For more than a decade, the notion of attack surface has been used to define the set of vulnerable assets that an adversary may exploit to penetrate a system, and various metrics have been developed to quantify the extent of a system's attack surface. However, most approaches to tackle this problem have failed to consider the complex interdependencies that exist between the many components of a distributed system, its vulnerabilities, and its configuration parameters. In our work, building upon previous research on vulnerability metrics and on graphical models to capture such interdependencies, we propose a novel approach to evaluate the potential risk associated with exposed vulnerabilities by studying how the effect of each vulnerability exploit propagates through chains of dependencies. Our analysis goes beyond the scope of traditional attack surface metrics, and considers the depth and implications of potential attacks, leading to the definition of a new family of metrics, which we refer to as attack volume metrics. We present experimental results illustrating how the proposed metric scales for graphs of realistic sizes, and illustrate its application to real‐world testbeds.
In the future, it will be possible to build high-quality models of building interiors based on data from a dense fleet of sensors reporting on air volumes much smaller than a room or zone. To enable such models, we are creating technologies that allow a fleet of sensors to be commissioned quickly at low cost. Our sensor commissioning process builds a 3D model of each building interior that includes sensor positions and sensor networking information such as sensor MAC addresses. It employs multiple technologies, including augmented reality, LiDAR, QR codes, and computer vision. Sensors can be commissioned at more than 10x the speed and at less than one tenth the cost of traditional approaches.
This paper describes a novel approach for generating accurate floor plans and 3D models of building interiors using scanned mesh data. Unlike previous methods, which begin with a high resolution point cloud from a laser range-finder, our approach begins with triangle mesh data, as from a Microsoft HoloLens. It generates two types of floor plans, a "pen-and-ink" style that preserves details and a drafting-style that reduces clutter. It processes the 3D model for use in applications by aligning it with coordinate axes, annotating important objects, dividing it into stories, and removing the ceiling. Its performance is evaluated on commercial and residential buildings, with experiments to assess quality and dimensional accuracy. Our approach demonstrates promising potential for automatic digitization and orientation of scanned mesh data, enabling floor plan and 3D model generation in various applications such as navigation, interior design, furniture placement, facilities management, building construction, and HVAC design.
The paper develops a data-driven approach to optimally control sub-zonal, spatiotemporal temperature profiles in a spacious room. We first calibrate a 2D diffusion Partial Differential Equation (PDE) model for heat transfer with Bluetooth Low Energy (BLE) sensor data (temperature/humidity) obtained from an experimental testbed. This model is then used by an iterative Linear Quadratic Regulator (iLQR) algorithm to generate optimal control policies for each receding horizon of a model predictive control problem. We use automatic differentiation to speed up this process while achieving good performance and convergence. In addition, we use feedback control to maintain the desired spatiotemporal temperature profiles while rejecting external disturbances or noises. Simulation results show the feasibility of optimally controlling the coolers/heaters to obtain the desired temperature at different regions of the room.
Vulnerability analysis has long been used to evaluate the security posture of a system, and vulnerability graphs have become an essential tool for modeling potential multi-step attacks and assessing a system's attack surface. More recently, vulnerability graphs have been adopted as part of a multi-faceted approach to configuration analysis and optimization that aims at leveraging relationships between the components, configuration parameters, and vulnerabilities of a complex system to improve its security while preserving functionality. However, this approach still lacks robust metrics to quantify several important aspects of the system being modeled. To address this limitation, we introduce metrics to enable practical and effective application of graph-based configuration analysis and optimization. Specifically, we define metrics to evaluate (i) the exploitation likelihood of a vulnerability, (ii) probability distributions over the edges of a vulnerability graph, and (iii) exposure factors of system components to vulnerabilities. Our approach builds upon standard vulnerability scoring systems, and we show that the proposed metrics can be easily extended. We evaluate our approach against the Common Weakness Scoring System (CWSS), showing a high degree of correlation between CWE scores and our metrics.
Addressing security misconfiguration in complex distributed systems, such as networked Industrial Control Systems (ICS) and Internet of Things (IoT) is challenging. Owners and operators must go beyond tuning parameters of individual components and consider the security implications of configuration changes on entire systems. Given the growing scale of cyber systems, this task must be highly automated. Unfortunately, prior work on configuration errors has largely ignored the security impact of configurations of connected components. To address this gap, we present SCIBORG, a framework that improves the security posture of distributed systems by examining the impact of configuration changes across interdependent components using a graph-based model of the system and its vulnerabilities. It formulates a Constraint Satisfaction Problem from the graph-based model and uses an SMT solver to find optimal configuration parameter values that minimize the impact of attacks while preserving system functionality. SCIBORG also provides supporting evidence for the proposed configuration changes. We evaluate SCIBORG on an IoT testbed.
This paper describes the process of design, implementation, and real world deployment of a web-based network exploration tool called Network Explorer. We designed Network Explorer based on the expressed needs of our clients and later deployed it as part of a larger system for fraud detection in health care. Our implementation of Network Explorer provides visual interactive access to large-scale network data. As part of the Network Explorer tool we contribute a dynamic group-in-a-box implementation for laying out clusters, and a node navigator widget that aids in the exploration of large networks. We are also contributing two open source components of the Network Explorer for the community to reuse: an in-browser clustering library, and the dynamic group-in-a-box algorithm. We have evaluated the network explorer tool in multiple real-world environments including the fraud detection setting above.
Detection of fraud, waste, and abuse (FWA) is an important yet difficult problem. In this paper, we describe a system to detect suspicious activities in large healthcare claims datasets. Each healthcare dataset is viewed as a heterogeneous network of patients, doctors, pharmacies, and other entities. These networks can be large, with millions of patients, hundreds of thousands of doctors, and tens of thousands of pharmacies, for example. Graph analysis techniques are developed to find suspicious individuals, suspicious relationships between individuals, unusual changes over time, unusual geospatial dispersion, and anomalous networks within the overall graph structure. The system has been deployed on multiple sites and data sets, both government and commercial, to facilitate the work of FWA investigation analysts.
The Receipts2Go system is about the world of one-page documents: cash register receipts, book covers, cereal boxes, price tags, train tickets, fire extinguisher tags. In that world, we're exploring techniques for extracting accurate information from documents for which we have no layout descriptions -- indeed no initial idea of what the document's genre is -- using photos taken with cell phone cameras by users who aren't skilled document capture technicians. This paper outlines the system and reports on some initial results, including the algorithms we've found useful for cleaning up those document images, and the techniques used to extract and organize relevant information from thousands of similar-but-different page layouts.
The Receipts2Go system is about the world of one-page documents: cash register receipts, book covers, cereal boxes, price tags, train tickets, fire extinguisher tags. In that world, we're exploring techniques for extracting accurate information from documents for which we have no layout descriptions -- indeed no initial idea of what the document's genre is -- using photos taken with cell phone cameras by users who aren't skilled document capture technicians. This paper outlines the system and reports on some initial results, including the algorithms we've found useful for cleaning up those document images, and the techniques used to extract and organize relevant information from thousands of similar-but-different page layouts.
A perennially interesting research topic in the field of visual analytics is how to effectively develop systems that support organizational users' decision-making and reasoning processes. The problem is, however, most domain analytical practices generally vary from organization to organization. This leads to diverse designs of visual analytics systems in incorporating domain analytical processes, making it difficult to generalize the success from one domain to another. Exacerbating this problem is the dearth of general models of analytical workflows available to enable such timely and effective designs. To alleviate these problems, we present a two-stage framework for informing the design of a visual analytics system. This design framework builds upon and extends current practices pertaining to analytical workflow and focuses, in particular, on incorporating both general domain analysis processes as well as individual's analytical activities. We illustrate both stages and their design components through examples, and hope this framework will be useful for designing future visual analytics systems. We validate the soundness of our framework with two visual analytics systems, namely Entity Workspace [8] and PatViz [37].
We present research focused on designing knowledge-assisted visual analytics systems for workers in organizational environments. We focus on business analysts and asset managers, who work collaboratively to analyze information and make decisions. Through extensive investigations in two organizational environments, we found that these knowledge workers struggle with managing and analyzing information from multiple perspectives. Their current tools lack support for aggregating, organizing, and sharing such information. To address their needs, we characterized their analytic workflows, extracted specific key knowledge actions for each task commonly found in these workflows, and designed and evaluated two visual analytics systems that support and encapsulate these knowledge actions. We provide design guidelines that should be used when designing knowledge-assisted visual analytics systems, and illustrate their effectiveness with two systems built by following them.
Massimiliano Albanese合作论文数George Mason University3
Benjamin Bederson合作论文数Department of Computer Science, University of Maryland2
Eric Saund合作论文数Palo Alto Research Center2