Searching for authors named "Michalis Polychronakis" – sorted by Relevance.
-
A Demand Driven Network Monitoring Architecture
- Abstract—The capability of dynamically monitoring the performance of the communication infrastructure is one of the emerging requirements for a Grid. We claim that such a capability is in fact orthogonal to the more popular collection of data for scheduling and diagnosis, which needs large storage a
- Add To MetaCart
-
Topnet: A Network-Aware top(1)
- System administrators regularly use the top utility for understanding the resource consumption of the processes running on UNIX computers. Top provides an accurate and real-time display of the computing and memory capacity of the system among the running processes, but it provides no information abo
- Add To MetaCart
-
Ghost turns Zombie: Exploring the Life Cycle of Web-based Malware
- While the web provides information and services that enrich our lives in many ways, it has also become the primary vehicle for delivering malware. Once infected with web-based malware, an unsuspecting user’s machine is converted into a productive member of the Internet underground. In this work, we
- Cited by 3 (1 self) – Add To MetaCart
-
Exclusion-based Signature Matching for Intrusion Detection
- We consider the problem of efficient string-based signature matching for Network Intrusion Detection Systems (NIDSes) . String matching computations dominate in the overall cost of running a NIDS, despite the use of efficient generalpurpose string matching algorithms. Aiming at increasing the effici
- Cited by 7 (0 self) – Add To MetaCart
-
Real-world Polymorphic Attack Detection
- As state-of-the-art attack detection technology becomes more prevalent, attackers have started to employ evasion techniques such as code obfuscation and polymorphism to defeat existing defenses. We have recently proposed network-level emulation, a heuristic detection method that scans network traffi
- Add To MetaCart
-
An Empirical Study of Real-world Polymorphic Code Injection Attacks
- Remote code injection attacks against network services remain one of the most effective and widely used exploitation methods for malware propagation. In this paper, we present a study of more than 1.2 million polymorphic code injection attacks targeting production systems, captured using network-lev
- Add To MetaCart
-
Network-level polymorphic shellcode detection using emulation
- Abstract. As state-of-the-art attack detection technology becomes more prevalent, attackers are likely to evolve, employing techniques such as polymorphism and metamorphism to evade detection. Although recent results have been promising, most existing proposals can be defeated using only minor enhan
- Cited by 11 (5 self) – Add To MetaCart
-
Emulation-based Detection of Non-self-contained Polymorphic Shellcode
- Abstract. Network-level emulation has recently been proposed as a method for the accurate detection of previously unknown polymorphic code injection attacks. In this paper, we extend network-level emulation along two lines. First, we present an improved execution behavior heuristic that enables the
- Cited by 4 (2 self) – Add To MetaCart
-
SCAMPI - A Scaleable Monitoring Platform for the Internet
- In this paper we describe the architecture of SCAMPI (A Scaleable Monitoring Platform for the Internet). SCAMPI allows easy writing of monitoring applications, which can run on top of different network adapters without changing the code and which can provide detailed monitoring of high-speed Interne
- Add To MetaCart
-
Appmon: An Application for Accurate per Application Network Traffic Characterisation, submitted for Broadband Europe
- Accurate per-application network traffic characterization is becoming increasingly difficult in the face of emerging applications that use dynamically negotiated port numbers. At the same time, information about the contribution of different network applications and services to the traffic mix is hi
- Cited by 1 (0 self) – Add To MetaCart

