Anand Handa

dblp:243/0466 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0003-0075-1165ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2025 Attackers' Profiling Based on Multi-Attack Patterns in SSH Service
Kriti Majumdar, Anand Handa, Sandeep K. Shukla
ICISSP (2)3
2024 ArkThor: Threat Categorization Based on Malware's C2 Communication
Mohammed Jawed, Sriram Parameshwaran, Anand Handa, Sandeep K. Shukla
ICISSP4
2022 RBMon: Real Time System Behavior Monitoring Tool
abstract
There are several security tools available to tackle cyber threats, but the sophistication of attacks leads to the failure of defense mechanisms. Among such tools, endpoint security agents are much prominent to safeguard organizations from potential threats. To monitor and investigate systems for unpredictable modifications and proof of tactics, techniques, and procedures (TTP) used by malware writers. In this work, we develop a real-time system behavior monitoring solution. We use three modules - monitoring, analysis, and mapping to counter the threats based on attack patterns. All three modules have their unique mechanism and are interconnected. The monitoring agent is developed for the Windows platform using the C++ programming language, which captures Windows kernel-level system events in a multi-threaded form. It captures critical information such as - network activity, registry, file, accessed paths, processes, etc. The monitoring agent ships the collected events to the analysis module. In the analysis module, we perform analysis in three phases: rule-based, machine learning (ML)-based, and risk-assessment. Rule-based mechanism finds the Indicator of Compromises (IoCs) from the system events related to exploits, web shell, malicious documents, etc. The ML-based analysis gives an overall understanding of normal vs. suspicious behavior. The risk-assessment analysis uses rule-based and ML-based analysis outputs, to provide the risk-score based on the number of IoCs detected and the suspicious behavior predicted. In the mapping phase, we offer an interactive dashboard to the end-user for visualizing all the activities and the analysis outcomes like running processes, suspicious processes, network activities, port accessed, suspicious paths accessed by a single process, etc., using Kibana. The designed tool monitors the system events in near real-time and reports any suspicious activity that helps in mitigating the threats posed to the user. Hence, it acts as a comprehensive security solution with multi-dimensional capabilities.
Anand Handa, Sandeep K. Shukla
AsiaCCS2
2022 Volatility Custom Profiling for Automated Hybrid ELF Malware Detection
Rahul Varshney, Anand Handa, Sandeep K. Shukla
ICDF2C3
2020 A multimodel keyword spotting system based on lip movement and speech features
Anand Handa, Rashi Agarwal, Narendra Kohli
Multim. Tools Appl.1
2019 Evading API Call Sequence Based Malware Classifiers
Fenil Fadadu, Anand Handa, Sandeep K. Shukla
ICICS2