VLDB 2026 Research / reviewers in the wild / expert
Shuyuan Jin
dblp:04/4127
· DBLP profile ↗
43ranked-venue papers
6as first author
22since 2021 · last 2026
0000-0003-2087-2853ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 8 · 2 first-author · 2 since 2021Computer networks · 8 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 7 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-authorSystems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LuaReSym: Recovering Variable Liveness Ranges in Stripped Lua Bytecode via Multi-Stage Static AnalysisabstractLua is a lightweight scripting language widely adopted across diverse application domains. In practice, Lua applications are often distributed as compiled bytecode to protect intellectual property and improve loading efficiency. Existing Lua decompilers rely heavily on debug symbols embedded in bytecode to generate human-readable code. When debug symbols are stripped, these tools utilize heuristic-based methods to infer variable liveness ranges. However, existing heuristic methods often produce inaccurate predictions, reducing the readability of the decompilation results. Ruizhi Xiao, Jiakun Sun, Yuqing Shao, Shuyuan Jin |
ICPC | 6 |
| 2026 | CeeDet: A Class-Incremental Learning Method with Early-Exit Mechanism for Malicious Traffic Detection in IIoT
Jiakun Sun, Ruizhi Xiao, Shuyuan Jin |
PAKDD (1) | 5 |
| 2026 | AutoGuard: Unified and lightweight cross-layer intrusion detection for automotive ethernet via contextual traffic analysis
Wentao Shang, Shuyuan Jin, Weihong Han |
Comput. Networks | 2 |
| 2026 | RSAFL: Guide protocol fuzzing by runtime state data
Shuyuan Jin, Guangyang Li, Weiquan Sang |
Comput. Secur. | 3 |
| 2026 | InterpLog: Interpretable log-based anomaly detection assisting troubleshooting for system reliability
Ruizhi Xiao, Jiakun Sun, Shuyuan Jin |
J. Syst. Softw. | 5 |
| 2026 | Graph-Based Malicious Domain Name Detection: How to Use the Heuristic RelationsabstractDomain Name System is widely abused by various types of malicious campaigns. Recently, many graph learning models have been proposed to detect malicious domains based on the domain name resolution process and related data. These models focus on associations among domain names, which are defined as heuristic relations in this paper, and typically report an F1-score exceeding 0.95, indicating high detection accuracy achieved in real-world DNS applications. In order to explore how far we are from excellent graph-based malicious domain name detection methods, this paper conducts an in-depth analysis of six representative graph-based models on three experimental datasets and one real-world dataset. Our experiments focus on several aspects of model evaluation, including heuristic relation distributions, heuristic relation selection, feature extraction, graph reduction operation, and imbalance distribution of malicious domain names in the real world. The experimental results demonstrate that all these aspects have a significant impact on the detection performance, existing models are still relatively shallow in utilizing heuristic relations, and that all the studied models do not always work well as claimed. We further propose several possible future works that may contribute to achieving excellent performance in malicious domain name detection. Ruizhi Xiao, Jiakun Sun, Shuyuan Jin |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Cache Periscope: Gain insights into the global epidemic of malicious domains through DNS Cache
Jiakun Sun, Ruizhi Xiao, Shuyuan Jin |
Comput. Networks | 5 |
| 2025 | PathFuzzer: Sensitive Information Flow Path-Guided Fuzzing for Intent Vulnerabilities in Android ApplicationsabstractIntent vulnerabilities pose a significant threat as they allow attackers to exploit unverified intent messages, leading to sensitive data leaks, privilege escalations, or unauthorized actions that compromise user privacy and system security. Fuzzing methods, as traditional Intent vulnerability detection methods, are guided by the edge coverage of the program‐directed graph and do not focus on sensitive information, resulting in a lack of ability to discover vulnerabilities related to sensitive information, especially long‐path vulnerabilities. This article proposes PathFuzzer, which is an intent‐sensitive information flow path‐guided fuzzing method designed to efficiently detect intent vulnerabilities in Android applications. It leverages intent‐sensitive information flow paths to guide fuzzing by sending test cases along these paths and mutating test cases based on the parameter within the paths. Additionally, PathFuzzer utilizes unique long path encoding and key node identification technology to enable test cases to efficiently test along sensitive information flow paths, while monitoring the test status to form a feedback mechanism for long paths. The evaluation results show that PathFuzzer successfully detected 131 intent vulnerabilities across 500 popular applications from Google Play. Compared to traditional methods, PathFuzzer achieved a 92% average path coverage rate on sensitive paths while improving detection efficiency by an average of up to 64%. In summary, PathFuzzer provides an efficient, accurate, and comprehensive method for detecting Intent vulnerabilities. Zhanhui Yuan, Shuyuan Jin, Jinglei Tan |
IET Inf. Secur. | 3 |
| 2025 | SHIFT: Selective Hardware Information Flow Tracking Driven by Deterministic ConstraintsabstractInformation flow tracking technology is commonly used in the security analysis of hardware design. This technology protects the confidentiality and integrity of essential assets by instrumenting trace logic on each operation unit to detect whether critical information has been leaked or tampered with. However, as hardware design becomes increasingly large-scale and complex, the significant performance overhead introduced by instrumentation has become a major challenge. This article proposes Selective Hardware Information Flow Tracking (SHIFT), a constraint-driven optimization technique. The core idea of SHIFT includes selective monitoring of operations and selective optimization of propagation logic. In the intermediate representation of the hardware design, SHIFT scans taint sources in the code statically using a conservative analysis algorithm to determine whether logic structures require monitoring and assigns optimization tags based on known conditions. During the synthesis process, these optimization tags are passed to the netlist, thereby enabling selective instrumentation of the trace logic on the cell. In the Trust-Hub AES test bench, SHIFT reduces the deployment time of the tracking model by 12.1%, decreases the number of cells by 19.9%, and reduces the synthesized area by 35.7%, Additionally, the security verification time of the flow model was reduced by 10.5%. In general, SHIFT reduces the overhead of deploying trace logic without introducing false positives. Shuyuan Jin |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2024 | CoMDet: A Contrastive Multimodal Pre-Training Approach to Encrypted Malicious Traffic DetectionabstractEncrypted malicious traffic detection aims at iden-tifying malicious activities without decrypting network traffic, which is essential for cybersecurity. Existing methods have shown effective performance in encrypted malicious traffic detection, but their heavy reliance on labeled datasets presents a chal-lenge. This paper presents CoMDet, a contrastive multimodal pre-training approach, to detect encrypted malicious traffic. CoMDet leverages three independent Transformer encoders to learn multimodal feature representations from encrypted traffic based on unlabeled data in the pre-training phase. Meanwhile, we introduce a novel inter-modal contrastive learning method to enhance feature representation by maximizing the mutual information among the modalities. Subsequently, we fine-tune the pre-trained model using limited labeled data. Experimental results demonstrate that CoMDet outperforms the existing semi- supervised learning methods and achieves comparable performance with existing supervised learning methods. It obtains an average ACC of 92% and an average macro-Fl of 86% with only 80 labeled samples in each malicious category. We conduct an investigation on the fine-tuning dataset size and discover that as the dataset size increases, the performance of CoMDet is increasingly comparable to existing supervised learning methods. Jiakun Sun, Shuyuan Jin |
COMPSAC | 4 |
| 2024 | RCFG2Vec: Considering Long-Distance Dependency for Binary Code Similarity DetectionabstractBinary code similarity detection(BCSD), as a fundamental technique in software security, has various applications, including malware family detection, known vulnerability detection and code plagiarism detection. Recent deep learning-based BCSD approaches have demonstrated promising performance. However, they face two significant challenges that limit detection performance. First, most approaches that use sequence networks (like RNN and Transformer) utilize coarse-grained tokenization methods, which results in large vocabulary size and severe out-of-vocabulary (OOV) problem. Second, CFG-based methods typically use variants of graph convolutional networks, which only consider local structural information and discard long-distance dependencies between basic blocks. Jintian Lu, Ruizhi Xiao, Shuyuan Jin |
ASE | 5 |
| 2024 | MC-Det: Multi-channel representation fusion for malicious domain name detection
Ruizhi Xiao, Jiakun Sun, Shuyuan Jin |
Comput. Networks | 4 |
| 2024 | ContexLog: Non-Parsing Log Anomaly Detection With All Information Preservation and Enhanced Contextual RepresentationabstractLogs are widely used in software to trace the runtime states and critical events. Log-based anomaly detection is crucial for software maintenance and reliability assurance. Existing log-based anomaly detection methods are suffering from imperfections of log parsing, the neglect of the log individual context, and the discarding of non-character tokens. In this paper, we propose ContexLog, a non-parsing log-based anomaly detection method with all information preservation and enhanced log contextual representation, to detect diverse anomalies effectively. Log messages are first grouped as sequences with different windowing techniques. To capture all log features, ContexLog tokenizes each log sequence and preserves all information, including character and non-character tokens. It then represents the log sequential context and individual context simultaneously to construct input for a Transformer encoder-based classification model. Experimental evaluations on real-world datasets and synthetic datasets demonstrate ContexLog outperforms existing methods in achieving accurate anomaly detection results, handling unseen logs to avoid log parsing imperfections, and utilizing non-character tokens to detect diverse anomalies. Ruizhi Xiao, Jintian Lu, Shuyuan Jin |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | FastDet: Detecting Encrypted Malicious Traffic Faster via Early Exit
Jiakun Sun, Jintian Lu, Shuyuan Jin |
ICA3PP (1) | 4 |
| 2023 | Investigating Pose Representations and Motion Contexts Modeling for 3D Motion PredictionabstractPredicting human motion from historical pose sequence is crucial for a machine to succeed in intelligent interactions with humans. One aspect that has been obviated so far, is the fact that how we represent the skeletal pose has a critical impact on the prediction results. Yet there is no effort that investigates across different pose representation schemes. We conduct an indepth study on various pose representations with a focus on their effects on the motion prediction task. Moreover, recent approaches build upon off-the-shelf RNN units for motion prediction. These approaches process input pose sequence sequentially and inherently have difficulties in capturing long-term dependencies. In this paper, we propose a novel RNN architecture termed AHMR (Attentive Hierarchical Motion Recurrent network) for motion prediction which simultaneously models local motion contexts and a global context. We further explore a geodesic loss and a forward kinematics loss for the motion prediction task, which have more geometric significance than the widely employed L2 loss. Interestingly, we applied our method to a range of articulate objects including human, fish, and mouse. Empirical results show that our approach outperforms the state-of-the-art methods in short-term prediction and achieves much enhanced long-term prediction proficiency, such as retaining natural human-like motions over 50 seconds predictions. Our codes are released. Zhenguang Liu, Shuang Wu 0002, Shuyuan Jin, Shouling Ji, Qi Liu 0049, Shijian Lu, Li Cheng 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2023 | AllInfoLog: Robust Diverse Anomalies Detection Based on All Log FeaturesabstractLarge-scale services are generating massive logs, which trace the runtime states and critical events. Anomaly detection via logs is critical for service maintenance and reliability assurance. Existing log-based anomaly detection methods make use of the limited information in log data, resulting in their incapability of detecting diverse anomalies related to unused log features. In this paper, we propose AllInfoLog, a robust log-based anomaly detection method taking advantage of all log information, to detect diverse types of anomalies. To capture all log features, AllInfoLog utilizes four encoders to extract semantic, parameter, time, and other feature embeddings, respectively. The embeddings of all log features are then combined to train an attention-based Bi-LSTM model to detect diverse anomalies. The experimental evaluations on real-world log datasets, synthetic datasets, and unstable log datasets demonstrate AllInfoLog outperforms the state-of-the-art log-based anomaly detection methods from aspects of performance and robustness, and has effectiveness to detect diverse types of anomalies. Ruizhi Xiao, Hao Chen 0133, Jintian Lu, Shuyuan Jin |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2022 | MEMTD: Encrypted Malware Traffic Detection Using Multimodal Deep Learning
Jintian Lu, Jiakun Sun, Ruizhi Xiao, Shuyuan Jin |
ICWE | 5 |
| 2022 | FSAFlow: Lightweight and Fast Dynamic Path Tracking and Control for Privacy Protection on Android Using Hybrid Analysis with State-Reduction StrategyabstractDespite the demonstrated effectiveness of dynamic taint analysis (DTA) in a variety of security applications, the poor performance achieved by available DTA prototypes prevents their widespread adoption in production systems, especially the Android system with limited computation and storage resources. To overcome DTA’s overhead bottlenecks, recent research efforts aim to decouple taint tracking logic from program execution. Continuing this line of research, this work proposes FSAFlow, a novel hybrid taint tracking and control system, to reduce DTA overhead significantly while ensuring sound Android privacy protection. FSAFlow further separates the path tracking logic from the corresponding taint tracking logic and the control of the information flow path is optimized. Specifically, a classic static analysis algorithm is first modified to search target paths and their key branch information. Then, the potential paths that violate the user’s predefined privacy protection policy are chosen and encoded with a Finite State Automaton (FSA). A small amount of FSA-based state management code is inserted into the corresponding position in the program. Finally, it monitors the program’s state of path execution and prevents information leakage during runtime. The efficiency and correctness of FSAFlow are proved by theoretical analysis. The experimental results show that FSAFlow incurs lower overhead than several representative DTA optimization approaches, 2.06% for popular applications, and 5.41% on CaffeineMark 3.0. FSAFlow has fewer false negatives in implicit flow tracking than the Android DTA platform, TaintDroid, and achieves higher precision than the static analysis tool, FlowDroid, by verifying the paths that never occur and tracking in the complete execution stage of the loop body at runtime. Zhanhui Yuan, Shuyuan Jin, Wenfa Li |
SP | 3 |
| 2022 | DIFCS: A Secure Cloud Data Sharing Approach Based on Decentralized Information Flow Control
Jintian Lu, Jiakun Sun, Ruizhi Xiao, Shuyuan Jin |
Comput. Secur. | 4 |
| 2021 | A Dynamic Access Control Model Based on Game Theory for the CloudabstractThe user's access history can be used as an important reference factor in determining whether to allow the current access request or not. And it is often ignored by the existing access control models. To make up for this defect, a Dynamic Trust - game theoretic Access Control model is proposed based on the previous work. This paper proposes a method to quantify the user's trust in the cloud environment, which uses identity trust, behavior trust, and reputation trust as metrics. By modeling the access process as a game and introducing the user's trust value into the pay-off matrix, the mixed strategy Nash equilibrium of cloud user and service provider is calculated respectively. Further, a calculation method for the threshold predefined by the service provider is proposed. Authorization of the access request depends on the comparison of the calculated probability of the user's adopting a malicious access policy with the threshold. Finally, we summarize this paper and make a prospect for future work. Shuyuan Jin |
GLOBECOM | 2 |
| 2021 | Unsupervised Anomaly Detection Based on System LogsabstractThe anomaly detection based on rich and descriptive system logs is critical to securing information systems.Existing techniques rarely consider semantic information of logs in the detection, resulting in their incapability to handle unseen log events, neither further improve their detection rates.This paper proposes a CNN and LSTM based anomaly detection approach.It utilizes the meaning of log entries -the semantic information of logs in the detection, where the relations among short sequences are automatically learned.The results of comparative experiments demonstrate the effectiveness of the proposed approach on both stable(fixed format) and unstable(unseen, unfixed format) logs. Ruizhi Xiao, Shuyuan Jin |
SEKE | 3 |
| 2021 | Hacks Hit the Phish: Phish Attack Detection Based on Hacks Search
Shuyuan Jin |
WASA (3) | 2 |
| 2020 | Web Attack Detection Based on User Behaviour Semantics
Jintian Lu, Shuyuan Jin |
ICA3PP (3) | 3 |
| 2020 | Privacy-aware OrLa Based Access Control Model in the Cloud
Shuyuan Jin |
SEKE | 2 |
| 2019 | Towards Natural and Accurate Future Motion Prediction of Humans and AnimalsabstractAnticipating the future motions of 3D articulate objects is challenging due to its non-linear and highly stochastic nature. Current approaches typically represent the skeleton of an articulate object as a set of 3D joints, which unfortunately ignores the relationship between joints, and fails to encode fine-grained anatomical constraints. Moreover, conventional recurrent neural networks, such as LSTM and GRU, are employed to model motion contexts, which inherently have difficulties in capturing long-term dependencies. To address these problems, we propose to explicitly encode anatomical constraints by modeling their skeletons with a Lie algebra representation. Importantly, a hierarchical recurrent network structure is developed to simultaneously encodes local contexts of individual frames and global contexts of the sequence. We proceed to explore the applications of our approach to several distinct quantities including human, fish, and mouse. Extensive experiments show that our approach achieves more natural and accurate predictions over state-of-the-art methods. Zhenguang Liu, Shuang Wu 0002, Shuyuan Jin, Qi Liu 0049, Shijian Lu, Roger Zimmermann, Li Cheng 0001 |
CVPR | 3 |
| 2015 | Botnet spoofing: fighting botnet with itselfabstractAs the arms race between botmasters and defenders becomes increasingly common, the emerging advanced botnets have evolved to be more resilient to traditional mitigation strategies. For security-conscious Internet users, the host-based security software i.e., antivirus and firewall could provide effective protection against the botnet attacks; however, the remaining security-unconscious users will suffer from the botnet attacks and will be compromised easily. Consequently, how to protect both security-conscious and security-unconscious users against advanced botnets without any command and control vulnerability has posed a great challenge to this day. In this paper, we propose the idea of botnet spoofing that aims at addressing the aforementioned challenge to some degree. Botnet spoofing exploits the essential property of a persistent bot that it MUST obtain its file path before subsequent autostart registration or self-propagation to spoof a specific bot and trick the specific bot to propagate BotSpoofer instead of propagating itself, consequently making the victim not only avoid an originally successful attack but also achieve extra protection provided by BotSpoofer. Thus, botnet spoofing is independent of the vulnerability, protocol, and structure of botnet command and control. To prove the feasibility of botnet spoofing, we create a prototype named ConSpoofer-targeting Conficker. The results show that ConSpoofer could be passively delivered to other victims, which are located by Conficker, through Conficker's three propagation methods in an automatic, simple, accurate, and scalable manner. The goal of our work is to provide a new mitigation strategy that will promote the development of more efficient countermeasures against advanced botnets. Copyright © 2013 John Wiley & Sons, Ltd. Xiang Cui, Lihua Yin, Shuyuan Jin, Zhiyu Hao |
Secur. Commun. Networks | 3 |
| 2015 | Privacy theft malware multi-process collaboration analysisabstractPrivacy theft malware has become a serious and challenging problem to cyber security. Previous methods are of different categories: one focuses on the outbound network traffic and the other one dives into the inside information flow of the program. We incorporate dynamic behavior analysis with network traffic analysis and present an abstract model called Privacy Petri Net PPN, which is more applicable to various kinds of malware and more understandable to users. In consideration of the multi-process technique adopted by new malware, we also model the collaborative behaviors between different malicious functionality modules with PPN. We apply our approach to real-world malware, and the experiment result shows that our approach can effectively find categories, content, source, and destination of the privacy theft behavior of the malware sample. Copyright © 2013 John Wiley & Sons, Ltd. Lejun Fan, Yuanzhuo Wang, Xueqi Cheng 0001, Shuyuan Jin |
Secur. Commun. Networks | 5 |
| 2014 | A uniform framework for community detection via influence maximization in social networksabstractCommunity structure as a significant feature helps us understand networks in a mesoscopic view. Existing approaches for community detection haven't considered about the formation of communities, whereas community in real social networks is usually established around influential nodes. In this paper, we present an efficient and effective framework based on local influence to detect both overlapping and hierarchical communities. We try to illuminate two fundamental questions: 1)Whether local influence regarded as a new property can affect the formation of communities; 2)How to quantify node's local influence and utilize it to detect communities. To demonstrate the effectiveness of local influence in terms of evaluating node importance, nodes with high local influence are selected to perform the influence maximization experiments on real social networks. Experimental results show that our framework is effective and efficient for both community detection and influence maximization. Shuyuan Jin, Yanlei Wu, Jin Xu 0002 |
ASONAM | 2 |
| 2012 | Privacy Theft Malware Detection with Privacy Petri NetabstractPrivacy theft malware has become serious and challenging problem to cyber security. Previous works are based on two categories of road map, the one focuses on the outbound network traffic, the other one dives into the inside information flow. We incorporate dynamic behavior analysis with network traffic analysis and present abstract model called Privacy Petri Net (PPN) which is more applicable to various kinds of malware and more meaningful to users. We apply our approach on real world malware and the experiment result shows that our approach can effectively find categories, content, source and destination of the privacy theft behavior of the malware sample. Lejun Fan, Yuanzhuo Wang, Xueqi Cheng 0001, Shuyuan Jin |
PDCAT | 4 |
| 2012 | Online Traffic Classification Based on Co-training MethodabstractOnline traffic classification has been widely used in quality of service measurements, network management and security monitoring. Currently, more and more research works tend to apply machine learning techniques to online traffic classification, and most of them are based on supervised learning and unsupervised learning techniques. Although supervised learning method has exhibited good classification performance, it needs lots of labeled training samples which are difficult to collect. The co-training method is a semi-supervised learning method, which can use little labeled samples and plenty of unlabeled samples to enhance the performance of supervised learning method. In this paper, we investigate the co-training algorithm for online traffic classification. The co-training algorithm needs two separate features which are sufficient to train a good classifier. We choose packet size and inter-packet time of the first packets of a traffic flow as two features. However, the inter-packet time is dependent to network conditions and will be impacted by network jitter. This paper constructs a robust inter-packet time feature named "Netipt" which is resilient to network jitter, and we integrate Netipt feature to co-training algorithm. We test our co-training algorithm based on two real-world traffic datasets. The results show that the co-training algorithm can enhance the accuracy of traffic classification drastically even when there are very few training samples. Jinghua Yan, Xiao-chun Yun, Zhi-Gang Wu, Hao Luo 0010, Shuzhuang Zhang, Shuyuan Jin |
PDCAT | 6 |
| 2012 | Automatic Covert Channel Detection in Asbestos System (Poster Abstract)
Shuyuan Jin, Xiang Cui |
RAID | 1 |
| 2012 | Optimal mining on security labels for decentralized information flow control
Lihua Yin, Shuyuan Jin |
Comput. Secur. | 3 |
| 2012 | Matching sequences of salient contour points characterized by Voronoi region features
Yuqing Song 0002, Shuyuan Jin |
Vis. Comput. | 2 |
| 2011 | Poster: towards formal verification of DIFC policies
Lihua Yin, Miyi Duan, Shuyuan Jin |
CCS | 4 |
| 2011 | Network Threat Assessment Based on Alert VerificationabstractIn face of overwhelming alerts produced by firewalls or intrusion detection devices, it is difficult to assess network threats that we face. In this paper, we propose a threat assessment approach to estimate the impact of attacks on network. The approach employs the Common Vulnerability Scoring System to quantitatively assess network threats and further correlates alerts with contextual information to improve the accuracy of assessment. In the case studies, we demonstrate how the approach is applied in real networks. The experimental results show that the approach can make an accurate assessment of network threats. Rongrong Xi, Xiao-chun Yun, Shuyuan Jin, Yongzheng Zhang 0002 |
PDCAT | 3 |
| 2011 | CNSSA: A Comprehensive Network Security Situation Awareness SystemabstractWith tremendous attacks in the Internet, there is a high demand for network analysts to know about the situations of network security effectively. Traditional network security tools lack the capability of analyzing and assessing network security situations comprehensively. In this paper, we introduce a novel network situation awareness tool CNSSA (Comprehensive Network Security Situation Awareness) to perceive network security situations comprehensively. Based on the fusion of network information, CNSSA makes a quantitative assessment on the situations of network security. It visualizes the situations of network security in its multiple and various views, so that network analysts can know about the situations of network security easily and comprehensively. The case studies demonstrate how CNSSA can be deployed into a real network and how CNSSA can effectively comprehend the situation changes of network security in real time. Rongrong Xi, Shuyuan Jin, Xiao-chun Yun, Yongzheng Zhang 0002 |
TrustCom | 2 |
| 2011 | A unique property of single-link distance and its application in data clustering
Yuqing Song 0002, Shuyuan Jin, Jie Shen 0009 |
Data Knowl. Eng. | 2 |
| 2009 | A review of classification methods for network vulnerabilityabstractClassification of network vulnerability is critical to detection and risk analysis of network vulnerability. A broad range of classification methods have been proposed in literature. This paper reviews a total of 25 selected approaches and identifies the differences and relations among them. It also points out some open issues for research in this field. Shuyuan Jin, Yong Wang 0032, Xiang Cui, Xiao-chun Yun |
SMC | 1 |
| 2007 | Internet Anomaly Detection Based on Statistical Covariance MatrixabstractIntrusion detection is an important part of assuring the reliability of computer systems. Different intrusion detection approaches vary with different patterns used and different intrusions addressed. However, what patterns are effective in constructing a detection system is still a challenge. This paper attempts to apply the traditional covariance matrix concept to the detection of multiple known and unknown network anomalies. With respect to the initiation of typical flood-based network intrusions, the proposed approach takes the measure of covariance matrix to reflect the changes of sequential correlativity of the network traffic when flood-based attacks happen. The differences among covariance matrices of network samples collected in temporal sequences of fixed and equal length are directly evaluated to detect multiple network anomalies. Extensive experiments on the subset of KDDCUP 1999 dataset show that the covariance matrix, as a new pattern, can be directly utilized to construct an effective detection system for flood-based attacks. It also points out that utilizing the covariance matrix in the detection of flood-based attacks can achieve higher performance over traditional approaches. Shuyuan Jin, Daniel S. Yeung, Xizhao Wang |
Int. J. Pattern Recognit. Artif. Intell. | 1 |
| 2007 | Network intrusion detection in covariance feature space
Shuyuan Jin, Daniel S. Yeung, Xizhao Wang |
Pattern Recognit. | 1 |
| 2007 | Covariance-Matrix Modeling and Detecting Various Flooding AttacksabstractThis paper presents a covariance-matrix modeling and detection approach to detecting various flooding attacks. Based on the investigation of correlativity changes of monitored network features during flooding attacks, this paper employs statistical covariance matrices to build a norm profile of normal activities in information systems and directly utilizes the changes of covariance matrices to detect various flooding attacks. The classification boundary is constrained by a threshold matrix, where each element evaluates the degree to which an observed covariance matrix is different from the norm profile in terms of the changes of correlation between the monitored network features represented by this element. Based on Chebyshev inequality theory, we give a practical (heuristic) approach to determining the threshold matrix. Furthermore, the result matrix obtained in the detection serves as the second-order features to characterize the detected flooding attack. The performance of the approach is examined by detecting Neptune and Smurf attacks-two common distributed Denial-of-Service flooding attacks. The evaluation results show that the detection approach can accurately differentiate the flooding attacks from the normal traffic. Moreover, we demonstrate that the system extracts a stable set of the second-order features for these two flooding attacks Daniel S. Yeung, Shuyuan Jin, Xizhao Wang |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2005 | A feature space analysis for anomaly detectionabstractIntrusion detection is an important part of assuring the reliability of computer systems. From the viewpoint of feature space partition of detectors, this paper investigates one of the limitations of two traditional anomaly detection technologies - NN-based anomaly detection and statistical detection approaches in detecting novel attacks. A high dimensional covariance matrix feature space and an on-line detection algorithm are proposed to detect various known and unknown attacks. An illustrative example of detecting various known and unknown probing attacks is provided. Shuyuan Jin, Daniel S. Yeung, Xizhao Wang, Eric C. C. Tsang |
SMC | 1 |
| 2004 | A covariance analysis model for DDoS attack detectionabstractThis paper discusses the effects of multivariate correlation analysis on the DDoS detection and proposes an example, a covariance analysis model for detecting SYN flooding attacks. The simulation results show that this method is highly accurate in detecting malicious network traffic in DDoS attacks of different intensities. This method can effectively differentiate between normal and attack traffic. Indeed, this method can detect even very subtle attacks only slightly different from the normal behaviors. The linear complexity of the method makes its real time detection practical. The covariance model in this paper to some extent verifies the effectiveness of multivariate correlation analysis for DDoS detection. Some open issues still exist in this model for further research. Shuyuan Jin, Daniel S. Yeung |
ICC | 1 |