This paper presents ARGOS, the first system that can automatically uncover the semantics of kernel objects directly from a kernel binary. Based on the principle of data use reveal...
Abstract. Software systems are often engineered and tested for functionality under normal rather than worst-case conditions. This makes the systems vulnerable to denial of service ...
Abstract. Program anomaly detection analyzes normal program behaviors and discovers aberrant executions caused by attacks, misconfigurations, program bugs, and unusual usage patte...
Xiaokui Shu, Danfeng (Daphne) Yao, Barbara G. Ryde...
Recent work demonstrated hardware-based online malware detection using only low-level features. This detector is envisioned as a first line of defense that prioritizes the applica...
Khaled N. Khasawneh, Meltem Ozsoy, Caleb Donovick,...
In this paper, we present the design and implementation of Haetae, a high-performance Suricata-based NIDS on many-core processors (MCPs). Haetae achieves high performance with thre...
Jaehyun Nam, Muhammad Jamshed, Byungkwon Choi, Don...