ERCIM News
  • Back issues
  • Subscription
  • About
  • Call for contributions
  • Advertise
Cover of ERCIM News 129

ERCIM News 129

April 2022

Special theme Fighting Cybercrime

Guest editors Florian Skopik (AIT Austrian Institute of Technology) and Kyriakos Stefanidis (ISI)

PDF of ERCIM News 129 ePub of ERCIM News 129 48 pages

In this issue

  • Special Theme
  • Research and Innovation
  • Joint ERCIM Actions
  • Announcements

Next issue October 2026

Special theme Quantum Technology

Call for contributions

  1. Home
  2. ERCIM News 129

Browse recent issues

  • Cover of ERCIM News 145 No. 145
  • Cover of ERCIM News 144 No. 144
  • Cover of ERCIM News 143 No. 143
  • Cover of ERCIM News 142 No. 142
  • Cover of ERCIM News 141 No. 141
  • Cover of ERCIM News 140 No. 140
  • Cover of ERCIM News 139 No. 139
  • Cover of ERCIM News 138 No. 138

Browse all issues

Fighting Cybercrime - Introduction to the Special Theme

Details
Category: Special Theme
Published: 01 April 2022
Hits: 5845

by Florian Skopik (AIT Austrian Institute of Technology) and Kyriakos Stefanidis  (ISI)

Cybercrime has grown to a profitable multi-billion-dollar business. The number of reported criminal offences is continuously rising every year. The reasons for this development are the ever-increasing dependency on IT technology for almost every business, the opportunity for attackers to operate in the dark, and the continuously growing attack surface. With the adoption of new computing paradigms, such as cloud computing and the Internet of Things, not only new opportunities for legitimate businesses arise, but also new ways for criminals to make profit or to attack and de-stabilise a country’s economy or society. In recent years, we have witnessed the rise of ransomware attacks on a large scale, Distributed Denial of Service (DDoS) attacks with high volumes that have never been observed before, and data leaks that massively harmed global businesses. Besides stealing business-critical data, harming or blackmailing individuals or organisations, large-scale attacks on critical infrastructures of a region or nation-state have become a severe threat. Some examples are the recent attacks on the US-East-Coast Colonial Pipeline, one of the largest US pipeline operators, and the use of cybersecurity attacks on Ukrainian infrastructures. Finally, the ever-growing de-stabilising disinformation campaigns and cyberwar practices in general are increasingly shaping social and political conflicts. Thousands of high-impact attacks have already demonstrated the vulnerability of complex interconnected systems.

Read more …

CC-DRIVER: Understanding the Technical Drivers of Cybercrime

Details
Category: Special Theme
Published: 01 April 2022
Hits: 5041

by Evangelos Markatos (FORTH and University of Crete), Mary Aiken, Julia Davidson (University of East London), Alexey Kirichenko (F-Secure Corporation) and David Wright (Trilateral Research)

Over the past few years, we have seen cybercrime rising to become a trillion-dollar business world-wide. Although the cost of cybercrime was close to $5.5 trillion in 2020 [1], it is now estimated to double by 2025 [2]. To put this number in perspective, a cost of $10.5 trillion a year is $28 billion per day, or $20 million a minute, or close to $330,000 a second. At such staggering rates, it is imperative to understand the drivers of cybercrime and how they can be mitigated.

Read more …

Countering Terrorist Financing

Details
Category: Special Theme
Published: 01 April 2022
Hits: 5068

by Ross King (AIT Austrian Institute of Technology GmbH), Georgios Kioumourtzis (IANUS Consulting) and Georgios Papadopoulos (FORTH-ICS)

The European Union’s Internal Security Fund (ISF) will contribute to ensuring a high level of security in the Union, by supporting actions that help to prevent and combat terrorism and radicalisation, serious and organised crime, and cybercrime. One such project that has launched in January 2022 is Anti-FinTer: Versatile artificial intelligence investigative technologies for revealing online cross-border financing activities of terrorism.

Read more …

Mitigating Financial Cybercrime with BPMN-based Standardised Investigation Procedures

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4165

by George Tsakalidis, (Financial and Economic Crime Unit - S.D.O.E. (Operational Directorate of Macedonia)) and Kostas Vergidis, (University of Macedonia)

A systematised investigation process for copyright-related cybercrime offences has been designed in the Business Process Model and Notation (BPMN) and implemented by financial crime investigators of a Law Enforcement Agency. The proposed approach has increased the efficiency of the performed investigations and the dissemination of knowledge to relevant agencies.

Read more …

Digital Forensics for the Detection of Deepfake Image Manipulations

Details
Category: Special Theme
Published: 01 April 2022
Hits: 8913

by Sara Ferreira (University of Porto), Mário Antunes (Polytechnic of Leiria) and Manuel E. Correia (University of Porto)

Tampered multimedia content is increasingly being used in a broad range of cybercrime activities. The spread of fake news, misinformation, digital kidnapping, and ransomware-related crimes are among the most recurrent crimes in which manipulated digital photos are being used as an attacking vector. One of the linchpins of accurately detecting manipulated multimedia content is the use of machine learning and deep learning algorithms. This work proposed a dataset of photos and videos suitable for digital forensics, which has been used to benchmark Support Vector Machines (SVM) and Convolution Neural Networks algorithms (CNN). An SVM-based module for the Autopsy digital forensics open-source application has also been developed. This was evaluated as a very capable and useful forensic tool, winning second place on the OSDFCon international Autopsy modules competition.

Read more …

Privacy-Preserving Collaborative Anomaly Detection to Fight Cybercrime

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3401

by Rudolf Mayer (SBA Research)

Anomaly detection is an important part of countering cybercrime, by detecting e.g., fraud or intrusions. Especially with an ever-growing amount of data (such as logs or transactions) being collected, automated analysis of these data for malicious behaviour becomes essential. In several settings, such analysis might be performed by third parties or be collaborative, to learn from more and diverse experiences by different collaborators. Thus, means to access such often confidential data in a privacy-preserving manner are required. Collaborative Learning and synthetic data are two promising approaches to fulfil this purpose.

Read more …

Tiny Machine Learning: A New Technique for AI Security

Details
Category: Special Theme
Published: 01 April 2022
Hits: 8021

by Hui Han (Fraunhofer IESE) and Jingyue Li (NTNU)

Tiny machine learning (TinyML) is the intersection of machine learning (ML) algorithms and embedded systems (hardware and software) in terms of low latency, low power, and small size. It allows data to be kept mainly on edge devices and to be processed and have ML tasks run directly in the device. Therefore, the TinyML paradigm is expected to preserve AI security and combat cybercrimes. In this study, we explore how TinyML, the cutting-edge of ML technologies, solves relevant AI security problems (including cybercrimes) from the AI lifecycle aspect: data engineering, model engineering and model deployment. Finally, we discuss the opportunities for future research.

Read more …

IoT Malware Detection with Machine Learning

Details
Category: Special Theme
Published: 01 April 2022
Hits: 7707

by Levente Buttyán (Budapest University of Technology and Economics) and Rudolf Ferenc (University of Szeged)

Embedded devices are increasingly connected to the Internet to provide new and innovative applications in many domains. However, these IoT devices can also contain security vulnerabilities, which allow attackers to compromise them using malware. We report on our recent work on using machine learning for efficient and effective malware detection on resource-constrained IoT devices.

Read more …

Fighting Cybercrime by Introducing Trustworthiness and Interpretability in Deep Learning Malware Detection

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4206

by Giacomo Iadarola, Fabio Martinelli (IIT-CNR) and Francesco Mercaldo (University of Molise and IIT-CNR)

Cybercriminals can use a device compromised by malware for a plethora of purposes. Malicious intentions include the theft of confidential data, using the victim's computer to perform further criminal acts, or data ciphering to ask a ransom. Recently, deep learning is widely considered for malware detection. The main problem in the real-world adoption of these methods is due to their “black box” working mechanism i.e., the security analyst must trust the prediction without the possibility to understand the reason why an application is detected as malicious. In this article we discuss a malicious family detector, providing a mechanism aimed to assess the prediction trustworthiness and explainability. Real-world case studies are discussed to show the effectiveness of the proposed method.

Read more …

Transparent and Explainable Information Quality Prediction

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4753

by Davide Ceolin (CWI)

Predicting the quality of the information online is a key step to contrast the spread of dis- and misinformation. Transparency and explainability of information quality prediction are key elements to increase their trustability and usefulness. We at CWI work on fostering online information quality explainability through transparent AI pipelines that combine argumentation reasoning, crowdsourcing, and logical reasoning.

Read more …

SPOTTED: Systematic Mapping of Detection Approaches on Data Sources for Enhanced Cyber Defence

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4761

by Manuel Kern and Florian Skopik

In the last decade there was a clear paradigm shift from focusing only on prevention and protection to also including detection and response. While prevention and protection are indispensable to enable a baseline security, it is presumed that attackers have already compromised systems to some extent (“presumption of compromise”). The fact that professional attackers often operate in the network over a long period of time has long been known in cyber security research. A key pillar of a holistic security approach is therefore the early detection of attackers in the network. But still, the average time to detect attackers remains high. In the course of a study commissioned by IBM Security [L1], the average time it takes to detect a data breach is quantified with a time period of 212 days, five days longer than the year before.

Read more …

Kyoushi Testbed Environment: A Model-driven Simulation Framework to Generate Open Log Data Sets for Security Evaluations

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4530

by Max Landauer, Florian Skopik, Markus Wurzenberger and Wolfgang Hotwagner (AIT)

Cyber security leverages intrusion detection systems that analyse log data and network traffic to disclose suspicious activities and protect networks against cyberattacks. Verifying the functionality and measuring the effectiveness of these detection systems is not trivial, since it usually is not desirable to launch actual attacks in an organisation’s productive infrastructure. Therefore, such evaluations are often carried out in isolated testbeds, i.e., simulated networks comprising components and applications that are representative of their real-world counterparts in terms of configuration, scale, and utilisation. However, setting up and maintaining such testbeds is complex and labour-intensive, particularly when experiments are required to be reproducible and adaptable. To alleviate these issues, we developed the Kyoushi Testbed Environment, an open-source simulation framework that enables automatic and parallel testbed instantiation through model-driven design, simulation of normal user activities to generate a baseline workload, injection of attack scenarios with variations, and labelling of collected log data.

Read more …

A Scalable Ensemble-based Framework to Analyse Users’ Digital Footprints for Cybersecurity

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3814

by Gianluigi Folino, Francesco Sergio Pisani (ICAR-CNR) and Carla Otranto Godano (HFactor Security)

In the field of cybersecurity, it is of great interest to analyse user logs in order to prevent data breach issues caused by user behaviour (human factor). A scalable framework based on the Elastic Stack (ELK) to process and store log data coming from digital footprints of different users and from applications is proposed. The system exploits the scalable architecture of ELK by running on top of a Kubernetes platform, and adopts ensemble-based machine learning algorithms to classify user behaviour and to eventually detect anomalies in behaviour.

Read more …

Timestamp Patterns in Windows Forensics

Details
Category: Special Theme
Published: 01 April 2022
Hits: 10775

by Robert Luh (University of Vienna and St. Pölten University of Applied Sciences) and Michael Galhuber (St. Pölten University of Applied Sciences)

Timestamps are among the most expressive artefacts in a digital forensic investigation. Our research shows that the distinct patterns caused by the interaction with individual files can yield more insight than previously documented and enables application fingerprinting within a Windows environment through timestamps alone. Furthermore, we classify timestamp forgery tools and present a means to detect their use.

Read more …

Meta-framework for Automating Static Malware Analysis

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4020

by Patrick Kochberger, Sebastian Schrittwieser (University of Vienna) and Edgar R. Weippl (SBA Research)

In cybercrime, malware plays a weighty role and malware authors heavily rely on different code obfuscation techniques such as packing, virtualisation, or control flow transformations, and other anti-analysis methods to hide malicious functionality in binary code. With thousands of new malware samples emerging every day, efficient analysis is crucial for fighting malware-based cybercrime. We present a novel meta-framework for malware analysis that helps find the optimal analysis strategy for a malware sample. The research for the work was conducted in a joint project together with the University of Gent in Belgium [L1].

Read more …

ARIMA Security Metrics: Facilitating Decision-making Processes and Situational Awareness in Threat Intelligence

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3814

by Jan Kohlrausch (DFN-CERT)

At DFN-CERT, we work on augmenting Security Metrics with a family of stochastic models. For a given Security Metric, an Autoregressive Integrated Moving Average (ARIMA) model is selected that encapsulates the sequence of metrics results and provides objective mathematical properties. This additional mathematical layer results in a better understanding of the metrics properties, facilitates decision-making processes, and supports situational awareness in Threat Intelligence.

Read more …

From Collaboration to Automation: A Proof of Concept for Improved Incident Response

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4704

by Lasse Nitz (Fraunhofer FIT), Martin Zadnik (CESNET), Mehdi Akbari Gurabi (Fraunhofer FIT), Mischa Obrecht (Dreamlab Technologies AG) and Avikarsha Mandal (Fraunhofer FIT)

Effective incident response relies on taking accurate and timely measures in reaction to cybersecurity incidents. The increase in both the number and variety of cyberattacks, however, makes it challenging for incident handlers to keep up with this task. In the H2020 project SAPPAN, we take a practical look at this problem and explore the sharing of incident handling information, the automation of incident response processes, as well as the relationship between these two topics, to assist human operators in their work.

Read more …

Towards Model-Driven DevSecOps for Cyberattack Prevention, Detection and Recovery

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4339

by Christophe Ponsard, Philippe Massonet, Valery Ramon (CETIC)

Coping with cybercrime in the scope of increasingly open and interconnected systems is a difficult challenge. DevSecOps provide an adequate framework to keep in control of this perpetual race. We show here how it can be efficiently supported by an internal model-based analysis and automation approach together with the external threat intelligence sharing.

Read more …

Strengthening the Mobile Forensics Investigation Chain

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3567

by Phil Cobley (MSAB), Georgina Humphries (NMPS), Harry Manifavas (FORTH-ICS), Rune Nordvik (NMPS), Matthew Sorell (Univ. of Adelaide)

Mobile devices, especially smartphones, constitute a major source of evidence in criminal activities investigated by law enforcement agencies (LEAs) [1]. Mobile devices present unique challenges; therefore, it is vital to empower all players involved in solving and judging cases where mobile data plays a significant role. FORMOBILE [L1], an EU-funded H2020 project aims to establish a complete end-to-end forensic investigation chain for mobile devices by developing the first standard for mobile forensics, novel tools, and a targeted training programme.

Read more …

Identifying Attack Propagation Threads and Root Cause in Internet-of-Vehicle Ecosystems Utilising Honeypots in Connected Autonomous Vehicles

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3494

by Christos Alexakos (ISI/ATHENA RC), Kristina Livitckaia (ITI/CERTH), Mike Anastasiadis (ITI/CERTH), Dimitrios Serpanos (University of Patras)

The importance of cybersecurity for Internet of Vehicles (IoV) systems is indisputable as possible attacks can cause the loss of lives. In nIoVe project, a cybersecurity framework has been developed. This framework includes tools for accurate detection of the propagation trends and root cause analysis of the attacks, providing additional knowledge for cyberattacks against lookalike infrastructures.

Read more …

PenQuest: Gamifying Cyberattacks

Details
Category: Special Theme
Published: 01 April 2022
Hits: 4127

by Robert Luh and Sebastian Eresheim (University of Vienna & St. Pölten University of Applied Sciences)

PenQuest is a digital multi-player game that allows users to recreate or emulate cyberattacks on a game board representing freely configurable IT infrastructures. The game’s model incorporates a multitude of security concepts and threat vocabularies translated into technical and organisational actions. PenQuest is intended to assist risk assessment, support the reconstruction of adversarial events, and gamify security education.

Read more …

Fighting Cybercrime through Education: Integration of an Educational Cyber Defence Centre into Cyber Security Curricula

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3002

by Jochen Hense, Simon Tjoa, Peter Kieseberg (St. Pölten University of Applied Sciences, Austria)

Traditional security education often focuses on teaching theoretical concepts but lacks hands-on experience. However, many aspects of modern security, especially in the incident management domain, cannot be taught in the abstract; they must be experienced. Our Cyber Defence Centre (CDC) allows us to train students in a simulated environment where they gain skills in detecting attacks, closing vulnerabilities, and responding to security breaches in a realistic but safe setting.

Read more …

Ludoteca del Registro.it: Cybersecurity in Education

Details
Category: Special Theme
Published: 01 April 2022
Hits: 3479

by Giorgia Bassi, Stefania Fabbri and Anna Vaccarelli (IIT-CNR)

Ludoteca del Registro.it is a project implemented by the Registro.it (the Registry of .it Internet domains) of the Institute of Informatics and Telematics of the CNR (National Research Council) in Pisa, aimed to help students develop more responsible use of the Internet, with a focus on cybersecurity topics.

Read more …

Artificial Intelligence Enabled Distributed Edge Computing for Internet of Things

Details
Category: Research and Innovation
Published: 01 April 2022
Hits: 3869

by Ali Balador, Sima Sinaei (RISE Research Institute of Sweden) and Mats Pettersson (Sensative AB)

DAIS is a huge step forward in the area of artificial intelligence and edge computing. DAIS intends to create a complete framework for self-organising, energy-efficient and private-by-design distributed AI. DAIS is a European project with a consortium of 47 partners from 11 countries coordinated by Ali Balador from RISE research institute of Sweden.

Read more …

Potential Hazard of Accidental Radioactive Discharges into the Calm Atmosphere

Details
Category: Research and Innovation
Published: 01 April 2022
Hits: 3061

by Petr Pecha, Miroslav Kárný, Emilie Pechová, Václav Šmídl  and Ondřej Tichý (Institute of Information Theory and Automation)

A research team from the department of Adaptive Systems of ÚTIA [L1] has solved the project HARP [L2] which included examination of various release scenarios under worst-case meteorological conditions. Recently, the team has been focused on inspection of the calm situations characterised by stable atmosphere at very low wind speed with possibility of rainfall. Although the probability of such episodes is low, possible radiological impact on the environment can be serious. Developed methodology supports deployment of the sampling-based methods for probabilistic estimation of the radiological impact of radiation accidents.

Read more …

Formal Modelling and Optimal Traffic Management for Future Railways

Details
Category: Research and Innovation
Published: 01 April 2022
Hits: 3841

by Francesco Flammini (Mälardalen University), Stefano Marrone (University of Campania Luigi Vanvitelli) and Lei Chen (University of Birmingham)

PERFORMINGRAIL aims to delineate, through formal modelling and optimal traffic management, moving block railway signalling using advanced train positioning approaches for diverse market segments.

Read more …

Tomasz Kociumaka wins the 2021 ERCIM Cor Baayen Young Researcher Award

Details
Category: Joint ERCIM Actions
Published: 01 April 2022
Hits: 2588

Announcement

Tomasz KociumakaThe ERCIM Cor Baayen Award selection committee has unanimously selected Tomasz Kociumaka as the winner of the competition for the 2021 ERCIM Cor Baayen Young Researcher Award. Tomasz Kociumaka was nominated by the University of Warsaw, which awarded him a PhD in 2019. Tomasz then worked at Bar-Ilan University, Israel, and he is currently a postdoctoral researcher at the University of California, Berkeley, USA.

Read more …

Dagstuhl Seminars and Perspectives Workshops

Details
Category: Announcements
Published: 01 April 2022
Hits: 2698

Call for Proposals

Schloss Dagstuhl – Leibniz-Zentrum für Informatik is accepting proposals for scientific seminars/workshops in all areas of computer science, in particular also in connection with other fields.

Read more …

FM 2023: 25th International Symposium on Formal Methods - Call for Papers

Details
Category: Announcements
Published: 01 April 2022
Hits: 4995

Lübeck, Germany, 6-10 March 2023

FM 2023 is the 25th international symposium in a series organized by Formal Methods Europe (FME), an independent association whose aim is to stimulate the use of, and research on, formal methods for software development. FME has a Memorandum of Understanding with the ERCIM Working Group on Formal Methods for Industrial Critical Systems (FMICS) to collaborate in holding an annual joint industry-focussed event. This Industry Day (I-Day) at FM targets the industrial development and use of formal methods.

Read more …

SAFECOMP 2022 and the DECSoS 2022 Workshop - ERCIM Working Group Dependable Embedded Systems

Details
Category: Announcements
Published: 01 April 2022
Hits: 3123

Munich and online 6-9 September 2022

Invitation for participation
SafeComp has contributed since 1979 to the progress of the state-of-the-art in dependable application of computers in safety-related and safety-critical systems. SafeComp is an annual event covering the state-of-the-art, experience and new trends in the areas of safety, security and reliability of critical computer applications. SafeComp provides ample opportunity to exchange insights and experience on emerging methods, ap-proaches and practical solutions. It is a single-track conference allowing easy networking. SAFECOMP 2022 will take place on 6-9 September 2022 at Fraunhofer AISEC and Galileo Science Technolgie Park in Munich Garching, a few subway stops from Munich city center.

Read more …

ERCIM News

ERCIM News is published by ERCIM – the European Research Consortium for Informatics and Mathematics.

ERCIM News is licensed under a Creative Commons Attribution 4.0 International License.

You are free to share and redistribute the material in any medium or format, provided that the authors and source are credited.

Indexing

Articles in the Special Theme and Research and Innovation sections are referenced by DBLP.

A joint publication of

  • CNR
  • CWI
  • Fraunhofer
  • FNR
  • FORTH
  • INESC
  • Inria
  • ISI
  • ITIS-UMA
  • NTNU
  • RISE
  • SBA Research
  • SZTAKI
  • University of Cyprus

© ERCIM • Legal information