3/30562
label Burse autorenew 2025-09-29, 17:01 history_edu Cristian Ion
SEC performs research in two areas vital to the security of decentralized and embedded systems: security-policy specification & enforcement, and security of embedded systems.

The vacancy is within the SpySpot project, part of the long-term-research program Cyber Security of the NWO, the Dutch organization for Scientific Research, financed by NWO-EW and STW.

SpySpot seeks to combine advanced network intrusion detection and visualization techniques to enable the detection of Advanced Persistent Threats and sophisticated attacks for exfiltration of data or sabotage of systems.

This call is for a PhD student position within the Security group. There will be a strong cooperation with the Visualization group (a separate call is available for the PhD position available in that group).



Project Description:

Cyber-attacks have grown in number and sophistication, achieving unprecedented success in reaching their targets. Advanced Persistent Threats (APTs) such as data exfiltration attacks are both dangerous and difficult to detect. These targeted and stealthy attacks using specifically developed malware circumvent classical detection systems based on signatures or statistical anomalies in network traffic. Only by looking in detail at the actual content of communication would it be possible to detect APTs. A method is thus needed to analyse the huge amount of data involved in an effective way.

SpySpot proposes a solution which combines deep packet analysis with visualization of the analysis results enabling an end user to easily spot anomalies created by APTS like digital espionage. In the deep packet analysis the meaning of communication is recovered using protocol syntax and semantics, abstraction brings additional structure to this meaning and anomaly detection finds patterns deviating from the norm.

While automated analysis is needed to manage the huge amount of data, no automatic method can match the ability of the human mind in recognizing deviations and evaluating these. The analysis will thus support visualization of results for human-based evaluation and be able to take into account feedback on the discovered anomalies, such as discarding harmless ones in future traffic.