Baoxu Liu

dblp:10/8471 · DBLP profile ↗
← Back
45ranked-venue papers
0as first author
38since 2021 · last 2026
0009-0006-9851-5548ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 18 since 2021Computer networks · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Systems, architecture and hardware · 4 · 3 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral Logic
abstract
Advanced Persistent Threats (APTs) are difficult to detect due to their complexity and stealthiness. To mitigate such attacks, many approaches model entities and their relationship using provenance graphs to detect the stealthy and persistent characteristics of APTs. However, existing detection methods suffer from the flaws of missing indirect dependencies, noisy complex scenarios, and missing behavioral logical associations, which make it difficult to detect complex scenarios and effectively identify stealthy threats. In this paper, we propose Sentient, an APT detection method that combines pre-training and intent analysis. It employs a graph transformer to learn structural and semantic information from provenance graphs to avoid missing indirect dependencies. We mitigate scenario noise by combining global and local information. Additionally, we design an Intent Analysis Module (IAM) to associate logical relationships between behaviors. Sentient is trained solely on easily obtainable benign data to detect malicious behaviors that deviate from benign behavioral patterns. We evaluated Sentient on three widely-used datasets covering real-world attacks and simulated attacks. Notably, compared to six state-of-the-art methods, Sentient achieved an average reduction of 44% in false positive rate(FPR) for detection.
Wei Qiao 0005, Weiheng Wu, Zhigang Lu 0002, Bo Jiang 0013, Baoxu Liu
AAAI7
2026 Forge: A Robust Multi-tab Website Fingerprinting Attack via Blind Source Separation
abstract
While Tor's strong anonymity shields users' privacy, it also enables malicious activities, motivating attacks that bypass its protections. Website Fingerprinting (WF) has emerged as a primary threat in this domain. However, existing WF methods struggle with realistic multi-tab browsing scenarios, often relying on prior knowledge of the number of open tabs and lacking robustness against network noise and defenses.
Yitan Huang, Wei Qiao 0005, Meng Shen 0001, Linxu Li, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
WWW10
2026 GranulNet: A unified framework for traffic identification using multi-grained feature fusion
Xueying Han, Yunpeng Li 0006, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
Comput. Networks8
2026 Hiding the trees in the forest: Building network covert channels with hash-based covert carrier filtering
Zexiao Zou, Baoxu Liu
Comput. Secur.3
2026 No train, no pain: a training-free few-shot traffic classifier based on LLMs
abstract
Abstract Encrypted web traffic and evolving Internet technologies pose an increasing challenge to network traffic analysis. However, existing traffic classification methods, though effective, require large labeled datasets and complex training. This makes sustaining them prohibitively expensive and difficult in real-world scenarios. To narrow this gap, we propose a novel training-free few-shot network traffic classification framework based on large language models (LLMs). By integrating meta-learning with LLMs, it reduces reliance on labeled data, eliminates task-specific training, and improves performance. Specifically, we first apply an efficient feature extraction method to extract features from traffic flows. We then design meta-tasks that combine task descriptions with textualized features to produce natural language meta-task formulations. Building on these meta-tasks, the LLM performs reasoning to carry out traffic classification. Finally, to mitigate hallucination in the LLM outputs, we exploit the temporal characteristics of network traffic and aggregate predictions over samples within a defined time window. Extensive experiments on three widely-used encrypted traffic datasets demonstrate that our proposed framework outperforms the state-of-the-art methods, achieving an average absolute improvement in F1 score of 9.75, 9.82, and 12.06 percentage points on the three datasets, respectively.
Xingmao Guan, Xueying Han, Jinlai Huang, Tao Wang 0029, Zelin Cui, Zhigang Lu 0002, Baoxu Liu
Cybersecur.9
2026 A Passive Network Storage Covert Channel for Internet of Things
abstract
Network covert channels in the Internet of Things (IoT) can conceal device communication behaviors, thereby protecting user privacy and ensuring secure transmission of sensitive data. However, existing active covert channels in IoT are constrained by the low computational power and limited storage of IoT terminal devices, making them unsuitable for complex steganographic algorithms. Moreover, the active covert channel is more vulnerable to targeted detection and blocking by traffic analysis. To address these challenges, this study proposes a passive network storage covert channel (PNSCC) that leverages intermediate IoT nodes. We also present solutions for synchronization and reversible data hiding within the PNSCC. A covert channel kernel module was designed and deployed on smart routers running the OpenWrt system, followed by experimental testing. The results indicate that the PNSCC achieves a relatively high capacity, with a covert data transmission rate of approximately 88.97 bps in real-world network environments. Additionally, it has minimal impact on actual network performance and exhibits resilience against traffic analysis.
Zexiao Zou, Zhiqiang Wang 0006, Qianli Huang, Baoxu Liu
IEEE Internet Things J.4
2026 MoPHoney: An adaptive honeyword generation system based on Mixture-of-prompts
Fangming Dong, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
J. Syst. Archit.6
2026 Robust Malicious Network Traffic Detection Framework With Automated Drift Detection, Identification, and Adaptation
abstract
The rise in network attacks has made robust malicious traffic detection crucial. However, the dynamic nature of network traffic causes concept drift, undermining the efficacy of traditional detection methods, which often rely on a static i.i.d data environment and struggle to adapt to new patterns. To overcome these limitations, we propose Argus, a novel framework for malicious traffic detection that operates in a comprehensive, automated, and adaptive manner. Argus tackles three core challenges: accurately classifying known traffic while detecting drift, automatically identifying malicious drifting traffic, and maintaining performance through continuous updates. To address these challenges, Argus integrates a contrastive learningbased module to produce compact representations of traffic and implements a fine-grained drift detection method using category-specific reconstruction loss distributions. For drifting traffic, Argus uses clustering-based automated identification to detect attacks without human intervention. Furthermore, a distance-constrained update mechanism ensures smooth model adaptation, preserving stability and accuracy. Extensive experiments demonstrate that Argus achieves superior performance, with an average F1 score exceeding 95% under various conditions and retaining robust performance even under extreme drift scenarios.
Xueying Han, Changzhi Zhao, Weike Fang, Weihang Wang 0001, Bo Jiang 0013, Susu Cui, Zhigang Lu 0002, Baoxu Liu
IEEE Trans. Inf. Forensics Secur.10
2025 DAB-LLM: Detection of Anomalies in API Call Behavior Based on Large Language Model
abstract
APIs are now central to digital transformation, carrying the core business logic and sensitive data of enterprises. Attackers can gain access to important information systems and sensitive data by attacking APIs, allowing them to steal high-value data. Besides being vulnerable to traditional attacks, APIs also face unique threats tailored to their characteristics, such as attacks targeting API business logic threats. This type of API attacks are complex, and the attack requests are very similar to legitimate traffic, making them difficult to distinguish from benign requests. Therefore, traditional single-request detection methods are ineffective against such complex attacks. By employing intelligent context-aware natural language processing techniques, we can understand API call behavior and establish a baseline of normal API call behavior to identify anomalies. In this paper, we propose DAB-LLM, a model for Detecting Anomalies in API call Behavior based on Large Language Model. Our approach utilizes extraction and representation methods for API call chains and API call graphs, prompt optimization algorithm, and LoRA fine-tuning technique to enable the model to deeply understand of API call behavior and enhance detection capabilities. Experimental results indicate that DAB-LLM excels in detecting attack behaviors and anomalies in API calls, achieving an f1-score of 97.35% along with significant improvements in recall rate, accuracy and precision. The overall performance of the model shows that our proposed model significantly outperforms other models in API call behavior anomaly detection.
Fangjiao Zhang, Baihang Liu, Baoxu Liu, Qixu Liu
CSCWD4
2025 Graph Representation Learning via Generative-Contrastive Fusion for Advanced Persistent Threat Detection
Yijiao Jiang, Fangming Dong, Zhengwei Jiang, Tianming Zheng, Baoxu Liu, Liling Xin
ICA3PP (4)6
2025 Detection and Analysis of Poisoned Image in Container Registry
abstract
Container technology provides isolated, consistent, and efficient application environments across diverse computing platforms. Docker, as the dominant container platform, simplifies container creation, deployment, and operation. However, the integrity of the container supply chain is threatened by malicious “poisoned” images distributed via public registries like Docker Hub, which pose significant security risks to unsuspecting users. This study presents the first comprehensive investigation into this container registry image supply chain threat. We reveal that image poisoning occurs primarily during the build phase, where attackers embed malicious payloads into Dockerfiles and associated build artifacts via specific common vectors. To empirically assess this threat, we developed a detection system combining dynamic and static analysis. Scanning 214,920 images from public registries, we identified 122 poisoned images with high precision ($\mathbf{9 5. 3 1 \%}$). Our in-depth analysis shows these compromised images serve diverse malicious purposes, with cryptocurrency mining being prevalent, and exhibit significant characteristic differences compared to benign images. Finally, we propose concrete mitigation measures to improve the security of the Docker ecosystem. We reported our findings to Docker and received its confirmation.
Siyuan Pang, Yongshan Wang, Yepeng Yao, Zhengwei Jiang, Zijing Fan, Baoxu Liu
ISSRE6
2025 Controller Makes Pentesting Better: An Improved Multi-Agent Automated Penetration Testing Framework
abstract
Penetration testing is a popular technique for identifying system vulnerabilities, requiring skilled professionals and several weeks to complete. Existing automated penetration testing systems based on multi-agent and large language models(LLMs) are unable to efficiently complete the testing process due to gaps in stage assessment, workflow control and task execution capabilities compared to human expertise.To bridge these gaps, we propose an improved automated penetration testing framework. Our framework employs a Controller that manages the execution of agents across stages, ensuring efficient workflow management and preventing insufficient execution or unnecessary token consumption. Additionally, our framework separates services and potential exploits into individual tasks, minimizing interference and enhancing the effectiveness of each agent’s exploration. Our framework also integrates user-defined tools, allowing agents to invoke these tools through prompt engineering, which bridges the gap between LLMs and human capabilities in penetration testing. We evaluate our framework using the real-world AI-Pentest-Benchmark dataset, and the results demonstrate that it outperforms or matches state-of-the-art methods in terms of task completion rates, while achieving token usage ranging from 29.42% to 88.83% of the baseline. Evaluations also demonstrate the contribution of user-defined tools to the penetration testing process from effectiveness to efficiency.
Xiaoyu Geng, Boyuan Xu, Bo Jiang 0013, Baoxu Liu
TrustCom6
2025 Brewing Vodka: Distilling Pure Knowledge for Lightweight Threat Detection in Audit Logs
abstract
Advanced Persistent Threats (APTs) are continuously evolving, leveraging their stealthiness and persistence to put increasing pressure on current provenance-based Intrusion Detection Systems (IDS). This evolution exposes several critical issues: (1) The dense interaction between malicious and benign nodes within provenance graphs introduces neighbor noise, hindering effective detection; (2) The complex prediction mechanisms of existing APTs detection models lead to the insufficient utilization of prior knowledge embedded in the data; (3) The high computational cost makes detection impractical.
Weiheng Wu, Wei Qiao 0005, Bo Jiang 0013, Baoxu Liu, Zhigang Lu 0002
WWW6
2025 Advanced code slicing with pre-trained model fine-tuned for open-source component malware detection
abstract
Abstract Open Source Software (OSS) is an essential part of modern software development, with platforms such as PyPI for Python, NPM for JavaScript, and RubyGems for Ruby facilitating code sharing and reuse. However, these repositories also pose significant security risks due to potential software supply chain attacks, where payloads are injected into components, propagating threats to downstream users and critical infrastructure. Existing automatic malicious component detection tools, particularly for PyPI, struggle to distinguish between subtle differences in malicious and benign behaviors, leading to high false positive rates. To address these issues, we systematically compare and explore these subtle differences, offering a more refined and accurate detection method, Open-Source Component Code Slices BERT (OCS-BERT). OCS-BERT leverages taint-based program slicing to isolate sensitive behavior segments and fine-tunes pre-trained model to capture subtle semantic differences across programming languages. This system excels in detecting malicious Python components and exhibits encouraging cross-language transferability to JavaScript's NPM and Ruby's RubyGems. Additionally, OCS-BERT successfully detected 107 malicious components from a total of 25,759 newly-uploaded PyPI components, taking two weeks to complete the process. This achievement demonstrates the effectiveness of our method, which serves as a potent enhancement to the current repertoire of software supply chain detection methodologies.
Yongshan Wang, Siyuan Pang, Zijing Fan, Shang Shang, Yepeng Yao, Zhengwei Jiang, Baoxu Liu
Comput. J.7
2025 FG-SAT: Efficient Flow Graph for Encrypted Traffic Classification Under Environment Shifts
abstract
Encrypted traffic classification plays a critical role in network security and management. Currently, mining deep patterns from side-channel contents and plaintext fields through neural networks is a major solution. However, existing methods have two major limitations: (1) They fail to recognize the critical link between transport layer mechanisms and applications, missing the opportunity to learn internal structure features for accurate traffic classification. (2) They assume network traffic in an unrealistically stable and singular environment, making it difficult to effectively classify real-world traffic under environment shifts. In this paper, we propose FG-SAT, the first end-to-end method for encrypted traffic analysis under environment shifts. We propose a key abstraction, theFlow Graph, to represent flow internal relationship structures and rich node attributes, which enables robust and generalized representation. Additionally, to address the problem of inconsistent data distribution under environment shifts, we introduce a novel feature selection algorithm based on Jensen-Shannon divergence (JSD) to select robust node attributes. Finally, we design a classifier, GraphSAT, which integrates Graph-SAGE and GAT to deeply learn Flow Graph features, enabling accurate encrypted traffic identification. FG-SAT exhibits both efficient and robust classification performance under environment shifts and outperforms state-of-the-art methods in encrypted attack detection and application classification.
Susu Cui, Xueying Han, Weihang Wang 0001, Bo Jiang 0013, Baoxu Liu, Zhigang Lu 0002
IEEE Trans. Inf. Forensics Secur.7
2025 SauronEyes: Disentangling Voluminous Logs to Unveil Camouflaged Attack Intentions
Wei Qiao 0005, Weiheng Wu, Yebo Feng, Teng Li 0003, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
IEEE Trans. Inf. Forensics Secur.10
2024 UAD-DPL: An Unknown Encrypted Attack Detection Method Based on Deep Prototype Learning
Liangchen Chen, Shu Gao, Baoxu Liu, Xu-Yao Zhang
ICPR (5)3
2024 ENS-RFMC: An Encrypted Network Traffic Sampling Method Based on Rule-Based Feature Extraction and Multi-hierarchical Clustering for Intrusion Detection
Liangchen Chen, Shu Gao, Zixuan Wei, Baoxu Liu, Xu-Yao Zhang
ICPR (24)4
2024 TAD-LLM: API Traffic Anomaly Detection Based on Large Language Model
abstract
APIs are increasingly prevalent in application environments, carrying the core business logic and sensitive data of enterprises, and have increasingly become the target of cyber attackers. The proportion of web attacks targeting APIs has exceeded half. The widespread use of APIs has expanded the attack surface, posing serious security challenges. Security risks, such as unauthorized access, misuse of business logic, data breaches, and complex cyber attacks, have intensified. Tr aditional security measures have proven inadequate in addressing API threats. There is an urgent demand for a more contextually aware and intelligent security mechanism capable of effectively mitigating API attacks. We proposed a novel model TAD-LLM based on Large Language Model for anomaly detection in API traffic. By using S2GS data transformation method, prompt optimization algorithm and LoRA fine-tuning technique, enables the model to acquire a profound comprehension of domain-specific knowledge in more elaborate detail, thereby enhancing the overall detection capability. Experimental results demonstrate that the proposed model TAD-LLM makes a significant advancement in securing APIs against cyber threats. The average f1-score of TAD-LLM reaches 99.27% in complex API attack scenarios. There are also notable improvements in precision, recall, and accuracy. Moreover, the overall performance of the model indicates that the model we proposed outperforms other models significantly and exhibits superior capability in handling complex API attack scenarios and advanced API attack techniques. It is worth noting that our model also shows strong performance on CSIC 2010, a widely used common http traffic dataset.
Baoxu Liu, Jingqiang Liu, Fangjiao Zhang, Qixu Liu
MSN2
2024 ContraMTD: An Unsupervised Malicious Network Traffic Detection Method based on Contrastive Learning
abstract
Malicious traffic detection has been a focal point in the field of network security, and deep learning-based approaches are emerging as a new paradigm. However, most of them are supervised methods, which highly depend on well-labeled data, and fail to handle unknown or continuously evolving attacks. Unsupervised methods alleviate the need for labeled data, but existing methods are often limited to detecting anomalies either in vertical perspective through historical comparisons or in horizontal perspective by comparing with concurrent entities. Relying on data from a single perspective is unreliable, and it limits the model's accuracy and generalizability. In this paper, we propose a novel method ContraMTD based on contrastive learning, which comprehensively considers both vertical and horizontal perspectives. ContraMTD extracts local behavior features and global interaction features from normal network traffic by proposed SEC and DE-GAT respectively, then employs contrastive learning to learn the relationship, especially consistency between them, and finally detects malicious traffic through a multi-round scoring approach. We conduct extensive experiments on three datasets, including a self-collected dataset, and the results demonstrate that our method outperforms many state-of-the-art methods in the domain of unsupervised malicious traffic detection.
Xueying Han, Susu Cui, Bo Jiang 0013, Cong Dong, Zhigang Lu 0002, Baoxu Liu
WWW8
2024 A survey of large language models for cyber threat detection
Mengjiao Cui, Yiyang Cao, Peian Yang, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
Comput. Secur.8
2024 ECNet: Robust Malicious Network Traffic Detection With Multi-View Feature and Confidence Mechanism
abstract
Malicious traffic detection in the real world faces the challenge of dealing with a diverse mix of known, unknown, and variant malicious traffic, requiring methods that are accurate, generalizable, and reliable for identifying both known and emerging threats. However, existing methods are unable to fully meet these requirements. Supervised methods can accurately detect known malicious traffic, but their performance declines significantly when encountering unknown attacks. Additionally, the misclassification is usually silent, leading to doubts about the reliability and practicality. Unsupervised methods can deal with unknown attacks, but their high false positive rate and inability to utilize the knowledge of existing attack data constitute obvious shortcomings. To overcome these limitations, we propose ECNet, an end-to-end robust malicious network traffic detection method. Particularly, ECNet incorporates multi-view features, including content and pattern features, and employs a gated-based feature fusion approach, providing an efficient and robust representation. Moreover, ECNet introduces a confidence mechanism and combines category probability and confidence values during training and detection; therefore, it can accurately detect both known and unknown malicious traffic while ensuring the credibility of results. To validate the performance of ECNet, we conduct comprehensive experiments on six reorganized datasets and compare ECNet with seven state-of-the-art methods. The results demonstrate that ECNet outperforms others, particularly showing significant improvements in detecting unknown attacks, with up to a 14.15% increase in F1 compared to the best-performing method.
Xueying Han, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
IEEE Trans. Inf. Forensics Secur.6
2023 Sherlock on Specs: Building LTE Conformance Tests through Automated Reasoning
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Baoxu Liu
USENIX Security Symposium8
2023 AppChainer: investigating the chainability among payloads in android applications
abstract
Abstract Statistics show that more than 80 applications are installed on each android smartphone. Vulnerability research on Android applications is of critical importance. Recently, academic researchers mainly focus on single bug patterns, while few of them investigate the relations between multiple bugs. Industrial researchers proposed a series of logic exploit chains leveraging multiple logic bugs. However, there is no general model to evaluate the chaining abilities between bugs. This paper presents a formal model to elucidate the relations between multiple bugs in Android applications. To prove the effectiveness of the model, we design and implement a prototype system named AppChainer. AppChainer automatically identifies attack surfaces of Android applications and investigates whether the payloads entering these attack surfaces are “chainable”. Experimental results on 2138 popular Android applications show that AppChainer is effective in identifying and chaining attacker-controllable payloads. It identifies 14467 chainable payloads and constructs 5458 chains both inside a single application and among various applications. The time cost and resource consumption of AppChainer are also acceptable. For each application, the average analysis time is 317 s, and the average memory consumed is 2368 MB. Compared with the most relevant work Jandroid, the experiment results on our custom DroidChainBench show that AppChainer outperforms Jandroid at the precision rate and performs equally with Jandroid at the recall rate.
Xiaobo Xiang, Qingli Guo, Xiaorui Gong, Baoxu Liu
Cybersecur.6
2022 The Hyperbolic Temporal Attention Based Differentiable Neural Turing Machines for Diachronic Graph Embedding in Cyber Threat Intelligence
abstract
Cyber Threat Intelligence (CTI) is an effective approach to solve cyber security problems, finding unknown threats is becoming a problem to be solved. Research based on threat intelligence knowledge graphs has gradually increased for its capability to capture entity characteristics and better predict unknown threats. Most of the current research focuses on Euclidean space, however, the Euclidean space is insufficient to capture the hierarchical information of the knowledge graph. In this paper, we propose a novel Hyperbolic Temporal Attention based Differential Neural Turing Machines for diachronic graph embedding framework (HTA-DNTM), which adopts a graph attention network model based on hyperbolic space, simultaneously uses multi-head self-attention to map the temporal graph into hyperbolic space and incorporates hyperbolic graph neural network and hyperbolic gated recurrent neural network, capturing the evolving behaviors and implicitly preserve hierarchical information simultaneously. Moreover, we demonstrate significantly improved performance over various approaches on CTI. A series of benchmark experiments illustrate HTA-DNTM has ability to generate higher quality than state-of-the-art word embedding models in CTI fields.
Binghua Song, Baoxu Liu, Zhengwei Jiang, Xuren Wang
CSCWD3
2022 ModX: Binary Level Partially Imported Third-Party Library Detection via Program Modularization and Semantic Matching
abstract
With the rapid growth of software, using third-party libraries (TPLs) has become increasingly popular. The prosperity of the library usage has provided the software engineers with a handful of methods to facilitate and boost the program development. Unfortunately, it also poses great challenges as it becomes much more difficult to manage the large volume of libraries. Researches and studies have been proposed to detect and understand the TPLs in the software. However, most existing approaches rely on syntactic features, which are not robust when these features are changed or deliberately hidden by the adversarial parties. Moreover, these approaches typically model each of the imported libraries as a whole, therefore, cannot be applied to scenarios where the host software only partially uses the library code segments.
Zhengzi Xu, Hongxu Chen 0001, Yang Liu 0003, Xiaorui Gong, Baoxu Liu
ICSE6
2022 Malware detection method based on image analysis and generative adversarial networks
abstract
Summary Malware detection is indispensable to cybersecurity. However, with the advent of new malware variants and scenarios with few and imbalanced samples, malware detection for various complex scenarios has been a very challenging problem. In this article, we propose a malware detection method based on image analysis and generative adversarial networks, named MadInG, which can improve the accuracy of malware detection for insufficient samples, sample imbalance, and new variants scenarios. Specifically, we first generate fixed‐size grayscale images of malware to reduce the workload of feature engineering or the involvement of domain expert knowledge on malware detection. Then we introduce auxiliary classifier generative adversarial networks into malware detection to enhance the generalization ability of the detector. Finally, we construct a variety of malware scenarios and compare our proposed method with existing popular detection methods. Extensive experimental results demonstrate that our method achieves high accuracy and well balance in malware detection for different scenarios, especially, the detection rate of malware variants reaches 99.5%.
Baoxu Liu, Xiaoling Gao, Ximeng Liu
Concurr. Comput. Pract. Exp.3
2022 Blockchain abnormal behavior awareness methods: a survey
abstract
Abstract With the wide application and development of blockchain technology in various fields such as finance, government affairs and medical care, security incidents occur frequently on it, which brings great threats to users’ assets and information. Many researchers have worked on blockchain abnormal behavior awareness in respond to these threats. We summarize respectively the existing public blockchain and consortium blockchain abnormal behavior awareness methods and ideas in detail as the difference between the two types of blockchain. At the same time, we summarize and analyze the existing data sets related to mainstream blockchain security, and finally discuss possible future research directions. Therefore, this work can provide a reference for blockchain security awareness research.
Chuyi Yan, Zhigang Lu 0002, Baoxu Liu
Cybersecur.6
2022 TIM: threat context-enhanced TTP intelligence mining on unstructured threat data
abstract
Abstract TTPs (Tactics, Techniques, and Procedures), which represent an attacker’s goals and methods, are the long period and essential feature of the attacker. Defenders can use TTP intelligence to perform the penetration test and compensate for defense deficiency. However, most TTP intelligence is described in unstructured threat data, such as APT analysis reports. Manually converting natural language TTPs descriptions to standard TTP names, such as ATT&CK TTP names and IDs, is time-consuming and requires deep expertise. In this paper, we define the TTP classification task as a sentence classification task. We annotate a new sentence-level TTP dataset with 6 categories and 6061 TTP descriptions from 10761 security analysis reports. We construct a threat context-enhanced TTP intelligence mining (TIM) framework to mine TTP intelligence from unstructured threat data. The TIM framework uses TCENet (Threat Context Enhanced Network) to find and classify TTP descriptions, which we define as three continuous sentences, from textual data. Meanwhile, we use the element features of TTP in the descriptions to enhance the TTPs classification accuracy of TCENet. The evaluation result shows that the average classification accuracy of our proposed method on the 6 TTP categories reaches 0.941. The evaluation results also show that adding TTP element features can improve our classification accuracy compared to using only text features. TCENet also achieved the best results compared to the previous document-level TTP classification works and other popular text classification methods, even in the case of few-shot training samples. Finally, the TIM framework organizes TTP descriptions and TTP elements into STIX 2.1 format as final TTP intelligence for sharing the long-period and essential attack behavior characteristics of attackers. In addition, we transform TTP intelligence into sigma detection rules for attack behavior detection. Such TTP intelligence and rules can help defenders deploy long-term effective threat detection and perform more realistic attack simulations to strengthen defense.
Yizhe You, Zhengwei Jiang, Peian Yang, Baoxu Liu, Huamin Feng, Xuren Wang
Cybersecur.5
2022 NDFuzz: a non-intrusive coverage-guided fuzzing framework for virtualized network devices
abstract
Abstract Network function virtualization provides programmable in-network middlewares by leveraging virtualization technologies and commodity hardware and has gained popularity among all mainstream network device manufacturers. Yet it is challenging to apply coverage-guided fuzzing, one of the state-of-the-art vulnerability discovery approaches, to those virtualized network devices, due to inevitable integrity protection adopted by those devices. In this paper, we propose a coverage-guided fuzzing framework NDFuzz for virtualized network devices with a novel integrity protection bypassing method, which is able to distinguish processes of virtualized network devices from hypervisors with a carefully designed non-intrusive page global directory inference technique. We implement NDFuzz atop of two black-box fuzzers and evaluate NDFuzz with three representative network protocols, SNMP , DHCP and NTP , on nine popular virtualized network devices. NDFuzz obtains an average 36% coverage improvement in comparison with its black-box counterparts. NDFuzz discovers 2 0-Day vulnerabilities and 1 1-Day vulnerability with coverage guidance while the black-box fuzzer can find only one of them. All discovered vulnerabilities are confirmed by corresponding vendors.
Nanyu Zhong, Wei You 0001, Yanyan Zou 0002, Kunpeng Jian, Jiahuan Xu, Baoxu Liu, Wei Huo 0005
Cybersecur.8
2021 Ghost in the Binder: Binder Transaction Redirection Attacks in Android System Services
abstract
Binder, the main mechanism for Android applications to access system services, adopts a client-server role model in its design, assuming the system service as the server and the application as the client. However, a growing number of scenarios require the system service to act as a Binder client and to send queries to a Binder server possibly instantiated by the application. Departing from this role-reversal possibility, this paper proposes the Binder Transaction Redirection (BiTRe) attacks, where the attacker induces the system service to transact with a customized Binder server and then attacks from the Binder server---an often unprotected direction. We demonstrate the scale of the attack surface by enumerating the utilizable Binder interfaces in BiTRe, and discover that the attack surface grows with the Android release version. In Android 11, more than 70% of the Binder interfaces are affected by or can be utilized in BiTRe. We prove the attacks' feasibility by (1) constructing a prototype system that can automatically generate executable programs to reach a substantial part of the attack surface, and (2) identifying a series of vulnerabilities, which are acknowledged by Google and assigned ten CVEs.
Xiaobo Xiang, Ren Zhang 0003, Hanxiang Wen, Xiaorui Gong, Baoxu Liu
CCS5
2021 Spear Phishing Emails Detection Based on Machine Learning
abstract
Spear phishing emails target to specific individual or organization, they are more elaborated, targeted, and harmful than phishing emails. The attackers usually harvest information about the recipient in any available ways, then create a carefully camouflaged email and lure the recipient to perform dangerous actions. In this paper we present a new effective approach to detect spear phishing emails based on machine learning. Firstly we extracted 21 Stylometric features from email, 3 forwarding features from Email Forwarding Relationship Graph Database(EFRGD), and 3 reputation features from two third-party threat intelligence platforms, Virus Total(VT) and Phish Tank(PT). Then we made an improvement on Synthetic Minority Oversampling Technique(SMOTE) algorithm named KM-SMOTE to reduce the impact of unbalanced data. Finally we applied 4 machine learning algorithms to distinguish spear phishing emails from non-spear phishing emails. Our dataset consists of 417 spear phishing emails and 13916 non-spear phishing emails. We were able to achieve a maximum recall of 95.56%, precision of 98.85% and 97.16% of F1-score with the help of forwarding features, reputation features and KM-SMOTE algorithm.
Xiong Ding, Baoxu Liu, Zhengwei Jiang, Qiuyun Wang, Liling Xin
CSCWD2
2021 Producing More with Less: A GAN-based Network Attack Detection Approach for Imbalanced Data
abstract
Machine learning techniques are shown to be effective for network attack detection systems in identifying malicious network behaviors. In the real-world environment, however, network attack traffic i soften hidden under a large amount of normal daily communication traffic. In this paper, to resolve such challenges that the large-scale data is difficult to be effectively labeled, we propose a data augmentation method based on generative adversarial networks. The features of flow-based network traffic are firstly pre-processed to fit the generative adversarial networks (GANs). Then, we enhance the original GANs by adopting Earth-Mover (EM) distance to catch the distribution of low dimensional subspace data and add an encoder structure to learn latent space representation. Compared to other data augmentation methods, our method generates data from learning data distribution rather than performing numerical calculations on existing data. We construct an imbalanced dataset based on the real-world dataset and compare it with other methods. Our method reports better performance in terms of the recall, F1-score, and AUC, which proved the effectiveness of our proposed method.
Xingran Hao, Zhengwei Jiang, Qingsai Xiao, Qiuyun Wang, Yepeng Yao, Baoxu Liu, Jian Liu 0008
CSCWD6
2021 Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation Analysis
abstract
In the past decade, the security of cellular networks has been increasingly under scrutiny, leading to the discovery of numerous vulnerabilities that expose the network and its users to a wide range of security risks, from denial of service to information leak. However, most of these findings have been made through ad-hoc manual analysis, which is inadequate for fundamentally enhancing the security assurance of a system as complex as the cellular network. An important observation is that the massive amount of technical documentation of cellular network can provide key insights into the protection it puts in place and help identify potential security flaws. Particularly, we found that such documentation often contains hazard indicators (HIs) – the statement that describes a risky operation (e.g., abort an ongoing procedure) when a certain event happens at a state, which can guide a test on the system to find out whether the operation can indeed be triggered by an unauthorized party to cause harm to the cellular core or legitimate users’ equipment. Based upon this observation, we present in this paper a new framework that makes the first step toward intelligent and systematic security analysis of cellular networks. Our approach, called Atomic, utilizes natural-language processing and machine learning techniques to scan a large amount of LTE documentation for HIs. The HIs discovered are further parsed and analyzed to recover state and event information for generating test cases. These test cases are further utilized to automatically construct tests in an LTE simulation environment, which runs the tests to detect the vulnerabilities in the LTE that allow the risky operations to happen without proper protection. In our research, we implemented Atomic and ran it on the LTE NAS specification, including 549 pages with 13,598 sentences and 283,850 words. In less than 5 hours, our prototype reported 42 vulnerabilities from 192 HIs discovered, including 10 never reported before, under two threat models. All these vulnerabilities have been confirmed through end-to-end attacks, which lead to unauthorized disruption of the LTE service a legitimate user’s equipment receives. We reported our findings to authorized parties and received their confirmation that these vulnerabilities indeed exist in major commercial carriers and $2,000 USD reward from Google.
Yi Chen 0024, Yepeng Yao, XiaoFeng Wang 0001, Dandan Xu, Chang Yue, Xiaozhong Liu 0001, Kai Chen 0012, Haixu Tang, Baoxu Liu
SP9
2021 Evil Under the Sun: Understanding and Discovering Attacks on Ethereum Decentralized Applications
Liya Su, Xinyue Shen 0001, Xiangyu Du, Xiaojing Liao, XiaoFeng Wang 0001, Luyi Xing, Baoxu Liu
USENIX Security Symposium7
2021 Automated Honey Document Generation Using Genetic Algorithm
Yun Feng 0003, Baoxu Liu, Jinli Zhang, Chaoge Liu, Qixu Liu
WASA (3)2
2021 ESRFuzzer: an enhanced fuzzing framework for physical SOHO router devices to discover multi-Type vulnerabilities
abstract
Abstract SOHO (small office/home office) routers provide services for end devices to connect to the Internet, playing an important role in cyberspace. Unfortunately, security vulnerabilities pervasively exist in these routers, especially in the web server modules, greatly endangering end users. To discover these vulnerabilities, fuzzing web server modules of SOHO routers is the most popular solution. However, its effectiveness is limited due to the lack of input specification, lack of routers’ internal running states, and lack of testing environment recovery mechanisms. Moreover, existing works for device fuzzing are more likely to detect memory corruption vulnerabilities.In this paper, we propose a solution ESRFuzzer to address these issues. It is a fully automated fuzzing framework for testing physical SOHO devices. It continuously and effectively generates test cases by leveraging two input semantic models, i.e., KEY-VALUE data model and CONF-READ communication model, and automatically recovers the testing environment with power management. It also coordinates diversified mutation rules with multiple monitoring mechanisms to trigger multi-type vulnerabilities. With the guidance of the two semantic models, ESRFuzzer can work in two ways: general mode fuzzing and D-CONF mode fuzzing. General mode fuzzing can discover both issues which occur in the CONF and READ operation, while D-CONF mode fuzzing focus on the READ-op issues especially missed by general mode fuzzing.We ran ESRFuzzer on 10 popular routers across five vendors. In total, it discovered 136 unique issues, 120 of which have been confirmed as 0-day vulnerabilities we found. As an improvement of SRFuzzer, ESRFuzzer have discovered 35 previous undiscovered READ-op issues that belong to three vulnerability types, and 23 of them have been confirmed as 0-day vulnerabilities by vendors. The experimental results show that ESRFuzzer outperforms state-of-the-art solutions in terms of types and number of vulnerabilities found.
Wei Huo 0005, Kunpeng Jian, Ji Shi 0002, Longquan Liu, Yanyan Zou 0002, Chao Zhang 0008, Baoxu Liu
Cybersecur.8
2021 MBTree: Detecting Encryption RATs Communication Using Malicious Behavior Tree
abstract
Network trace signature matching is one reliable approach to detect active Remote Control Trojan, (RAT). Compared to statistical-based detection of malicious network traces in the face of known RATs, the signature-based method can achieve more stable performance and thus more reliability. However, with the development of encrypted technologies and disguise tricks, current methods suffer inaccurate signature descriptions and inflexible matching mechanisms. In this paper, we propose to tackle above problems by presenting MBTree, an approach to detect encryption RATs Command and Control (C&C) communication based on host-level network trace behavior. MBTree first models the RAT network behaviors as the malicious set by automatically building the multiple level tree, MLTree from distinctive network traces of each sample. Then, MBTree employs a detection algorithm to detect malicious network traces that are similar to any MLTrees in the malicious set. To illustrate the effectiveness of our proposed method, we adopt theoretical analysis of MBTree from the probability perspective. In addition, we have implemented MBTree to evaluate it on five datasets which are reorganized in a sophisticated manner for comprehensive assessment. The experimental results demonstrate the accurate and robust of MBTree, especially in the face of new emerging benign applications.
Cong Dong, Zhigang Lu 0002, Zelin Cui, Baoxu Liu, Kai Chen 0012
IEEE Trans. Inf. Forensics Secur.4
2020 RouAlign: Cross-Version Function Alignment and Routine Recovery with Graphlet Edge Embedding
Jian Liu 0008, Mengxia Luo, Xiaorui Gong, Baoxu Liu
SEC5
2020 CETAnalytics: Comprehensive effective traffic information analytics for encrypted traffic classification
Cong Dong, Zhigang Lu 0002, Baoxu Liu, Bo Jiang 0013
Comput. Networks4
2020 Malware classification for the cloud via semi-supervised transfer learning
abstract
Malware threats and privacy protection are two of the biggest challenges in the cloud computing environment. Many studies have focused on the accuracy of malware detection, but they did not sufficiently take into account the privacy protection of cloud tenants. This paper proposes a novel malware detection model, based on semi-supervised transfer learning (SSTL) for the cloud, that consists of detection, prediction, and transfer components. To protect the privacy of tenants in the public cloud, a byte classifier based on a recurrent neural network (RNN) for its detection component is designed to detect malware. However, because it is limited by the scarcity of training samples, the accuracy of the byte classifier is only 94.72% after supervised learning. An asm classifier is proposed for the prediction component, and it achieves 99.69% accuracy. The transfer component invokes the prediction component to classify an unlabeled dataset, and it combines the predicted labels and byte features of the unlabeled dataset into a new training dataset. Through the advantages of semi-supervised learning, the new dataset is transferred to the byte classifier for training again. The test results on the Kaggle malware datasets show that semi-supervised transfer learning improved the accuracy of the detection component from 94.72% to 96.9%. The improved malware detection method can not only do a better job of resolving the privacy concerns of tenants in the public cloud than other similar methods, but it can also detect malware more accurately.
Xianwei Gao, Changzhen Hu, Chun Shan, Baoxu Liu, Zequn Niu
J. Inf. Secur. Appl.4
2020 THS-IDPC: A three-stage hierarchical sampling method based on improved density peaks clustering algorithm for encrypted malicious traffic detection
Liangchen Chen, Shu Gao, Baoxu Liu, Zhigang Lu 0002, Zhengwei Jiang
J. Supercomput.3
2019 SRFuzzer: an automatic fuzzing framework for physical SOHO router devices to discover multi-type vulnerabilities
abstract
SOHO (small office/home office) routers provide services for end devices to connect to the Internet, playing an important role in the cyberspace. Unfortunately, security vulnerabilities pervasively exist in these routers, especially in the web server modules, greatly endangering end users. To discover these vulnerabilities, fuzzing web server modules of SOHO routers is the most popular solution. However, its effectiveness is limited, due to the lack of input specification, lack of routers' internal running states, and lack of testing environment recovery mechanisms. Moreover, fuzzing in general only reports memory corruption vulnerabilities, and fails to discover other vulnerabilities, e.g., web-based vulnerabilities.
Wei Huo 0005, Kunpeng Jian, Ji Shi 0002, Haoliang Lu, Longquan Liu, Dandan Sun, Chao Zhang 0008, Baoxu Liu
ACSAC10
2019 An Approach for Scale Suspicious Network Events Detection
abstract
Detecting the real suspicious events from a large number of low-quality alerts is a severe challenge to the security operations center teams. In this paper, we present an approach to this problem by following the sequence of machine learning steps. The highlight of our approach is the method to generate two simple but effective categories of features based on group and aggregation operations, which can scale with a large number of alerts using MapReduce framework. The two generated types of features are local features and global features. The local features cover the alert aggregation information of the same group of events, while the global features cover the network aggregation information of different groups of events. Moreover, we also introduce the model stacking mechanism to enhance the robustness of the model. The proposed approach achieves AUC scores of 0.9512 on the validating dataset and 0.9303 on the test set, which is the 2ndhighest final score in the competition.
Cong Dong, YunJian Zhang, Bo Jiang 0013, Dongxu Han, Baoxu Liu
IEEE BigData6
2017 State-of-the-Art: Security Competition in Talent Education
Baoxu Liu, Xiaorui Gong
Inscrypt2