Saumya Debray
· ProfessorUniversity of Arizona · Computer Science & Engineering
Active 1984–2025
Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.
About
Saumya Debray is a Professor of Computer Science at The University of Arizona, where he has been a faculty member since August 1986. He received a B.Tech. (Hons.) degree in Electronics and Electrical Communications Engineering from the Indian Institute of Technology, Kharagpur, in 1981; and M.S. and Ph.D. degrees in computer science from the State University of New York at Stony Brook, in 1983 and 1986 respectively. His research interests are primarily in the area of compilers and language implementation, focusing on low-level program analysis, transformation, and optimization. Currently, he is working on software security and malware analysis in the context of the lynx project. In his spare time, he enjoys hiking and backpacking, and plays very mediocre chess.
Research topics
- Computer Science
- Parallel computing
- Operating system
- Programming language
- Embedded system
- Computer architecture
Selected publications
A Generic Approach to Automatic Deobfuscation of Executable Code
2015-05-01 · 193 citations
articleOpen accessSenior authorMalicious software are usually obfuscated to avoid detection and resist analysis. When new malware is encountered, such obfuscations have to be penetrated or removed ("deobfuscated") in order to understand the internal logic of the code and devise countermeasures. This paper discusses a generic approach for deobfuscation of obfuscated executable code. Our approach does not make any assumptions about the nature of the obfuscations used, but instead uses semantics-preserving program transformation…
Symbolic Execution of Obfuscated Code
2015-10-06 · 85 citations
articleSenior authorSymbolic and concolic execution find important applications in a number of security-related program analyses, including analysis of malicious code. However, malicious code tend to very often be obfuscated, and current concolic analysis tech-niques have trouble dealing with some of these obfuscations, leading to imprecision and/or excessive resource usage. This paper discusses three such obfuscations: two of these are al-ready found in obfuscation tools used by malware, while the third is a simpl…
2014-09-01 · 32 citations
articleSenior authorTaint analysis has a wide variety of applications in software analysis, making the precision of taint analysis an important consideration. Current taint analysis algorithms, including previous work on bit-precise taint analyses, suffer from shortcomings that can lead to significant loss of precision (under/over tainting) in some situations. This paper discusses these limitations of existing taint analysis algorithms, shows how they can lead to imprecise taint propagation, and proposes a generali…
Identifying and Understanding Self-Checksumming Defenses in Software
2015-02-23 · 21 citations
articleSoftware self-checksumming is widely used as an anti-tampering mechanism for protecting intellectual property and deterring piracy. This makes it important to understand the strengths and weaknesses of various approaches to self-checksumming. This paper describes a dynamic information-flow-based attack that aims to identify and understand self-checksumming behavior in software. Our approach is applicable to a wide class of self chesumming defenses and the information obtained can be used to dete…
A Framework for Understanding Dynamic Anti-Analysis Defenses
2014-12-09 · 17 citations
articleMalicious code often use a variety of anti-analysis and anti-tampering defenses to hinder analysis. Researchers trying to understand the internal logic of the malware have to penetrate these defenses. Existing research on such anti-analysis defenses tend to study them in isolation, thereby failing to see underlying conceptual similarities between different kinds of anti-analysis defenses. This paper proposes an information-flow-based framework that encompasses a wide variety of anti-analysis def…
Recent grants
TC: Small: Simplification of Obfuscated Executables
NSF · $401k · 2011–2015
SaTC: CORE: Small: Reasoning about dependencies and information flow in dynamic code
NSF · $515k · 2019–2023
TWC: Small: Understanding Anti-Analysis Defenses in Malicious Code
NSF · $547k · 2015–2019
Frequent coauthors
- 16 shared
Maurice Bruynooghe
KU Leuven
- 16 shared
M. Hermenegildo
Universidad Politécnica de Madrid
- 16 shared
Michael J. Maher
- 9 shared
Babak Yadegari
University of Arizona
- 9 shared
Robert Muth
- 8 shared
David S. Warren
- 7 shared
Peter A. Bigot
- 7 shared
Gregory R. Andrews
University of Massachusetts Chan Medical School
Similar researchers at University of Arizona
- Resume-aware match score
- Save to shortlist
- AI-drafted outreach
See your match with Saumya Debray
PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.
- Free to start
- No credit card
- 30-second signup
