1,720,952 research outputs found
DokterService: A Security Information and Event Management System (SIEMS)
KPMG is a multinational firm, which is focused on three pillars: tax advisory, accountancy and advisory. The advisory section, in particular the IT Advisory, required a system that is able to analyze, process and visualize captured network traffic. This network traffic is gathered from the own company or their clients. The goal of this project is to design and develop a "Security Information and Event Management System (SEAMS)" that manages Network Intrusion Detection services and provides a report specifying the condition of the analyzed network. In order to manage the different Intrusion Detection Systems (IDS) their results need to be merged. Every IDS produces a different result based on their focus. To gain the most valuable information of the network traffic, one has to merge all IDS’s results. The major challenge in developing such a SEAM System is that the system should be able to process an enormous amount of data. This data is roughly between 2- 10TB. The stakeholder required the system to be built in a modular way. This leads to both maintainability and adaptability of the system since the customer accounts for the extension of the product. During the research the development team acquired a large amount of knowledge about network traffic. In addition to this knowledge, they gained understanding and expertise in the used IDSs. By gathering this knowledge, the product got molded into a useful, extendable and efficient Dokterservice for the client. The process, for the development of the Dokterservice, was set up by means of the Scrum methodology. A change of requirements is a pristine reason to apply the scrum methodology, as development tasks are flexibly generated. Hence during the development process, any (un)expected changes could easily be adapted to the product and into Scrum. The dokterservice that is created is able to read, process, merge and visualize the data gathered from the network traffic. Continously throughout the development, the product got tested on captured malicious network traffic, which varied tremendously in size. Furthermore, the product got tested by means of unit tests and continous integration. This ensured the team that the developed components work as they should. In addition to the aforementioned ways of testing, we also had continuous interaction with our stakeholders and organized demo’s for possible future end-users. The future outlook of the Dokterservice is very prosperous. KPMG plans on applying the Dokterservice for future network analysis. We also have provided some future work recommendations which are included in our final report.Department of Intelligent SystemsElectrical Engineering, Mathematics and Computer Scienc
Non-intrusive Detection of Compromised PLC's in ICS and SCADA Systems
Electrical Engineering, Mathematics and Computer ScienceIntelligent System
Classifying scanners: Mapping their behaviour
This thesis focuses on the classification of behavioural aspects of scanners based on unroutable traffic collected from two /16 subnets. Firstly the study determines that the use of a smaller dataset achieves similar results and allows for the same correctness compared to larger ones. Secondly different scanning tools are analysed, and methods for their fingerprinting are explained. The implementation of detection methods reveals the usage of particular tools and the the existence of previously unknown software. Analysing these previously unknown tools shows that there is a difference in levels of sophistication of the tools used by scanners. Following, this thesis confirms the existence of the horizontal, vertical and strobe scanner classes, it also describes a new method in which a destination port and address are only scanned once. In addition a method to identify individual scans from traffic captures for further analysis is presented and evaluated. This method is then used to reveal similarities between scans from one address but also confirming collaboration between multiple addresses. Finally the behaviour of scanners is compared showing cyclic behaviours are common amongst single and multi host scanners.Electrical Engineering, Mathematics and Computer ScienceIntelligent System
Efficient Crawling of Community Structures in Online Social Networks
Online social networks showed an enormous growth in the last decade. With the rise of online social networks such as Twitter and Facebook, researchers got the opportunity to access the data of social behavior of millions of people, whereas in the past it was limited to hundreds of people. For these researchers and marketeers it is of great interest to find communities within these large networks, as this is one of the opportunities to see how people behave in groups on a large scale. The most common approach of analyzing community structures in online social networks is to gather the network by downloading the user profiles one by one (crawling) and afterwards partition the network into groups or communities by community detection algorithms. However, crawling an entire social network is very time consuming and analyzing the networks with community detection algorithms can be computationally expensive. To overcome these problems, in this thesis a method is proposed for crawling nodes using the community structure of a network. It enables the researcher to start the analysis before completing the crawl. This new method performs between 66% and 480% better than existing crawling techniques such as Breadth First Search (BFS) and Depth First Search (DFS), because a smaller portion of the networks has to be crawled in order to crawl entire communities. The computer-generated networks used in this thesis were created using a new network generator which uniquely combines three features; it creates networks with explicit community structure, arbitrary degree distributions and adaptable community strength.TelecommunicationsElectrical EngineeringElectrical Engineering, Mathematics and Computer Scienc
Estimating popularity by sentiment and polarization classification on social media
Mass processing of social media posts has been brought to scientists' attention during the last decade. The massive growth of online social networks, like Twitter and Facebook, have created a need for determining peoples' opinions and moods through these means. This thesis constitutes a research on measuring users' sentiment upon a particular subject by analysing their posts. Establishing an efficient sentiment measurement technique, can be used into estimating popularity of products or persons. For separating subjective from objective posts, a hybrid classifier based on the syntax analysis of texts, is proposed, performing clearly better than existing classifying tools. Moreover, a new sentiment evaluation technique for measuring the polarity and magnitude of posts' sentiment is described and tested over different social media. Results are compared to various real ratings and show that this approach can have a promising accuracy on sentiment establishment of online posts.Network Architectures and ServicesTelecommunicationsElectrical Engineering, Mathematics and Computer Scienc
Understanding the Topological Structure and Semantic Content of Darknet Communities
For over a decade Darknet has been gaining tremendous popularity proportional to the growing concerns fostered by lack of anonymity and privacy on the World Wide Web. In the recent years, illegitimate use of the Darknet has resulted into investigation in the research community that is analogous to a domino effect further adding to popularity of this type of network. Unfortunately, higher percentages have been attributed to the illegitimate use of the Darknet rather than to the legitimate use. This is because researchers of the Darknet communities have relied on the knowledge obtained through the use of Breadth First Search crawling algorithm. Crawling makes up the main step in the exploration of these communities. Crawling is also an effective method to understand the topological and semantic structure of the Darknet communities. The algorithms chosen to crawl thus, decide the knowledge obtained from these communities. This thesis demonstrates how these crawling algorithms spread out over the Darknet communities and how this affects what and how much we know about them. The considerations presented eliminate the skew in the representation of Darknet communities. The knowledge explored through the behavior of BFS, DFS and RFS algorithms have been presented in this thesis.Electrical Engineering, Mathematics and Computer ScienceTelecommunicationsCybersecurit
Implementing Link-state Update Policies for Quality of Service Routing
This thesis describes the implementation of available bandwidth link-state update policies for Quality of Service routing. Periodic, threshold-based and class-based policies are described and implemented in a QoS router testbed, using Quagga and its OSPF-API for low-level communications. The implementation is thoroughly tested using unit tests and simulated traffic. A performance comparison of the link-state update policies is done, using two different scenarios. The results of this comparison show that determining the right parameters for the policy is more important than the kind of policy used. The performance of the policies is generally worse than in previous work, due to the absence of explicit flow admission control, which makes it impossible to account for traffic until after it has been sent. The results also indicate that the use of a moving average instead of a hold-down timer leads to less link-state updates, while not impacting performance.Network Architectures and ServicesTelecommunicationsElectrical Engineering, Mathematics and Computer Scienc
Last line of defence: Cyber security of industrial control systems
The world is rapidly embracing networked technology and transitioning into one of hyperconnectivity, a term first coined by social scientists Anabel Quan-Haase and Barry Wellman. Increased connectivity provides benefits such as automation and, remote access and control of networks and equipment, thereby decreasing operational costs. Maritime and offshore companies are increasingly automating their vessels and platforms to reduce the required workers on-board and centralise platform control. With this tight coupling of complex ICT and industrial control systems however comes an increase in risks. These risks are further increased due to the application of security controls. Where in mechanical and structural engineering the focus lies on failure (e.g. safety factors), this is not necessarily the case for ICT related systems, which are often only verified to be working as specified and expected. Unexpected behaviour is not taken into consideration. Thus, while most vessels and platforms depend on automated systems, it seems little is being done to protect them from cyber incidents and attacks. The impact of security breaches on these systems can be disastrous due to the potential for physical damage to people and planet. This is especially true within the oil and gas industries. For example a fire at the Piper Alpha production platform in the North Sea in 1988, caused by an oil and gas leak, resulted in the loss of 169 lives. While computer viruses or worms might not directly injure people, or destroy equipment, automated control systems can. This work thus focusses on the area where mechanical systems meet automation systems, a field called industrial control systems. An investigation into the current state of cyber security within the dredging industry has been conducted, which was followed by a threat analysis on industrial control systems. These systems operate at the heart of the dredging industry. This has revealed that malicious software can cause physical damage to equipment and injury to people. In an effort to improve the current state and help prevent cyber incidents from occurring the following research question has been formulated: Can adversaries operating on Control System infrastructures be detected by an Intrusion Detection System which is monitoring the physical state? To answers this question a novel intrusion detection system is designed which takes advantage of the physical state of the processes. This new concept deviates from other systems in that they obtain information from the network, as opposed to the physical process, where the data cannot necessarily be trusted. Additionally, when malicious events or cyber incidents occur within or behind the controller (PLC), the control network does not necessarily contain the required information detailing ongoing attacks. Looking at the physical system then allows for malicious attacks and cyber incidents to be detected by observing anomalous and unexpected behaviour of the monitored physical process. This enables the detection of advanced malicious threats which would be missed otherwise. The required information on the physical state of the process is obtained on the last line, between the controller and field devices.Mechanical, Maritime and Materials EngineeringMarine and Transport TechnologyOffshore and Dredging Engineerin
Content Propagation in Online Social Networks
This thesis presents methods and techniques to analyze content propagation within online social networks (OSNs) using a graph theoretical approach. Important factors and different techniques to analyze and describe content propagation, starting from the smallest entity in a network, representing a user-account, up to complete friendship graphs and traces of content are described. All individuals and their attributes are stating the basic elements for statistical analysis of user behavior and individuals interests. When trying to identify the opinion of the population of a country for example, a random sample or data from everyone within the population is needed, a task which is not trivial because of different activity patterns and the fact that individuals may either do not provide information about themselves or obscure their data by supplying bogus information. This thesis shows that obtaining a random sample of the population of the Netherlands is possible in terms of certain parameters like the location, family and first names of users. Such a sample is likely not to be “random” in terms of the age of inhabitants and the usage of gathered data in order to predict the outcome of elections may be questioned. The representation of an individual's view onto an OSN is called an ego-centric network. It contains all friends and relations between friends of an ego within a sub-graph. Within such graphs, the influence between friends can be estimated improving the usability of recommendation systems which also raises concerns about the privacy of users. This thesis describes possibilities to reconstruct private information of a user if only a few friends of the individual share their data publicly because most friendships are created between persons having similar interests. Therefore the current way of dealing with privacy concerns, by enabling users to protect their data, is not sufficient. The structure of ego-centric networks also unveils the ability of egos to spread and control the spread of information as a person completely embedded in a group has less control over disseminating content than a person connecting multiple groups. A snapshot of a whole network of an OSN includes all user-accounts (nodes) and friendships (links) at a certain point in time. But as OSNs may contain millions of nodes the process of obtaining data by crawling is likely to be skewed depending on the used method and duration. Therefore a new way of traversing the graph called “Mutual Friend Crawling” is proposed in which certain network metrics converge faster to the final value by also detecting communities of users while traversing the graph. When analyzing the diffusion process of content in multiple OSNs, only a limited fraction of the neighbors of a user (i.e. friends) are ”useful” in terms of spreading content to their peers. Commonly used network metrics which reflect the centrality of a node are shown to have no correlation with the ability to repeatedly succeed in passing messages to a high number of users. The reason lies in the fact that the whole network of friends contains inactive or abandoned user accounts and a critical dependency to the time a message was sent exist. This denotes that friends of a user that forward a message have to be available or online at the time they are “needed” in order to forward content. On the other hand, influential groups might exist which act together in order to spread content with the help of each other. These groups might organize themselves via external communication channels, shown by the example of a famous group, the “Digg Patriots”, where members of the group cannot be found through purely topological measures. A similar time dependency exists in terms of the evolution of OSNs, because users can only forward information or befriend others when they are online. The interactivity durations of these actions are shown to be log-normal like distributed rather than exponential or power-law as assumed in multiple previous publications. The argumentation for such an assumption is based on the fact that power-law and exponential distributions would indicate most interactivity durations to be very short whereas individuals always need some time to complete tasks. However, it is shown that the time-scale of observations is crucial, because log-normal and power-law distributions with a small exponent might look the same in a log-log plot if the chosen bin-size is too large. Another process involved in the structural evolution of a friendship network is given by markets that sell friendship relations in OSNs. These markets are accounting for quite a high number of friendship relations whereas their usage has usually a negative connotation. But in terms of content propagation they might be beneficial because, for example politicians, “buying” followers are able to reach users which would otherwise not connect to them. The term viral spreading is often used in combination with content propagation within the network of an OSN. Therefore certain parameters of epidemiology are compared to ”viral spreading” in Twitter. It was found that most messages had a low basic reproductive ratio <1, a ratio depicting the infectious a virus, whereas few messages were highly infectious because a high number of users forwarded them. Interestingly even these popular messages were not able to spread to a large fraction of the total number of Twitter users. When trying to use epidemiological theory the “Susceptible-Exposed-Infected-Removed” model seems to be applicable to content propagation exhibiting the complication that the distribution of the duration a user is “exposed” and “infected” seems to be log-normal distributed. The distribution of these durations, also called observation and reaction duration denotes that Markov theory cannot be applied to model the “epidemics”. Another more general approach is therefore given by a Bellman-Harris branching process. The content, propagating though a network can be analyzed using graph theory as well in order to get insights into population statistics. The example of mobility pattern was chosen to depict the “meaning” of community detection within graphs created out of locations of Twitter users. The detected patterns allow better planning of transportation services, depicting in which areas of the Netherlands people are most frequently traveling during the working weekdays and weekends. Analyzing the most common type of content, short colloquial text, using a new unsupervised way of estimating the sentiment of messages enables the analysis of graphs in which words are denoted as nodes and links describe the co-occurrence of words. These graphs reflect which words are related to concepts and their sentiment allowing to infer the perception of products and concepts within the population of OSN users.Intelligent SystemsElectrical Engineering, Mathematics and Computer Scienc
Detecting malicious behaviour using system calls
The emergence of Apple’s Macintosh computers’ popularity introduces new threats and challenges for the security on the Mac. For a long time, OS X security has benefitted from the popularity of Microsoft Windows. The threat landscape for the Mac is rapidly changing as the marketshare of the Mac is approaching 15%1. Malware on Apple’s OS X systems emerges to be an increasing security threat that is currently solely countered with ancient anti-virus (AV) technologies [18]. Current AV technologies pose a performance overhead on the entire system and have an inherent delayed effectiveness, due to their signature based detection [15][31]. In addition, current malware uses many forms of obfuscation to prevent detection by AV technologies, redering AV technologies useless against advanced threats [15][31]. Consequently, the need for more advanced detection and prevention techniques of malware is increasing. Detection of malicious behaviour instead of malicious signatures, ought to provide a more advanced form of protection. A system call is referred to as the request and service of specific, basic, functionality provided to applications by the operating system. This Master thesis answers the research question: “Is it possible to detect malicious behaviour per- formed by malware, based on monitoring system calls?” Presented is a novel, generic, behavioural detection and prevention mechanism for malware on OS X based on system calls. System call traces can be used to describe the behaviour of processes [11]. Much effort was put into the development of a kernel module that bypasses kernel security mechanisms and rewires one of the operating system’s core functionalities; system call handling. The rewiring of system call handling provided the ability to log all of the system call invocations performed by processes running on the monitored system. A significant amount of OS X malware and benign applications were executed in a monitored environment of which system call traces were collected. Based on analysing heat map visualisations and manual sequential analysis of the system call traces of both malicious and benign processes, anomalies in the malicious traces could be observed. Subsequently, several mali- cious system call patterns and detection rules were extracted providing detection of malware on OS X. The most successful defined pattern is constructed around the executions of Unix shell processes per- formed by malware. It is shown that this detection pattern results in a 100% detection rate of all malware possible to obtain for this thesis. Even advanced malware in an infected OS X application, known as OSX.KeyRanger.A, was detected using this method. In order to evaluate the False Positive Rate (FPR) accurately in real world scenarios, three different user profiles were defined. Applications distributed via the Mac App Store do not generate false positives. In case of the developer user profile type, the FPR increases to 20%. Applications responsible for the false positives feature a cross-platform nature, such as MATLAB, R, LaTeX and interpreters for scripting languages. A conducted survey under Mac users verified these conclusions. However, the number of false positive generating benign applications is very limited and whitelisting solutions provided can reduce the FPR in this developer user profile.Electrical Engineering, Mathematics and Computer ScienceIntelligent System
- …
