Jeffrey Fairbanks

dblp:311/1952 · DBLP profile ↗
← Back
3ranked-venue papers in the field
3as first author
3since 2021 · last 2025
0009-0007-6079-4868ORCID · corroborated

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 3 (3 first)
YearPublicationVenuePosition
2025 Reflective Beam Search for Automated TTP Extraction and Sigma Rule Generation from Cyber Threat Intelligence
Jeffrey Fairbanks, Edoardo Serra
IEEE Big Data1
2024 Generating Phishing Attacks and Novel Detection Algorithms in the Era of Large Language Models
abstract
Phishing is a significant cybersecurity threat, with the financial impact of email security breaches and lack of awareness estimated to be between $50-100 billion in 2022. The advent of Large Language Models (LLMs) has further automated and intensified phishing attacks, posing greater challenges for defenders, especially large organizations being targeted by Advanced Persistent Threats (APT) at scale, such as Department of Energy National Labs. This study presents the development of two innovative algorithms. The first algorithm improves the efficacy of phishing attacks, while the second algorithm counteracts and defends against phishing attacks that leverage LLMs. The attack method takes detectable malicious phishing emails and rewrites them using an innovative LLM-based automatic output optimization technique, which includes Reflection and Beam Search, while preserving the original semantic meaning and Indicators Of Compromise (IOC). This approach bypasses most-commonly used institutional security tools, NLP and other LLM phishing detection systems. The results indicate that this attack algorithm increases the success rate of phishing attacks by up to 98%. The defensive algorithm presented in this research is also employed for defensive measures. When the proposed defensive algorithm is applied, it identifies malicious emails with 97% greater accuracy. The research detailed in this paper demonstrates that these algorithm serve dual purposes: one is utilized as an attack mechanism by altering the output, and the other as a defensive measure against phishing attacks by modifying the defensive prompt. Taking these algorithms and implementing them in the Department of Energy Laboratory (DOE) has demonstrated the effectiveness of applying these approaches to real world applications, and has been implemented into large-scale production environments.
Jeffrey Fairbanks, Edoardo Serra
IEEE Big Data1
2021 Identifying ATT&CK Tactics in Android Malware Control Flow Graph Through Graph Representation Learning and Interpretability
abstract
To mitigate a malware threat it is important to understand the malware’s behavior. The MITRE ATT&ACK ontology specifies an enumeration of tactics, techniques, and procedures (TTP) that characterize malware. However, absent are automated procedures that would characterize, given the malware executable, which part of the execution flow is connected with a specific TTP. This paper is the first in providing an automation methodology to locate TTP in a sub-part of the control flow graph that describes the execution flow of a mal-ware executable. This methodology merges graph representation learning and tools for machine learning explanation.
Jeffrey Fairbanks, Andres Orbe, Christine Patterson, Janet Layne, Edoardo Serra, Marion Scheepers
IEEE BigData1