中文
相关论文

相关论文: A Large-Scale Analysis of Attacker Activity in Com…

200 篇论文

Problem: We address the challenge in responsible computing where an exploitable mobile app is misused by one app user (an abuser) against another user or bystander (victim). We introduce the idea of a misuse audit of apps as a way of…

密码学与安全 · 计算机科学 2024-11-11 Vaibhav Garg , Hui Guo , Nirav Ajmeri , Saikath Bhattacharya , Munindar P. Singh

Advanced attack campaigns span across multiple stages and stay stealthy for long time periods. There is a growing trend of attackers using off-the-shelf tools and pre-installed system applications (such as \emph{powershell} and \emph{wmic})…

密码学与安全 · 计算机科学 2019-05-21 Aditya Kuppa , Slawomir Grzonkowski , Muhammad Rizwan Asghar , Nhien-An Le-Khac

Cloud-based documents are inherently valuable, due to the volume and nature of sensitive personal and business content stored in them. Despite the importance of such documents to Internet users, there are still large gaps in the…

密码学与安全 · 计算机科学 2016-07-05 Martin Lazarov , Jeremiah Onaolapo , Gianluca Stringhini

Machine learning models were shown to be vulnerable to model stealing attacks, which lead to intellectual property infringement. Among other methods, substitute model training is an all-encompassing attack applicable to any machine learning…

机器学习 · 计算机科学 2025-03-11 Daryna Oliynyk , Rudolf Mayer , Andreas Rauber

Malware writers frequently try to hide the activities of their agents within tunnelled traffic. Within the Kill Chain model the infection time is often measured in seconds, and if the infection is not detected and blocked, the malware…

密码学与安全 · 计算机科学 2019-07-30 Peter McLaren , William J Buchanan , Gordon Russell , Zhiyuan Tan

In this work we analyse five popular commercial password managers for security vulnerabilities. Our analysis is twofold. First, we compile a list of previously disclosed vulnerabilities through a comprehensive review of the academic and…

密码学与安全 · 计算机科学 2020-03-18 Michael Carr , Siamak F. Shahandashti

Adversarial attacks present a significant threat to modern machine learning systems. Yet, existing detection methods often lack the ability to detect unseen attacks or detect different attack types with a high level of accuracy. In this…

密码学与安全 · 计算机科学 2025-10-06 Chinthana Wimalasuriya , Spyros Tragoudas

Phishing continues to pose a significant cybersecurity threat. While blocklists currently serve as a primary defense, due to their reactive, passive nature, these delayed responses leave phishing websites operational long enough to harm…

密码学与安全 · 计算机科学 2025-04-18 Kyungchan Lim , Raffaele Sommese , Mattis Jonker , Ricky Mok , kc claffy , Doowon Kim

Cyber-security analysts face an increasingly large number of alerts received on any given day. This is mainly due to the low precision of many existing methods to detect threats, producing a substantial number of false positives. Usually,…

密码学与安全 · 计算机科学 2022-09-28 Iwona Hawryluk , Henrique Hoeltgebaum , Cole Sodja , Tyler Lalicker , Joshua Neil

This paper identifies and analyzes a novel vulnerability class in Model Context Protocol (MCP) based agent systems. The attack chain describes and demonstrates how benign, individually authorized tasks can be orchestrated to produce harmful…

密码学与安全 · 计算机科学 2025-08-28 David Noever

In this digital era, our lives highly depend on the internet and worldwide technology. Wide usage of technology and platforms of communication makes our lives better and easier. But on the other side it carries out some security issues and…

密码学与安全 · 计算机科学 2024-04-18 Muhammad Shoaib Farooq , Hina jabbar

Ransomware is considered as a significant threat for most enterprises since the past few years. In scenarios wherein users can access all files on a shared server, one infected host can lock the access to all shared files. We propose a tool…

密码学与安全 · 计算机科学 2022-02-16 Eduardo Berrueta , Daniel Morato , Eduardo Magaña , Mikel Izal

The ever-evolving capabilities of cyber attackers force security administrators to focus on the early identification of emerging threats. Targeted cyber attacks usually consist of several phases, from initial reconnaissance of the network…

密码学与安全 · 计算机科学 2022-06-22 Lukáš Sadlek , Pavel Čeleda , Daniel Tovarňák

A reputable social media or review account can be a good cover for spamming activities. It has become prevalent that spammers buy/sell such accounts openly on the Web. We call these sold/bought accounts the changed-hands (CH) accounts. They…

社会与信息网络 · 计算机科学 2021-06-30 Geli Fei , Shuai Wang , Bing Liu , Leman Akoglu

Recent developments in cloud storage architectures have originated new models of online storage as cooperative storage systems and interconnected clouds. Such distributed environments involve many organizations, thus ensuring…

密码学与安全 · 计算机科学 2016-06-30 Marco Baldi , Alessandro Cucchiarelli , Linda Senigagliesi , Luca Spalazzi , Francesco Spegni

Cryptojacking is the permissionless use of a target device to covertly mine cryptocurrencies. With cryptojacking, attackers use malicious JavaScript codes to force web browsers into solving proof-of-work puzzles, thus making money by…

密码学与安全 · 计算机科学 2023-04-27 Muhammad Saad , David Mohaisen

The early detection of cybersecurity events such as attacks is challenging given the constantly evolving threat landscape. Even with advanced monitoring, sophisticated attackers can spend as many as 146 days in a system before being…

密码学与安全 · 计算机科学 2018-08-02 Sandeep Narayanan , Ashwinkumar Ganesan , Karuna Joshi , Tim Oates , Anupam Joshi , Tim Finin

Desktops and laptops can be maliciously exploited to violate privacy. In this paper, we consider the daily battle between the passive attacker who is targeting a specific user against a user that may be adversarial opponent. In this…

密码学与安全 · 计算机科学 2020-07-21 Amit Dvir , Yehonatan Zion , Jonathan Muehlstein , Ofir Pele , Chen Hajaj , Ran Dubin

Whilst adversarial attack detection has received considerable attention, it remains a fundamentally challenging problem from two perspectives. First, while threat models can be well-defined, attacker strategies may still vary widely within…

计算机视觉与模式识别 · 计算机科学 2021-11-04 Nathan Drenkow , Neil Fendley , Philippe Burlina

In the digital age, users store personal data in corporate databases, making data security central to enterprise management. Given the extensive attack surface, assets face challenges like weak authentication, vulnerabilities, and malware.…

密码学与安全 · 计算机科学 2024-11-12 Zilin Huang , Xiulai Li , Xinyi Cao , Ke Chen , Longjuan Wang , Logan Bo-Yee Liu