1,720,959 research outputs found
Clustering Malware's Network Behavior using Simple Sequential Features
Developing malware variants is extremely cheap for attackers because of the availability of various obfuscation tools. These variants can be grouped in malware families, based on information retrieved from their static and dynamic analysis. Dynamic, network-level analysis of malware shows its core behavior since it captures the interaction with its developer. On the other hand, increasingly more emphasis is given to using Deep Packet Inspection (DPI) in order to cluster malware’s network behavior. However, DPI has severe privacy implications, as it involves inspecting payloads of the network traffic.This thesis presents an exploratory study, the aim of which is to characterize and cluster malware behavior using high-level, non-privacy-invasive, sequential features extracted from its network activity. The key intuition behind the proposed solution is that if the underlying infrastructure of distinct malware samples is similar, the order in which they perform certain actions should also be similar. The results of this research show that sequence clustering allows flexible and robust clusters, as opposed to using non-sequential features. The clusters themselves reveal interesting attacking capabilities, such as port scans, and the same Command and Control server responding to different malware families. Lastly, a comparison with clusters obtained from static analysis reveals that network-based clustering is far more qualified to determine the many behaviors exhibited by a single malware family, as well as behaviors common across multiple malware families.Computer Science | Cyber Securit
Cybersecurity as a Crosscutting Concept Across an Undergrad Computer Science Curriculum: An Experience Report
Although many Computer Science (CS) programs offer cybersecurity courses,
they are typically optional and placed at the periphery of the program. We
advocate to integrate cybersecurity as a crosscutting concept in CS curricula,
which is also consistent with latest cybersecurity curricular guidelines, e.g.,
CSEC2017. We describe our experience of implementing this crosscutting
intervention across three undergraduate core CS courses at a leading technical
university in Europe between 2018 and 2023, collectively educating over 2200
students. The security education was incorporated within CS courses using a
partnership between the responsible course instructor and a security expert,
i.e., the security expert (after consultation with course instructors)
developed and taught lectures covering multiple CSEC2017 knowledge areas. This
created a complex dynamic between three stakeholders: the course instructor,
the security expert, and the students. We reflect on our intervention from the
perspective of the three stakeholders -- we conducted a post-course survey to
collect student perceptions, and semi-supervised interviews with responsible
course instructors and the security expert to gauge their experience. We found
that while the students were extremely enthusiastic about the security content
and retained its impact several years later, the misaligned incentives for the
instructors and the security expert made it difficult to sustain this
intervention without organizational support. By identifying limitations in our
intervention, we suggest ideas for sustaining it.Comment: 6 pages; Accepted at SIGCSE TS '2
Forecasting Attacker Actions using Alert-driven Attack Graphs
While intrusion detection systems form the first line-of-defense against cyberattacks, they often generate an overwhelming volume of alerts, leading to alert fatigue among security operations center (SOC) analysts. Alert-driven attack graphs (AGs) have been developed to reduce alert fatigue by automatically discovering attack paths in intrusion alerts. However, they only work in offline settings and cannot prioritize critical attack paths. This paper builds an action forecasting capability on top of the existing alert-driven AG framework for predicting the next likely attacker action given a sequence of observed actions, thus enabling analysts to prioritize non-trivial attack paths. We also modify the framework to build AGs in real time, as new alerts are triggered. This way, we convert alert-driven AGs into an early warning system that enables analysts to circumvent ongoing attacks and break the cyber killchain. We propose an expectation maximization approach to forecast future actions in a reversed suffix-based probabilistic deterministic finite automaton (rSPDFA). By utilizing three real-world intrusion and endpoint alert datasets, we empirically demonstrate that the best performing rSPDFA achieves an average top-3 accuracy of 67.27%, which reflects a 57.17% improvement over three baselines, on average. We also invite six SOC analysts to use the evolving AGs in two scenarios. Their responses suggest that the action forecasts help them prioritize critical incidents, while the evolving AGs enable them to choose countermeasures in real-time
Laptop Theft in a University Setting can be Avoided with Warnings
Laptops have become an indispensable asset in today's digital age. They often
contain highly sensitive information, such as credentials and confidential
documents. As a result, the value of a laptop is an accumulation of the value
of both the physical device itself and the cyber assets it contains, making it
a lucrative target for theft. Educational institutions have a large population
of potential victims of laptop theft. To mitigate this risk, we investigate
whether a simple warning sign can reduce the opportunity for potential
offenders. To this end, we have conducted an empirical study to observe the
prevalence of students/staff leaving their laptops unattended at a university
study hall at the Delft University of Technology in the Netherlands, both with
and without a warning sign. We observed 148 out of 220 subjects leaving their
laptops unattended in just three weeks. The results also showed that without
the warning banner, 75.5% (83 out of 110) of subjects left their laptops
unattended and with the warning, only 59.1% (65 out of 110) of subjects showed
the same behavior, which is a significant reduction of 16.4%. In addition, a
qualitative analysis was performed on the responses of subjects who left their
laptops unattended after the warning banner was placed. The results showed a
mix of convenience, and a blind trust on the safety of the faculty. In
conclusion, a simple banner was effective in reducing the opportunity for
laptop theft. However, the percentage of laptops left unattended was still high
even after the introduction of the banner.Comment: The results in this paper are erroneous. Due to selection bias, the
results are not statistically significan
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
Forecasting Attacker Actions using Alert-driven Attack Graphs
While intrusion detection systems form the first line-of-defense against cyberattacks, they often generate an overwhelming volume of alerts, leading to alert fatigue among security operations center (SOC) analysts. Alert-driven attack graphs (AGs) have been developed to reduce alert fatigue by automatically discovering attack paths in intrusion alerts. However, they only work in offline settings and cannot prioritize critical attack paths. This paper builds an action forecasting capability on top of the existing alert-driven AG framework for predicting the next likely attacker action given a sequence of observed actions, thus enabling analysts to prioritize non-trivial attack paths. We also modify the framework to build AGs in real time, as new alerts are triggered. This way, we convert alert-driven AGs into an early warning system that enables analysts to circumvent ongoing attacks and break the cyber killchain. We propose an expectation maximization approach to forecast future actions in a reversed suffix-based probabilistic deterministic finite automaton (rSPDFA). By utilizing three real-world intrusion and endpoint alert datasets, we empirically demonstrate that the best performing rSPDFA achieves an average top-3 accuracy of 67.27%, which reflects a 57.17% improvement over three baselines, on average. We also invite six SOC analysts to use the evolving AGs in two scenarios. Their responses suggest that the action forecasts help them prioritize critical incidents, while the evolving AGs enable them to choose countermeasures in real-time
Behaviour Modelling and Anomaly Detection in Smart-Home IoT Devices
The usage of Internet of Things (IoT) devices has been exponentially increasing and their security is often overlooked. Hackers exploit the vulnerabilities present to perform large scale attacks as well as to obtain privacy-sensitive information. Resource constraints combined with a lack of incentives for manufacturers makes it harder to implement security solutions part of these devices. This thesis aims at developing a system that monitors the behaviour of these IoT devices. Network traffic is captured and analysed as part of a network middle-box to model the behaviour of an IoT device. This traffic shows the interactions of the IoT device with other devices and hosts. By modelling the normal behaviour of a device, we can detect anomalies exhibited. Denial of Service attack was performed to evaluate the effectiveness of state machines in detecting anomalies. To verify the validity of state machines built based on network traffic in a laboratory setup, a test environment with a different setting was used. Traffic was captured from a smart home setting and used to validate the state machines. We show that state machines can be effectively used to model the behaviour of IoT devices at the packet level and can also be used to uniquely identify commands issued from smartphone to IoT device. They can also effectively distinguish attack traffic from normal traffic.Computer Science | Cyber Securit
Variations on the Author
“Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
- …
