DM
D. Mouwen
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
2 records found
1
Every day, Intrusion Detection Systems around the world generate huge amounts of data. This data can be used to learn attacker behaviour, such as Techniques, Tactics, and Procedures (TTPs). Attack Graphs (AGs) provide a visual way of describing these attack patterns. They can be generated without expert knowledge and vulnerability reports. The goal of AGs is to reduce alert fatigue, and to give another perspective on attacker behaviour.
SAGE, the state-of-the-art method for generating AGs uses FlexFringe's state merging algorithms to learn the underlying state machine to model these attacks. A big challenge of these state merging algorithms is learning infrequent behaviour. Next to that, the underlying state machines cannot deal with noisy input data.
In this work, a sequence-automaton alignment algorithm is used to align sequences of states to a state machine. Our method iteratively aligns infrequent sequences to the model, effectively learning both frequent and infrequent behaviour.
The method is evaluated on a security competition dataset, where experiments show that the algorithm is able to recover from noise such as added or removed events. The learned models are also reduced to half its original size, while better fitting to the training data.
Last, we show how our method can be used to learn the model of an anomaly detection dataset. The test data is predicted using three anomaly conditions, and results in all anomalous data being labelled correctly. The F1-score is competitive compared to other state of the art methods. ...
SAGE, the state-of-the-art method for generating AGs uses FlexFringe's state merging algorithms to learn the underlying state machine to model these attacks. A big challenge of these state merging algorithms is learning infrequent behaviour. Next to that, the underlying state machines cannot deal with noisy input data.
In this work, a sequence-automaton alignment algorithm is used to align sequences of states to a state machine. Our method iteratively aligns infrequent sequences to the model, effectively learning both frequent and infrequent behaviour.
The method is evaluated on a security competition dataset, where experiments show that the algorithm is able to recover from noise such as added or removed events. The learned models are also reduced to half its original size, while better fitting to the training data.
Last, we show how our method can be used to learn the model of an anomaly detection dataset. The test data is predicted using three anomaly conditions, and results in all anomalous data being labelled correctly. The F1-score is competitive compared to other state of the art methods. ...
Every day, Intrusion Detection Systems around the world generate huge amounts of data. This data can be used to learn attacker behaviour, such as Techniques, Tactics, and Procedures (TTPs). Attack Graphs (AGs) provide a visual way of describing these attack patterns. They can be generated without expert knowledge and vulnerability reports. The goal of AGs is to reduce alert fatigue, and to give another perspective on attacker behaviour.
SAGE, the state-of-the-art method for generating AGs uses FlexFringe's state merging algorithms to learn the underlying state machine to model these attacks. A big challenge of these state merging algorithms is learning infrequent behaviour. Next to that, the underlying state machines cannot deal with noisy input data.
In this work, a sequence-automaton alignment algorithm is used to align sequences of states to a state machine. Our method iteratively aligns infrequent sequences to the model, effectively learning both frequent and infrequent behaviour.
The method is evaluated on a security competition dataset, where experiments show that the algorithm is able to recover from noise such as added or removed events. The learned models are also reduced to half its original size, while better fitting to the training data.
Last, we show how our method can be used to learn the model of an anomaly detection dataset. The test data is predicted using three anomaly conditions, and results in all anomalous data being labelled correctly. The F1-score is competitive compared to other state of the art methods.
SAGE, the state-of-the-art method for generating AGs uses FlexFringe's state merging algorithms to learn the underlying state machine to model these attacks. A big challenge of these state merging algorithms is learning infrequent behaviour. Next to that, the underlying state machines cannot deal with noisy input data.
In this work, a sequence-automaton alignment algorithm is used to align sequences of states to a state machine. Our method iteratively aligns infrequent sequences to the model, effectively learning both frequent and infrequent behaviour.
The method is evaluated on a security competition dataset, where experiments show that the algorithm is able to recover from noise such as added or removed events. The learned models are also reduced to half its original size, while better fitting to the training data.
Last, we show how our method can be used to learn the model of an anomaly detection dataset. The test data is predicted using three anomaly conditions, and results in all anomalous data being labelled correctly. The F1-score is competitive compared to other state of the art methods.
Bachelor thesis
(2019)
-
Gijs Koning, Thijmen Langendam, Dennis Mouwen, Jochem Raat, Jeroen Breukels, Mark Neerincx, Otto Visser, Huijuan Wang
Our challenge was to define a format for a mission plan, and develop an application which allows the users of the robot to create a mission plan effectively. This application should assist the user in the process of creating a mission plan as much as possible. Our client was Allseas who was already the sponsor of the LOBSTER project. During the research phase we learned that our application would be best suited for an offline environment, as the user would not necessarily have an internet connection due to being at sea. Furthermore, we learned that the application had to be easy to use and not too complex. Throughout the course of this project we worked with Scrum, our repository was hosted on GitHub, with Travis CI integrated to test our code. Using this we could see our coverage and errors could not enter our final product. In our team we cooperated with an open culture to prevent frustrations. We made agreements on work hours and software methodologies. Still, we faced challenges which ranged from underestimating time needed for certain features to an increasing complexity of code and data gathering. The final product is a web application which can be accessed offline. This application can be successfully used to create missions for Autonomous Underwater Vehicles, which we showed in our final usability evaluation. The LOBSTER team will be using our product to plan their missions in the future. However, before it can be fully used, the low-level control software of the LOBSTER robots needs to be finished by the LOBSTER team.
...
Our challenge was to define a format for a mission plan, and develop an application which allows the users of the robot to create a mission plan effectively. This application should assist the user in the process of creating a mission plan as much as possible. Our client was Allseas who was already the sponsor of the LOBSTER project. During the research phase we learned that our application would be best suited for an offline environment, as the user would not necessarily have an internet connection due to being at sea. Furthermore, we learned that the application had to be easy to use and not too complex. Throughout the course of this project we worked with Scrum, our repository was hosted on GitHub, with Travis CI integrated to test our code. Using this we could see our coverage and errors could not enter our final product. In our team we cooperated with an open culture to prevent frustrations. We made agreements on work hours and software methodologies. Still, we faced challenges which ranged from underestimating time needed for certain features to an increasing complexity of code and data gathering. The final product is a web application which can be accessed offline. This application can be successfully used to create missions for Autonomous Underwater Vehicles, which we showed in our final usability evaluation. The LOBSTER team will be using our product to plan their missions in the future. However, before it can be fully used, the low-level control software of the LOBSTER robots needs to be finished by the LOBSTER team.