Stratosphere Project: Free Software
Machine Learning to protect NGOs
Sebastián García PhD.
sebastian.garcia@agents.fel.cvut.cz
@eldracote
Live Slides bit.ly/fsfe2016
1 . 1
NGOs are at risk
1 . 2
Highly political targets.
Attacked by powerful actors
No resources.
Not their goal.
Strong concerns about their privacy.
Concerns about Trust.
Problems for NGOs Security
1 . 3
Stratosphere Project
https://stratosphereips.org/
Free
Software
Machine
Learning
Behavioral
IPS
Protecting
NGOs
1 . 4
To put state-of-the-art machine learning techniques in
the hands of the civil society.
To offer this detection service to NGOs for free.
We focus on what the computers are doing, not the
attacks they receive.
Stratosphere Project
1 . 5
Stratosphere Principles
Less is More
Disassociate
Verify
Analyze the behavior of groups of flows.
Representation of behavior from detection.
With real and labeled datasets.
1 . 6
About Behaviors
Your behavior is usually the same when connecting
with the same service.
Group flows going to a specific service by ignoring
the source port. We call it a connection.
The connection, composed of several flows, now
shows a behavior in time.
1 . 7
The Behavior of a Connection
10.0.2.111-217.23.10.139-80-tcp 55*V0v00v*E*v*v*v*v*E*v
1 flow -> 4 features -> 1 letter + 1 symbol
1 . 8
Behaviors or Malware
Malware mostly generate the same behaviors.
Changing the behavior is costly for the attacker.
These behaviors do not expire quickly.
Malware Open Data
https://stratosphereips.org/category/dataset.html
1 . 9
Machine Learning Detection
From the letters create a Markov Chains behavioral model
Train Markov Models with known Malware Behaviors.
For detection: Compare the unknown traffic of a
network to each trained Markov Model.
1 . 10
Types of Stratosphere
Stand alone Detector
Cloud service for NGOs (in our University)
Stratosphere Testing Framework
Stratosphere Linux IPS
Stratosphere Windows IPS
1 . 11
Stratosphere Data Analysis
Cloud-based Detection service for NGOs.
Add new algorithms continually.
Update the models.
Verify the detections if necessary.
NGOs can send the Flows or only the
letters! Privacy matters.
1 . 12
Organizations working with us
People In Need. CZ. Helping 22
countries. Human-rights, war, etc.
CZ.NIC. Manager of .cz and Turris
Project. 2,000 Internet Networks.
ICT help for policy makers in 20
African Countries
CTU University. With more than
7,000 hosts.
1 . 13
Thanks!
Sebastian Garcia
sebastian.garcia@agents.fel.cvut.cz
@stratosphereips
https://stratosphereips.org
1 . 14
In our datasets
96% TPR. Our own botnet traffic connections that
are detected.
Real Traffic
~0.0002% FPR (30 FP in 132,000 connections/5min)
Novel Success cases: Linux Botnet, DDoS, etc.
Errors? For sure.
Results
1 . 15

More Related Content

PDF
Research on Online Digital Cultures — Community Extraction from Twitter Netwo...
ODP
Twitter Community Extraction by Markov Clustering
DOCX
Who You Should Not Follow: Extracting Word Embeddings from Tweets to Identify...
PPTX
EMTACL 2012: Connecting Researchers to Information - and Unlocking It!
PPT
Finding Emerging Topics Using Chaos and Community Detection in Social Media G...
PDF
When the world beats a path to your door. Collaboration in the era of big data
PPTX
Publishing infrastructure: the good, the bad, and the expensive
PPTX
Social networking analysis
Research on Online Digital Cultures — Community Extraction from Twitter Netwo...
Twitter Community Extraction by Markov Clustering
Who You Should Not Follow: Extracting Word Embeddings from Tweets to Identify...
EMTACL 2012: Connecting Researchers to Information - and Unlocking It!
Finding Emerging Topics Using Chaos and Community Detection in Social Media G...
When the world beats a path to your door. Collaboration in the era of big data
Publishing infrastructure: the good, the bad, and the expensive
Social networking analysis

Similar to Stratosphere project: free software machine learning to protect ng os (20)

DOC
Intruder adaptability
DOCX
Security of WhatsApp 1 Christophe Bassono Su.docx
PDF
20160713 2016 the honeynet projct annual workshop focus and global trends
PPT
InSTEDD HISA Conference
PPT
InSTEDD: Collaboration in Disease Surveillance & Response
PDF
How to Use OSINT and Web Scraping for Data Collection.pdf
PPT
In Stedd May2009
PPTX
Enhancing Soft Power: using cyberspace to enhance Soft Power
PPT
TOTEM: Threat Observation, Tracking, and Evaluation Model
PPT
FOSS and Security
PPTX
iMinds The Conference: Danny Hughes
PDF
Chinese Hackers Exploit Tools: Researchers Reveal New Cyber | Cyber Pro Magazine
PDF
Target attack (hkust gold edition)(public version)
PDF
Analysis of Malware Infected Systems & Classification with Gradient-boosted T...
PDF
Personam Solution - How it Works Brief
PDF
Personam Solution - How it Works Brief
PDF
Mobile Crowdsensing with Mobile Agents
PDF
Honeypots for Network Security
Intruder adaptability
Security of WhatsApp 1 Christophe Bassono Su.docx
20160713 2016 the honeynet projct annual workshop focus and global trends
InSTEDD HISA Conference
InSTEDD: Collaboration in Disease Surveillance & Response
How to Use OSINT and Web Scraping for Data Collection.pdf
In Stedd May2009
Enhancing Soft Power: using cyberspace to enhance Soft Power
TOTEM: Threat Observation, Tracking, and Evaluation Model
FOSS and Security
iMinds The Conference: Danny Hughes
Chinese Hackers Exploit Tools: Researchers Reveal New Cyber | Cyber Pro Magazine
Target attack (hkust gold edition)(public version)
Analysis of Malware Infected Systems & Classification with Gradient-boosted T...
Personam Solution - How it Works Brief
Personam Solution - How it Works Brief
Mobile Crowdsensing with Mobile Agents
Honeypots for Network Security
Ad

Recently uploaded (20)

PPTX
Understanding the Circulatory System……..
PPTX
bone as a tissue presentation micky.pptx
PPTX
AP CHEM 1.2 Mass spectroscopy of elements
PPT
1. INTRODUCTION TO EPIDEMIOLOGY.pptx for community medicine
PPTX
Cells and Organs of the Immune System (Unit-2) - Majesh Sir.pptx
PPTX
ELISA(Enzyme linked immunosorbent assay)
PDF
Social preventive and pharmacy. Pdf
PPTX
Toxicity Studies in Drug Development Ensuring Safety, Efficacy, and Global Co...
PPTX
diabetes and its complications nephropathy neuropathy
PDF
Cosmology using numerical relativity - what hapenned before big bang?
PPTX
Introcution to Microbes Burton's Biology for the Health
PDF
The Future of Telehealth: Engineering New Platforms for Care (www.kiu.ac.ug)
PPTX
2currentelectricity1-201006102815 (1).pptx
PDF
Worlds Next Door: A Candidate Giant Planet Imaged in the Habitable Zone of ↵ ...
PDF
Integrative Oncology: Merging Conventional and Alternative Approaches (www.k...
PDF
Worlds Next Door: A Candidate Giant Planet Imaged in the Habitable Zone of ↵ ...
PPTX
Substance Disorders- part different drugs change body
PDF
7.Physics_8_WBS_Electricity.pdfXFGXFDHFHG
PDF
Packaging materials of fruits and vegetables
PPTX
Platelet disorders - thrombocytopenia.pptx
Understanding the Circulatory System……..
bone as a tissue presentation micky.pptx
AP CHEM 1.2 Mass spectroscopy of elements
1. INTRODUCTION TO EPIDEMIOLOGY.pptx for community medicine
Cells and Organs of the Immune System (Unit-2) - Majesh Sir.pptx
ELISA(Enzyme linked immunosorbent assay)
Social preventive and pharmacy. Pdf
Toxicity Studies in Drug Development Ensuring Safety, Efficacy, and Global Co...
diabetes and its complications nephropathy neuropathy
Cosmology using numerical relativity - what hapenned before big bang?
Introcution to Microbes Burton's Biology for the Health
The Future of Telehealth: Engineering New Platforms for Care (www.kiu.ac.ug)
2currentelectricity1-201006102815 (1).pptx
Worlds Next Door: A Candidate Giant Planet Imaged in the Habitable Zone of ↵ ...
Integrative Oncology: Merging Conventional and Alternative Approaches (www.k...
Worlds Next Door: A Candidate Giant Planet Imaged in the Habitable Zone of ↵ ...
Substance Disorders- part different drugs change body
7.Physics_8_WBS_Electricity.pdfXFGXFDHFHG
Packaging materials of fruits and vegetables
Platelet disorders - thrombocytopenia.pptx
Ad

Stratosphere project: free software machine learning to protect ng os