Ru Tan

dblp:174/1373 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
8since 2021 · last 2026
0009-0001-5324-2455ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TGNN: Enhancing Pixel Tracking Detection via LLM-driven Annotation and GAT-powered Structural Representation
abstract
Web tracking is increasingly pervasive, raising serious concerns about user privacy and security. Among existing techniques, pixel tracking is particularly stealthy and cost-effective, embedding invisible images that exfiltrate user activities to third-party servers. Current defenses, including filter list blocking and conventional machine learning, often fail to capture the cross-site associations that enable pixel tracking to evade detection.
Shenping Xiong, Xutong Wang, Ze Jin, Xinyu Liu 0019, Haoqiang Wang, Ru Tan, Qixu Liu
WWW7
2026 TLBAC: a zero-trust based cloud-edge-endpoint access control system using trusted labels
abstract
Abstract With the rapid development of cloud computing, enterprises have increasingly migrated their servers and services from internal networks to cloud environments. Traditional boundary-based protection mechanisms are no longer sufficient for addressing the security requirements of modern cloud-based systems. As cyberattacks continue to evolve, ensuring the long-term, secure, and reliable operation of increasingly complex IT systems has become a significant challenge. Consequently, researchers have proposed various fine-grained access control approaches. Fine-grained access control remains a significant challenge in complex cloud-edge-endpoint collaboration scenarios. Existing approaches often rely on intricate policy definitions to achieve granular control, which can lead to increased computational overhead and degraded system performance. In this paper, we propose a lightweight, Zero-Trust-based Cloud-Edge-Endpoint Access Control System—TLBAC. By embedding trusted labels into TCP packets at the security endpoint (Endpoint), TLBAC enables traffic blocking and forwarding through access control policies issued by the Security Cloud Brain (Cloud) via the Edge Decision Gateway (Edge). This framework achieves fine-grained access control through trusted labels in a cloud-edge-endpoint architecture. To evaluate the effectiveness of TLBAC, four experiments are designed. The first experiment examines the impact of trusted labels insertion on TCP traffic packet transmission behavior. The experimental results show that even under high-latency, significant jitter, and high packet loss conditions in an LTE network, TCP packets with embedded trusted labels maintain stable and reliable data transmission. The second experiment assesses the resource consumption of TLBAC, focusing on CPU and memory overhead. The experimental results indicate that TLBAC’s resource consumption rate is only ± 0.2%. The third experiment simulates a realistic attack environment by launching attacks against the protected system from an adversarial perspective to validate TLBAC’s defensive capabilities. The experimental results demonstrate that TLBAC successfully detected and blocked all attacks in over thirty vulnerability cases involving different components, versions, and exploitation methods. The fourth experiment evaluates the practical operational capability of TLBAC in a multi-tenant environment. The results show that TLBAC can achieve connection-oriented fine-grained access control with low latency, while maintaining policy accuracy and isolation in multi-tenant scenarios.
Ru Tan, Baihang Liu, Yaqin Cao, Qixu Liu
Cybersecur.1
2025 RBAClock: Contain RBAC Permissions through Secure Scheduling
abstract
Kubernetes has emerged as the de facto standard for container orchestration. However, existing container scheduling strategies prioritize QoS, leading to the co-location of pods with varying permission levels on the same node. This not only introduces risks of privilege escalation but also facilitates the spread of pods with risky permissions across the cluster, exacerbating the potential for attackers to elevate their privileges. In this work, our goal is to mitigate permission disparity among pods on each node, thereby reducing the risk of privilege escalation from co-location attack and curbing the spread of high-risk permissions across the cluster. We introduce a novel metric, Extraneous Risk Privileges (ERP), to quantify additional privileges derived from the combination of RBAC permissions and cluster parameters that are utilized by other pods on the node but not by the target pod itself. The RBAClock scheduling framework is designed to minimize ERP increase during pod placement, prioritizing the aggregation of pods with similar risk profiles and isolation of those with divergent privileges. Experimental evaluations across 24 CNCF applications demonstrate that, compared to the default scheduler, RBAClock alone achieves an average reduction of 41.46% in aggregated privileges in cluster, 64.63% in privilege escalation risk, and 34.59% in high-privilege nodes proportion, with an 8% performance tradeoff. Notably, our investigation uncovered privilege escalation risks in the Kubernetes services of two major cloud providers, Alibaba Cloud and Tencent Cloud, and demonstrated that RBAClock can effectively mitigate these threats.
Qingwang Chen, Ru Tan, Yuqi Shu, Zhou Tong, Haoqiang Wang, Ze Jin, Qixu Liu
RAID2
2025 DEPHP: A Source Code Recovery Method for PHP Bytecode with Improved Structural Analysis
abstract
Over the past decade, PHP has consistently been one of the most popular server-side programming languages among developers for web development. To protect intellectual property, various PHP source code obfuscation and encryption methods have been developed, which has led to difficulties in performing security analysis on PHP source code. Previous work has demonstrated the feasibility of recovering source code by extracting bytecode from PHP during dynamic execution. However, there is still a lack of a universal decompilation method for this kind of bytecode, tailored to PHP’s unique syntax. Thus, we propose a systematic decompilation framework for PHP bytecode. First, we design a unified intermediate representation that eliminates the differences between bytecodes from different PHP versions. Then, we introduce a structural analysis algorithm specifically for PHP syntax, improving upon existing methods to better accommodate PHP’s unique syntax. We use over 3 million lines of PHP code as a dataset and compiled it into PHP bytecode. After decompiling it with our method, we successfully recovered 92% of the classes and 85% of the methods. Furthermore, from the encrypted dataset containing 37 SQL injection and 31 XSS vulnerability patterns, we fully restored the original vulnerability patterns and reconstructed the exploitation chains. Furthermore, we identified a series of vulnerabilities in real-world projects and were assigned 6 new CVE IDs1, demonstrating the correctness of our method and its ability to assist in static analysis for vulnerability discovery.1CVE-2025-45046, CVE-2025-45047, CVE-2025-45048, CVE-2025-45049, CVE-2025-45050, CVE-2025-45052
Shiwu Zhao, Ningjun Zheng, Ruizhi Feng, Xingchen Chen, Ru Tan, Qixu Liu
RAID6
2025 Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integration
abstract
Abstract As cloud-native technologies continue to evolve, containerization and orchestration have become fundamental for deploying microservices. However, this advancement introduces significant security vulnerabilities, particularly due to vulnerabilities and misconfigurations that grant attackers excessive control over clusters. Existing works, including model-based learning and static rule-based approaches, suffer from limitations such as false positives and maintenance overhead, which pose significant challenges to cloud-native security. To mitigate intrusion targeting container orchestration, we present ShadowKube, an innovative active defense framework tailored for Kubernetes. ShadowKube integrates behavioral monitoring with shadow honeypots to effectively detect and neutralize anomalous behavior. By establishing behavioral baselines to identify deviations and converting compromised nodes into honeypots, ShadowKube isolates and traps attackers, thereby mitigating the threats they pose. Comprehensive evaluations demonstrate ShadowKube’s ability to detect and migrate exploitations across 43 severe CVEs and 7 common misconfiguration types. Deployment in a live environment further validates its effectiveness, with ShadowKube identifying 635 attack attempts, successfully decoying 23 active attacks. Additionally, ShadowKube could isolate attackers and convert affected nodes into honeypots within seconds. These results highlight ShadowKube’s efficacy as a robust solution for enhancing security in Kubernetes clusters, offering a proactive defense mechanism against both current and emerging threats.
Qingwang Chen, Ru Tan, Ze Jin, Juxin Xiao, Fangjiao Zhang, Qixu Liu
Cybersecur.3
2024 MalPolymer: A Threat Identification System Utilizing Cognate Malicious Login Behavior Detection
abstract
Accurate attribution and tracing of cyber attacks require a comprehensive understanding of the resources employed by malicious actors. However, Indicators of Compromise (IoCs) can only reveal a portion of the attacker’s assets. To enhance the capability of clue expansion, this study introduces a novel approach to associating attack sources, facilitating the identification of additional IP addresses and subnets that may correspond to a single malicious actor. We focus on the scenario of compromised email accounts and utilize login logs as foundational data. We employ Gaussian Mixture Models (GMM) to construct a reference model that captures known malicious behaviors. Then, we utilize a genetic algorithm to filter and select candidate subnets that exhibit the attack patterns outlined by the reference model. Through evaluation on real-world data, we demonstrate the effectiveness of our proposed method in successfully attributing multiple attack sources to a single attacker, thereby providing valuable insights for manual investigations.
Ru Tan, Yaqin Cao, Xutong Wang, Qixu Liu, Xiang Cui
CSCWD2
2024 Dissecting zero trust: research landscape and its implementation in IoT
abstract
Abstract As a progressive security strategy, the zero trust model has attracted notable attention and importance within the realm of network security, especially in the context of the Internet of Things (IoT). This paper aims to evaluate the current research regarding zero trust and to highlight its practical applications in the IoT sphere through extensive bibliometric analysis. We also delve into the vulnerabilities of IoT and explore the potential role of zero trust security in mitigating these risks via a thorough review of relevant security schemes. Nevertheless, the challenges associated with implementing zero trust security are acknowledged. We provide a summary of these issues and suggest possible pathways for future research aimed at overcoming these challenges. Ultimately, this study aims to serve as a strategic analysis of the zero trust model, intending to empower scholars in the field to pursue deeper and more focused research in the future.
Chunwen Liu, Ru Tan, Yun Feng 0003, Ze Jin, Fangjiao Zhang, Qixu Liu
Cybersecur.2
2023 SWDNet: Stealth Web Shell Detection Technology based on Triplet Network
abstract
Amid escalating cyber threats, websites have emerged as predominant targets for attackers employing web shells to maintain extended control. Web shells, frequently used by Advanced Persistent Threat (APT) groups, often result in significant damage, despite the conspicuous lack of focused academic research on their detection. This paper illuminates the stealth variant of the web shell, covertly embedded within benign files, and addresses the unique detection challenges presented by their covert nature and the dearth of targeted datasets. In response to these challenges, we construct three datasets: small web shells, benign files, and stealth web shells, subsequently proposing an innovative triplet network detection model for the stealth web shell. This model excels in differentiating stealth web shells from benign files while simultaneously aligning them more closely with small web shells, thereby refining classification precision. Our methodology transforms samples into opcode sequences through a series of processing steps, and then integrates them into the specially designed triplet network. Benchmarked against a cutting-edge deep learning network model and recognized detection tools, our detection methodology yields superior performance, delivering a high accuracy of 92.56% and a robust F1-score of 89.17%. These results substantiate the potency of our approach in countering the mounting threat posed by stealth web shells.
Jinli Zhang, Yaqin Cao, Ru Tan, Xiang Cui, Qixu Liu
MSN4
2016 A region-adaptive semi-fragile dual watermarking scheme
Mingchu Li, Cheng Guo 0001, Ru Tan
Multim. Tools Appl.4