← Search

Jack W Stokes

11 accepted papers

2025

Heterogeneous Graph Neural Network on Semantic Tree

AAAI 2025technical

The recent past has seen an increasing interest in Heterogeneous Graph Neural Networks (HGNNs), since many real-world graphs are heterogeneous in nature, from citation graphs to email graphs. However, existing methods ignore a tree hierarchy among metapaths, naturally constituted by different node t…

2021

Detection Of Malicious DNS and Web Servers using Graph-Based Approaches

ICASSP 2021accepted

The DNS hijacking attack represents a significant threat to users. In this type of attack, a malicious DNS server redirects a victim domain to an attacker-controlled web server. Existing defenses are not scalable and have not been widely deployed. In this work, we propose both unsupervised and semi-…

Cited by 0SourceScholar
2020

Detection of Malicious Vbscript Using Static and Dynamic Analysis with Recurrent Deep Learning

ICASSP 2020accepted

Attackers have used malicious VBScripts as an important computer infection vector. In this study, we explore a system that employs both static and dynamic analysis to detect malicious VBScripts. For the static analysis, we investigate two deep recurrent models, LaMP (LSTM and Max Pooling) and CPoLS…

Cited by 0SourceScholar
2020

Privacy-Preserving Phishing Web Page Classification Via Fully Homomorphic Encryption

ICASSP 2020accepted

This work introduces a fast and lightweight homomorphic-encryption pipeline that enables privacy-preserving machine learning for phishing web page recognition. The primary goals are to use visual features to train an accurate model and to implement an inference pipeline with practical runtime and co…

Cited by 0SourceScholar
2020

Texception: A Character/Word-Level Deep Learning Model for Phishing URL Detection

ICASSP 2020accepted

Phishing is the starting point for many cyberattacks that threaten the confidentiality, availability and integrity of enterprises' and consumers' data. The URL of a web page that hosts the attack provides a rich source of information to determine the maliciousness of the web server. In this work, we…

Cited by 0SourceScholar
2019

Attention in Recurrent Neural Networks for Ransomware Detection

ICASSP 2019accepted

Ransomware, as a specialized form of malicious software, has recently emerged as a major threat in computer security. With an ability to lock out user access to their content, recent ransomware attacks have caused severe impact at an individual and organizational level. While research in malware det…

Cited by 0SourceScholar
2019

Detecting Cyber Attacks Using Anomaly Detection with Explanations and Expert Feedback

ICASSP 2019accepted

Detecting cyber attacks in large computer networks is crucial for many organizations. To that purpose, different types of detectors capture the important signals resembling a security attack from individual computers and bring that to the attention of a security analyst. Unfortunately, the analyst s…

Cited by 0SourceScholar
2018

Neural Sequential Malware Detection with Parameters

ICASSP 2018accepted

Sequential models which analyze system API calls have shown promise for detecting unknown malware. Athiwaratkun and Stokes recently proposed a two-stage model which uses a long short-term memory (LSTM) model for learning a set of features which are then input to a second classifier. Kolosnjaji et al…

Cited by 0SourceScholar
2015

Malware classification with recurrent networks

ICASSP 2015accepted

Attackers often create systems that automatically rewrite and reorder their malware to avoid detection. Typical machine learning approaches, which learn a classifier based on a handcrafted feature vector, are not sufficiently robust to such reorderings. We propose a different approach, which, simila…

Cited by 0SourceScholar