63 citations · 130 across the 10 of their papers we have counts for
7 papers · 1 filter
How do information security workers use host data? A summary of interviews with security analysts
Robert A. Bridges, Michael D. Iannacone, John R. Goodall +1
Modern security operations centers (SOCs) employ a variety of tools for intrusion detection, prevention, and widespread log aggregation and analysis. While research efforts are qui…
ACTT: Automotive CAN Tokenization and Translation
Miki E. Verma, Robert A. Bridges, Samuel C. Hollifield
Modern vehicles contain scores of Electrical Control Units (ECUs) that broadcast messages over a Controller Area Network (CAN). Vehicle manufacturers rely on security through obscu…
Defining a Metric Space of Host Logs and Operational Use Cases
Miki E. Verma, Robert A. Bridges
Host logs, in particular, Windows Event Logs, are a valuable source of information often collected by security operation centers (SOCs). The semi-structured nature of host logs inh…
Exploiting the Shape of CAN Data for In-Vehicle Intrusion Detection
Zachariah Tyree, Robert A. Bridges, Frank L. Combs +1
Modern vehicles rely on scores of electronic control units (ECUs) broadcasting messages over a few controller area networks (CANs). Bereft of security features, in-vehicle CANs are…
Forming IDEAS Interactive Data Exploration & Analysis System
Robert A. Bridges, Maria A. Vincent, Kelly M. T. Huffer +3
Modern cyber security operations collect an enormous amount of logging and alerting data. While analysts have the ability to query and compute simple statistics and plots from thei…
Towards Malware Detection via CPU Power Consumption: Data Collection Design and Analytics (Extended Version)
Robert Bridges, Jarilyn Hernandez Jimenez, Jeffrey Nichols +2
This paper presents an experimental design and data analytics approach aimed at power-based malware detection on general-purpose computers. Leveraging the fact that malware executi…