New Approaches to Network Security


Overview

Our approach to network security is simple; find new ways to solve well known problems to create solutions that are flexible, diverse, and easy to deploy.

We focus on three primary areas related to network security: improving email spam detection, accommodating mini-flash crowds, and improving malware detection. In the area of spam, we focus on evaluating how effective current spam filters are and developing new ways to improve them. A key component to our work is the idea of examining whitelists and ham email to help us with our classification instead of only focusing on spam email. We also expanded the use of TCP fingerprints to help identify spam that usually is not classified as spam by traditional mechanisms. In the area of mini-flash crowds, we present an initial design of a light-weight wide-area profiling service that reveals resource bottlenecks in Web-server infrastructures, including access bandwidth, processing resources, and back-end data management. In malware evolution, we analyze a large corpus of malcode meta data to understand how malcode has evolved over the years, and in particular, how different instances of malcode relate to one another

Our data

Papers

People

Graduate students: Holly Esquivel.
Alumni: Archit Gupta (Masters, May 08), Pratap Ramamurthy (Masters, Dec 08), Pavan Kuppili (Masters, May 08)
Collaborators: Tatsuya Mori, Vyas Sekar, Paul Barford, Balachander Krishnamurthy and Anees Shaikh.