The Experts below are selected from a list of 1521 Experts worldwide ranked by ideXlab platform

Salvatore J. Stolfo - One of the best experts on this subject based on the ideXlab platform.

  • MMM-ACNS - A Behavior-Based Approach to Securing Email Systems
    Lecture Notes in Computer Science, 2003
    Co-Authors: Salvatore J. Stolfo, Shlomo Hershkop, Ke Wang, Olivier Nimeskern
    Abstract:

    The Malicious Email Tracking (MET) system, reported in a prior publication, is a behavior-based security system for Email services. The Email Mining Toolkit (EMT) presented in this paper is an offline Email archive data mining analysis system that is designed to assist computing models of Malicious Email behavior for deployment in an online MET system. EMT includes a variety of behavior models for Email attachments, user accounts and groups of accounts. Each model computed is used to detect anomalous and errant Email behaviors. We report on the set of features implemented in the current version of EMT, and describe tests of the system and our plans for extensions to the set of models.

  • system and methods for detecting Malicious Email transmission
    2002
    Co-Authors: Salvatore J. Stolfo, Shlomo Herskop, Eleazar Eskin, Manasi Bhattacharyya
    Abstract:

    A system and methods of detecting an occurrence of a violation of an Email security policy of a computer system. A model relating to the transmission of prior Emails through the computer system is defined which is derived from statistics relating to the prior Emails. For selected Emails to be analyzed, statistics concerning the selected Email are gathered. Such statistics may refer to the behavior or other features of the selected Emails, attachments to Emails, or Email accounts. The determination of whether a violation of an Email security policy has occurred is performed by applying the model of prior Email transmission to the statistics relating to the selected Email. The model may be statistical or probabilistic. A model of prior Email transmission may include grouping Email recipients into cliques. A determination of a violation of a security policy may occur if Email recipients for a particular Email are in more than one clique.

  • mef Malicious Email filter a unix mail filter that detects Malicious windows executables
    USENIX Annual Technical Conference, 2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

  • USENIX Annual Technical Conference, FREENIX Track - MEF: Malicious Email Filter - A UNIX Mail Filter That Detects Malicious Windows Executables
    2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

Manasi Bhattacharyya - One of the best experts on this subject based on the ideXlab platform.

  • met an experimental system for Malicious Email tracking
    New Security Paradigms Workshop, 2002
    Co-Authors: Manasi Bhattacharyya, Shlomo Hershkop, Eleazar Eskin
    Abstract:

    Despite the use of state of the art methods to protect against Malicious programs, they continue to threaten and damage computer systems around the world. In this paper we present MET, the Malicious Email Tracking system, designed to automatically report statistics on the flow behavior of Malicious software delivered via Email attachments both at a local and global level. MET can help reduce the spread of Malicious software worldwide, especially self-replicating viruses, as well as provide further insight toward minimizing damage caused by Malicious programs in the future. In addition, the system can help system administrators detect all of the points of entry of a Malicious Email into a network. The core of MET's operation is a database of statistics about the trajectory of Email attachments in and out of a network system, and the culling together of these statistics across networks to present a global view of the spread of the Malicious software. From a statistical perspective sampling only a small amount of traffic (for example, .1 %) of a very large Email stream is sufficient to detect suspicious or otherwise new Email viruses that may be undetected by standard signature-based scanners. Therefore, relatively few MET installations would be necessary to gather sufficient data in order to provide broad protection services. Small scale simulations are presented to demonstrate MET in operation and suggests how detection of new virus propagations via flow statistics can be automated.

  • system and methods for detecting Malicious Email transmission
    2002
    Co-Authors: Salvatore J. Stolfo, Shlomo Herskop, Eleazar Eskin, Manasi Bhattacharyya
    Abstract:

    A system and methods of detecting an occurrence of a violation of an Email security policy of a computer system. A model relating to the transmission of prior Emails through the computer system is defined which is derived from statistics relating to the prior Emails. For selected Emails to be analyzed, statistics concerning the selected Email are gathered. Such statistics may refer to the behavior or other features of the selected Emails, attachments to Emails, or Email accounts. The determination of whether a violation of an Email security policy has occurred is performed by applying the model of prior Email transmission to the statistics relating to the selected Email. The model may be statistical or probabilistic. A model of prior Email transmission may include grouping Email recipients into cliques. A determination of a violation of a security policy may occur if Email recipients for a particular Email are in more than one clique.

  • NSPW - MET: an experimental system for Malicious Email Tracking
    Proceedings of the 2002 workshop on New security paradigms - NSPW '02, 2002
    Co-Authors: Manasi Bhattacharyya, Shlomo Hershkop, Eleazar Eskin
    Abstract:

    Despite the use of state of the art methods to protect against Malicious programs, they continue to threaten and damage computer systems around the world. In this paper we present MET, the Malicious Email Tracking system, designed to automatically report statistics on the flow behavior of Malicious software delivered via Email attachments both at a local and global level. MET can help reduce the spread of Malicious software worldwide, especially self-replicating viruses, as well as provide further insight toward minimizing damage caused by Malicious programs in the future. In addition, the system can help system administrators detect all of the points of entry of a Malicious Email into a network. The core of MET's operation is a database of statistics about the trajectory of Email attachments in and out of a network system, and the culling together of these statistics across networks to present a global view of the spread of the Malicious software. From a statistical perspective sampling only a small amount of traffic (for example, .1 %) of a very large Email stream is sufficient to detect suspicious or otherwise new Email viruses that may be undetected by standard signature-based scanners. Therefore, relatively few MET installations would be necessary to gather sufficient data in order to provide broad protection services. Small scale simulations are presented to demonstrate MET in operation and suggests how detection of new virus propagations via flow statistics can be automated.

  • mef Malicious Email filter a unix mail filter that detects Malicious windows executables
    USENIX Annual Technical Conference, 2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

  • USENIX Annual Technical Conference, FREENIX Track - MEF: Malicious Email Filter - A UNIX Mail Filter That Detects Malicious Windows Executables
    2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

Eleazar Eskin - One of the best experts on this subject based on the ideXlab platform.

  • met an experimental system for Malicious Email tracking
    New Security Paradigms Workshop, 2002
    Co-Authors: Manasi Bhattacharyya, Shlomo Hershkop, Eleazar Eskin
    Abstract:

    Despite the use of state of the art methods to protect against Malicious programs, they continue to threaten and damage computer systems around the world. In this paper we present MET, the Malicious Email Tracking system, designed to automatically report statistics on the flow behavior of Malicious software delivered via Email attachments both at a local and global level. MET can help reduce the spread of Malicious software worldwide, especially self-replicating viruses, as well as provide further insight toward minimizing damage caused by Malicious programs in the future. In addition, the system can help system administrators detect all of the points of entry of a Malicious Email into a network. The core of MET's operation is a database of statistics about the trajectory of Email attachments in and out of a network system, and the culling together of these statistics across networks to present a global view of the spread of the Malicious software. From a statistical perspective sampling only a small amount of traffic (for example, .1 %) of a very large Email stream is sufficient to detect suspicious or otherwise new Email viruses that may be undetected by standard signature-based scanners. Therefore, relatively few MET installations would be necessary to gather sufficient data in order to provide broad protection services. Small scale simulations are presented to demonstrate MET in operation and suggests how detection of new virus propagations via flow statistics can be automated.

  • system and methods for detecting Malicious Email transmission
    2002
    Co-Authors: Salvatore J. Stolfo, Shlomo Herskop, Eleazar Eskin, Manasi Bhattacharyya
    Abstract:

    A system and methods of detecting an occurrence of a violation of an Email security policy of a computer system. A model relating to the transmission of prior Emails through the computer system is defined which is derived from statistics relating to the prior Emails. For selected Emails to be analyzed, statistics concerning the selected Email are gathered. Such statistics may refer to the behavior or other features of the selected Emails, attachments to Emails, or Email accounts. The determination of whether a violation of an Email security policy has occurred is performed by applying the model of prior Email transmission to the statistics relating to the selected Email. The model may be statistical or probabilistic. A model of prior Email transmission may include grouping Email recipients into cliques. A determination of a violation of a security policy may occur if Email recipients for a particular Email are in more than one clique.

  • NSPW - MET: an experimental system for Malicious Email Tracking
    Proceedings of the 2002 workshop on New security paradigms - NSPW '02, 2002
    Co-Authors: Manasi Bhattacharyya, Shlomo Hershkop, Eleazar Eskin
    Abstract:

    Despite the use of state of the art methods to protect against Malicious programs, they continue to threaten and damage computer systems around the world. In this paper we present MET, the Malicious Email Tracking system, designed to automatically report statistics on the flow behavior of Malicious software delivered via Email attachments both at a local and global level. MET can help reduce the spread of Malicious software worldwide, especially self-replicating viruses, as well as provide further insight toward minimizing damage caused by Malicious programs in the future. In addition, the system can help system administrators detect all of the points of entry of a Malicious Email into a network. The core of MET's operation is a database of statistics about the trajectory of Email attachments in and out of a network system, and the culling together of these statistics across networks to present a global view of the spread of the Malicious software. From a statistical perspective sampling only a small amount of traffic (for example, .1 %) of a very large Email stream is sufficient to detect suspicious or otherwise new Email viruses that may be undetected by standard signature-based scanners. Therefore, relatively few MET installations would be necessary to gather sufficient data in order to provide broad protection services. Small scale simulations are presented to demonstrate MET in operation and suggests how detection of new virus propagations via flow statistics can be automated.

  • mef Malicious Email filter a unix mail filter that detects Malicious windows executables
    USENIX Annual Technical Conference, 2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

  • USENIX Annual Technical Conference, FREENIX Track - MEF: Malicious Email Filter - A UNIX Mail Filter That Detects Malicious Windows Executables
    2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

Matthew G Schultz - One of the best experts on this subject based on the ideXlab platform.

  • mef Malicious Email filter a unix mail filter that detects Malicious windows executables
    USENIX Annual Technical Conference, 2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

  • USENIX Annual Technical Conference, FREENIX Track - MEF: Malicious Email Filter - A UNIX Mail Filter That Detects Malicious Windows Executables
    2001
    Co-Authors: Matthew G Schultz, Manasi Bhattacharyya, Eleazar Eskin, Erez Zadok, Salvatore J. Stolfo
    Abstract:

    We present Malicious Email Filter, MEF, a freely distributed Malicious binary filter incorporated into Procmail that can detect Malicious Windows attachments by integrating with a UNIX mail server. The system has three capabilities: detection of known and unknown Malicious attachments, tracking the propagation of Malicious attachments and efficient model update algorithms. The system filters multiple Malicious attachments in an Email by using detection models obtained from data mining over known Malicious attachments. It leverages preliminary research in data mining applied to Malicious executables which allows the detection of previously unseen, Malicious attachments. In addition, the system provides a method for monitoring and measurement of the spread of Malicious attachments. Finally, the system also allows for the efficient propagation of detection models from a central server. These updated models can be downloaded by a system administrator and easily incorporated into the current model. The system will be released under GPL in June 2001.

Nicolás Figueroa - One of the best experts on this subject based on the ideXlab platform.

  • Online phishing classification using adversarial data mining and signaling games
    ACM SIGKDD Explorations Newsletter, 2010
    Co-Authors: Gaston L'huillier, Richard Weber, Nicolás Figueroa
    Abstract:

    In adversarial systems, the performance of a classifier decreases after it is deployed, as the adversary learns to defeat it. Recently, adversarial data mining was introduced as a solution to this, where the classification problem is viewed as a game mechanism between an adversary and an intelligent and adaptive classifier. Over the last years, phishing fraud through Malicious Email messages has been a serious threat that affects global security and economy, where traditional spam filtering techniques have shown to be ineffective. In this domain, using dynamic games of incomplete information, a game theoretic data mining framework is proposed in order to build an adversary aware classifier for phishing fraud detection. To build the classifier, an online version of the Weighted Margin Support Vector Machines with a game theoretic prior knowledge function is proposed. In this paper, a new content-based feature extraction technique for phishing filtering is described. Experiments show that the proposed classifier is highly competitive compared with previously proposed online classification algorithms in this adversarial environment, and promising results where obtained using traditional machine learning techniques over extracted features. Copyright 2009 ACM.

  • KDD Workshop on CyberSecurity and Intelligence Informatics - Online phishing classification using adversarial data mining and signaling games
    Proceedings of the ACM SIGKDD Workshop on CyberSecurity and Intelligence Informatics - CSI-KDD '09, 2009
    Co-Authors: Gaston L'huillier, Richard Weber, Nicolás Figueroa
    Abstract:

    In adversarial systems, the performance of a classifier decreases after it is deployed, as the adversary learns to defeat it. Recently, adversarial data mining was introduced as a solution to this, where the classification problem is viewed as a game mechanism between an adversary and an intelligent and adaptive classifier. Over the last years, phishing fraud through Malicious Email messages has been a serious threat that affects global security and economy, where traditional spam filtering techniques have shown to be ineffective. In this domain, using dynamic games of incomplete information, a game theoretic data mining framework is proposed in order to build an adversary aware classifier for phishing fraud detection. To build the classifier, an online version of the Weighted Margin Support Vector Machines with a game theoretic prior knowledge function is proposed. In this paper, a new content-based feature extraction technique for phishing filtering is described. Experiments show that the proposed classifier is highly competitive compared with previously proposed online classification algorithms in this adversarial environment, and promising results where obtained using traditional machine learning techniques over extracted features.