We apply a variation of socio-cultural cognitive mapping (SCM) to computer malware features explored previously by Saxe and Berlin that characterized malware binaries as benign or malicious based on 1024 program features derived from a deep neural network-based detection system. In this work, we model the features as attributes within a latent spatial domain using a weighted consensus graph representation to visualize and analyze the malware binary communities. The data used in our analysis is extracted from a Remote Access Trojan family named Sakula that first appeared in 2012, and has been used to enable an adversary to run interactive commands and execute remote program functions. Our results show that by SCM we were able to identify distinct malware communities within the malware family, which revealed insights into the overall structure of the various binaries as well as possible temporal relationships between the binaries.
Solving potential problems, such as those that occur in the analysis of steady-state heat transfer, electrostatics, ideal fluid flow, and groundwater flow, is important in several fields of engineering, science, and applied mathematics. Numerical solution of the relevant governing equations typically involves using techniques such as domain methods (including finite element, finite difference, or finite volume), or boundary element methods (using either real or complex variables). In this paper, the Complex Variable Boundary Element method (“CVBEM”) is examined with respect to the use of different types of basis functions in the CVBEM approximation function. Four basis function families are assessed in their solution success in modeling an important benchmark problem in ideal fluid flow; namely, flow around a 90 degree bend. Identical problem domains are used in the examination, and identical degrees of freedom are used in the CVBEM approximation functions. Further, a new computational modeling error is defined and used to compare the results herein; specifically, M = E / N where M is the proposed computational error measure, E is the maximum difference (in absolute value) between approximation and boundary condition value, and N is the number of degrees of freedom used in the approximation.
The complex variable boundary element method or CVBEM is a numerical technique that can provide solutions to potential value problems in two or more dimensions by the use of an approximation function that is derived from the Cauchy integral equation in complex analysis.Given the potential values (i.e. a Dirichlet problem) along the boundary, the typical problem is to use the potential function to solve the governing Laplace equation.In this approach, it is not necessary to know the streamline values on the boundary.The modeling approach can be extended to problems where the streamline function is needed because there are known streamline values along the problem boundary (i.e. a mixed boundary value problem).Two common problems that have such conditions are insulation on a boundary and fluid flow around a solid obstacle.In this paper, five advances in the CVBEM are made with respect to the modeling of the mixed boundary value problem; namely (1) the use of Mathematica and Matlab in tandem to calculate and plot the flow net of a boundary value problem.(2) The magnitude of the size of the problem domain is extended.(3) The modeling results include direct computation and development of a flow net.(4) The graphical displays of the total flownet are developed simultaneously.And (5) the nodal point location as an additional degree of freedom in the CVBEM modeling approach is extended to mixed boundaries.A demonstration problem of fluid flow is included to illustrate the flownet development capability.
The Laplace equation that results from specifying either the normal or tangential force equilibrium equation in terms of the warping functions or its conjugate can be modeled as a complex variable boundary element method or CVBEM mixed boundary problem. The CVBEM is a well-known numerical technique that can provide solutions to potential value problems in two or more dimensions by the use of an approximation function that is derived from the Cauchy Integral in complex analysis. This paper highlights three customizations to the technique.•A least squares approach to modeling the complex-valued approximation function will be compared and analyzed to determine if modeling error on the boundary can be reduced without the need to find and evaluated additional linearly independent complex functions.•The nodal point locations will be moved outside the problem domain.•Contour and streamline plots representing the warping function and its complementary conjugate are generated simultaneously from the complex-valued approximating function.
The complex variable boundary element method (CVBEM) provides solutions of partial differential equations of the Laplace and Poisson type. Because the CVBEM is based upon convex combinations from a basis set of functions that are analytic throughout the problem domain, boundary, and exterior of the problem domain union boundary (except along branch cuts), both the real and imaginary parts of the CVBEM approximations satisfy the Laplace equation, leaving the modeling error reduction effort to be that of fitting the problem boundary conditions. In this paper, the approximate boundary approach is used to depict the goodness of fit between the CVBEM results and the problem boundary conditions. The approximate boundary is the locus of points where the CVBEM approximation function meets the values of the problem boundary conditions. Because of the collocation method, the approximate boundary necessarily intersects the problem boundary at least at the collocation points specified on the problem boundary. Consequently, adding nodes and collocation points on the problem boundary results in reducing the departure between the approximate boundary and the true problem boundary. Thus, the approximate boundary is developed by tracking level curves from the real and/or imaginary parts of the CVBEM approximation function.
Evolutionary graph theory (EGT), studies the ability of a mutant gene to overtake a finite structured population. In this review, we describe the original framework for EGT and the major work that has followed it. This review looks at the calculation of the “fixation probability” – the probability of a mutant taking over a population and focuses on game-theoretic applications. We look at varying topics such as alternate evolutionary dynamics, time to fixation, special topological cases, and game theoretic results. Throughout the review, we examine several interesting open problems that warrant further research.
Two key problems in the study of longitudinal networks are determining when to chunk continuous time data into discrete time periods for network analysis and identifying periodicity in the data. In addition, statistical process control applied to longitudinal social network measures can be biased by the effects of relational dependence and periodicity in the data. Thus, the detection of change is often obscured by random noise. Fourier analysis is used to determine statistically significant periodic frequencies in longitudinal network data. Two approaches are then offered: using significant periods as a basis to chunk data for longitudinal network analysis or using the significant periods to filter the longitudinal data. E-mail communication collected at the United States Military Academy is examined.
Security organizations often attempt to disrupt terror or insurgent networks by targeting "high value targets" (HVT's). However, there have been numerous examples that illustrate how such networks are able to quickly re-generate leadership after such an operation. Here, we introduce the notion of a "shaping" operation in which the terrorist network is first targeted for the purpose of reducing its leadership re-generation ability before targeting HVT's. We look to conduct shaping by maximizing the network-wide degree centrality through node removal. We formally define this problem and prove solving it is NP-Complete. We introduce a mixed integer-linear program that solves this problem exactly as well as a greedy heuristic for more practical use. We implement the greedy heuristic and found in examining five real-world terrorist networks that removing only 12% of nodes can increase the network-wide centrality between 17% and 45%.
This article views all educational approaches as either traditional (teacher-centered) or non-traditional (learner-centered), with not much emphasis placed on differentiating between the non-traditional models. The purpose of this paper is to describe the impediments to changing one's approach to teaching and some strategies to overcome those impediments. We will also focus our attention on those educators who seek to change from a traditional approach to a more non-traditional approach to teaching. The three main sources of resistance described are the students, the administration, and the individual attempting the change. The rest of the paper describes strategies and actions to deal with the resistances encountered.
An eighth order method for finding simple zeros of nonlinear functions is developed. The method requires two function- and three derivative-evaluation per step. If we define informational efficiency of a method as the order per function evaluation, we find that our method has informational efficiency of 1.6.
Real world communication networks are dynamic, thus reliably estimating network measures is challenging. Therefore a new framework is proposed to determine the underlying probability distribution of specific communication network measures. Communications between two individuals that are socially connected may vary, yet their underlying relationship remains unchanged. In this case, estimates of network measures, such as density or degree centrality may be severely affected by the occurrence or absence of observed communication between individuals. Two communication networks are modeled from empirical data using the network probability matrix (NPM). The NPM estimates the underlying edge probabilities between each pair of individuals. This framework can model a specific social group regardless of their network topology. Monte Carlo simulation is used with the NPM to generate instances of each communication network. A statistical distribution is fit to the density measure. This probability distribution can then be used to detect statistically significant changes in density.
A method of order four for finding multiple zeros of nonlinear functions is developed. The method is based on Jarratt’s fifth-order method (for simple roots) and it requires one evaluation of the function and three evaluations of the derivative. The informational efficiency of the method is the same as previously developed schemes of lower order. For the special case of double root, we found a family of fourth-order methods requiring one less derivative. Thus this family is more efficient than all others. All these methods require the knowledge of the multiplicity.
A three-dimensional (3-D) continuum mechanics approach to the development of a time-dependent finite element model for optimizing the position and excitation of a seismo-acoustic sonar source array to detect the presence of buried landmines will be presented. Various source configurations will demonstrate the use of constructive and destructive interference, which maximizes the radiated energy of unidirectional Rayleigh waves while suppressing the radiation of body waves. Radiation characteristics are analyzed in a linear, horizontally stratified (isotropic and homogeneous within each layer) half-space with a discrete number of transient seismic sources. Results for Rayleigh wave strengths are presented in both a homogeneous half-space and a layered medium.
A three-dimensional (3-D) continuum mechanics approach to the development of a time-dependent finite-element model for optimizing the position and excitation of source array elements for use in a seismic sonar to detect buried landmines is presented. Mathematical formulation of the problem consists of the coupling of a system of linear, second order, partial differential equations and related boundary conditions into one single wave equation, from which a composite elastic finite element is derived. The hp-adaptive finite-element kernel, ProPHLEX [Altair Engineering, Inc., McKinney, TX], is used to perform the numerical computations. The radiation characteristics of a discrete number of transient seismic sources are analyzed in a linear, isotropic, homogeneous half-space. Results for radial and vertical radiation fields, and for radiated Rayleigh wave strength will be presented for various source configurations. Particular attention will be paid to those configurations which maximize the radiation of unidirectional Rayleigh waves, while suppressing the radiation of unwanted body waves.