维普中文期刊产品整合服务
224篇 您的检索式:期刊名="Cybersecurity"
    题名 作者 年代 出处 被引量
1Survey of intrusion detection systems:techniques,datasets and challenges显示文摘Cyber-attacks are becoming more sophisticated and thereby presenting increasing challenges in accurately detecting intrusions.Failure to prevent the intrusions could degrade the credibility of security services,e.g.data confidentiality,integrity,and availability.Numerous intrusion detection methods have been proposed in the literature to tackle computer security threats,which can be broadly classified into Signature-based Intrusion Detection Systems(SIDS)and Anomaly-based Intrusion Detection Systems(AIDS).This survey paper presents a taxonomy of contemporary IDS,a comprehensive review of notable recent works,and an overview of the datasets commonly used for evaluation purposes.It also presents evasion techniques used by attackers to avoid detection and discusses future research challenges to counter such techniques so as to make computer systems more secure.Ansam Khraisat Iqbal Gondal Peter Vamplew Joarder Kamruzzaman 2019Cybersecurity2019,2,1:13
2The privacy protection mechanism of Hyperledger Fabric and its application in supply chain finance显示文摘Blockchain technology ensures that data is tamper-proof,traceable,and trustworthy.This article introduces a wellknown blockchain technology implementation—Hyperledger Fabric.The basic framework and privacy protection mechanisms of Hyperledger Fabric such as certificate authority,channel,Private Data Collection,etc.are described.As an example,a specific business scenario of supply chain finance is figured out.And accordingly,some design details about how to apply these privacy protection mechanisms are described.Chaoqun Ma Xiaolin Kong Qiujun Lan Zhongding Zhou 2019Cybersecurity2019,2,1:6
3Fuzzing:a survey显示文摘Security vulnerability is one of the root causes of cyber-security threats.To discover vulnerabilities and fix them in advance,researchers have proposed several techniques,among which fuzzing is the most widely used one.In recent years,fuzzing solutions,like AFL,have made great improvements in vulnerability discovery.This paper presents a summary of the recent advances,analyzes how they improve the fuzzing process,and sheds light on future work in fuzzing.Firstly,we discuss the reason why fuzzing is popular,by comparing different commonly used vulnerability discovery techniques.Then we present an overview of fuzzing solutions,and discuss in detail one of the most popular type of fuzzing,i.e.,coverage-based fuzzing.Then we present other techniques that could make fuzzing process smarter and more efficient.Finally,we show some applications of fuzzing,and discuss new trends of fuzzing and potential future directions.Jun Li Bodong Zhao Chao Zhang 2018Cybersecurity2018,1,1:5
4Social engineering in cybersecurity:a domain ontology and knowledge graph application examples显示文摘Social engineering has posed a serious threat to cyberspace security.To protect against social engineering attacks,a fundamental work is to know what constitutes social engineering.This paper first develops a domain ontology of social engineering in cybersecurity and conducts ontology evaluation by its knowledge graph application.The domain ontology defines 11 concepts of core entities that significantly constitute or affect social engineering domain,together with 22 kinds of relations describing how these entities related to each other.It provides a formal and explicit knowledge schema to understand,analyze,reuse and share domain knowledge of social engineering.Furthermore,this paper builds a knowledge graph based on 15 social engineering attack incidents and scenarios.7 knowledge graph application examples(in 6 analysis patterns)demonstrate that the ontology together with knowledge graph is useful to 1)understand and analyze social engineering attack scenario and incident,2)find the top ranked social engineering threat elements(e.g.the most exploited human vulnerabilities and most used attack mediums),3)find potential social engineering threats to victims,4)find potential targets for social engineering attackers,5)find potential attack paths from specific attacker to specific target,and 6)analyze the same origin attacks.Zuoguang Wang Hongsong Zhu Peipei Liu Limin Sun 2021Cybersecurity2021,4,1:4
5Data and knowledge-driven named entity recognition for cyber security显示文摘Named Entity Recognition(NER)for cyber security aims to identify and classify cyber security terms from a large number of heterogeneous multisource cyber security texts.In the field of machine learning,deep neural networks automatically learn text features from a large number of datasets,but this data-driven method usually lacks the ability to deal with rare entities.Gasmi et al.proposed a deep learning method for named entity recognition in the field of cyber security,and achieved good results,reaching an F1 value of 82.8%.But it is difficult to accurately identify rare entities and complex words in the text.To cope with this challenge,this paper proposes a new model that combines data-driven deep learning methods with knowledge-driven dictionary methods to build dictionary features to assist in rare entity recognition.In addition,based on the data-driven deep learning model,an attentionmechanism is adopted to enrich the local features of the text,better models the context,and improves the recognition effect of complex entities.Experimental results show that our method is better than the baseline model.Our model is more effective in identifying cyber security entities.The Precision,Recall and F1 value reached 90.19%,86.60%and 88.36%respectively.Chen Gao Xuan Zhang Hui Liu 2021Cybersecurity2021,4,1:4
6An emerging threat Fileless malware:a survey and research challenges显示文摘With the evolution of cybersecurity countermeasures,the threat landscape has also evolved,especially in malware from traditional file-based malware to sophisticated and multifarious fileless malware.Fileless malware does not use traditional executables to carry-out its activities.So,it does not use the file system,thereby evading signature-based detection system.The fileless malware attack is catastrophic for any enterprise because of its persistence,and power to evade any anti-virus solutions.The malware leverages the power of operating systems,trusted tools to accomplish its malicious intent.To analyze such malware,security professionals use forensic tools to trace the attacker,whereas the attacker might use anti-forensics tools to erase their traces.This survey makes a comprehensive analysis of fileless malware and their detection techniques that are available in the literature.We present a process model to handle fileless malware attacks in the incident response process.In the end,the specific research gaps present in the proposed process model are identified,and associated challenges are highlighted.Sudhakar Sushil Kumar 2020Cybersecurity2020,3,1:4
7A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network显示文摘Command and control(C2)servers are used by attackers to operate communications.To perform attacks,attackers usually employee the Domain Generation Algorithm(DGA),with which to confirm rendezvous points to their C2 servers by generating various network locations.The detection of DGA domain names is one of the important technologies for command and control communication detection.Considering the randomness of the DGA domain names,recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names.However,these methods are insufficient to handle wordlist-based DGA threats,which generate domain names by randomly concatenating dictionary words according to a special set of rules.In this paper,we proposed a a deep learning framework ATT-CNN-BiLSTMfor identifying and detecting DGA domains to alleviate the threat.Firstly,the Convolutional Neural Network(CNN)and bidirectional Long Short-Term Memory(BiLSTM)neural network layer was used to extract the features of the domain sequences information;secondly,the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names.Finally,the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification.Our extensive experimental results demonstrate the effectiveness of the proposed model,both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones.To be precise,we got a F1 score of 98.79%for the detection and macro average precision and recall of 83%for the classification task of DGA domain names.Fangli Ren Zhengwei Jiang Xuren Wang Jian Liu 2020Cybersecurity2020,3,1:4
8LSTM RNN:detecting exploit kits using redirection chain sequences显示文摘While consumers use the web to perform routine activities,they are under the constant threat of attack from malicious websites.Even when visiting‘trusted’sites,there is always a risk that site is compromised,and,hosting a malicious script.In this scenario,the injected script would typically force the victim’s browser to undergo a series of redirects before reaching an attacker-controlled domain,which,delivers the actual malware.Although these malicious redirection chains aim to frustrate detection and analysis efforts,they could be used to help identify web-based attacks.Building upon previous work,this paper presents the first known application of a Long Short-Term Memory(LSTM)network to detect Exploit Kit(EK)traffic,utilising the structure of HTTP redirects.Samples are processed as sequences,where each timestep represents a redirect and contains a unique combination of 48 features.The experiment is conducted using a ground-truth dataset of 1279 EK and 5910 benign redirection chains.Hyper-parameters are tuned via K-fold cross-validation(5f-CV),with the optimal configuration achieving an F1 score of 0.9878 against the unseen test set.Furthermore,we compare the results of isolated feature categories to assess their importance.Jonah Burgess Philip O’Kane Sakir Sezer Domhnall Carlin 2021Cybersecurity2021,4,1:4
9Server-aided immediate and robust user revocation mechanism for SM9显示文摘As the only approved Identity-Based Encryption scheme in China that is also standardized by ISO,SM9-IBE has been widely adopted in many real-world applications.However,similar to other IBE standard algorithms,SM9-IBE currently lacks revocation mechanism,which is vital for a real system.Worse still,we find that existing revocable techniques may not be suitable and efficient when applying to SM9-IBE.Given the widespread use of SM9-IBE,an efficient and robust user revocation mechanism becomes an urgent issue.In this work,we propose a dedicated server-aided revocation mechanism,which for the first time achieves the secure,immediate and robust user revocation for SM9-IBE.Provided with a compact system model,the proposed method leverages an existing server to perform all heavy workloads during user revocation,thus leaving no communication and computation costs for the key generation center and users.Moreover,the mechanism supports key-exposure resistance,meaning the user revocation mechanism is robust even if the revocation key leaks.We then formally define and prove the security.At last,we present theoretical comparisons and an implementation in terms of computational latency and throughput.The results indicate the efficiency and practicability of the proposed mechanism.Shuzhou Sun Hui Ma Rui Zhang Wenhan Xu 2020Cybersecurity2020,3,1:4
10Sensitive system calls based packed malware variants detection using principal component initialized MultiLayers neural networks显示文摘Malware detection has become mission sensitive as its threats spread from computer systems to Internet of things systems.Modern malware variants are generally equipped with sophisticated packers,which allow them bypass modern machine learning based detection systems.To detect packed malware variants,unpacking techniques and dynamic malware analysis are the two choices.However,unpacking techniques cannot always be useful since there exist some packers such as private packers which are hard to unpack.Although dynamic malware analysis can obtain the running behaviours of executables,the unpacking behaviours of packers add noisy information to the real behaviours of executables,which has a bad affect on accuracy.To overcome these challenges,in this paper,we propose a new method which first extracts a series of system calls which is sensitive to malicious behaviours,then use principal component analysis to extract features of these sensitive system calls,and finally adopt multi-layers neural networks to classify the features of malware variants and legitimate ones.Theoretical analysis and real-life experimental results show that our packed malware variants detection technique is comparable with the the state-of-art methods in terms of accuracy.Our approach can achieve more than 95.6\%of detection accuracy and 0.048 s of classification time cost.Jixin Zhang Kehuan Zhang Zheng Qin Hui Yin Qixin Wu 2018Cybersecurity2018,1,1:3
11Automated extraction of attributes from natural language attribute-based access control(ABAC)Policies显示文摘The National Institute of Standards and Technology(NIST)has identified natural language policies as the preferred expression of policy and implicitly called for an automated translation of ABAC natural language access control policy(NLACP)to a machine-readable form.To study the automation process,we consider the hierarchical ABAC model as our reference model since it better reflects the requirements of real-world organizations.Therefore,this paper focuses on the questions of:how can we automatically infer the hierarchical structure of an ABAC model given NLACPs;and,how can we extract and define the set of authorization attributes based on the resulting structure.To address these questions,we propose an approach built upon recent advancements in natural language processing and machine learning techniques.For such a solution,the lack of appropriate data often poses a bottleneck.Therefore,we decouple the primary contributions of this work into:(1)developing a practical framework to extract authorization attributes of hierarchical ABAC system from natural language artifacts,and(2)generating a set of realistic synthetic natural language access control policies(NLACPs)to evaluate the proposed framework.Our experimental results are promising as we achieved-in average-an F1-score of 0.96 when extracting attributes values of subjects,and 0.91 when extracting the values of objects’attributes from natural language access control policies.Manar Alohaly Hassan Takabi Eduardo Blanco 2019Cybersecurity2019,2,1:3
12Graph-based visual analytics for cyber threat intelligence显示文摘The ever-increasing amount of major security incidents has led to an emerging interest in cooperative approaches to encounter cyber threats.To enable cooperation in detecting and preventing attacks it is an inevitable necessity to have structured and standardized formats to describe an incident.Corresponding formats are complex and of an extensive nature as they are often designed for automated processing and exchange.These characteristics hamper the readability and,therefore,prevent humans from understanding the documented incident.This is a major problem since the success and effectiveness of any security measure rely heavily on the contribution of security experts.To meet these shortcomings we propose a visual analytics concept enabling security experts to analyze and enrich semi-structured cyber threat intelligence information.Our approach combines an innovative way of persisting this data with an interactive visualization component to analyze and edit the threat information.We demonstrate the feasibility of our concept using the Structured Threat Information eXpression,the state-ofthe-art format for reporting cyber security issues.Fabian Bohm Florian Menges Gunther Pernul 2018Cybersecurity2018,1,1:2
13Performance analysis of machine learning models for intrusion detection system using Gini Impurity-based Weighted Random Forest (GIWRF) feature selection technique显示文摘To protect the network, resources, and sensitive data, the intrusion detection system (IDS) has become a fundamental component of organizations that prevents cybercriminal activities. Several approaches have been introduced and implemented to thwart malicious activities so far. Due to the effectiveness of machine learning (ML) methods, the proposed approach applied several ML models for the intrusion detection system. In order to evaluate the performance of models, UNSW-NB 15 and Network TON_IoT datasets were used for offline analysis. Both datasets are comparatively newer than the NSL-KDD dataset to represent modern-day attacks. However, the performance analysis was carried out by training and testing the Decision Tree (DT), Gradient Boosting Tree (GBT), Multilayer Perceptron (MLP), AdaBoost, Long-Short Term Memory (LSTM), and Gated Recurrent Unit (GRU) for the binary classification task. As the performance of IDS deteriorates with a high dimensional feature vector, an optimum set of features was selected through a Gini Impurity-based Weighted Random Forest (GIWRF) model as the embedded feature selection technique. This technique employed Gini impurity as the splitting criterion of trees and adjusted the weights for two different classes of the imbalanced data to make the learning algorithm understand the class distribution. Based upon the importance score, 20 features were selected from UNSW-NB 15 and 10 features from the Network TON_IoT dataset. The experimental result revealed that DT performed well with the feature selection technique than other trained models of this experiment. Moreover, the proposed GIWRF-DT outperformed other existing methods surveyed in the literature in terms of the F1 score.Raisa Abedin Disha Sajjad Waheed 2022Cybersecurity2022,5,2:2
14A PLS blockchain for IoT applications:protocols and architecture显示文摘This paper proposes an architecture and a protocol suite for a permissioned blockchain for a local IoT network.The architecture is based on a sealed Sequencer and a Fog Server running(post-quantum)Guy Fawkes protocols.The blocks of the blockchain are stored in networked Content Addressable Storage alongside any user data and validity proofs.We maintain that a typical IoT device can,despite its resource limitations,use our blockchain protocols directly,without a trusted intermediary.This includes posting and monitoring transactions as well as off-chain(post-quantum)emergency communications without an explicit public key.Alex Shafarenko 2021Cybersecurity2021,4,1:2
15A critical review of intrusion detection systems in the internet of things:techniques,deployment strategy,validation strategy,attacks,public datasets and challenges显示文摘The Internet of Things(IoT)has been rapidly evolving towards making a greater impact on everyday life to large industrial systems.Unfortunately,this has attracted the attention of cybercriminals who made IoT a target of malicious activities,opening the door to a possible attack on the end nodes.To this end,Numerous IoT intrusion detection Systems(IDS)have been proposed in the literature to tackle attacks on the IoT ecosystem,which can be broadly classified based on detection technique,validation strategy,and deployment strategy.This survey paper presents a comprehensive review of contemporary IoT IDS and an overview of techniques,deployment Strategy,validation strategy and datasets that are commonly applied for building IDS.We also review how existing IoT IDS detect intrusive attacks and secure communications on the IoT.It also presents the classification of IoT attacks and discusses future research challenges to counter such IoT attacks to make IoT more secure.These purposes help IoT security researchers by uniting,contrasting,and compiling scattered research efforts.Consequently,we provide a unique IoT IDS taxonomy,which sheds light on IoT IDS techniques,their advantages and disadvantages,IoT attacks that exploit IoT communication systems,corresponding advanced IDS and detection capabilities to detect IoT attacks.Ansam Khraisat Ammar Alazab 2021Cybersecurity2021,4,1:2
16Feedback control can make data structure layout randomization more cost-effective under zero-day attacks显示文摘In the wake of the research community gaining deep understanding about control-hijacking attacks,data-oriented attacks have emerged.Among data-oriented attacks,data structure manipulation attack(DSMA)is a major category.Pioneering research was conducted and shows that DSMA is able to circumvent the most effective defenses against control-hijacking attacks-DEP,ASLR and CFI.Up to this day,only two defense techniques have demonstrated their effectiveness:Data Flow Integrity(DFI)and Data Structure Layout Randomization(DSLR).However,DFI has high performance overhead,and dynamic DSLR has two main limitations.L-1:Randomizing a large set of data structures will significantly affect the performance.L-2:To be practical,only a fixed sub-set of data structures are randomized.In the case that the data structures targeted by an attack are not covered,dynamic DSLR is essentially noneffective.To address these two limitations,we propose a novel technique,feedback-control-based adaptive DSLR and build a system named SALADSPlus.SALADSPlus seeks to optimize the trade-off between security and cost through feedback control.Using a novel feedback-control-based adaptive algorithm extended from the Upper Confidence Bound(UCB)algorithm,the defender(controller)uses the feedbacks(cost-effectiveness)from previous randomization cycles to adaptively choose the set of data structures to randomize(the next action).Different from dynamic DSLR,the set of randomized data structures are adaptively changed based on the feedbacks.To obtain the feedbacks,SALADSPlus inserts canary in each data structure at the time of compilation.We have implemented SALADSPlus based on gcc-4.5.0.Experimental results show that the runtime overheads are 1.8%,3.7%,and 5.3% when the randomization cycles are selected as 10s,5s,and 1s respectively.Ping Chen Zhisheng Hu Jun Xu Minghui Zhu Peng Liu 2018Cybersecurity2018,1,1:2
17Machine learning for intrusion detection in industrial control systems:challenges and lessons from experimental evaluation显示文摘Gradual increase in the number of successful attacks against Industrial Control Systems(ICS)has led to an urgent need to create defense mechanisms for accurate and timely detection of the resulting process anomalies.Towards this end,a class of anomaly detectors,created using data-centric approaches,are gaining attention.Using machine learning algorithms such approaches can automatically learn the process dynamics and control strategies deployed in an ICS.The use of these approaches leads to relatively easier and faster creation of anomaly detectors compared to the use of design-centric approaches that are based on plant physics and design.Despite the advantages,there exist significant challenges and implementation issues in the creation and deployment of detectors generated using machine learning for city-scale plants.In this work,we enumerate and discuss such challenges.Also presented is a series of lessons learned in our attempt to meet these challenges in an operational plant.Gauthama Raman M.R. Chuadhry Mujeeb Ahmed Aditya Mathur 2021Cybersecurity2021,4,1:2
18ICPFuzzer:proprietary communication protocol fuzzing by using machine learning and feedback strategies显示文摘The fuzzing test is able to discover various vulnerabilities and has more chances to hit the zero-day targets.And ICS(Industrial control system)is currently facing huge security threats and requires security standards,like ISO 62443,to ensure the quality of the device.However,some industrial proprietary communication protocols can be customized and have complicated structures,the fuzzing system cannot quickly generate test data that adapt to various protocols.It also struggles to define the mutation field without having prior knowledge of the protocols.Therefore,we propose a fuzzing system named ICPFuzzer that uses LSTM(Long short-term memory)to learn the features of a protocol and generates mutated test data automatically.We also use the responses of testing and adjust the weight strategies to further test the device under testing(DUT)to find more data that cause unusual connection status.We verified the effectiveness of the approach by comparing with the open-source and commercial fuzzers.Furthermore,in a real case,we experimented with the DLMS/COSEM for a smart meter and found that the test data can cause a unusual response.In summary,ICPFuzzer is a black-box fuzzing system that can automatically execute the testing process and reveal vulnerabilities that interrupt and crash industrial control communication.Not only improves the quality of ICS but also improves safety.Pei-Yi Lin Chia-Wei Tien Ting-Chun Huang Chin-Wei Tien 2021Cybersecurity2021,4,1:2
19ASSERT:attack synthesis and separation with entropy redistribution towards predictive cyber defense显示文摘The sophistication of cyberattacks penetrating into enterprise networks has called for predictive defense beyond intrusion detection,where different attack strategies can be analyzed and used to anticipate next malicious actions,especially the unusual ones.Unfortunately,traditional predictive analytics or machine learning techniques that require training data of known attack strategies are not practical,given the scarcity of representative data and the evolving nature of cyberattacks.This paper describes the design and evaluation of a novel automated system,ASSERT,which continuously synthesizes and separates cyberattack behavior models to enable better prediction of future actions.It takes streaming malicious event evidences as inputs,abstracts them to edge-based behavior aggregates,and associates the edges to attack models,where each represents a unique and collective attack behavior.It follows a dynamic Bayesian-based model generation approach to determine when a new attack behavior is present,and creates new attack models by maximizing a cluster validity index.ASSERT generates empirical attack models by separating evidences and use the generated models to predict unseen future incidents.It continuously evaluates the quality of the model separation and triggers a re-clustering process when needed.Through the use of 2017 National Collegiate Penetration Testing Competition data,this work demonstrates the effectiveness of ASSERT in terms of the quality of the generated empirical models and the predictability of future actions using the models.Ahmet Okutan Shanchieh Jay Yang 2019Cybersecurity2019,2,1:2
20A framework for the extended evaluation of ABAC policies显示文摘A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,making ABAC policies vulnerable to attribute-hiding attacks.Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation,where the evaluation of a query considers all queries that can be obtained by extending the initial query.This method counters attribute-hiding attacks,but a na飗e implementation is intractable,as it requires an evaluation of the whole query space.In this paper,we present a framework for the extended evaluation of ABAC policies.The framework relies on Binary Decision Diagram(BDDs)data structures for the efficient computation of the extended evaluation of ABAC policies.We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation,respectively.We illustrate our framework using three real-world policies,which would be intractable with the original method but which are analyzed in seconds using our framework.Charles Morisset Tim A.C.Willemse Nicola Zannone 2019Cybersecurity2019,2,1:1
返回顶部 每页显示:
共12页 首页 上一页 第1页 下一页 末页 /12 跳转

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费