EDBT 2026 Demo / reviewers in the wild / expert
Xinming Ou
dblp:41/4686 · also Xinming Simon Ou
· DBLP profile ↗
39ranked-venue papers
3as first author
3since 2021 · last 2024
0009-0007-2501-7991ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 4Software engineering, systems software and programming languages · 4Systems, architecture and hardware · 3Human-computer interaction and ubiquitous computing · 3Databases, data management, data science and information retrieval · 2Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | ACM CCS 2024 Doctoral SymposiumabstractACM CCS started Doctoral Symposium in 2024 to provide PhD students who are in the middle of their dissertation research an opportunity to present their work to the broader research community and get feedback. We briefly describe the design of the first CCS Doctoral Symposium, the rationale, and the submission/acceptance status. Gabriela F. Ciocarlie, Xinming Ou |
CCS | 2 |
| 2023 | Revealing Human Attacker Behaviors Using an Adaptive Internet of Things Honeypot Ecosystem
Armin Ziaie Tabari, Xinming Ou, Anoop Singhal |
IFIP Int. Conf. Digital Forensics | 3 |
| 2023 | Towards Optimal Triage and Mitigation of Context-Sensitive Cyber VulnerabilitiesabstractCyber vulnerabilities are security deficiencies in computer and network systems of organizations, which can be exploited by an adversary to cause significant damage. The technology and security personnel resources currently available in organizations to mitigate the vulnerabilities are highly inadequate. As a result, systems routinely remain unpatched, thus making them vulnerable to security breaches from the adversaries. The potential consequences of an exploited vulnerability depend upon the context as well as the severity of the vulnerability, which may differ among networks and organizations. Furthermore, security personnel tend to have varying levels of expertise and technical proficiencies associated with different computer and network devices. There exists a critical need to develop a resource-constrained approach for effectively identifying and mitigating important context-sensitive cyber vulnerabilities. In this article, we develop an advanced analytics and optimization framework to address this need and compare our approach with rule-based methods employed in real-world cybersecurity operations centers, as well as a vulnerability prioritization method from recent literature. First, we propose a machine learning-based vulnerability priority scoring system (VPSS) to calculate the priority scores for each of the vulnerabilities found in an organization’s network and quantify organizational context-based vulnerability exposure. Next, we propose a decision-support system, which consists of a two-step sequential optimization approach. The first model selects the high priority vulnerability instances from the dense report subject to resource constraints, and the second model then optimally allocates them to the security personnel with matching skill types for mitigation. Experiment results conducted using a real-world vulnerability data set show that our approach 1) outperforms both the rule-based methods and the vulnerability prioritization method from literature in prioritizing context-sensitive vulnerabilities, which are found across highly susceptible organizationally relevant host machines, and 2) maximizes the pairs of vulnerability instance type and the respective security analyst skill type for optimal mitigation. Soumyadeep Hore, Fariha Moomtaheen, Ankit Shah 0002, Xinming Ou |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | A Multi-phased Multi-faceted IoT Honeypot EcosystemabstractThe rapid growth of Internet of Things (IoT) devices makes it vitally important to understand real-world cybersecurity threats to them. Traditionally, honeypots have been used as decoys to mimic real devices on a network and help researchers/organizations understand the dynamic of threats. A crucial condition for a honeypot to yield useful insights is to let attackers believe they are real systems used by humans and organizations. However, IoT devices pose unique challenges in this respect, due to the large variety of device types and the physical-connectedness nature. In this work, we (1) presented an approach to create a multi-phased multi-faceted honeypot ecosystem, where researchers gradually increase the sophistication of a low-interaction IoT honeypot by observing real-world attackers' behaviors, (2) built a low-interaction honeypot for IoT cameras that allowed researchers to gain a concrete understanding of what attackers were going after on IoT camera devices, and (3) designed a proxy instance, called ProxyPot, that sits between IoT devices and the external network and helps researchers study the IoT devices' inbound/outbound communication. We used PorxyPot as a means to understanding attacks against IoT cameras and increasing the honeypot's sophistication. We deployed honeypots for more than two years. Our preliminary results showed that we were able to attract increasingly sophisticated attack data in each new phase. Moreover, we captured activities that appeared to involve direct human interactions rather than purely automated scripts. Armin Ziaie Tabari, Xinming Ou |
CCS | 2 |
| 2020 | GPU-Based Static Data-Flow Analysis for Fast and Scalable Android App VettingabstractMany popular vetting tools for Android applications use static code analysis techniques. In particular, Interprocedural Data-Flow Graph (IDFG) construction is the computation at the core of Android static data-flow analysis and consumes most of the analysis time. Many analysis tools use a worklist algorithm, an iterative fixed-point approach, to construct the IDFG. In this paper, we observe that a straightforward GPU parallelization of the worklist algorithm leads to significant underutilization of the GPU resources. We identify four performance bottlenecks, namely, frequent dynamic memory allocations, high branch divergence, workload imbalance, and irregular memory access patterns. Accordingly, we propose GDroid, a GPU-based worklist algorithm implementation with multiple fine-grained optimizations tailored to common characteristics of Android applications. The optimizations considered are: matrix-based data structure, memory access-based node grouping, and worklist merging. Our experimental evaluation, performed on 1000 Android applications, shows that the proposed optimizations are beneficial to performance, and GDroid can achieve up to 128X speedups against a plain GPU implementation. Xiaodong Yu 0001, Fengguo Wei, Xinming Ou, Michela Becchi, Tekin Bicer, Danfeng Yao |
IPDPS | 3 |
| 2019 | Topology-Aware Hashing for Effective Control Flow Graph Similarity Analysis
Jiyong Jang, Xinming Ou |
SecureComm (1) | 3 |
| 2018 | JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeabstractAndroid allows application developers to use native language (C/C++) to implement a part or the complete program. Recent research and our own statistics show that native payloads are commonly used in both benign and malicious apps. Current state-of-the-art Android static analysis tools, such as Amandroid, FlowDroid, DroidSafe, IccTA, and CHEX avoid handling native method invocation and apply conservative models for their data-flow behavior. None of those tools have capability to capture the inter-language dataflow. We propose a new approach to conduct inter-language dataflow analysis for security vetting of Android apps, and build an analysis framework, called JN-SAF to compute flow and context-sensitive inter-language points-to information in an efficient way. We show that: 1) Precise and efficient inter-language dataflow analysis is completely feasible with support of a summary-based bottom-up dataflow analysis (SBDA) algorithm, 2) A comprehensive model of Java Native Interface (JNI) and Native Development Kit (NDK) for binary analysis is essential as none of the existing binary analysis frameworks is able to handle Android binaries, 3) JN-SAF is capable of capturing inter-language security issues in real-world Android apps as demonstrated by our evaluation result. Fengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen 0002, Xiaosong Zhang 0001 |
CCS | 3 |
| 2018 | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android
Yaohui Chen 0001, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang 0004, Xinming Ou |
NDSS | 7 |
| 2018 | A Population-Based Incremental Learning Approach to Network HardeningabstractEnterprise networks constantly face new security challenges. Obtaining complete network security is almost impossible, especially when usability requirements are taken into account. Previous research has provided ways to identify multi-stage attacks caused by network vulnerabilities and misconfigurations, but few have addressed ways to circumvent those multi-stage attacks, especially when usability requirements are taken into account. The latter problem is reckoned as Network Hardening problem [10] and is known to be an NP hard combinatorial problem. In this paper, we map the network hardening problem to a constrained optimization problem and resort to the theory of Population-Based Incremental Learning (PBIL) in order to solve it. We devise two approaches based on the PBIL, namely the Acceptance-Rejection approach, and the Penalty-based approach. Our aim is to tighten the security of the network by minimizing the number of privileges that an attacker can gain over network under some usability constraints measured in terms of the number of configurations in a network that can be activated or cannot be deactivated. The Acceptance-Rejection approach disqualifies configurations that violate the usability constraint while the Penalty-based approach relaxes the latter constraint by attempting to find a compromise between security and usability of the configuration. While the Acceptance-Rejection approach can be seen as a simple alternative to the state of the art MinCostSAT solution adopted in [10], the Penalty-based approach is, to the best of our knowledge, the first solution in the literature that tries to find such compromise. Experimental results show that the devised approaches are computationally efficient, scalable and reliable. Alexander Paulsen, Anis Yazidi, Boning Feng, Xinming Ou |
SoMeT | 4 |
| 2018 | Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android AppsabstractWe present a new approach to static analysis for security vetting of Android apps and a general framework called Amandroid. Amandroid determines points-to information for all objects in an Android app component in a flow and context-sensitive (user-configurable) way and performs data flow and data dependence analysis for the component. Amandroid also tracks inter-component communication activities. It can stitch the component-level information into the app-level information to perform intra-app or inter-app analysis. In this article, (a) we show that the aforementioned type of comprehensive app analysis is completely feasible in terms of computing resources with modern hardware, (b) we demonstrate that one can easily leverage the results from this general analysis to build various types of specialized security analyses—in many cases the amount of additional coding needed is around 100 lines of code, and (c) the result of those specialized analyses leveraging Amandroid is at least on par and often exceeds prior works designed for the specific problems, which we demonstrate by comparing Amandroid’s results with those of prior works whenever we can obtain the executable of those tools. Since Amandroid’s analysis directly handles inter-component control and data flows, it can be used to address security problems that result from interactions among multiple components from either the same or different apps. Amandroid’s analysis is sound in that it can provide assurance of the absence of the specified security problems in an app with well-specified and reasonable assumptions on Android runtime system and its library. Fengguo Wei, Sankardas Roy, Xinming Ou, Robby |
ACM Trans. Priv. Secur. | 3 |
| 2017 | Android Malware Detection with Weak Ground Truth DataabstractFor Android malware detection, precise ground truth is a rare commodity. As security knowledge evolves, what may be considered ground truth at one moment in time may change, and apps once considered benign may turn out to be malicious. The inevitable noise in data labels poses a challenge to inferring effective machine learning classifiers. Our work is focused on approaches for learning classifiers for Android malware detection in a manner that is methodologically sound with regard to the uncertain and ever-changing ground truth in the problem space. We leverage the fact that although data labels are unavoidably noisy, a malware label is much more precise than a benign label. While you can be confident that an app is malicious, you can never be certain that a benign app is really benign, or just undetected malware. Based on this insight, we leverage a modified Logistic Regression classifier that allows us to learn from only positive and unlabeled data, without making any assumptions about benign labels. We find Label Regularized Logistic Regression to perform well for noisy app datasets, as well as datasets where there is a limited amount of positive labeled data, both of which are representative of real-world situations. Jordan DeLoach, Doina Caragea, Xinming Ou |
AAAI | 3 |
| 2017 | MTD 2017: Fourth ACM Workshop on Moving Target Defense (MTD)abstractThe fourth ACM Workshop on Moving Target Defense (MTD) is held in Dallas, Texas, USA on October 30, 2017, co-located with the 24th ACM Conference on Computer and Communications Security (CCS). The main objective of the workshop is to discuss novel randomization, diversification, and dynamism techniques for computer systems and networks, new metric and analysis frameworks to assess and quantify the effectiveness of MTD, and discuss challenges and opportunities that such defenses provide. We have constructed an exciting and diverse program of nine refereed papers and two invited keynote talks that will provide the participant with a vibrant and thought-provoking set of ideas and insights. Hamed Okhravi, Xinming Ou |
CCS | 2 |
| 2017 | Deep Ground Truth Analysis of Current Android Malware
Fengguo Wei, Sankardas Roy, Xinming Ou |
DIMVA | 4 |
| 2017 | MTD CBITS: Moving Target Defense for Cloud-Based IT Systems
Alexandru G. Bardas, Sathya Chandran Sundaramurthy, Xinming Ou, Scott A. DeLoach |
ESORICS (1) | 3 |
| 2017 | Android Malware Clustering Through Malicious Payload Mining
Jiyong Jang, Xin Hu 0001, Xinming Ou |
RAID | 4 |
| 2016 | Android malware detection with weak ground truth dataabstractFor Android malware detection, precise ground truth is a rare commodity. As security knowledge evolves, what may be considered ground truth at one moment in time may change, and apps once considered benign turn out to be malicious. The inevitable noise in data labels poses a challenge to creating effective machine learning models. Our work is focused on approaches for learning classifiers for Android malware detection in a manner that is methodologically sound with regard to the uncertain and ever-changing ground truth in the problem space. We leverage the fact that although data labels are unavoidably noisy, a malware label is much more precise than a benign label. While you can be confident that an app is malicious, you can never be certain that a benign app is really benign or just an undetected malware. Based on this insight, we leverage a modified Logistic Regression classifier that allows us to learn from only positive and unlabeled data, without making any assumptions about benign labels. We find Label Regularized Logistic Regression to perform well for noisy app datasets, as well as datasets where there is a limited amount of positive labeled data, both of which are representative of real-world situations. Jordan DeLoach, Doina Caragea, Xinming Ou |
IEEE BigData | 3 |
| 2016 | Turning Contradictions into Innovations or: How We Learned to Stop Whining and Improve Security Operations
Sathya Chandran Sundaramurthy, John McHugh, Xinming Ou, Michael Wesch, Alexandru G. Bardas, S. Raj Rajagopalan |
SOUPS | 3 |
| 2016 | Security Optimization of Dynamic Networks with Probabilistic Graph Modeling and Linear ProgrammingabstractSecuring the networks of large organizations is technically challenging due to the complex configurations and constraints. Managing these networks requires rigorous and comprehensive analysis tools. A network administrator needs to identify vulnerable configurations, as well as tools for hardening the networks. Such networks usually have dynamic and fluidic structures, thus one may have incomplete information about the connectivity and availability of hosts. In this paper, we address the problem of statically performing a rigorous assessment of a set of network security defense strategies with the goal of reducing the probability of a successful large-scale attack in a dynamically changing and complex network architecture. We describe a probabilistic graph model and algorithms for analyzing the security of complex networks with the ultimate goal of reducing the probability of successful attacks. Our model naturally utilizes a scalable state-of-the-art optimization technique called sequential linear programming that is extensively applied and studied in various engineering problems. In comparison to related solutions on attack graphs, our probabilistic model provides mechanisms for expressing uncertainties in network configurations, which is not reported elsewhere. We have performed comprehensive experimental validation with real-world network configuration data of a sizable organization. Hussain M. J. Almohri, Layne T. Watson, Danfeng Yao, Xinming Ou |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2015 | Experimental Study with Real-world Data for Android App Security Analysis using Machine LearningabstractAlthough Machine Learning (ML) based approaches have shown promise for Android malware detection, a set of critical challenges remain unaddressed. Some of those challenges arise in relation to proper evaluation of the detection approach while others are related to the design decisions of the same. In this paper, we systematically study the impact of these challenges as a set of research questions (i.e., hypotheses). We design an experimentation framework where we can reliably vary several parameters while evaluating ML-based Android malware detection approaches. The results from the experiments are then used to answer the research questions. Meanwhile, we also demonstrate the impact of some challenges on some existing ML-based approaches. The large (market-scale) dataset (benign and malicious apps) we use in the above experiments represents the real-world Android app security analysis scale. We envision this study to encourage the practice of employing a better evaluation strategy and better designs of future ML-based approaches for Android malware detection. Sankardas Roy, Jordan DeLoach, Nic Herndon, Doina Caragea, Xinming Ou, Venkatesh Prasad Ranganath, Hongmin Li 0001, Nicolais Guevara |
ACSAC | 6 |
| 2015 | Practical Always-on Taint Tracking on Mobile Devices
Justin Paupore, Earlence Fernandes, Atul Prakash 0001, Sankardas Roy, Xinming Ou |
HotOS | 5 |
| 2015 | Assessing Attack Surface with Component-Based Package Dependency
Xinwen Zhang, Xinming Ou, Liqun Chen 0002, Nigel Edwards |
NSS | 3 |
| 2015 | A Human Capital Model for Mitigating Security Analyst Burnout
Sathya Chandran Sundaramurthy, Alexandru G. Bardas, Jacob Case, Xinming Ou, Michael Wesch, John McHugh, S. Raj Rajagopalan |
SOUPS | 4 |
| 2014 | Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android AppsabstractWe propose a new approach to conduct static analysis for security vetting of Android apps, and built a general framework, called Amandroid for determining points-to information for all objects in an Android app in a flow- and context-sensitive way across Android apps components. We show that: (a) this type of comprehensive analysis is completely feasible in terms of computing resources needed with modern hardware, (b) one can easily leverage the results from this general analysis to build various types of specialized security analyses -- in many cases the amount of additional coding needed is around 100 lines of code, and (c) the result of those specialized analyses leveraging Amandroid is at least on par and often exceeds prior works designed for the specific problems, which we demonstrate by comparing Amandroid's results with those of prior works whenever we can obtain the executable of those tools. Since Amandroid's analysis directly handles inter-component control and data flows, it can be used to address security problems that result from interactions among multiple components from either the same or different apps. Amandroid's analysis is sound in that it can provide assurance of the absence of the specified security problems in an app with well-specified and reasonable assumptions on Android runtime system and its library. Fengguo Wei, Sankardas Roy, Xinming Ou, Robby |
CCS | 3 |
| 2014 | After we knew it: empirical study and modeling of cost-effectiveness of exploiting prevalent known vulnerabilities across IaaS cloudabstractInfrastructure as a Service (IaaS) cloud has been attracting more and more customers as it provides the highest level of flexibility by offering configurable virtual machines (VMs) and computing infrastructures. Public VM images are usually available for customers to customize and launch. However, the 1 to N mapping between VM images and running instances in IaaS makes vulnerabilities propagate rapidly across the entire public cloud. Besides, IaaS cloud naturally comes with a larger and more stable attack surface and more concentrated target resources than traditional surroundings. In this paper, we first identify the threat of exploiting prevalent vulnerabilities over public IaaS cloud with an empirical study in Amazon EC2. We find that attackers can compromise a considerable number of VMs with trivial cost. We then do a qualitative cost-effectiveness analysis of this threat. Our main result is a two-fold observation: in IaaS cloud, exploiting prevalent vulnerabilities is much more cost-effective than traditional in-house computing environment, therefore attackers have stronger incentive; Fortunately, on the other hand, cloud defenders (cloud providers and customers) also have much lower cost-loss ratio than in traditional environment, therefore they can be more effective for defending attacks. We then build a game-theoretic model and conduct a risk-gain analysis to compare exploiting and patching strategies under cloud and traditional computing environments. Our modeling indicates that under cloud environment, both attack and defense become less cost-effective as time goes by, and the earlier actioner can be more rewarding. We propose countermeasures against such threat in order to bridge the gap between current security situation and defending mechanisms. To our best knowledge, we are the first to analyze and model the threat with prevalent known-vulnerabilities in public cloud. Xinwen Zhang, Xinming Ou |
AsiaCCS | 3 |
| 2014 | Compiling Abstract Specifications into Concrete Systems - Bringing Order to the Cloud
Ian Unruh, Alexandru G. Bardas, Rui Zhuang, Xinming Ou, Scott A. DeLoach |
LISA | 4 |
| 2013 | Aiding Intrusion Analysis Using Machine LearningabstractIntrusion analysis, i.e., the process of combing through IDS alerts and audit logs to identify real successful and attempted attacks, remains a difficult problem in practical network security defense. The major contributing cause to this problem is the high false-positive rate in the sensors used by IDS systems to detect malicious activities. The goal of our work is to examine whether a machine-learned classifier can help a human analyst filter out non-interesting scenarios reported by an IDS alert correlator, so that analysts' time can be saved. This research is conducted in the open-source SnIPS intrusion analysis framework. Throughout observing the output of SnIPS running on our departmental network, we found that an analyst would need to perform repetitive tasks in pruning out the false positives in the correlation graphs produced by it. We hypothesized that such repetitive tasks can yield (limited) labeled data that can enable the use of a machine learning-based approach to prune SnIPS' output based on the human analysts' feedback, much similar to spam filters that can learn from users' past judgment to prune emails. Our goal is to classify the correlation graphs produced from SnIPS into "interesting" and "non-interesting", where "interesting" means that a human analyst would want to conduct further analysis on the events. We spent significant amount of time manually labeling SnIPS' output correlations based on this criterion, and built prediction models using both supervised and semi-supervised learning approaches. Our experiments revealed a number of interesting observations that give insights into the pitfalls and challenges of applying machine learning in intrusion analysis. The experimentation results also indicate that semi-supervised learning is a promising approach towards practical machine learning-based tools that can aid human analysts, when a limited amount of labeled data is available. Loai Zomlot, Sathya Chandran Sundaramurthy, Doina Caragea, Xinming Ou |
ICMLA (2) | 4 |
| 2013 | Aggregating vulnerability metrics in enterprise networks using attack graphsabstractQuantifying security risk is an important and yet difficult task in enterprise network security management. While metrics exist for individual software vulnerabilities, there is currently no standard way of aggregating such metrics. We present a model that can be used to aggregate vulnerability metrics in an enterprise network, producing quantitative metrics that measure the likelihood breaches can occur within a given network configuration. A clear semantic model for this aggregation is an important first step toward a comprehensive network security metric model. We utilize existing work in attack graphs and apply probabilistic reasoning to produce an aggregation that has clear semantics and sound computation. We ensure that shared dependencies between attack paths have a proportional effect on the final calculation. We correctly reason over cycles, ensuring that privileges are evaluated without any self-referencing effect. We introduce additional modeling artifacts in our probabilistic graphical model to capture and account for hidden correlations among exploit steps. The paper shows that a clear semantic model for aggregation is critical in interpreting the results, calibrating the metric model, and explaining insights gained from empirical evaluation. Our approach has been rigorously evaluated using a number of network models, as well as data from production systems. John Homer, Xinming Ou, Yanhui Du, S. Raj Rajagopalan, Anoop Singhal |
J. Comput. Secur. | 3 |
| 2011 | Distilling critical attack graph surface iteratively through minimum-cost SAT solvingabstractIt has long been recognized that it can be tedious and even infeasible for system administrators to figure out critical security problems residing in full attack graphs, even for small-sized enterprise networks. Therefore a trade-off between analysis accuracy and efficiency needs to be made to achieve a reasonable balance between completeness of the attack graph and its usefulness. In this paper, we provide an approach to attack graph distillation, so that the user can control the amount of information presented by sifting out the most critical portion of the full attack graph. The user can choose to see only the k most critical attack paths, based on specified severity metrics, e.g. the likelihood for an attacker to carry out certain exploit on certain machine and the chance of success. We transform an dependency attack graph into a Boolean formula and assign cost metrics to attack variables in the formula, based on the severity metrics. We then apply Minimum-Cost SAT Solving (MCSS) to find the most critical path in terms of the least cost incurred for the attacker to deploy multi-step attacks leading to certain crucial assets in the network. An iterative process inspired by Counter Example Guided Abstraction and Refinement (CEGAR) is designed to efficiently guide the MCSS to render solutions that contain a controlled number of realistic attack paths, forming a critical attack graph surface. Our method can distill critical attack graph surfaces from the full attack graphs generated for moderate-sized enterprise networks in only several minutes. Experiments on various sized network scenarios show that even for a small-sized critical attack graph surface (around 15% the size of the original full attack graph), the calculated risk metrics are good approximation of the values computed with the full attack graph, meaning the distilled critical attack graph surface is able to capture the crucial security problems in an enterprise network for further in-depth analysis. Xinming Ou, Atul Prakash 0001, Karem A. Sakallah |
ACSAC | 3 |
| 2011 | An Empirical Study on Using the National Vulnerability Database to Predict Software Vulnerabilities
Doina Caragea, Xinming Ou |
DEXA (1) | 3 |
| 2011 | Effective Network Vulnerability Assessment through Model Abstraction
Xinming Ou, John Homer |
DIMVA | 2 |
| 2010 | Using Bayesian networks for cyber security analysisabstractCapturing the uncertain aspects in cyber security is important for security analysis in enterprise networks. However, there has been insufficient effort in studying what modeling approaches correctly capture such uncertainty, and how to construct the models to make them useful in practice. In this paper, we present our work on justifying uncertainty modeling for cyber security, and initial evidence indicating that it is a useful approach. Our work is centered around near real-time security analysis such as intrusion response. We need to know what is really happening, the scope and severity level, possible consequences, and potential countermeasures. We report our current efforts on identifying the important types of uncertainty and on using Bayesian networks to capture them for enhanced security analysis. We build an example Bayesian network based on a current security graph model, justify our modeling approach through attack semantics and experimental study, and show that the resulting Bayesian network is not sensitive to parameter perturbation. Jason H. Li, Xinming Ou, Peng Liu 0005, Renato Levy |
DSN | 3 |
| 2009 | An Empirical Approach to Modeling Uncertainty in Intrusion AnalysisabstractUncertainty is an innate feature of intrusion analysis due to the limited views provided by system monitoring tools, intrusion detection systems (IDS), and various types of logs. Attackers are essentially invisible in cyber space and monitoring tools can only observe the symptoms or effects of malicious activities. When mingled with similar effects from normal or non-malicious activities they lead intrusion analysis to conclusions of varying confidence and high false positive/negative rates. This paper presents an empirical approach to the problem of uncertainty where the inferred security implications of low-level observations are captured in a simple logical language augmented with certainty tags. We have designed an automated reasoning process that enables us to combine multiple sources of system monitoring data and extract highly-confident attack traces from the numerous possible interpretations of low-level observations. We have developed our model empirically: the starting point was a true intrusion that happened on a campus network that we studied to capture the essence of the human reasoning process that led to conclusions about the attack. We then used a Datalog-like language to encode the model and a Prolog system to carry out the reasoning process. Our model and reasoning system reached the same conclusions as the human administrator on the question of which machines were certainly compromised. We then automatically generated the reasoning model needed for handling Snort alerts from the natural-language descriptions in the Snort rule repository, and developed a Snort add-on to analyze Snort alerts. Keeping the reasoning model unchanged, we applied our reasoning system to two third-party data sets and one production network. Our results showed that the reasoning model is effective on these data sets as well. We believe such an empirical approach has the potential of codifying the seemingly ad-hoc human reasoning of uncertain events, and can yield useful tools for automated intrusion analysis. Xinming Ou, S. Raj Rajagopalan, Sakthiyuvaraja Sakthivelmurugan |
ACSAC | 1 |
| 2009 | SAT-solving approaches to context-aware enterprise network security managementabstractEnterprise network security management is a complex task of balancing security and usability, with trade-offs often necessary between the two. Past work has provided ways to identify intricate attack paths due to misconfiguration and vulnerabilities in an enterprise system, but little has been done to address how to correct the security problems within the context of various other requirements such as usability, ease of access, and cost of countermeasures. This paper presents an approach based on Boolean satisfiability solving (SAT solving) that can reason about attacks, usability requirements, cost of actions, etc. in a unified, logical framework. Preliminary results show that the approach is both effective and efficient. John Homer, Xinming Ou |
IEEE J. Sel. Areas Commun. | 2 |
| 2008 | Identifying Critical Attack Assets in Dependency Attack Graphs
Reginald E. Sawilla, Xinming Ou |
ESORICS | 2 |
| 2008 | Improving Attack Graph Visualization through Data Reduction and Attack Grouping
John Homer, Ashok Varikuti, Xinming Ou, Miles A. McQueen |
VizSEC | 3 |
| 2006 | A scalable approach to attack graph generationabstractAttack graphs are important tools for analyzing security vulnerabilities in enterprise networks. Previous work on attack graphs has not provided an account of the scalability of the graph generating process, and there is often a lack of logical formalism in the representation of attack graphs, which results in the attack graph being difficult to use and understand by human beings. Pioneer work by Sheyner, et al. is the first attack-graph tool based on formal logical techniques, namely model-checking. However, when applied to moderate-sized networks, Sheyner's tool encountered a significant exponential explosion problem. This paper describes a new approach to represent and generate attack graphs. We propose logical attack graphs, which directly illustrate logical dependencies among attack goals and configuration information. A logical attack graph always has size polynomial to the network being analyzed. Our attack graph generation tool builds upon MulVAL, a network security analyzer based on logical programming. We demonstrate how to produce a derivation trace in the MulVAL logic-programming engine, and how to use the trace to generate a logical attack graph in quadratic time. We show experimental evidence that our logical attack graph generation algorithm is very efficient. We have generated logical attack graphs for fully connected networks of 1000 machines using a Pentium 4 CPU with 1GB of RAM. Xinming Ou, Wayne F. Boyer, Miles A. McQueen |
CCS | 1 |
| 2005 | A Two-Tier Technique for Supporting Quantifiers in a Lazily Proof-Explicating Theorem Prover
K. Rustan M. Leino, Madan Musuvathi, Xinming Ou |
TACAS | 3 |
| 2005 | MulVAL: A Logic-based Network Security Analyzer
Xinming Ou, Sudhakar Govindavajhala, Andrew W. Appel |
USENIX Security Symposium | 1 |
| 2003 | Theorem Proving Using Lazy Proof Explication
Cormac Flanagan, Rajeev Joshi, Xinming Ou, James B. Saxe |
CAV | 3 |