Steven Noel

dblp:26/2771 · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
2since 2021 · last 2025
0000-0002-8540-0702ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 6 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 first-authorArtificial intelligence and machine learning · 3 · 1 first-authorSystems, architecture and hardware · 1Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2025 Detecting Anomalous Communication Behaviors in Dynamically Evolving Networked Systems
Mehedi Hassan, M. Engin Tozal, Vipin Swarup, Steven Noel, Raju N. Gottumukkala, Vijay Raghavan 0001
IEEE Trans. Inf. Forensics Secur.4
2022 Dependency-Based Link Prediction for Learning Microsegmentation Policy
Steven Noel, Vipin Swarup
ICICS1
2014 k-Zero Day Safety: A Network Security Metric for Measuring the Risk of Unknown Vulnerabilities
abstract
By enabling a direct comparison of different security solutions with respect to their relative effectiveness, a network security metric may provide quantifiable evidences to assist security practitioners in securing computer networks. However, research on security metrics has been hindered by difficulties in handling zero-day attacks exploiting unknown vulnerabilities. In fact, the security risk of unknown vulnerabilities has been considered as something unmeasurable due to the less predictable nature of software flaws. This causes a major difficulty to security metrics, because a more secure configuration would be of little value if it were equally susceptible to zero-day attacks. In this paper, we propose a novel security metric, k-zero day safety, to address this issue. Instead of attempting to rank unknown vulnerabilities, our metric counts how many such vulnerabilities would be required for compromising network assets; a larger count implies more security because the likelihood of having more unknown vulnerabilities available, applicable, and exploitable all at the same time will be significantly lower. We formally define the metric, analyze the complexity of computing the metric, devise heuristic algorithms for intractable cases, and finally demonstrate through case studies that applying the metric to existing network security practices may generate actionable knowledge.
Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Pengsu Cheng, Steven Noel
IEEE Trans. Dependable Secur. Comput.5
2012 Time-efficient and cost-effective network hardening using attack graphs
abstract
Attack graph analysis has been established as a powerful tool for analyzing network vulnerability. However, previous approaches to network hardening look for exact solutions and thus do not scale. Further, hardening elements have been treated independently, which is inappropriate for real environments. For example, the cost for patching many systems may be nearly the same as for patching a single one. Or patching a vulnerability may have the same effect as blocking traffic with a firewall, while blocking a port may deny legitimate service. By failing to account for such hardening interdependencies, the resulting recommendations can be unrealistic and far from optimal. Instead, we formalize the notion of hardening strategy in terms of allowable actions, and define a cost model that takes into account the impact of interdependent hardening actions. We also introduce a near-optimal approximation algorithm that scales linearly with the size of the graphs, which we validate experimentally.
Massimiliano Albanese, Sushil Jajodia, Steven Noel
DSN3
2010 k-Zero Day Safety: Measuring the Security Risk of Networks against Unknown Attacks
Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Steven Noel
ESORICS4
2008 A Graph-Theoretic Visualization Approach to Network Risk Analysis
Scott O'Hare, Steven Noel, Kenneth Prole
VizSEC2
2006 Minimum-cost network hardening using attack graphs
Lingyu Wang 0001, Steven Noel, Sushil Jajodia
Comput. Commun.2
2005 Understanding Complex Network Attack Graphs through Clustered Adjacency Matrices
abstract
We apply adjacency matrix clustering to network attack graphs for attack correlation, prediction, and hypothesizing. We self-multiply the clustered adjacency matrices to show attacker reachability across the network for a given number of attack steps, culminating in transitive closure for attack prediction over all possible number of steps. This reachability analysis provides a concise summary of the impact of network configuration changes on the attack graph. Using our framework, we also place intrusion alarms in the context of vulnerability-based attack graphs, so that false alarms become apparent and missed detections can be inferred. We introduce a graphical technique that shows multiple-step attacks by matching rows and columns of the clustered adjacency matrix. This allows attack impact/responses to be identified and prioritized according to the number of attack steps to victim machines, and allows attack origins to be determined. Our techniques have quadratic complexity in the size of the attack graph
Steven Noel, Sushil Jajodia
ACSAC1
2005 Multiple Coordinated Views for Network Attack Graphs
abstract
While efficient graph-based representations have been developed for modeling combinations of low-level network attacks, relatively little attention has been paid to effective techniques for visualizing such attack graphs. This paper describes a number of new attack graph visualization techniques, each having certain desirable properties and offering different perspectives for solving different kinds of problems. Moreover, the techniques we describe can be applied not only separately, but can also be combined into coordinated attack graph views. We apply improved visual clustering to previously described network protection domains (attack graph cliques), which reduces graph complexity and makes the overall attack flow easier to understand. We also visualize the attack graph adjacency matrix, which shows patterns of network attack while avoiding the clutter usually associated with drawing large graphs. We show how the attack graph adjacency matrix concisely conveys the impact of network configuration changes on attack graphs. We also describe a novel attack graph filtering technique based on the interactive navigation of a hierarchy of attack graph constraints. Overall, our techniques scale quadratically with the number of machines in the attack graph.
Steven Noel, Michael Jacobs 0001, Pramod Kalapa, Sushil Jajodia
VizSEC1
2004 Correlating Intrusion Events and Building Attack Scenarios Through Attack Graph Distances
abstract
We map intrusion events to known exploits in the network attack graph, and correlate the events through the corresponding attack graph distances. From this, we construct attack scenarios, and provide scores for the degree of causal correlation between their constituent events, as well as an overall relevancy score for each scenario. While intrusion event correlation and attack scenario construction have been previously studied, this is the first treatment based on association with network attack graphs. We handle missed detections through the analysis of network vulnerability dependencies, unlike previous approaches that infer hypothetical attacks. In particular, we quantify lack of knowledge through attack graph distance. We show that low-pass signal filtering of event correlation sequences improves results in the face of erroneous detections. We also show how a correlation threshold can be applied for creating strongly correlated attack scenarios. Our model is highly efficient, with attack graphs and their exploit distances being computed offline. Online event processing requires only a database lookup and a small number of arithmetic operations, making the approach feasible for real-time applications.
Steven Noel, Eric Robertson 0001, Sushil Jajodia
ACSAC1
2004 Managing attack graph complexity through visual hierarchical aggregation
abstract
We describe a framework for managing network attack graph complexity through interactive visualization, which includes hierarchical aggregation of graph elements. Aggregation collapses non-overlapping subgraphs of the attack graph to single graph vertices, providing compression of attack graph complexity. Our aggregation is recursive (nested), according to a predefined aggregation hierarchy. This hierarchy establishes rules at each level of aggregation, with the rules being based on either common attribute values of attack graph elements or attack graph connectedness. The higher levels of the aggregation hierarchy correspond to higher levels of abstraction, providing progressively summarized visual overviews of the attack graph. We describe rich visual representations that capture relationships among our semantically-relevant attack graph abstractions, and our views
Steven Noel, Sushil Jajodia
VizSEC1
2003 Efficient Minimum-Cost Network Hardening Via Exploit Dependency Graphs
abstract
In-depth analysis of network security vulnerability must consider attacker exploits not just in isolation, but also in combination. The general approach to this problem is to compute attack paths (combinations of exploits), from which one can decide whether a given set of network hardening measures guarantees the safety of given critical resources. We go beyond attack paths to compute actual sets of hardening measures (assignments of initial network conditions) that guarantee the safety of given critical resources. Moreover, for given costs associated with individual hardening measures, we compute assignments that minimize overall cost. By doing our minimization at the level of initial conditions rather than exploits, we resolve hardening irrelevancies and redundancies in a way that cannot be done through previously proposed exploit-level approaches. Also, we use an efficient exploit-dependency representation based on monotonic logic that has polynomial complexity, as opposed to many previous attack graph representations having exponential complexity.
Steven Noel, Sushil Jajodia, Brian O'Berry, Michael Jacobs 0001
ACSAC1
2003 Protecting multimedia authenticity with ICA vaccination of digital bacteria watermarks
abstract
We propose the application of independent component analysis (ICA), via unsupervised neural networks, to authenticity protection for multimedia products. We give an overview of the current state of multimedia authenticity protection, including the requirements of various multimedia applications, current approaches to the problem, and the robustness of the approaches. For watermark security, a covert independent-component watermarking signal can serve as a vaccination against a dormant digital bacteria protecting the multimedia data. Unauthorized removal of the watermark triggers the bacterium, which then responds appropriately against the pirated data. We insure that our digital bacteria meet established requirements for beneficial virus-like programs. Overall, we show how these new approaches contribute to a flexible, robust, and secure system for protecting the authenticity of multimedia products.
Harold Szu, Steven Noel, Seong-Bin Yim, Jefferson M. Willey, Joe Landa
IJCNN2
2003 Multimedia authenticity protection with ICA watermarking and digital bacteria vaccination
Harold Szu, Steven Noel, Seong-Bin Yim, Jefferson M. Willey, Joe Landa
Neural Networks2
2002 Representing TCP/IP Connectivity For Topological Analysis of Network Security
abstract
The individual vulnerabilities of hosts on a network can be combined by an attacker to gain access that would not be possible if the hosts were not interconnected. Currently available tools report vulnerabilities in isolation and in the context of individual hosts in a network. Topological vulnerability analysis (TVA) extends this by searching for sequences of interdependent vulnerabilities, distributed among the various network hosts. Model checking has been applied to the analysis of this problem with some interesting initial results. However previous efforts did not take into account a realistic representation of network connectivity. These models were enough to demonstrate the usefulness of the model checking approach but would not be sufficient to analyze real-world network security problems. This paper presents a modem of network connectivity at multiple levels of the TCP/IP stack appropriate for use in a model checker. With this enhancement, it is possible to represent realistic networks including common network security devices such as firewalls, filtering routers, and switches.
Ronald W. Ritchey, Brian O'Berry, Steven Noel
ACSAC3
2002 Visualization of Document Co-Citation Counts
abstract
Visualization can facilitate the understanding of the structures of a collection of documents that are related to each other by links, such as citations in formal publications. We present results of visualizing minimum spanning trees based on document co-citation counts and on document citation correlations.
Steven Noel, Chee-Hung Henry Chu, Vijay Raghavan 0001
IV1
2001 Visualizing Association Mining Results through Hierarchical Clusters
abstract
We propose a new methodology for visualizing association mining results. Inter-item distances are computed from combinations of itemset supports. The new distances retain a simple pairwise structure, and are consistent with important frequently occurring itemsets. Thus standard tools of visualization, e.g. hierarchical clustering dendrograms can still be applied, while the distance information upon which they are based is richer. Our approach is applicable to general association mining applications, as well as applications involving information spaces modeled by directed graphs, e.g. the Web. In the context of collections of hypertext documents, the inter-document distances capture the information inherent in a collection's link structure, a form of link mining. We demonstrate our methodology with document sets extracted from the Science Citation Index, applying a metric that measures consistency between clusters and frequent itemsets.
Steven Noel, Vijay Raghavan 0001, Chee-Hung Henry Chu
ICDM1