We establish results on the 2-adic valuations of the Central Stirling numbers of the second kind S(2k,k) . We determine the base 2 patterns of the k values that result in nu = nu(2)(S(2k,k))=0,1,2 , and 3. The proofs are based on finding the patterns that yield the particular valuations by means of partitions of numbers which are less than or equal to k. We use these patterns to find explicit formulas for the number of k < 2h , in terms of Fibonacci numbers, such that nu(2)(S(2k,k))=0,1,2,3. We also prove a theorem on the 3-adic valuations of 3-Central Stirling numbers of the second kind S(3k,k) which illustrates how different the analysis for odd primes is from the analysis for the prime 2.
Zeckendorf's Theorem states that any positive integer can be uniquely decomposed into a sum of distinct, nonadjacent Fibonacci numbers. There are many generalizations, including results on existence of decompositions using only even indexed Fibonacci numbers. We extend these further and prove that similar results hold when only using indices in a given arithmetic progression. As part of our proofs, we generate a range of new recurrences for the Fibonacci numbers that are of interest in their own right.
We generalize results on the $p$-adic valuations of $S(n,k)$, the Stirling number of the second kind and $s(n,k)$ the Stirling number of the first kind. We have several new estimates for these valuations, along with criteria for when the estimates are sharp. The primary foci are the explicit evaluation of $\nu_2(S(n,k))$ with $n=c2^h$, $k=b2^h+a$, $a, b, c, h, k, n \in Z^+$, and $1\le a \le 2^{h-1}$, and $\nu_p(S(n,k))$ when $n=cp^h$ for an odd prime $p$. We have strong new results, which generalize and strengthen previous results, for all primes. We also have some new results on the $p$-adic valuations $\nu_p(s(n,k))$ for all primes. We generally assume that $p-1|n-k$ for exact values of $\nu_p(S(n,k))$ or $\nu_p(s(n,k))$. In addition, we have proved some new Amdeberhan-type identities for Stirling numbers of both kinds. We also extend some recent results and propose two new conjectures, as well as proofs and extensions of previous ones.
Summary: The Delannoy number d ( n ) is defined as the number of paths from (0 , 0) to ( n, n ) with steps (1 , 0) , (1 , 1) , and (0 , 1) , which is equal to the number of paths from (0 , 0) to (2 n, 0) using only steps (1 , 1) , (2 , 0) and (1 , − 1) . The Schröder number s ( n ) counts only those paths that never go below the x -axis. We discuss some p -adic properties of the sequences { d ( p n ) } n →∞ , and { d ( ap n + b ) } n →∞ with a ∈ N , ( a, p ) = 1 , b ∈ Z , and prime p . We also present similar p -adic properties of the Schröder numbers. We provide several supercongruences for these numbers and their differences. Some conjectures are also proposed.
We study the length of the initial up-down alternating segment of a permutation of [n] selected uniformly at random. It turns out that as n tends to infinity, the expected value and the standard deviation of this statistic converge to small constants.
We present research on the limitations of detecting atypical activity by a hypervisor from the perspective of a guest domain. Individual instructions which have virtual machine exiting capability were evaluated, using wall timing and kernel thread racing as metrics. Cache-based memory access timing is performed with the Flush + Reload technique. Analysis of the potential methods for detecting non-temporal memory accesses are also discussed. It is found that a guest domain can use these techniques to reliably determine whether instructions or memory regions are being accessed in manner that deviates from normal hypervisor behavior.
Let [Formula: see text] with [Formula: see text] and [Formula: see text] be an odd prime. We find a supercongruence for [Formula: see text] and related sums of powers of binomial coefficients. These results complement prior results for [Formula: see text] with [Formula: see text] obtained recently by the author.
Tamas Lengyel received his Ph.D. from Eotvos University of Budapest. His mathematical interest span a range of subjects from combinatorics, number theory, and game theory to probability theory, mathematical statistics, and their applications. He has been a faculty member at Occidental College in Los Angeles for 27 years.
ARM has become the leading processor architecture for mobile and IoT devices, while it has recently started claiming a bigger slice of the server market pie as well. As such, it will not be long before malware more regularly target the ARM architecture. Therefore, the stealthy operation of Virtual Machine Introspection (VMI) is an obligation to successfully analyze and proactively mitigate this growing threat. Stealthy VMI has proven itself perfectly suitable for malware analysis on Intel's architecture, yet, it often lacks the foundation required to be equally effective on ARM.
Let [Formula: see text] be an even integer and [Formula: see text] be an odd prime. We study Franel-like sums and alternating sums, as well as lacunary sums of [Formula: see text]th powers of binomial coefficients from the point of view of arithmetic properties. This paper complements the author’s prior work on the cases with [Formula: see text] odd although, it uses a different approach. It develops new supercongruences and determines the [Formula: see text]-adic order of these sums as well as of generalized harmonic sums restricted to particular remainder classes modulo [Formula: see text].
The best-4-of-7 series is a popular playoff format to decide the champion in most North American professional sports. World Series (best-4-of-7) type competitions give rise to interesting probabilistic and statistical questions. We determine the expected length of this type of series by relating it to a problem involving order statistics. We also calculate the variance of the length and provide a simple formula for series of fair games. The method can be extended to derive higher order moments. This novel approach leads to new results that can be formulated in closed forms in terms of the distribution function of various binomial distributions. The emphasis is on establishing the connection to order statistics and obtaining closed forms. The relation to the negative binomial distribution as well as to the sooner waiting time problem in sequential testing is also discussed. We also consider the case when ties are allowed in the single games.
Let [Formula: see text] be an integer and [Formula: see text] be an odd prime. We study sums and lacunary sums of [Formula: see text]th powers of binomial coefficients from the point of view of arithmetic properties. We develop new congruences and prove the [Formula: see text]-adic convergence of some subsequences and that in every step we gain at least one or three more [Formula: see text]-adic digits of the limit if [Formula: see text] or [Formula: see text], respectively. These gains are exact under some explicitly given conditions. The main tools are congruential and divisibility properties of the binomial coefficients and multiple and alternating harmonic sums.
The inability of existing architectures to allow corporations to quickly process information at scale and share knowledge with peers makes it difficult for malware analysis researchers to present a clear picture of criminal activity. Hence, analysis is limited in effectively and accurately identify the full scale of adversaries' activities and develop effective mitigation strategies. In this paper, we present SKALD: a novel architecture which guides the creation of analysis systems to support the research of malicious activities plaguing computer systems. Our design provides the scalability, flexibility, and robustness needed to process current and future volumes of data. We show that our prototype is able to process millions of samples in only few milliseconds per sample with zero critical errors. Additionally, SKALD enables the development of new methodologies for information sharing, enabling analysis across collective knowledge. Consequently, defenders can perform accurate investigations and real-time discovery, while reducing mitigation time and infrastructure cost.
Automatic malware classification is an essential improvement over the widely-deployed detection procedures using manual signatures or heuristics. Although there exists an abundance of methods for collecting static and behavioral malware data, there is a lack of adequate tools for analysis based on these collected features. Machine learning is a statistical solution to the automatic classification of malware variants based on heterogeneous information gathered by investigating malware code and behavioral traces. However, the recent increase in variety of malware instances requires further development of effective and scalable automation for malware classification and analysis processes. In this paper, we investigate the topic modeling approaches as semantics-aware solutions to the classification of malware based on logs from dynamic malware analysis. We combine results of static and dynamic analysis to increase the reliability of inferred class labels. We utilize a semi-supervised learning architecture to make use of unlabeled data in classification. Using a nonparametric machine learning approach to topic modeling we design and implement a scalable solution while maintaining advantages of semantics-aware analysis. The outcomes of our experiments reveal that our approach brings a new and improved solution to the reoccurring problems in malware classification and analysis.
Malicious file analysis is well beyond the days when creating simple hashes for binaries was sufficient. The use of malicious PDF, Office, and other files present a far more diverse threat than our defensive tools were originally designed to handle. Even PE32 executables have been turned into poliand meta-morphic binaries with layers of packing applied to hide from detection. To make matters worse, the sheer influx of files to analyze presents a meaningful logistical problem which becomes increasingly complex as analytic methods move from static to dynamic analysis. When the point in time problem is considered the fact that historical discoveries can be viewed differently in the light of new analytic techniques or information the problem seems all but intractable. To this end, we designed the Skald framework, a blueprint for future analytic systems. We leveraged this framework to develop TOTEM, a system which is capable of coordinating, orchestrating, and scaling malware analytics across multiple cloud providers and thousands of running instances. TOTEM makes it easy to add new capabilities and can intelligently segregate work based on features, such as filetype, analytic duration, and computational complexity. TOTEM supports dynamic analysis through DRAKVUF, a novel open-source dynamic malware analysis system which was designed specifically to achieve unparalleled scalability, while maintaining a high level of stealth and visibility into the executing sample. Building on the latest hardware virtualization extensions found in Intel processors and the Xen hypervisor, DRAKVUF remains completely hidden from the executing sample and requires no special software to be installed within the sandbox. Further addressing the problem of monitoring kernel-mode rootkits as well as userspace applications, DRAKVUF significantly raises the bar for evasive malware to remain undetected. This paper will discuss the design, implementation, and practical deployment of TOTEM and DRAKVUF to analyze tremendous numbers of binary files.
Due to the proliferation of cloud computing, cloud-based systems are becoming an increasingly attractive target for malware. In an Infrastructure-as-a-Service (IaaS) cloud, malware located in a customer’s virtual machine (VM) affects not only this customer, but may also attack the cloud infrastructure and other co-hosted customers directly. This paper presents CloudIDEA, an architecture that provides a security service for malware defens in cloud environments. It combines lightweight intrusion monitoring with on-demand isolation, evidence collection, and in-depth analysis of VMs on dedicated analysis hosts. A dynamic decision engine makes on-demand decisions on how to handle suspicious events considering cost-efficiency and quality-of-service constraints.
The goal of this paper is to describe s(n, k) mod p(e) and calculate v(p)(s(n, k)) for a prime p, fixed integer k >= 1, and large enough e and n. Some special cases of the form s(ap(n), k) mod p(e) and its relation to s(ap(n+1), kp) mod p(e) as well as bounds on v(p)(s(ap(n), k)) and its exact values in some special cases are completely determined.We also investigate the properties of v(p)(s(n,n - k)) and v(p)(s(ap(n) + b, ap(n) + b - k)) which are significantly different from those of v(p)(s(n, k)) and vp (s (ap(n), k)).We use congruential identities for the generalized harmonic numbers, and new congruential and convolution identities for s(n, k). (C) 2014 Elsevier Inc. All rights reserved.