The Experts below are selected from a list of 2274 Experts worldwide ranked by ideXlab platform

Yuval Elovici - One of the best experts on this subject based on the ideXlab platform.

  • Handbook of Social Network Technologies - Optimizing Targeting of Intrusion Detection Systems in Social Networks
    Handbook of Social Network Technologies and Applications, 2010
    Co-Authors: Rami Puzis, Meytal Tubi, Yuval Elovici
    Abstract:

    Internet users communicate with each other in various ways: by Emails, instant messaging, social networking, accessing Web sites, etc. In the course of communicating, users may unintentionally copy files contaminated with Computer viruses and Worms [1, 2] to their Computers and spread them to other users [3]. (Hereafter we will use the term “threats”, rather than Computer viruses and Computer Worms). The Internet is the chief source of these threats [4].

  • Using artificial neural networks to detect unknown Computer Worms
    Neural Computing and Applications, 2009
    Co-Authors: D. Stopel, Robert Moskovitch, Yuval Shahar, Zvi Boger, Yuval Elovici
    Abstract:

    Detecting Computer Worms is a highly challenging task. We present a new approach that uses artificial neural networks (ANN) to detect the presence of Computer Worms based on measurements of Computer behavior. We compare ANN to three other classification methods and show the advantages of ANN for detection of known Worms. We then proceed to evaluate ANN’s ability to detect the presence of an unknown worm. As the measurement of a large number of system features may require significant computational resources, we evaluate three feature selection techniques. We show that, using only five features, one can detect an unknown worm with an average accuracy of 90%. We use a causal index analysis of our trained ANN to identify rules that explain the relationships between the selected features and the identity of each worm. Finally, we discuss the possible application of our approach to host-based intrusion detection systems.

  • active learning to improve the detection of unknown Computer Worms activity
    International Conference on Information Fusion, 2008
    Co-Authors: Robert Moskovitch, Nir Nissim, Roman Englert, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. We propose an innovative technique for detecting the presence of an unknown worm based on the Computer measurements extracted from the operating system. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection measures were used to reduce the number of features. We applied support vector machines on the resulting feature subsets. In addition, we used active learning as a selective sampling method to increase the performance of the classifier and improve its robustness in noisy data. Our results indicate that using the proposed approach resulted in a mean accuracy in excess of 90%, and for specific unknown Worms accuracy reached above 94%, using just 20 features while maintaining a low false positive rate.

  • FUSION - Active learning to improve the detection of unknown Computer Worms activity
    2008
    Co-Authors: Robert Moskovitch, Nir Nissim, Roman Englert, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. We propose an innovative technique for detecting the presence of an unknown worm based on the Computer measurements extracted from the operating system. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection measures were used to reduce the number of features. We applied support vector machines on the resulting feature subsets. In addition, we used active learning as a selective sampling method to increase the performance of the classifier and improve its robustness in noisy data. Our results indicate that using the proposed approach resulted in a mean accuracy in excess of 90%, and for specific unknown Worms accuracy reached above 94%, using just 20 features while maintaining a low false positive rate.

  • Detection of unknown Computer Worms based on behavioral classification of the host
    Computational Statistics & Data Analysis, 2008
    Co-Authors: Robert Moskovitch, Yuval Elovici, Lior Rokach
    Abstract:

    Machine learning techniques are widely used in many fields. One of the applications of machine learning in the field of information security is classification of a Computer behavior into malicious and benign. Antiviruses consisting of signature-based methods are helpless against new (unknown) Computer Worms. This paper focuses on the feasibility of accurately detecting unknown worm activity in individual Computers while minimizing the required set of features collected from the monitored Computer. A comprehensive experiment for testing the feasibility of detecting unknown Computer Worms, employing several Computer configurations, background applications, and user activity, was performed. During the experiments 323 Computer features were monitored by an agent that was developed. Four feature selection methods were used to reduce the number of features and four learning algorithms were applied on the resulting feature subsets. The evaluation results suggest that by using classification algorithms applied on only 20 features the mean detection accuracy exceeded 90%, and for specific unknown Worms accuracy reached above 99%, while maintaining a low level of false positive rate.

Robert Moskovitch - One of the best experts on this subject based on the ideXlab platform.

  • Using artificial neural networks to detect unknown Computer Worms
    Neural Computing and Applications, 2009
    Co-Authors: D. Stopel, Robert Moskovitch, Yuval Shahar, Zvi Boger, Yuval Elovici
    Abstract:

    Detecting Computer Worms is a highly challenging task. We present a new approach that uses artificial neural networks (ANN) to detect the presence of Computer Worms based on measurements of Computer behavior. We compare ANN to three other classification methods and show the advantages of ANN for detection of known Worms. We then proceed to evaluate ANN’s ability to detect the presence of an unknown worm. As the measurement of a large number of system features may require significant computational resources, we evaluate three feature selection techniques. We show that, using only five features, one can detect an unknown worm with an average accuracy of 90%. We use a causal index analysis of our trained ANN to identify rules that explain the relationships between the selected features and the identity of each worm. Finally, we discuss the possible application of our approach to host-based intrusion detection systems.

  • active learning to improve the detection of unknown Computer Worms activity
    International Conference on Information Fusion, 2008
    Co-Authors: Robert Moskovitch, Nir Nissim, Roman Englert, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. We propose an innovative technique for detecting the presence of an unknown worm based on the Computer measurements extracted from the operating system. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection measures were used to reduce the number of features. We applied support vector machines on the resulting feature subsets. In addition, we used active learning as a selective sampling method to increase the performance of the classifier and improve its robustness in noisy data. Our results indicate that using the proposed approach resulted in a mean accuracy in excess of 90%, and for specific unknown Worms accuracy reached above 94%, using just 20 features while maintaining a low false positive rate.

  • FUSION - Active learning to improve the detection of unknown Computer Worms activity
    2008
    Co-Authors: Robert Moskovitch, Nir Nissim, Roman Englert, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. We propose an innovative technique for detecting the presence of an unknown worm based on the Computer measurements extracted from the operating system. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection measures were used to reduce the number of features. We applied support vector machines on the resulting feature subsets. In addition, we used active learning as a selective sampling method to increase the performance of the classifier and improve its robustness in noisy data. Our results indicate that using the proposed approach resulted in a mean accuracy in excess of 90%, and for specific unknown Worms accuracy reached above 94%, using just 20 features while maintaining a low false positive rate.

  • Detection of unknown Computer Worms based on behavioral classification of the host
    Computational Statistics & Data Analysis, 2008
    Co-Authors: Robert Moskovitch, Yuval Elovici, Lior Rokach
    Abstract:

    Machine learning techniques are widely used in many fields. One of the applications of machine learning in the field of information security is classification of a Computer behavior into malicious and benign. Antiviruses consisting of signature-based methods are helpless against new (unknown) Computer Worms. This paper focuses on the feasibility of accurately detecting unknown worm activity in individual Computers while minimizing the required set of features collected from the monitored Computer. A comprehensive experiment for testing the feasibility of detecting unknown Computer Worms, employing several Computer configurations, background applications, and user activity, was performed. During the experiments 323 Computer features were monitored by an agent that was developed. Four feature selection methods were used to reduce the number of features and four learning algorithms were applied on the resulting feature subsets. The evaluation results suggest that by using classification algorithms applied on only 20 features the mean detection accuracy exceeded 90%, and for specific unknown Worms accuracy reached above 99%, while maintaining a low level of false positive rate.

  • Detection of Unknown Computer Worms Activity Based on Computer Behavior using Data Mining
    Computational Intelligence and Data Mining, 2007. CIDM 2007. IEEE Symposium on, 2007
    Co-Authors: Robert Moskovitch, I. Gus, S. Pluderman, D. Stopel, Clint Feher, Y. Eloyici, Chanan Glezer, Yuval Shahar, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. Extant solutions, such as anti-virus tools, rely mainly on prior explicit knowledge of specific worm signatures. As a result, after the appearance of a new worm on the Web there is a significant delay until an update carrying the worm's signature is distributed to anti-virus tools. During this time interval a new worm can infect many Computers and cause significant damage. We propose an innovative technique for detecting the presence of an unknown worm, not necessarily by recognizing specific instances of the worm, but rather based on the Computer measurements. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection techniques were used to reduce the amount of features and four classification algorithms were applied on the resulting feature subsets. Our results indicate that using this approach resulted in exceeding 90% mean accuracy, and for specific unknown Worms accuracy reached above 99%, using just 20 features while maintaining a low level of false positive rate.

Jose Maria Barcelo-ordinas - One of the best experts on this subject based on the ideXlab platform.

  • Understanding, Modeling and Taming Mobile Malware Epidemics in a Large-scale Vehicular Network
    2013
    Co-Authors: Oscar Trullols-cruces, Marco Fiore, Jose Maria Barcelo-ordinas
    Abstract:

    The large-scale adoption of vehicle-to-vehicle (V2V) communication technologies risks to significantly widen the attack surface available to mobile malware targeting critical automobile operations. Given that outbreaks of vehicular Computer Worms self-propagating through V2V links could pose a significant threat to road traffic safety, it is important to understand the dynamics of such epidemics and to prepare adequate countermeasures. In this paper we perform a com- prehensive characterization of the infection process of variously behaving vehicular Worms throughout a road traffic scenario of unprecedented scale and heterogeneity. We then propose a simple yet effective data-driven model of the worm epidemics, and we show how it can be leveraged for smart patching infected vehicles through the cellular network in presence of a vehicular worm outbreak.

  • WOWMOM - Understanding, modeling and taming mobile malware epidemics in a large-scale vehicular network
    2013 IEEE 14th International Symposium on "A World of Wireless Mobile and Multimedia Networks" (WoWMoM), 2013
    Co-Authors: Oscar Trullols-cruces, Marco Fiore, Jose Maria Barcelo-ordinas
    Abstract:

    The large-scale adoption of vehicle-to-vehicle (V2V) communication technologies risks to significantly widen the attack surface available to mobile malware targeting critical automobile operations. Given that outbreaks of vehicular Computer Worms self-propagating through V2V links could pose a significant threat to road traffic safety, it is important to understand the dynamics of such epidemics and to prepare adequate countermeasures. In this paper we perform a comprehensive characterization of the infection process of variously behaving vehicular Worms on a road traffic scenario of unprecedented scale and heterogeneity. We then propose a simple yet effective data-driven model of the worm epidemics, and we show how it can be leveraged for smart patching infected vehicles through the cellular network in presence of a vehicular worm outbreak.

Oscar Trullols-cruces - One of the best experts on this subject based on the ideXlab platform.

  • Understanding, Modeling and Taming Mobile Malware Epidemics in a Large-scale Vehicular Network
    2013
    Co-Authors: Oscar Trullols-cruces, Marco Fiore, Jose Maria Barcelo-ordinas
    Abstract:

    The large-scale adoption of vehicle-to-vehicle (V2V) communication technologies risks to significantly widen the attack surface available to mobile malware targeting critical automobile operations. Given that outbreaks of vehicular Computer Worms self-propagating through V2V links could pose a significant threat to road traffic safety, it is important to understand the dynamics of such epidemics and to prepare adequate countermeasures. In this paper we perform a com- prehensive characterization of the infection process of variously behaving vehicular Worms throughout a road traffic scenario of unprecedented scale and heterogeneity. We then propose a simple yet effective data-driven model of the worm epidemics, and we show how it can be leveraged for smart patching infected vehicles through the cellular network in presence of a vehicular worm outbreak.

  • WOWMOM - Understanding, modeling and taming mobile malware epidemics in a large-scale vehicular network
    2013 IEEE 14th International Symposium on "A World of Wireless Mobile and Multimedia Networks" (WoWMoM), 2013
    Co-Authors: Oscar Trullols-cruces, Marco Fiore, Jose Maria Barcelo-ordinas
    Abstract:

    The large-scale adoption of vehicle-to-vehicle (V2V) communication technologies risks to significantly widen the attack surface available to mobile malware targeting critical automobile operations. Given that outbreaks of vehicular Computer Worms self-propagating through V2V links could pose a significant threat to road traffic safety, it is important to understand the dynamics of such epidemics and to prepare adequate countermeasures. In this paper we perform a comprehensive characterization of the infection process of variously behaving vehicular Worms on a road traffic scenario of unprecedented scale and heterogeneity. We then propose a simple yet effective data-driven model of the worm epidemics, and we show how it can be leveraged for smart patching infected vehicles through the cellular network in presence of a vehicular worm outbreak.

D. Stopel - One of the best experts on this subject based on the ideXlab platform.

  • Using artificial neural networks to detect unknown Computer Worms
    Neural Computing and Applications, 2009
    Co-Authors: D. Stopel, Robert Moskovitch, Yuval Shahar, Zvi Boger, Yuval Elovici
    Abstract:

    Detecting Computer Worms is a highly challenging task. We present a new approach that uses artificial neural networks (ANN) to detect the presence of Computer Worms based on measurements of Computer behavior. We compare ANN to three other classification methods and show the advantages of ANN for detection of known Worms. We then proceed to evaluate ANN’s ability to detect the presence of an unknown worm. As the measurement of a large number of system features may require significant computational resources, we evaluate three feature selection techniques. We show that, using only five features, one can detect an unknown worm with an average accuracy of 90%. We use a causal index analysis of our trained ANN to identify rules that explain the relationships between the selected features and the identity of each worm. Finally, we discuss the possible application of our approach to host-based intrusion detection systems.

  • Detection of Unknown Computer Worms Activity Based on Computer Behavior using Data Mining
    Computational Intelligence and Data Mining, 2007. CIDM 2007. IEEE Symposium on, 2007
    Co-Authors: Robert Moskovitch, I. Gus, S. Pluderman, D. Stopel, Clint Feher, Y. Eloyici, Chanan Glezer, Yuval Shahar, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. Extant solutions, such as anti-virus tools, rely mainly on prior explicit knowledge of specific worm signatures. As a result, after the appearance of a new worm on the Web there is a significant delay until an update carrying the worm's signature is distributed to anti-virus tools. During this time interval a new worm can infect many Computers and cause significant damage. We propose an innovative technique for detecting the presence of an unknown worm, not necessarily by recognizing specific instances of the worm, but rather based on the Computer measurements. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection techniques were used to reduce the amount of features and four classification algorithms were applied on the resulting feature subsets. Our results indicate that using this approach resulted in exceeding 90% mean accuracy, and for specific unknown Worms accuracy reached above 99%, using just 20 features while maintaining a low level of false positive rate.

  • CIDM - Detection of Unknown Computer Worms Activity Based on Computer Behavior using Data Mining
    2007 IEEE Symposium on Computational Intelligence and Data Mining, 2007
    Co-Authors: Robert Moskovitch, I. Gus, S. Pluderman, D. Stopel, Clint Feher, Chanan Glezer, Yuval Shahar, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. Extant solutions, such as anti-virus tools, rely mainly on prior explicit knowledge of specific worm signatures. As a result, after the appearance of a new worm on the Web there is a significant delay until an update carrying the worm's signature is distributed to anti-virus tools. During this time interval a new worm can infect many Computers and cause significant damage. We propose an innovative technique for detecting the presence of an unknown worm, not necessarily by recognizing specific instances of the worm, but rather based on the Computer measurements. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection techniques were used to reduce the amount of features and four classification algorithms were applied on the resulting feature subsets. Our results indicate that using this approach resulted in exceeding 90% mean accuracy, and for specific unknown Worms accuracy reached above 99%, using just 20 features while maintaining a low level of false positive rate.

  • CISDA - Detection of Unknown Computer Worms Activity Based on Computer Behavior using Data Mining
    2007 IEEE Symposium on Computational Intelligence in Security and Defense Applications, 2007
    Co-Authors: Robert Moskovitch, I. Gus, S. Pluderman, D. Stopel, Chanan Glezer, Yuval Shahar, Yuval Elovici
    Abstract:

    Detecting unknown Worms is a challenging task. Extant solutions, such as anti-virus tools, rely mainly on prior explicit knowledge of specific worm signatures. As a result, after the appearance of a new worm on the Web there is a significant delay until an update carrying the worm's signature is distributed to anti-virus tools. During this time interval a new worm can infect many Computers and create significant damage. We propose an innovative technique for detecting the presence of an unknown worm, not necessarily by recognizing specific instances of the worm, but rather based on the Computer measurements. We designed an experiment to test the new technique employing several Computer configurations and background applications activity. During the experiments 323 Computer features were monitored. Four feature selection techniques were used to reduce the amount of features and four classification algorithms were applied on the resulting feature subsets. Our results indicate that using this approach resulted, in above 90% average accuracy, and for specific unknown Worms accuracy reached above 99%, using just 20 features while maintaining a low level of false positive rate

  • IJCNN - Application of Artificial Neural Networks Techniques to Computer Worm Detection
    The 2006 IEEE International Joint Conference on Neural Network Proceedings, 2006
    Co-Authors: D. Stopel, Robert Moskovitch, Yuval Shahar, Zvi Boger, Yuval Elovici
    Abstract:

    Detecting Computer Worms is a highly challenging task. Commonly this task is performed by antivirus software tools that rely on prior explicit knowledge of the worm's code, which is represented by signatures. We present a new approach based on artificial neural networks (ANN) for detecting the presence of Computer Worms based on the Computer's behavioral measures. In order to evaluate the new approach, several Computers were infected with seven different Worms and more than sixty different parameters of the infected Computers were measured. The ANN and two other known classifications techniques, decision tree and k-nearest neighbors, were used to test their ability to classify correctly the presence, and the type, of the Computer Worms even during heavy user activity on the infected Computers. The comparisons between the three approaches suggest that the ANN approach have computational advantages when real-time computation is needed, and has the potential to detect previously unknown Worms. In addition, ANN may be used to identify the most relevant, measurable, features and thus reduce the feature dimensionality.