Technical Publications

Research Papers

Wenke Lee
Vice President of Research

Journals

q-Gram Matching Using Tree Models
Prahlad Fogla and Wenke Lee
IEEE Transactions on Knowledge and Data Engineering, Vol. 18, No. 4 (April 2006).

Using Artificial Anomalies to Detect Unknown and Known Network Intrusions
Wei Fan, Matt Miller, Sal Stolfo, Wenke Lee, and Phil Chan
Knowledge and Information Systems, Vol. 6, No. 5 (September 2004), Springer.

Intrusion Detection Techniques for Mobile Wireless Networks
Yongguang Zhang, Wenke Lee, and Yian Huang
ACM/Kluwer Wireless Networks Journal (ACM WINET), Vol. 9, No. 5 (September 2003).

Proactive Intrusion Detection and Distributed Denial of Service Attacks - A Case Study in Security Management
Joao B. D. Cabrera, Lundy Lewis, Xinzhou Qin, Wenke Lee, and Raman K. Mehra
Journal of Network and Systems Management, Vol. 10, No. 2 (June 2002).

Toward Cost-Sensitive Modeling for Intrusion Detection and Response (Postscript)
Wenke Lee, Wei Fan, Matt Miller, Sal Stolfo, and Erez Zadok
Journal of Computer Security, Vol. 10, Numbers 1,2, 2002.

A Framework for Constructing Features and Models for Intrusion Detection Systems (Postscript)
Wenke Lee and Sal Stolfo
ACM Transactions on Information and System Security, Volume 3, Number 4 (November 2000).

Adaptive Intrusion Detection: a Data Mining Approach (Postscript)
Wenke Lee, Sal Stolfo, and Kui Mok
Artificial Intelligence Review, Kluwer Academic Publishers, 14(6):533-567 (December 2000).

Interfacing Oz with the PCTE OMS: A Case Study of Integrating a Legacy System with a Standard Object Management System (Postscript)
Wenke Lee and Gail Kaiser
Journal of Systems Integration, 9(4):329-358, Kluwer Academic Publishers, 1999.

Refereed Book Chapters

Security in Mobile Ad-Hoc Networks
Yongguang Zhang and Wenke Lee
Ad Hoc Networks: Technologies and Protocols. P. Mohapatra and S. Krishnamurthy (eds), Springer, 2004.

Using MIB II Variables for Network Intrusion Detection
Xinzhou Qin, Wenke Lee, Lundy Lewis, Joao B. Cabrera
Applications of Data Mining in Computer Security. D. Barbara and S. Jajodia (eds), Kluwer Academic Publishers, May 2002.

Proactive Intrusion Detection - A Study on Temporal Data Mining
Joao B.D. Cabrera, Lundy Lewis, Xinzhou Qin, Wenke Lee, Raman K. Mehra
Applications of Data Mining in Computer Security. D. Barbara and S. Jajodia (eds), Kluwer Academic Publishers, May 2002

Algorithms for Mining System Audit Data
Wenke Lee, Sal Stolfo, and Kui Mok (Postscript)
Data Mining, Rough Sets, and Granular Computing, T. Y. Lin, Y. Y. Yao, and L. A. Zadeh (eds), Physica-Verlag, 2002

Jadve: An Extensible Data Visualization Environment
Wenke Lee and Naser Barghouti (Postscript)
in Object-Oriented Applications Frameworks , M. Fayad, D. Schmidt, and R. Johnson (eds), John Wiley & Sons, 1999

Papers in Referred Conferences

Secure and Flexible Monitoring of Virtual Machines.
Bryan D. Payne and Martim Carbone and Wenke Lee.
In Proceedings of The 23rd Annual Computer Security Applications Conference (ACSAC 2007), Miami Beach, FL, December 2007.

A Taxonomy of Botnet Structures.
David Dagon, Guofei Gu, Chris Lee and Wenke Lee.
In Proceedings of The 23rd Annual Computer Security Applications Conference (ACSAC 2007), Miami Beach, FL, December 2007.

Misleading and Defeating Importance-Scanning Malware Propagation.
Guofei Gu, Zesheng Chen, Phillip Porras and Wenke Lee.
In Proceedings of The 3rd International Conference on Security and Privacy in Communication Networks (SecureComm'07), Nice, France, September 2007.

An Assessment of VoIP Covert Channel Threats.
Takehiro Takahashi and Wenke Lee.
In Proceedings of The 3rd International Conference on Security and Privacy in Communication Networks (SecureComm'07), Nice, France, September 2007.

Understanding Precision in Host Based Intrusion Detection: Formal Analysis and Practical Models.
Monirul Sharif, Kapil Singh, Jonathon Giffin and Wenke Lee.
In Proceedings of The 10th International Symposium on Recent Advances in Intrusion Detection (RAID), Surfers Paradise, Australia, September 2007.

BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation.
Guofei Gu, Phillip Porras, Vinod Yegneswaran, Martin Fong, Wenke Lee.
In Proceedings of The 16th USENIX Security Symposium (Security'07), Boston, MA, August 2007.

Intrusion-Resilient Key Exchange in the Bounded Retrieval Model.
David Cash, Yan Zong Ding, Yevgeniy Dodis, Wenke Lee, Richard Lipton, and Shabsi Walfish.
In Proceedings of The Fourth IACR Theory of Cryptography Conference (TCC 2007), Amsterdam, The Netherlands, February 2007.

Using an Ensemble of One-Class SVM Classifiers to Harden Payload-based Anomaly Detection Systems.
Roberto Perdisci, Guoei Gu, and Wenke Lee.
In Proceedings of The 2006 IEEE International Conference on Data Mining (ICDM '06) , Hong Kong, China, December 2006.

PolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware.
Paul Royal, Mitch Halpin, David Dagon, Robert Edmonds, and Wenke Lee.
In Proceedings of The 22th Annual Computer Security Applications Conference (ACSAC 2006), Miami Beach, FL, December 2006.

Evading Network Anomaly Detection Systems: Formal Reasoning and Practical Techniques.
Prahlad Fogla and Wenke Lee.
In Proceedings of The 13th ACM Conference on Computer and Communications Security (CCS 2006) , Alexandria, VA, October 2006.

Towards an Information-Theoretic Framework for Analyzing Intrusion Detection Systems.
Guofei Gu, Prahlad Fogla, David Dagon, Wenke Lee, and Boris Skoric.
In Proceedings of The 11th European Symposium Research Computer Security (ESORICS 2006) , Hamburg, Germany, September 2006.

Polymorphic Blending Attacks.
Prahlad Fogla, Monirul Sharif, Roberto Perdisci, Oleg Kolesnikov, and Wenke Lee.
In Proceedings of The 15th USENIX Security Symposium (SECURITY '06) , Vancouver, B.C., Canada, August 2006.

Using Labeling to Prevent Cross-Service Attacks Against Smart Phones.
Collin Mulliner, Giovanni Vigna, David Dagon, and Wenke Lee.
In Proceedings of The 3rd Conference on Detection of Intrusions & Malware, and Vulnerability Assessment (DIMVA 2006), Berlin, Germany, July 2006.

Agent-Based Cooperative Anomaly Detection for Wireless Ad Hoc Networks.
Hongmei Deng, Roger Xu, Jason H. Li, Frank Zhang, Renato Levy, and Wenke Lee.
In Proceedings of The 12th International Conference on Parallel and Distributed Systems (ICPADS 2006), Minneapolis, Minnesota, July 2006.

DSO: Dependable Signing Overlay.
Guofei Gu, Prahlad Fogla, Wenke Lee, and Douglas Blough.
In Proceedings of The 4th International Conference on Applied Cryptography and Network Security (ACNS '06), Singapore, June 2006.

Misleading Worm Signature Generators Using Deliberate Noise Injection (full paper).
Roberto Perdisci, David Dagon, Wenke Lee, Prahlad Fogla, and Monirul Sharif.
In Proceedings of The 2006 IEEE Symposium on Security and Privacy, Oakland, CA, May 2006.

Measuring Intrusion Detection Capability: An Information-Theoretic Approach.
Guofei Gu, Prahlad Fogla, David Dagon, Wenke Lee, and Boris Skoric.
In Proceedings of ACM Symposium on InformAction, Computer and Communications Security (ASIACCS '06), Taipei, Taiwan, March 2006.

Modeling Botnet Propagation Using Time Zones.
David Dagon, Cliff Zou, and Wenke Lee.
In Proceedings of The 13th Annual Network and Distributed System Security Symposium (NDSS 2006), San Diego, CA, February 2006.

Anomalous Path Detection with Hardware Support.
Tao Zhang, Xiaotong Zhuang, Santosh Pande, and Wenke Lee.
In Proceedings of The 2005 International Conference on Compilers, Architecture, and Synthesis for Embedded Systems (CASES 2005), San Francisco, CA, September 2005.

An Extensible Environment for Evaluating Secure MANET.
Yongguang Zhang, Yi-an Huang, and Wenke Lee.
In Proceedings of The 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks (SecureComm 2005), Athens, Greece, September 2005.

Hotspot-Based Traceback for Mobile Ad Hoc Networks.
Yi-an Huang and Wenke Lee.
In Proceedings of The ACM Workshop on Wireless Security (WiSe 2005), Cologne, Germany, September 2005.

Environment-Sensitive Intrusion Detection.
Jonanthon T. Giffin, David Dagon, Somesh Jha, Wenke Lee, and Barton P. Miller.
In Proceedings of The 8th International Symposium on Recent Advances in Intrusion Detection (RAID 2005), Seattle, WA, September 2005.

Comparative Study between Analytical Models and Packet-Level Worm Simulations.
Monirul Sharif, George Riley, and Wenke Lee.
In Proceedings of The 19th Workshop on Parallel and Distributed Simulation (PADS 2005), Monterey, CA, June 2005.

Protecting Secret Data from Insider Attacks.
David Dagon, Wenke Lee, and Richard Lipton.
In Proceedings of Ninth International Conference on Financial Cryptography and Data Security, Roseau, Dominica, Feb. 2005.

Worm Detection, Early Warning, and Response Based on Local Victim Information.
Guofei Gu, David Dagon, Xinzhou Qin, Monirul I. Sharif, Wenke Lee, and George F. Riley.
In Proceedings of The 20th Annual Computer Security Applications Conference (ACSAC 2004), Tucson, Arizona, December 2004.

Attack Plan Recognition and Prediction Using Causal Networks.
Xinzhou Qin and Wenke Lee.
In Proceedings of The 20th Annual Computer Security Applications Conference (ACSAC 2004), Tucson, Arizona, December 2004.

On the Statistical Distribution of Processing Times in Network Intrusion Detection.
Joao B.D. Cabrera, Jaykumar Gosar, Wenke Lee, and Raman K. Mehra.
In Proceedings of The 43rd IEEE Conference on Decision and Control (CDC 2004), Bahamas, December 2004.

Simulating Internet Worms.
George F. Riley, Monirul I. Sharif, and Wenke Lee.
In Proceedings of The 12th Annual Meeting of the IEEE/ACM International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems (MASCOTS), Volendam, The Netherlands, October 2004

Attack Analysis and Detection for Ad Hoc Routing Protocols.
Yian Huang and Wenke Lee.
In Proceedings of The 7th International Symposium on Recent Advances in Intrusion Detection (RAID 2004), Sophia Antipolis, France, September 2004.

HoneyStat: Local Worm Detection Using Honeypots.
David Dagon, Xinzhou Qin, Guofei Gu, Wenke Lee, Julian Grizzard, John Levin, and Henry Owen.
In Proceedings of The 7th International Symposium on Recent Advances in Intrusion Detection (RAID 2004), Sophia Antipolis, France, September 2004.

Discovering Novel Attack Strategies from INFOSEC Alerts.
Xinzhou Qin and Wenke Lee.
In Proceedings of The 9th European Symposium on Research in Computer Security (ESORICS 2004) , Sophia Antipolis, France, September 2004.

Formalizing Sensitivity in Static Analysis for Intrusion Detection (Postscript).
Henry H. Feng, Jonathon T. Giffin, Yong Huang, Somesh Jha, Wenke Lee, and Barton P. Miller
In Proceedings of The 2004 IEEE Symposium on Security and Privacy, Oakland, CA, May 2004.

A Hardware Platform for Network Intrusion Detection and Prevention.
Chris Clark, Wenke Lee, David Schimmel, Didier Contis, Mohamed Kone, and Ashley Thomas
In Proceedings of The 3rd Workshop on Network Processors and Applications (NP3), Madrid, Spain, February 2004.

A Cooperative Intrusion Detection System for Ad Hoc Networks.
Yian Huang and Wenke Lee
In Proceedings of the ACM Workshop on Security of Ad Hoc and Sensor Networks (SASN '03), Fairfax VA, October 2003.

Statistical Causality Analysis of INFOSEC Alert Data (Postscript).
Xinzhou Qin and Wenke Lee
In Proceedings of The 6th International Symposium on Recent Advances in Intrusion Detection (RAID 2003), Pittsburgh, PA, September 2003.

Anomaly Detection Using Call Stack Information (Postscript).
Henry H. Feng, Oleg Kolesnikov, Prahlad Fogla, Wenke Lee, and Weibo Gong
In Proceedings of The 2003 IEEE Symposium on Security and Privacy, Oakland, CA, May 2003.

Cross-Feature Analysis for Detecting Ad-Hoc Routing Anomalies.
Yi-an Huang, Wei Fan, Wenke Lee, and Philip S. Yu
In Proceedings of The 23rd International Conference on Distributed Computing Systems (ICDCS), Providence, RI, May 2003.

Performance Adaptation in Real-Time Intrusion Detection Systems (Postscript).
Wenke Lee, Joao B. D. Cabrera, Ashley Thomas, Niranjan Balwalli, Sunmeet Saluja, and Yi Zhang
In Proceedings of The 5th International Symposium on Recent Advances in Intrusion Detection (RAID 2002), Zurich, Switzerland, October 2002.

Integrating Intrusion Detection and Network Management.
Xinzhou Qin, Wenke Lee, Lundy Lewis, and Joao B. D. Cabrera
In Proceedings of The IEEE/IFIP Network Operations and Management Symposium (NOMS 2002), Florence, Italy, May 2002.

Using Artificial Anomalies to Detect Unknown and Known Network Intrusions (Postscript).
Wei Fan, Matt Miller, Sal Stolfo, Wenke Lee, and Phil Chan
In Proceedings of The First IEEE International Conference on Data Mining, San Jose, CA, November 2001.

Heterogeneous Networking: A New Survivability Paradigm.
Yongguang Zhang, Harrick Vin, Lorenzo Alvisi, Wenke Lee, and Son K. Dao
In Proceedings of The 2001 New Security Paradigms Workshop (NSPW), Cloudcroft, New Mexico, September 2001.

Real Time Data Mining-based Intrusion Detection (Postscript).
Wenke Lee, Sal Stolfo, Phil Chan, Eleazar Eskin, Wei Fan, Matt Miller, Shlomo Hershkop, and Junxin Zhang
In Proceedings of The 2001 DARPA Information Survivability Conference and Exposition (DISCEX II) (selected for presentation), Anaheim, CA, June 2001.

Information-Theoretic Measures for Anomaly Detection (Postscript)
Wenke Lee and Dong Xiang
In Proceedings of The 2001 IEEE Symposium on Security and Privacy, Oakland, CA, May 2001.

Proactive Detection of Distributed Denial of Service Attacks Using MIB Traffic Variables - A Feasibility Study (Postscript)
J. B. D. Cabrera, L. Lewis, X. Qin, Wenke Lee, Ravi Prasanth, B. Ravichandran, and Raman Mehra
In Proceedings of The Seventh IFIP/IEEE International Symposium on Integrated Network Management (IM 2001), Seattle, WA, May 2001.

A Data Mining and CIDF Based Approach for Detecting Novel and Distributed Intrusions (Postscript)
Wenke Lee, Rahul Nimbalkar, Kam Yee, Sunil Patil, Pragnesh Desai, Thuan Tran, and Sal Stolfo
In Proceedings of The Third International Workshop on Recent Advances in Intrusion Detection (RAID 2000), Lecture Notes in Computer Science No. 1907, Toulouse, France, October 2000

Intrusion Detection in Wireless Ad-Hoc Networks (Postscript)
Yongguang Zhang and Wenke Lee
In Proceedings of The Sixth International Conference on Mobile Computing and Networking (MobiCom 2000), Boston, MA, August 2000

A Multiple Model Cost-Sensitive Approach for Intrusion Detection (Postscript)
Wei Fan, Wenke Lee, Sal Stolfo, and Matt Miller
In Proceedings of The Eleventh European Conference on Machine Learning (ECML 2000), Lecture Notes in Artificial Intelligence No. 1810, Barcelona, Spain, May 2000

Cost-based Modeling for Fraud and Intrusion Detection: Results from the JAM Project (Postscript)
Sal Stolfo, Wei Fan, Wenke Lee, Andreas Prodromidis, and Phil Chan
In Proceedings of the 2000 DARPA Information Survivability Conference and Exposition (DISCEX '00) (selected for presentation), Hilton Head, SC, January 2000

Mining in a Data-flow Environment: Experience in Network Intrusion Detection (Postscript)
(Best Paper Award in Applied Research Category)
Wenke Lee, Sal Stolfo, and Kui Mok
In Proceedings of the 5th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD '99), San Diego, CA, August 1999

A Data Mining Framework for Building Intrusion Detection Models (Postscript)
Wenke Lee, Sal Stolfo, and Kui Mok
In Proceedings of the 1999 IEEE Symposium on Security and Privacy, Oakland, CA, May 1999

Mining Audit Data to Build Intrusion Detection Models (Postscript)
(Honorable mention (runner-up) for Best Paper Award in Applied Research Category)
Wenke Lee, Sal Stolfo, and Kui Mok
In Proceedings of the Fourth International Conference on Knowledge Discovery and Data Mining (KDD '98), New York, NY, August 1998

Data Mining Approaches for Intrusion Detection (Postscript)
Wenke Lee and Sal Stolfo
In Proceedings of the Seventh USENIX Security Symposium (SECURITY '98), San Antonio, TX, January 1998

JAM: Java Agents for Meta-learning over Distributed Databases (Postscript)
Sal Stolfo, Andreas Prodromidis, Shelley Tselepis, Wenke Lee, Dave Fan, and Phil Chan
(Honorable mention (runner-up) for Best Paper Award in Applied Research Category)
In Proceedings of the Third International Conference on Knowledge Discovery and Data Mining (KDD '97), Newport Beach, CA, August 1997

Grappa: A GRAPh PAckage in Java (Postscript)
Naser S. Barghouti, John Mocenigo, and Wenke Lee
Fifth Annual Symposium on Graph Drawing (Graph Drawing '97), Rome, Italy, September 1997

OzCare: A Workflow Automation System for Care Plans (Postscript)
Wenke Lee, Gail Kaiser, Paul Clayton, and Eric Sherman
In Proceedings of the American Medical Informatics Association Annual Fall Symposium, Washington DC, October 1996

PAPERS IN WORKSHOPS

Using MIB II Variables for Network Anomaly Detection - A Feasibility Study.
Xinzhou Qin, Wenke Lee, Lundy Lewis, and Joao B. D. Cabrera.
ACM Workshop on Data Mining for Security Applications, Philadelphia, PA, November 2001.

Toward Cost-Sensitive Modeling for Intrusion Detection and Response (Postscript)
Wenke Lee, Wei Fan, Matt Miller, Sal Stolfo, and Erez Zadok
ACM Workshop on Intrusion Detection Systems , Athens, Greece, November 2000

Towards Automatic Intrusion Detection using NFR
Wenke Lee, Chris Park, and Sal Stolfo
In Proceedings of the 1st USENIX Workshop on Intrusion Detection and Network Monitoring, April 1999

Learning Patterns from Unix Process Execution Traces for Intrusion Detection (Postscript)
Wenke Lee, Sal Stolfo, and Phil Chan
AAAI Workshop: AI Approaches to Fraud Detection and Risk Management, July 1997

Credit Card Fraud Detection Using Meta-Learning: Issues and Initial Results (Postscript)
Sal Stolfo, Dave Fan, Wenke Lee, Andreas Prodromidis, and Phil Chan
AAAI Workshop: AI Approaches to Fraud Detection and Risk Management, July 1997

Pay No Attention to the Man Behind the Curtain
Gail Kaiser and Wenke Lee
NSF Workshop on Workflow and Process Automation, May 1996

Data Modeling and Management for Large Spatial Databases
Wenke Lee
In Proceedings of the Third International Workshop in GIS, Beijing, China, August 1993

Ph.D. Thesis
A Data Mining Framework for Constructing Features and Models for Intrusion Detection Systems (Postscript), Computer Science Department, Columbia University, New York, NY. June 1999.
Other

A Layered Approach to Simplified Access Control in Virtualized Systems.
Bryan D. Payne, Reiner Sailer, Ramon Caceres, Ronald Perez, and Wenke Lee
In ACM SIGOPS Operating Systems Review, 4(2), July 2007.

Applying Data Mining to Intrusion Detection: The Quest for Automation, Efficiency, and Credibility.
Wenke Lee
In SIGKDD Explorations, 4(2), December 2002.

Mining System Audit Data: Opportunities and Challenges.
Wenke Lee and Wei Fan
In SIGMOD Record, 30(4), December 2001.

Roberto Perdisci
Principal Scientist

Journals

G. Giacinto, R. Perdisci, Mauro Del Rio, F. Roli. "Intrusion Detection in Computer Networks by a Modular Ensemble of One-Class Classifiers". Information Fusion, Special Issue on Applications of Ensemble Methods (to appear). (pdf)


R. Perdisci, G. Giacinto, F. Roli. "Alarm clustering for intrusion detection systems in computer networks". Engineering Applications of Artificial Intelligence, 19(4), 2006, 429-438. (pdf)

Conference Proceedings

D. Ariu, G. Giacinto, R. Perdisci. "Sensing Attacks in Computers Networks with Hidden Markov Models". International Conference on Machine Learning and Data Mining in Pattern recognition, MLDM 2007. (pdf)

R. Perdisci, G. Gu, W. Lee. "Using an Ensemble of One-Class SVM Classifiers to Harden Payload-based Anomaly Detection Systems". IEEE International Conference on Data Mining, ICDM 2006. (pdf)

P. Fogla, M. Sharif, R. Perdisci, O. Kolesnikov, W. Lee. "Polymorphic Blending Attacks". USENIX Security 2006. (pdf)

R. Perdisci, D. Dagon, W. Lee, P. Fogla, M. Sharif. "Misleading Worm Signature Generators Using Deliberate Noise Injection". IEEE Symposium on Security and Privacy 2006. (pdf)

G. Giacinto, R. Perdisci, F. Roli. "Network Intrusion Detection by Combining One-class Classifiers". International Conference on Image Analysis and Processing, ICIAP 2005. (pdf)

G. Giacinto, R. Perdisci, and F. Roli, "Alarm Clustering for Intrusion Detection Systems in Computer Networks". International Conference on Machine Learning and Data Mining in Pattern recognition, MLDM 2005. (pdf)

PhD Thesis

R. Perdisci. "Statistical Pattern Recognition Techniques for Intrusion Detection in Computer Networks, Challenges and Solutions". Department of Electrical and Electronic Engineering, University of Cagliari, ITALY (2006). (pdf)