Matches in SemOpenAlex for { <https://semopenalex.org/work/W4294198530> ?p ?o ?g. }
Showing items 1 to 69 of
69
with 100 items per page.
- W4294198530 abstract "Modern computer threats are far more complicated than those seen in the past. They are constantly evolving, altering their appearance, perpetually changing disguise. Under such circumstances, detecting known threats, a fortiori zero-day attacks, requires new tools, which are able to capture the essence of their behavior, rather than some fixed signatures. In this work, we propose novel universal anomaly detection algorithms, which are able to learn the normal behavior of systems and alert for abnormalities, without any prior knowledge on the system model, nor any knowledge on the characteristics of the attack. The suggested method utilizes the Lempel-Ziv universal compression algorithm in order to optimally give probability assignments for normal behavior (during learning), then estimate the likelihood of new data (during operation) and classify it accordingly. The suggested technique is generic, and can be applied to different scenarios. Indeed, we apply it to key problems in computer security. The first is detecting Botnets Command and Control (C&C) channels. A Botnet is a logical network of compromised machines which are remotely controlled by an attacker using a C&C infrastructure, in order to perform malicious activities. We derive a detection algorithm based on timing data, which can be collected without deep inspection, from open as well as encrypted flows. We evaluate the algorithm on real-world network traces, showing how a universal, low complexity C&C identification system can be built, with high detection rates and low false-alarm probabilities. Further applications include malicious tools detection via system calls monitoring and data leakage identification." @default.
- W4294198530 created "2022-09-02" @default.
- W4294198530 creator A5034254887 @default.
- W4294198530 creator A5050033032 @default.
- W4294198530 date "2015-08-14" @default.
- W4294198530 modified "2023-09-25" @default.
- W4294198530 title "Universal Anomaly Detection: Algorithms and Applications" @default.
- W4294198530 doi "https://doi.org/10.48550/arxiv.1508.03687" @default.
- W4294198530 hasPublicationYear "2015" @default.
- W4294198530 type Work @default.
- W4294198530 citedByCount "0" @default.
- W4294198530 crossrefType "posted-content" @default.
- W4294198530 hasAuthorship W4294198530A5034254887 @default.
- W4294198530 hasAuthorship W4294198530A5050033032 @default.
- W4294198530 hasBestOaLocation W42941985301 @default.
- W4294198530 hasConcept C110875604 @default.
- W4294198530 hasConcept C11413529 @default.
- W4294198530 hasConcept C116834253 @default.
- W4294198530 hasConcept C119857082 @default.
- W4294198530 hasConcept C124101348 @default.
- W4294198530 hasConcept C136764020 @default.
- W4294198530 hasConcept C148730421 @default.
- W4294198530 hasConcept C154945302 @default.
- W4294198530 hasConcept C22735295 @default.
- W4294198530 hasConcept C26517878 @default.
- W4294198530 hasConcept C2776836416 @default.
- W4294198530 hasConcept C35525427 @default.
- W4294198530 hasConcept C38652104 @default.
- W4294198530 hasConcept C41008148 @default.
- W4294198530 hasConcept C541664917 @default.
- W4294198530 hasConcept C59822182 @default.
- W4294198530 hasConcept C739882 @default.
- W4294198530 hasConcept C77052588 @default.
- W4294198530 hasConcept C86803240 @default.
- W4294198530 hasConceptScore W4294198530C110875604 @default.
- W4294198530 hasConceptScore W4294198530C11413529 @default.
- W4294198530 hasConceptScore W4294198530C116834253 @default.
- W4294198530 hasConceptScore W4294198530C119857082 @default.
- W4294198530 hasConceptScore W4294198530C124101348 @default.
- W4294198530 hasConceptScore W4294198530C136764020 @default.
- W4294198530 hasConceptScore W4294198530C148730421 @default.
- W4294198530 hasConceptScore W4294198530C154945302 @default.
- W4294198530 hasConceptScore W4294198530C22735295 @default.
- W4294198530 hasConceptScore W4294198530C26517878 @default.
- W4294198530 hasConceptScore W4294198530C2776836416 @default.
- W4294198530 hasConceptScore W4294198530C35525427 @default.
- W4294198530 hasConceptScore W4294198530C38652104 @default.
- W4294198530 hasConceptScore W4294198530C41008148 @default.
- W4294198530 hasConceptScore W4294198530C541664917 @default.
- W4294198530 hasConceptScore W4294198530C59822182 @default.
- W4294198530 hasConceptScore W4294198530C739882 @default.
- W4294198530 hasConceptScore W4294198530C77052588 @default.
- W4294198530 hasConceptScore W4294198530C86803240 @default.
- W4294198530 hasLocation W42941985301 @default.
- W4294198530 hasOpenAccess W4294198530 @default.
- W4294198530 hasPrimaryLocation W42941985301 @default.
- W4294198530 hasRelatedWork W117948112 @default.
- W4294198530 hasRelatedWork W1525689148 @default.
- W4294198530 hasRelatedWork W1706668261 @default.
- W4294198530 hasRelatedWork W2078868204 @default.
- W4294198530 hasRelatedWork W2108235800 @default.
- W4294198530 hasRelatedWork W2149686398 @default.
- W4294198530 hasRelatedWork W2368759418 @default.
- W4294198530 hasRelatedWork W2390710607 @default.
- W4294198530 hasRelatedWork W2785391232 @default.
- W4294198530 hasRelatedWork W2982280075 @default.
- W4294198530 isParatext "false" @default.
- W4294198530 isRetracted "false" @default.
- W4294198530 workType "article" @default.