Home
|
Research Projects | Publications
- EffHunter
EFFHUNTER is a system that facilitates cyber threat hunting in computer systems using OSCTI. My contribution is to parse and store Sysdig logs and Darpa-TC logs into PostgresSQL and Neo4j for the evaluations.
- WebEvo
WebEvo is a novel tool to monitor web element changes that can break IR tools and web test scripts. It consists of DOM tree based change detection, history based semantic structure change detection
and a novel semantics-based visual search module to find semantic structure changes occuring between different versions of a web page.
- ProGQL
ProGQL is a novel graph query language that enables constrained graph search on provenance graph built from system audit logs. It also supports edge weight assignment and value propagation through weighted edges, enabling more complex provenance analysis on the provenance graph to reveal cyber attack steps.