EDBT 2026 Demo / reviewers in the wild / expert
Roy A. Maxion
dblp:27/7005
· DBLP profile ↗
37ranked-venue papers
10as first author
1since 2021 · last 2024
0000-0002-2833-7276ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 6 first-authorSystems, architecture and hardware · 12 · 5 first-authorHuman-computer interaction and ubiquitous computing · 3 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Computer networks · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Biometric security · 55% Authentication and access control · 36% Network security · 7% | |
| Databases, data mining, and information retrieval
1 paper |
Data mining · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Distributed systems · 61% Electronic design automation · 30% Embedded and real-time systems · 9% |
Topics — the 17 heaviest of 22, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Biometric security
behavioral biometrics |
0.9 | 3 | 2020 | Pattern-Growth Based Mining Mouse-Interaction Behavior for an Active User Authentication System · IEEE Trans. Dependable Secur. Comput. 2020 Performance Analysis of Multi-Motion Sensor Behavior for Active Smartphone Authentication · IEEE Trans. Inf. Forensics Secur. 2018 User Authentication Through Mouse Dynamics · IEEE Trans. Inf. Forensics Secur. 2013 |
Authentication and access control
user authentication |
0.5 | 2 | 2018 | Performance Analysis of Multi-Motion Sensor Behavior for Active Smartphone Authentication · IEEE Trans. Inf. Forensics Secur. 2018 User Authentication Through Mouse Dynamics · IEEE Trans. Inf. Forensics Secur. 2013 |
Authentication and access control › continuous authentication
active authentication |
0.4 | 1 | 2020 | Pattern-Growth Based Mining Mouse-Interaction Behavior for an Active User Authentication System · IEEE Trans. Dependable Secur. Comput. 2020 |
Biometric security › biometric authentication
motion sensor-based authentication |
0.3 | 1 | 2018 | Performance Analysis of Multi-Motion Sensor Behavior for Active Smartphone Authentication · IEEE Trans. Inf. Forensics Secur. 2018 |
Biometric security › biometric authentication
behavioral biometric authentication |
0.2 | 1 | 2016 | Performance Analysis of Touch-Interaction Behavior for Active Smartphone Authentication · IEEE Trans. Inf. Forensics Secur. 2016 |
Authentication and access control
continuous authentication |
0.2 | 1 | 2013 | User Authentication Through Mouse Dynamics · IEEE Trans. Inf. Forensics Secur. 2013 |
Biometric security › behavioral biometrics
mouse dynamics authentication |
0.2 | 1 | 2013 | User Authentication Through Mouse Dynamics · IEEE Trans. Inf. Forensics Secur. 2013 |
Data mining
pattern mining |
0.1 | 1 | 2020 | Pattern-Growth Based Mining Mouse-Interaction Behavior for an Active User Authentication System · IEEE Trans. Dependable Secur. Comput. 2020 |
Network security › intrusion detection and prevention › intrusion detection
anomaly detection |
0.1 | 2 | 2003 | Determining the operational limits of an anomaly-based intrusion detector · IEEE J. Sel. Areas Commun. 2003 "Why 6?" Defining the Operational Limits of Stide, an Anomaly-Based Intrusion Detector · S&P 2002 |
Network security › intrusion detection and prevention
intrusion detection |
0.1 | 2 | 2003 | Determining the operational limits of an anomaly-based intrusion detector · IEEE J. Sel. Areas Commun. 2003 "Why 6?" Defining the Operational Limits of Stide, an Anomaly-Based Intrusion Detector · S&P 2002 |
Network security › intrusion detection and prevention › intrusion detection › intrusion detection system › host-based intrusion detection
masquerader detection |
0.0 | 2 | 2003 | "Why 6?" Defining the Operational Limits of Stide, an Anomaly-Based Intrusion Detector · S&P 2002 Determining the operational limits of an anomaly-based intrusion detector · IEEE J. Sel. Areas Commun. 2003 |
Distributed systems
anomaly detection |
0.0 | 1 | 2002 | Anomaly Detection in Embedded Systems · IEEE Trans. Computers 2002 |
Electronic design automation › hardware verification and test
fault detection |
0.0 | 1 | 2002 | Anomaly Detection in Embedded Systems · IEEE Trans. Computers 2002 |
Distributed systems
fault tolerance |
0.0 | 1 | 2002 | Anomaly Detection in Embedded Systems · IEEE Trans. Computers 2002 |
Software testing
dependability case |
0.0 | 1 | 2000 | Eliminating Exception Handling Errors with Dependability Cases: A Comparative, Empirical Study · IEEE Trans. Software Eng. 2000 |
Programming languages and type systems › control structures
exception handling |
0.0 | 1 | 2000 | Eliminating Exception Handling Errors with Dependability Cases: A Comparative, Empirical Study · IEEE Trans. Software Eng. 2000 |
Network management and operations › fault management
fault detection |
0.0 | 1 | 1993 | Fault Detection in an Ethernet Network Using Anomaly Signature Matching · SIGCOMM 1993 |
Methods — techniques the papers use, named apart from their topics
one-class learning · 1.4SVM · 0.9pattern-growth mining · 0.4pattern growth mining · 0.4wavelet-domain features · 0.3markov-based decision · 0.3support vector machine · 0.2random forest · 0.2neural network · 0.2nearest neighbor · 0.2distance measurement · 0.2error mitigation techniques · 0.1anomaly detection · 0.0fault injection · 0.0n-version programming · 0.0group collaboration · 0.0controlled experiment · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | The Seven Faces of Stress: Understanding Facial Activity Patterns During Cognitive StressabstractStress has been recognized as one of the main contributors to mental health problems, as well as cardiovascular diseases. To reduce the risk of severe diseases, early detection of stress is needed. One of the recent methods studied to detect stress is through facial expression analysis from videos. Although computer vision techniques combined with deep learning have been shown to detect stressful faces, there is a lack of work attempting to define how stressful faces look. One of the main challenges is that the expression of stress is person-dependent and one individual can show stress in various ways. In this work, we present a semi-automatic method that allows to distill from a large quantity of data facial activity patterns that are recognized to show stress. We are the first to combine quantitative and qualitative methods on data from 115 subjects to identify and propose seven facial activity patterns during stress. We support this proposal by analyzing the relationship of the different stress facial expressions with the basic emotions and show how individual components of anger, fear, surprise, and sadness co-occur during our defined stress facial activity patterns. Carla Viegas, Roy A. Maxion, Alex Hauptmann 0001, João Magalhães |
FG | 2 |
| 2020 | Pattern-Growth Based Mining Mouse-Interaction Behavior for an Active User Authentication SystemabstractAnalyzing mouse-interaction behaviors for implicitly identifying computer users has received growing interest from security and biometric researchers. This study presents a simple but efficient active user authentication system by modeling mouse-interaction behavior, which is accurate and competent for future deployments. A pattern-growth-based mining method is proposed to extract frequent behavior segments, in obtaining a stable and discriminative representation of mouse-interaction behavior. Then procedural features are extracted to provide an accurate and fine-grained characterization of the behavior segments. A SVM-based decision procedure using one-class learning techniques is applied to the feature space for performing authentication. Analyses are conducted using data from around 1,526,400 mouse operations of 159 participants, and the authentication performance is evaluated across various application scenarios and tasks. Our experimental results show that characteristics from frequent behavior segments are more stable and discriminative than those from holistic behavior, and the system achieves a practically useful level of performance with FAR of 0.09 percent and FRR of 1 percent. Additional experiments on usability to sample length, reliability to application task, scalability to user size, robustness to mimic attack, and response to behavior change are provided to further explore the applicability. We also compare the proposed approach with the state-of-the-art approaches for the collected data. Chao Shen 0001, Yufei Chen 0001, Xiaohong Guan, Roy A. Maxion |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2018 | Towards Independent Stress Detection: A Dependent Model Using Facial Action UnitsabstractOur society is increasingly more susceptible to chronic stress. Reasons are daily worries, workload, and the wish to fulfil a myriad of expectations. Unfortunately, long-exposure to stress leads to physical and mental health problems. To avoid the described consequences, mobile applications have been studied to track stress in combination with wearables. However, wearables need to be worn all day long and can be costly. Given that most laptops have inbuilt cameras, using video data for personal tracking of stress levels could be a more affordable alternative. In previous work, videos have been used to detect cognitive stress during driving by measuring the presence of anger or fear through a limited number of facial expressions. In contrast, we propose the use of 17 facial action units (AUs) not solely restricted to those emotions. We used five one-hour long videos from the dataset collected by Lau [1]. The videos show subjects while typing, resting, and exposed to a stressor, being a multitasking exercise combined with social evaluation. We performed binary classification using several simple classifiers on AUs extracted in each video frame and were able to achieve an accuracy of up to 74% in subject independent classification and 91% in subject dependent classification. These preliminary results indicate that the AUs most relevant for stress detection are not consistently the same for all 5 subjects. Also in previous work, using facial cues, a strong person-specific component was found during classification. Carla Viegas, Shing-Hon Lau, Roy A. Maxion, Alex Hauptmann 0001 |
CBMI | 3 |
| 2018 | Performance Analysis of Multi-Motion Sensor Behavior for Active Smartphone AuthenticationabstractThe increasing use of smartphones as personal computing platforms to access personal information has stressed the demand for secure and usable authentication techniques, and for constantly protecting privacy. Smartphone sensors can measure users' unique behavioral characteristics when they interact with smartphones, based on different habits, gestures, and angle preferences of touch actions. This paper investigates the reliability and applicability of using motion-sensor behavior for active and continuous smartphone authentication across various operational scenarios, and presents a systematic evaluation of the distinctiveness and permanence properties of the behavior. For each sample of sensor behavior, kinematic information sequences are extracted and analyzed, which are characterized by statistic-, frequency-, and wavelet-domain features, to provide accurate and fine-grained characterization of users' touch actions. A Markov-based decision procedure, using one-class learning techniques, is developed and applied to the feature space for performing authentication. Analyses are conducted using the sensor data of 520 200 touch actions from 102 subjects across various operational scenarios. Extensive experiments show that motion-sensor behavior exhibits sufficient discriminability and stability for active and continuous authentication, and can achieve a false-rejection rate of 5.03% and a false-acceptance rate of 3.98%. Additional experiments on usability to operation length, sensitivity to application scenario, scalability to user size, contribution to different sensors, and response to behavior change are provided to further explore the effectiveness and applicability. We also implement an authentication system into the Android system that can react to the presence of the legitimate user. Chao Shen 0001, Yuanxun Li, Yufei Chen 0001, Xiaohong Guan, Roy A. Maxion |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2016 | Application of HAZOP to the Design of Cyber Security ExperimentsabstractHazard and Operability studies have been extensively used in chemical engineering and designing safety critical systems. Its rigorous analysis based on discovering deviations and hazard makes it ideal in the study of designs and experiments with confounding variables. In this paper, HAZOP methodology is applied to a case study of network security experiment to reliably measure the IP tracking behavior of malicious websites using a low interaction client honeypot. The experiment's design involves a large number of factors and components which could potentially introduce bias in the study and result in invalid analysis. We demonstrate that HAZOP can be applied to security experiments to create a proper experimental design and properly control potential bias of confounding variables. Masood Mansoori, Ian Welch, Kim-Kwang Raymond Choo, Roy A. Maxion |
AINA | 4 |
| 2016 | MouseIdentity: Modeling Mouse-Interaction Behavior for a User Verification SystemabstractAnalysis of mouse-interaction behaviors for identifying individual computer users has experienced growing interest from information security and biometric researchers. This paper presents a simple and efficient user verification system by modeling mouse-interaction behavior, which is accurate and competent for future deployment. For each mouse-operation sample, holistic attributes of mouse trajectories are first analyzed using a power transformation method, to derive a schematic representation of behavior eigenspace. Then, a propagation-based segmentation method is developed to model the detailed dynamic process of mouse movements by performing adaptive behavior segmentation and then characterizing each obtained segment using fine-grained procedural motion metrics. Both schematic and procedural cues from mouse-interaction behaviors may be used independently for verification, being fused at the decision level using combination rules. Analyses are conducted using data from 106 subjects with 21 200 mouse-operation samples. The verification system achieves a 1.96% false-rejection rate and a 1.18% false-acceptance rate with a short verification time (about 6 s) and lightweight system overload. Additional experiments on the effect of sample length and subject pool further examine the applicability of our verification system. We also compare the proposed approach with the state-of-the-art approaches for the data collected. Our findings suggest that mouse-interaction behaviors can enhance traditional authentication systems. Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Roy A. Maxion |
IEEE Trans. Hum. Mach. Syst. | 5 |
| 2016 | Performance Analysis of Touch-Interaction Behavior for Active Smartphone AuthenticationabstractThe increasing use of touchscreen smartphones to access sensitive and privacy data has given rise to the need of secure and usable authentication technique. Smartphone users have their own unique behavioral characteristics when performing touch operations. These personal characteristics are reflected on different rhythm, strength, and angle preferences of touch-interaction behavior. This paper investigates the reliability and applicability on the usage of users' touch-interaction behavior for active authentication on smartphones. For each common type of touch operations, both static and dynamic features are extracted and analyzed for fine-grained characterization of users' touch behavior. Classification techniques (nearest neighbor, neural network, support vector machine, and random forest) are applied to the feature space for performing the task of active authentication. Analyses are conducted using data from around 134 900 touch operations of 71 participants in real-world scenarios, and the authentication performance is evaluated across various types of touch operations, varying operation lengths, different application tasks, and different application scenarios. The extensive experimental results are included to show that touch-interaction behavior exhibits sufficient discriminability and stability among smartphone users for active authentication, and achieves equal-error rates between 1.72% and 9.01% for different types of touch operations with the operation length of 11; the authentication accuracies improve when having long observation or small timespan between the training and testing phases, and express more reliably and stably in a specific task than in the free task. We also discuss a number of avenues for additional research that we believe are necessary to advance the state-of-the-art in this area. Chao Shen 0001, Xiaohong Guan, Roy A. Maxion |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2014 | Performance evaluation of anomaly-detection algorithms for mouse dynamics
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Roy A. Maxion |
Comput. Secur. | 4 |
| 2013 | On User Interaction Behavior as Evidence for Computer Forensic Analysis
Chao Shen 0001, Zhongmin Cai, Roy A. Maxion, Xiaohong Guan |
IWDW | 3 |
| 2013 | User Authentication Through Mouse DynamicsabstractBehavior-based user authentication with pointing devices, such as mice or touchpads, has been gaining attention. As an emerging behavioral biometric, mouse dynamics aims to address the authentication problem by verifying computer users on the basis of their mouse operating styles. This paper presents a simple and efficient user authentication approach based on a fixed mouse-operation task. For each sample of the mouse-operation task, both traditional holistic features and newly defined procedural features are extracted for accurate and fine-grained characterization of a user's unique mouse behavior. Distance-measurement and eigenspace-transformation techniques are applied to obtain feature components for efficiently representing the original mouse feature space. Then a one-class learning algorithm is employed in the distance-based feature eigenspace for the authentication task. The approach is evaluated on a dataset of 5550 mouse-operation samples from 37 subjects. Extensive experimental results are included to demonstrate the efficacy of the proposed approach, which achieves a false-acceptance rate of 8.74%, and a false-rejection rate of 7.69% with a corresponding authentication time of 11.8 seconds. Two additional experiments are provided to compare the current approach with other approaches in the literature. Our dataset is publicly available to facilitate future research. Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Youtian Du, Roy A. Maxion |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2010 | Keystroke biometrics with number-pad inputabstractKeystroke dynamics is the process of identifying individual users on the basis of their typing rhythms, which are in turn derived from the timestamps of key-press and key-release events in the keyboard. Many researchers have explored this domain, with mixed results, but few have examined the relatively impoverished territory of digits only, particularly when restricted to using a single finger - which might come into play on an automated teller machine, a mobile phone, a digital telephone dial, or a digital electronic security keypad at a building entrance. In this work, 28 users typed the same 10-digit number, using only the right-hand index finger. Employing statistical machine-learning techniques (random forest), we achieved an unweighted correct-detection rate of 99.97% with a corresponding false-alarm rate of 1.51%, using practiced 2-of-3 encore typing with outlier handling. This level of accuracy approaches sufficiency for two-factor authentication for passwords or PIN numbers. Roy A. Maxion, Kevin S. Killourhy |
DSN | 1 |
| 2010 | Why is there no science in cyber science?: a panel discussion at NSPW 2010abstractAs researchers with scientific training in fields that depend on experimental results to make progress, we have long been puzzled by the resistance of the experimental computer science community in general, and computer security research in particular, to the use of the methods of experimentation and reporting that are commonplace in most scientific undertakings. To bring our concerns to a broader audience, we proposed a discussion topic for NSPW 2010 that covers the history and practicality of experimental information security with an emphasis on exposing the pros and cons of the application of rigorous scientific experimental methodology in our work. We focused on discussion points that explore the challenges we face as scientists, and we tried to identify a set of concrete steps to resolve the apparent conflict between desire and practice. We hoped that the application of these steps to the papers accepted at NSPW could be an early opportunity to begin a journey toward putting more science into cyber science. The discussion, as expected, was wide ranging, interesting, and often frustrating. This paper is a slight modification of the discussion proposal that was accepted by NSPW with the addition of a brief summary of the discussion. Roy A. Maxion, Thomas A. Longstaff, John McHugh |
NSPW | 1 |
| 2010 | Why Did My Detector Do That?! - Predicting Keystroke-Dynamics Error Rates
Kevin S. Killourhy, Roy A. Maxion |
RAID | 2 |
| 2009 | Comparing anomaly-detection algorithms for keystroke dynamicsabstractKeystroke dynamics-the analysis of typing rhythms to discriminate among users-has been proposed for detecting impostors (i.e., both insiders and external attackers). Since many anomaly-detection algorithms have been proposed for this task, it is natural to ask which are the top performers (e.g., to identify promising research directions). Unfortunately, we cannot conduct a sound comparison of detectors using the results in the literature because evaluation conditions are inconsistent across studies. Our objective is to collect a keystroke-dynamics data set, to develop a repeatable evaluation procedure, and to measure the performance of a range of detectors so that the results can be compared soundly. We collected data from 51 subjects typing 400 passwords each, and we implemented and evaluated 14 detectors from the keystroke-dynamics and pattern-recognition literature. The three top-performing detectors achieve equal-error rates between 9.6% and 10.2%. The results-along with the shared data and evaluation methodology-constitute a benchmark for comparing detectors and measuring progress. Kevin S. Killourhy, Roy A. Maxion |
DSN | 2 |
| 2009 | Designing and evaluating usable security and privacy technologyabstractNo abstract available. M. Angela Sasse, Clare-Marie Karat, Roy A. Maxion |
SOUPS | 3 |
| 2008 | The Effect of Clock Resolution on Keystroke Dynamics
Kevin S. Killourhy, Roy A. Maxion |
RAID | 2 |
| 2007 | Toward Realistic and Artifact-Free Insider-Threat DataabstractProgress in insider-threat detection is currently limited by a lack of realistic, publicly available, real-world data. For reasons of privacy and confidentiality, no one wants to expose their sensitive data to the research community. Data can be sanitized to mitigate privacy and confidentiality concerns, but the mere act of sanitizing the data may introduce artifacts that compromise its utility for research purposes. If sanitization artifacts change the results of insider-threat experiments, then those results could lead to conclusions which are not true in the real world. The goal of this work is to investigate the consequences of sanitization artifacts on insider-threat detection experiments. We assemble a suite of tools and present a methodology for collecting and sanitizing data. We use these tools and methods in an experimental evaluation of an insider-threat detection system. We compare the results of the evaluation using raw data to the results using each of three types of sanitized data, and we measure the effect of each sanitization strategy. We establish that two of the three sanitization strategies actually alter the results of the experiment. Since these two sanitization strategies are commonly used in practice, we must be concerned about the consequences of sanitization artifacts on insider-threat research. On the other hand, we demonstrate that the third sanitization strategy addresses these concerns, indicating that realistic, artifact-free data sets can be created with appropriate tools and methods. Kevin S. Killourhy, Roy A. Maxion |
ACSAC | 2 |
| 2007 | User Discrimination through Structured Writing on PDAsabstractThis paper explores whether features of structured writing can serve to discriminate users of handheld devices such as Palm PDAs. Biometric authentication would obviate the need to remember a password or to keep it secret, requiring only that a user's manner of writing confirm his or her identity. Presumably, a user's dynamic and invisible writing style would be difficult for an imposter to imitate. We show how handwritten, multi-character strings can serve as personalized, non-secret passwords. A prototype system employing support vector machine classifiers was built to discriminate 52 users in a closed-world scenario. On high-quality data, strings as short as four letters achieved a false-match rate of 0.04%, at a corresponding false non-match rate of 0.64%. Strings of at least 8 to 16 letters in length delivered perfect results--a 0% equal-error rate. Very similar results were obtained upon decreasing the data quality or upon increasing the data quantity. Rachel R. M. Roberts, Roy A. Maxion, Kevin S. Killourhy, Fahd Arshad |
DSN | 2 |
| 2006 | User Interface Defect Detection by Hesitation AnalysisabstractDelays and errors are the frequent consequences of people having difficulty with a user interface. Such delays and errors can result in severe problems, particularly for mission-critical applications in which speed and accuracy are of the essence. User difficulty is often caused by interface-design defects that confuse or mislead users. Current techniques for isolating such defects are time-consuming and expensive, because they require human analysts to identify the points at which users experience difficulty; only then can diagnosis and repair of the defects take place. This paper presents an automated method for detecting instances of user difficulty based on identifying hesitations during system use. The method's accuracy was evaluated by comparing its judgments of user difficulty with ground truth generated by human analysts. The method's accuracy at a range of threshold parameter values is given; representative points include 92% of periods of user difficulty identified (with a 35% false-alarm rate); 86% (24% false-alarm rate); and 20% (3% false-alarm rate). Applications of the method to addressing interface defects are discussed Robert W. Reeder, Roy A. Maxion |
DSN | 2 |
| 2006 | Anomaly Detector Performance Evaluation Using a Parameterized Environment
Jeffery P. Hansen, Kymie M. C. Tan, Roy A. Maxion |
RAID | 3 |
| 2005 | User Interface Dependability through Goal-Error PreventionabstractUser interfaces form a critical coupling between humans and computers. When the interface fails, the user fails, and the mission is lost. For example, in computer security applications, human-made configuration errors can expose entire systems to various forms of attack. To avoid interaction failures, a dependable user interface must facilitate the speedy and accurate completion of user tasks. Defects in the interface cause user errors (e.g., goal, plan, action and perception errors), which impinge on speed and accuracy goals, and can lead to mission failure. One source of user error is poor information representation in the interface. This can cause users to commit a specific class of errors - goal errors. A design principle (anchor-based subgoaling) for mitigating this cause was formulated. The principle was evaluated in the domain of setting Windows file permissions. The native Windows XP file permissions interface, which did not support anchor-based subgoaling, was compared to an alternative, called Salmon, which did. In an experiment with 24 users, Salmon achieved as much as a four-fold increase in accuracy for a representative task and a 94% reduction in the number of goal errors committed, compared to the XP interface. Robert W. Reeder, Roy A. Maxion |
DSN | 2 |
| 2005 | The Effects of Algorithmic Diversity on Anomaly Detector PerformanceabstractCommon practice in anomaly-based intrusion detection assumes that one size fits all: a single anomaly detector should detect all anomalies. Compensation for any performance shortcoming is sometimes effected by resorting to correlation techniques, which could be seen as making use of detector diversity. Such diversity is intuitively based on the assumption that detector coverage is different - perhaps widely different - for different detectors, each covering some disparate portion of the anomaly space. Diversity, then, enhances detection coverage by combining the coverages of individual detectors across multiple sub-regions of the anomaly space, resulting in an overall detection coverage that is superior to the coverage of any one detector. No studies have been done, however, in which measured effects of diversity amongst anomaly detectors have been obtained. This paper explores the effects of using diverse anomaly-detection algorithms in intrusion detection. Experimental results indicate that while performance/coverage improvements can in fact be effected by combining diverse detection algorithms, the gains are not the result of combining large, non-overlapping regions of the anomaly space. Rather, the gains are seen at the edges of the space, and are heavily dependent on the parameter values of the detectors, as well as on anomaly characteristics. Based on this study, defenders can be provided with knowledge of how combinations of diverse, sequence-based detectors behave to effect detection performance superior to that of a single detector. Kymie M. C. Tan, Roy A. Maxion |
DSN | 2 |
| 2005 | Use of diversity as a defense mechanismabstractDiversity, a concept suggestive of a composition of distinct or unlike elements or qualities, has served to mitigate error in modern computer systems for decades, going back at least as far as the 1971 JPL STAR (self testing and repairing) system, designed and built in the Spacecraft Computers Section of the Jet Propulsion Laboratory Astrionics Division [2]. In that context the concept of diversity was termed redundancy. In computer security, diversity is being contemplated as an approach toward mitigating security breaches, or what might be regarded as errors in security. The panel contemplates various issues regarding diversity and security, and this panelist in particular raises a number of questions whose answers may prove valuable at such time as they become available. Until then, perhaps these questions will serve to provoke thoughtful research directions. Roy A. Maxion |
NSPW | 1 |
| 2005 | Improving user-interface dependability through mitigation of human error
Roy A. Maxion, Robert W. Reeder |
Int. J. Hum. Comput. Stud. | 1 |
| 2004 | A Defense-Centric Taxonomy Based on Attack ManifestationsabstractMany classifications of attacks have been tendered, often in taxonomic form, A common basis of these taxonomies is that they have been framed from the perspective of an attacker - they organize attacks with respect to the attacker's goals, such as privilege elevation from user to root (from the well known Lincoln taxonomy). Taxonomies based on attacker goals are attack-centric; those based on defender goals are defense-centric. Defenders need a way of determining whether or not their detectors will detect a given attack. It is suggested that a defense-centric taxonomy would suit this role more effectively than an attack-centric taxonomy. This paper presents a new, defense-centric attack taxonomy, based on the way that attacks manifest as anomalies in monitored sensor data. Unique manifestations, drawn from 25 attacks, were used to organize the taxonomy, which was validated through exposure to an intrusion-detection system, confirming attack detect ability. The taxonomy's predictive utility was compared against that of a well-known extant attack-centric taxonomy. The defense-centric taxonomy is shown to be a more effective predictor of a detector's ability to detect specific attacks, hence informing a defender that a given detector is competent against an entire class of attacks. Kevin S. Killourhy, Roy A. Maxion, Kymie M. C. Tan |
DSN | 2 |
| 2004 | Masquerade detection augmented with error analysisabstractA masquerade attack, in which one user impersonates another, may be one of the most serious forms of computer abuse. Automatic discovery of masqueraders is sometimes undertaken by detecting significant departures from normal user behavior, as represented by a user profile formed from system audit data. A major obstacle for this type of research is the difficulty in obtaining such system audit data, largely due to privacy concerns. An immense contribution in this regard has been made by Schonlau et al., who have made available UNIX command-line data from 50+ users collected over a number of months. Most of the research in this area has made use of this dataset, so this paper takes as its point of departure the Schonlau et al. dataset and a recent series of experiments with this data framed by the same researchers . In extending that work with a new classification algorithm, a 56% improvement in masquerade detection was achieved at a corresponding false-alarm rate of 1.3%. In addition, encouraging results were obtained at a more realistic sequence length of 10 commands (as opposed to sequences of 100 commands used by Schonlau et al.). A detailed error analysis, based on an alternative configuration of the same data, reveals a serious flaw in this type of data which hinders masquerade detection and indicates some steps that need to be taken to improve future results. The error analysis also demonstrates the insights that can be gained by inspecting decision errors, instead of concentrating only on decision successes. Roy A. Maxion, Tahlia N. Townsend |
IEEE Trans. Reliab. | 1 |
| 2003 | Masquerade Detection Using Enriched Command LinesabstractA masquerade attack, in which one user impersonates another, is among the most serious forms of computer abuse, largely because such attacks are often mounted by insiders, and can be very difficult to detect. Automatic discovery of masqueraders is sometimes undertaken by detecting significant departures from normal user behavior, as represented by user profiles based on users ’ command histories. A series of experiments performed by Schonlau et al. [12] achieved moderate success in masquerade detection based on a data set comprised of truncated command lines, i.e., single commands, stripped of any accompanying flags, arguments or elements of shell grammar such as pipes or semi-colons. Using the same data, Maxion and Townsend [8] improved on the Schonlau et al. results by 56%, raising the detection rate from 39.4 % to 61.5 % at false-alarm rates near 1%. The present paper extends this work by testing the hypothesis that a limitation of these approaches is the use of truncated command-line data, as opposed to command lines enriched with flags, shell grammar, arguments and information about aliases. Enriched command lines were found to facilitate correct detection at the 82 % level, far exceeding previous results, with a corresponding 30% reduction in the overall cost of errors, and only a small increase in false alarms. Descriptions of pathological cases illustrate strengths and limitations of both the data and the detection algorithm. 1. Roy A. Maxion |
DSN | 1 |
| 2003 | Determining the operational limits of an anomaly-based intrusion detectorabstractAnomaly-detection techniques have considerable promise for two difficult and critical problems in information security and intrusion detection: detecting novel attacks, and detecting masqueraders. One of the best-known anomaly detectors used in intrusion detection is stide. (Rather than STIDE or Stide or s-tide, we have chosen "stide" in keeping with the way the detector was referred to in the paper by Warrender et al., 1999.) Developed at the University of New Mexico, stide aims to detect attacks that exploit processes that run with root privileges. The original work on stide presented empirical results indicating that data sequences of length six and above were required for effective intrusion detection. This observation has given rise to the long-standing question, "why six?" accompanied by related questions regarding the conditions under which six may (not) be appropriate. This paper addresses the "why six" issue by presenting an evaluation framework for mapping out stide's effective operating space and by identifying conditions that contribute to detection capability, particularly detection blindness. A theoretical justification explains the effectiveness of sequence lengths of six and above, as well as the consequences of using other values. In addition, results of an investigation are presented, comparing stide's anomaly-detection capabilities with those of a competing detector. Kymie M. C. Tan, Roy A. Maxion |
IEEE J. Sel. Areas Commun. | 2 |
| 2002 | Masquerade Detection Using Truncated Command LinesabstractA masquerade attack, in which one user impersonates another, can be the most serious form of computer abuse. Automatic discovery of masqueraders is sometimes undertaken by detecting significant departures from normal user behavior, as represented by a user profile formed from system audit data. While the success of this approach has been limited, the reasons for its unsatisfying performance are not obvious, possibly because most reports do not elucidate the origins of errors made by the detection mechanisms. This paper takes as its point of departure a recent series of experiments framed by Schonlau et al. (2001). In extending that work with a new classification algorithm, a 56% improvement in masquerade detection was achieved at a corresponding false-alarm rate of 1.3%. A detailed error analysis, based on an alternative data configuration, reveals why some users are good masqueraders and others are not. Roy A. Maxion, Tahlia N. Townsend |
DSN | 1 |
| 2002 | Undermining an Anomaly-Based Intrusion Detection System Using Common Exploits
Kymie M. C. Tan, Kevin S. Killourhy, Roy A. Maxion |
RAID | 3 |
| 2002 | "Why 6?" Defining the Operational Limits of Stide, an Anomaly-Based Intrusion DetectorabstractAnomaly-detection techniques have considerable promise for two difficult and critical problems in information security and intrusion detection: detecting novel attacks, and detecting masqueraders. One of the best-known anomaly detectors used in intrusion detection is stide. Developed at the University of New Mexico, stide aims to detect attacks that exploit processes that run with root privileges. The original work on stide presented empirical results indicating that data sequences of length six and above were required for effective intrusion detection. This observation has given rise to the long-standing question, "why six?" accompanied by related questions regarding the conditions under which six may or may not be appropriate. This paper addresses the "why six" issue by presenting an evaluation framework that maps out stide's effective operating space, and identifies the conditions that contribute to detection capability, particularly detection blindness. A theoretical justification explains the effectiveness of sequence lengths of six and above, as well as the consequences of using other values. In addition, results of an investigation are presented, comparing stide's anomaly-detection capabilities with those of a competing detector. Kymie M. C. Tan, Roy A. Maxion |
S&P | 2 |
| 2002 | Anomaly Detection in Embedded SystemsabstractBy employing fault tolerance, embedded systems can withstand both intentional and unintentional faults. Many fault tolerance mechanisms are invoked only after a fault has been detected by whatever fault-detection mechanism is used; hence, the process of fault detection must itself be dependable if the system is expected to be fault-tolerant. Many faults are detectable only indirectly as a result of performance disorders that manifest as anomalies in monitored system or sensor data. Anomaly detection, therefore, is often the primary means of providing early indications of faults. As with any other kind of detector, one seeks full coverage of the detection space with the anomaly detector being used. Even if coverage of a particular anomaly detector falls short of 100%, detectors can be composed to effect broader coverage, once their respective sweet spots and blind regions are known. This paper provides a framework and a fault-injection methodology for mapping an anomaly detector's effective operating space and shows that two detectors, each designed to detect the same phenomenon, may not perform similarly, even when the event to be detected is unequivocally anomalous and should be detected by either detector. Both synthetic and real-world data are used. Roy A. Maxion, Kymie M. C. Tan |
IEEE Trans. Computers | 1 |
| 2001 | Markov Chains, Classifiers, and Intrusion DetectionabstractAbstract: This paper presents a statistical anomaly detection algorithm based on Markov chains. Our algorithm can be directly applied for intrusion detection by discovering anomalous activities. Our framework for constructing anomaly detectors is very general and can be used by other researchers for constructing Markov-chain-based anomaly detectors. We also present performance metrics for evaluating the effectiveness of anomaly detectors. Extensive experimental results clearly demonstrate the effectiveness of our algorithm. We discuss several future directions for research based on the framework presented in this paper. Somesh Jha, Kymie M. C. Tan, Roy A. Maxion |
CSFW | 3 |
| 2000 | Benchmarking Anomaly-Based Detection SystemsabstractAnomaly detection is a key element of intrusion detection and other detection systems in which perturbations of normal behavior suggest the presence of intentionally or unintentionally induced attacks, faults, defects, etc. Because most anomaly detectors are based on probabilistic algorithms that exploit the intrinsic structure (or regularity) embedded in data logs, a fundamental question is whether or not such structure influences detection performance. If detector performance is indeed a function of environmental regularity, it would be critical to match detectors to environmental characteristics. In intrusion-detection settings, however, this is not done, possibly because such characteristics are not easily ascertained. This paper introduces a metric for characterizing structure in data environments, and tests the hypothesis that intrinsic structure influences probabilistic detection. In a series of experiments, an anomaly detection algorithm was applied to a benchmark suite of 165 carefully calibrated, anomaly-injected data sets of varying structure. The results showed performance differences of as much as an order of magnitude, indicating that current approaches to anomaly detection may not be universally dependable. Roy A. Maxion, Kymie M. C. Tan |
DSN | 1 |
| 2000 | Eliminating Exception Handling Errors with Dependability Cases: A Comparative, Empirical StudyabstractPrograms fail mainly for two reasons: logic errors in the code and exception failures. Exception failures can account for up to two-thirds of system crashes, hence, are worthy of serious attention. Traditional approaches to reducing exception failures, such as code reviews, walkthroughs, and formal testing, while very useful, are limited in their ability to address a core problem: the programmer's inadequate coverage of exceptional conditions. The problem of coverage might be rooted in cognitive factors that impede the mental generation (or recollection) of exception cases that would pertain in a particular situation, resulting in insufficient software robustness. This paper describes controlled experiments for testing the hypothesis that robustness for exception failures can be improved through the use of various coverage-enhancing techniques: N-version programming, group collaboration, and dependability cases. N-version programming and collaboration are well known. Dependability cases, derived from safety cases, comprise a new methodology based on structured taxonomies and memory aids for helping software designers think about and improve exception handling coverage. All three methods showed improvements over control conditions in increasing robustness to exception failures but dependability cases proved most efficacious in terms of balancing cost and effectiveness. Roy A. Maxion, Robert T. Olszewski |
IEEE Trans. Software Eng. | 1 |
| 1993 | Fault Detection in an Ethernet Network Using Anomaly Signature MatchingabstractIn an Ethernet network, a common type of failure is the temporary of extended loss of bandwidth, or soft failure as it is referred to in the literature. Though the causes of soft failures vary, to the network user such failures are perceived as noticeably degraded or anomalous performance.This work uses anomaly detection as a means to signal performance degradations that are indicative of network soft failures. Detection is done via a signature matching mechanism, call a fault feature vector, which will detect the occurrence of a fault by looking for anomaly conditions particular to the fault. In a two-year study of the Carnegie Mellon University Computer Science Network the fault feature vector mechanism proved effective in detecting faults and discriminating between faults types. This mechanism was also effective at abstracting large amounts of network data to only those events which warranted operator attention; in this two-year study, over 32 million monitored data points were reduced to under a two hundred event matchings. Frank Feather, Daniel P. Siewiorek, Roy A. Maxion |
SIGCOMM | 3 |
| 1989 | Expert system design for symptom based diagnosis in local area networks
Perfecto Mariño Espiñeira, Roy A. Maxion |
Microprocessing and Microprogramming | 2 |