<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>FP7-ICT-216026-WOMBAT</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/" />
    <link rel="self" type="application/atom+xml" href="http://wombat-project.eu/atom.xml" />
    <id>tag:wombat-project.eu,2008-03-19://1</id>
    <updated>2011-06-07T18:07:24Z</updated>
    <subtitle>Worldwide Observatory of Malicious Behaviors and Attack Threats  project public space</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Open Source 4.1</generator>

<entry>
    <title>D24/D6.4 Second Open Workshop Proceedings</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/05/d24d64-second-open-workshop-pr.html" />
    <id>tag:wombat-project.eu,2011://1.46</id>

    <published>2011-05-18T09:41:10Z</published>
    <updated>2011-06-07T18:07:24Z</updated>

    <summary>This is the deliverable for...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="FORTH-ICS" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="France Télécom R&amp;D-Orange Labs" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Hispasec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institute for Infocomm Research" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="NASK" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Politecnico di Milano" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Second open workshop" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Symantec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Vrije Universiteit Amsterdam" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP6-Dissemination" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wombatworkshop" label="Wombat workshop" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp6" label="WP6" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[This is the deliverable for the second wombat open workshop, BADGERS, that took place within the EuroSys 2011 conference on April 10 in Salzburg (Austria). In this document we discuss the preparation of the second workshop, our expectations vs. feedback and impressions we collected by authors and attenders. Proceedings are included.<br /><br /><br /><a href="http://wombat-project.eu/WP6/FP7-ICT-216026-Wombat_WP6_D24_V01_Second-Open-Workshop-Proceedings-BADGERS-2011.pdf">FP7-ICT-216026-Wombat_WP6_D24_V01_Second-Open-Workshop-Proceedings-BADGERS-2011.pdf<br /></a> ]]>
        
    </content>
</entry>

<entry>
    <title>D23/D5.3 Early Warning System: Experimental report</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/05/d23d53-early-warning-system-ex.html" />
    <id>tag:wombat-project.eu,2011://1.45</id>

    <published>2011-05-18T09:32:54Z</published>
    <updated>2011-05-18T09:36:22Z</updated>

    <summary>A large part of Workpackage...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="FORTH-ICS" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Hispasec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="NASK" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="earlywarningsystem" label="Early Warning System" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="experimentalreport" label="Experimental Report" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp5" label="WP5" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[A large part of Workpackage 5 concerns the Early Warning System functionality. This deliverable offers a report of the experiments carried out as part of the effort to create the Early Warning System. Several specialized alerting systems are presented, including FIRE, Exposure, BANOMAD and HoneyBuddy myIMhoneypot<br /><br /><br /><a href="http://wombat-project.eu/WP5/FP7-ICT-216026-Wombat_WP5_D23_V01_Early-warning-system-experimental-report.pdf">FP7-ICT-216026-Wombat_WP5_D23_V01_Early-warning-system-experimental-report.pdf</a><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>D22/D5.2 Root Causes Analysis: Experimental Report</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/05/d22d52-root-causes-analysis-ex.html" />
    <id>tag:wombat-project.eu,2011://1.44</id>

    <published>2011-05-18T09:22:57Z</published>
    <updated>2011-05-18T09:32:05Z</updated>

    <summary>This deliverable offers an extensive...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Hispasec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Symantec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="experimentalreport" label="Experimental Report" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp5" label="WP5" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[This deliverable offers an extensive report of all experiments carried out with respect to root cause analysis techniques. This final deliverable for Workpackage 5 (Threats Intelligence ) builds upon D12 (D5.1 - Technical Survey on Root Cause Analysis) and benefits from the modifications made to the various software modules developed in WP4, following up the experimental feedback.<br />The R&amp;D efforts carried out in WP5 with respect to root cause analysis have produced a novel framework for attack attribution called triage. This framework has been successfully applied to various wombat datasets to perform intelligence analyses by taking advantage of several structural and contextual features of the data sets developed by the different partners. These experiments enabled us to get insights into the underlying root phenomena that have likely caused many security events observed by sensors deployed by wombat partners.<br />In this deliverable, we provide an in-depth description of experimental results obtained with triage, in particular with respect to (i) the analysis of Rogue AV campaigns (based on&nbsp; HARMUR data), and (ii) the analysis of different malware variants attributed to the Allaple malware family (based on data from SGNET, VirusTotal and Anubis). <br />Finally, we describe another experiment performed on a large spam data set obtained from Symantec.Cloud (formerly MessageLabs), for which triage was successfully used to analyze spam botnets and their ecosystem, i.e., how those botnets are used by spammers to organize and coordinate their spam campaigns. Thanks to this application, we are considering a possible technology transfer of triage to Symantec.Cloud, who is interested in carrying out regular intelligence analyses of their spam data sets, and may ralso consider the integration of triage to their Skeptic ○ spam filtering technology.<br /><br /><br /><br /><a href="http://wombat-project.eu/WP5/FP7-ICT-216026-Wombat_WP5_D22_V01_Root-Cause-Analysis-Experimental-report.pdf">FP7-ICT-216026-Wombat_WP5_D22_V01_Root-Cause-Analysis-Experimental-report.pdf</a><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>D21/D4.7 Consolidated report with evaluation results</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/05/d21d47-consolidated-report-wit.html" />
    <id>tag:wombat-project.eu,2011://1.43</id>

    <published>2011-05-18T09:14:59Z</published>
    <updated>2011-05-18T09:30:02Z</updated>

    <summary>This is the final deliverable...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="FORTH-ICS" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="France Télécom R&amp;D-Orange Labs" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Hispasec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institute for Infocomm Research" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="NASK" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Politecnico di Milano" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Symantec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Vrije Universiteit Amsterdam" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP4-Data enrichment and characterization" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="evaluationresults" label="Evaluation results" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp4" label="WP4" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[This is the final deliverable for Workpackage 4 within the wombat project. In this document we discuss the final extensions and improvements to our data collection and analysis techniques that were implemented as part of wombat. Furthermore, we present some additional results obtained from the analysis of data collected within wombat.<br /><br /><br /><a href="http://wombat-project.eu/WP4/FP7-ICT-216026-Wombat_WP4_D21_V01_Consolidated-reports-with-evaluation-results.pdf">FP7-ICT-216026-Wombat_WP4_D21_V01_Consolidated-reports-with-evaluation-results.pdf</a><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>The Wombat API (WAPI) is now available on sourceforge</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/04/the-wombat-api-wapi-is-now-ava.html" />
    <id>tag:wombat-project.eu,2011://1.48</id>

    <published>2011-04-19T15:38:29Z</published>
    <updated>2011-06-09T15:50:25Z</updated>

    <summary> WAPI, or WOMBAT API,...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="FORTH-ICS" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="France Télécom R&amp;D-Orange Labs" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Hispasec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institute for Infocomm Research" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="NASK" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Politecnico di Milano" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Symantec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Vrije Universiteit Amsterdam" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP6-Dissemination" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="wapi" label="WAPI" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[


    <article id="project-description">
    <p>WAPI, or WOMBAT API, is a SOAP-based API built in the context of the project to facilitate the remote access and exploration of security-related datasets. </p>
</article>The package contains all the essential code to start using the WAPI. The WAPI represents an attempt to tackle two main challenges for
security data providers:

<br /><br />- Many of the data access primitives are not easily scriptable. Many data
sources provide web-based interfaces that, while easily accessible by human
operators, are not convenient for automated analysis.

<br /><br />- The interfaces for security datasets are very diverse in structure and
methodology. The analyst who wants to take advantage of multiple data sources
to perform correlations among them is thus forced to implement ad-hoc plugins
and parsers for each data feed. This process is not necessarily a simple task,
and requires the analyst to fully understand, for example, the schema of the
SQL database provided by the data owner.
<br /><br /><br /><br />You can find the package on sourceforge : <a href="http://sourceforge.net/projects/wombat-api/">http://sourceforge.net/projects/wombat-api</a>/<br /><br /><br />More information and details on WAPI are available in the <a href="http://wombat-project.eu/2010/02/wombat-deliverable-d10d63-seco.html">deliverable D10/D6.3</a>.<br /> ]]>
        
    </content>
</entry>

<entry>
    <title>WOMBAT second open workshop proceedings</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/04/wombat-third-open-workshop-pro.html" />
    <id>tag:wombat-project.eu,2011://1.42</id>

    <published>2011-04-18T11:57:32Z</published>
    <updated>2011-06-07T18:15:18Z</updated>

    <summary>This volume collects the proceedings...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Second open workshop" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP6-Dissemination" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Workshops and meetings" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="demonstrations" label="demonstrations" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="eurosys" label="EuroSys" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wombatworkshop" label="Wombat workshop" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[This volume collects the proceedings of the second WOMBAT Project Workshop,held on April 10 in Salzburg.<br /><br /><a href="http://wombat-project.eu/WP6/badgers2011-proceedings.pdf">badgers2011-proceedings.pdf</a><br />]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D18/D4.6 Final description of contextual features</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2011/04/wombat-deliverable-d18d46-fina.html" />
    <id>tag:wombat-project.eu,2011://1.41</id>

    <published>2011-04-13T11:34:35Z</published>
    <updated>2011-04-21T11:53:19Z</updated>

    <summary>The objective of Workpackage 4...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="FORTH-ICS" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Hispasec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="NASK" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Politecnico di Milano" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Symantec" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Vrije Universiteit Amsterdam" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="contextualfeatures" label="Contextual Features" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp6" label="WP6" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[The objective of Workpackage 4 is to develop techniques to characterize the malicious<br />code that is collected in the previous workpackage. The main idea is to enrich the<br />collected code thanks to metadata that might reveal insights into the origin of the code<br />and the intentions of those that created, released or used it.<br />This deliverable is an extension of D15 (D4.5), and provides a final description of the<br />contextual features collected within the wombat consortium. Furthermore, it presents<br />initial results, statistics, and insights obtained by analyzing the collected contextual<br />features.<br /><br /><a href="http://wombat-project.eu/WP4/FP7-ICT-216026-Wombat_WP4-D18_V01_Final-Contextual-features.pdf">FP7-ICT-216026-Wombat_WP4-D18_V01_Final-Contextual-features.pdf</a><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>WOMBAT second open workshop Call For Paper</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/12/wombat-third-open-workshop-cal.html" />
    <id>tag:wombat-project.eu,2010://1.39</id>

    <published>2010-12-09T18:18:51Z</published>
    <updated>2011-06-07T18:16:45Z</updated>

    <summary> BADGERS 2011 Building Analysis...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Second open workshop" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="eurosys" label="EuroSys" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="workshop" label="Workshop" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[<div id="logo">
	    <h1><font style="font-size: 1.5625em;"><b><a href="http://iseclab.org/badgers2011/"><font style="font-size: 0.8em;">BADGERS 2011</font></a></b></font></h1>
	    <p>Building Analysis Datasets and Gathering Experience Returns
              for Security</p><p><em>Workshop on development of large scale
              security-related data collection and analysis
              initiatives</em></p><p>The WOMBAT consortium will organise its second open workshop in Salzburg, Austria, on April 10. The BADGERS workshop is co-located with the
		  EuroSys 2011
		  conference. <a href="http://eurosys2011.cs.uni-salzburg.at/">Check
		  the conference page for up-to-date info</a>.</p><p><br /></p><p><br /><em></em></p><h2 class="title"><font style="font-size: 1.5625em;"><u><b>About BADGERS</b></u></font></h2><blockquote>
The BADGERS workshop is intended to encourage the development of large 
scale security-related data collection and analysis initiatives. It will
 provide an environment to describe already existing real-world, 
large-scale datasets, and to share with the systems community the return
 on experiences acquired by analyzing such collected data. Furthermore, 
novel approaches to collect and study such data sets are welcome.<br /></blockquote><br /><div class="entry">
		  <h2 class="title"><u><font style="font-size: 1.5625em;"><b>Call for Papers</b></font></u></h2>
        <p><font style="font-size: 1em;">In contrast to the systems community, security researchers 
have only recently started collecting and looking at large-scale, 
real-world data (e.g., the EU WOMBAT and the US PREDICT initiatives). It
 is well known that experimental work is often hampered by concerns such
 as confidentiality, privacy, and liability. However, the threat 
landscape is rapidly changing and this represents a growing concern for 
individuals and organisations. To address these issues appropriately, 
there is a dire need to better understand the modus operandi and the 
motivations of the attackers. This can only be achieved by getting 
access to large-scale, real-world data, and by designing techniques to 
mine relevant knowledge out of it.</font></p>

<p><font style="font-size: 1em;">This workshop aims at bringing together people (e.g., researchers, 
practitioners, system administrators, system programmers) active in the 
emerging domain of security-related data collection and analysis. By 
giving visibility to existing solutions, we expect that the workshop 
will promote and encourage the better sharing of data and knowledge.</font></p>

<p><font style="font-size: 1em;">By co-locating the BADGERS workshop with EuroSys, we wish to create a
 bridge between the well-established systems community and the members 
of the security community who are interested in experimental systems 
work.</font></p>

<p><font style="font-size: 1em;">The BADGER workshop solicits two kinds of submissions: Regular papers and
work in progress papers. Regular papers should not exceed 8 pages,
excluding well-marked appendixes. Work in progress papers should not
exceed two pages.</font></p>
		</div><font style="font-size: 1em;"><br /></font><h3><font style="font-size: 1.5625em;"><u><b>Submissions</b></u></font></h3><font style="font-size: 1em;">
	Papers can be submitted to the workshop through the <a href="https://eurosys2011.ertos.nicta.com.au/workshops/badgers/hotcrp/">HotCrp Submission System</a> that we've set up.
		</font><br /><p><em></em></p>
	  </div> ]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D17/D4.4 Final Analysis Report of Structural Features</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/08/wombat-deliverable-d17d44-fina.html" />
    <id>tag:wombat-project.eu,2010://1.38</id>

    <published>2010-08-01T17:01:07Z</published>
    <updated>2010-12-17T18:17:33Z</updated>

    <summary>This deliverable is a final...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Politecnico di Milano" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP4-Data enrichment and characterization" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="structuralfeatures" label="Structural features" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp4" label="WP4" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[This deliverable is a final report on the experimental results obtained by using structural<br />features to characterize executable code. It discusses and evaluates a number of tech-<br />niques, based on these features, that have been developed in the context of the wombat<br />project, and aim to provide a deeper understanding of malicious code and of the relations<br />between malicious code samples.<br /><div><br /><br /><a href="http://wombat-project.eu/WP4/FP7-ICT-216026-Wombat_WP4_D17_V01_Final_Analysis_Report_of_Structural_features.pdf">FP7-ICT-216026-Wombat_WP4_D17_V01_Final_Analysis_Report_of_Structural_features.pdf</a><br /></div><div><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D16/D4.2 Analysis Report of Behavioral Features</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/07/wombat-deliverable-d16d42-anal.html" />
    <id>tag:wombat-project.eu,2010://1.40</id>

    <published>2010-07-31T17:42:51Z</published>
    <updated>2010-12-17T18:48:49Z</updated>

    <summary>This deliverable provides a discussion...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Vrije Universiteit Amsterdam" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP4-Data enrichment and characterization" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="behavioralfeatures" label="Behavioral Features" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp4" label="WP4" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[This deliverable provides a discussion of the features used to characterize the behavior<br />of code, and a discussion of preliminary results of applying these features to a set of<br />malicious code. It discusses the project's results in behavior-based clustering, malware<br />detection at end hosts in different ways, system call analysis, but also our work on<br />shellcode behavior.<br /><br /><a href="http://wombat-project.eu/WP4/FP7-ICT-216026-Wombat_WP4_D16_V01_Analysis-Report-of-Behavioral-features.pdf">FP7-ICT-216026-Wombat_WP4_D16_V01_Analysis-Report-of-Behavioral-features.pdf</a><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D15/D4.5 Intermediate Report on Contextual Features</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/02/wombat-deliverable-d15d45-inte.html" />
    <id>tag:wombat-project.eu,2010://1.37</id>

    <published>2010-02-16T17:09:17Z</published>
    <updated>2010-02-22T14:11:22Z</updated>

    <summary>The objective of this Workpackage...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP4-Data enrichment and characterization" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="contextualfeatures" label="Contextual Features" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp4" label="WP4" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[<font><font size="2">The objective of this Workpackage 4 is to develop techniques to characterize the malicious code that is collected in the previous workpackage. The main idea is to enrich the collected code thanks to metadata that might reveal insights into the origin of the code and the intentions of those that created, released or used it. This deliverable provides a preliminary discussion of possible contextual features of malware, and for each feature, an estimate on its effectiveness and the difficulty to obtain it. Some of these features can be used to analyze potential threats and discriminate collected samples that are mere variations of already known threats.</font><br /><br /><a href="http://wombat-project.eu/WP4/FP7-ICT-216026-Wombat_WP4-D15_V01_Intermediate-Contextual-features.pdf">FP7-ICT-216026-Wombat_WP4-D15_V01_Intermediate-Contextual-features.pdf</a><br /><br /></font> ]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D13/D3.3 Sensor Deployment</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/02/wombat-deliverable-d13d33-sens.html" />
    <id>tag:wombat-project.eu,2010://1.36</id>

    <published>2010-02-16T16:58:21Z</published>
    <updated>2010-02-16T17:08:12Z</updated>

    <summary>This deliverable reports the deployment...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="FORTH-ICS" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP3-Data collection and distribution" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sensordeployment" label="Sensor Deployment" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp3" label="WP3" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[<font><font size="2">This deliverable reports the deployment of all types of sensors implemented in the WOMBAT project and includes descriptions of experiences with the sensors from several months of deployment and experimentation. The sensors that are deployed are the SGNET, HARMUR, Shelia, Paranoid Android, HoneySpider Network, Bluebat and NoAH. The early experiences show that the WOMBAT Project is fulfilling our preliminary expectations about having powerful tools for collecting data. These data are useful for categorizing attackers and malware behaviors. Moreover our experiments reveal that the sensors can cooperate with each other, enriching in this way the information offered for analysis.</font><br /><br /><a href="http://wombat-project.eu/WP3/FP7-ICT-216026-Wombat_WP3_D13_V01-Sensor-deployment.pdf">FP7-ICT-216026-Wombat_WP3_D13_V01-Sensor-deployment.pdf</a><br /><br /></font> ]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D12/D5.1 Root Causes Analysis</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/02/wombat-deliverable-d12d51-root.html" />
    <id>tag:wombat-project.eu,2010://1.35</id>

    <published>2010-02-16T16:46:07Z</published>
    <updated>2010-02-16T16:57:37Z</updated>

    <summary>This deliverable aims at giving...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Institut Eurecom" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP5-Threat Intelligence." scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="rootcausesanalysis" label="Root Causes Analysis" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp5" label="WP5" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[<font><font size="2">This deliverable aims at giving an overview of existing techniques for root cause analysis, and provides some preliminary results with respect to the root cause analysis work performed in the project so far. The deliverable is mainly made up of 6 published peer-reviewed papers and one technical report that has reached a wide-audience.<br /><br /><a href="http://wombat-project.eu/WP5/FP7-ICT-216026-Wombat_WP5_D12_V01_RCA-Technical-survey.pdf">FP7-ICT-216026-Wombat_WP5_D12_V01_RCA-Technical-survey.pdf</a><br /></font></font> ]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D11/D4.3 Intermediate Analysis Report of Structural Features</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/02/wombat-deliverable-d11d43-inte.html" />
    <id>tag:wombat-project.eu,2010://1.34</id>

    <published>2010-02-16T16:33:16Z</published>
    <updated>2010-02-16T16:40:29Z</updated>

    <summary>This deliverable provides a preliminary...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Technical University Vienna" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP4-Data enrichment and characterization" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="deliverable" label="Deliverable" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="executablecodecharacterization" label="Executable code characterization" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="structuralfeatures" label="Structural features" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wp4" label="WP4" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[<font><font size="2">This deliverable provides a preliminary discussion of structural features that can be used to characterize executable code. Furthermore, it discusses a number of techniques, based on these features, that are being developed in the context of the wombat project, and aim to provide a deeper understanding of malicious code and of the relations between malicious code samples.</font><br /><br /><a href="http://wombat-project.eu/WP4/FP7-ICT-216026-Wombat_WP4_D11_V01-Intermediate-analysis-report-of-structural-features.pdf">FP7-ICT-216026-Wombat_WP4_D11_V01-Intermediate-analysis-report-of-structural-features.pdf</a><br /></font> ]]>
        
    </content>
</entry>

<entry>
    <title>Wombat Deliverable D10/D6.3 First WOMBAT open workshop proceedings</title>
    <link rel="alternate" type="text/html" href="http://wombat-project.eu/2010/02/wombat-deliverable-d10d63-seco.html" />
    <id>tag:wombat-project.eu,2010://1.33</id>

    <published>2010-02-16T16:19:27Z</published>
    <updated>2011-06-07T18:23:41Z</updated>

    <summary>This volume collects the presentations...</summary>
    <author>
        <name>Nicolas Deschamps</name>
        
    </author>
    
        <category term="Deliverables" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="First open workshop" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="WP6-Dissemination" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="demonstrations" label="demonstrations" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="raid" label="RAID" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="stmalo" label="St Malo" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wapi" label="WAPI" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="wombatworkshop" label="Wombat workshop" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://wombat-project.eu/">
        <![CDATA[<font><font size="2">This volume collects the presentations and handouts of the first WOMBAT open Workshop,held on September 22-23, 2009 in St. Malo. This year's workshop focuses on the introduction of early results of the project, and in particular on the Wombat APIs or WAPI, a set of API developed by the project partners to allow integrated access to different attack dataset. <br />
The aim of the workshop was to give participants a first-hand experience on how the WAPIs<br />
help the analyst and the researcher in investigating new phenomena. The demos and presentations were prepared thanks to the collective effort of the project partners: France Telecom, Hispasec, Politecnico di Milano, Technical University of Vienna, Institut<br />
Eurecom, FORTH-ICS, Symantec Corporation, Vrije Universiteit Amsterdam, Institute for Infocomm Research, NASK.<br /><br /><a href="http://wombat-project.eu/WP6/FP7-ICT-216026-Wombat_WP6_D10_V01_2nd-Wombat-Proceedings-St-Malo.pdf">FP7-ICT-216026-Wombat_WP6_D10_V01_2nd-Wombat-Proceedings-St-Malo.pdf</a><br /></font><br /><br /></font> ]]>
        
    </content>
</entry>

</feed>

