Cybersecurity Research Podcast: Recent Episodes

Matthew Wright

The Cybersecurity Research Podcast is hosted by the Global Cybersecurity Institute at Rochester Institute of Technology. We talk about the latest in cybersecurity research with the experts who are pushing the field forward, with a definite bias towards the host's own areas of interest. Hosted by Matt Wright, Director of Research for the Global Cybersecurity Institute and a Professor of Computing Security.

View Details

Today, I’ll be chatting with Dr. David Mohaisen, an Associate Professor of Computer Science at the University of Central Florida. David works in the broad area of computer security and online privacy, which includes a lot of work in the area of applied Machine Learning.

In today’s interview, you’ll hear how he’s handling time in the pandemic, his take on academic research versus industry research, speculating on what has changed in 30 years of academic research, how he got started in the application of ML to cybersecurity problems, and a bit near the end about how he gets real work done.

We’ll also go deeper on his upcoming paper on “Soteria” at IEEE’s ICDCS 2020, which will happen in late November. This work is about detecting IoT malware based on control flow graphs, including malware that uses adversarial examples to bypass other classifiers based on control flow graphs. If you don’t know, control flow graphs abstract the sequence of function calls in software into a tree, with a root at the start of program and branches depending on what function calls can occur during a run. As you’ll hear, malware has different graph structures than most benign software, making it a fruitful source of features to both classify on and for attackers to try to manipulate. Super cool stuff!

If you’re interested to know more about the Global Cybersecurity Institute, please visit us online at www.rit.edu/cybersecurity.

This podcast episode was brought to you with support of the National Science Foundation under Grant No. 1816851. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Science Foundation.

Links

  • David’s UCF page: http://cs.ucf.edu/~mohaisen/
  • Alasmary, Hisham, Ahmed Abusnaina, Rhongho Jang, Mohammed Abuhamad, Afsah Anwar, D. Nyang, and David Mohaisen. “Soteria: Detecting adversarial examples in control flow graph-based malware classifiers.” In 40th IEEE International Conference on Distributed Computing Systems, ICDCS, pp. 1296-1305. 2020. http://seal.cs.ucf.edu/doc/icdcs20aml.pdf
  • Abusnaina, Ahmed, Aminollah Khormali, Hisham Alasmary, Jeman Park, Afsah Anwar, and Aziz Mohaisen. “Adversarial learning attacks on graph-based IoT malware detection systems.” In 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS), pp. 1296-1305. IEEE, 2019. https://bit.ly/3lMqEvv
  • Some of David’s early work on privacy-preserving data mining: Mohaisen, Abedelaziz, Nam-Su Jho, Dowon Hong, and DaeHun Nyang. "Privacy preserving association rule mining revisited: Privacy enhancement and resources efficiency." IEICE transactions on information and systems 93, no. 2 (2010): 315-325. https://www.jstage.jst.go.jp/article/transinf/E93.D/2/E93.D_2_315/_pdf
  • David on Twitter: https://twitter.com/DavidMohaisen
  • Music by John Bartmann, found on Pixabay

View Details

Today, in our first-ever episode, I’ll be chatting with Dr. Rachel Greenstadt, an Associate Professor of Computer Science and Engineering at New York University. Rachel is an expert on trustworthy intelligent systems, an area she has worked on since about 2006, well before the intersection of cybersecurity and AI became such a hot topic.

In today’s interview, you’ll hear about how she got started in this area, some her thoughts on working with students in research, what it’s like to take cryptography classes from famous MIT cryptographers, and a deep dive on her recently published paper on “Pod People” at ACM’s Web conference, WWW 2020, which took place online this April. This work is about understanding and potentially detecting groups, or pods, of people giving each other likes and comments in social networks like Instagram to boost their popularity and try to become influencers online.

If you’re interested to know more about the Global Cybersecurity Institute, please visit us online at www.rit.edu/cybersecurity.

This podcast episode was brought to you with support of the National Science Foundation under Grant No. 1816851. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Science Foundation.

Links

  • Rachel’s NYU page: https://engineering.nyu.edu/faculty/rachel-greenstadt
  • The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity Abuse. Janith Weerasinghe, Bailey Flanigan, Aviel Stein, Damon McCoy, and Rachel Greenstadt. WWW 2020. https://dl.acm.org/doi/10.1145/3366423.3380256
  • One of the early AI works that kicked off Rachel’s AI-related work: Experimental analysis of privacy loss in DCOP algorithms. R Greenstadt, JP Pearce, E Bowring, and M Tambe. AAMAS 2006.
  • Rachel’s first work on authorship attribution: Practical attacks against authorship recognition techniques. MR Brennan and R Greenstadt. IAAI 2009.
  • Upcoming USENIX Security paper: The Tools and Tactics Used in Intimate Partner Surveillance: An Analysis of Online Infidelity Forums. Emily Tseng, Rosanna Bellini, Nora McDonald, Matan Danos, Rachel Greenstadt, Damon McCoy, Nicola Dell, and Thomas Ristenpart.
  • Rachel on Twitter: https://twitter.com/ragreens