People / Faculty / William Enck

William Enck

  • Goodnight Distinguished Professor
  • Director of the Wolfpack Security and Privacy Research (WSPR) laboratory
  • Co-Director of the Secure Computing Institute
  • Member of the Secure Software Supply Chain Center (S3C2)
Profile photo of William Enck

Bio

William Enck is a Professor in the Department of Computer Science at the North Carolina State University where he is co-director of the Secure Computing Institute (SCI) and director of the Wolfpack Security and Privacy Research (WSPR) laboratory. Prof. Enck’s research interests span the broad area of systems security with applications to the software supply chain, 5G and cloud infrastructure, mobile platforms, Internet of Things (IoT), and networks. In particular, his work in mobile application security has led to significant consumer awareness and changes to platforms, as well as a SIGOPS Hall of Fame Award. He is currently serving as Secretary for the USENIX Board of Directors, as associate editor for ACM TOPS, and on the steering committee of the USENIX Security Symposium. He was program co-chair of USENIX Security 2018 and is program co-chair of the 2024 and 2025 IEEE Symposium on Security and Privacy (S&P). Prior to joining NC State, Prof. Enck earned his Ph.D., M.S., and B.S in Computer Science and Engineering from the Pennsylvania State University in 2011, 2006, and 2004, respectively. Prof. Enck is a member of the ACM, IEEE, ISSA, and USENIX.

Publications

  • Seaver Thorn, Nathaniel Bennett, Kevin Butler, Patrick Traynor, and William Enck, ASN1spect: Uncovering ASN.1 Compiler-Generated Vulnerabilities in Critical Infrastructure, in Proceedings of the ACM Secure Development Conference (SecDev), Jul. 2026.
  • Greg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil, Antonio Bianchi, Aravind Machiry, Alexandros Kapravelos, and William Enck, Cosseter: GitHub Actions Permission Reduction Using Demand-Driven Static Analysis, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), May 2026.
  • Nathaniel Bennett, Tyler Tucker, Carson Stillman, William Enck, Patrick Traynor, and Kevin Butler, Fizzle: A Framework for Deterministic and Reproducible Network Fuzzing, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), May 2026.
  • Imranur Rahman, Jill Marley, William Enck, and Laurie Williams, Which Is Better For Reducing Outdated And Vulnerable Dependencies: Pinning Or Floating?, in Proceedings of the IEEE/ACM International Conference on Automated Software Engineering, Nov. 2025.
  • Elizabeth Lin, Sparsha Gowda, William Enck, and Dominik Wermke, Context Matters: Qualitative Insights into Developers’ Approaches and Challenges with Software Composition Analysis, in Proceedings of the USENIX Security Symposium, Aug. 2025.
  • Ben Weintraub, Chanyuan Liu, William Enck, and Cristina Nita-Rotaru, ProfessorX: Detecting Silent Vulnerabilities in Policy Engine Implementations, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jul. 2025.
  • Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, and William Enck, Research Directions in Software Supply Chain Security, ACM Transactions on Software Engineering Methodology (TOSEM), pp. 1–38, May 2025.
    [PDF]
  • Giacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl, William Enck, Christian Kästner, Alexandros Kapravelos, Alessio Merlo, and Luca Verderame, An Empirical Study on Reproducible Packaging in Open-Source Ecosystems, in Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), Apr. 2025.
  • Nathaniel Bennett, Weidong Zhu, Benjamin Simon, Ryon Kennedy, William Enck, Patrick Traynor, and Kevin Butler, RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces, in Proceedings of the ACM Conference on Computer and Communications Security (CCS), Oct. 2024.
  • Nusrat Zahan, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2023-11: Industry Secure Supply Chain Summit. Aug-2024. arXiv:2408.16529.
    [PDF]
  • Trevor Dunlap, John Speed Meyers, Brad Reaves, and William Enck, Pairing Security Advisories with Vulnerable Functions Using Open-Source LLMs, in Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), Jul. 2024.
  • Trevor Dunlap, Elizabeth Lin, William Enck, and Bradley Reaves, VFCFinder: Pairing Security Advisories and Patches, in Proceedings of the ACM ASIA Conference on Computer and Communications Security (AsiaCCS), Jul. 2024.
  • K. Virgil English, Nathaniel Bennett, Seaver Thorn, Kevin Butler, William Enck, and Patrick Traynor, Examining Cryptography and Randomness Failures in Open-Source Cellular Cores, in Proceedings of the ACM Conference on Data and Application Security and Privacy (CODASPY), Jun. 2024.
  • Seaver Thorn, K. Virgil English, Kevin Butler, and William Enck, 5GAC-Analyzer: Identifying Over-Privilege Between 5G Core Network Functions, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2024.
  • Isaac Polinsky, Pubali Datta, Adam Bates, and William Enck, GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security Policies, in Proceedings of ACM The Web Conference, May 2024.
  • Greg Tystahl, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2024-03: Industry Secure Supply Chain Summit. May-2024. arXiv:2405.08762.
    [PDF]
  • Elizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck, and Alexandros Kapravelos, UntrustIDE: Exploiting Weaknesses in VS Code Extensions, in Proceedings of the ISOC Network and Distributed Systems Symposium (NDSS), Feb. 2024.
  • Yu-Tsung Lee, Haining Chen, William Enck, Hayawardh Vijayakumar, Ninghui Li, Zhiyun Qian, Giuseppe Petracca, and Trent Jaeger, PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage, IEEE Transactions on Dependable and Secure Computing, Aug. 2023. (early access).
  • Siddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl, Brad Reaves, Antonio Bianchi, William Enck, Alexandros Kapravelos, and Aravind Machiry, ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions, in Proceedings of the USENIX Security Symposium, Aug. 2023.
  • William Enck, Yasemin Acar, Michel Cukier, Alexandros Kapravelos, Christian Kästner, and Laurie Williams, S3C2 Summit 2023-06: Government Secure Supply Chain Summit. Aug-2023. arXiv:2308.06850.
    [PDF]
  • Trevor Dunlap, Seaver Thorn, William Enck, and Bradley Reaves, Finding Fixed Vulnerabilities with Off-the-Shelf Static Analysis, in Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), Jul. 2023.
  • Trevor Dunlap, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, and Laurie Williams, S3C2 Summit 2023-02: Industry Secure Supply Chain Summit. Jul-2023. arXiv:2307.16557.
    [PDF]
  • Mindy Tran, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, and Laurie Williams, S3C2 Summit 2022-09: Industry Secure Suppy Chain Summit. Jul-2023. arXiv:2307.15642.
    [PDF]
  • Iffat Anjum, Jessica Sokal, Hafiza Ramzah Rehman, Ben Weintraub, Ethan Leba, William Enck, Cristina Nitarotaru, and Bradley Reaves, MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2023.
  • Marcel Fourné, Dominik Wermke, William Enck, Sascha Fahl, and Yasemin Acar, It’s like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), May 2023.
  • Nusrat Zahan, Elizabeth Lin, Mahzabin Tamanna, William Enck, and Laurie Williams, Software Bills of Materials Are Required. Are We There Yet?, IEEE Security and Privacy Magazine, vol. 21, no. 2, pp. 82–88, Mar. 2023. (column).
  • Mohammad Sujan Miah, Mu Zhu, Alonso Granados, Nazia Sharmin, Iffat Anjum, Anthony Ortiz, Christopher Kiekintveld, William Enck, and Munindar P. Singh, Optimizing Honey Traffic Using Game Theory and Adversarial Learning, in Cyber Deception: Techniques, Strategies, and Human Aspects, Cham: Springer International Publishing, 2023, pp. 97–124.
    [PDF]
  • Samin Yaseer Mahmud, K. Virgil English, Seaver Thorn, William Enck, Adam Oest, and Muhammad Saad, Analysis of Payment Service Provider SDKs in Android, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), Dec. 2022.
  • Pubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates, and William Enck, ALASTOR: Reconstructing the Provenance of Serverless Intrusions, in Proceedings of the USENIX Security Symposium, Aug. 2022.
  • Sigmund Albert Gorski III, Seaver Thorn, William Enck, and Haining Chen, FReD: Identifying File Re-Delegation in Android System Services, in Proceedings of the USENIX Security Symposium, Aug. 2022.
  • Iffat Anjum, Daniel Kostecki, Ethan Leba, Jessica Sokal, Rajit Bharambe, William Enck, Cristina Nita-Rotaru, and Bradley Reaves, Removing the Reliance on Perimeters for Security using Network Views, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2022. (best student paper).
  • Trevor Dunlap, William Enck, and Bradley Reaves, A Study of Application Sandbox Policies in Linux, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2022.
  • Samin Yaseer Mahmud and William Enck, A Study of Security Weaknesses in Android Payment Service Provider SDKs, in Proceedings of the Symposium and Bootcamp on the Science of Security (HotSoS) Poster Session, Apr. 2022.
  • William Enck and Laurie Williams, Top Five Challenges in Software Supply Chain Security: Observations From 30 Industry and Government Organizations, IEEE Security and Privacy Magazine, vol. 20, no. 2, pp. 96–100, Mar. 2022. (column).
  • Yu-Tsung Lee, William Enck, Haining Chen, Zhiyun Qian, Ninghui Li, Hayawardh Vijayakumar, Trent Jaeger, Giuseppe Petracca, and Daimeng Wang, PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems, in Proceedings of the USENIX Security Symposium, Aug. 2021.
  • Isaac Polinsky, Pubali Datta, Adam Bates, and William Enck, SCIFFS: Enabling Secure Third-Party Security Analytics using Serverless Computing, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2021.
  • Iffat Anjum, Mu Zhu, Isaac Polinsky, William Enck, Michael K. Reiter, and Munindar Singh, Role-Based Deception in Enterprise Networks, in Proceedings of the ACM Conference on Data and Application Security and Privacy (CODASPY), Apr. 2021.
  • Christopher Lentzsch, Sheel Jayesh Shah, Martin Degeling, Benjamin Andow, Anupam Das, and William Enck, Hey Alexa, is this Skill Safe?: Taking a Closer Look at the Alexa Skill Ecosystem, in Proceedings of the ISOC Network and Distributed Systems Symposium (NDSS), Feb. 2021.
  • Richard Mitev, Anna Pazii, Markus Miettinen, William Enck, and Ahmad-Reza Sadeghi, LeakyPick: IoT Audio Spy Detector, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), Dec. 2020.
    (acceptance rate=23.2%)
  • Rayhanur Rahman, William Enck, and Laurie Williams, Do Configuration Management Tools Make Systems More Secure? An Empirical Research Plan, in Proceedings of the Symposium and Bootcamp on the Science of Security (HotSoS) Poster Session, Sep. 2020.
  • Samin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck, and Bradley Reaves, Cardpliance: PCI DSS Compliance of Android Applications, in Proceedings of the USENIX Security Symposium, Boston, MA, Aug. 2020.
    (acceptance rate=16.3%)
  • Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Serge Egelman, Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheck, in Proceedings of the USENIX Security Symposium, Boston, MA, Aug. 2020.
    (acceptance rate=16.3%)
  • Luke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu, and William Enck, Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, May 2020.
    (acceptance rate=12.3%)
  • Isaac Polinsky, Kyle Martin, William Enck, and Mike Reiter, n-m-Variant Systems: Adversarial-Resistant Software Rejuvenation for Cloud-Based Web Applications, in Proceedings of the ACM Conference on Data and Application Security and Privacy (CODASPY), New Orleans, LA, Mar. 2020.
    (acceptance rate=20%)
  • Mu Zhu, Mohammad Miah, Nazia Sharmin, Iffat Anjum, Christopher Kiekintveld, William Enck, and Munindar Singh, Optimizing Vulnerability-Driven Honey Traffic Using Game Theory, in Proceedings of the AAAI Workshop on Artificial Intelligence for Cyber Security (AICS), Feb. 2020.
  • Justin Whitaker, Sathvik Prasad, Bradley Reaves, and William Enck, Thou Shalt Discuss Security: Quantifying the Impacts of Instructions to RFC Authors, in Proceedings of the Security Standardisation Research Conference, Nov. 2019.
    (acceptance rate=35%)
  • Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie, PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play, in Proceedings of the USENIX Security Symposium, Santa Clara, CA, Aug. 2019.
  • TJ OConnor, Reham Mohamed, Markus Miettinen, William Enck, Bradley Reaves, and Ahmad-Reza Sadeghi, HomeSnitch: Behavior Transparency and Control for Smart Home IoT Devices, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019.
    (acceptance rate=25.6%)
  • TJ OConnor, William Enck, and Bradley Reaves, Blinded and Confused: Uncovering Systemic Flaws in Device Telemetry for Smart-Home Internet of Things, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019.
    (acceptance rate=25.6%)
  • Sigmund Albert Gorski III and William Enck, ARF: Identifying Re-Delegation Vulnerabilities in Android System Services, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019.
    (acceptance rate=25.6%)
  • Sanket Goutam, William Enck, and Bradley Reaves, Hestia: Simple Least Privilege Network Policies for Smart Homes, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019. (short paper).
    (acceptance rate=32.2%)
  • Sigmund Albert Gorski III, Benjamin Andow, Adwait Nadkarni, Sunil Manandhar, William Enck, Eric Bodden, and Alexandre Bartel, ACMiner: Extraction and Analysis of Authorization Checks in Android’s Middleware, in Proceedings of the ACM Conference on Data and Application Security and Privacy (CODASPY), Dallas, TX, Mar. 2019.
    [PDF] (acceptance rate=23.5%)
  • Sigmund Albert Gorski III, Benjamin Andow, Adwait Nadkarni, Sunil Manandhar, William Enck, Eric Bodden, and Alexandre Bartel, ACMiner: Extraction and Analysis of Authorization Checks in Android’s Middleware, arXiv:1901.03603, Jan. 2019.
    [PDF] (extends gan+19)
  • Reham Mohamed, Terrence O’Connor, Markus Miettinen, William Enck, and Ahmad-Reza Sadeghi, HONEYSCOPE: IoT Device Protection with Deceptive Network Views, in Autonomous Cyber Deception: Reasoning, Adaptive Planning, and Evaluation of HoneyThings, E. Al-Shaer, J. Wei, K. W. Hamlen, and C. Wang, Eds. Springer, 2019.
    [PDF]
  • Luke Deshotels, Razvan Deaconescu, Costin Carabas, Iulia Manda, William Enck, Mihai Chiroiu, Ninghui Li, and Ahmad-Reza Sadeghi, iOracle: Automated Evaluation of Access Control Policies in iOS, in Proceedings of the ACM Asia Conference on Computer and Communications Security (ASIACCS), Songdo, Incheon, Korea, Jun. 2018.
    [PDF] (acceptance rate=20.0%)
  • TJ OConnor, William Enck, W. Michael Petullo, and Akash Verma, PivotWall: SDN-Based Information Flow Control, in Proceedings of the ACM Symposium on SDN Research (SOSR), Los Angeles, CA, Mar. 2018.
    (acceptance rate=28.6%)
  • Haining Chen, Ninghui Li, William Enck, Yousra Aafer, and Xiangyu Zhang, Analysis of SEAndroid Policies: Combining MAC and DAC in Android, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), San Juan, Puerto Rico, USA, Dec. 2017.
    (acceptance rate=19.7%)
  • Adwait Nadkarni, Akash Verma, Vasant Tendulkar, and William Enck, Reliable Ad Hoc Smartphone Application Creation for End Users, in Intrusion Detection and Prevention for Mobile Ecosystems, CRC Press, Jul. 2017.
    [PDF]
  • Benjamin Andow, Akhil Acharya, Dengfeng Li, William Enck, Kapil Singh, and Tao Xie, UiRef: Analysis of Sensitive User Inputs in Android Applications, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), Jul. 2017.
    [PDF] (acceptance rate=22.3%)
  • Ruowen Wang, Ahmed M. Azab, William Enck, Ninghui Li, Peng Ning, Xun Chen, Wenbo Shen, and Yueqiang Cheng, SPOKE: Scalable Knowledge Collection and Attack Surface Analysis of Access Control Policy for Security Enhanced Android, in Proceedings of the ACM Asia Conference on Computer and Communications Security (ASIACCS), Apr. 2017.
    (acceptance rate=18.7%)
  • Rui Shu, Xiaohui Gu, and William Enck, A Study of Security Vulnerabilities on Docker Hub, in Proceedings of the ACM Conference on Data and Application Security and Privacy (CODASPY), Scottsdale, Arizona, Mar. 2017.
  • Stephan Heuser, Bradley Reaves, Praveen Kumar Pendyala, Henry Carter, Alexandra Dmitrienko, William Enck, Negar Kiyavash, Ahmad-Reza Sadeghi, and Patrick Traynor, Phonion: Practical Protection of Metadata in Telephony Networks, Proceedings on Privacy Enhancing Technologies (PoPETS), vol. 2017, no. 1, Jan. 2017.
  • Bradley Reaves, Jasmine Bowers, Sigmund Albert Gorski III, Olabode Anise, Rahul Bobhate, Raymond Cho, Hiranava Das, Sharique Hussain, Hamza Karachiwala, Nolen Scaife, Byron Wright, Kevin Butler, William Enck, and Patrick Traynor, *droid: Assessment and Evaluation of Android Application Analysis Tools, ACM Computing Surveys (CSUR), vol. 2016, no. 3, Dec. 2016.
  • Rui Shu, Peipei Wang, Sigmund A. Gorski III, Benjamin Andow, Adwait Nadkarni, Luke Deshotels, Jason Gionta, William Enck, and Xiaohui Gu, A Study of Security Isolation Techniques, ACM Computing Surveys (CSUR), vol. 49, no. 3, Oct. 2016.
    [PDF]
  • Luke Deshotels, Razvan Deaconescu, Mihai Chiroiu, Lucas Davi, William Enck, and Ahmad-Reza Sadeghi, SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles, in Proceedings of the ACM Conference on Computer and Communications Security (CCS), Vienna, Austria, Oct. 2016.
    (acceptance rate=16.5%)
  • Jason Gionta, William Enck, and Per Larsen, Preventing Kernel Code-Reuse Attacks Through Disclosure Resistant Code Diversification, in Proceedings of the IEEE Conference on Communications and Network Security (CNS), Philadelphia, PA, Oct. 2016.
    (acceptance rate=29.0%)
  • Adwait Nadkarni, Benjamin Andow, William Enck, and Somesh Jha, Practical DIFC Enforcement on Android, in Proceedings of the USENIX Security Symposium, Austin, TX, Aug. 2016.
    [PDF] (acceptance rate=15.6%)
  • Terrence OConnor and William Enck, Code-Stop: Code-Reuse Prevention By Context-Aware Traffic Proxying, in Proceedings of the International Conference on Internet Monitoring and Protection (ICIMP), Valencia, Spain, May 2016.
    [PDF] (acceptance rate=28%)
  • Benjamin Andow, Adwait Nadkarni, Blake Bassett, William Enck, and Tao Xie, A Study of Grayware on Google Play, in Proceedings of the IEEE Mobile Security Technologies workshop (MoST), May 2016.
    (acceptance rate=28.6%)
  • William Enck and Adwait Nadkarni, What if the FBI tried to crack an Android phone? We attacked one to find out, The Conversation, Mar. 2016.
    [PDF]
  • Qian Liu, Anne Collins McLaughlin, Benjamin Watson, William Enck, and Agnes Davis, Multitasking Increases Stress and Insecure Behavior on Mobile Devices, in Proceedings of the International Annual Meeting of the Human Factors and Ergonomics Society (HFES), Oct. 2015, pp. 1110–1114.
    [PDF]
  • Ruowen Wang, William Enck, Douglas Reeves, Xinwen Zhang, Peng Ning, Dingbang Xu, Wu Zhou, and Ahmed Azab, EASEAndroid: Automatic Policy Analysis and Refinement for Security Enhanced Android via Large-Scale Semi-Supervised Learning, in Proceedings of the USENIX Security Symposium, Washington, DC, Aug. 2015.
    [PDF] (acceptance rate=15.7%)
  • Wei Yang, Xusheng Xiao, Benjamin Andow, Sihan Li, Tao Xie, and William Enck, AppContext: Differentiating Malicious and Benign Mobile App Behaviors Using Context, in Proceedings of the International Conference on Software Engineering (ICSE), Firenze, Italy, May 2015.
    [PDF] (acceptance rate=18.5%)
  • Jason Gionta, William Enck, and Peng Ning, HideM: Protecting the Contents of Userspace Memory in the Face of Disclosure Vulnerabilities, in Proceedings of the Fourth ACM Conference on Data and Application Security and Privacy (CODASPY), San Antonio, TX, Mar. 2015.
    [PDF] (acceptance rate=21.3%)
  • Jason Gionta, Ahmed Azab, William Enck, Peng Ning, and Xiaolan Zhang, SEER: Practical Memory Virus Scanning as a Service, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), New Orleans, LA, Dec. 2014.
    [PDF] (acceptance rate=19.9%)
  • Stephan Heuser, Adwait Nadkarni, William Enck, and Ahmad-Reza Sadeghi, ASM: A Programmable Interface for Extending Android Security, in Proceedings of the USENIX Security Symposium, San Diego, CA, Aug. 2014.
    [PDF] (acceptance rate=19.1%) (supercedes TUD-CS-2014-0063)
  • Jason Gionta, Ahmed Azab, William Enck, Peng Ning, and Xiaolan Zhang, DACSA: A Decoupled Architecture for Cloud Security Analysis, in Proceedings of the 7th Workshop on Cyber Security Experimentation and Test (CSET), Aug. 2014.
    [PDF] (acceptance rate=40.0%)
  • Adwait Nadkarni, Anmol Sheth, Udi Weinsberg, Nina Taft, and William Enck, GraphAudit: Privacy Auditing for Massive Graph Mining, North Carolina State University, Department of Computer Science, Raleigh, NC, TR-2014-10, Aug. 2014.
  • Adwait Nadkarni, Vasant Tendulkar, and William Enck, NativeWrap: Ad Hoc Smartphone Application Creation for End Users, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), Oxford, United Kingdom, Jul. 2014.
    [PDF] (acceptance rate=26.0%)
  • William Enck, Peter Gilbert, Seungyeop Han, Vasant Tendulkar, Byung-Gon Chun, Landon Cox, Jaeyeon Jung, Patrick McDaniel, and Anmol Sheth, TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones, ACM Transactions on Computer Systems (TOCS), vol. 32, no. 2, Jun. 2014.
    (extends egc+10)
  • Vasant Tendulkar and William Enck, An Application Package Configuration Approach to Mitigating Android SSL Vulnerabilities, in Proceedings of the IEEE Mobile Security Technologies workshop (MoST), May 2014.
    [PDF] (acceptance rate=36.7%)
  • Wei Yang, Xusheng Xiao, Rahul Pandita, William Enck, and Tao Xie, Improving Mobile Application Security via Bridging User Expectations and Application Behaviors, in Proceedings of the Symposium and Bootcamp on the Science of Security (HotSoS) Poster Session, Apr. 2014.
  • Agnes Davis, Ashwin Shashidharan, Qian Liu, William Enck, Anne Mclaughlin, and Benjamin Watson, Insecure Behaviors on Mobile Devices under Stress, in Proceedings of the Symposium and Bootcamp on the Science of Security (HotSoS) Poster Session, Apr. 2014.
  • Qian Liu, Juhee Bae, Benjamin Watson, and William Enck, Modeling and Sensing Risky User Behavior based on Mobile Devices, in Proceedings of the Symposium and Bootcamp on the Science of Security (HotSoS) Poster Session, Apr. 2014.
  • William Enck, Peter Gilbert, Byung-Gon Chun, Landon P. Cox, Jaeyeon Jung, Patrick McDaniel, and Anmol N. Sheth, TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones, Communications of the ACM, vol. 57, no. 3, Mar. 2014. Research Highlight.
  • Tsung-Hsuan Ho, Daniel Dean, Xiaohui Gu, and William Enck, PREC: Practical Root Exploit Containment for Android Devices, in Proceedings of the Fourth ACM Conference on Data and Application Security and Privacy (CODASPY), San Antonio, TX, Mar. 2014.
    [PDF] (acceptance rate=16.0%) (supercedes TR-2012-12)
  • Stephan Heuser, Adwait Nadkarni, William Enck, and Ahmad-Reza Sadeghi, ASM: A Programmable Interface for Extending Android Security, Intel CRI-SC at TU Darmstadt, North Carolina State University, CASED / TU Darmstadt, TUD-CS-2014-0063, Mar. 2014.
    [PDF]
  • Adwait Nadkarni and William Enck, Preventing Accidental Data Disclosure in Modern Operating Systems, in Proceedings of the 20th ACM Conference on Computer and Communications Security (CCS), Berlin, Germany, Nov. 2013.
    [PDF] (acceptance rate=19.8%)
  • Rahul Pandita, Xusheng Xiao, Wei Yang, William Enck, and Tao Xie, WHYPER: Towards Automating Risk Assessment of Mobile Applications, in Proceedings of the USENIX Security Symposium, Washington, D.C., Aug. 2013.
    [PDF] (acceptance rate=16.2%)
  • Saurabh Chakradeo, Brad Reaves, Patrick Traynor, and William Enck, MAST: Triage for Market-scale Mobile Malware Analysis, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), Budapest, Hungary, Apr. 2013. (\bf best paper).
    [PDF] (acceptance rate=15.1%)
  • Vaibhav Rastogi, Yan Chen, and William Enck, AppsPlayground: Automatic Large-scale Dynamic Analysis of Android Applications, in Proceedings of the 3rd ACM Conference on Data and Application Security and Privacy (CODASPY), San Antonio, TX, Feb. 2013.
    [PDF] (acceptance rate=23.1%)
  • Vasant Tendulkar, Joe Pletcher, Ashwin Shashidharan, Ryan Snyder, Kevin Butler, and William Enck, Abusing Cloud-based Browsers for Fun and Profit, in Proceedings of the 28th Annual Computer Security Applications Conference (ACSAC), Orlando, FL, Dec. 2012.
    [PDF] (acceptance rate=19.0%)
  • Tsung-Hsuan Ho, Daniel J. Dean, Xiaohui Gu, and William Enck, Less is More: Selective Behavior Learning for Efficient Android Root Exploit Detection, North Carolina State University, Department of Computer Science, Raleigh, NC, TR-2012-12, Sep. 2012.
  • David Barrera, William Enck, and Paul C. van Oorschot, Meteor: Seeding a Security-Enhancing Infrastructure for Multi-market Application Ecosystems, in Proceedings of the IEEE Mobile Security Technologies workshop (MoST), May 2012.
    [PDF] (acceptance rate=39.3%) (supercedes TR-11-06)
  • William Enck, Defending Users Against Smartphone Apps: Techniques and Future Directions, in Proceedings of 7th International Conference on Information Systems Security (ICISS), Kolkata, India, Dec. 2011. (Invited).
    [PDF]
  • David Barrera, William Enck, and Paul C. van Oorschot, Seeding a Security-Enhancing Infrastructure for Multi-market Application Ecosystems, Carleton University, School of Computer Science, Ottawa, ON, Canada, TR-11-06, Apr. 2011.
    [PDF]