Dakota State University

Beadle Scholar at Dakota State University
Not a member yet
    1393 research outputs found

    Divergent Detection: A Comprehensive Study of DGAS Using FNNS for Original, Noise-Modified, and Linear Recursive Sequences(LRS)

    Get PDF
    This comprehensive research endeavors to address a pressing issue within the realm of cybersecurity—the challenge posed by malicious activities utilizing Domain Generation Algorithms (DGAs). These algorithms, numbering at least 84 traditional malware families as of late 2023, dynamically generate domain names to facilitate nefarious operations while evading conventional detection mechanisms. The study generated over 159,750 domains and studied more than 1.27 million data points. Existing studies have predominantly focused on surface-level aspects of DGAs, including domain lengths, alphanumeric values, and top-level domains (TLDs). In response to this challenge, the research question at the core of this study aims to investigate whether sophisticated classifiers can effectively detect and classify DGA-enabled malware by discerning variations in DGAs, including original DGAs, those modified with injected noise, and a novel approach of modification through Linear Recursive Sequences (LRS). The chosen methodology for this research adopts a quantitative design, utilizing Python programming and a suite of libraries for efficient data manipulation, machine learning, and visualization. The focal point of the methodology involves training a Feedforward Neural Network (FNN) using a meticulously curated dataset comprising both original DGAs and their modified counterparts. To facilitate effective classification, the dataset undergoes a detailed segmentation into categories. The FNN architecture, with specific hyperparameters, employs the Adam optimizer, sigmoid activation functions, and three dense layers. Eight features, including Damerau Levenshtein Distance and String Entropy, and others to contribute to the FNN’s understanding of the input data. The research explores the intricacies of neural network comprehension, dataset classification, and feature identification, overcoming these challenges through extensive multiclassification learning processes. The training configuration involves a Learning Rate of 0.0001, 50 epochs, a batch size of 32, and a 80/20% validation split. Rigorous feature selection and engineering, model selection, and hyperparameter adjustment are integral to the methodology. The study reviews five primary DGA datasets Banjori, Dnschanger, Dyre, Gameover, Murofetweekly, presenting detailed insights into their characteristics. The analysis reveals the challenges posed by DGA families with insufficient sample sizes, necessitating a strategic selection process. The FNN’s performance is explicitly evaluated on its ability to classify instances into original DGAs, Noise-Modified DGAs, and LRS-Modified DGAs. In conclusion, this research contributes significantly to cybersecurity by offering a sophisticated approach to DGA detection. The methodology’s robustness is examined through potential challenges, and recommendations for addressing these challenges are provided. This research demonstrates the effectiveness of the FNN in identifying an average of 99.5 percent of noise and LRS DGA modifications. This significant contribution enhances cybersecurity by introducing a sophisticated approach to DGA detection. It underscores the significance of staying abreast of evolving cyber threats and emphasizes the need for proactive cybersecurity measures in the face of continually adapting tactics employed by malicious actors

    Securing Modbus via Proxied Approach

    Get PDF
    This study investigated the network performance of introducing a Transport Layer Security (TLS) proxy to secure the Modbus protocol. To address the lack of security of the Modbus protocol, a proxy based on Python’s socket, ssl, and threading packages was developed and tested. Additional network latency generated by the inclusion of this proxy was assessed for TLS handshakes, as well as Modbus operations. Statistically significant figures were generated, proving that this device introduces overhead (though negligible in implementations). A more featured proxy leaves a path open for future research. The study showed an avenue that could remedy problems present in operational technology systems

    Mirage: A VBA Macro Emulator for Behavioral Analysis Powered by Machine Learning

    Get PDF
    Microsoft Office documents being utilized for the distribution of malware has become an increasing problem, and in recent years the utilization of malware distributed through malicious Microsoft Office documents has seen an increase. Current research has found machine learning algorithms to be effective in the detection of malicious Office documents by the use of static document properties for a method of detection. However, this provides the author of such malicious Office document macros control of the parameters utilized in machine learning techniques for detection, and by utilizing static macro properties, this does not allow for the extraction of behavioral details which are important in the classification of an Office document’s macros, whether it be benign or malicious. In this study the creation and validation of a VBA emulator and a behavioral analysis machine learning classifier is performed through the utilization of 1,000 VBA macros, allowing for a foundation to be formalized in the design of technology specific emulators, designed specifically for behavioral data extraction and analysis, thus providing insight into the behavior of an Office document’s macro(s) allowing for better detection methodologies to be created powered by machine learning algorithms, and preventing static properties from being altered to evade current detection methods

    SETC: A Vulnerability Telemetry Collection Framework

    Get PDF
    As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This research enables scalable exploit data generation to drive innovations in threat modeling, detection methods, analysis techniques, and remediation strategies. The capabilities of the framework are demonstrated through an example scenario. By addressing key barriers in security data generation, SETC represents a valuable platform to support impactful vulnerability and defensive security research

    Flying through the air with the greatest of ease? Evaluation of glide capability in basal maniraptoran theropods

    Get PDF
    Pterosaurs, a lineage of Mesozoic flying archosaurs, include the largest flying animals ever known. Quetzalcoatlus nortropi a Late Cretaceous representative, had a wingspan of over 10 m and likely weighed more than 200 kg. It presents a combination of features (large head, massive wingspan, shoulder height equivalent to an extant giraYe) that has led to ecological interpretations of it as a major predator in the North American Maastrichtian Biome, perhaps second to only Tyrannosaurus rex. Here we examine the probability of that from an energetics perspective. Despite the great wingspan of Quetzalcoatlus, the body length (gleno- acetabular distance) is relatively small (~500 mm) and a volume of ~1.5 times that of an average sized human male. When factoring in lung volume this restricted the gut capacity and thus prey size. We estimate, for a 200- 250 kg adult, a maximum prey size of 5-7 kg. We then examined if this would be enough to sustain an adult Quetzalcoatlus and based on extant mammalian and avian field metabolic rates (FMR). We suggest that a daily food requirement would be around 3.5-5 kg per day using FMR. This suggests that such large creatures would be feeding on either very small prey items or could scavenge leftovers well after the larger theropods had secured their fill. In addition, take oY and flapping flight would be so extremely costly at such a large size, as demonstrated by the fact that in extant birds this value is often 20 times basal metabolic rate or greater. Given these factors (expected glide speeds on the order of 20 m/s or more, the costs of landing and launching are high, the maximum gut capacity low) we suggest that the primary ecological role was a terrestrial walking small prey specialist and/or scavenger. In the largest adults, flight would likely be minimized to extreme cases like escape or long-distance migration, with the daily locomotion primarily done terrestrially, though juveniles were likely more aerial. Given the lack of mid-sized carnivores in the environment Quetzalcoatlus likely used its size to intimidate smaller rivals such as Saurornitholestes, while feeding on similar sized prey. It was not in competition with sub adult or mature Tyrannosaurs, nor preying on all but the smallest members of the dinosaurian fauna. Thus, we suggest it played the role of a lower trophic level consumer and not an apex predator.https://scholar.dsu.edu/research-symposium/1051/thumbnail.jp

    Bones et. al: Educational Human Skeletons Restoration and Investigation

    Get PDF
    There has been a longstanding tradition to use real human skeletons as educational aids in classrooms (2). The interactive nature of hands-on learning often results in the degradation of these skeletal specimens, and repairs are needed to bring them back to being fully functional. Drawing techniques from one of the few guides to restoring educational classroom skeletons {1) and museum approaches (2, 3, 5), we are able to find a method that works for three human skeletons at Dakota State University.https://scholar.dsu.edu/erposters/1003/thumbnail.jp

    Bi-Directional Transformers vs. word2vec: Discovering Vulnerabilities in Lifted Compiled Code

    Get PDF
    Detecting vulnerabilities within compiled binaries is challenging due to lost high-level code structures and other factors such as architectural dependencies, compilers, and optimization options. To address these obstacles, this research explores vulnerability detection using natural language processing (NLP) embedding techniques with word2vec, BERT, and RoBERTa to learn semantics from intermediate representation (LLVM IR) code. Long short-term memory (LSTM) neural networks were trained on embeddings from encoders created using approximately 48k LLVM functions from the Juliet dataset. This study is pioneering in its comparison of word2vec models with multiple bidirectional transformers (BERT, RoBERTa) embeddings built using LLVM code to train neural networks to detect vulnerabilities in compiled binaries. Word2vec Skip-Gram models achieved 92% validation accuracy in detecting vulnerabilities, outperforming word2vec Continuous Bag of Words (CBOW), BERT, and RoBERTa. This suggests that complex contextual embeddings may not provide advantages over simpler word2vec models for this task when a limited number (e.g. 48K) of data samples are used to train the bidirectional transformer-based models. The comparative results provide novel insights into selecting optimal embeddings for learning compiler-independent semantic code representations to advance machine learning detection of vulnerabilities in compiled binaries

    Do Online Proctoring Software Abide by Standard Data Protections?

    Get PDF
    In the aftermath of the COVID-19 pandemic, schools adopted new software to allow for online learning. Online exam proctoring has seen rapid growth in both K-12 and higher education. Even high stakes exit exams, such as the bar exam, have seen the use of online proctoring software since the pandemic. This rapid migration towards online proctoring has led to issues concerning test integrity and data security. The security of online proctoring suites is critical due to their extensive access to student devices and sensitive information. Online proctoring suites have the capabilities to assess and configure student devices, access the microphone and camera, and view student information in the scope of the exam. Unlike other eLearning software that mainly has access to student documents, these proctoring suites enjoy a level of access comparable to some malware. This case study investigates the security of data sent over the network using dynamic software analysis and network monitoring while using the Respondus Lockdown Browser. Any transmissions lacking encryption may leak information regarding a student or an exam. Exposing this sensitive information damages both the confidentiality of students using the software as well as diminishing exam integrity

    Toward Automated Knowledge Discovery in Case-Based Reasoning

    Get PDF
    Automated Case Elicitation (ACE) enables case-based reasoning (CBR) systems to automatically acquire knowledge through real-time exploration and interaction with environments. CBR is an explainable AI methodology, where decisions are based on previous encounters. ACE combined with CBR continues learning as it is being deployed, and produces specific cases that can be reviewed by humans, unlike pretrained large language models (LLMs) that learn by training offline on prior data. ACE and CBR may be useful methods to gather training data for use with generative AI, or to help them to adapt on the fly. This research explores ACE\u27s potential by applying it to chess and conducting extensive experiments against Stockfish, the world\u27s highest rated chess engine. An ACE agent was developed that combines random exploration with shallow alpha-beta search for novel game states. Results over 1000+ games showed the ACE player defeated Stockfish in nearly 10% of games—a notable achievement given Stockfish\u27s extreme strength. Notably, the ACE agent required only 0.1 seconds per game compared an average of 8 minutes for Stockfish, while still gradually improving its win rate through accrued experience. Detailed analyses revealed how the relaxation of ACE\u27s case matching criteria along with selective retention of useful cases enabled accumulation of strategic chess knowledge. The research provides valuable insights into ACE\u27s proficiency for knowledge discovery in complex, adversarial domains. It lays groundwork for integrating ACE, an unsupervised CBR learner, with modern deep learning techniques like neural networks and large language models to combine the strengths of symbolic and subsymbolic AI. By demonstrating ACE\u27s ability to extract strategic knowledge against world-class opponents, this work highlights its potential for impact across gaming, autonomous systems, and other complex problem-solving domains

    Toward extracting the scattering phase shift from integrated correlation functions. II. A relativistic lattice field theory model

    Get PDF
    In the present work, a relativistic relation that connects the difference of interacting and noninteracting integrated two-particle correlation functions in finite volume to infinite volume scattering phase shift through an integral is derived. We show that the difference of integrated finite volume correlation functions converges rapidly to its infinite volume limit as the size of the periodic box is increased. The fast convergence of our proposed formalism is illustrated by analytic solutions of a contact interaction model, the perturbation theory calculation, and also the Monte Carlo simulation of a complex 4 lattice field theory model

    0

    full texts

    0

    metadata records
    Updated in last 30 days.
    Beadle Scholar at Dakota State University
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇