The Experts below are selected from a list of 15 Experts worldwide ranked by ideXlab platform

Shamik Sengupta - One of the best experts on this subject based on the ideXlab platform.

  • sharing susceptible passwords as cyber Threat Intelligence Feed
    Military Communications Conference, 2018
    Co-Authors: Iman Vakilinia, Sui Cheung, Shamik Sengupta
    Abstract:

    Password-strength checkers provide Feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber Threat Intelligence Feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

  • MILCOM - Sharing Susceptible Passwords as Cyber Threat Intelligence Feed
    MILCOM 2018 - 2018 IEEE Military Communications Conference (MILCOM), 2018
    Co-Authors: Iman Vakilinia, Sui Cheung, Shamik Sengupta
    Abstract:

    Password-strength checkers provide Feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber Threat Intelligence Feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

Iman Vakilinia - One of the best experts on this subject based on the ideXlab platform.

  • sharing susceptible passwords as cyber Threat Intelligence Feed
    Military Communications Conference, 2018
    Co-Authors: Iman Vakilinia, Sui Cheung, Shamik Sengupta
    Abstract:

    Password-strength checkers provide Feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber Threat Intelligence Feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

  • MILCOM - Sharing Susceptible Passwords as Cyber Threat Intelligence Feed
    MILCOM 2018 - 2018 IEEE Military Communications Conference (MILCOM), 2018
    Co-Authors: Iman Vakilinia, Sui Cheung, Shamik Sengupta
    Abstract:

    Password-strength checkers provide Feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber Threat Intelligence Feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

Sui Cheung - One of the best experts on this subject based on the ideXlab platform.

  • sharing susceptible passwords as cyber Threat Intelligence Feed
    Military Communications Conference, 2018
    Co-Authors: Iman Vakilinia, Sui Cheung, Shamik Sengupta
    Abstract:

    Password-strength checkers provide Feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber Threat Intelligence Feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

  • MILCOM - Sharing Susceptible Passwords as Cyber Threat Intelligence Feed
    MILCOM 2018 - 2018 IEEE Military Communications Conference (MILCOM), 2018
    Co-Authors: Iman Vakilinia, Sui Cheung, Shamik Sengupta
    Abstract:

    Password-strength checkers provide Feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber Threat Intelligence Feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

John Pirc - One of the best experts on this subject based on the ideXlab platform.

  • 9 – Connecting the Dots
    Threat Forecasting, 2020
    Co-Authors: John Pirc
    Abstract:

    Connecting the dots is a symbolic way of stating we want to discuss all the topics within the preceding chapters by interweaving other related topics to show the value Threat forecasting has for your organization. This chapter is broken into five main sections ranging from the comparing and contrasting of historical Threat reporting and Threat forecasting, to real-world examples where Threat forecasting played a role or could have played a role in some of the major data breaches in recent time. The first section discusses historical Threat reporting and its relationship to Threat forecasting. When discussing this topic with fellow colleagues in the information security industry, there was an automatic assumption that we no longer believe this is of any value. The opposite is in fact true. Historical Threat reporting provides great value to organizations around the world, and these types of reports are available from security product vendors to security Intelligence companies. There are several pitfalls associated with historical Threat reports, however these are overcome when applying Threat forecasting within your organization. The next section dives into the state of the security industry by discussing the types of Threats security products deal with as well as analyzing data from a third party, independent security testing lab. The types of Threats security products need to deal with can be broken into three types. These are Threats completely known to the security product, Threats detected partially by the security product and Threats completely unknown to the security product. The final type is where security products are the weakest and this is where Threat Intelligence combined with Threat forecasting can help improve the gaps in your security coverage thus limiting exposure to your Threat landscape. These unknown Threats are best highlighted by the data within the study carried out by the cited independent testing lab, as they show, historically, that security products have had security efficacy issues. Finally, we will outline how you can begin to apply Threat forecasting techniques within your organization. We will give you a three-phased approach to entering Threat forecasting to help lower the barrier to entry and make this new technique more accessible. Phase 1 focuses on research into Threat Intelligence Feeds and improvements in your organization’s existing security practices. Phase 2 introduces the creation of knowledge elements and helps you to begin Threat modeling (and thus begin Threat forecasting) using your data and, eventually, data from at least one Threat Intelligence Feed. In the third and final phase you jump in with both feet and begin contributing to the Threat Intelligence community. Knowledge is power and by sharing knowledge elements you are enabling the global Threat Intelligence community through more actionable Intelligence, as they are enabling your organization via your subscription to the Feeds you are accessing. Successful implementation of Threat forecasting techniques, powered by big data, will give you the data you need to better understand your organization’s Threat landscape and give you actionable Intelligence so that your organization can help prevent the next major data breach. This chapter is a call to action to begin applying the techniques within this book to improve your organization’s security practices and procedures and begin Threat forecasting.

  • 9 - Connecting the Dots
    Threat Forecasting, 2016
    Co-Authors: John Pirc, David Desanto, Iain Davison, Will Gragido
    Abstract:

    Abstract Connecting the dots is a symbolic way of stating we want to discuss all the topics within the preceding chapters by interweaving other related topics to show the value Threat forecasting has for your organization. This chapter is broken into five main sections ranging from the comparing and contrasting of historical Threat reporting and Threat forecasting, to real-world examples where Threat forecasting played a role or could have played a role in some of the major data breaches in recent time. The first section discusses historical Threat reporting and its relationship to Threat forecasting. When discussing this topic with fellow colleagues in the information security industry, there was an automatic assumption that we no longer believe this is of any value. The opposite is in fact true. Historical Threat reporting provides great value to organizations around the world, and these types of reports are available from security product vendors to security Intelligence companies. There are several pitfalls associated with historical Threat reports, however these are overcome when applying Threat forecasting within your organization. The next section dives into the state of the security industry by discussing the types of Threats security products deal with as well as analyzing data from a third party, independent security testing lab. The types of Threats security products need to deal with can be broken into three types. These are Threats completely known to the security product, Threats detected partially by the security product and Threats completely unknown to the security product. The final type is where security products are the weakest and this is where Threat Intelligence combined with Threat forecasting can help improve the gaps in your security coverage thus limiting exposure to your Threat landscape. These unknown Threats are best highlighted by the data within the study carried out by the cited independent testing lab, as they show, historically, that security products have had security efficacy issues. Finally, we will outline how you can begin to apply Threat forecasting techniques within your organization. We will give you a three-phased approach to entering Threat forecasting to help lower the barrier to entry and make this new technique more accessible. Phase 1 focuses on research into Threat Intelligence Feeds and improvements in your organization’s existing security practices. Phase 2 introduces the creation of knowledge elements and helps you to begin Threat modeling (and thus begin Threat forecasting) using your data and, eventually, data from at least one Threat Intelligence Feed. In the third and final phase you jump in with both feet and begin contributing to the Threat Intelligence community. Knowledge is power and by sharing knowledge elements you are enabling the global Threat Intelligence community through more actionable Intelligence, as they are enabling your organization via your subscription to the Feeds you are accessing. Successful implementation of Threat forecasting techniques, powered by big data, will give you the data you need to better understand your organization’s Threat landscape and give you actionable Intelligence so that your organization can help prevent the next major data breach. This chapter is a call to action to begin applying the techniques within this book to improve your organization’s security practices and procedures and begin Threat forecasting.

Will Gragido - One of the best experts on this subject based on the ideXlab platform.

  • 9 - Connecting the Dots
    Threat Forecasting, 2016
    Co-Authors: John Pirc, David Desanto, Iain Davison, Will Gragido
    Abstract:

    Abstract Connecting the dots is a symbolic way of stating we want to discuss all the topics within the preceding chapters by interweaving other related topics to show the value Threat forecasting has for your organization. This chapter is broken into five main sections ranging from the comparing and contrasting of historical Threat reporting and Threat forecasting, to real-world examples where Threat forecasting played a role or could have played a role in some of the major data breaches in recent time. The first section discusses historical Threat reporting and its relationship to Threat forecasting. When discussing this topic with fellow colleagues in the information security industry, there was an automatic assumption that we no longer believe this is of any value. The opposite is in fact true. Historical Threat reporting provides great value to organizations around the world, and these types of reports are available from security product vendors to security Intelligence companies. There are several pitfalls associated with historical Threat reports, however these are overcome when applying Threat forecasting within your organization. The next section dives into the state of the security industry by discussing the types of Threats security products deal with as well as analyzing data from a third party, independent security testing lab. The types of Threats security products need to deal with can be broken into three types. These are Threats completely known to the security product, Threats detected partially by the security product and Threats completely unknown to the security product. The final type is where security products are the weakest and this is where Threat Intelligence combined with Threat forecasting can help improve the gaps in your security coverage thus limiting exposure to your Threat landscape. These unknown Threats are best highlighted by the data within the study carried out by the cited independent testing lab, as they show, historically, that security products have had security efficacy issues. Finally, we will outline how you can begin to apply Threat forecasting techniques within your organization. We will give you a three-phased approach to entering Threat forecasting to help lower the barrier to entry and make this new technique more accessible. Phase 1 focuses on research into Threat Intelligence Feeds and improvements in your organization’s existing security practices. Phase 2 introduces the creation of knowledge elements and helps you to begin Threat modeling (and thus begin Threat forecasting) using your data and, eventually, data from at least one Threat Intelligence Feed. In the third and final phase you jump in with both feet and begin contributing to the Threat Intelligence community. Knowledge is power and by sharing knowledge elements you are enabling the global Threat Intelligence community through more actionable Intelligence, as they are enabling your organization via your subscription to the Feeds you are accessing. Successful implementation of Threat forecasting techniques, powered by big data, will give you the data you need to better understand your organization’s Threat landscape and give you actionable Intelligence so that your organization can help prevent the next major data breach. This chapter is a call to action to begin applying the techniques within this book to improve your organization’s security practices and procedures and begin Threat forecasting.