{"id":1049,"date":"2015-10-15T13:37:07","date_gmt":"2015-10-15T17:37:07","guid":{"rendered":"http:\/\/wordpress.cs.vt.edu\/csblog\/?p=1049"},"modified":"2015-10-06T09:35:23","modified_gmt":"2015-10-06T13:35:23","slug":"new-research-method-identifies-stealth-attacks-on-complicated-computer-systems","status":"publish","type":"post","link":"https:\/\/wordpress.cs.vt.edu\/csblog\/2015\/10\/15\/new-research-method-identifies-stealth-attacks-on-complicated-computer-systems\/","title":{"rendered":"New research method identifies stealth attacks on complicated computer systems"},"content":{"rendered":"<p><strong>New research method identifies stealth attacks on complicated computer systems<\/strong><\/p>\n<p>Blacksburg, Virginia, October XX, 2015 \u00ad \u2013 Imagine millions of lines of instructions. Then try and picture how one extremely tiny anomaly could be found in almost real-time and prevent a cyber security attack.<\/p>\n<p>Called a \u201cprogram anomaly detection approach,\u201d a trio of Virginia Tech computer scientists have tested their innovation against many real-world attacks. One type of attack is when an adversary is able to remotely access a computer bypassing authentication such as a login screen. A second example of attack is called heap feng shui where attackers hijack the control of a browser by manipulating its memory layout. Another example of attack is called directory harvesting where spammers interact with vulnerable mail servers to steal valid email addresses. The prototype developed by the Virginia Tech scientists proved to be effective and reliable at these types of attacks with a less than 0.01 percent false positive rate.<\/p>\n<p>Their findings are reported today in an invited presentation at the\u00a022nd Association of Computing Machinery (ACM) Conference on Computer and Communications Security, Denver, CO, Oct 12-16, 2015. <a href=\"http:\/\/www.sigsac.org\/ccs\/CCS2015\/\">http:\/\/www.sigsac.org\/ccs\/CCS2015\/<\/a><\/p>\n<p>\u201cOur work, in collaboration with Naren Ramakrishnan, <a href=\"http:\/\/www.cs.vt.edu\/user\/ramakrishnan\">http:\/\/www.cs.vt.edu\/user\/ramakrishnan<\/a> is titled, &#8220;Unearthing Stealthy Program Attacks Buried in Extremely Long Execution Paths,&#8221; said Danfeng (Daphne) Yao, <a href=\"http:\/\/www.cs.vt.edu\/user\/yao\">http:\/\/www.cs.vt.edu\/user\/yao<\/a> associate professor of computer science at Virginia Tech. Xiaokui Shu, a computer science doctoral student of Anqing, China, advised by Yao, was the first author.<\/p>\n<p>\u201cStealthy attacks buried in long execution paths of a software program cannot be revealed by examining fragments of the path,\u201d Yao, who holds the title of the L-3 Communications Cyber Faculty Fellow of Computer Science, said.<\/p>\n<p>Yao explained, \u201cModern exploits have manipulation tactics that hide them from existing detection tools. An example is an attacker who overwrites one of the variables before the actual authentication procedure. As a result, the attacker bypasses critical security control and logs in without authentication.\u201d<\/p>\n<p>Over time, these stealthy attacks on computer systems have just become more and more sophisticated.<\/p>\n<p>The Virginia Tech computer scientists\u2019 secret formula in finding a stealth attack is in their algorithms. With specific matrix-based pattern recognition, the three were able to analyze the execution path of a software program and discover correlations among events. \u201cThe idea is to profile the program\u2019s behavior, determine how often some events are supposed to occur, and with which other events, and use this information to detect anomalous activity\u201d said Ramakrishnan.<\/p>\n<p>\u201cBecause the approach works by analyzing the behavior of computer code, it can be used to study a variety of different attacks\u201d added Yao. Their anomaly detection algorithms were able to detect erratic program behaviors with very low false alarms even when there are complex and diverse execution patterns.<\/p>\n<p><a href=\"http:\/\/people.cs.vt.edu\/~danfeng\/\">Yao<\/a> and <a href=\"http:\/\/people.cs.vt.edu\/~ramakris\/\">Ramakrishnan<\/a> have lengthy portfolios in the study of malicious software and data mining.<\/p>\n<p>In 2014, Yao received a U.S. Army Research Office Young Investigator award to detect anomalies that are caused by system compromises and malicious insiders. This award allowed her to design big data algorithms that focused on discovering logical relations among human activities. In 2010 she won a National Science Foundation CAREER award to develop software that differentiated human-user computer interaction from that of malware, commonly known as malicious software.<\/p>\n<p>Ramakrishnan, who holds the Thomas L. Phillips Professorship of Engineering, directs Virginia Tech\u2019s Discovery Analytics Center <a href=\"http:\/\/dac.cs.vt.edu\/\">http:\/\/dac.cs.vt.edu<\/a>, supported by the Institute for Critical Technology and Applied Science <a href=\"http:\/\/www.ictas.vt.edu\">http:\/\/www.ictas.vt.edu<\/a> . A Distinguished Scientist of the ACM, Ramakrishnan has concentrated his research on data mining, the science of processing massive quantities of data to discover patterns and to produce new insights.<\/p>\n<p>The Office of Naval Research and the Army Research Office supported this new work.<\/p>\n<p>##<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_129\" class=\"thumbnail wp-caption alignnone\" style=\"width: 124px\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-129\" src=\"http:\/\/wordpress.cs.vt.edu\/csblog\/wp-content\/uploads\/sites\/6\/2014\/10\/image115.jpg\" alt=\"Dr. Yao\" width=\"114\" height=\"150\" \/><figcaption class=\"caption wp-caption-text\">Dr. Yao<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_93\" class=\"thumbnail wp-caption alignnone\" style=\"width: 135px\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-93\" src=\"http:\/\/wordpress.cs.vt.edu\/csblog\/wp-content\/uploads\/sites\/6\/2014\/10\/image16.jpg\" alt=\"Dr. Ramakrishnan\" width=\"125\" height=\"179\" \/><figcaption class=\"caption wp-caption-text\">Dr. Ramakrishnan<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>New research method identifies stealth attacks on complicated computer systems Blacksburg, Virginia, October XX, 2015 \u00ad \u2013 Imagine millions of lines of instructions. Then try and picture how one extremely tiny anomaly could be found in almost real-time and prevent a cyber security attack. Called a \u201cprogram anomaly detection approach,\u201d a trio of Virginia Tech [&hellip;]<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,1],"tags":[],"class_list":["post-1049","post","type-post","status-publish","format-standard","hentry","category-faculty","category-news"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/posts\/1049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/comments?post=1049"}],"version-history":[{"count":5,"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/posts\/1049\/revisions"}],"predecessor-version":[{"id":1070,"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/posts\/1049\/revisions\/1070"}],"wp:attachment":[{"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/media?parent=1049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/categories?post=1049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.cs.vt.edu\/csblog\/wp-json\/wp\/v2\/tags?post=1049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}