Title :
Dynamic information-theoretic measures for security informatics
Author :
Colbaugh, Richard ; Glass, Kevin ; Bauer, Thomas
Author_Institution :
Sandia Nat. Labs., Albuquerque, NM, USA
Abstract :
Many important security informatics problems require consideration of dynamical phenomena for their solution; examples include predicting the behavior of individuals in social networks and distinguishing malicious and innocent computer network activities based on activity traces. While information theory offers powerful tools for analyzing dynamical processes, to date the application of information-theoretic methods in security domains has focused on static analyses (e.g., cryptography, natural language processing). This paper leverages information-theoretic concepts and measures to quantify the similarity of pairs of stochastic dynamical systems, and shows that this capability can be used to solve important problems which arise in security applications. We begin by presenting a concise review of the information theory required for our development, and then address two challenging tasks: 1.) characterizing the way influence propagates through social networks, and 2.) distinguishing malware from legitimate software based on the instruction sequences of the disassembled programs. In each application, case studies involving real-world datasets demonstrate that the proposed techniques outperform standard methods.
Keywords :
information theory; invasive software; social networking (online); activity trace; behavior prediction; cryptography; dynamic information-theoretic measure; dynamical process analysis; innocent computer network activity; instruction sequence; legitimate software; malicious computer network activity; malware; natural language processing; security application; security domain; security informatics; social network; static analysis; stochastic dynamical system; Informatics; Information theory; Malware; Markov processes; Social network services; Vehicle dynamics; cyber security; information theory; predictive analytics; security informatics; social network dynamics;
Conference_Titel :
Intelligence and Security Informatics (ISI), 2013 IEEE International Conference on
Conference_Location :
Seattle, WA
Print_ISBN :
978-1-4673-6214-6
DOI :
10.1109/ISI.2013.6578784