The Experts below are selected from a list of 33 Experts worldwide ranked by ideXlab platform

Mohammad Zulkernine - One of the best experts on this subject based on the ideXlab platform.

  • NSS - Detecting DNS Tunneling Using Ensemble Learning
    Network and System Security, 2017
    Co-Authors: Saeed Shafieian, Daniel Smith, Mohammad Zulkernine
    Abstract:

    Domain Name System (DNS) is one of the building blocks of the Internet that plays the key role of translating domain names into IP addresses. DNS can be vulnerable to security threats affecting DNS servers or exploiting the DNS protocol. In this paper, we address DNS protocol exploitation that causes data breaches via DNS tunneling, where an Attacker employs techniques to exfiltrate sensitive data from a victim network. This usually happens by breaking the target data into small chunks and encoding them into DNS queries. The malicious DNS queries are then communicated from the target to the Attacker Machine. These DNS queries will finally be decoded and put together at the Attacker side to recover the breached data. Since DNS is a fundamental service, it cannot be blocked in order to mitigate these DNS tunneling attacks. Conventional signature-based intrusion detection systems are not very effective to detect these anomalies, either. Using some of the available DNS tunneling tools we first show how this phenomenon can occur. Then, we discuss our technique which employs a special ensemble of Machine learning algorithms to build a robust classifier to detect such attacks. Our ensemble classifier achieves high accuracy and near-zero false positives on a training set based on real benign data and generated malicious DNS traffic.

  • Detecting DNS Tunneling Using Ensemble Learning
    Network and System Security, 2017
    Co-Authors: Saeed Shafieian, Daniel Smith, Mohammad Zulkernine
    Abstract:

    Domain Name System (DNS) is one of the building blocks of the Internet that plays the key role of translating domain names into IP addresses. DNS can be vulnerable to security threats affecting DNS servers or exploiting the DNS protocol. In this paper, we address DNS protocol exploitation that causes data breaches via DNS tunneling, where an Attacker employs techniques to exfiltrate sensitive data from a victim network. This usually happens by breaking the target data into small chunks and encoding them into DNS queries. The malicious DNS queries are then communicated from the target to the Attacker Machine. These DNS queries will finally be decoded and put together at the Attacker side to recover the breached data. Since DNS is a fundamental service, it cannot be blocked in order to mitigate these DNS tunneling attacks. Conventional signature-based intrusion detection systems are not very effective to detect these anomalies, either. Using some of the available DNS tunneling tools we first show how this phenomenon can occur. Then, we discuss our technique which employs a special ensemble of Machine learning algorithms to build a robust classifier to detect such attacks. Our ensemble classifier achieves high accuracy and near-zero false positives on a training set based on real benign data and generated malicious DNS traffic.

Saeed Shafieian - One of the best experts on this subject based on the ideXlab platform.

  • NSS - Detecting DNS Tunneling Using Ensemble Learning
    Network and System Security, 2017
    Co-Authors: Saeed Shafieian, Daniel Smith, Mohammad Zulkernine
    Abstract:

    Domain Name System (DNS) is one of the building blocks of the Internet that plays the key role of translating domain names into IP addresses. DNS can be vulnerable to security threats affecting DNS servers or exploiting the DNS protocol. In this paper, we address DNS protocol exploitation that causes data breaches via DNS tunneling, where an Attacker employs techniques to exfiltrate sensitive data from a victim network. This usually happens by breaking the target data into small chunks and encoding them into DNS queries. The malicious DNS queries are then communicated from the target to the Attacker Machine. These DNS queries will finally be decoded and put together at the Attacker side to recover the breached data. Since DNS is a fundamental service, it cannot be blocked in order to mitigate these DNS tunneling attacks. Conventional signature-based intrusion detection systems are not very effective to detect these anomalies, either. Using some of the available DNS tunneling tools we first show how this phenomenon can occur. Then, we discuss our technique which employs a special ensemble of Machine learning algorithms to build a robust classifier to detect such attacks. Our ensemble classifier achieves high accuracy and near-zero false positives on a training set based on real benign data and generated malicious DNS traffic.

  • Detecting DNS Tunneling Using Ensemble Learning
    Network and System Security, 2017
    Co-Authors: Saeed Shafieian, Daniel Smith, Mohammad Zulkernine
    Abstract:

    Domain Name System (DNS) is one of the building blocks of the Internet that plays the key role of translating domain names into IP addresses. DNS can be vulnerable to security threats affecting DNS servers or exploiting the DNS protocol. In this paper, we address DNS protocol exploitation that causes data breaches via DNS tunneling, where an Attacker employs techniques to exfiltrate sensitive data from a victim network. This usually happens by breaking the target data into small chunks and encoding them into DNS queries. The malicious DNS queries are then communicated from the target to the Attacker Machine. These DNS queries will finally be decoded and put together at the Attacker side to recover the breached data. Since DNS is a fundamental service, it cannot be blocked in order to mitigate these DNS tunneling attacks. Conventional signature-based intrusion detection systems are not very effective to detect these anomalies, either. Using some of the available DNS tunneling tools we first show how this phenomenon can occur. Then, we discuss our technique which employs a special ensemble of Machine learning algorithms to build a robust classifier to detect such attacks. Our ensemble classifier achieves high accuracy and near-zero false positives on a training set based on real benign data and generated malicious DNS traffic.

Sridhar Ramalingam - One of the best experts on this subject based on the ideXlab platform.

  • How to Bypass Verified Boot Security in Chromium OS
    2012
    Co-Authors: Husain, Mohammad Iftekhar, Mandvekar Lokesh, Qiao Chunming, Sridhar Ramalingam
    Abstract:

    Verified boot is an interesting feature of Chromium OS that supposedly can detect any modification in the root file system (rootfs) by a dedicated adversary. However, by exploiting a design flaw in verified boot, we show that an adversary can replace the original rootfs by a malicious rootfs containing exploits such as a spyware or keylogger and still pass the verified boot process. The exploit is based on the fact that a dedicated adversary can replace the rootfs and the corresponding verification information in the bootloader. We experimentally demonstrate an attack using both the base and developer version of Chromium OS in which the adversary installs a spyware in the target system to send cached user data to the Attacker Machine in plain text which are otherwise encrypted, and thus inaccessible. We also demonstrate techniques to mitigate this vulnerability.Comment: Update information about Chromium OS. Added new and advanced exploits. Added mitigation techniques and evaluatio

Ramalingam Sridhar - One of the best experts on this subject based on the ideXlab platform.

  • How to Bypass Verified Boot Security in Chromium OS
    arXiv: Cryptography and Security, 2012
    Co-Authors: Mohammad Iftekhar Husain, Lokesh Mandvekar, Chunming Qiao, Ramalingam Sridhar
    Abstract:

    Verified boot is an interesting feature of Chromium OS that supposedly can detect any modification in the root file system (rootfs) by a dedicated adversary. However, by exploiting a design flaw in verified boot, we show that an adversary can replace the original rootfs by a malicious rootfs containing exploits such as a spyware or keylogger and still pass the verified boot process. The exploit is based on the fact that a dedicated adversary can replace the rootfs and the corresponding verification information in the bootloader. We experimentally demonstrate an attack using both the base and developer version of Chromium OS in which the adversary installs a spyware in the target system to send cached user data to the Attacker Machine in plain text which are otherwise encrypted, and thus inaccessible. We also demonstrate techniques to mitigate this vulnerability.

Dawood Al Abri - One of the best experts on this subject based on the ideXlab platform.

  • Detection of MITM attack in LAN environment using payload matching
    2015 IEEE International Conference on Industrial Technology (ICIT), 2015
    Co-Authors: Dawood Al Abri
    Abstract:

    Man-in-the-Middle (MITM) attack enables an Attacker to monitor the communication exchange between two parties by directing the traffic between them to pass through the Attacker's Machine. Most existing schemes for discovering MITM attack focus on detecting the mechanism used to direct the traffic through the Attacker Machine. This paper presents a new detection scheme that is based on matching the payload of frames exchanged in the network. The proposed scheme is independent of the mechanism used to launch the MITM attack. Experimental result shows that the proposed scheme can achieve excellent detection performance with proper choice of the scheme's tuning parameters.

  • ICIT - Detection of MITM attack in LAN environment using payload matching
    2015 IEEE International Conference on Industrial Technology (ICIT), 2015
    Co-Authors: Dawood Al Abri
    Abstract:

    Man-in-the-Middle (MITM) attack enables an Attacker to monitor the communication exchange between two parties by directing the traffic between them to pass through the Attacker's Machine. Most existing schemes for discovering MITM attack focus on detecting the mechanism used to direct the traffic through the Attacker Machine. This paper presents a new detection scheme that is based on matching the payload of frames exchanged in the network. The proposed scheme is independent of the mechanism used to launch the MITM attack. Experimental result shows that the proposed scheme can achieve excellent detection performance with proper choice of the scheme's tuning parameters.