The Experts below are selected from a list of 258 Experts worldwide ranked by ideXlab platform

Ibrahim Baggili - One of the best experts on this subject based on the ideXlab platform.

  • ARES - I Know What You Did Last Summer: Your Smart Home Internet of Things and Your iPhone Forensically Ratting You Out
    Proceedings of the 13th International Conference on Availability Reliability and Security - ARES 2018, 2018
    Co-Authors: Gokila Dorai, Shiva Houshmand, Ibrahim Baggili
    Abstract:

    The adoption of smart home Internet of Things (IoT) devices continues to grow. What if your devices can snitch on you and let us know where you are at any given point in time? In this work we examined the forensic artifacts produced by Nest devices, and in specific, we examined the logical backup structure of an iPhone used to control a Nest thermostat, Nest Indoor Camera and a Nest Outdoor Camera. We also integrated the Google Home Mini as another method of controlling the studied Smart Home devices. Our work is the primary account for the examination of Nest artifacts produced by an iPhone, and is also the first open source research to produce a usable Forensics Tool we name the Forensic Evidence Acquisition and Analysis System (FEAAS). FEAAS consolidates evidentiary data into a readable report that can infer user events (like entering or leaving a home) and what triggered an event (whether it was the Google Assistant through a voice command, or the use of an iPhone application). Our results are important for the advancement of digital Forensics, as there are cases starting to emerge in which smart home IoT devices have already been used as culpatory evidence.

  • Mobile Phone Forensics Tool Testing: A Database Driven Approach.
    International Journal of Digital Evidence, 2007
    Co-Authors: Ibrahim Baggili, Richard Mislan, Marcus K. Rogers
    Abstract:

    The Daubert process used in the admissibility of evidence contains major guidelines applied in assessing forensic procedures, two of which are testing and error rates. The Digital Forensic Science (DFS) community is growing and the error rates for the forensic Tools need to be continuously re-evaluated as the technology changes. This becomes more difficult in the case of mobile phone Forensics, because they are proprietary. This paper discusses a database driven approach that could be used to store data about the mobile phone evidence acquisition testing process. This data can then be used to calculate Tool error rates, which can be published and used to validate or invalidate the mobile phone acquisition Tools.

Demertzis Konstantinos - One of the best experts on this subject based on the ideXlab platform.

  • Darknet Traffic Big-Data Analysis and Network Management to Real-Time Automating the Malicious Intent Detection Process by a Weight Agnostic Neural Networks Framework
    2021
    Co-Authors: Demertzis Konstantinos, Tsiknas Konstantinos, Takezis Dimitrios, Skianis Charalabos, Iliadis Lazaros
    Abstract:

    Attackers are perpetually modifying their tactics to avoid detection and frequently leverage legitimate credentials with trusted Tools already deployed in a network environment, making it difficult for organizations to proactively identify critical security risks. Network traffic analysis products have emerged in response to attackers relentless innovation, offering organizations a realistic path forward for combatting creative attackers. Additionally, thanks to the widespread adoption of cloud computing, Device Operators processes, and the Internet of Things, maintaining effective network visibility has become a highly complex and overwhelming process. What makes network traffic analysis technology particularly meaningful is its ability to combine its core capabilities to deliver malicious intent detection. In this paper, we propose a novel darknet traffic analysis and network management framework to real-time automating the malicious intent detection process, using a weight agnostic neural networks architecture. It is an effective and accurate computational intelligent Forensics Tool for network traffic analysis, the demystification of malware traffic, and encrypted traffic identification in real-time. Based on Weight Agnostic Neural Networks methodology, we propose an automated searching neural net architectures strategy that can perform various tasks such as identify zero-day attacks. By automating the malicious intent detection process from the darknet, the advanced proposed solution is reducing the skills and effort barrier that prevents many organizations from effectively protecting their most critical assets

  • The Next Generation Cognitive Security Operations Center: Adaptive Analytic Lambda Architecture for Efficient Defense against Adversarial Attacks
    'MDPI AG', 2019
    Co-Authors: Demertzis Konstantinos, Kikiras Panayiotis, Tziritas Nikos, Sanchez, Salvador Llopis, Iliadis Lazaros
    Abstract:

    International audienceA Security Operations Center (SOC) is a central technical level unit responsible for monitoring, analyzing, assessing, and defending an organization's security posture on an ongoing basis. The SOC staff works closely with incident response teams, security analysts, network engineers and organization managers using sophisticated data processing technologies such as security analytics, threat intelligence, and asset criticality to ensure security issues are detected, analyzed and finally addressed quickly. Those techniques are part of a reactive security strategy because they rely on the human factor, experience and the judgment of security experts, using supplementary technology to evaluate the risk impact and minimize the attack surface. This study suggests an active security strategy that adopts a vigorous method including ingenuity, data analysis, processing and decision-making support to face various cyber hazards. Specifically, the paper introduces a novel intelligence driven cognitive computing SOC that is based exclusively on progressive fully automatic procedures. The proposed λ-Architecture Network Flow Forensics Framework (λ-ΝF3) is an efficient cybersecurity defense framework against adversarial attacks. It implements the Lambda machine learning architecture that can analyze a mixture of batch and streaming data, using two accurate novel computational intelligence algorithms. Specifically, it uses an Extreme Learning Machine neural network with Gaussian Radial Basis Function kernel (ELM/GRBFk) for the batch data analysis and a Self-Adjusting Memory k-Nearest Neighbors classifier (SAM/k-NN) to examine patterns from real-time streams. It is a Forensics Tool for big data that can enhance the automate defense strategies of SOCs to effectively respond to the threats their environments face

  • The Next Generation Cognitive Security Operations Center: Network Flow Forensics Using Cybersecurity Intelligence
    'MDPI AG', 2018
    Co-Authors: Demertzis Konstantinos, Kikiras Panayiotis, Tziritas Nikos, Sanchez, Salvador Llopis, Siliadis Lazaro
    Abstract:

    International audienceA Security Operations Center (SOC) can be defined as an organized and highly skilled team that uses advanced computer Forensics Tools to prevent, detect and respond to cybersecurity incidents of an organization. The fundamental aspects of an effective SOC is related to the ability to examine and analyze the vast number of data flows and to correlate several other types of events from a cybersecurity perception. The supervision and categorization of network flow is an essential process not only for the scheduling, management, and regulation of the network's services, but also for attacks identification and for the consequent Forensics' investigations. A serious potential disadvantage of the traditional software solutions used today for computer network monitoring, and specifically for the instances of effective categorization of the encrypted or obfuscated network flow, which enforces the rebuilding of messages packets in sophisticated underlying protocols, is the requirements of computational resources. In addition, an additional significant inability of these software packages is they create high false positive rates because they are deprived of accurate predicting mechanisms. For all the reasons above, in most cases, the traditional software fails completely to recognize unidentified vulnerabilities and zero-day exploitations. This paper proposes a novel intelligence driven Network Flow Forensics Framework (NF3) which uses low utilization of computing power and resources, for the Next Generation Cognitive Computing SOC (NGC2SOC) that rely solely on advanced fully automated intelligence methods. It is an effective and accurate Ensemble Machine Learning Forensics Tool to Network Traffic Analysis, Demystification of Malware Traffic and Encrypted Traffic Identification

Konstantinos Demertzis - One of the best experts on this subject based on the ideXlab platform.

  • The Next Generation Cognitive Security Operations Center: Adaptive Analytic Lambda Architecture for Efficient Defense against Adversarial Attacks
    Big Data and Cognitive Computing, 2019
    Co-Authors: Konstantinos Demertzis, Panayiotis Kikiras, Salvador Llopis Sanchez, Nikos Tziritas, Lazaros Iliadis
    Abstract:

    A Security Operations Center (SOC) is a central technical level unit responsible for monitoring, analyzing, assessing, and defending an organization’s security posture on an ongoing basis. The SOC staff works closely with incident response teams, security analysts, network engineers and organization managers using sophisticated data processing technologies such as security analytics, threat intelligence, and asset criticality to ensure security issues are detected, analyzed and finally addressed quickly. Those techniques are part of a reactive security strategy because they rely on the human factor, experience and the judgment of security experts, using supplementary technology to evaluate the risk impact and minimize the attack surface. This study suggests an active security strategy that adopts a vigorous method including ingenuity, data analysis, processing and decision-making support to face various cyber hazards. Specifically, the paper introduces a novel intelligence driven cognitive computing SOC that is based exclusively on progressive fully automatic procedures. The proposed λ-Architecture Network Flow Forensics Framework (λ-ΝF3) is an efficient cybersecurity defense framework against adversarial attacks. It implements the Lambda machine learning architecture that can analyze a mixture of batch and streaming data, using two accurate novel computational intelligence algorithms. Specifically, it uses an Extreme Learning Machine neural network with Gaussian Radial Basis Function kernel (ELM/GRBFk) for the batch data analysis and a Self-Adjusting Memory k-Nearest Neighbors classifier (SAM/k-NN) to examine patterns from real-time streams. It is a Forensics Tool for big data that can enhance the automate defense strategies of SOCs to effectively respond to the threats their environments face.

  • The Next Generation Cognitive Security Operations Center: Network Flow Forensics Using Cybersecurity Intelligence
    Big Data and Cognitive Computing, 2018
    Co-Authors: Konstantinos Demertzis, Panayiotis Kikiras, Salvador Llopis Sanchez, Nikos Tziritas, Lazaro Siliadis
    Abstract:

    A Security Operations Center (SOC) can be defined as an organized and highly skilled team that uses advanced computer Forensics Tools to prevent, detect and respond to cybersecurity incidents of an organization. The fundamental aspects of an effective SOC is related to the ability to examine and analyze the vast number of data flows and to correlate several other types of events from a cybersecurity perception. The supervision and categorization of network flow is an essential process not only for the scheduling, management, and regulation of the network's services, but also for attacks identification and for the consequent Forensics' investigations. A serious potential disadvantage of the traditional software solutions used today for computer network monitoring, and specifically for the instances of effective categorization of the encrypted or obfuscated network flow, which enforces the rebuilding of messages packets in sophisticated underlying protocols, is the requirements of computational resources. In addition, an additional significant inability of these software packages is they create high false positive rates because they are deprived of accurate predicting mechanisms. For all the reasons above, in most cases, the traditional software fails completely to recognize unidentified vulnerabilities and zero-day exploitations. This paper proposes a novel intelligence driven Network Flow Forensics Framework (NF3) which uses low utilization of computing power and resources, for the Next Generation Cognitive Computing SOC (NGC2SOC) that rely solely on advanced fully automated intelligence methods. It is an effective and accurate Ensemble Machine Learning Forensics Tool to Network Traffic Analysis, Demystification of Malware Traffic and Encrypted Traffic Identification.

  • A Computational Intelligence System Identifying Cyber-Attacks on Smart Energy Grids
    Springer Optimization and Its Applications, 2018
    Co-Authors: Konstantinos Demertzis, Lazaros S. Iliadis
    Abstract:

    According to the latest projections of the International Energy Agency, smart grid technologies have become essential to handling the radical changes expected in international energy portfolios through 2030. A smart grid is an energy transmission and distribution network enhanced through digital control, monitoring, and telecommunication capabilities. It provides a real-time, two-way flow of energy and information to all stakeholders in the electricity chain, from the generation plant to the commercial, industrial, and residential end user. New digital equipment and devices can be strategically deployed to complement existing equipment. Using a combination of centralized IT and distributed intelligence within critical system control nodes ranging from thermal and renewable plant controls to grid and distribution utility servers to cities, commercial and industrial infrastructures, and homes a smart grid can bring unprecedented efficiency and stability to the energy system. Information and communication infrastructures will play an important role in connecting and optimizing the available grid layers. Grid operation depends on control systems called Supervisory Control and Data Acquisition (SCADA) that monitor and control the physical infrastructure. At the heart of these SCADA systems are specialized computers known as Programmable Logic Controllers (PLCs). There are destructive cyber-attacks against SCADA systems as Advanced Persistent Threats (APT) were able to take over the PLCs controlling the centrifuges, reprogramming them in order to speed up the centrifuges, leading to the destruction of many and yet displaying a normal operating speed in order to trick the centrifuge operators and finally can not only shut things down but can alter their function and permanently damage industrial equipment. This paper proposes a computational intelligence System for Identification Cyber-Attacks on the Smart Energy Grids (SICASEG). It is a big data Forensics Tool which can capture, record, and analyze the smart energy grid network events to find the source of an attack to both prevent future attacks and perhaps for prosecution.

Christian Moch - One of the best experts on this subject based on the ideXlab platform.

  • Anti-Forensics: The Next Step in Digital Forensics Tool Testing
    2013 Seventh International Conference on IT Security Incident Management and IT Forensics, 2013
    Co-Authors: Martin Wundram, Felix C Freiling, Christian Moch
    Abstract:

    We classify and present established and new attacks on digital Forensics Tools. In particular, we present the first and surprisingly simple code injection attack on a commercial analysis Tool that potentially allows to infiltrate the analysis system. We argue that digital Forensics Tool testing must mature to cater for malicious adversaries. We also discuss possible countermeasures.

  • IMF - Anti-Forensics: The Next Step in Digital Forensics Tool Testing
    2013 Seventh International Conference on IT Security Incident Management and IT Forensics, 2013
    Co-Authors: Martin Wundram, Felix C Freiling, Christian Moch
    Abstract:

    We classify and present established and new attacks on digital Forensics Tools. In particular, we present the first and surprisingly simple code injection attack on a commercial analysis Tool that potentially allows to infiltrate the analysis system. We argue that digital Forensics Tool testing must mature to cater for malicious adversaries. We also discuss possible countermeasures.

Iliadis Lazaros - One of the best experts on this subject based on the ideXlab platform.

  • Darknet Traffic Big-Data Analysis and Network Management to Real-Time Automating the Malicious Intent Detection Process by a Weight Agnostic Neural Networks Framework
    2021
    Co-Authors: Demertzis Konstantinos, Tsiknas Konstantinos, Takezis Dimitrios, Skianis Charalabos, Iliadis Lazaros
    Abstract:

    Attackers are perpetually modifying their tactics to avoid detection and frequently leverage legitimate credentials with trusted Tools already deployed in a network environment, making it difficult for organizations to proactively identify critical security risks. Network traffic analysis products have emerged in response to attackers relentless innovation, offering organizations a realistic path forward for combatting creative attackers. Additionally, thanks to the widespread adoption of cloud computing, Device Operators processes, and the Internet of Things, maintaining effective network visibility has become a highly complex and overwhelming process. What makes network traffic analysis technology particularly meaningful is its ability to combine its core capabilities to deliver malicious intent detection. In this paper, we propose a novel darknet traffic analysis and network management framework to real-time automating the malicious intent detection process, using a weight agnostic neural networks architecture. It is an effective and accurate computational intelligent Forensics Tool for network traffic analysis, the demystification of malware traffic, and encrypted traffic identification in real-time. Based on Weight Agnostic Neural Networks methodology, we propose an automated searching neural net architectures strategy that can perform various tasks such as identify zero-day attacks. By automating the malicious intent detection process from the darknet, the advanced proposed solution is reducing the skills and effort barrier that prevents many organizations from effectively protecting their most critical assets

  • The Next Generation Cognitive Security Operations Center: Adaptive Analytic Lambda Architecture for Efficient Defense against Adversarial Attacks
    'MDPI AG', 2019
    Co-Authors: Demertzis Konstantinos, Kikiras Panayiotis, Tziritas Nikos, Sanchez, Salvador Llopis, Iliadis Lazaros
    Abstract:

    International audienceA Security Operations Center (SOC) is a central technical level unit responsible for monitoring, analyzing, assessing, and defending an organization's security posture on an ongoing basis. The SOC staff works closely with incident response teams, security analysts, network engineers and organization managers using sophisticated data processing technologies such as security analytics, threat intelligence, and asset criticality to ensure security issues are detected, analyzed and finally addressed quickly. Those techniques are part of a reactive security strategy because they rely on the human factor, experience and the judgment of security experts, using supplementary technology to evaluate the risk impact and minimize the attack surface. This study suggests an active security strategy that adopts a vigorous method including ingenuity, data analysis, processing and decision-making support to face various cyber hazards. Specifically, the paper introduces a novel intelligence driven cognitive computing SOC that is based exclusively on progressive fully automatic procedures. The proposed λ-Architecture Network Flow Forensics Framework (λ-ΝF3) is an efficient cybersecurity defense framework against adversarial attacks. It implements the Lambda machine learning architecture that can analyze a mixture of batch and streaming data, using two accurate novel computational intelligence algorithms. Specifically, it uses an Extreme Learning Machine neural network with Gaussian Radial Basis Function kernel (ELM/GRBFk) for the batch data analysis and a Self-Adjusting Memory k-Nearest Neighbors classifier (SAM/k-NN) to examine patterns from real-time streams. It is a Forensics Tool for big data that can enhance the automate defense strategies of SOCs to effectively respond to the threats their environments face