ENGLISH

Science of Cyber Security: Third International Conference, SciSec 2021, Virtual Event, August 13–15, 2021, Revised Selected Papers (Lecture Notes in Computer Science)

Book information

Publisher
Springer
Year
2021
ISBN
3030891364, 9783030891367
Language
english
Format
PDF
Filesize
32 MB (33928086 bytes)
Edition
1st ed. 2021
Pages
280\273
Time added
2021-11-10 14:57:04

Description

This book constitutes the proceedings of the Third International Conference on Science of Cyber Security, SciSec 2021, held in Shanghai, China, in August 2021. The 17 full papers and  5 short papers presented in this volume were carefully reviewed and selected from  50 submissions. These papers cover the following subjects: Cyber Security, Detection, Machine Learning and much more. Preface Organization Contents Keynote Report SARR: A Cybersecurity Metrics and Quantification Framework (Keynote) 1 Introduction 2 The SARR Framework 2.1 Terminology 2.2 SARR Overview 2.3 Assumptions 2.4 Metrics When Assumptions Are Certainly Not Violated 2.5 Metrics When Assumptions Are Certainly Violated 2.6 Metrics When Assumptions May Be Violated 3 Status Quo 3.1 Assumptions 3.2 Security Metrics 3.3 Agility Metrics 3.4 Resilience Metrics 3.5 Risk Metrics 4 Future Research Directions 5 Conclusion References Detection for Cybersecurity Detecting Internet-Scale Surveillance Devices Using RTSP Recessive Features 1 Introduction 2 Related Work 3 Protocol Analysis on RTSP 3.1 Methods of RTSP 3.2 Features Selection 3.3 Challenges of Internet-Wide Measurement 4 Methodology 4.1 Data Collection 4.2 Pre-processing 4.3 Labeling 4.4 Training 4.5 Classification 4.6 Identification 5 Real-World Experiments and Result 5.1 Experimental Data 5.2 Evaluation 5.3 Comparison 5.4 Distribution 6 Discussion and Conclusion References An Intrusion Detection Framework for IoT Using Partial Domain Adaptation 1 Introduction 2 Background 2.1 Generative Adversarial Networks (GAN) 2.2 Domain Adaptation and Partial Domain Adaptation 3 The Proposed Framework 3.1 System Model 3.2 Pre-processing and Pre-training 3.3 Partial Domain Adaptation 3.4 Online Intrusion Detection 4 Evaluation 4.1 Datasets and Experiment Setup 4.2 Detection of Partial Domain Adaptation 4.3 Detection of Unknown Attack 4.4 Detection of Non-partial Domain Adaptation 5 Discussion 5.1 Classification of Unknown Attacks 5.2 Detection of the New Attacks 6 Related Work 7 Conclusion References Mining Trojan Detection Based on Multi-dimensional Static Features 1 Introduction 2 Background and Related Work 2.1 Mining Trojan 2.2 Malware Detection 3 MSFV Extraction on Mining Trojans 3.1 Static Analysis 3.2 Multi-dimensional Static Feature Vector 4 Miner-Killer System 5 Experiments 5.1 Dataset 5.2 Evaluation Metrics 5.3 Analysis of Our Proposed Features 5.4 Compared with Well-Known AVs 5.5 Compared with Other Methods 6 Conclusion and Future Work References Botnet Detection Based on Multilateral Attribute Graph 1 Introduction 2 Multilateral Attribute Graph of Botnet 2.1 Communication Features of Botnet 2.2 Fine-Grained Multilateral Attribute Graph 3 Botnet Detection Method Based on fMAG 3.1 Multi-Edge Embedding (MEE) 3.2 Direct On-Vertex Embedding(DVE) 3.3 Latent-GCN 3.4 Bot Detection Methods 4 Experiments and Analysis 4.1 Datasets 4.2 Experiments and Discussions 5 Conclusion References A New Method for Inferring Ground-Truth Labels and Malware Detector Effectiveness Metrics 1 Introduction 2 Problem Statement 3 Relative Accuracy Revisited 3.1 Review of Previous Approach ch6charlton2018measuring to Computing Relative Accuracy 3.2 New Approach to Computing Relative Accuracy and Deeper Analysis 3.3 Enhancing Algorithm 2 with a Bellwether Reference Detector 4 Inferring Ground-Truth Labels and Effectiveness Metrics 5 Applying the Method to Real-World Dataset 6 Conclusion References Machine Learning for Cybersecurity Protecting Data Privacy in Federated Learning Combining Differential Privacy and Weak Encryption 1 Introduction 2 Related Work and Background 2.1 Privacy Threats in Federated Learning 2.2 Relevant Privacy Protection Technology 3 Preliminaries 3.1 Related Technologies 3.2 Threat Model 4 Methodology 4.1 Overview 4.2 Parameter Perturbation 4.3 Weak Encryption 5 Experiments 5.1 Defensive Performance 5.2 Computational Cost 5.3 Accuracy 6 Conclusion and Future Work References Using Chinese Natural Language to Configure Authorization Policies in Attribute-Based Access Control System 1 Introduction 2 Related Work 3 Methodology 3.1 Overview 3.2 Key Words Extraction 3.3 Tag Alignment 3.4 Expression Transformation 4 Experiments 4.1 Experiment Settings 4.2 Metrics 4.3 Evaluations on Key Words Extraction and Tag Alignment 4.4 Evaluations on Expression Transformation 4.5 Systematic Evaluations 5 Conclusion and Future Work A Parsing Rules for Tag Sequence B Algorithm for Key Words Extraction C Algorithm for Tag Alignment D Algorithm for Expression Transformation References A Data-Free Approach for Targeted Universal Adversarial Perturbation 1 Introduction 2 Related Work 3 Our Approach 3.1 Universal Adversarial Attack 3.2 Data-Free Targeted UAP 3.3 Update Perturbation 3.4 Algorithm 4 Federated Learning 4.1 Difficulties in UAP Attack 4.2 Threaten to Model 5 Experimental Results 5.1 Experiment Setup 5.2 Metrics 5.3 Classification Result 5.4 Transferability 5.5 Federated Learning 6 Discussion 6.1 Defense of UAP Attack 6.2 Federated Learning Data Distribution 7 Conclusion References Caps-LSTM: A Novel Hierarchical Encrypted VPN Network Traffic Identification Using CapsNet and LSTM 1 Introduction 2 Related Work 2.1 Traditional Encrypted Traffic Identification Methods 2.2 Encrypted Traffic Identification Methods Based on Deep Learning 3 The Proposed Model 3.1 Original Flow Conversion Module 3.2 Hierarchical Training Model Based on CapsNet and LSTM 3.3 The Final Identification Module of Encrypted Flow 4 Experiment 4.1 Dataset and Evaluation Criteria 4.2 Data Preprocessing 5 Experimental Results 5.1 Encrypted Traffic Service Identification Effect Evaluation 5.2 Encrypted Traffic Application Identification Effect Evaluation 6 Conclusion References Multi-granularity Mobile Encrypted Traffic Classification Based on Fusion Features 1 Introduction 2 Related Work 2.1 Internet Encrypted Traffic Classification 2.2 Mobile Application Traffic Classification 3 Fusion Feature Based Model 3.1 Data Preprocessing 3.2 Feature Extraction 3.3 Training and Recognition 4 Evaluation 4.1 Data Set 4.2 Evaluation Index 4.3 Comparison Methods 4.4 MainParameters 4.5 Comparative Experiment 4.6 Confusion Matrix 5 Conclusion References Stochastic Simulation Techniques for Inference and Sensitivity Analysis of Bayesian Attack Graphs 1 Introduction 2 Bayesian Attack Graphs 2.1 Motivating Example 2.2 Bayesian Attack Graphs 2.3 Problem Statement 3 Sampling Techniques 3.1 Generating Samples 3.2 Probabilistic Logic Sampling 3.3 Likelihood Weighting 3.4 Backward Simulation 3.5 Confidence Bounds 4 Comparison 5 Sensitivity Analysis 6 Related Work 7 Conclusion References Simulations of Event-Based Cyber Dynamics via Adversarial Machine Learning 1 Introduction 1.1 Research Background 1.2 Basic Concept 1.3 Paper Outline 2 Machine Learning Model Deployment: Anomaly Detection Task Based on Text Classification 2.1 Experiment Settings 2.2 The Performance of Each Model Under Adversarial Attacks 3 Scenario 1: Observe the States of Network Nodes Through Machine Learning 3.1 Scenario Description 3.2 Scenario Task: Estimate the Equilibrium of Cybersecurity Dynamics 3.3 Scenario Variable: The Deployed Machine Learning Model is Under Adversarial Attack 4 Scenario 2: Using Machine Learning to Assist in Removing Malware 4.1 Scenario Description 4.2 Scenario Task: Control the Cybersecurity Dynamics 4.3 Scenario Variable: The Deployed Machine Learning Model Is Under Adversarial Attack 5 Conclusion References Dynamics, Network and Inference Dismantling Interdependent Networks Based on Supra-Laplacian Energy 1 Introduction 2 Laplacian Energy of Interdependent Networks 3 Collective Influence Maximizing Algorithm 4 Experimental Analysis 4.1 Baseline Methods 4.2 Evaluation Metrics 4.3 Monolayer and Interdependent Network 4.4 Experimental Results 5 Conclusion References DWT-DQFT-Based Color Image Blind Watermark with QR Decomposition 1 Introduction 2 Related Theories 2.1 Discrete Wavelet Transform 2.2 Quaternion and Quaternion Fourier Transform 2.3 The Quaternion Matrix Representation of Color Image 2.4 Watermark Embedding Combined with Matrix QR Decomposition 3 Watermarking Algorithm 3.1 Watermark Embedding Algorithm 3.2 Watermark Extraction Algorithm 4 Experiment and Analysis 5 Conclusion References A Multi-level Elastic Encryption Protection Model 1 Introduction 2 Rated Work 3 Model Design 4 Implementation of the Mode 4.1 The Generation Method of Dynamic Encryption Key 4.2 Inverse Ordered Key Blocking Storage Scheme 5 Experiment Data Analysis 5.1 Comparison of Encryption Speed of Different Encryption Levels 5.2 The Impact of Security Level on Host Hardware Performance 6 Conclusion and Future Work References An Event-Based Parameter Switching Method for Controlling Cybersecurity Dynamics 1 Introduction 1.1 Our Contributions 1.2 Related Work 1.3 Paper Outline 2 Problem Statement 2.1 Review of Preventive and Reactive Defense Dynamics 2.2 Problem Statement: Controlling Cybersecurity Dynamics 2.3 Notations 3 An Event-Based Parameter Switching Method 3.1 Designing Event-Based Parameter Switching Rule 3.2 Analyzing the Event-Based Parameter Switching Method 3.3 Numerical Examples 4 Putting the Event-Based Method into Practice 4.1 Estimation via 0-1 State Sequences Within a Time Window 4.2 Using the Event-Based Control Method in Practice 5 Conclusion References RansomLens: Understanding Ransomware via Causality Analysis on System Provenance Graph 1 Introduction 2 Background and Motivation 3 Related Work 4 Threat Model and Definitions 4.1 Threat Model 4.2 Definitions 5 Analysis Infrastructure 6 Under the Hood 6.1 Dataset 6.2 Inter-family Analysis 6.3 Intra-family Analysis 7 Conclusion References Author Index

Similar books