
Sanghyun Ahn, University of Seoul Amir H. Alavi, University of Missouri Ladjel Bellatreche, LIAS/ENSMA Athman Bouguettaya, The University of Sydney Stephane Bressan, National University of Singapore K. Selcuk Candan, Arizona State University Tru Cao, Ho Chi Minh City University of Technology Songcan Chen, Nanjing University of Aeronautics & Astronautics Hong Chen, Renmin University of China Heeryon Cho, Kookmin University Soo-Mi Choi, Sejong University Mi-Jung Choi, Kangwon National University Hoon Choi, Chungnam National University Jaegul Choo, Korea University Soon Ae Chun, City University of New York Shifei Ding, China University of Mining and Technology Gill Dobbie, The University of Auckland Koji Eguchi, Hiroshima University Sameh Elnikety, Microsoft Young Ik Eom, Sungkyunkwan University Sergio Flesca, University of Calabria Zhipeng Gao, Beijing University of Posts and Telecommunications Wei Gao, Nanjing University Hong Gao, Harbin Institute of Technology Xin Geng, Southeast University Chen Gong, Shanghai Jiao Tong University Hyoil Han, Illinois State University Kenji Hatano, Doshisha University Kazumasa Horie, University of Tsukuba Wen Hua, The University of Queensland Seung-Won Hwang, Yonsei University Eenjun Hwang, Korea University Hyeonseung Im, Kangwon National University Md. Saiful Islam, Griffith University Young-Seob Jeong, SoonChunHyang University Seong-Ho Jeong, Hankuk University of Foreign Studies Xiaolong Jin, Chinese Academy of Sciences
Air-gapped computers are hermetically isolated from the Internet to eliminate any means of information leakage. In this paper we present HOTSPOT - a new type of airgap crossing technique. Signals can be sent secretly from air-gapped computers to nearby smartphones and then on to the Internet - in the form of thermal pings. The thermal signals are generated by the CPUs and GPUs and intercepted by a nearby smartphone. We examine this covert channel and discuss other work in the field of air-gap covert communication channels. We present technical background and describe thermal sensing in modern smartphones. We implement a transmitter on the computer side and a receiver Android App on the smartphone side, and discuss the implementation details. We evaluate the covert channel and tested it in a typical work place. Our results show that it possible to send covert signals from air-gapped PCs to the attacker on the Internet through the thermal pings. We also propose countermeasures for this type of covert channel which has thus far been overlooked.
These keynotes discusses the following: Cyber Training Activities of the European Security and Defence College, Understanding Firmware Forensics using the Trusted Platform Module, AI: Trustworthy or Not on Software Security?, A Glimpse of 5G Security: Challenges and Opportunities, Upcoming Global Initiative Report.
The temptation to influence and sway public opinion most certainly increases with the growth of open online forums where anyone anonymously can express their views and opinions. Since online review sites are a popular venue for opinion influencing attacks, there is a need to automatically identify deceptive posts. The main focus of this work is on automatic identification of deceptive reviews, both positive and negative biased. With this objective, we build a deceptive review SVM based classification model and explore the performance impact of using different feature types (TF-IDF, word2vec, PCFG). Moreover, we study the transferability of trained classification models applied to review data sets of other types of products, and, the classifier robustness, i.e., the accuracy impact, against attacks by stylometry obfuscation trough machine translation. Our findings show that i) we achieve an accuracy of over 90% using different feature types, ii) the trained classification models do not perform well when applied on other data sets containing reviews of different products, and iii) machine translation only slightly impacts the results and can not be used as a viable attack method.
Onboarding of new customers is a sensitive task for various services, like Banks who have to follow the Know Your Customer (KYC) rules. Mobile Onboarding Applications or KYC by Streaming are expanding rapidly to provide this capacity at home. Unfortunately, this leaves the authentication tools in the hand of end-users, allowing the attacker to directly tamper the video stream. With the rise of new digital face manipulation technologies, traditional face spoofing attacks such as presentation attacks or replay attacks should not be the only one to be considered. A new kind of face spoofing attacks (i.e. digital face spoofing) needs to be studied carefully. In this paper, we analyze those new kinds of attacks and propose a method to secure identity documents against both the traditional attacks and the new ones.
This article proposes a mathematical model for quantifying relationships between agents within a network based on their similarity, dissimilarity, level of friendship, group and activity status of the agent. We propose a set of functions to facilitate quantifying social dynamics. Our functions cover the comparison of an agent with group and comparing a group with groups based on their set of attributes. We also propose a model of comparison for agent vs. agent based on their attributes, features and the likelihood of attribute similarity between agents. The model employs a method of determining connection probabilities between nodes in order to find hidden connections between agents. We build on existing work in the study of social networks.
This paper proposes a correlation point matching approach, i.e. an efficient methodology for applying geometric normalization for profile face images. This method is used to increase accuracy without imposing a significant increase in face matching computational time when using different feature descriptors. In our work, several such descriptors are tested to compare the accuracy with which low level facial features (edges), useful for profile face image geometric normalization, are extracted. Hence, we determined the most efficient normalization approach that does not substantially increase computational time. Experimental results show that the use of eigenvalues produces a higher than average edge point count, while having a lower increase in computational complexity compared to other similar algorithms. Then, the extracted features are matched using the random sample consensus algorithm (RANSAC). Next, the rotational angles between the pairs of features are calculated and averaged to yield the angle of rotation necessary to achieve a proper profile face image normalization representation. After applying our proposed approach to a deep learning-based profile face recognition algorithm, an increase of 7.2% accuracy is achieved when compared to the baseline (non-normalized profile faces). To the best of our knowledge, this is the first time in the open literature that the impact of automated profile face normalization is being investigated to improve deep learning-based profile face matching performance.
Identifying and profiling threat actors are high priority tasks for a number of governmental organizations. These threat actors may operate actively, using the Internet to promote propaganda, recruit new members, or exert command and control over their networks. Alternatively, threat actors may operate passively, demonstrating operational security awareness online while using their Internet presence to gather information they need to pose an offline physical threat. This paper presents a flexible new prototype system that allows analysts to automatically detect, monitor and characterize threat actors and their networks using publicly available information. The proposed prototype system fills a need in the intelligence community for a capability to automate manual construction and analysis of online threat networks. Leveraging graph sampling approaches, we perform targeted data collection of extremist social media accounts and their networks. We design and incorporate new algorithms for role classification and radicalization detection using insights from social science literature of extremism. Additionally, we develop and implement analytics to facilitate monitoring the dynamic social networks over time. The prototype also incorporates several novel machine learning algorithms for threat actor discovery and characterization, such as classification of user posts into discourse categories, user post summaries and gender prediction.
Sporting events can attract large crowds who are capable of spurring on their teams. Emotionally charged crowds have a potential to become violent and disruptive, damaging and destroying public properties. Managing and controlling riotous crowds is an important responsibility for police officers to keep public order and safety. Devising and optimizing crowd management strategies is difficult without the knowledge of the scale and situations of the crowd in advance. This paper presents a three-dimensional (3D) simulation framework that simulates a riot and the police response to the riot. The simulation framework is based on agent-based modeling and simulation, consisting of crowd agents, police agents, and transit systems. This study focuses on a specific crowd control strategy: pushing the crowd to the public transit. The police officers in this simulation form police lines which move towards targeted positions pushing the crowd towards the position. In order to optimally disperse the crowd, the police lines move towards public access stations in the transit systems, coercing the crowd to the vicinity of the public transit and containing them there. By directing the crowd into the area where public transit picks up passengers, the crowd would dissipate as crowd occupants got on the transit to leave. The 2011 Vancouver Stanley Cup riot is used in the simulation as a case study. The result of the actual crowd control of the event and that of the crowd control simulation are compared. The framework of this study can be used for other sporting or large crowd events at various locations and for devising different crowd control planning strategies.
Can hotel reviews be used as a proxy for predicting crime hotspots? Domain knowledge indicates that hotels are crime attractors, and therefore, hotel guests might be reliable “human crime sensors”. In order to assess this heuristic, we propose a novel method by mapping actual crime events into hotel reviews from London, using spatial clustering and sentiment feedback. Preliminary findings indicate that sentiment scores from hotel reviews are inversely correlated with crime intensity. Hotels with positive reviews are more likely to be adjacent to crime hotspots, and vice versa. One possible explanation for this counterintuitive finding that the review data are not mapped against specific crime types, and thus the crime data capture mostly police visibility on the site. More research and domain knowledge are needed to establish the strength of hotel reviews as a proxy for crime prediction.
In this paper, we present a novel language model-based method for detecting both human trafficking ads and trafficking indicators. The proposed system leverages language models to learn language structures in adult service ads, automatically select a list of keyword features, and train a machine learning model to detect human trafficking ads. The method is interpretable and adaptable to changing keywords used by traffickers. We apply this method to the Trafficking-10k dataset and show that it achieves better results than the previous models that leverage both ad text and images for detection. Furthermore, we demonstrate that our system can be successfully applied to detect suspected human trafficking organizations and rank these organizations based on their risk scores. This method provides a powerful new capability for law enforcement to rapidly identify ads and organizations that are suspected of human trafficking and allow more proactive policing using data.
Sentiment analysis, also known as opinion mining, plays a big role in both private and public sector Business Intelligence (BI); it attempts to improve public and customer experience. Nevertheless, de-identified sentiment scores from public social media posts can compromise individual privacy due to their vulnerability to record linkage attacks. Established privacy-preserving methods like k-anonymity, l-diversity and t-closeness are offline models exclusively designed for data at rest. Recently, a number of online anonymization algorithms (CASTLE, SKY, SWAF) have been proposed to complement the functional requirements of streaming applications, but without open-source implementation. In this paper, we present a reusable Apache NiFi dataflow that buffers tweets from multiple edge devices and performs anonymized sentiment analysis in real-time, using randomization. The solution can be easily adapted to suit different scenarios, enabling researchers to deploy custom anonymization algorithms.
Global social media networks' omnipresent access, real time responsiveness and ability to connect with and influence people have been responsible for these networks' sweeping growth. However, as an unintended consequence, these defining characteristics helped create a powerful new technology for spread of propaganda and false information. We present a novel approach for characterizing disinformation networks on social media and distinguishing between different network roles using graph embeddings and hierarchical clustering. In addition, using topic filtering, we correlate the node characterization results with proxy opinion estimates. We plan to study opinion dynamics using signal processing on graphs approaches using longer-timescale social media datasets with the goal to model and infer influence among users in social media networks.
Currently, packet data networks are widespread. Their architectural features allow constructing covert channels that are able to transmit covert data under the conditions of using standard protection measures. However, encryption or packets length normalization, leave the possibility for an intruder to transfer covert data via timing covert channels (TCCs). In turn, inter-packet delay (IPD) normalization leads to reducing communication channel capacity. Detection is an alternative countermeasure. At the present time, detection methods based on machine learning are widely studied. The complexity of TCCs detection based on machine learning depends on the availability of traffic samples, and on the possibility of an intruder to change covert channels parameters. In the current work, we explore the cases of TCCs detection via machine learning and study the possibility to implement learning machines algorithms for detecting TCCs under conditions of varying covert channel characteristics: flow capacity and encoding scheme.
The last years has witnessed a surge of auto-generated content on social media. While many uses are legitimate, bots have also been deployed in influence operations to manipulate election results, affect public opinion in a desired direction, or to divert attention from a specific event or phenomenon. Today, many approaches exist to automatically identify bot-like behaviour in order to curb illegitimate influence operations. While progress has been made, existing models are exceedingly complex and nontransparent, rendering validation and model testing difficult. We present a transparent and parsimonious method to study influence operations on Twitter. We define nine different attributes that can be used to describe and reason about different characteristics of a Twitter account. The attributes can be used to group accounts that have similar characteristics and the result can be used to identify accounts that are likely to be used to influence public opinion. The method has been tested on a Twitter data set consisting of 66,000 accounts. Clustering the accounts based on the proposed features show promising results for separating between different groups of reference accounts.
Nowadays, smartphones are used for getting access to sensitive and private data. As a result, we need an authentication system that will provide smartphones with additional security and at the same time will not cause annoyance to users. Existing authentication mechanisms provide just a one-time user verification and do not perform re-authentication in the process of further interaction. In this paper, we present a continuous user authentication system based on user's interaction with the touchscreen in conjunction with micromovements, performed by smartphones at the same time. We consider two of the most common types of gestures performed by users (vertical swipes up and down, and taps). The novelty of our approach is that swipes and taps are both analyzed to provide continuous authentication. Swipes are informative gestures, while taps are the most common gestures. This way, we aim to reduce the time of impostors' detection. The proposed scheme collects data from the touchscreen and multiple 3-dimensional sensors integrated in all modern smartphones. We use One-Class Support Vector Machine (OSVM) algorithm to get a model of a legitimate user. The obtained results show that the proposed scheme of continuous authentication can improve smartphone security.
This study examines how social network based approach can be applied in order to mine the security oriented discussions in Suomi24 online forum. The approach employs a student survey questionnaire to collect a dictionary related to Finland national security. In subsequent analysis, the vocabulary terms are mapped to Suomi24 corpus in order to construct the associated social network analysis that quantifies the dependency among the various vocabulary terms. Especially, the analysis of the dynamic variation of the network topology would enable the decision-maker to devise appropriate communication scheme to maximize intervention in the public sphere and reach a wider audience. Besides, a parser that finds the keywords from VeRticalzed text data format is developed to aid the construction of the underlined social network.
In recent years, the perpetrators of cyber-attacks have been playing a dynamic cat and mouse game with cybersecurity analysts who try to trace the attack and reconstruct the attack steps. While analysts rely on alert correlations, machine learning, and advanced visualizations in order to come up with sound attack hypotheses, they primarily rely on their knowledge and experience. Cyber Threat Intelligence (CTI) on past similar attacks may help with attack reconstruction by providing a deeper understanding of the tools and attack patterns used by attackers. In this paper, we present the Attack Hypothesis Generator (AHG) which takes advantage of a knowledge graph derived from threat intelligence in order to generate hypotheses regarding attacks that may be present in an organizational network. Based on five recommendation algorithms we have developed and preliminary analysis provided by a security analyst, AHG provides an attack hypothesis comprised of yet unobserved attack patterns and tools presumed to have been used by the attacker. The proposed algorithms can help security analysts by improving attack reconstruction and proposing new directions for investigation. Experiments show that when implemented with the MITRE ATT&CK knowledge graph, our algorithms can significantly increase the accuracy of the analyst's preliminary analysis.
Personally Identifiable Information (PII) is often called the “currency of the Internet” as identity assets are collected, shared, sold, and used for almost every transaction on the Internet. PII is used for all types of applications from access control to credit score calculations to targeted advertising. Every market sector relies on PII to know and authenticate their customers and their employees. With so many businesses and government agencies relying on PII to make important decisions and so many people being asked to share personal data, it is critical to better understand the fundamentals of identity to protect it and responsibly use it. Previously developed comprehensive Identity Ecosystem utilizes graphs to model PII assets and their relationships and is powered by empirical data from almost 6,000 real-world identity theft and fraud news reports to populate the UT CID Identity Ecosystem. We obtained UT CID Identity Ecosystem from its authors to analyze using graph theory. We report numerous novel statistics using identity asset content, structure, value, accessibility, and impact. Our work sheds light on how identity is used and paves the way for improving identity protection.