VLDB 2026 Research / reviewers in the wild / expert
Futai Zou
dblp:09/5645
· DBLP profile ↗
45ranked-venue papers
7as first author
27since 2021 · last 2026
0000-0002-5898-7317ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 4 first-author · 16 since 2021Computer networks · 11 · 7 since 2021Systems, architecture and hardware · 5 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SnipleyFuzz: Enhancing Black-Box Fuzzing of IoT Devices with Shapley-Based Priority Selection
Futai Zou, Jiaping Gui |
DSN | 2 |
| 2026 | SemanCall: recovery of indirect calls in binaries via semantic graph deep matching
Xiangzhi Wang, Futai Zou, Ken Zhong |
Autom. Softw. Eng. | 2 |
| 2026 | ApexSentinel: Detecting and Explaining Advanced Persistent Threats with Large Language Models
Futai Zou, Canyang Wu, Heming Zhang 0009 |
Comput. Networks | 2 |
| 2026 | SFBD: Backdoor Detection via Sequential Fingerprinting of Neural Networks for Securing the IoT Model Supply Chain
Fan Hong, Futai Zou, Ping Yi, Yue Wu 0010 |
IEEE Internet Things J. | 4 |
| 2025 | SRVul: A High-Quality Self-Restrained Vulnerable Code Dataset for Vulnerability DetectionabstractAutomated software vulnerability detection using learning-based approaches has been a focal point in the field of software engineering. However, the training and benchmarking of software vulnerability detection models are significantly influenced by the quality of the training data. Existing solutions have made limited efforts in addressing data quality issues due to limited and challenging data collection. Publicly available datasets have been found to suffer from data quality problems, hindering effective model training and performance evaluation. Although awareness of the potential negative impact of software vulnerability data quality is increasing, to the best of our knowledge, no systematic solution has been proposed to improve data quality during the automated labeling process. In this paper, we propose a data collection and cleansing framework that first collects the latest vulnerabilities and patches from publicly available vulnerability databases. Then, a rule-based filter is applied to classify function-level vulnerability fixing modifications into three categories: high quality, unknown quality, and low quality. Subsequently, a semantic filter trained on high-quality samples is used to filter samples of unknown quality, resulting in a cleansed version of the raw dataset. This is the first framework that distinguishes the quality of function-level modification samples for software vulnerability fixes and performs data cleansing, without solely relying on traditional heuristic label assignment strategies. In our experiments, we evaluate the properties of SRVul, the effectiveness of the framework, and the feasibility of using it for training vulnerability detection models. SRVul outperforms existing works on multiple metrics, demonstrating the best combination of dataset scale and quality, with a well-designed and effective framework and components. Training the advanced LineVul model with SRVul yields improved performance on benchmark datasets, indicating that SRVul is well-suited for the effective training of vulnerability detection models. Hongjun Huang, Futai Zou, Jiaping Gui, Tianming Zheng, Yue Wu 0010 |
IJCNN | 2 |
| 2025 | A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics
Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan |
INFOCOM | 4 |
| 2025 | DISTR: Detecting multi-stage IoT botnets through contextual traffic and causal analytics
Jiaping Gui, Futai Zou, Yunbo Li, Yue Wu 0010 |
Comput. Secur. | 3 |
| 2025 | OTP-Hunter: An App-Based Fuzzing Framework to Discover One Time Password Vulnerabilities
Futai Zou, Yuzong Hu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Dictionary Learning-Enabled Privacy Preserving Semantic Communication SystemabstractFor deep learning-enabled semantic communication, existing privacy protection methods only take into account the presence of eavesdropper while ignoring malicious receiver aiming to detect confidential information. Only informationtheoretical security can transmitter defend against malicious receiver. However, private information are always entangled with pragmatic information in feature space, which leads global perturbation to degrade communication performance. To handle these difficulties, in this paper a privacy preserving semantic communication system is proposed. Different from traditional paradigm, a novel privacy preserving semantic encoder is designed to realize targeted privacy protection while remaining useful information unaffected. Within proposed privacy preserving semantic encoder, feature decoupling module aims to disentangle semantic information by learning two sets of basis vectors which can express private and pragmatic information of data, respectively. Accordingly differential privacy mechanism is employed to provide information-theoretical security. Experimental results demonstrate that proposed method not only achieves better communication performance in both data recovery and pragmatic task, but also more effectively degrades the accuracy of malicious receiver to infer sensitive information than global perturbation does. Shuo Shao 0001, Futai Zou, Yue Wu 0010 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | A Secure and Private Authentication Based on Radio Frequency FingerprintingabstractThe technology development of wireless communication has brought about the rapid growth of various wireless devices, but also brings in many security threats. This paper focuses on the security and privacy problems in wireless authentication and proposes a novel authentication scheme based on the design of reusable fuzzy extractor (RFE) for device's radio frequency (RF) fingerprinting. Firstly, unlike the traditional authentication protocol, our scheme can accomplish the mutual authentication without the storage of long-term secret key, thus tackles with the key-compromise threats. Furthermore, although the scheme authenticates devices based on their RF fingerprint, it does not store RF fingerprinting information explicitly to safeguard it from eavesdroppers who may use it to impersonate the identity of valid users. Finally, our designed protocol relies on the correspondent peer to measure the fingerprint, rather than the device itself, thus is more secure against various adversaries. The security analysis shows the resiliency against theft of secret keys, wireless channel attacks and privacy disclosure. And the performance evaluation demonstrates that the design of RFE for device's RF fingernrinting is efficient in terms of recognition accuracy. Chengchen Zhu, Kunling Li, Jianan Hong, Cunqing Hua, Futai Zou |
ICC | 5 |
| 2024 | Enhancing Runtime Application Self-Protection with Unsupervised Deep Learning
Bolun Wu, Futai Zou, Mingyi Huang, Jiajia Han |
SecureComm (1) | 2 |
| 2024 | LLM-TIKG: Threat intelligence knowledge graph construction utilizing large language model
Yuelin Hu, Futai Zou, Jiajia Han |
Comput. Secur. | 2 |
| 2024 | Detection and Analysis of Broken Access Control Vulnerabilities in App-Cloud Interaction in IoTabstractAt present, there is less research on the detection of broken access control vulnerabilities in IoT systems, mostly using state machines to analyze abnormal state transitions, and no systematic tools have been developed. The main challenges include the inaccessibility of communication messages, a lack of effective detection for broken access control vulnerabilities, and excessive manual involvement. Moreover, due to the existence of encryption, signatures, and other fields, it is challenging to directly port web-based detection tools to IoT. In response to these challenges, we propose a framework for detecting broken access control vulnerabilities based on the interaction between applications and cloud platforms. The framework employs man-in-the-middle techniques to obtain communication messages between the two entities, enabling fast and effective fuzz testing through keyword extraction, database-guided fuzzing, and response-based detection algorithms. In addition, a combination of dynamic and static reverse analysis techniques are used to overcome anti-tampering measures, such as encryption and signatures. Following the detection framework, we implemented the semi-automated BACDetector system and tested it on six applications from four manufacturers. BACDetector discovered nine broken access control vulnerabilities, including risks of device hijacking and privacy leakage. This validated its effectiveness in detecting vulnerabilities in IoT. Futai Zou, Jianan Hong, Libo Chen 0001, Ping Yi |
IEEE Internet Things J. | 2 |
| 2023 | Link Prediction-Based Multi-Identity Recognition of Darknet Vendors
Futai Zou, Yuelin Hu, Wenliang Xu, Yue Wu 0010 |
ICICS | 1 |
| 2023 | SlicedLocator: Code vulnerability locator based on sliced dependence graph
Bolun Wu, Futai Zou, Ping Yi, Yue Wu 0010 |
Comput. Secur. | 2 |
| 2023 | Multi-field relation mining for malicious HTTP traffic detection based on attention and cross network
Bolun Wu, Futai Zou, Tangda Yu |
J. Inf. Secur. Appl. | 2 |
| 2022 | Tracing Tor Hidden Service Through Protocol CharacteristicsabstractTor is a relay-based communication network that provides users with anonymous access to the Internet. Tor hidden services protect the identities of the content publishers to achieve anonymity and anti-censorship. However, hidden services are abused to conduct illegal activities, including hosting botnets and trading drugs. This paper proposes a tracing approach to locate illegal hidden services based on the Tor protocol characteristics, which allows a Tor client to embed a signal into a Tor circuit connecting with the illegal hidden service. Once the Tor node nearest to the the hidden service detects the signal, the identity of the hidden service can be revealed. Our approach is simple, powerful, and stable compared with previous methods. We implemented the approach and performed experiments over the Tor network, whose results show that our approach is feasible and effective, with 100% accuracy, 99.25% true positive rate, and zero false positive rate. Tianming Zheng, Yue Wu 0010, Futai Zou |
ICCCN | 4 |
| 2022 | Breaking Tor's Anonymity by Modifying Cell's CommandabstractTor is a relay-based communication network that provides users with anonymous access to the Internet. This paper proposes a new attack to associate the anonymous communication relationship between the client and the server in the Tor network, which exploits defects of the Tor protocol, resulting in deanonymizing the Tor network. In this attack, a malicious entry onion router modifies the command field of cell sequences derived from the client to embed a signal sequence. While the exit onion router detects a signal sequence consistent with the embedded signal sequence, the anonymous communication relationships between the client and the server can be confirmed. We have implemented the attack in a private Tor network and our experiments validate its feasibility and effectiveness, with 100% accuracy, 97.5 % true positive rate, and zero false positive rate. Jiahe Wu, Futai Zou, Yue Wu 0010 |
ISCC | 3 |
| 2022 | Towards High Transferability on Neural Network for Black-Box Adversarial Attacks
Haochen Zhai, Futai Zou, Junhua Tang, Yue Wu 0010 |
SecureComm | 2 |
| 2022 | FS-IDS: A framework for intrusion detection based on few-shot learning
Hongwei Li 0011, Shuo Shao 0001, Futai Zou, Yue Wu 0010 |
Comput. Secur. | 4 |
| 2021 | SPIN: Structure-Preserving Inner Offset Network for Scene Text RecognitionabstractArbitrary text appearance poses a great challenge in scene text recognition tasks. Existing works mostly handle with the problem in consideration of the shape distortion, including perspective distortions, line curvature or other style variations. Rectification (i.e., spatial transformers) as the preprocessing stage is one popular approach and extensively studied. However, chromatic difficulties in complex scenes have not been paid much attention on. In this work, we introduce a new learnable geometric-unrelated rectification, Structure-Preserving Inner Offset Network (SPIN), which allows the color manipulation of source data within the network. This differentiable module can be inserted before any recognition architecture to ease the downstream tasks, giving neural networks the ability to actively transform input intensity rather than only the spatial rectification. It can also serve as a complementary module to known spatial transformations and work in both independent and collaborative ways with them. Extensive experiments show the proposed transformation outperforms existing rectification networks and has comparable performance among the state-of-the-arts. Chengwei Zhang 0003, Yunlu Xu, Zhanzhan Cheng, Shiliang Pu, Fei Wu 0001, Futai Zou |
AAAI | 7 |
| 2021 | DeepMark: Embedding Watermarks into Deep Neural Network Using PruningabstractWith the rapid development of artificial intelligence in recent years, the deep neural network model has been used in many fields such as speech and images due to its excellent performance, and has achieved remarkable results. As we all know, training a deep model requires a lot of time and resources. But these trained deep learning models are very easy to be copied and diffused. Therefore, the protection of intellectual property rights of the model has gradually attracted people’s attention. A series of algorithms or technologies came into being, and one of them is model watermarking technology. Model watermarks can function like digital watermarks. Once the model is stolen, watermarks can prove the copyright of model by verifying the watermarks, maintain its intellectual property rights, and protect the model. This paper proposes a model watermark generation method based on pruning. Where to prune is selected by the calculation result of connection sensitivity, and then the information is embedded by pruning. Compared with the four proposed model watermarking methods, our method has higher fidelity and reliability. Experiments show that our watermarking method is robust against fine-tuning and weight pruning. Chenqi Xie, Ping Yi, Baowen Zhang, Futai Zou |
ICTAI | 4 |
| 2021 | Word-Map: Using Community Detection Algorithm to Detect AGDs
Futai Zou, Qianying Shen, Yuzong Hu |
ISC | 1 |
| 2021 | Automatic Generation of Malware Threat Intelligence from Unstructured Malware Traces
Yuheng Wei, Futai Zou |
SecureComm (1) | 2 |
| 2021 | Malware Classification by Learning Semantic and Structural Features of Control Flow GraphsabstractMalware has become one of the biggest threats in the cyber world due to its ever-evolving nature. Machine learning-based methods rely on expertise in selecting handcrafted features which is time-consuming. Recent control flow graphs (CFGs) based method makes the best of graph neural network (GNN) on malware classification. But it ignores the semantic information inside CFGs and also relies on manually-designed features. To overcome these drawbacks, in this work, we introduce a malware classification model called MCBG that applies BERT and Graph Isomorphism Network with JumpingKnowledge (GIN-JK) to capture both semantic and structural features of CFGs. We conduct 5-fold cross-validation on Microsoft Malware Classification Challenge dataset to evaluate our model and it achieves an accuracy of 99.53%. The experimental results demonstrate that building semantic models on basic blocks is essential. Besides, MCBG outperforms the model which only considers CFG's structural information. Also, without using any manually-selected feature, it outperforms those of the state-of-the-art methods based on handcrafted malware features. Bolun Wu, Yuanhang Xu, Futai Zou |
TrustCom | 3 |
| 2021 | DePL: Detecting Privacy Leakage in DNS-over-HTTPS TrafficabstractDNS attack is one of the main threats to the Internet. Aiming at detecting the privacy leakage of DoH (DNS-over-HTTPS), in this paper, we proposed a model called DePL based on n-shot learning. This model can analyze which websites the user visits by classifying DoH traffic, and then we evaluate the impact of DoH protocol on user privacy leakage risk. In our experiments, we only used 15 training samples to obtain an accuracy of 86.54% in a closed environment. In an open environment, when the threshold is set to 0.7, the model still has an accuracy of 78.86%. Compared with the existing algorithms, DePL solves the problem of insufficient samples in real applications. A small number of training samples can obtain high-accuracy recognition, which proves the possibility of the detection of privacy leakage in DoH traffic. Futai Zou, Dechao Meng |
TrustCom | 1 |
| 2021 | Obfuscated Tor Traffic Identification Based on Sliding WindowabstractTor is an anonymous communication network used to hide the identities of both parties in communication. Apart from those who want to browse the web anonymously using Tor for a benign purpose, criminals can use Tor for criminal activities. It is recognized that Tor is easily intercepted by the censorship mechanism, so it uses a series of obfuscation mechanisms to avoid censorship, such as Meek, Format-Transforming Encryption (FTE), and Obfs4. In order to detect Tor traffic, we collect three kinds of obfuscated Tor traffic and then use a sliding window to extract 12 features from the stream according to the five-tuple, including the packet length, packet arrival time interval, and the proportion of the number of bytes sent and received. And finally, we use XGBoost, Random Forest, and other machine learning algorithms to identify obfuscated Tor traffic and its types. Our work provides a feasible method for countering obfuscated Tor network, which can identify the three kinds of obfuscated Tor traffic and achieve about 99% precision rate and recall rate. Wenliang Xu, Futai Zou |
Secur. Commun. Networks | 2 |
| 2020 | Quantitatively Assessing the Cyber-to-Physical Risk of Industrial Cyber-Physical SystemsabstractIndustrial cyber-physical systems (ICPSs) are widely used in critical infrastructures. However, they threaten by various cyberattacks which can directly damage the physical processes of ICPSs. Therefore, we proposed a method to quantitatively assess the risk of cyberattacks on the physical systems of ICPSs. This method conduces implement-appropriate security strategies to protect the security of ICPSs. We use an extended Bayesian attack graph to quantify the probabilities of cyberattacks. In addition, we model the cyberattacks as the illegal control signals injected into the physical system and the illegal actions that change the structure of the physical system. With the established model, we compute a new metric: Physical-System-Deviation-Risk (PSDR), which is used to assess the impact of cyberattacks on the physical system. The risk of the physical systems caused by cyberattacks can be quantified by the PSDR and the probabilities of cyberattacks. Moreover, we use a specific case to demonstrate the effectiveness of this assessment method. Lingxuan Zhang, Futai Zou, Jiachao Niu |
ACM Great Lakes Symposium on VLSI | 3 |
| 2020 | Detecting Dictionary Based AGDs Based on Community Detection
Qianying Shen, Futai Zou |
SecureComm (1) | 2 |
| 2020 | pyDNetTopic: A Framework for Uncovering What Darknet Market Users Talking About
Haowei Ye, Futai Zou |
SecureComm (1) | 3 |
| 2020 | Traffic Classification of User Behaviors in Tor, I2P, ZeroNet, FreenetabstractIn recent years, more and more anonymous network have been developed. Since user's identity is difficult to trace in anonymous networks, many illegal activities are carried out in darknet. In this paper, we propose a hierarchical classifier of darknet traffic which can distinguish four types of darknet(Tor, I2P, ZeroNet, Freenet) and 25 darknet users' behavior. Due to the lack of public datasets, we deployed a darknet data probe that can capture real darknet traffic in Tor, I2P, ZeroNet, Freenet. After collecting and labeling darknet traffic, we extract 26 time-based flow features that can represent the characteristics of darknet traffic and train a hierarchical classifier constructed by 6 local classifiers. Results show that the classifier can easily distinguish Tor, I2P, ZeroNet, Freenet four kinds of darknet clients with an accuracy of 96.9% and identify 8 kinds of user behaviors for each type of darknet with an accuracy of 91.6% on average. With the help of this hierarchical classification method, darknet user behaviors can be accurately distinguished at the traffic exit. Yuzong Hu, Futai Zou, Ping Yi |
TrustCom | 2 |
| 2019 | Evolutionary Anti-Jamming Game in Non-Orthogonal Multiple Access SystemabstractAs a candidate radio access technique for 5G, Non- Orthogonal Multiple Access (NOMA) has become an important research topic. Radio Frequency (RF) jamming attack can reduce the communication efficiency in NOMA system. Moreover, the jammer equipped Reinforcement Learning (RL) algorithm will be more destructive. On the other hand, the base station (BS) can implement RL to counter the jamming attack. Thus, the whole system evolves to a multi-agent RL system. The interaction between agents results in a highly dynamic environment and the equilibrium state of the system cannot be intuitively predicted. In the past few years, based on Evolutionary Game Theory (EGT), numbers of researchers have developed useful tools to study the multi-agent RL system in detail. The EGT tools give us insight into the equilibrium of the system and make it possible to compare the performance of different RL algorithms. In this paper, we investigate the anti-jamming problem in the NOMA system where both the base station and the jammer equip RL algorithm. We establish the two-player game and demonstrate the existence and uniqueness of equilibrium. Three RL algorithms and their learning dynamics are introduced, which are Q-learning, Lenient Frequency adjusted Q-learning and Regret Minimization. In experiments, the simulation result shows consistency to the theoretical result given by EGT. Regret Minimization outperforms the other two algorithms in term of average reward and converging rate. Yue Bi, Yue Wu 0010, Cunqing Hua, Futai Zou |
GLOBECOM | 4 |
| 2019 | A Novel Image-Based Malware Classification Model Using Deep Learning
Yongkang Jiang, Shenghong Li 0001, Yue Wu 0010, Futai Zou |
ICONIP (2) | 4 |
| 2019 | Adversarial Seeded Sequence Growing for Weakly-Supervised Temporal Action LocalizationabstractTemporal action localization is an important yet challenging research topic due to its various applications. Since the frame-level or segment-level annotations of untrimmed videos require amounts of labor expenditure, studies on the weakly-supervised action detection have been springing up. However, most of existing frameworks rely on Class Activation Sequence (CAS) to localize actions by minimizing the video-level classification loss, which exploits the most discriminative parts of actions but ignores the minor regions. In this paper, we propose a novel weakly-supervised framework by adversarial learning of two modules for eliminating such demerits. Specifically, the first module is designed as a well-designed Seeded Sequence Growing (SSG) Network for progressively extending seed regions (namely the highly reliable regions initialized by a CAS-based framework) to their expected boundaries. The second module is a specific classifier for mining trivial or incomplete action regions, which is trained on the shared features after erasing the seeded regions activated by SSG. In this way, a whole network composed of these two modules can be trained in an adversarial manner. The goal of the adversary is to mine features that are difficult for the action classifier. That is, erasion from SSG will force the classifier to discover minor or even new action regions on the input feature sequence, and the classifier will drive the seeds to grow, alternately. At last, we could obtain the action locations and categories from the well-trained SSG and the classifier. Extensive experiments on two public benchmarks THUMOS'14 and ActivityNet1.3 demonstrate the impressive performance of our proposed method compared with the state-of-the-arts. Chengwei Zhang 0003, Yunlu Xu, Zhanzhan Cheng, Shiliang Pu, Fei Wu 0001, Futai Zou |
ACM Multimedia | 7 |
| 2019 | CCID: Cross-Correlation Identity Distinction Method for Detecting Shrew DDoSabstractThis study presents a new method for detecting Shrew DDoS (Distributed Denial of Service) attacks and analyzes the characteristics of the Shrew DDoS attack. Shrew DDoS is periodic to be suitable for the server’s TCP (Transmission Control Protocol) timer. It has lower maximum to bypass peak detection. This periodicity makes it distinguishable from normal data packets. By proposing the CCID (Cross-Correlation Identity Distinction) method to distinguish the flow properties, it quantifies the difference between a normal flow and an attack flow. Simultaneously, we calculated the cross-correlation between the attack flow and the normal flow in three different situations. The server can use its own TCP flow timer to construct a periodic attack flow. The cross-correlation between Gaussian white noise and simulated attack flow is less than 0.3. The cross-correlation between single-door function and simulated attack flow is 0.28. The cross-correlation between actual attack flow and simulated attack flow is more than 0.8. This shows that we can quantitatively distinguish the attack effects of different signals. By testing 4 million data, we can prove that it has a certain effect in practice. Ping Yi, Futai Zou, Yao Yao 0009, Wei Wang 0190, Ting Zhu 0001 |
Wirel. Commun. Mob. Comput. | 3 |
| 2018 | Intelligent Large-Scale AP Control with Remarkable Energy Saving in Campus WiFi SystemabstractFull WiFi coverage is more and more prevalent in many places such as university, enterprise, big mall, etc. To achieve full WiFi coverage in a wide area is very costly. Not only extensive AP deployments are expensive, to operate and maintain such large-scale APs every day can also cost much, e.g., the huge power consumption. In this paper, we collect large-scale AP status data in our campus WiFi system, which contains over 8,000 APs and serves about 40,000 active end-users in the area of 3.0925 km2. After conducting empirical studies on AP loads, we find Idle Phenomenon prevails throughout the trace. A large portion of APs are running without any user association, which will inevitably lead to unnecessary energy consumption. Inspired by this, we propose an intelligent large-scale AP control scheme, named as ACE (i.e., AP Control with Energy saving), to dynamically control large-scale APs (On or Off for energy saving meanwhile without loss of WiFi coverage. In ACE, the load of each AP is predicted first by the random forest algorithm, and those APs whose idle durations last for more than the length of the pre-defined sliding window will be turned off. We conduct extensive trace-driven simulations to demonstrate the efficiency of the ACE scheme; specifically, more than 70% of power energy can be saved with over 92 % of user WiFi coverage guaranteed in average. Guangtao Xue, Feng Lyu 0001, Hao Sheng 0001, Futai Zou, Minglu Li 0001 |
ICPADS | 5 |
| 2018 | Detecting Domain-Flux Malware Using DNS Failure TrafficabstractDomain-Flux malware is hard to detect because of the variable C&C (Command and Control) domains which were randomly generated by the technique of domain generation algorithm (DGA). In this paper, we propose a Domain-Flux malware detection approach based on DNS failure traffic. The approach fully leverages the behavior of DNS failure traffic to recognize nine features, and then mines the DGA-generated domains by a clustering algorithm and determinable rules. Theoretical analysis and experimental results verify its efficiency with both test dataset and real-world dataset. On the test dataset, our approach can achieve a true positive rate of 99.82% at false positive rate of 0.39%. On the real-world dataset, the approach can also achieve a relatively high precision of 98.3% and find out 197,026 DGA domains by analyzing DNS traffic in campus network for seven days. We found 1213 hosts of Domain-Flux malware existing on campus network, including the known Conficker, Fosniw and several new Domain-Flux malwares that have never been reported before. We classified 197,026 DGA domains and gave the representative generated patterns for a better understanding of the Domain-Flux mechanism. Futai Zou, Yue Wu 0010, Jianhua Li 0001, Kaida Jiang |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2018 | Web Phishing Detection Using a Deep Learning FrameworkabstractWeb service is one of the key communications software services for the Internet. Web phishing is one of many security threats to web services on the Internet. Web phishing aims to steal private information, such as usernames, passwords, and credit card details, by way of impersonating a legitimate entity. It will lead to information disclosure and property damage. This paper mainly focuses on applying a deep learning framework to detect phishing websites. This paper first designs two types of features for web phishing: original features and interaction features. A detection model based on Deep Belief Networks (DBN) is then presented. The test using real IP flows from ISP (Internet Service Provider) shows that the detecting model based on DBN can achieve an approximately 90% true positive rate and 0.6% false positive rate. Ping Yi, Futai Zou, Yao Yao 0009, Wei Wang 0190, Ting Zhu 0001 |
Wirel. Commun. Mob. Comput. | 3 |
| 2012 | Cost based routing in delay tolerant networksabstractDelay tolerant networks (DTNs) attempt to minimize the possible adverse impacts due to limitations and anomalies in intermittently connected networks. Routing in such sparse and dynamic networks is difficult as the source has little information about the destination, rendering a key challenge to find one simple and effective message delivery mechanism. In this paper, we propose PriCost, a protocol based on the cost for efficient routing of messages, and use the node's past interactions with others to determine the cost of potential routing, in the absence of any other information. Our simulations show that PriCost performs better than MaxProp with reduced complexity. The evaluations also show different cost based metrics hardly affect the performance provided they depend on the same feature extraction algorithm. Jiaping Gui, Yue Wu 0010, Chenji Pan, Futai Zou |
PIMRC | 4 |
| 2009 | On Efficient Content Matching in Distributed Pub/Sub SystemsabstractThe efficiency of matching structures is the key issue for content publish/subscribe systems. In this paper, we propose an efficient matching tree structure, named CobasTree, for a distributed environment. Particularly, we model a predicate in each subscription filter as an interval and published content value as a data point. The CobasTree is designed to index all subscription intervals and a matching algorithm is proposed to match the data points to these indexed intervals. Through a set of techniques including selective multicast by bounding intervals, cost model-based interval division, and CobasTree merging, CobasTree can match the published contents against subscription filters with a high efficiency. We call the whole framework including CobasTree and the associated techniques as COBAS. The performance evaluation in simulation environment and PlanetLab environment shows COBAS significantly outperforms two counterparts with low cost and fast forwarding. Weixiong Rao, Lei Chen 0002, Ada Wai-Chee Fu, Hanhua Chen, Futai Zou |
INFOCOM | 5 |
| 2007 | Targeted Local Immunization in Scale-Free Peer-to-Peer Networks
Xinli Huang, Futai Zou, Fanyuan Ma |
J. Comput. Sci. Technol. | 2 |
| 2004 | PWSD: A Scalable Web Service Discovery Architecture Based on Peer-to-Peer Overlay Network
Yin Li 0005, Futai Zou, Zengde Wu, Fanyuan Ma |
APWeb | 2 |
| 2004 | Using the Linking Model to Understand the Performance of DHT Routing Algorithms
Futai Zou, Shudong Chen, Fanyuan Ma, Junjun Tang |
ISPA | 1 |
| 2004 | Build a Distributed Repository for Web Service Discovery Based on Peer-to-Peer Network
Yin Li 0005, Futai Zou, Fanyuan Ma, Minglu Li 0001 |
NPC | 2 |
| 2004 | CCAN: Cache-Based CAN Using the Small World Model
Futai Zou, Yin Li 0005, Fanyuan Ma |
WAIM | 1 |