fraud Detection and Risk Management},
      month     = {jul},
      year      = {1997}
    }
  12. Gail Kaiser and Wenke Lee. Pay No Attention to the Man Behind the Curtain. NSF Workshop on Workflow and Process Automation, May 1996.
    BibTeX
    @inproceedings{kaiser1996pay,
      author    = {Gail Kaiser and Wenke Lee},
      title     = {Pay No Attention to the Man Behind the Curtain},
      booktitle = {NSF Workshop on Workflow and Process Automation},
      month     = {may},
      year      = {1996}
    }
  13. Wenke Lee. Data Modeling and Management for Large Spatial Databases. The Third International Workshop in Geographic Information Systems, Beijing, China, August 1993.
    BibTeX
    @inproceedings{lee1993data,
      author    = {Wenke Lee},
      title     = {Data Modeling and Management for Large Spatial Databases},
      booktitle = {The Third International Workshop in Geographic Information Systems},
      month     = {aug},
      year      = {1993}
    }

Others

  1. Wenke Lee. Machine Learning and Security: The Good, The Bad, and The Ugly (keynote). In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 2020.
    BibTeX
    @inproceedings{lee2020machine, series={CCS ’20}, title={Machine Learning and Security: The Good, The Bad, and The Ugly}, url={http://dx.doi.org/10.1145/3372297.3424552}, DOI={10.1145/3372297.3424552}, booktitle={Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Lee, Wenke}, year={2020}, month=Oct, pages={1--2}, collection={CCS ’20} }
  2. Matt Blaze, Sampath Kannan, Insup Lee, Oleg Sokolsky, Jonathan Smith, Angelos Keromytis, and Wenke Lee. Dynamic Trust Management. In IEEE Computer, February 2009.
    BibTeX
    @article{blaze2009dynamic, title={Dynamic Trust Management}, volume={42}, ISSN={0018-9162}, url={http://dx.doi.org/10.1109/mc.2009.51}, DOI={10.1109/mc.2009.51}, number={2}, journal={Computer}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Blaze, Matt and Kannan, Sampath and Lee, Insup and Sokolsky, Oleg and Smith, Jonathan M. and Keromytis, Angelos D. and Lee, Wenke}, year={2009}, month=Feb, pages={44--52} }
  3. Martim Carbone, Diego Zamboni, and Wenke Lee. Taming Virtualization. In IEEE Security & Privacy, 6(1), January/February 2008.
    BibTeX
    @article{carbone2008taming, title={Taming Virtualization}, volume={6}, ISSN={1540-7993}, url={http://dx.doi.org/10.1109/msp.2008.24}, DOI={10.1109/msp.2008.24}, number={1}, journal={IEEE Security \& Privacy Magazine}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Carbone, Martim and Zamboni, Diego and Lee, Wenke}, year={2008}, pages={65--67} }
  4. Bryan D. Payne, Reiner Sailer, Ramon Caceres, Ronald Perez, and Wenke Lee. A Layered Approach to Simplified Access Control in Virtualized Systems. In ACM SIGOPS Operating Systems Review, 4(2), July 2007.
    BibTeX
    @article{payne2007layered, title={A layered approach to simplified access control in virtualized systems}, volume={41}, ISSN={0163-5980}, url={http://dx.doi.org/10.1145/1278901.1278905}, DOI={10.1145/1278901.1278905}, number={4}, journal={ACM SIGOPS Operating Systems Review}, publisher={Association for Computing Machinery (ACM)}, author={Payne, Bryan D. and Sailer, Reiner and Cáceres, Ramón and Perez, Ron and Lee, Wenke}, year={2007}, month=July, pages={12--19} }
  5. Wenke Lee. Applying Data Mining to Intrusion Detection: The Quest for Automation, Efficiency, and Credibility. SIGKDD Explorations, 4(2), December 2002.
    BibTeX
    @article{lee2002applying, title={Applying data mining to intrusion detection: the quest for automation, efficiency, and credibility}, volume={4}, ISSN={1931-0153}, url={http://dx.doi.org/10.1145/772862.772868}, DOI={10.1145/772862.772868}, number={2}, journal={ACM SIGKDD Explorations Newsletter}, publisher={Association for Computing Machinery (ACM)}, author={Lee, Wenke}, year={2002}, month=Dec, pages={35--42} }
  6. Wenke Lee and Wei Fan. Mining System Audit Data: Opportunities and Challenges. SIGMOD Record, 30(4), December 2001.
    BibTeX
    @article{lee2001mining, title={Mining system audit data: opportunities and challenges}, volume={30}, ISSN={0163-5808}, url={http://dx.doi.org/10.1145/604264.604270}, DOI={10.1145/604264.604270}, number={4}, journal={ACM SIGMOD Record}, publisher={Association for Computing Machinery (ACM)}, author={Lee, Wenke and Fan, Wei}, year={2001}, month=Dec, pages={35--44} }
  7. Salvatore J. Stolfo, Wenke Lee, Philip K. Chan, Wei Fan, and Eleazar Eskin. Data Mining-Based Intrusion Detectors: An Overview of the Columbia IDS Project. SIGMOD Record, 30(4), December 2001.
    BibTeX
    @article{stolfo2001data, title={Data mining-based intrusion detectors: an overview of the columbia IDS project}, volume={30}, ISSN={0163-5808}, url={http://dx.doi.org/10.1145/604264.604267}, DOI={10.1145/604264.604267}, number={4}, journal={ACM SIGMOD Record}, publisher={Association for Computing Machinery (ACM)}, author={Stolfo, Salvatore J. and Lee, Wenke and Chan, Philip K. and Fan, Wei and Eskin, Eleazar}, year={2001}, month=Dec, pages={5--14} }

Ph.D. Thesis