Polina Zilberman

dblp:79/234 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0003-3593-7330ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorSystems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2023 Attack Hypotheses Generation Based on Threat Intelligence Knowledge Graph
abstract
Cyber threat intelligence on past attacks may help with attack reconstruction and the prediction of the course of an ongoing attack by providing deeper understanding of the tools and attack patterns used by attackers. Therefore, cyber security analysts employ threat intelligence, alert correlations, machine learning, and advanced visualizations in order to produce sound attack hypotheses. In this article, we present AttackDB, a multi-level threat knowledge base that combines data from multiple threat intelligence sources to associate high-level ATT&CK techniques with low-level telemetry found in behavioral malware reports. We also present the Attack Hypothesis Generator which relies on knowledge graph traversal algorithms and a variety of link prediction methods to automatically infer ATT&CK techniques from a set of observable artifacts. Results of experiments performed with 53K VirusTotal reports indicate that the proposed algorithms employed by the Attack Hypothesis Generator are able to produce accurate adversarial technique hypotheses with a mean average precision greater than 0.5 and area under the receiver operating characteristic curve of over 0.8 when it is implemented on the basis of AttackDB. The presented toolkit will help analysts to improve the accuracy of attack hypotheses and to automate the attack hypothesis generation process.
Florian Klaus Kaiser, Uriel Dardik, Aviad Elitzur, Polina Zilberman, Nir Daniel, Marcus Wiens, Frank Schultmann, Yuval Elovici, Rami Puzis
IEEE Trans. Dependable Secur. Comput.4
2023 MABAT: A Multi-Armed Bandit Approach for Threat-Hunting
abstract
Threat hunting relies on cyber threat intelligence to perform active hunting of prospective attacks instead of waiting for an attack to trigger some pre-configured alerts. One of the most important aspects of threat hunting is automation, especially when it concerns targeted data collection. Multi-armed bandits (MAB) is a family of problems that can be used to optimize the targeted data collection and balance between exploration and exploitation of the collected data. Unfortunately, state-of-the-art policies for solving MAB with dependent arms do not utilize the detailed interrelationships between attacks such as telemetry or artifacts shared by multiple attacks. We propose new policies, one of which is theoretically proven, to prioritize the investigated attacks during targeted data collection. Experiments with real data extracted from VirusTotal behavior reports show the superiority of the proposed techniques and their robustness in presence of noise.
Liad Dekel, Ilia Leybovich, Polina Zilberman, Rami Puzis
IEEE Trans. Inf. Forensics Secur.3
2021 Spillover Today? Predicting Traffic Overflows on Private Peering of Major Content Providers
abstract
Large content providers and content distribution network operators usually connect with large Internet service providers (eyeball networks) through dedicated private peering. The capacity of these private network interconnects is provisioned to match the volume of the real content demand by the users. Unfortunately, in cases in which there is a surge in traffic demand, (e.g., due to trending content or massive software updates) the capacity of the private interconnect may deplete, requiring the content provider/distributor to reroute the excess traffic through transit providers. Although such overflow events are rare, they negatively impact content providers, Internet service providers, and end-users. Such impact includes unexpected delays and disruptions that reduce the quality of the user experience, as well as direct costs paid by the Internet service provider to the transit providers. In this article, we examine the problem of predicting an overflow event in order to enable content and Internet service providers to handle the excess traffic in a timely manner. We propose an ensemble of deep learning models trained to predict overflow events over a short-term horizon of 2–4 hours and predict the specific interconnections through which the excess traffic will enter the Internet service provider. Evaluated with 2.5 years (2017-2019) of traffic measurement data from a large European Internet service provider, the models were shown to successfully recall 65% of the events with precision of 51% on average. While the lockdowns imposed by the COVID-19 pandemic reduced the overflow prediction accuracy, the pandemic’s impact on the accuracy was temporary. Although the lockdown continued on and off, the performance of models trained before the pandemic regained their performance during April-May 2020.
Elad Rapaport, Ingmar Poese, Polina Zilberman, Oliver Holschke, Rami Puzis
IEEE Trans. Netw. Serv. Manag.3
2020 PALE: Time Bounded Practical Agile Leader Election
abstract
Many tasks executed in dynamic distributed systems, such as sensor networks or enterprise environments with bring-your-own-device policy, require central coordination by a leader node. In the past it has been proven that distributed leader election in dynamic environments with constant changes and asynchronous communication is not possible. Thus, state-of-the-art leader election algorithms are not applicable in asynchronous environments with constant network changes. Some algorithms converge only after the network stabilizes (an unrealistic requirement in many dynamic environments). Other algorithms reach consensus in the presence of network changes but require a global clock or some level of communication synchrony. Determining the weakest assumptions, under which bounded leader election is possible, remains an unresolved problem. In this study we present a leader election algorithm that operates in the presence of changes and under weak (realistic) assumptions regarding message delays and regarding the clock drifts of the distributed nodes. The proposed algorithm is self-sufficient, easy to implement and can be extended to support multiple regions, self-stabilization, and mobile ad-hoc networks. We prove the algorithm's correctness and provide a complexity analysis of the time, space, and number of messages required to elect a leader.
Bronislav Sidik, Rami Puzis, Polina Zilberman, Yuval Elovici
IEEE Trans. Parallel Distributed Syst.3
2018 Anti-forensic = Suspicious: Detection of Stealthy Malware that Hides Its Network Traffic
Mayank Agarwal, Rami Puzis, Jawad Haj-Yahya, Polina Zilberman, Yuval Elovici
SEC4
2017 On Network Footprint of Traffic Inspection and Filtering at Global Scrubbing Centers
abstract
Traffic diversion through powerful cloud-based scrubbing centers provides a solution for protecting against various DDoS attacks. In one respect, such a solution enables sanitizing attack traffic close to its source and saves precious resources for the network service provider. Contrarily, the diversion of the inspected traffic toward the scrubbing centers may increase its footprint in the network. The location of the scrubbing centers greatly affects the network resource utilization and, therefore, should be carefully considered in the design of the security service. In this paper, we investigate four deployment strategies and compare their performance on a network of Points-of-Presence and on several router level topologies obtained from the RocketFuel project. The deployment quality was measured using the following criteria: the footprint of the inspected traffic, the redistribution of load on the links, and the increase in communication latency. Our results show that the deployment strategy that is considered to perform well for locating network monitors by maximizing flow coverage results in the worst footprint when traffic diversion is employed. Overall, we show that the deployment strategy that is tailored for traffic filtering is also suitable for traffic monitoring, but not the other way around.
Polina Zilberman, Rami Puzis, Yuval Elovici
IEEE Trans. Dependable Secur. Comput.1
2013 Analyzing group E-mail exchange to detect data leakage
abstract
Today's organizations spend a great deal of time and effort on e‐mail leakage prevention. However, there are still no satisfactory solutions; addressing mistakes are not detected and in some cases correct recipients are wrongly marked as potential mistakes. In this article we present a new approach for preventing e‐mail addressing mistakes in organizations. The approach is based on an analysis of e‐mail exchanges among members of an organization and the identification of groups based on common topics. When a new e‐mail is about to be sent, each recipient is analyzed. A recipient is approved if the e‐mail's content belongs to at least one common topic to both the sender and the recipient. This can be applied even if the sender and recipient have never communicated directly before. The new approach was evaluated using the Enron e‐mail data set and was compared with a well known method for the detection of e‐mail addressing mistakes. The results show that the proposed approach is capable of detecting 87% of nonlegitimate recipients while incorrectly classifying only 0.5% of the legitimate recipients. These results outperform previous work, which reports a detection rate of 82% without reference to the false positive rate.
Polina Zilberman, Gilad Katz, Asaf Shabtai, Yuval Elovici
J. Assoc. Inf. Sci. Technol.1
2011 Analyzing group communication for preventing data leakage via email
abstract
Modern business activities rely on extensive email exchange. Various solutions attempt to analyze email exchange in order to prevent emails from being sent to the wrong recipients. However there are still no satisfying solutions; many email addressing mistakes are not detected and in many cases correct recipients are wrongly marked as potential addressing mistakes. In this paper we present a new approach for preventing emails addressing mistakes in organizations. The approach is based on analysis of emails exchange among members of the organization and the identification of groups based on common topics. Each member's topics are then used during the enforcement phase for detecting potential leakage. When a new email is composed and about to be sent, each email recipient is analyzed. A recipient is approved if the email's content belongs to at least one of the topics common to the sender and the recipient. We evaluated the new approach using the Enron Email dataset. Our evaluation results suggest that the new approach easily copes with email recipients that have no previous direct connection with the sender.
Polina Zilberman, Shlomi Dolev, Gilad Katz, Yuval Elovici, Asaf Shabtai
ISI1
2009 Trawling Traffic under Attack, Overcoming DDoS Attacks by Target-Controlled Traffic Filtering
abstract
As more and more services are provided by servers via the Internet, Denial-of-Service (DoS) attacks pose an increasing threat to the Internet community. A DoS attack overloads the target server with a large volume of adverse requests, thereby rendering the server unavailable to ¿well-behaved¿ users. Recently, the novel paradigm of traffic ownership that enables the clients of Internet service providers (ISP) to configure their own traffic processing policies has gained popularity. In this paper, we propose two algorithms belonging to this paradigm that allow attack targets to dynamically filter their incoming traffic based on a distributed policy. The proposed algorithms defend the target against DoS and distributed DoS (DDoS) attacks and simultaneously ensure that it continues to receive valuable users' traffic. In a nutshell, a target can define a filtering policy which consists of a set of traffic classification rules and the corresponding amounts of traffic, measured in bandwidth units, which match each rule. The filtering algorithm is enforced by the ISP's or the Network Service Provider's (NSP) routers when a target is being overloaded with traffic. The goal is to maximize the amount of filtered traffic forwarded to the target, according to the filtering policy, from the ISP's or the NSP's network. The first algorithm we propose relies on complete collaboration among the ISP/NSP routers. It computes the filtering policy in polynomial time and delivers the best possible traffic mix to the target. The second algorithm is a distributed algorithm which assumes no collaboration among the ISP/NSP routers, each router only uses local information about its incoming traffic. We show the intuition behind the proof of lower bound on the second algorithm's worst-case performance.
Shlomi Dolev, Yuval Elovici, Alexander Kesselman, Polina Zilberman
PDCAT4
2009 Incremental deployment of network monitors based on Group Betweenness Centrality
Shlomi Dolev, Yuval Elovici, Rami Puzis, Polina Zilberman
Inf. Process. Lett.4