The Experts below are selected from a list of 1107 Experts worldwide ranked by ideXlab platform

Rowena Chau - One of the best experts on this subject based on the ideXlab platform.

  • APWeb - Identifying parallel web documents by Filenames
    Advanced Web Technologies and Applications, 2004
    Co-Authors: Jisong Chen, Chung-hsing Yeh, Rowena Chau
    Abstract:

    Parallel Web documents are the crucial lexical basis for constructing robust multilingual Web-based linguistic knowledge resources. To identify parallel Web documents efficiently and effectively, this paper develops a new automatic approach based on Filenames using the commonly used parallel document naming practice on the Web. The approach involves three procedures for identifying common File Descriptor, language flag, and language flag-pair respectively among all File names examined. To examine how these three procedures can be used to get the best result, five methods are developed by incorporating these procedures in different ways. An experimental study on a Hong Kong government Web site is conducted to evaluate the performance of these five methods in terms of recall and precision. The experimental result shows that the method combining the procedures of the File Descriptor alignment and the language flag-pair alignment outperforms other methods, with a 95.3% of precision rate and a 91.0% of recall rate.

  • Identifying parallel Web documents by Filenames
    Lecture Notes in Computer Science, 2004
    Co-Authors: Jisong Chen, Chung-hsing Yeh, Rowena Chau
    Abstract:

    Parallel Web documents are the crucial lexical basis for constructing robust multilingual Web-based linguistic knowledge resources. To identify parallel Web documents efficiently and effectively, this paper develops a new automatic approach based on Filenames using the commonly used parallel document naming practice on the Web. The approach involves three procedures for identifying common File Descriptor, language flag, and language flag-pair respectively among all File names examined. To examine how these three procedures can be used to get the best result, five methods are developed by incorporating these procedures in different ways. An experimental study on a Hong Kong government Web site is conducted to evaluate the performance of these five methods in terms of recall and precision. The experimental result shows that the method combining the procedures of the File Descriptor alignment and the language flag-pair alignment outperforms other methods, with a 95.3% of precision rate and a 91.0% of recall rate.

Debin Gao - One of the best experts on this subject based on the ideXlab platform.

  • D.: Towards Ground Truthing Observations in Gray-Box Anomaly Detection
    2011
    Co-Authors: Jiang Ming, Haibin Zhang, Debin Gao
    Abstract:

    Abstract—Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides groun

  • NSS - Towards ground truthing observations in gray-box anomaly detection
    2011 5th International Conference on Network and System Security, 2011
    Co-Authors: Jiang Ming, Haibin Zhang, Debin Gao
    Abstract:

    Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.

Jiang Ming - One of the best experts on this subject based on the ideXlab platform.

  • D.: Towards Ground Truthing Observations in Gray-Box Anomaly Detection
    2011
    Co-Authors: Jiang Ming, Haibin Zhang, Debin Gao
    Abstract:

    Abstract—Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides groun

  • Towards ground truthing observations in gray-box anomaly detection
    2011 5th International Conference on Network and System Security, 2011
    Co-Authors: Jiang Ming, Haibin Zhang
    Abstract:

    Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.

  • NSS - Towards ground truthing observations in gray-box anomaly detection
    2011 5th International Conference on Network and System Security, 2011
    Co-Authors: Jiang Ming, Haibin Zhang, Debin Gao
    Abstract:

    Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.

Jisong Chen - One of the best experts on this subject based on the ideXlab platform.

  • APWeb - Identifying parallel web documents by Filenames
    Advanced Web Technologies and Applications, 2004
    Co-Authors: Jisong Chen, Chung-hsing Yeh, Rowena Chau
    Abstract:

    Parallel Web documents are the crucial lexical basis for constructing robust multilingual Web-based linguistic knowledge resources. To identify parallel Web documents efficiently and effectively, this paper develops a new automatic approach based on Filenames using the commonly used parallel document naming practice on the Web. The approach involves three procedures for identifying common File Descriptor, language flag, and language flag-pair respectively among all File names examined. To examine how these three procedures can be used to get the best result, five methods are developed by incorporating these procedures in different ways. An experimental study on a Hong Kong government Web site is conducted to evaluate the performance of these five methods in terms of recall and precision. The experimental result shows that the method combining the procedures of the File Descriptor alignment and the language flag-pair alignment outperforms other methods, with a 95.3% of precision rate and a 91.0% of recall rate.

  • Identifying parallel Web documents by Filenames
    Lecture Notes in Computer Science, 2004
    Co-Authors: Jisong Chen, Chung-hsing Yeh, Rowena Chau
    Abstract:

    Parallel Web documents are the crucial lexical basis for constructing robust multilingual Web-based linguistic knowledge resources. To identify parallel Web documents efficiently and effectively, this paper develops a new automatic approach based on Filenames using the commonly used parallel document naming practice on the Web. The approach involves three procedures for identifying common File Descriptor, language flag, and language flag-pair respectively among all File names examined. To examine how these three procedures can be used to get the best result, five methods are developed by incorporating these procedures in different ways. An experimental study on a Hong Kong government Web site is conducted to evaluate the performance of these five methods in terms of recall and precision. The experimental result shows that the method combining the procedures of the File Descriptor alignment and the language flag-pair alignment outperforms other methods, with a 95.3% of precision rate and a 91.0% of recall rate.

Haibin Zhang - One of the best experts on this subject based on the ideXlab platform.

  • D.: Towards Ground Truthing Observations in Gray-Box Anomaly Detection
    2011
    Co-Authors: Jiang Ming, Haibin Zhang, Debin Gao
    Abstract:

    Abstract—Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides groun

  • Towards ground truthing observations in gray-box anomaly detection
    2011 5th International Conference on Network and System Security, 2011
    Co-Authors: Jiang Ming, Haibin Zhang
    Abstract:

    Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.

  • NSS - Towards ground truthing observations in gray-box anomaly detection
    2011 5th International Conference on Network and System Security, 2011
    Co-Authors: Jiang Ming, Haibin Zhang, Debin Gao
    Abstract:

    Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a File Descriptor being equal to a socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.