The Experts below are selected from a list of 3918 Experts worldwide ranked by ideXlab platform
Mohamed-slim Alouini - One of the best experts on this subject based on the ideXlab platform.
-
Spatial Firewalls: Quarantining Malware Epidemics in Large Scale Massive Wireless Networks
arXiv: Cryptography and Security, 2020Co-Authors: Hesham Elsawy, Mustafa A. Kishk, Mohamed-slim AlouiniAbstract:Billions of wireless devices are foreseen to participate in big data aggregation and smart automation in order to interface the cyber and physical worlds. Such large-scale ultra-dense wireless connectivity is vulnerable to Malicious Software (Malware) epidemics. Malware worms can exploit multi-hop wireless connectivity to stealthily diffuse throughout the wireless network without being noticed to security servers at the core network. Compromised devices can then be used by adversaries to remotely launch cyber attacks that cause large-scale critical physical damage and threaten public safety. This article overviews the types, threats, and propagation models for Malware epidemics in large-scale wireless networks (LSWN). Then, the article proposes a novel and cost efficient countermeasure against Malware epidemics in LSWN, denoted as spatial firewalls. It is shown that equipping a strategically selected small portion (i.e., less than 10\%) of the devices with state-of-the-art security mechanisms is sufficient to create spatially secured zones that quarantine Malware epidemics. Quarantined infected devices are then cured by on-demand localized Software patching. To this end, several firewall deployment strategies are discussed and compared.
-
Spatial Firewalls: Quarantining Malware Epidemics in Large-Scale Massive Wireless Networks
IEEE Communications Magazine, 2020Co-Authors: Hesham Elsawy, Mustafa A. Kishk, Mohamed-slim AlouiniAbstract:Billions of wireless devices are foreseen to participate in big data aggregation and smart automation in order to interface the cyber and physical worlds. Such large-scale ultra-dense wireless connectivity is vulnerable to Malicious Software (Malware) epidemics. Malware worms can exploit multihop wireless connectivity to stealthily diffuse throughout the wireless network without being noticed by security servers at the core network. Compromised devices can then be used by adversaries to remotely launch cyber attacks that cause large-scale critical physical damage and threaten public safety. This article overviews the types, threats, and propagation models for Malware epidemics in large-scale wireless networks (LSWNs). Then the article proposes a novel and cost-efficient countermeasure against Malware epidemics in LSWNs, called spatial firewalls. It is shown that equipping a strategically selected small portion (i.e., less than 10 percent) of the devices with state-of-the-art security mechanisms is sufficient to create spatially secured zones that quarantine Malware epidemics. Quarantined infected devices are then cured by on-demand localized Software patching. To this end, several firewall deployment strategies are discussed and compared.
Wolfgang Aigner - One of the best experts on this subject based on the ideXlab platform.
-
A knowledge-assisted visual Malware analysis system
Computers & Security, 2017Co-Authors: Markus Wagner, Alexander Rind, Niklas Thr, Wolfgang AignerAbstract:IT-security experts engage in behavior-based Malware analysis in order to learn about previously unknown samples of Malicious Software (Malware) or Malware families. For this, they need to find and categorize suspicious patterns from large collections of execution traces. Currently available systems do not meet the analysts' needs described as: visual access suitable for complex data structures, visual representations appropriate for IT-security experts, provide work flow-specific interaction techniques, and the ability to externalize knowledge in the form of rules to ease analysis and for sharing with colleagues. To close this gap, we designed and developed KAMAS, a knowledge-assisted visualization system for behavior-based Malware analysis. KAMAS supports Malware analysts with visual analytics and knowledge externalization methods for the analysis process. The paper at hand is a design study that describes the design, implementation, and evaluation of the prototype. We report on the validation of KAMAS by expert reviews, a user study with domain experts, and focus group meetings with analysts from industry. Additionally, we reflect the gained insights of the design study and discuss the advantages and disadvantages of the applied visualization methods.Comment: 15 pages, 8 figure
-
a survey of visualization systems for Malware analysis
Eurographics, 2015Co-Authors: Markus Wagner, Alexander Rind, Fabian Fischer, Robert Luh, Andrea Haberson, Daniel A Keim, Wolfgang AignerAbstract:Due to the increasing threat from Malicious Software (Malware), monitoring of vulnerable systems is becoming increasingly important. The need to log and analyze activity encompasses networks, individual computers, as well as mobile devices. While there are various automatic approaches and techniques available to detect, identify, or capture Malware, the actual analysis of the ever-increasing number of suspicious samples is a time-consuming process for Malware analysts. The use of visualization and highly interactive visual analytics systems can help to support this analysis process with respect to investigation, comparison, and summarization of Malware samples. Currently, there is no survey available that reviews available visualization systems supporting this important and emerging field. We provide a systematic overview and categorization of Malware visualization systems from the perspective of visual analytics. Additionally, we identify and evaluate data providers and commercial tools that produce meaningful input data for the reviewed Malware visualization systems. This helps to reveal data types that are currently underrepresented, enabling new research opportunities in the visualization community.
-
EuroVis (STARs) - A Survey of Visualization Systems for Malware Analysis
2015Co-Authors: Markus Wagner, Alexander Rind, Fabian Fischer, Robert Luh, Andrea Haberson, Daniel A Keim, Wolfgang AignerAbstract:Due to the increasing threat from Malicious Software (Malware), monitoring of vulnerable systems is becoming increasingly important. The need to log and analyze activity encompasses networks, individual computers, as well as mobile devices. While there are various automatic approaches and techniques available to detect, identify, or capture Malware, the actual analysis of the ever-increasing number of suspicious samples is a time-consuming process for Malware analysts. The use of visualization and highly interactive visual analytics systems can help to support this analysis process with respect to investigation, comparison, and summarization of Malware samples. Currently, there is no survey available that reviews available visualization systems supporting this important and emerging field. We provide a systematic overview and categorization of Malware visualization systems from the perspective of visual analytics. Additionally, we identify and evaluate data providers and commercial tools that produce meaningful input data for the reviewed Malware visualization systems. This helps to reveal data types that are currently underrepresented, enabling new research opportunities in the visualization community.
Hesham Elsawy - One of the best experts on this subject based on the ideXlab platform.
-
Spatial Firewalls: Quarantining Malware Epidemics in Large Scale Massive Wireless Networks
arXiv: Cryptography and Security, 2020Co-Authors: Hesham Elsawy, Mustafa A. Kishk, Mohamed-slim AlouiniAbstract:Billions of wireless devices are foreseen to participate in big data aggregation and smart automation in order to interface the cyber and physical worlds. Such large-scale ultra-dense wireless connectivity is vulnerable to Malicious Software (Malware) epidemics. Malware worms can exploit multi-hop wireless connectivity to stealthily diffuse throughout the wireless network without being noticed to security servers at the core network. Compromised devices can then be used by adversaries to remotely launch cyber attacks that cause large-scale critical physical damage and threaten public safety. This article overviews the types, threats, and propagation models for Malware epidemics in large-scale wireless networks (LSWN). Then, the article proposes a novel and cost efficient countermeasure against Malware epidemics in LSWN, denoted as spatial firewalls. It is shown that equipping a strategically selected small portion (i.e., less than 10\%) of the devices with state-of-the-art security mechanisms is sufficient to create spatially secured zones that quarantine Malware epidemics. Quarantined infected devices are then cured by on-demand localized Software patching. To this end, several firewall deployment strategies are discussed and compared.
-
Spatial Firewalls: Quarantining Malware Epidemics in Large-Scale Massive Wireless Networks
IEEE Communications Magazine, 2020Co-Authors: Hesham Elsawy, Mustafa A. Kishk, Mohamed-slim AlouiniAbstract:Billions of wireless devices are foreseen to participate in big data aggregation and smart automation in order to interface the cyber and physical worlds. Such large-scale ultra-dense wireless connectivity is vulnerable to Malicious Software (Malware) epidemics. Malware worms can exploit multihop wireless connectivity to stealthily diffuse throughout the wireless network without being noticed by security servers at the core network. Compromised devices can then be used by adversaries to remotely launch cyber attacks that cause large-scale critical physical damage and threaten public safety. This article overviews the types, threats, and propagation models for Malware epidemics in large-scale wireless networks (LSWNs). Then the article proposes a novel and cost-efficient countermeasure against Malware epidemics in LSWNs, called spatial firewalls. It is shown that equipping a strategically selected small portion (i.e., less than 10 percent) of the devices with state-of-the-art security mechanisms is sufficient to create spatially secured zones that quarantine Malware epidemics. Quarantined infected devices are then cured by on-demand localized Software patching. To this end, several firewall deployment strategies are discussed and compared.
Markus Wagner - One of the best experts on this subject based on the ideXlab platform.
-
A knowledge-assisted visual Malware analysis system
Computers & Security, 2017Co-Authors: Markus Wagner, Alexander Rind, Niklas Thr, Wolfgang AignerAbstract:IT-security experts engage in behavior-based Malware analysis in order to learn about previously unknown samples of Malicious Software (Malware) or Malware families. For this, they need to find and categorize suspicious patterns from large collections of execution traces. Currently available systems do not meet the analysts' needs described as: visual access suitable for complex data structures, visual representations appropriate for IT-security experts, provide work flow-specific interaction techniques, and the ability to externalize knowledge in the form of rules to ease analysis and for sharing with colleagues. To close this gap, we designed and developed KAMAS, a knowledge-assisted visualization system for behavior-based Malware analysis. KAMAS supports Malware analysts with visual analytics and knowledge externalization methods for the analysis process. The paper at hand is a design study that describes the design, implementation, and evaluation of the prototype. We report on the validation of KAMAS by expert reviews, a user study with domain experts, and focus group meetings with analysts from industry. Additionally, we reflect the gained insights of the design study and discuss the advantages and disadvantages of the applied visualization methods.Comment: 15 pages, 8 figure
-
a survey of visualization systems for Malware analysis
Eurographics, 2015Co-Authors: Markus Wagner, Alexander Rind, Fabian Fischer, Robert Luh, Andrea Haberson, Daniel A Keim, Wolfgang AignerAbstract:Due to the increasing threat from Malicious Software (Malware), monitoring of vulnerable systems is becoming increasingly important. The need to log and analyze activity encompasses networks, individual computers, as well as mobile devices. While there are various automatic approaches and techniques available to detect, identify, or capture Malware, the actual analysis of the ever-increasing number of suspicious samples is a time-consuming process for Malware analysts. The use of visualization and highly interactive visual analytics systems can help to support this analysis process with respect to investigation, comparison, and summarization of Malware samples. Currently, there is no survey available that reviews available visualization systems supporting this important and emerging field. We provide a systematic overview and categorization of Malware visualization systems from the perspective of visual analytics. Additionally, we identify and evaluate data providers and commercial tools that produce meaningful input data for the reviewed Malware visualization systems. This helps to reveal data types that are currently underrepresented, enabling new research opportunities in the visualization community.
-
EuroVis (STARs) - A Survey of Visualization Systems for Malware Analysis
2015Co-Authors: Markus Wagner, Alexander Rind, Fabian Fischer, Robert Luh, Andrea Haberson, Daniel A Keim, Wolfgang AignerAbstract:Due to the increasing threat from Malicious Software (Malware), monitoring of vulnerable systems is becoming increasingly important. The need to log and analyze activity encompasses networks, individual computers, as well as mobile devices. While there are various automatic approaches and techniques available to detect, identify, or capture Malware, the actual analysis of the ever-increasing number of suspicious samples is a time-consuming process for Malware analysts. The use of visualization and highly interactive visual analytics systems can help to support this analysis process with respect to investigation, comparison, and summarization of Malware samples. Currently, there is no survey available that reviews available visualization systems supporting this important and emerging field. We provide a systematic overview and categorization of Malware visualization systems from the perspective of visual analytics. Additionally, we identify and evaluate data providers and commercial tools that produce meaningful input data for the reviewed Malware visualization systems. This helps to reveal data types that are currently underrepresented, enabling new research opportunities in the visualization community.
Thorsten Holz - One of the best experts on this subject based on the ideXlab platform.
-
SSS - TRUMANBOX: improving dynamic Malware analysis by emulating the internet
Lecture Notes in Computer Science, 2011Co-Authors: Christian Gorecki, Felix C Freiling, Marc Kührer, Thorsten HolzAbstract:Dynamic analysis of Malicious Software (Malware) is a powerful tool in countering modern threats on the Internet. In dynamic analysis, a Malware sample is executed in a controlled environment and its actions are logged. Through dynamic analysis, an analyst can quickly obtain an overview of Malware behavior and can decide whether or not to indulge into tedious manual analysis of the sample. However, usual dynamic analysis exposes the Internet to the threats of an executed Malware (like portscans) because advanced concealment techniques of Malware often require full Internet access. For example, a missing link to the Internet or the unavailability of a specific server often causes the Malware to not trigger its Malicious behavior. In this paper, we present TRUMANBOX, a technique to emulate relevant parts of the Internet to enhance dynamic Malware analysis. We show that TRUMANBOX not only prevents many threats but also enlarges the scope of the types of Malware that can be analyzed dynamically.
-
visual analysis of Malware behavior using treemaps and thread graphs
Visualization for Computer Security, 2009Co-Authors: Philipp Trinius, Thorsten Holz, Jan Gobel, Felix C FreilingAbstract:We study techniques to visualize the behavior of Malicious Software (Malware). Our aim is to help human analysts to quickly assess and classify the nature of a new Malware sample. Our techniques are based on a parametrized abstraction of detailed behavioral reports automatically generated by sandbox environments. We then explore two visualization techniques: treemaps and thread graphs. We argue that both techniques can effectively support a human analyst (a) in detecting Maliciousness of Software, and (b) in classifying Malicious behavior.
-
VizSEC - Visual analysis of Malware behavior using treemaps and thread graphs
2009 6th International Workshop on Visualization for Cyber Security, 2009Co-Authors: Philipp Trinius, Thorsten Holz, Jan Gobel, Felix C FreilingAbstract:We study techniques to visualize the behavior of Malicious Software (Malware). Our aim is to help human analysts to quickly assess and classify the nature of a new Malware sample. Our techniques are based on a parametrized abstraction of detailed behavioral reports automatically generated by sandbox environments. We then explore two visualization techniques: treemaps and thread graphs. We argue that both techniques can effectively support a human analyst (a) in detecting Maliciousness of Software, and (b) in classifying Malicious behavior.