中文
相关论文

相关论文: A Large-Scale Analysis of Attacker Activity in Com…

200 篇论文

Cyber-attacks are increasing and varying dramatically day by day. It has become challenging to control cyber-attacks and to identify the perpetrators and their intentions. In general, the analysis of the intentions of cyber-attacks is one…

密码学与安全 · 计算机科学 2021-01-06 Mohammad Rasmi Al-Mousa

We present an empirical and large-scale analysis of malware samples captured from two different enterprises from 2017 to early 2018. Particularly, we perform threat vector, social-engineering, vulnerability and time-series analysis on our…

密码学与安全 · 计算机科学 2019-10-02 Abbas Acar , Long Lu , A. Selcuk Uluagac , Engin Kirda

Phishing attacks are one of the most common social engineering attacks targeting users emails to fraudulently steal confidential and sensitive information. They can be used as a part of more massive attacks launched to gain a foothold in…

密码学与安全 · 计算机科学 2022-01-27 Fatima Salahdine , Zakaria El Mrabet , Naima Kaabouch

Recent high-profile cyber attacks exemplify why organizations need better cyber defenses. Cyber threats are hard to accurately predict because attackers usually try to mask their traces. However, they often discuss exploits and techniques…

计算与语言 · 计算机科学 2019-02-05 Ashok Deb , Kristina Lerman , Emilio Ferrara

Malware affects millions of users worldwide, impacting the daily lives of many people as well as businesses. Malware infections are increasing in complexity and unfold over a number of stages. A malicious downloader often acts as the…

密码学与安全 · 计算机科学 2022-08-30 François Labrèche , Enrico Mariconti , Gianluca Stringhini

As item trading becomes more popular, users can change their game items or money into real money more easily. At the same time, hackers turn their eyes on stealing other users game items or money because it is much easier to earn money than…

密码学与安全 · 计算机科学 2017-05-02 Hana Kim , Seongil Yang , Huy Kang Kim

Enterprise Networks are growing in scale and complexity, with heterogeneous connected assets needing to be secured in different ways. Nevertheless, virtually all connected assets use the Domain Name System (DNS) for address resolution, and…

密码学与安全 · 计算机科学 2022-05-19 Jawad Ahmed

Recommender system has attracted much attention during the past decade. Many attack detection algorithms have been developed for better recommendations, mostly focusing on shilling attacks, where an attack organizer produces a large number…

信息检索 · 计算机科学 2020-07-07 Ming Pang , Wei Gao , Min Tao , Zhi-Hua Zhou

The detection of BGP prefix hijacking attacks has been the focus of research for more than a decade. However, state-of-the-art techniques fall short of detecting more elaborate types of attack. To study such attacks, we devise a novel…

网络与互联网体系结构 · 计算机科学 2016-07-04 Johann Schlamp , Ralph Holz , Quentin Jacquemart , Georg Carle , Ernst W. Biersack

In successful enterprise attacks, adversaries often need to gain access to additional machines beyond their initial point of compromise, a set of internal movements known as lateral movement. We present Hopper, a system for detecting…

密码学与安全 · 计算机科学 2021-05-31 Grant Ho , Mayank Dhiman , Devdatta Akhawe , Vern Paxson , Stefan Savage , Geoffrey M. Voelker , David Wagner

In order to understand the overall picture of cyber attacks and to identify the source of cyber attacks, a method to identify malicious activities by automatically creating a graph that ties together the dependencies of a series of related…

密码学与安全 · 计算机科学 2025-03-26 Taishin Saito

This paper presents a practical side-channel attack that identifies the social web service account of a visitor to an attacker's website. Our attack leverages the widely adopted user-blocking mechanism, abusing its inherent property that…

密码学与安全 · 计算机科学 2018-05-15 Takuya Watanabe , Eitaro Shioji , Mitsuaki Akiyama , Keito Sasaoka , Takeshi Yagi , Tatsuya Mori

Many cyberattacks succeed because they exploit flaws at the human level. To address this problem, organizations rely on security awareness programs, which aim to make employees more resilient against social engineering. While some works…

密码学与安全 · 计算机科学 2025-12-01 Matthias Pfister , Giovanni Apruzzese , Irdin Pekaric

The decentralization, redundancy, and pseudo-anonymity features have made permission-less public blockchain platforms attractive for adoption as technology platforms for cryptocurrencies. However, such adoption has enabled cybercriminals to…

密码学与安全 · 计算机科学 2021-08-27 Banwari Lal , Rachit Agarwal , Sandeep Kumar Shukla

Honeypots are a well-studied defensive measure in network security. This work proposes an effective low-cost honeypot that is easy to deploy and maintain. The honeypot introduced in this work is able to handle commands in a non-standard way…

密码学与安全 · 计算机科学 2021-01-07 Daniel Schneider , Daniel Fraunholz , Daniel Krohmer

Offensive security-tests are a common way to pro-actively discover potential vulnerabilities. They are performed by specialists, often called penetration-testers or white-hat hackers. The chronic lack of available white-hat hackers prevents…

软件工程 · 计算机科学 2023-08-24 Andreas Happe , Jürgen Cito

Adversarial lateral movement via compromised accounts remains difficult to discover via traditional rule-based defenses because it generally lacks explicit indicators of compromise. We propose a behavior-based, unsupervised framework…

密码学与安全 · 计算机科学 2021-08-06 Brian A. Powell

The rapid detection of attackers within firewalls of enterprise computer net- works is of paramount importance. Anomaly detectors address this problem by quantifying deviations from baseline statistical models of normal network behav- ior…

密码学与安全 · 计算机科学 2016-09-02 Justin Grana , David Wolpert , Joshua Neil , Dongping Xie , Tanmoy Bhattacharya , Russel Bent

Cybercrimes such as online scams and fraud have become prevalent. Cybercriminals often abuse various global or regional events as themes of their fraudulent activities to breach user trust and attain a higher attack success rate. These…

密码学与安全 · 计算机科学 2025-10-01 Maraz Mia , Mir Mehedi A. Pritom , Tariqul Islam , Shouhuai Xu

Before executing an attack, adversaries usually explore the victim's network in an attempt to infer the network topology and identify vulnerabilities in the victim's servers and personal computers. Falsifying the information collected by…

密码学与安全 · 计算机科学 2019-03-08 Rami Puzis , Hadar Polad , Bracha Shapira