The Experts below are selected from a list of 51 Experts worldwide ranked by ideXlab platform
Debin Gao - One of the best experts on this subject based on the ideXlab platform.
-
D.: Towards Ground Truthing Observations in Gray-Box Anomaly Detection
2011Co-Authors: Jiang Ming, Haibin Zhang, Debin GaoAbstract:Abstract—Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides groun
-
NSS - Towards ground truthing observations in gray-box anomaly detection
2011 5th International Conference on Network and System Security, 2011Co-Authors: Jiang Ming, Haibin Zhang, Debin GaoAbstract:Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.
Jiang Ming - One of the best experts on this subject based on the ideXlab platform.
-
D.: Towards Ground Truthing Observations in Gray-Box Anomaly Detection
2011Co-Authors: Jiang Ming, Haibin Zhang, Debin GaoAbstract:Abstract—Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides groun
-
Towards ground truthing observations in gray-box anomaly detection
2011 5th International Conference on Network and System Security, 2011Co-Authors: Jiang Ming, Haibin ZhangAbstract:Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.
-
NSS - Towards ground truthing observations in gray-box anomaly detection
2011 5th International Conference on Network and System Security, 2011Co-Authors: Jiang Ming, Haibin Zhang, Debin GaoAbstract:Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.
Haibin Zhang - One of the best experts on this subject based on the ideXlab platform.
-
D.: Towards Ground Truthing Observations in Gray-Box Anomaly Detection
2011Co-Authors: Jiang Ming, Haibin Zhang, Debin GaoAbstract:Abstract—Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides groun
-
Towards ground truthing observations in gray-box anomaly detection
2011 5th International Conference on Network and System Security, 2011Co-Authors: Jiang Ming, Haibin ZhangAbstract:Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.
-
NSS - Towards ground truthing observations in gray-box anomaly detection
2011 5th International Conference on Network and System Security, 2011Co-Authors: Jiang Ming, Haibin Zhang, Debin GaoAbstract:Anomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file Descriptor being equal to a Socket Descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training.
Jan-simon Pendry - One of the best experts on this subject based on the ideXlab platform.
-
USENIX - Portals in 4.4BSD
1995Co-Authors: W. Richard Stevens, Jan-simon PendryAbstract:Portals were added to 4.4BSD as an experimental feature and are in the publicly available 4.4BSD-Lite distribution. Portals provide access to alternate file types or devices using names in the normal filesystem that a process just opens. For example, an open of /p/tcp/foo.com/smtp returns a TCP Socket Descriptor to the calling process that is connected to the SMTP server on the specified host. By providing access through the normal filesystem, the calling process need not be aware of the special functions necessary to create a TCP Socket and establish a TCP connection. This makes TCP connections, for example, available to programs such as Awk, Tcl, and shell scripts. This paper describes the implementation of portals in 4.4BSD as another type of filesystem and provides some examples.
W. Richard Stevens - One of the best experts on this subject based on the ideXlab platform.
-
USENIX - Portals in 4.4BSD
1995Co-Authors: W. Richard Stevens, Jan-simon PendryAbstract:Portals were added to 4.4BSD as an experimental feature and are in the publicly available 4.4BSD-Lite distribution. Portals provide access to alternate file types or devices using names in the normal filesystem that a process just opens. For example, an open of /p/tcp/foo.com/smtp returns a TCP Socket Descriptor to the calling process that is connected to the SMTP server on the specified host. By providing access through the normal filesystem, the calling process need not be aware of the special functions necessary to create a TCP Socket and establish a TCP connection. This makes TCP connections, for example, available to programs such as Awk, Tcl, and shell scripts. This paper describes the implementation of portals in 4.4BSD as another type of filesystem and provides some examples.