The Experts below are selected from a list of 8502 Experts worldwide ranked by ideXlab platform
William W Streilein - One of the best experts on this subject based on the ideXlab platform.
-
probabilistic threat propagation for Malicious Activity detection
International Conference on Acoustics Speech and Signal Processing, 2013Co-Authors: Kevin M Carter, Nwokedi Idika, William W StreileinAbstract:In this paper, we present a method for detecting Malicious Activity within networks of interest. We leverage prior community detection work by propagating threat probabilities across graph nodes, given an initial set of known Malicious nodes. We enhance prior work by employing constraints which remove the adverse effect of cyclic propagation that is a byproduct of current methods. We demonstrate the effectiveness of Probabilistic Threat Propagation on the task of detecting Malicious web destinations.
-
ICASSP - Probabilistic threat propagation for Malicious Activity detection
2013 IEEE International Conference on Acoustics Speech and Signal Processing, 2013Co-Authors: Kevin M Carter, Nwokedi Idika, William W StreileinAbstract:In this paper, we present a method for detecting Malicious Activity within networks of interest. We leverage prior community detection work by propagating threat probabilities across graph nodes, given an initial set of known Malicious nodes. We enhance prior work by employing constraints which remove the adverse effect of cyclic propagation that is a byproduct of current methods. We demonstrate the effectiveness of Probabilistic Threat Propagation on the task of detecting Malicious web destinations.
Oliver Spatscheck - One of the best experts on this subject based on the ideXlab platform.
-
automatically inferring the evolution of Malicious Activity on the internet
Network and Distributed System Security Symposium, 2013Co-Authors: Shobha Venkataraman, David Brumley, Subhabrata Sen, Oliver SpatscheckAbstract:Internet-based services routinely contend with a range of Malicious Activity (e.g., spam, scans, botnets) that can potentially arise from virtually any part of the global Internet infrastructure and that can shift longitudinally over time. In this paper, we develop the first algorithmic techniques to automatically infer regions of the Internet with shifting security characteristics in an online fashion. Conceptually, our key idea is to model the Malicious Activity on the Internet as a decision tree over the IP address space, and identify the dynamics of the Malicious Activity by inferring the dynamics of the decision tree. Our evaluations on large corpuses of mail data and botnet data indicate that our algorithms are fast, can keep up with Internet-scale traffic data, and can extract changes in sources of Malicious Activity substantially better (a factor of 2.5) than approaches based on using predetermined levels of aggregation such as BGP-based network-aware clusters. Our case studies demonstrate our algorithm’s ability to summarize large shifts in Malicious Activity to a small number of IP regions (by as much as two orders of magnitude), and thus help focus limited operator resources. Using our algorithms, we find that some regions of the Internet are prone to much faster changes than others, such as a set of small and medium-sized hosting providers that are of particular interest to mail operators.
-
NDSS - Automatically Inferring the Evolution of Malicious Activity on the Internet
2013Co-Authors: Shobha Venkataraman, David Brumley, Subhabrata Sen, Oliver SpatscheckAbstract:Internet-based services routinely contend with a range of Malicious Activity (e.g., spam, scans, botnets) that can potentially arise from virtually any part of the global Internet infrastructure and that can shift longitudinally over time. In this paper, we develop the first algorithmic techniques to automatically infer regions of the Internet with shifting security characteristics in an online fashion. Conceptually, our key idea is to model the Malicious Activity on the Internet as a decision tree over the IP address space, and identify the dynamics of the Malicious Activity by inferring the dynamics of the decision tree. Our evaluations on large corpuses of mail data and botnet data indicate that our algorithms are fast, can keep up with Internet-scale traffic data, and can extract changes in sources of Malicious Activity substantially better (a factor of 2.5) than approaches based on using predetermined levels of aggregation such as BGP-based network-aware clusters. Our case studies demonstrate our algorithm’s ability to summarize large shifts in Malicious Activity to a small number of IP regions (by as much as two orders of magnitude), and thus help focus limited operator resources. Using our algorithms, we find that some regions of the Internet are prone to much faster changes than others, such as a set of small and medium-sized hosting providers that are of particular interest to mail operators.
-
tracking dynamic sources of Malicious Activity at internet scale
Neural Information Processing Systems, 2009Co-Authors: Shobha Venkataraman, Subhabrata Sen, Avrim Blum, Dawn Song, Oliver SpatscheckAbstract:We formulate and address the problem of discovering dynamic Malicious regions on the Internet. We model this problem as one of adaptively pruning a known decision tree, but with additional challenges: (1) severe space requirements, since the underlying decision tree has over 4 billion leaves, and (2) a changing target function, since Malicious Activity on the Internet is dynamic. We present a novel algorithm that addresses this problem, by putting together a number of different "experts" algorithms and online paging algorithms. We prove guarantees on our algorithm's performance as a function of the best possible pruning of a similar size, and our experiments show that our algorithm achieves high accuracy on large real-world data sets, with significant improvements over existing approaches.
-
NIPS - Tracking Dynamic Sources of Malicious Activity at Internet Scale
2009Co-Authors: Shobha Venkataraman, Subhabrata Sen, Avrim Blum, Dawn Song, Oliver SpatscheckAbstract:We formulate and address the problem of discovering dynamic Malicious regions on the Internet. We model this problem as one of adaptively pruning a known decision tree, but with additional challenges: (1) severe space requirements, since the underlying decision tree has over 4 billion leaves, and (2) a changing target function, since Malicious Activity on the Internet is dynamic. We present a novel algorithm that addresses this problem, by putting together a number of different "experts" algorithms and online paging algorithms. We prove guarantees on our algorithm's performance as a function of the best possible pruning of a similar size, and our experiments show that our algorithm achieves high accuracy on large real-world data sets, with significant improvements over existing approaches.
Yanzhi Wang - One of the best experts on this subject based on the ideXlab platform.
-
database and benchmark for early stage Malicious Activity detection in 3d printing
Asia and South Pacific Design Automation Conference, 2020Co-Authors: Qinru Qiu, Yanzhi WangAbstract:Increasing Malicious users have sought practices to leverage 3D printing technology to produce unlawful tools in criminal activities. It is of vital importance to enable 3D printers to identify the objects to be printed and terminate at early stage if illegal objects are identified. Deep learning yields significant rises in performance in the object recognition tasks. However, the lack of large-scale databases in 3D printing domain stalls the advancement of automatic illegal weapon recognition. This paper presents a new 3D printing image database, namely C3PO, which compromises two subsets for the different system working scenarios. We extract images from the numerical control programming code files of 22 3D models, and then categorize the images into 10 distinct labels. These two sets are designed for identifying: (i). printing knowledge source (G-code) at beginning of manufacturing, (ii). printing procedure during manufacturing. Importantly, we demonstrate that the weapons can be recognized in either scenario using deep learning based approaches using our proposed database. The quantitative results are promising, and the future exploration of the database and the crime prevention in 3D printing are demanding tasks.
-
c3po database and benchmark for early stage Malicious Activity detection in 3d printing
arXiv: Computer Vision and Pattern Recognition, 2018Co-Authors: Aditya Singh Rathore, Qinru Qiu, Yanzhi WangAbstract:Increasing Malicious users have sought practices to leverage 3D printing technology to produce unlawful tools in criminal activities. Current regulations are inadequate to deal with the rapid growth of 3D printers. It is of vital importance to enable 3D printers to identify the objects to be printed, so that the manufacturing procedure of an illegal weapon can be terminated at the early stage. Deep learning yields significant rises in performance in the object recognition tasks. However, the lack of large-scale databases in 3D printing domain stalls the advancement of automatic illegal weapon recognition. This paper presents a new 3D printing image database, namely C3PO, which compromises two subsets for the different system working scenarios. We extract images from the numerical control programming code files of 22 3D models, and then categorize the images into 10 distinct labels. The first set consists of 62,200 images which represent the object projections on the three planes in a Cartesian coordinate system. And the second sets consists of sequences of total 671,677 images to simulate the cameras' captures of the printed objects. Importantly, we demonstrate that the weapons can be recognized in either scenario using deep learning based approaches using our proposed database. % We also use the trained deep models to build a prototype of object-aware 3D printer. The quantitative results are promising, and the future exploration of the database and the crime prevention in 3D printing are demanding tasks.
Hideya Ochiai - One of the best experts on this subject based on the ideXlab platform.
-
IMCOM - ARP Request Trend Fitting for Detecting Malicious Activity in LAN.
Advances in Intelligent Systems and Computing, 2019Co-Authors: Kai Matsufuji, Satoru Kobayashi, Hiroshi Esaki, Hideya OchiaiAbstract:Security of local area networks (LANs) attract enormous attention these days. LANs are not safe even under a well-configured firewall, because malware can be easily delivered through network applications. Thus we need to take counter measures against Malicious activities by focusing on each device itself. However, we cannot adopt many of existing methods to the devices which have limited resource capacity like IoT. Accordingly, we consider that the request pattern of address resolution protocol (ARP) may provide some indicators for finding such Malicious activities without putting a burden on each device. In this paper, We propose a method to detect Malicious network Activity by ARP monitoring. The detection method is based on a fitting model of ARP request trend. We especially focus on the destination devices of ARP request in outlier detection with the model. We made an experiment with a data of monitored ARP requests in our network. We also discuss parameter tuning and validity of the model based on three notable requirements.
-
arp request trend fitting for detecting Malicious Activity in lan
International Conference on Ubiquitous Information Management and Communication, 2019Co-Authors: Kai Matsufuji, Satoru Kobayashi, Hiroshi Esaki, Hideya OchiaiAbstract:Security of local area networks (LANs) attract enormous attention these days. LANs are not safe even under a well-configured firewall, because malware can be easily delivered through network applications. Thus we need to take counter measures against Malicious activities by focusing on each device itself. However, we cannot adopt many of existing methods to the devices which have limited resource capacity like IoT. Accordingly, we consider that the request pattern of address resolution protocol (ARP) may provide some indicators for finding such Malicious activities without putting a burden on each device. In this paper, We propose a method to detect Malicious network Activity by ARP monitoring. The detection method is based on a fitting model of ARP request trend. We especially focus on the destination devices of ARP request in outlier detection with the model. We made an experiment with a data of monitored ARP requests in our network. We also discuss parameter tuning and validity of the model based on three notable requirements.
Kevin M Carter - One of the best experts on this subject based on the ideXlab platform.
-
probabilistic threat propagation for Malicious Activity detection
International Conference on Acoustics Speech and Signal Processing, 2013Co-Authors: Kevin M Carter, Nwokedi Idika, William W StreileinAbstract:In this paper, we present a method for detecting Malicious Activity within networks of interest. We leverage prior community detection work by propagating threat probabilities across graph nodes, given an initial set of known Malicious nodes. We enhance prior work by employing constraints which remove the adverse effect of cyclic propagation that is a byproduct of current methods. We demonstrate the effectiveness of Probabilistic Threat Propagation on the task of detecting Malicious web destinations.
-
ICASSP - Probabilistic threat propagation for Malicious Activity detection
2013 IEEE International Conference on Acoustics Speech and Signal Processing, 2013Co-Authors: Kevin M Carter, Nwokedi Idika, William W StreileinAbstract:In this paper, we present a method for detecting Malicious Activity within networks of interest. We leverage prior community detection work by propagating threat probabilities across graph nodes, given an initial set of known Malicious nodes. We enhance prior work by employing constraints which remove the adverse effect of cyclic propagation that is a byproduct of current methods. We demonstrate the effectiveness of Probabilistic Threat Propagation on the task of detecting Malicious web destinations.