Custom Query (1408 matches)
Results (40 - 42 of 1408)
Ticket | Resolution | Summary | Owner | Reporter |
---|---|---|---|---|
#1254 | fixed | ARCCN Demorpheus: Shellcode Detection in High-Speed Network Channels | ||
Description |
ARCCN demo for Gaivoronsky. In this presentation we propose an approach and hybrid shellcode detection method, aimed at early detection and filtering of unknown 0-days exploits at the network level. The proposed approach allows us to summarize capabilities of shellcode detection algorithms developed over the last ten years into an optimal classifier. The proposed approach allows us to reduce total false-positives rate to almost zero, provides full coverage of shellcode classes detected by individual classifiers, and significantly increases total throughput of detectors. Evaluation with shellcode datasets, including Metasploit Framework plain-text, encrypted and obfuscated shellcodes, benign Windows and Linux binaries, random (normal) data and multimedia shows that hybrid data-flow classifier significantly boosts analysis throughput for benign data - up to 45 times faster than linear combination of classifiers, and almost 1.5 times faster for shellcode datasets. We also give a tool demonstration.
1 laptop, 1 monitor
1
1
none
|
|||
#1438 | invalid | ARCCN: Key Research Findings | ||
Description |
One-sentence layman's description:
PI Ruslan Smeliansky of ARCCN is sole demo attendee. Request made by Vitaly Antonenko on Ruslan's behalf. |
|||
#1252 | fixed | ARCCN Network Prototype Simulator | ||
Description |
ARCCN demo for Antonenko. Network Prototyping Simulator is a simulation system that expands Mininet network emulator to computer cluster. That allow us to reproduce the network with such an amount of nodes that hardly was possible before. The maximum size of network topology in NPS depends on number of cluster nodes with Mininet instances. One cluster node can emulate more than thousand hosts, and an modern server could execute at least 15 cluster nodes packed in virtual machines. As the result, we get about 15 thousands hosts per server. The scalability of NPS makes it possible to emulate really big networks. By the architecture, NPS saves features of Mininet, so it does not become a clear simulation system, it remains a network prototyping system. Means one could trust the results of such simulation and there is no need to prove correctness and adequacy of the model built.
1 laptop, 1 monitor
1
1
1
|