<node id="661889">
  <nid>661889</nid>
  <type>event</type>
  <uid>
    <user id="36253"><![CDATA[36253]]></user>
  </uid>
  <created>1665071137</created>
  <changed>1665071137</changed>
  <title><![CDATA[SCP Security Seminar ]]></title>
  <body><![CDATA[<p><strong>Speaker</strong>: Mingxuan Yao, Ph.D. student</p>

<p><strong>Title</strong>: C&amp;C On-Demand: An Empirical Study of Web Application Abuse for Malware Command and Control</p>

<p><strong>Abstract</strong>:&nbsp;Web applications (apps) provide a wide array of utilities that are being abused by malware authors as a&nbsp;replacement for attacker-deployed C&amp;C servers. Stopping this Web App-based Command and Control&nbsp;(WACC) requires collaboration between Incident Responders (IRs) and web app providers. However, little&nbsp;research has been done to prove that WACC malware are prevalent enough to warrant such an investment.&nbsp;To this end, we designed Marcea, a malware analysis pipeline to study the prevalence of WACC. Marcea&nbsp;revealed 487 WACC malware in 72 families abusing 30 web apps over the last 15 years. Our research&nbsp;uncovered the number of WACC malware increased by 5.5 times since 2020 and that 86% did not need to&nbsp;connect to an attacker-deployed C&amp;C server. Our study uncovered patterns indicating how specific web apps&nbsp;attract or disincentivize WACC malware. Moreover, web app engagement data collected by Marcea suggests&nbsp;that these malware are active enough to produce up to 5,844,144 access points. To date, we have used Marcea to collaborate with the web&nbsp;app providers to take down 70% of the active WACC malware.</p>

<p><strong>Biography</strong>: Mingxuan Yao is a fourth year Ph.D. student in the&nbsp;School of Electrical &amp; Computer Engineering(ECE) at&nbsp;&nbsp;Georgia Institute of Technology, under the guidance of Professor&nbsp;Brendan&nbsp;Saltaformaggio&nbsp;in the Cyber Forensics Innovation (CyFI) Lab. He finished his Master&nbsp;Degree in&nbsp;Cybersecurity&nbsp;before that. His research interests lie in cyber attack&nbsp;forensics, and binary analysis techniques. His current research focuses on cyber-threats abusing prestigious web services, aiming to adopt different novel strategies to&nbsp;boost the analysis process.</p>

<p>&nbsp;</p>
]]></body>
  <field_summary_sentence>
    <item>
      <value><![CDATA[Join us for a student led seminar series about today's security issues]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_summary>
  <field_time>
    <item>
      <value><![CDATA[2022-10-26T13:00:00-04:00]]></value>
      <value2><![CDATA[2022-10-26T14:00:00-04:00]]></value2>
      <rrule><![CDATA[]]></rrule>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_time>
  <field_fee>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_fee>
  <field_extras>
          <item>
        <value><![CDATA[free_food]]></value>
      </item>
      </field_extras>
  <field_audience>
          <item>
        <value><![CDATA[Faculty/Staff]]></value>
      </item>
          <item>
        <value><![CDATA[Public]]></value>
      </item>
          <item>
        <value><![CDATA[Graduate students]]></value>
      </item>
      </field_audience>
  <field_media>
          <item>
        <nid>
          <node id="661730">
            <nid>661730</nid>
            <type>image</type>
            <title><![CDATA[SCP Title Card]]></title>
            <body><![CDATA[]]></body>
                          <field_image>
                <item>
                  <fid>250652</fid>
                  <filename><![CDATA[SCP newsletter logo3.jpg]]></filename>
                  <filepath><![CDATA[/sites/default/files/images/SCP%20newsletter%20logo3.jpg]]></filepath>
                  <file_full_path><![CDATA[http://hg.gatech.edu//sites/default/files/images/SCP%20newsletter%20logo3.jpg]]></file_full_path>
                  <filemime>image/jpeg</filemime>
                  <image_740><![CDATA[]]></image_740>
                  <image_alt><![CDATA[]]></image_alt>
                </item>
              </field_image>
            
                      </node>
        </nid>
      </item>
      </field_media>
  <field_contact>
    <item>
      <value><![CDATA[<p>Pradyumna&nbsp;Shome, Ph.D. Student</p>

<p>pradyumna.shome@gatech.edu</p>
]]></value>
    </item>
  </field_contact>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_phone>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_phone>
  <field_url>
    <item>
      <url><![CDATA[]]></url>
      <title><![CDATA[]]></title>
            <attributes><![CDATA[]]></attributes>
    </item>
  </field_url>
  <field_email>
    <item>
      <email><![CDATA[]]></email>
    </item>
  </field_email>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <links_related>
          <item>
        <url>https://gatech.zoom.us/j/93110228192?pwd=amhYdzVkLzhOb3NHdVN5eTBKaDc0Zz09</url>
        <link_title><![CDATA[Attend Virtually on Zoom]]></link_title>
      </item>
          <item>
        <url>http://mingxuan.ece.gatech.edu/</url>
        <link_title><![CDATA[Mingxuan's Website]]></link_title>
      </item>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>47223</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[College of Computing]]></item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>1795</tid>
        <value><![CDATA[Seminar/Lecture/Colloquium]]></value>
      </item>
      </field_categories>
  <field_keywords>
          <item>
        <tid>1404</tid>
        <value><![CDATA[Cybersecurity]]></value>
      </item>
          <item>
        <tid>3221</tid>
        <value><![CDATA[privacy]]></value>
      </item>
          <item>
        <tid>2437</tid>
        <value><![CDATA[lecture]]></value>
      </item>
          <item>
        <tid>166896</tid>
        <value><![CDATA[seminar]]></value>
      </item>
          <item>
        <tid>167058</tid>
        <value><![CDATA[Student]]></value>
      </item>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
