Bobby Filar Profile Banner
Bobby Filar Profile
Bobby Filar

@filar

2,099
Followers
948
Following
316
Media
6,271
Statuses

dad. security machine learning @sublime_sec fmr: @elastic , @endgameinc

MPLS
Joined July 2008
Don't wanna be here? Send us removal request.
@filar
Bobby Filar
4 years
Excited to see @elastic open up its detection rules repo. Blog post by @rw_access does a great job detailing how to get rules into your detection engine and how best to contribute to the community.
2
59
157
@filar
Bobby Filar
4 years
Finally releasing MalwareRL, an OpenAI gym for Ember and MalConv malware classifiers. This builds on the RL research @drhyrum @mrphilroth and I did on malware evasions. There are new binary modifications and a baseline (random) agent to get you started.
2
43
105
@filar
Bobby Filar
6 years
Me avoiding feature tickets in JIRA during that final sprint before testing...
3
9
96
@filar
Bobby Filar
4 years
@newbury_eric @passantino @neontaster You're right these can definitely can be used as an alternative, but they are still not ventilators. Saying that you sent ventilators when you actually sent CPAP machines is why articles like this get written.
4
1
80
@filar
Bobby Filar
5 years
About to give my talk at #VB2019 on using ML and graph theory to identify malicious process chains in event data. Slides here:
3
36
87
@filar
Bobby Filar
3 years
I am beyond excited about the SecML team's work here @elastic . This post shows how our team uses transforms to identify beaconing malware. We hope this post encourages security researchers to prototype new statistical models to detect bad in their data!
0
18
85
@filar
Bobby Filar
6 years
@SwiftOnSecurity @HuntOperator - Where do they get training data? - How do they generate labels? - What are the performance metric? - How often are models retrained? (Do they degrade over time?) - How well does it generalize to previously unobserved samples/events?
3
2
79
@filar
Bobby Filar
6 years
Ember: An Open Source Classifier And Dataset by @EndgameInc . Huge step forward for reproducibility in malware classification research. Thanks @mrphilroth and @drhyrum for your hard work! Github: Blog:
1
38
69
@filar
Bobby Filar
7 years
Two ML/infosec papers on identifying malicious strings: Predicting Domain Generation Algorithms with LSTMs by @jswoodbridge et al. eXpose: A Char-Level CNNs For Detecting Malicious URLs, Paths and Reg Keys by @joshua_saxe et al.
1
39
68
@filar
Bobby Filar
5 years
Just came across @struppigel 's "Malware Analysis For Hedgehogs" channel. His breakdown of the Basic Structure of PE Files is super helpful for Data Scientists who may be working on malware classification. Very simple, intuitive explanations.
2
20
66
@filar
Bobby Filar
7 years
A fantastic book is now a great online resource too! "Data Science at the Command Line" by @jeroenhjanssens is now freely available at:
0
17
59
@filar
Bobby Filar
2 years
I am excited to start my new role as the Head of Data Science at @sublime_sec . I look forward to showing how we can combine ML & custom rule logic to build a genuinely novel, adaptable, and transparent email security experience.
4
4
60
@filar
Bobby Filar
5 years
@caleb_fenton @JulesBaderrrr @pantalea0 @j_opdenakker i haven't seen this post in ages, but it still cracks me up
0
1
55
@filar
Bobby Filar
2 years
After 7 years, today is my last day at @elastic . I am incredibly lucky to have worked with such a talented group! I want to thank @mark_dufresne and @snowboardvstree for their patience, mentorship, and friendship. @SamanthaZeitlin for her outstanding leadership
8
0
54
@filar
Bobby Filar
6 years
More evidence that I work w/ some brilliant folks @EndgameInc . 2 #BHUSA Talks accepted! @malwareunicorn & @rseymour - FINDING XORI: MALWARE ANALYSIS TRIAGE WITH AUTOMATED DISASSEMBLY @dez_ & @gabriellandau - KERNEL MODE THREATS AND PRACTICAL DEFENSES
0
16
55
@filar
Bobby Filar
7 years
Two books coming out this year on Machine Learning in Infosec by some real smart folks. "Machine Learning and Security" by @cchio & Freeman (Facebook) "Malware Data Science" by @joshua_saxe & @hillarymsanders
0
21
53
@filar
Bobby Filar
6 years
PassGAN: A Deep Learning Approach for Password Guessing. Great breakdown of GAN architecture and how it works w/ text datasets. Paper: Code:
Tweet media one
0
24
54
@filar
Bobby Filar
6 years
RAPTOR: Ransomware Attack PredicTOR DGA features coupled w/ time series methods used to build model to identify potentially malicious domains while watching new DNS registrations. Interesting approach, susceptible to bypass by sophisticated adversaries.
1
27
51
@filar
Bobby Filar
3 years
Machine learning proverb
Tweet media one
0
9
53
@filar
Bobby Filar
7 years
2 great posts on WCry by @EndgameInc researchers. Covers both analysis and prevention.
2
26
45
@filar
Bobby Filar
3 years
In the post on "Linux malware protection in @elastic Security," @DanielStepanic and @gradientjanitor show how we leverage ML to generate YARA signatures for detecting Linux malware. Code included below. Post: Repo:
Tweet media one
0
12
47
@filar
Bobby Filar
3 years
No @CamlisOrg submission for me this year. Spending a lot of time with my new reinforcement learning project…
Tweet media one
0
1
47
@filar
Bobby Filar
3 years
I really like this graphic the folks #ThreatHuntingSummit made for @randomuserid talk on "Practical Threat Hunting w/ ML." It captures how we can effectively leverage (un)supervised ML w/o drowning users in FP-prone signals.
Tweet media one
0
14
47
@filar
Bobby Filar
7 years
Infosec Data Scientists there is a new dataset to start tinkering with courtesy of @Andrew___Morris Greynoise API Python Wrapper
@Andrew___Morris
Andrew Morris
7 years
My dude @filar coming in hot with the library and ipython notebook analysis of Grey Noise data approximately 0.34125 seconds after it was released
Tweet media one
Tweet media two
1
1
10
0
20
47
@filar
Bobby Filar
2 years
Using GPT-3 to craft phishing emails to test against the @sublime_sec NLU engine is way more fun than I expected to have on a Monday afternoon.
Tweet media one
Tweet media two
2
7
43
@filar
Bobby Filar
6 years
Important ML+Infosec research from @MSFTResearch . "Neural Classification of Malicious Scripts: A study with JavaScript and VBScript" Highlights difficulties of building a proper dataset and challenges working w/ malicious scripts.
1
27
45
@filar
Bobby Filar
6 years
"Using Recurrent Neural Networks for Decompilation" Uses machine translation methods to decompile binaries. Really cool to see Deep Learning NLP techniques applied to the security space.
0
17
43
@filar
Bobby Filar
5 years
Re-reading @willcfleshman 's post on winning the Malware Evasion Comp. Excellent breakdown of potential blindspots in deep learning (MalConv) and tree-based (Ember) classifiers. Also good background on the malware features used in these models.
0
20
43
@filar
Bobby Filar
4 years
I’m super excited that ML-backed Malware Prevention is being released under the free tier. Congrats to @mrphilroth and the rest of the Data Science team on getting this feature developed and released!
@elastic
Elastic
4 years
Elastic 7.9 is now available! Elastic Agent (beta) and one-click data ingestion simplify data onboarding and ingest management in the #ElasticStack . Plus, we’re launching malware prevention and Workplace Search features under the free distribution tier →
7
85
130
1
3
42
@filar
Bobby Filar
4 years
"From 0 to 60 with Elastic Security" by @wesleyraptor is an excellent end-to-end tutorial on how to create an Adversary Simulation Environment, collect data, and explore the results w/in the Elastic ecosystem.
1
12
40
@filar
Bobby Filar
6 years
Posting slides from my @BsidesDC talk "Bringing Red vs. Blue to Machine Learning" High-level overview of adversarial ML nomenclature/techniques, plus "practical" application via scenario-based RvBs
1
29
40
@filar
Bobby Filar
2 months
I cannot believe it's already been two years since I joined @sublime_sec . Super interesting work with a great group of people has made the time fly by. I cannot wait to see what comes next!
3
1
41
@filar
Bobby Filar
6 years
Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection. Unsupervised approach to identifying network intrusions. Great section on adversarial attacks & countermeasures. Paper: Code:
0
19
40
@filar
Bobby Filar
6 years
My talk proposal “Bringing Red vs. Blue to Machine Learning” was accepted!!!
@BsidesDC
BSidesDC
6 years
Speaker notifications are going out! If you submitted keep an eye on your inbox!
2
7
21
4
5
40
@filar
Bobby Filar
7 years
Awesome Machine Learning for Cyber Security by @jivoi Great resource for datasets, papers and talks
0
17
40
@filar
Bobby Filar
6 years
Adversarial Malware Binaries: Evading Deep Learning for Malware Detection in Executables by @biggiobattista et al. Targets the MalConv DL malware model. This group has been doing adversarial research for a while and their papers are fantastic!
2
22
40
@filar
Bobby Filar
6 years
0
10
39
@filar
Bobby Filar
4 years
I'm worried that WFH is rubbing off on my 4y.o... She just came into my office, brow furrowed, saying "the server must be down or something" while holding an iPad w/ a crashed kid's app.
4
3
39
@filar
Bobby Filar
5 years
Pumped to have my talk "TreeHuggr: Discovering where tree-based classifiers are vulnerable to adversarial attack" accepted @USENIXSecurity ScAINet19
3
4
37
@filar
Bobby Filar
6 years
"Quantifying the Robustness of ML & Current Anti-Virus" by @willcfleshman & @EdwardRaffML introduces adversarial testing methodology focused on binary manipulations. Also excellent list of ML/infosec papers in the References section.
3
21
36
@filar
Bobby Filar
5 years
"Why We Release Our Research" @drhyrum , @comathematician and myself layout the importance of releasing ML research to the academic and infosec communities.
2
10
37
@filar
Bobby Filar
2 years
If you're going to @defcon , check out @aivillage_dc . They have a fantastic set of talks lined up: - @harini on modeling User Behavior - @NMspinach on hacking RL systems - Salma Taoufiq and Ben Gelman ( @SophosAI ) - Alert Prioritization - @drhyrum on this year's ML Evasion Comp!
1
8
35
@filar
Bobby Filar
3 years
If you are interested in how the @elastic Security Data Science team implemented a stack-based model for detecting anomalous parent-child processes, read our post on ProblemChild. Code and feature transforms made available too!
0
12
37
@filar
Bobby Filar
4 years
My 4y.o. daughter is really getting into chess and lately she’s become obsessed with endgame puzzles. She likes writing down the notation to practice her letters/numbers.
Tweet media one
4
0
36
@filar
Bobby Filar
4 years
Excited to present "Getting Passive Aggressive About False Positives" @USENIXSecurity SCAINet in August w/ @EdwardRaffML . We will demonstrate how human-in-the-loop feedback via PA algorithms can enable global malware models to gain local knowledge to reduce FPs.
1
9
34
@filar
Bobby Filar
2 years
Fridays on our team are now "Research Fridays" to allow folks to nerd out on an applied SecML/MLOps problem. I spent the day implementing the transformer in URLTran: Improving Phishing URL Detection w/ @PyTorch & @huggingface Paper, code, and data tips:
1
6
33
@filar
Bobby Filar
6 years
"Neural Machine Translation Inspired Binary Code Similarity Comparison beyond Function Pairs" Really neat use of NLP techniques applied to the security domain. Paper: Model/Embeddings:
2
13
34
@filar
Bobby Filar
2 years
Acquiring a dataset for Macro-based malware classification is tough! However, yesterday I stumbled across this paper/dataset containing featurized and raw macro data. It is an excellent place to start experimenting. Dataset: Paper:
1
6
33
@filar
Bobby Filar
1 year
Just gave a shout out to my 7 year old during my BSidesLV talk. I told we her it was going to be streamed and she naturally assumed I’m a YouTube star.
2
0
34
@filar
Bobby Filar
6 years
End-to-End Active Learning for Computer Security Experts. Useful looking interface for labeling data and training/analyzing models. Github: Paper:
0
15
33
@filar
Bobby Filar
7 years
Pumped to see @EndgameInc listed in the AI 100 by @CBinsights
Tweet media one
1
13
30
@filar
Bobby Filar
4 years
I the ported code from the @EndgameInc paper "Predicting Domain Generation Algorithms using LSTMs" over to py3 and Tensorflow 2. Updates to DGA datasets and interpretability methods coming soon.
1
13
29
@filar
Bobby Filar
6 years
Had a blast presenting my talk “Bringing Red vs. Blue to ML” today @BsidesDC Thanks for all who stuck around until the end and asked such great questions!
2
4
29
@filar
Bobby Filar
5 years
Really excited to be a part of the new Security Data Science Team @elastic !
@elastic
Elastic
5 years
We’ve officially joined forces with @EndgameInc . Hear from CEO Shay Banon ( @kimchy ) and Endgame CEO Nate Fick ( @ncfick ) live on Oct. 15 at 8:30 a.m. EDT to learn more about what we have in store →
Tweet media one
0
61
91
1
3
31
@filar
Bobby Filar
1 year
Excited that my @BSidesLV talk has been accepted! I will be introducing BabbelPhish, our upcoming open source framework for text-to-code generation. I'll also show how @sublime_sec uses LLMs to make it easier for detection engineers to grasp our DSL.
2
6
31
@filar
Bobby Filar
5 years
. @andyplayse4 presenting on making Meterpreter an Adversarial Example. Using some research from @EndgameInc on Reinforcement Learning for Malware Evasion.
0
15
31
@filar
Bobby Filar
2 years
A new Python-based parser for preprocessing and feature engineering on Portable Executable (PE) files. This is a great way to start ML research on windows binaries. - metadata - ngrams - entropy - generate grayscale image representations.
2
10
30
@filar
Bobby Filar
8 years
If you thought the Iliad was too short and love Reverse Engineering check out @MalwareMechanic 's post on @EndgameInc
2
18
27
@filar
Bobby Filar
4 years
WFH @zoom_us meetings in DC...
Tweet media one
1
0
29
@filar
Bobby Filar
6 years
Happy Father’s Day everyone! Here is my daughter getting into a dance off with a windsock.
0
1
29
@filar
Bobby Filar
1 year
We took our 7 year old to San Diego for her spring break. After the zoo, we went to a brewery where we saw her go up to the bartender to order a Sprite and pretzels and say “put it on my parents tab. It’s under filar”.
2
0
29
@filar
Bobby Filar
7 years
New headshot courtesy of @OReillySecurity was interrupted by a clever girl
Tweet media one
1
3
29
@filar
Bobby Filar
6 years
"Detecting Homoglyph Attacks with a Siamese Neural Network" Presented @IEEESSP workshop by @EndgameInc researchers @drhyrum @jack8daniels2 and Daniel Grant. Targets name spoofing commonly used to obfuscate file and domain names in malware/C2 comms.
0
10
27
@filar
Bobby Filar
6 years
Highlights from @drhyrum & @phtully #RSAC18 talk on "Navigating the Data Labeling Bottleneck as Security Embraces Artificial Intelligence"
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
17
24
@filar
Bobby Filar
5 years
Deceiving Portable Executable Malware Classifiers into Targeted Misclassification with Practical Adversarial Samples. Comprehensive lit review and interesting approach from the authors.
0
4
26
@filar
Bobby Filar
3 months
If you are at RSA next week, swing by the @sublime_sec booth, so we can talk about: - Email security - Machine learning - The Minnesota Timberwolves
@sublime_sec
Sublime Security
3 months
If you're attending RSA next week: @filar will give a talk at our booth on Tues & Wed at 10:45am. Learn how explainable, transparent machine learning provides much-needed confidence and context in your triage workflow.
Tweet media one
0
2
7
2
4
27
@filar
Bobby Filar
6 months
New mantra just dropped…
Tweet media one
4
2
26
@filar
Bobby Filar
4 years
Thinking about starting a food truck in DC for election season called "The Deep Steak" Let me know if you'd like to invest.
5
4
25
@filar
Bobby Filar
6 years
Packed house @aivillage_dc for @magerbomb talk on using Sentiment Analysis to identify notes dropped by ransomware.
Tweet media one
0
7
26
@filar
Bobby Filar
5 years
Excited to present TreeHuggr: Discovering Where GBDTs are Vulnerable to Adversarial Attack at @USENIXSecurity ScAINet Workshop this morning!
0
3
25
@filar
Bobby Filar
6 years
Congrats to the @EndgameInc researchers for getting their paper "Detecting Homoglyph Attacks with a Siamese Neural Network" accepted in to the @IEEESSP Deep Learning & Security Workshop! Looks like a great list of talks!
Tweet media one
1
6
26
@filar
Bobby Filar
6 years
"TreeHuggr: Discovering where tree-based classifiers are vulnerable to adversarial attack" was accepted to @CamlisOrg !!!
1
7
26
@filar
Bobby Filar
5 years
"Feature Selection for Malware Detection Based on Reinforcement Learning" An agent is trained through Q-learning to maximize expected accuracy. Action space covers PE header, section and import table.
Tweet media one
1
9
24
@filar
Bobby Filar
6 years
Anyone working on Insider Threat detection? @SEInews has a pretty neat dataset that provides both background and malicious actor synthetic data. Data: Paper:
1
6
25
@filar
Bobby Filar
6 years
Part 2 of the "Detecting Phishing With Computer Vision" series by @EndgameInc researchers @laborious_dtg and Bill Finlayson. Provides a great overview of CV techniques and how they applied the YOLO object detection framework. Lots of code samples too!
0
15
24
@filar
Bobby Filar
6 years
How AI can help in infosec (if it can fight through the marketing hype) by @lilyhnewman @mrphilroth offers his opinion and shares some valuable insights he gained while creating @EndgameInc malware classifier and the Ember dataset.
0
9
25
@filar
Bobby Filar
6 years
"MEADE: Towards a Malicious Email Attachment Detection Engine" by @rharang & @joshua_saxe Super interesting research highlighting features to leverage, classifier comparison, and future research considerations.
0
7
24
@filar
Bobby Filar
6 years
"Anomaly Detection in Cyber Network Data Using a Cyber Language Approach" by @keeghin and team. Creates a language to build a probabilistic tree structure to identify interesting network events.
1
15
24
@filar
Bobby Filar
4 years
Explaining to my 3y.o. a proposal I just saw that would give her $1K. Me: "What would you do with $1000?" C: "A $1000 cash money?" Me: "Yep." C: "I would probably put that into my ice cream shop" Reinvesting in her small business...
2
2
23
@filar
Bobby Filar
5 years
Are you interested in machine learning & security? My team at @elastic is hiring a Security Data Scientist. Come work on malware classification, detecting anomalous events, and more!
0
12
24
@filar
Bobby Filar
4 years
Elastic Security Data Science is looking for a Security Researcher to help grow our malware prevention capabilities. If you have experience in malware analysis or RE w/ a passion for ML we want to hear from you! DM if you have any questions.
1
20
24
@filar
Bobby Filar
2 years
We added a new member to the family! Meet Frankie
Tweet media one
1
0
23
@filar
Bobby Filar
1 year
Tweet media one
1
1
24
@filar
Bobby Filar
4 years
I’m super excited to have @gradientjanitor onboard the Security Data Science team @elastic starting today! Interested to see what he and @mrphilroth cook up for Malware Classification.
1
0
23
@filar
Bobby Filar
6 years
If you needed another reason to attend @aivillage_dc this weekend @Andrew___Morris is providing 60 days of @GreyNoiseIO API access for those who stop by. Check out his talk this Friday @ 1:20pm
0
10
23
@filar
Bobby Filar
6 years
Best papers I read this week: "Statistical Estimation of Malware Detection Metrics in the Absence of Ground Truth" "Two Can Play That Game: An Adversarial Evaluation of a Cyber-alert Inspection System"
0
9
23
@filar
Bobby Filar
3 years
Spent some time this weekend building a simple (crappy) annotation platform for a NER model I'm building. The idea is to extract entities from poorly written vulnerability reports to grab software name/version info.
Tweet media one
Tweet media two
Tweet media three
3
0
23