SearcharxivSearch

arXiv subjects

Brian Weber

Publications and source records attributed to Brian Weber.

At least 19 recordsLinked to original sources

On the Abuse and Detection of Polyglot Files

A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for malware detection systems that route files to format-specific detectors/signatures, as well as file upload and sanitization tools. In this work we found that existing file-format and embedded-file detection tools, even those developed specifically for polyglot files, fail to reliably detect polyglot files used in the wild, leaving organizations vulnerable to attack. To address this issue, we studied the use of polyglot files by malicious actors in the wild, finding $30$ polyglot samples and $15$ attack chains that leveraged polyglot files. In this report, we highlight two well-known APTs whose cyber attack chains relied on polyglot files to bypass detection mechanisms. Using knowledge from our survey of polyglot usage in the wild -- the first of its kind -- we created a novel data set based on adversary techniques. We then trained a machine learning detection solution, PolyConv, using this data set. PolyConv achieves a precision-recall area-under-curve score of $0.999$ with an F1 score of $99.20$% for polyglot detection and $99.47$% for file-format identification, significantly outperforming all other tools tested. We developed a content disarmament and reconstruction tool, ImSan, that successfully sanitized $100$% of the tested image-based polyglots, which were the most common type found via the survey. Our work provides concrete tools and suggestions to enable defenders to better defend themselves against polyglot files, as well as directions for future work to create more robust file specifications and methods of disarmament.

cs.CR

Stability of Information in the Heat Flow Clustering

Clustering methods must be tailored to the dataset it operates on, as there is no objective or universal definition of ``cluster,'' but nevertheless arbitrariness in the clustering method must be minimized. This paper develops a quantitative ``stability'' method of determining clusters, where stable or persistent clustering signals are used to indicate real structures have been identified in the underlying dataset. This method is based on modulating clustering methods by controlling a parameter -- through a thermodynamic analogy, the modulation parameter is considered ``time'' and the evolving clustering methodologies can be considered a ``heat flow.'' When the information entropy of the heat flow is stable over a wide range of times -- either globally or in the local sense which we define -- we interpret this stability as an indication that essential features of the data have been found, and create clusters on this basis.

cs.IT

The Path To Autonomous Cyber Defense

Defenders are overwhelmed by the number and scale of attacks against their networks.This problem will only be exacerbated as attackers leverage artificial intelligence to automate their workflows. We propose a path to autonomous cyber agents able to augment defenders by automating critical steps in the cyber defense life cycle.

cs.CR

Data needs and challenges for quantum dot devices automation

Gate-defined quantum dots are a promising candidate system for realizing scalable, coupled qubit systems and serving as a fundamental building block for quantum computers. However, present-day quantum dot devices suffer from imperfections that must be accounted for, which hinders the characterization, tuning, and operation process. Moreover, with an increasing number of quantum dot qubits, the relevant parameter space grows sufficiently to make heuristic control infeasible. Thus, it is imperative that reliable and scalable autonomous tuning approaches are developed. This meeting report outlines current challenges in automating quantum dot device tuning and operation with a particular focus on datasets, benchmarking, and standardization. We also present insights and ideas put forward by the quantum dot community on how to overcome them. We aim to provide guidance and inspiration to researchers invested in automation efforts.

cond-mat.mes-hall

QDA$^2$: A principled approach to automatically annotating charge stability diagrams

Gate-defined semiconductor quantum dot (QD) arrays are a promising platform for quantum computing. However, presently, the large configuration spaces and inherent noise make tuning of QD devices a nontrivial task and with the increasing number of QD qubits, the human-driven experimental control becomes unfeasible. Recently, researchers working with QD systems have begun putting considerable effort into automating device control, with a particular focus on machine-learning-driven methods. Yet, the reported performance statistics vary substantially in both the meaning and the type of devices used for testing. While systematic benchmarking of the proposed tuning methods is necessary for developing reliable and scalable tuning approaches, the lack of openly available standardized datasets of experimental data makes such testing impossible. The QD auto-annotator -- a classical algorithm for automatic interpretation and labeling of experimentally acquired data -- is a critical step toward rectifying this. QD auto-annotator leverages the principles of geometry to produce state labels for experimental double-QD charge stability diagrams and is a first step towards building a large public repository of labeled QD data.

cond-mat.mes-hall

Complete scalar-flat Kahler 4-manifolds with a continuous symmetry

We study complete scalar-flat Kahler manifolds with a Killing field and a mild asymptotic condition. We show that topological and geometric rigidities exist that powerfully restrict the manifold's behavior at infinity. We create a rough classification for scalar-flat Kahler manifolds with a Killing field.

math.DG

AI ATAC 1: An Evaluation of Prominent Commercial Malware Detectors

This work presents an evaluation of six prominent commercial endpoint malware detectors, a network malware detector, and a file-conviction algorithm from a cyber technology vendor. The evaluation was administered as the first of the Artificial Intelligence Applications to Autonomous Cybersecurity (AI ATAC) prize challenges, funded by / completed in service of the US Navy. The experiment employed 100K files (50/50% benign/malicious) with a stratified distribution of file types, including ~1K zero-day program executables (increasing experiment size two orders of magnitude over previous work). We present an evaluation process of delivering a file to a fresh virtual machine donning the detection technology, waiting 90s to allow static detection, then executing the file and waiting another period for dynamic detection; this allows greater fidelity in the observational data than previous experiments, in particular, resource and time-to-detection statistics. To execute all 800K trials (100K files $\times$ 8 tools), a software framework is designed to choreographed the experiment into a completely automated, time-synced, and reproducible workflow with substantial parallelization. A cost-benefit model was configured to integrate the tools' recall, precision, time to detection, and resource requirements into a single comparable quantity by simulating costs of use. This provides a ranking methodology for cyber competitions and a lens through which to reason about the varied statistical viewpoints of the results. These statistical and cost-model results provide insights on state of commercial malware detection.

cs.CR

Testing SOAR Tools in Use

Modern security operation centers (SOCs) rely on operators and a tapestry of logging and alerting tools with large scale collection and query abilities. SOC investigations are tedious as they rely on manual efforts to query diverse data sources, overlay related logs, and correlate the data into information and then document results in a ticketing system. Security orchestration, automation, and response (SOAR) tools are a new technology that promise to collect, filter, and display needed data; automate common tasks that require SOC analysts' time; facilitate SOC collaboration; and, improve both efficiency and consistency of SOCs. SOAR tools have never been tested in practice to evaluate their effect and understand them in use. In this paper, we design and administer the first hands-on user study of SOAR tools, involving 24 participants and 6 commercial SOAR tools. Our contributions include the experimental design, itemizing six characteristics of SOAR tools and a methodology for testing them. We describe configuration of the test environment in a cyber range, including network, user, and threat emulation; a full SOC tool suite; and creation of artifacts allowing multiple representative investigation scenarios to permit testing. We present the first research results on SOAR tools. We found that SOAR configuration is critical, as it involves creative design for data display and automation. We found that SOAR tools increased efficiency and reduced context switching during investigations, although ticket accuracy and completeness (indicating investigation quality) decreased with SOAR use. Our findings indicated that user preferences are slightly negatively correlated with their performance with the tool; overautomation was a concern of senior analysts, and SOAR tools that balanced automation with assisting a user to make decisions were preferred.

cs.CR

Pseudoconvex submanifolds in Kahler 4-manifolds

On Kahler 4-manifolds, not necessarily compact or of finite topological type, we obtain relationships between the fundamental group of compact embedded Levi-flat or pseudoconvex submanifold and the fundamental group of the ambient manifold $M^4$. When a Levi-flat submanifold $V^3$ has finite fundamental group then $\pi_1(M^4)=\iota_*\pi_1(V^3)$; when a non-separating pseudoconvex submanifold $V^3$ has finite fundamental group, then $\pi_1(M^4)=\iota_*\pi_1(V^3)\rtimes\mathbb{Z}$. As applications, if a Kahler manifold (compact or not) has an embedded holomorphic $\mathbb{P}^1$ of positive self-intersection, it must intersect all other holomorphic $P^1$ of non-negative self-intersection, the fundamental group of $M^4$ is trivial, and no ALE or ALF ends exist. If a Levi-flat submanifold and an embedded holomorphic $\mathbb{P}^1$ of positive self-intersection both exist, they intersect. The total number of ALE plus ALF ends is zero or one regardless of what other kinds of ends exist. We provide examples, such as a 2-ended scalar-flat Kahler metric conformal to the Taub-NUT.

math.DG

Asymptotic geometry of toric Kahler instantons

The symplectic reduction of a complete toric K\"ahler manifold need not be closed or even be a polygon. Sharp differences in behavior occur between those complete toric K\"ahler 4-manifolds with closed and with non-closed reductions. This paper establishes geometric criteria for these reductions to be closed, and classifies all asymptotic geometries possible in the case of scalar-flat instantons with closed reductions. Contrasting this, we provide examples of complete instantons with non-closed and non-polygon reductions.

math.DG

Toward the Detection of Polyglot Files

Standardized file formats play a key role in the development and use of computer software. However, it is possible to abuse standardized file formats by creating a file that is valid in multiple file formats. The resulting polyglot (many languages) file can confound file format identification, allowing elements of the file to evade analysis.This is especially problematic for malware detection systems that rely on file format identification for feature extraction. File format identification processes that depend on file signatures can be easily evaded thanks to flexibility in the format specifications of certain file formats. Although work has been done to identify file formats using more comprehensive methods than file signatures, accurate identification of polyglot files remains an open problem. Since malware detection systems routinely perform file format-specific feature extraction, polyglot files need to be filtered out prior to ingestion by these systems. Otherwise, malicious content could pass through undetected. To address the problem of polyglot detection we assembled a data set using the mitra tool. We then evaluated the performance of the most commonly used file identification tool, file. Finally, we demonstrated the accuracy, precision, recall and F1 score of a range of machine and deep learning models. Malconv2 and Catboost demonstrated the highest recall on our data set with 95.16% and 95.45%, respectively. These models can be incorporated into a malware detector's file processing pipeline to filter out potentially malicious polyglots before file format-dependent feature extraction takes place.

cs.CR

A Mathematical Framework for Evaluation of SOAR Tools with Limited Survey Data

Security operation centers (SOCs) all over the world are tasked with reacting to cybersecurity alerts ranging in severity. Security Orchestration, Automation, and Response (SOAR) tools streamline cybersecurity alert responses by SOC operators. SOAR tool adoption is expensive both in effort and finances. Hence, it is crucial to limit adoption to those most worthwhile; yet no research evaluating or comparing SOAR tools exists. The goal of this work is to evaluate several SOAR tools using specific criteria pertaining to their usability. SOC operators were asked to first complete a survey about what SOAR tool aspects are most important. Operators were then assigned a set of SOAR tools for which they viewed demonstration and overview videos, and then operators completed a second survey wherein they were tasked with evaluating each of the tools on the aspects from the first survey. In addition, operators provided an overall rating to each of their assigned tools, and provided a ranking of their tools in order of preference. Due to time constraints on SOC operators for thorough testing, we provide a systematic method of downselecting a large pool of SOAR tools to a select few that merit next-step hands-on evaluation by SOC operators. Furthermore, the analyses conducted in this survey help to inform future development of SOAR tools to ensure that the appropriate functions are available for use in a SOC.

cs.HC

Canonical metrics and ambiK\"ahler structures on 4-manifolds with $U(2)$ symmetry

For $U(2)$-invariant 4-metrics, we show that the $B^t$-flat metrics are very different from the other canonical metrics (Bach-flat, Einstein, extremal K\"ahler, etc). We show every $U(2)$-invariant metric is conformal to two separate K\"ahler metrics, leading to ambiK\"ahler structures. Using this observation we find new complete extremal K\"ahler metrics on the total spaces of $\mathcal{O}(-1)$ and $\mathcal{O}(+1)$ that are conformal to the Taub-bolt metric. In addition to its usual hyperK\"ahler structure, the Taub-NUT's conformal class contains two additional complete K\"ahler metrics that make up an ambi-K\"ahler pair, making five independent compatible complex structures for the Taub-NUT, each of which has a conformally K\"ahler (1,1) form.

math.DG

A classification of scalar-flat toric K\"ahler instantons in dimension 4

We classify all scalar-flat toric K\"ahler 4-manifolds under either of two asymptotic conditions: that the action fields decay slowly (or at all), or that the curvature decay is quadratic; for example we fully classify instantons that have any of the ALE-F-G-H asymptotic types. The momentum functions satisfy a degenerate elliptic equation, and under either asymptotic condition the image of the moment map is closed. Using a recent Liouville theorem for degenerate-elliptic equations, we classify all possibilities for the momentum functions, and from this, all possible metrics.

math.DG

Beyond the Hype: A Real-World Evaluation of the Impact and Cost of Machine Learning-Based Malware Detection

In this paper, we present a scientific evaluation of four prominent malware detection tools to assist an organization with two primary questions: To what extent do ML-based tools accurately classify previously- and never-before-seen files? Is it worth purchasing a network-level malware detector? To identify weaknesses, we tested each tool against 3,536 total files (2,554 or 72\% malicious, 982 or 28\% benign) of a variety of file types, including hundreds of malicious zero-days, polyglots, and APT-style files, delivered on multiple protocols. We present statistical results on detection time and accuracy, consider complementary analysis (using multiple tools together), and provide two novel applications of the recent cost-benefit evaluation procedure of Iannacone \& Bridges. While the ML-based tools are more effective at detecting zero-day files and executables, the signature-based tool may still be an overall better option. Both network-based tools provide substantial (simulated) savings when paired with either host tool, yet both show poor detection rates on protocols other than HTTP or SMTP. Our results show that all four tools have near-perfect precision but alarmingly low recall, especially on file types other than executables and office files -- 37% of malware tested, including all polyglot files, were undetected. Priorities for researchers and takeaways for end users are given.

cs.CR

Generalized Kahler Taub-NUTs and Two Exceptional Instantons

We study the one-parameter family of twisted Kahler Taub-NUT metrics (discovered by Donaldson), along with two exceptional Taub-NUT-like instantons, and understand them to the extend that should be sufficient for blow-up and gluing arguments. In particular we parametrize their geodesics from the origin, determine curvature fall-off rates, volume growth rates for metric balls, and find blow-down limits.

math.DG

Regularity and a Liouville theorem for a class of boundary-degenerate second order equations

We study a class of second-order boundary-degenerate elliptic equations in two dimensions with minimal regularity assumptions. We prove a maximum principle and a Harnack inequality at the degenerate boundary, and assuming local boundedness, we prove continuity. On globally defined non-negative solutions we provide strong constraints on behavior at infinity, and prove a Liouville-type theorem for entire solutions on the closed half-plane. The class of PDE in question includes many from mathematical finance, Keldysh- and Tricomi-type PDE, and the 2nd order reduction of the fully non-linear 4th order Abreu equation from Kähler geometry.

math.AP

A Gap Theorem for Half-Conformally Flat Manifolds

We show that any compact half-conformally flat manifold of negative type, with bounded $L^2$ energy, sufficiently small scalar curvature, and a non-collapsing assumption, has all betti numbers bounded. We show that this result is optimal from an analytic perspective by demonstrating singularity models that are 2-ended, and are asymptotically Kähler on both ends. We show that bounded self-dual solutions of $dω=0$ on ALE manifold ends are either asymptotically Kähler, or they have a decay rate of $O(r^{-4})$ or better.

math.DG