Guozhong Dong

dblp:146/2028 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0002-7144-1327ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Dynamic Adaptive Aggregation and Feature Pyramid Network Enhanced GraphSAGE for Advanced Persistent Threat Detection in Next-Generation Communication Networks
abstract
Advanced Persistent Threats (APTs) pose severe challenges to Next-Generation Communication Networks (NGCNs) due to their stealthiness and NGCNs’ dynamic topology, while conventional GNN-based intrusion detection systems suffer from static aggregation and poor adaptability to unseen nodes. To address these issues, this paper proposes DAA-FPN-SAGE, a lightweight graph-based detection framework integrating Dynamic Adaptive Aggregation (DAA) and Multi-Scale Feature Pyramid Network (MSFPM). Leveraging GraphSAGE’s inductive learning capability, the framework effectively models unseen nodes or subgraphs and adapts to NGCN’s dynamic changes (e.g., elastic network slicing, online AI model updates)—a key advantage for handling NGCN’s real-time topological variations. The DAA module employs multi-hop attention to dynamically assign weights to neighbors at different hop distances, enhancing capture of hierarchical dependencies in multi-stage APT attack chains. The MSFPM module fuses local-global structural information via a gated feature selection mechanism, resolving dimensional inconsistency and enriching attack behavior representation. Extensive experiments on StreamSpot, Unicorn, and DARPA TC#3 datasets demonstrate superior performance, meeting detection requirements of large-scale NGCNs.
Liang Kou, Xiaochen Pan, Guozhong Dong, Chunyu Miao, Pingxia Duan
IEEE Trans. Netw. Serv. Manag.3
2024 DNS Covert Channel Attack Detection Based on Spatio-Temporal Feature Fusion
abstract
An increasing number of Advanced Persistent Threat (APT) organizations are utilizing DNS (Domain Name System) covert channels to evade network intrusion detection systems and establish private authoritative servers for remote attacks. However, current detection models for DNS covert channels often have poor performance and limited generalization ability. To address these challenges, we propose a DNS covert channel attack detection method based on spatiotemporal feature fusion. This method combines the Interaction timing sequence features of DNS traffic with the spatial statistical features of domain names, and constructs a detection model called ConvSLSTM, which integrates a Convolutional Neural Network (CNN) with a stacked Long Short Term Memory (LSTM) network. CNN extracts local spatial features from traffic, while stacked LSTM captures Interaction timing sequence features, significantly improving detection accuracy. This article uses three typical public datasets for experiments, which contain a total of 440000 DNS covert channel attack data. Comparative experiments show that our method is significantly superior to existing methods and exhibits stronger generalization ability in detecting DNS covert channel attacks constructed by unknown tools.
Chunlei Zhao, Chao Shan, Guozhong Dong
ISPA4
2024 LTAChecker: Lightweight Android Malware Detection Based on Dalvik Opcode Sequences Using Attention Temporal Networks
abstract
Android applications have emerged as a prime target for hackers. Android malware detection stands as a pivotal technology, crucial for safeguarding network security and thwarting anomalies. However, traditional static analysis makes it difficult to analyze new malicious applications, while dynamic analysis requires higher system resources. We propose a novel lightweight Android malware deep-learning detection framework based on attention temporal networks. This study delves into the Dalvik opcode sequences of Android malware, employing the N-gram algorithm to partition sequences and extract contextual information features. Then, LSTM and TCN algorithms are employed to capture long-term dependencies and local features, enabling comprehensive comprehension of temporal information within Dalvik opcode sequences. Especially, TCN facilitates feature extraction across various time scales, thereby enabling the detection of anomaly patterns across diverse temporal scales within Dalvik opcode sequences. Moreover, we introduce multi-head attention mechanisms and reinforced learning to direct the model’s focus toward behavioral cues within malicious software sequences. Finally, extensive experiment results show that our proposed methodology and model exhibit higher detection accuracy and robustness, achieving an accuracy rate of 98.69% on average, surpassing traditional machine learning methods such as random forest, and Pseudo-Label deep neural networks.
Liangyi Gong, Xiuliang Mo, Guozhong Dong
IEEE Internet Things J.4
2021 A Novel Android Malware Detection Method Based on Visible User Interface
abstract
Machine learning has been increasingly adopted to detect Android malwares. Most existing studies depend on features in code space such as information flows and API calls. Malware variants would engage these models in a never-ending war. Inspired by the observation that some variants share similar or even identical user interfaces (UIs), this paper explores employing visible UI screenshot as the indicator to build a novel Android malware detection method. To achieve this vision, we built the first Android Application Screenshot Dataset (AnASD) consisting of more than twenty thousand UI screenshots produced by both benign applications and malwares. A thorough analysis was conducted to characterize the dataset, especially the UI difference between benign applications and malwares. Then a set of state of the art deep learning classifiers on AnASD were trained and evaluated. The results of both sim-ilarity measurement and classification performance proved the feasibility to detect Android malwares based on user interfaces. To facilitate the research community, the dataset is free available at https://doi.org/10.6084/m9.figshare.14445768.
Shuaishuai Tan, Zhiyi Tian, Xiaoxiong Zhong, Shui Yu 0001, Weizhe Zhang, Guozhong Dong
TrustCom6
2021 EOM-NPOSESs: Emergency Ontology Model Based on Network Public Opinion Spread Elements
abstract
The construction of an emergency ontology model plays an important role in emergency management, which is an important basis for emergency public opinion management and decision-making. Integration of network public opinion spread elements into the emergency ontology model is crucial for realizing knowledge sharing in the field of emergency and public opinion responses. In this study, we crawl a large amount of emergency data from different data sources and construct an emergency dataset. Based on this dataset, we analyze the public opinion elements of emergencies and propose an emergency ontology model based on network public opinion spread elements (EOM-NPOSESs). Thereafter, we consider the coronavirus disease (COVID-19) emergency as an example to construct the EOM-NPOSESs. Finally, we design some strategies to realize rule reasoning and present the COVID-19 emergency application based on the constructed EOM-NPOSESs and the geographic information system platform. The results demonstrate that EOM-NPOSESs can not only describe the semantic relationship between emergencies and emergency elements but also perform semantic logical reasoning on different emergencies.
Guozhong Dong, Weizhe Zhang, Haowen Tan, Shuaishuai Tan
Secur. Commun. Networks1
2016 Detecting Community Pacemakers of Burst Topic in Twitter
Guozhong Dong, Wu Yang 0001, Feida Zhu 0001, Wei Wang 0076
APWeb (1)1
2015 Anomaly Detection in Microblogging via Co-Clustering
Wu Yang 0001, Guowei Shen, Wei Wang 0076, Liangyi Gong, Miao Yu 0006, Guozhong Dong
J. Comput. Sci. Technol.6