Talos: A prototype Intrusion Detection and Prevention System based on behavioral profiling

Speaker: Ashley Wood, PhD Student and VL, Computer Science
Venue: Microsoft Teams (https://bit.ly/3u2oIm6)
Date: 29/4/2021 12:00 - 13:00

Abstract

In a society and economy that is growing increasingly reliant upon IT, networks, and systems for its day-to-day activities. Cyberattacks have the real potential to cause and inflict serious damage and disruption to critical systems and infrastructure which society relies upon. As such cyberattacks are becoming an increasingly attractive option for cybercriminals and opportunists alike, who are seeking to develop ever more intrusive and disruptive forms of attack. This issue has been exacerbated by the continuing advancement of the COVID-19 pandemic, where entire business infrastructures have been moved online to facilitate remote working, which has made cyberattacks an increasingly attractive option for criminals.

In this online seminar, Ashley will introduce his PhD research and summarise the work carried out thus far. This seminar will include a brief discussion, history and overview of Intrusion Detection and Prevention technology and present challenges, before then moving onto a discussion of the growing problem of malware attacks. Ashley will then discuss his previous and current malware-analysis which led onto his PhD research, before then discussing an alternative approach to Intrusion Detection and Prevention achieved through the behavioral-profiling of malware variants. Ashley will then discuss and detail the prototype Talos system that has been developed to detect malware based on commonly occurring behaviors and features. The online seminar will then conclude with a discussion of the next steps in the research and how Intrusion Detection and Prevention technology may be advanced moving forward.

Speaker's Bio

Ashley is a Visiting Lecturer and a PhD student in the department of CSEEE at the University of Chester working towards a PhD investigating Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). His PhD work thus far has aimed to identify the common challenges associated with current systems which has resulted in the stagnation of current research. Ashley has extensive experience in malware-analysis and his previous research has focused on the analysis of several recent strains of malware/ransomware attacks, which has led to a recent publication Wood & Eze (2020) and a further paper on utilising malware behaviours for Intrusion Detection and Prevention Wood, Eze & Speakman (2021).

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments