QSignature 1.0: A Dynamical Regime Classification Framework for Causal Time Series Data
14th International Symposium on Digital Forensics and Security, ISDFS 2026, Massachusetts, Amerika Birleşik Devletleri, 19 - 20 Mart 2026, (Tam Metin Bildiri)
- Yayın Türü: Bildiri / Tam Metin Bildiri
- Doi Numarası: 10.1109/isdfs69419.2026.11459049
- Basıldığı Şehir: Massachusetts
- Basıldığı Ülke: Amerika Birleşik Devletleri
- Anahtar Kelimeler: causal response, dynamical systems, ECU-MALNETT, forensic analysis, linear time-invariant systems, open-source code, persistence timescales, regime classification, Δsu
- İstanbul Ticaret Üniversitesi Adresli: Evet
Özet
The causal response of a system to external perturbation encodes its governing dynamical signature. When only the output response R(t) is observable without knowledge of the input or a parametric model, inferring the system class remains a fundamental challenge. This work introduces two persistence timescale estimators, τs and τu, which yield two scalar diagnostics, Δsu= (τs-τu) / τu and Rsu=τs/ τu. These diagnostics provide a fingerprint of linear time-invariant dynamical systems. Evaluation on 49 canonical systems yields five distinct regions in the (Δsu, Rsu) plane (QSpace): exponential monotonic, fractional, underdamped, weakly damped, and conservative oscillatory. The framework admits direct physical interpretation: Δsu varies monotonically with the damping ratio ζ, and negative Rsu signals centroid reversal in weakly damped systems. Crucially, we applied the framework to real-world forensic data, analyzing 20 malware execution traces from the ECU-MALNETT corpus, which contains 20,500 samples across 58 families, focusing on APT28, APT29, and Lazarus families, Packet-rate analysis reveals distinct behavioral fingerprints: APT29 exhibits weakly damped beaconing (Δsu ≈-1.14, Rsu ≈-0.14), APT28 shows extreme oscillatory activity (Δsu<-2.0), and Lazarus spans multiple regimes, all distinguishable purely from timing signatures without deep packet inspection. The QSignature library implementing these estimators is available on GitHub.