A key step in cyberdefense is knowing when and how you are being attacked. This paper discusses how Chebyshev’s Inequality can be used for spotting anomalies. This technique is simple, universal, and resource-light. It also does not require any unusual technology nor does it require any training before it can be applied. This method can be applied to detect both external and internal threats, and can be helpful in protecting intellectual property within an organization. We also show that the method is robust and produces the same results even if the data has been transformed by change of scale or constant displacement. We also discuss how to adjust the technique in situations where the underlying variable is experiencing a dynamic change. We also show how to implement these techniques using simple Python code and basic Excel functions. We also discuss methods for extracting numerical data from visuallypresented information. This technique is very useful in situations where AI impractical because of lack of resources or experience.
This paper deals with the problem of detecting the malware by using emulation approach. Modern malware include various avoid techniques, to hide its anomaly actions. Advantages of using sandbox and emulation technologies are described. Various anti-emulation techniques that are used in modern malware considered. Obfuscation as one primary approach to hide malware malicious actions described and discussed. State of emulator is presented, and the advantages of its usage are covered. Distributed model for malware detection is considered. Basic emulator and its current capabilities presented. Prepared files that represent malware are described. Experimental results for developed files that differs with included avoid techniques are presented. Disadvantages of proposed approach is described. Future research and sandbox improvement are described.
Botnets are often used in cyberattacks on network services and individual users, so the ability to detect botnets is very important. Botnets use DNS tunneling to send malicious command-and-control (C&C) commands to victims' hosts. Unfortunately, DNS tunneling attacks are very hard to detect. The paper presents a new approach for DNS tunneling botnet detection, which considers all the features and architectural characteristics of botnets. The technique described in this paper is highly efficient at detecting DNS tunneling attacks.
In his classic book Aircraft in Warfare, F. W. Lanchester discussed different types of warfare and presented equations, called the Lanchester equations, that can be used to model the results of battles between two forces of different sizes or capabilities. This paper introduces the Lanchester equations and provides a theoretical discussion leading to an analysis of the relative value of increasing the effectiveness of military assets vs. increasing the quantity of those assets. In particular, we show that increasing the effectiveness contributes only linearly to the power of a combatant, but increasing the quantity contributes quadratically. This paper also presents a Python script that models the Lanchester equations, together with a visualization demonstrating the effect of force concentration. The paper concludes with a discussion of the equations' relevance to cyberwarfare, specifically to drone warfare and DDoS attacks.
Order-theoretic lattices and their visualizations are proposed as a means of exploring and analyzing databases. The max-complete lattice is formed and the significance of lattice nodes and of the top node are demonstrated. These novel visualizations serve as a useful complement to well-known charting techniques such as bar charts and may extend the knowledge gained from critical databases. The Carver2 dataset is used as an illustrative example, highlighting the formation of the max-complete lattice from the original dataset and the computational advantage provided by compressing the lattice using only its irreducible elements. Regional information from the Global Terrorism Database (GTD), which has been extensively analyzed and visualized using well-known methods, is visualized using max-complete lattices, and juxtaposing the GTD lattice visualizations with corresponding bar charts demonstrates their complementary nature.
The paper proposes a new socially oriented protocol that avoids pseudo-decentralization and monopolization of the network, increases the availability of the system, provides a fair selection of potential validator nodes, and provides a fair reward for creating new blocks and adding them to the blockchain. Our proposed protocol provides for the creation and addition of new blocks to a blockchain. Defines a node validator, which will create the next block according to its useful activity in the network according to predefined conditions, which can be formed according to the requirements of the system and will satisfy the individual needs of the blockchain. Also in the process of developing the proposed protocol, the main aspects of security related to protection against various types of malicious software, including botnets and computer viruses, were addressed. To apply PoA, the network is designed on a Layered Peer to Peer (LP2P) architecture, the feature of which is that nodes interact at different levels according to their typing or parameterization, which will be used to execute the algorithm developed and find consensus. In addition, the protocol may be one of the steps in the implementation of new principles of local tax policy, where taxes will be tied to the activities of individual members of the public, as well as the renewal of suffrage based on the social activity of network members and a qualitatively new principle of conducting new ones, experimental but qualitative choices.
The paper presents a botnet detection approach for the distributed systems. It is based on the developed three level model, which includes botnet’s components: command and control center, control centers, basic elements of the botnet (bots). The novel framework provides the ability to detect known and unknown botnets, and consists of the host and the network levels. At the host level, the detection procedure is based on the implementation of the Bayes classification. The network level extends the results obtained at the host level to the rest of the local area network. Proposed approach provides the exchange of the results obtained by the Bayes classification for further use by other program units of the distributed system. The results of the developed classifier show that representation of the botnets’ samples for different classes and subclasses is sufficient for efficient botnet detection. Proposed technique demonstrates promising results concerning botnet detection in the distributed systems.
Automated and semi-automated systems that derive actionable information from massive, heterogeneous datasets are essential for many applications. The reasoning of such systems must be as clear as possible in order to earn our trust. Lattices have begun to play a key role in computer science finding applications in distributed computing, programming languages, concurrency theory, and data mining, thereby justifying G. C. Rota's belief that lattice theory will play an important role in 21st Century mathematics [1]. In some instances, researchers must deal with posets that are not necessarily lattices and the question arises how these posets can be embedded in lattices. A classic way to answer this question is to construct the MacNeille completion of the lattice, which is the most compact way to embed a poset into a lattice. In 1973 G. Markowsky introduced the poset of irreducibles construction in his dissertation and demonstrated that this was a very compact way to represent a lattice. In addition, the poset of irreducibles has many of the properties of the poset of join-irreducibles of distributive lattices that was introduced by G. Birkhoff and described in his book [2]. In this paper, we show how to construct the poset of irreducibles for the MacNeille completion of a poset efficiently. We conclude with some applications of these ideas.
The paper proposes the architecture of a distributed malware detection system based on decentralized architecture in local area computer networks. Its feature is the synthesis of its requirements of distribution, decentralization, multilevel. This allows you to use it autonomously. In addition, the feature of the components of the system is the same organization, which allows the exchange of knowledge in the middle of the system, which, unlike the known systems, allows you to use the knowledge gained by separate parts of the system in other parts. The developed system allows to fill it with subsystems of detection of various types of malicious software in local area networks. The paper presents the results of experiments on the use of the developed system for the detection of metamorphic viruses.
The paper presents an approach for the metamorphic viruses detec- tion based on its obfuscation features analysis. The obfuscation features were obtained on the basis of the equivalent functional block search in the suspicious program and its modified version. The results of the research demonstrated that the efficiency of metamorphic viruses detection based on the proposed obfusca- tion quantitative features depends on the choice of the similarity metric at the stages of the search and the choice refinement of the equivalent functional blocks. The adequate choice of similarity metrics at both stages allowed in- creasing the detection efficiency of the metamorphic viruses.
The paper proposes the architecture of distributed multilevel detection system of malicious software in local area networks. Its feature is the synthesis of its requirements of distribution, decentralization, multilevel. This allows you to use it autonomously. In addition, the feature of autonomous program modules of the system is the same organization, which allows the exchange of knowledge in the middle of the system, which, unlike the known systems, allows you to use the knowledge gained by separate parts of the system in other parts. The developed system allows to fill it with subsystems of detection of various types of malicious software in local area networks.
This paper is an extension of my earlier paper [1]. It examines the continuing growth of this problem, and the likelihood that it will continue to get worse. Since the previous paper, the author was contacted by a lawyer involved in litigating a dispute related to TLDs. As noted in the previous paper, misdirected communication has obvious security and privacy ramifications and is an age old problem that predates the Internet. In recent years it has been exacerbated by the arrival of electronic communication and the multitude of ways that communication can be misdirected. A new chapter in this age old problem is being written with the proliferation of top level domains (TLDs). This paper examines this problem in more detail and provides a full analysis of the current set of TLDs. In particular, we are concerned with TLDs that have a nontrivial probability of intercepting traffic intended for another TLD. Intercepting TLDs have the potential of intercepting a lot of traffic since a TLD can support many domain names. This paper updates the results in the previous paper and also performs an auditory similarity measurement between domain names. The issue here is that sometimes TLDs are given orally, such as over the telephone. There are TLDs which, although spelled differently, sound similar to each other. Finally, we give the results of some experiments performed with purchased domain names to be deliberately confusing.
This paper describes an open-source project called RATCHET whose goal is to create software that can be used by large groups of people to construct attack trees. The value of an attack tree increases when the attack tree explores more scenarios. Crowdsourcing an attack tree reduces the possibility that some options might be overlooked. RATCHET has been tested in classroom settings with positive results. This paper gives an overview of RATCHET and describes some of the features that we plan to add. Keywords—crowdsourcing, attack tree, security, attack surface
We describe the recent developments of an open-source project called RATCHET that can be used by groups of users to collectively construct attack trees. We present the RATCHET framework as well as a model for testing and evaluation of the produced attack trees. RATCHET has been tested in classroom settings with positive results and this paper presents the plans for expanding its outreach to the community at large and building attack trees through crowdsourcing. This paper gives an overview of RATCHET and an introduction to its use.
Misdirected communication has obvious security and privacy ramifications and is an age old problem that predates the Internet. In recent years it has been exacerbated by the arrival of electronic communication and the multitude of ways that communication can be misdirected. A new chapter in this age old problem is being written with the proliferation of top level domains (TLDs). This paper examines this problem in more detail and provides a full analysis of the current set of TLDs. In particular, we are concerned with TLDs that have a non-trivial probability of intercepting traffic intended for another TLD. Intercepting TLDs have the potential of intercepting a lot of traffic since a TLD can support many domain names.
Security and Management is a compendium of articles and papers that were presented at SAM '13, an international conference that serves researchers, scholars, professionals, students, and academicians. Selected topics include: * Security Management, Security Education, and Hardware Security* Biometric And Forensics* Computer Security* Information Assurance* Cryptographic Technologies* Systems Engineering and Security* Computer and Network Security* Network Security* Cybersecurity Education* Cryptography + Malware and Spam Detection + Network Security and Cyber Security Education
Many smart, resource-constrained, and seldom-updated devices in the Internet of Things present unanticipated vulnerabilities. The Internet Census 2012 scanned for such devices to construct its Carna Botnet, which then surveyed the entire IPv4 address space. This census provides an order of magnitude for the number of devices vulnerable to just one type of attack. Finally, three scans of different types demonstrate how to scan for vulnerable devices in the Internet of Things. The first uses Shodan to find vulnerable Cayman DSL routers; the second uses Masscan to find devices vulnerable to Heartbleed, and the third used Nmap and PFT to find and connect to vulnerable networked printers.
In this paper we examine the history of using random numbers in computer programs. Unfortunately, this history is sad because it is replete with disasters ranging from one of the first pseudo-random number generators, RANDU, beingverybadtothemostrecenteffortsbytheNSAtounderminethepseudorandom number generator in RSA’s BSAFE cryptographic library. Failures in this area have been both intentional and unintentional, but unfortunately the same sorts of mistakes are repeated. The repeated failures in getting our “randomnumbers”correctsuggeststhattheremightbesomesystemicreasons forthesefailures.Inthispaperwereviewsomeofthesefailuresinmoredetail, and the 2006 Debian OpenSSL Debacle in great detail. This last event left users of Debian and its derivatives with seriously compromised cryptographic capabilities for two years. We also illustrate how this failure can be exploited in an attack. We also modify the concept of a system accident developed in the work of Charles Perrow [1]. We identify some system failures in building pseudo-randomnumbergeneratorsandoffersomesuggestionstohelpdevelop PRNGs and other code more securely.
Big Data tools can give “explanations” of complex and elaborate data sets. There is the danger that we might be content with the explanations that these tools produce. It is important to bear in mind that truly understanding something often requires simplifying the initial explanation. Indeed, the wellknown “Occam’s Razor” states roughly that the simplest explanation is the best. This paper examines two cases, Copernicus’s Solar System Model and a “Big Data” search for Paul Revere, where the initial models were too complex. It shows that simpler models are possible, and more fruitful for further research. Some general techniques for finding simpler explanations are discussed.
Anatoly Sachenko合作论文数Department of Information Computing Systems and Control
Ternopil National Economic University20