SHARKFIN: Spatio-temporal mining of software adoption and penetration

被引:1
|
作者
Papalexakis, Evangelos E. [1 ]
Dumitras, Tudor [2 ]
Chau, Duen Horng [3 ]
Prakash, B. Aditya [4 ]
Faloutsos, Christos [1 ]
机构
[1] Carnegie Mellon Univ, Sch Comp Sci, Pittsburgh, PA 15213 USA
[2] Univ Maryland, Dept ECE, College Pk, MD 20742 USA
[3] Georgia Tech, Sch Computat Sci & Engn, Atlanta, GA USA
[4] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24061 USA
关键词
Malware propagation; Internet security; Data analysis;
D O I
10.1007/s13278-014-0240-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
How does malware propagate? Does it form spikes over time? Does it resemble the propagation pattern of benign files, such as software patches? Does it spread uniformly over countries? How long does it take for a URL that distributes malware to be detected and shut down? In this work, we answer these questions by analyzing patterns from 22 million malicious (and benign) files, found on 1.6 million hosts worldwide during the month of June 2011. We conduct this study using the WINE database available at Symantec Research Labs. Additionally, we explore the research questions raised by sampling on such large databases of executables; the importance of studying the implications of sampling is twofold: First, sampling is a means of reducing the size of the database hence making it more accessible to researchers; second, because every such data collection can be perceived as a sample of the real world. We discover the SHARKFIN temporal propagation pattern of executable files, the GEOSPLIT pattern in the geographical spread of machines that report executables to Symantec's servers, the Periodic Power Law (PPL) distribution of the lifetime of URLs, and we show how to efficiently extrapolate crucial properties of the data from a small sample. We further investigate the propagation pattern of benign and malicious executables, unveiling latent structures in the way these files spread. To the best of our knowledge, our work represents the largest study of propagation patterns of executables.
引用
收藏
页码:1 / 15
页数:15
相关论文
共 50 条
  • [41] Periodic Pattern Mining for Spatio-Temporal Trajectories: A Survey
    Zhang, Dongzhi
    Lee, Kyungmi
    Lee, Ickjai
    2015 10TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND KNOWLEDGE ENGINEERING (ISKE), 2015, : 306 - 313
  • [42] Mining Regular Crime Patterns in Spatio-Temporal Databases
    Kumar, G. Vijay
    Kumar, N. Dilip
    Sai, R. Lakshmi Prasanna
    2017 INTERNATIONAL CONFERENCE OF ELECTRONICS, COMMUNICATION AND AEROSPACE TECHNOLOGY (ICECA), VOL 1, 2017, : 231 - 236
  • [43] Social network discovery by mining spatio-temporal events
    Lauw H.W.
    Lim E.-P.
    Pang H.
    Tan T.-T.
    Computational & Mathematical Organization Theory, 2005, 11 (2): : 97 - 118
  • [44] Spatio-temporal data mining for typhoon image collection
    Kitamoto, A
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2002, 19 (01) : 25 - 41
  • [45] Spatio-temporal Sequential Pattern Mining for Tourism Sciences
    Bermingham, Luke
    Lee, Ickjai
    2014 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE, 2014, 29 : 379 - 389
  • [46] Deep Learning for Spatio-Temporal Data Mining: A Survey
    Wang, Senzhang
    Cao, Jiannong
    Yu, Philip S.
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2022, 34 (08) : 3681 - 3700
  • [47] Adoption of cropping sequences in northeast Montana: A spatio-temporal analysis
    Long, John A.
    Lawrence, Rick L.
    Miller, Perry R.
    Marshall, Lucy A.
    Greenwood, Mark C.
    AGRICULTURE ECOSYSTEMS & ENVIRONMENT, 2014, 197 : 77 - 87
  • [48] Spatio-Temporal Prediction of Suspect Location by Spatio-Temporal Semantics
    Duan L.
    Hu T.
    Zhu X.
    Ye X.
    Wang S.
    Wuhan Daxue Xuebao (Xinxi Kexue Ban)/Geomatics and Information Science of Wuhan University, 2019, 44 (05): : 765 - 770
  • [49] Spatio-temporal association mining for un-sampled sites
    Li, D
    Deogun, J
    FOUNDATIONS OF INTELLIGENT SYSTEMS, 2003, 2871 : 478 - 485
  • [50] Spatio-temporal periodic behavior mining algorithm for social networks
    Hu, Y.-P., 1600, Editorial Board of Journal on Communications (34):