Security Applications of the Ε-machine Acknowledgments for Their Endless Patience and Encouragement, I'd like to Thank My past and Present Advisors

نویسندگان

  • Jim Crutchfield
  • Felix Wu
  • John Mahoney
  • Chris Ellison
چکیده

The field of computational mechanics applies ideas from statistical mechanics, information theory, automata theory, and machine learning to create minimally-sized, optimal predictors of stochastic processes. These predictors, called ε-machines, are a subset of a well known statistical model class called the Hidden Markov Model (HMM). Despite being a subset, ε-machines have several important advantages over traditional HMMs. This dissertation illustrates these advantages by applying ε-machines to several problems in computer security: anomaly-based intrusion detection in High Performance Computing (HPC) environments, automated protocol reverse engineering, and structural drift. Intrusion detection systems (IDSs) detect attacks on computer systems at the host or network level. IDS research is largely ad hoc, and often produces systems that cannot generalize to new attacks or raise prohibitive amounts of alerts. Our first application attempts to address these shortcomings for HPC environments. We construct ε-machine classifiers from the communication patterns of cluster nodes, as well as hardware counters including floating point and integer operation counts. We find these features are sufficient for accurate classification of parallel computation as well as detection of anomalous behavior. Next, consider computers on a network exchanging data using some protocol whose specification is unknown—for example, a botnet command and control channel. Our work in automated protocol reverse engineering constructs a protocol ε-machine using only observed network traffic. The ε-machine captures both the topological and probabilistic structure of the protocol and is used for anomaly detection, traffic generation, and fuzzing without requiring access to binaries or source code. Finally, we introduce a model of sequential inference to study the propagation of errors in chains of ε-machine learners. This model, called structural drift, is a generalization of memoryless drift models found in the field of population dynamics. We examine the drift of mem-

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Program Analysis Techniques for Self-Similar Parallel Programs

Acknowledgments There are a number of people I'd like to thank for their help and encouragement during my time at the University of Minnesota in general, and during the preparation of this thesis in particular. I apologize in advance if I've missed anyone (you probably know who you are). First, I'd like to thank my wife, Merry Sawdey for putting up with five years of graduate school, for the el...

متن کامل

Effects of Resting State on Perceptual Learning

DEDICATION ~~~ This work is dedicated to my brother Stephen Alwin (1986-2010) who lives on in reactivations of networks in my brain. ~~~ iv ACKNOWLEDGEMENTS I would like to acknowledge the following people for their support and influence over the years: A doctoral program requires patient family members and for that I'm very thankful for the patience and support of my husband David Eagleman. I'...

متن کامل

Holistic confidentiality in open networks

Diese Dissertation ist auf den Internetseiten der Hochschulbibliothek online verfügbar. This work was created with the help and support of many helpful and kind people. Representative for all, I'd like to thank my wife for her endless patience. Thank you.

متن کامل

Segmental discriminative analysis for American Sign Language recognition and verification

who made all of this possible, for their endless encouragement and patience. iii ACKNOWLEDGEMENTS I owe special thanks to many people, whose support and help were indispensable in completing this thesis. First, I would like to thank my advisors, Dr. and Dr. Jim Rehg, for their thorough guidance of my research and many aspects of my life as a foreign student in this country. The thoughtful discu...

متن کامل

The Complexity of Extended Formulations

Tyger Tyger, burning bright, In the forests of the night; What immortal hand or eye, Could frame thy fearful symmetry? William Blake To Mom and Dad. ACKNOWLEDGMENTS First I would like to thank my parents. I dedicate this work to my dad, the first PhD in the family, and to my mom, who may be the only person who never doubted I could get there too. I could fill another thesis with what you both h...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010