20 results for “network security”
CS papers onlyHybrid search: Keyword + semantic, ranked by combined score.ⓘ
Want pure semantic search? Try claim verification →
This paper analyzes the Node Package Manager (npm) dependency network, demonstrates its vulnerability to targeted attacks, and proposes a defense strategy consisting of Centrality-Based Node-Hardening…
RefinementEngine is an automated system that translates high-level security intents and threat intelligence into deployable, low-level network filtering policies, overcoming manual deployment challeng…
This paper proposes a two-stage machine learning system that accurately detects I2P traffic and subsequently classifies it as data exfiltration or legitimate activity, achieving high accuracy in both…
The paper introduces the concept of 'host-space perturbations,' arguing that real-world attackers can only manipulate network inputs by controlling specific hosts, a constraint that significantly weak…
The paper introduces ClawTrap, a MITM-based red-teaming framework, to evaluate the security robustness of web agents like OpenClaw against dynamic, real-world network attacks, finding that model stren…
Shereen Ismail, Taelyn Dyer, Raul Martinez, Garrett Gastman +2 more
Analyzing 10 days of global internet traffic from a network telescope reveals that a small fraction of source IPs dominate traffic, with a notable focus on exploiting legacy IoT devices via Telnet por…
This paper identifies and characterizes NTP Pool servers that harvest IPv6 client addresses and uses them for reconnaissance, port scanning, and service enumeration.
The paper identifies and demonstrates the existence of a covert sublayer, called the Exclusive Network, within the I2P anonymous network, which allows nodes to host services without being discoverable…
Yuxiang Yang, Ao Wang, Xuewei Feng, Qi Li +1 more
This paper systematically identifies and demonstrates multiple session manipulation attacks against VPN connection tracking frameworks, revealing widespread vulnerabilities in popular VPN services.
This paper analyzes the security vulnerabilities of emerging pay-for-use Wi-Fi hotspots in rural areas, demonstrating practical attacks like connection hijacking and rogue hotspots.
The paper analyzes persistent TLS misconfigurations and introduces TLSGatekeeper, a high-performance, network-based tool that enforces security policies by monitoring TLS handshakes without requiring…
Henrique Curi de Miranda, Ágney Lopes Roth Ferraz, Wagner Comin Sonaglio, Lourenço Alves Pereira Júnior
The paper proposes a systematic security testing approach, documented in a Testing Guide, for InterUSS-based Unmanned Traffic Management (UTM) federated ecosystems to address unaddressed infrastructur…
MeshGuard is a framework that extends MUD-based network access control to complex, large-scale Thread IoT networks by adapting the MLE protocol and using SDN for scalable policy enforcement.
ML Defender (aRGus NDR) is an open-source, embedded Machine Learning Network Intrusion Detection System (NIDS) that achieves superior detection rates for botnet and anomalous traffic on resource-const…
Shiqi Xu, Yuyang Du, Mingyue Zhang, Hongwei Cui +1 more
LightGuard introduces a dual-link architecture that uses a physically confined LiFi channel to securely bootstrap cryptographic session keys, thereby mitigating the risk of key exposure inherent in tr…
Stefan Lenz, Julia Raab, Benedikt Holzbach, Deniz Köller +2 more
This paper discusses the significant challenges in developing a holistic intrusion detection system for Industrial Control Systems (ICS) that must cover all operational dimensions.
Cuidi Wei, Shaoyu Tu, Daiki Hata, Toru Hasegawa +4 more
immUNITY is a system that enhances network security by combining programmable switches and SmartNICs to efficiently detect and mitigate low-volume and slow network attacks.
The paper proposes a RADIUS-based framework to maintain persistent device identity for Network Access Control (NAC) despite modern operating system MAC address randomization, ensuring regulatory compl…
FIDEM introduces a standard-compliant framework that uses Zero-Knowledge Proofs to securely bind IoT devices to their Manufacturer Usage Description (MUD) profiles, mitigating risks associated with in…