57 citations · 125 across the 18 of their papers we have counts for
7 papers · 1 filter
Hybrid Privilege Escalation and Remote Code Execution Exploit Chains
Miguel Tulla, Andrea Vignali, Christian Colon +5
Research on exploit chains predominantly focuses on sequences with one type of exploit, e.g., either escalating privileges on a machine or executing remote code. In networks, hybri…
LLMs Killed the Script Kiddie: How Agents Supported by Large Language Models Change the Landscape of Network Threat Testing
Stephen Moskal, Sam Laney, Erik Hemberg +1
In this paper, we explore the potential of Large Language Models (LLMs) to reason about threats, generate information about tools, and automate cyber campaigns. We begin with a man…
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
Erik Hemberg, Una-May O'Reilly
Artificial Intelligence (AI) and Machine Learning (ML) algorithms can support the span of indicator-level, e.g. anomaly detection, to behavioral level cyber security modeling and i…
Proceedings - AI/ML for Cybersecurity: Challenges, Solutions, and Novel Ideas at SIAM Data Mining 2021
John Emanuello, Kimberly Ferguson-Walter, Erik Hemberg +5
Malicious cyber activity is ubiquitous and its harmful effects have dramatic and often irreversible impacts on society. Given the shortage of cybersecurity professionals, the ever-…
Automating Cyber Threat Hunting Using NLP, Automated Query Generation, and Genetic Perturbation
Prakruthi Karuna, Erik Hemberg, Una-May O'Reilly +1
Scaling the cyber hunt problem poses several key technical challenges. Detecting and characterizing cyber threats at scale in large enterprise networks is hard because of the vast…
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Erik Hemberg, Jonathan Kelly, Michal Shlapentokh-Rothman +4
Many public sources of cyber threat and vulnerability information exist to help defend cyber systems. This paper links MITRE's ATT&CK MATRIX of Tactics and Techniques, NIST's Commo…