NCSU SoS Lablet Quarterly Executive Summary

A. Fundamental Research
We continued to produce science of security outcomes. The following are the major contributions from Lablet projects.


  • We built a dataflow-based static program analysis tool for Payment Service Provider (PSP) libraries for mobile Android apps store security-critical information. This tool generates warnings based on modeling interrelated rules that sometimes seem to allow or disallow the same action.
  • We refined and evaluated our framework for identifying rogue apps (those that violate privacy expectations) based on app reviews. Our method achieves a higher F1 score than the previous approach and provides a high recall of 89%, which is a more valuable metric than precision in that it captures more rogue apps for further scrutiny.
  • We implemented three approaches based on natural language processing with respect to their effectiveness in extracting attacker techniques from cyberthreat intelligence (CTI) reports. We compared these approaches using the MITRE ATT%CK dataset.

B. Community Engagement(s)
We brought up the Science of Security in a variety of fora, including

  • Three Secure Software Supply Chain summits that we conducted.  Two of the summits were with industrial organizations involving 24 organizations.  One summit was with five government organizations.
  • Discussions with non-lablet colleagues locally and at other universities.


C. Educational Advances
C. Educational Advances