1,721,035 research outputs found

    Anomaly detection using network metadata

    Get PDF
    Networks are traditionally configured manually by operators who can potentially introduce misconfigurations, exposing the network to security risks. Furthermore, as network complexity grows it becomes harder to track anomalous activity in networks, especially for configuration changes which may go unnoticed unless they have an immediate impact on network operation. Existing techniques for detecting anomalies rely on inspecting irregular patterns in network traffic or configuration files. In this work, we present a preliminary framework which utilizes network metadata for detecting anomalies across enterprise networks. Network metadata helps describe properties of a network that may not be expressed by traffic data, and provides an additional metric to evaluate the overall health of a network. Examples of network metadata include software version and interface status for each device in a network. We perform statistical analysis on a combination of network data plane and metadata features in order to detect anomalies as close as possible to the network’s actual behavior. Using a private enterprise dataset, we were able to analyze network metadata to identify anomalous trends which may render a network vulnerable to security threats.Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-05-01The student, Hassan Shahid Khan, accepted the attached license on 2017-04-17 at 11:08.The student, Hassan Shahid Khan, submitted this Thesis for approval on 2017-04-17 at 11:16.This Thesis was approved for publication on 2017-04-19 at 12:51.DSpace SAF Submission Ingestion Package generated from Vireo submission #10800 on 2019-08-22 at 16:17:28Made available in DSpace on 2019-08-23T20:44:14Z (GMT). No. of bitstreams: 2 KHAN-THESIS-2017.pdf: 1274782 bytes, checksum: 34a30a2d974be27b1751451cd27193ee (MD5) LICENSE.txt: 4215 bytes, checksum: d70afb6d720e09ee7d5ac6dddadadc33 (MD5) Previous issue date: 2017-04-19Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:44:50Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemEmbargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:46:41Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemEmbargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:47:38Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemEmbargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemLimited Restriction Lifted for Item 112228 on 2021-08-24T09:15:10Z

    Network analysis, inference and verification

    Get PDF
    Securely operating large-scale networks is a non-trivial task involving interactions between various hardware devices, protocols, and configurations, all of which need to work in tandem for the network to be secure and in the desired state that the network administrators want it to be in. Misconfigurations or malicious activities in the network can disrupt it resulting in dire effects including but not limited to outages of critical applications and breach of sensitive information. In this work, we propose a robust framework for diagnosing such anomalies across enterprise networks, and study their impact in terms of changes in routing behavior and reachability. To study the network as closely as possible to its actual behavior we perform analysis on data plane features as they govern the journey of a packet during its life-cycle across the network. We perform temporal analysis of the network as a whole and inspect the evolution of various properties. We then determine the deviation of the network relative to its previous states and identify as accurately as possible if the current state is anomalous. Given the historic states of the network over some time, we also try to infer high-level policies and invariants in the network. These allow for running various verification techniques on the network. Finally, we propose a network verification tool designed to verify the network as a dynamic, multi-layer distributed system. The richness of this tool’s network model allows it to find network issues that are not detectable using state of the art tools which work solely on either data plane states or control plane states without examining the interaction of the two among themselves and temporally with the network environment. Building on this verification tool, we propose a technique for high-coverage testing of end-to-end network correctness using the real software that is deployed in these networks; our design is effectively a hybrid, using an explicit-state model checker to explore all network-wide execution paths and event orderings, but executing real software as subroutines for each device. We show that this approach can detect correctness issues that would be missed both by existing verification and testing approaches, and a prototype implementation suggests that the technique can scale to larger networks with reasonable performance. Thus, our framework provides an end to end solution for network analysis, inference and verification.Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2020-05-01The student, Gohar Irfan Chaudhry, accepted the attached license on 2018-04-23 at 21:13.The student, Gohar Irfan Chaudhry, submitted this Thesis for approval on 2018-04-23 at 21:16.This Thesis was approved for publication on 2018-04-24 at 12:28.DSpace SAF Submission Ingestion Package generated from Vireo submission #12437 on 2019-08-22 at 16:17:51Made available in DSpace on 2019-08-23T20:44:18Z (GMT). No. of bitstreams: 2 CHAUDHRY-THESIS-2018.pdf: 9733981 bytes, checksum: e9bc81e075768c62a2abbc0c90d1c2eb (MD5) LICENSE.txt: 4217 bytes, checksum: 34322a2fe53f873f2039adb2ecba21d6 (MD5) Previous issue date: 2018-04-24Embargo set by: Seth Robbins for item 112234 Lift date: 2021-08-23T20:44:50Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemEmbargo set by: Seth Robbins for item 112234 Lift date: 2021-08-23T20:46:41Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemEmbargo set by: Seth Robbins for item 112234 Lift date: 2021-08-23T20:47:38Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemEmbargo set by: Seth Robbins for item 112234 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemLimited Restriction Lifted for Item 112234 on 2021-08-24T09:15:31Z

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Reinforcement learning for dynamic aerial base station positioning

    Get PDF
    Reliable communication infrastructure plays an extremely important role in peoples' everyday lives and the lack of sufficient communication means could have severe negative consequences. In the case of a post-disaster situation, it could be the difference in an emergency responder's ability to rescue a trapped victim. In the case of a state-wide stay-at-home order, it could be the difference in a parent's ability to continue their work remotely and in a student's ability to receive a proper education. In the case of a remote region, it could be the difference in someone's ability to connect with the outside world. Unfortunately, in many of these cases, the number of functioning communication network infrastructure is actually limited. In such scenarios, unmanned aerial vehicles (UAVs) can be used as aerial base stations or relays to help form a connected network amongst users. Since users are likely to be constantly mobile, the problem of where these UAVs are placed and how they move in response to the changing environment could have a large effect on the number of connections this UAV relay network is able to maintain. In this work, we propose DroneDR, a reinforcement learning framework for UAV positioning that uses information about connectivity requirements and user node positions to decide how to move each UAV in the network while maintaining connectivity between UAVs. The proposed approach is shown to outperform other baseline methods across a broad range of scenarios and demonstrates the potential in using reinforcement learning techniques to aid in communication efforts.Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-05-01The student, Isabella Lee, accepted the attached license on 2020-05-11 at 15:48.The student, Isabella Lee, submitted this Thesis for approval on 2020-05-11 at 16:04.This Thesis was approved for publication on 2020-05-12 at 11:24.DSpace SAF Submission Ingestion Package generated from Vireo submission #15333 on 2020-08-25 at 17:31:00Made available in DSpace on 2020-08-26T23:58:46Z (GMT). No. of bitstreams: 2 LEE-THESIS-2020.pdf: 1619556 bytes, checksum: 0c22650bfd90f6134fe5a80588dcc488 (MD5) LICENSE.txt: 4209 bytes, checksum: f2e6eafcd9c2627c5ed616050df9b325 (MD5) Previous issue date: 2020-05-12Embargo set by: Seth Robbins for item 115797 Lift date: 2022-08-26T23:58:55Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD systemAuthor requested U of Illinois access only (OA after 2yrs) in Vireo ETD systemU of I Onl

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis

    Design and implementation of an evaluation platform for internet of things

    Get PDF
    Internet of Things (IoT) is an active area of research in both academia and industry. It has attracted a large amount of interest due to its potential of revolutionizing different industries by “giving intelligence” to vast numbers of objects in the environment. Although much attention is put in developing new protocols and applications with IoT, a comprehensive evaluation system is also crucial in assessing these new applications. This thesis proposes an evaluation system for IoT. This system comprises of two parts to match the typical cloud architecture of IoT solutions. Such IoT architecture usually contains cloud and device parts. As such, the first part in our system is an evaluation platform for IoT cloud. We use VMware NSX to create virtualized networks to emulate different cloud topologies. The second part is an evaluation platform for IoT devices. In this platform, we designed an event-based simulation environment that could run device codes and coordinate device interactions. The simulation platform also supports cross-level simulation and custom circuit builds. Our goal is for the proposed system to provide help and insights for future IoT developers in their designing and evaluation process.Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2021-05-01The student, Zhichun Wan, accepted the attached license on 2019-04-23 at 11:47.The student, Zhichun Wan, submitted this Thesis for approval on 2019-04-23 at 12:07.This Thesis was approved for publication on 2019-04-23 at 13:26.DSpace SAF Submission Ingestion Package generated from Vireo submission #13841 on 2019-08-22 at 16:23:40Made available in DSpace on 2019-08-23T20:48:24Z (GMT). No. of bitstreams: 2 WAN-THESIS-2019.pdf: 1164420 bytes, checksum: 1f3ac8c733d4c40a22a7b25c66dc7e0a (MD5) LICENSE.txt: 4208 bytes, checksum: b73ae26c2b7dde8d8cdcfc7808091b49 (MD5) Previous issue date: 2019-04-23Embargo set by: Seth Robbins for item 112371 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD systemLimited Restriction Lifted for Item 112371 on 2021-08-24T09:15:16Z

    Automated static analysis of virtual-machine packers

    Get PDF
    The ability to reverse the most advanced software protection schemes is a critical step in mitigating malicious code attacks. Unfortunately, the analyst side seems to be losing in the ongoing arms race between malware developers and reverse engineers. Obfuscation that takes advantage of a virtual- machine like architecture has proven to be one of the most difficult to deal with. Virtual-machine packers are able to hide the intentions of programs they are applied to and are resistant to formerly effective unpacking techniques. Others have proposed methods to deal with such complex protec- tions, but they are often tedious, expensive, and/or inflexible. We propose a novel approach to automate the analysis process of virtualization protected executables. Our design avoids many pit- falls and performance issues of dynamic-analysis systems by only employing static program-analysis techniques and emphasizing work-reuse and generality in order to maintain efficiency, flexibility, and accessibility, for even novice analysts. The proof-of-concept system we have developed shows promise for the future of virtual-machine protected software analysis.Item withdrawn by Mark Zulauf ([email protected]) on 2013-07-17T20:18:28Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Leong_Joseph.pdf: 342080 bytes, checksum: ef3d2532aab6eeb2955919ea32917ed8 (MD5)Made available in DSpace on 2013-08-22T16:49:00Z (GMT). No. of bitstreams: 2 Joseph_Leong.pdf: 341845 bytes, checksum: 8262c94e87650a486743b2f366ead3d6 (MD5) license.txt: 4060 bytes, checksum: 84bb2e47b9b6c55ad84db5784a80244d (MD5)Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins ([email protected]) on 2013-08-22T16:49:44Z Item is restricted until 2015-08-22T16:49:27ZRestriction data tranferred 2014-07-01T11:34:28-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2015-08-22 11:49:27 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD systemU of I Only Restriction Lifted for Item 45577 on 2015-08-22T10:00:35Z

    Recurrence-based models for improving coverage within GPS and satellite-denied mobile sensor networks

    Get PDF
    This Thesis was approved for publication on 2021-04-28 at 11:15.DSpace SAF Submission Ingestion Package generated from Vireo submission #16540 on 2021-09-16 at 17:05:08Made available in DSpace on 2021-09-17T02:34:46Z (GMT). No. of bitstreams: 3 BALAKRISHNAN-THESIS-2021.pdf: 1503457 bytes, checksum: 73b2a9f653fd093b3f75d9f0293c85d8 (MD5) Thesis (Version 4748).zip: 1653625 bytes, checksum: 29a693cca856901486faf117b491160d (MD5) LICENSE.txt: 4215 bytes, checksum: abdfb70f0ee13111fee03381b3e451e8 (MD5) Previous issue date: 2021-04-28Adversarial GPS-denial and coordinate spoofing, as well as satellite jamming, serve as common obstacles to disaster-recovery and military-based teams. While such teams are often supported by UAVs that connect multiple personnel by serving as relay devices, UAV position schemes that rely on centralized controllers are also disrupted by such hurdles, as GPS and satellite-based denial will effect the ability of UAVs to communicate with the controller and drones outside line of sight. In this thesis, we design and implement a drone-relay system that allows drones to cooperatively maximize coverage in a GPS-denied and satellite-denied scenario. Here, we define coverage as the ability of one entity to speak to another entity using a drone network as an intermediate relay system and is measured as the ratio of fulfilled entity-to-entity connections to all possible entity-to-entity connections. We maximize coverage over an extended experiment duration, consisting of 300–1000 timesteps, by devising algorithms that rely on a centralized controller with full knowledge of drone and ground entity position. Particle Swarm Optimization (85% coverage), Reinforcement Learning on a Recurrent Neural Network (75% coverage), and a Time-Series based Inference Optimizer (71% coverage) were amongst the best performing movement algorithms, improving upon movement models in related works by up to 40%. We then design a distributed backend that disperses commands from a centralized controller using a distributed drone-to-drone communication scheme, also collecting observations made by each drone and relaying them to the centralized controller. This backend is additionally integrated with failure recovery and security-based protocols to ensure recovery in drone-downtime and drone-compromised scenarios; both systems feature minimal overhead, allowing drone recovery from downtime in 7% of the simulated episode length and featuring a constant time-addition from encryption that does not increase as drone count increases. Finally, we remove all notions of centrality by designing and implementing a fully decentralized system, where drones operate in squads and house their own models and decision-making protocols. In this system, drone squads are able to share observations of their surroundings with neighboring drone squads to improve predictive performance. This final system complies with GPS and satellite-denial limitations as drones only perform observations in a surrounding vision radius, assuming a camera to be mounted on each drone, and drones can only send messages to neighbors in a transmission radius, avoiding the need of sending satellite-based messages.Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2023-05-01The student, Rahul Balakrishnan, accepted the attached license on 2021-04-23 at 19:58.The student, Rahul Balakrishnan, submitted this Thesis for approval on 2021-04-23 at 20:11.Embargo set by: Seth Robbins for item 118580 Lift date: 2023-09-17T02:34:57Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD systemAuthor requested U of Illinois access only (OA after 2yrs) in Vireo ETD systemU of I Onl
    corecore