paper-with-me

홈 › Papers

Tracking Dynamic Sources of Malicious Activity at Internet Scale

2009-12-01 · NeurIPS 2009 12 · Shobha Venkataraman, Avrim Blum, Dawn Song, Subhabrata Sen, Oliver Spatscheck

We formulate and address the problem of discovering dynamic malicious regions on the Internet. We model this problem as one of adaptively pruning a known decision tree, but with additional challenges: (1) severe space requirements, since the underlying decision tree has over 4 billion leaves, and (2) a changing target function, since malicious activity on the Internet is dynamic. We present a novel algorithm that addresses this problem, by putting together a number of different ``experts algorithms and online paging algorithms. We prove guarantees on our algorithms performance as a function of the best possible pruning of a similar size, and our experiments show that our algorithm achieves high accuracy on large real-world data sets, with significant improvements over existing approaches.

📄 PDF Abstract BibTeX

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Beyond Content: Behavioral Policies Reveal Actors in Information Operations

2026-02-02 · Philipp J. Schneider, Lanqin Yuan, Marian-Andrei Rizoiu arxiv

The detection of online influence operations -- coordinated campaigns by malicious actors to spread narratives -- has traditionally depended on content analysis or network features. These approaches are increasingly brit…

A source separation approach to temporal graph modelling for computer networks

2023-03-28 · Corentin Larroche

Detecting malicious activity within an enterprise computer network can be framed as a temporal link prediction task: given a sequence of graphs representing communications between hosts over time, the goal is to predict …

Link Prediction

Machine Learning Approach on Multiclass Classification of Internet Firewall Log Files

2023-06-12 · Md Habibur Rahman, Taminul Islam, Md Masum Rana, Rehnuma Tasnim 외

Firewalls are critical components in securing communication networks by screening all incoming (and occasionally exiting) data packets. Filtering is carried out by comparing incoming data packets to a set of rules design…

DANTE: A framework for mining and monitoring darknet traffic

2020-03-05 · Dvir Cohen, Yisroel Mirsky, Yuval Elovici, Rami Puzis 외

Trillions of network packets are sent over the Internet to destinations which do not exist. This 'darknet' traffic captures the activity of botnets and other malicious campaigns aiming to discover and compromise devices …

Time SeriesTime Series Analysis

Tracking Temporal Evolution of Network Activity for Botnet Detection

2019-08-09 · Kapil Sinha, Arun Viswanathan, Julian Bunn

Botnets are becoming increasingly prevalent as the primary enabling technology in a variety of malicious campaigns such as email spam, click fraud, distributed denial-of-service (DDoS) attacks, and cryptocurrency mining.…