VLDB 2026 Research / reviewers in the wild / expert
Yi Shen 0012
dblp:18/1762-12
· DBLP profile ↗
22ranked-venue papers
2as first author
21since 2021 · last 2026
0000-0002-2923-7963ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 1 first-author · 9 since 2021Security and privacy · 7 · 1 first-author · 7 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Darkness at dawn: understanding illicit websites in newly registered domain namesabstractAbstract Illicit website represents a significant challenge on the Internet. Miscreants exploit the inherent flexibility and invisibility of the Internet to promote illicit activities, particularly online gambling and pornography, intending to generate substantial profits. Previous studies have primarily focused on illicit website detection techniques and analyzed illicit activities using passive datasets. However, constrained by the limitations of passive dataset perspectives, the security community lacks a global understanding of illicit website deployment and operational behavior patterns, particularly during the early stages of website activation. In this paper, we conduct an in-depth analysis of the activities of illicit websites through the advantageous lens of newly registered domains (NRDs). The NRD dataset’s key strength is its broad coverage of emerging illicit activities during observation, complementing previous studies. Specifically, we designed and implemented a framework, NRDMiner, for tracking and analyzing illicit activities associated with large-scale NRDs. This framework supports long-term monitoring of vast quantities of domains and enables accurate identification of illicit websites. Over a 133-day period (July 1–Nov 10, 2024), we collected 27,623,326 NRDs across 481 top-level domains (e.g., and ), and identified 910,794 abusive domains. Our analysis highlights several important patterns. First, illicit activity shows a consistent and steady pattern, with an average of 3.3% of NRDs flagged for illicit website. Moreover, 98% of these domains are first-time registrations. Second, 60% of abusive domains are activated on the same day they are registered, indicating mature automated domain abuse techniques. Third, from a global NRD perspective, we observed regional tendencies in illicit activities, like Asia identified as the primary concentration area, with over 70% of illicit website pages being in Asian languages. Furthermore, we analyzed the deployment and operation of illicit websites. Our work provides a large-scale empirical study of the early-stage activities of illicit websites from the perspective of NRDs, offering valuable evidence that contribute to the timely mitigation of illicit activities. Bingyang Guo, Fan Shi 0003, Min Zhang 0054, Chengxi Xu, Yi Shen 0012 |
Cybersecur. | 7 |
| 2026 | PGMaP: Password generation based on mask predictionabstractNumerous studies have focused on data-driven password guessing methods in recent years, aiming to reduce the use of weak passwords by users and improve password security. Existing password generation models learn the distribution of password datasets and generate candidate guesses by fitting sequential conditional probabilities. These methods are based on a key assumption: users construct passwords in one direction from left to right. However, with the more complex password policy requirements of authentication systems and the increasing security awareness of people, users construct passwords by modifying existing or popular passwords. At this point, users consider global and bi-directional information of passwords. This breaks the key assumption of uni-directional construction and leads to omissions when generating passwords by existing methods. Motivated by this, we propose a password generation method based on mask prediction, named PGMaP, which captures this large number of omitted passwords. First, we design a password construction template extraction algorithm to cluster the templates used by users for constructing and modifying passwords. Then we construct a transformer-based masked language model to learn password bi-directional features. The extracted templates are fed into the model to generate password guesses by means of mask prediction. Different from existing auto-regressive model based methods that generate in one direction, PGMaP uses the auto-encoding model to generate passwords based on the bidirectional information. Finally, through password guessing experiments all eight real-world datasets, we demonstrate that PGMaP can effectively generate a large number of omitted passwords, and its password guessing performance outperforms existing methods. Fan Shi 0003, Shasha Guo 0001, Min Zhang 0054, Yi Shen 0012, Chengxi Xu |
Expert Syst. Appl. | 5 |
| 2026 | Software defect detection using large language models: a literature reviewabstractAbstract As software systems grow in complexity, the importance of efficient defect detection escalates, becoming vital to maintain software quality. In recent years, artificial intelligence technology has boomed. In particular, with the proposal of Large Language Models (LLMs), researchers have found the huge potential of LLMs to enhance the performance of software defect detection. This review aims to elucidate the relationship between LLMs and software defect detection. We categorize and summarize existing research based on the distinct applications of LLMs in dynamic and static detection scenarios. Dynamic detection methods are categorized based on the different phases in which they employ LLMs, such as using them for test case generation, providing feedback guidance, and conducting output assessment. Static detection methods are classified according to whether they analyze the source code or the binary of the software under test. Furthermore, we investigate the prompt engineering and model fine-tuning strategies adopted within these studies. Finally, we summarize the emerging trend of integrating LLMs into software defect detection, identify challenges to be addressed and prospect for some potential research directions. Yu Chen 0053, Yi Shen 0012, Taiyan Wang, Shiwen Ou, Yuwei Li 0002, Zulie Pan |
Frontiers Comput. Sci. | 2 |
| 2026 | Unreachable Features? Exposing the Security Risks of Invisible Interfaces in Embedded Web Services of IoT DevicesabstractIoT devices, now integral to our daily routines, offer unparalleled convenience but also face mounting security threats. Embedded web services, prevalent in public networks, pose a major risk to these devices. While research has focused on detecting vulnerabilities in IoT embedded web services, it has overlooked the presence of invisible interfaces, which have emerged as significant security threats. In this paper, we propose InvRadar, a novel framework for detecting vulnerabilities in invisible interfaces of embedded web services in IoT devices. Specifically, InvRadar identifies invisible interfaces by analyzing the differences between the front-end visible interface keywords and the back-end interface keywords through a correlation analysis method. Subsequently, InvRadar uses a static taint analysis method to detect the vulnerabilities that can be triggered by the invisible interfaces. To validate the performance of InvRadar, we conduct extensive experiments and compare InvRadar with the state-of-the-art methods. In testing 13 device firmware, InvRadar identifies 1,793 invisible interfaces and detects 124 vulnerabilities, including 53 newly discovered ones, with 34 receiving new CVE/CNVD IDs. Additionally, InvRadar outperforms the state-of-the-art methods in interface keyword extraction, border binary and data ingestion function identification. Yuanchao Chen, Yuwei Li 0002, Yi Shen 0012, Yu Chen 0053, Yang Li 0215, Taiyan Wang, Yuliang Lu, Zulie Pan, Shouling Ji |
IEEE Internet Things J. | 3 |
| 2026 | Password Guessing Based on Hidden Weak Password AnalysisabstractPassword has become the mainstream method of authentication today. To improve password security, researchers evaluate the strength of target password datasets through early brute-force attacks to current password guessing methods, aiming to help users reduce the use of weak passwords. With users becoming more aware of security, they make local variations on weak passwords to improve the password strength while being easy to remember. These transformations render passwords more complex and enhance the score in password strength meter. However, such variations do not genuinely enhance password security, as human habits tend to converge. This allows attackers to deduce the modification patterns and consequently crack these passwords. Motivated by this, this paper defines the hidden weak passwords, a local variant of explicit weak passwords, which appear to enhance password security yet remain vulnerable. We systematically analyze transformation behavior between explicit and hidden weak passwords. Then we design an automated rule generation algorithm to identify hidden weak passwords and generate transformation rules. Based on automatically mined rules, we generate a large number of password guesses and fuses them with existing methods to improve password guessing performance. Finally, we demonstrate the effectiveness of the proposed method through password guessing experiments on eight real-world datasets, where the cracking rate improves on all five state-of-the-art methods. Min Zhang 0054, Zhijie Xie, Shasha Guo 0001, Yuliang Lu, Fan Shi 0003, Yi Shen 0012 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | Toward Security-Enhanced In-Band Network Telemetry in Programmable NetworksabstractIn-band Network Telemetry (INT) is a widely used monitoring framework in modern large-scale networks. It provides packet-level visibility into network conditions by inserting telemetry data into packets, enabling unprecedented fine-grained network management. However, this mechanism also introduces new vulnerabilities that malicious attackers can exploit. In this paper, we present eight In-band Network Telemetry Manipulation Attacks that take advantage of INT’s weakness, demonstrating that attackers can cause severe damage with little effort by manipulating INT packets. To address this issue, we designed SecureINT, a security-enhanced INT prototype that provides encryption and integrity verification for INT packets. Specifically, SecureINT deploys Even-Mansour and SipHash for confidentiality and integrity, respectively. It also uses a zero-delay rotation mechanism, which enables administrators to dynamically change the version of the deployed Even-Mansour/SipHash running on programmable switches without the need to re-install new programs. In this way, SecureINT can provide lasting security for INT packets using the limited resources of programmable switches. According to the experiments, SecureINT can be deployed on programmable switches using a single pipeline. Besides, the overhead of the rotation mechanism running on the control plane is still minimal. Dezhang Kong, Xiang Chen 0017, Zhengyan Zhou, Yi Shen 0012, Hongyan Liu 0001, Qiumei Cheng, Xuan Liu 0006, Dong Zhang 0010, Chunming Wu 0001, Muhammad Khurram Khan |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Insvdf: Interface-State-Aware Virtual Device FuzzingabstractHypervisor is the core technology of virtualization for emulating independent hardware resources for each virtual machine. Virtual devices serve as the main interface of the hypervisor, making the security of virtual devices crucial, as any vulnerabilities can impact the entire virtualization environment and pose a threat to the host machine's security. Direct Memory Access (DMA) is the interface of virtual devices, enabling communication with the host machine. Recently, many efforts have focused on fuzzing against DMA to discover the hypervisor's vulnerabilities. However, the lack of sensitivity to the DMA state causes these efforts to be hindered in efficiency during fuzzing. Specifically, there are two main issues: the uncertain interaction moment and the unclear interaction depth. In this paper, we introduce InSVDF, a DMA interface stateaware fuzzing engine. InSVDF first models the intra-interface state of the DMA interface and incorporates an asynchronyaware state snapshot mechanism along with a depth-aware seed preservation mechanism. To validate our approach, we compare InSVDF with a state-of-the-art fuzzer. The results demonstrate that InSVDF significantly enhances vulnerability discovery speed, with improvements of up to 24.2 x in the best case. Furthermore, InSVDF has identified 2 new vulnerabilities, one of which has been assigned a CVE ID. Zexiang Zhang, Yiming Tao, Zulie Pan, Cheng Tu, Min Zhang 0054, Yang Li 0215, Yi Shen 0012, Chunming Wu 0001 |
ICSE | 9 |
| 2025 | Understanding the Security Risks of Websites Using Cloud Storage for Direct User File UploadsabstractWith the rising demand for website data storage, leveraging cloud storage services for vast user file storage has become prevalent. Nowadays, a new file upload scenario has been introduced, allowing web users to upload files directly to the cloud storage service. This new scenario offers convenience but involves more roles (i.e., web users, web servers, and cloud storage services) and their interactions, bringing new security threats. In this paper, we perform the first systematic security study in this scenario. With in-depth analysis, we identify six new types of vulnerabilities and conduct large-scale real-world measurements on the top 500 Alexa Rank websites. Among these websites, 182 (36.4%) use cloud storage services, illustrating the widespread use of the cloud. Then, we perform a detailed analysis of 28 popular websites that allow user upload. Surprisingly, they all have at least one of the six vulnerabilities. Totally, we discover 79 new vulnerabilities and responsibly report them to the websites. Many popular websites respond positively, including Google, Reddit, and CSDN. We discuss the root causes of these vulnerabilities and propose possible mitigation methods. In summary, our work offers significant value in understanding the security risks of cloud storage services for websites and facilitating future research. Yuanchao Chen, Yuwei Li 0002, Yuliang Lu, Zulie Pan, Shouling Ji, Yu Chen 0053, Yang Li 0103, Yi Shen 0012 |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2024 | rDefender: A Lightweight and Robust Defense Against Flow Table Overflow Attacks in SDNabstractThe flow table is a critical component of Software-Defined Networking (SDN). However, flow tables’ limited capacity makes them highly vulnerable to flow table overflow attacks (FTOAs). Due to the low attack cost and highly flexible attack forms, it is hard to eradicate FTOAs. This paper addresses three unsolved problems for table security and proposes a robust defense accordingly. First, we reveal that the existing defenses with fixed defense speeds will cause severe packet loss when handling diverse traffic. We prove that deleting multiple rules can efficiently solve this problem and give a rigorous derivation to calculate the suitable deletion number according to the environment. Second, we illustrate that abnormal table occupancy squeezing is a constant characteristic of FTOAs regardless of attack forms. It can be used to identify attacked ports accurately in different scenarios. Third, we mathematically prove that random deletion can guarantee the continuous decrease of malicious flow rules after confirming attacked ports. It achieves fast speed and robust effectiveness in different environments. Based on these findings, we design rDefender, a robust and lightweight defense prototype. We evaluate its effect by designing diverse, powerful attacks and using real-world datasets and topology. The results demonstrate that it achieves the best overall performance compared to six existing mainstream defenses, providing stable security for switch flow tables. Dezhang Kong, Xiang Chen 0017, Chunming Wu 0001, Yi Shen 0012, Zhengyan Zhou, Qiumei Cheng, Xuan Liu 0006, Yubing Qiu, Dong Zhang 0010, Muhammad Khurram Khan |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | DynPen: Automated Penetration Testing in Dynamic Network Scenarios Using Deep Reinforcement LearningabstractPenetration testing, a crucial industrial practice for securing networked systems and infrastructures, has traditionally depended on the extensive expertise of human professionals. Addressing the scarcity of human experts, the development of automated penetration testing tools emerges as a promising avenue. Against the backdrop of rapid advancements in artificial intelligence technologies, reinforcement learning has demonstrated considerable potential for realizing automated penetration testing. However, existing research predominantly concentrates on reinforcement learning-based automated penetration testing tools within static scenarios, with limited exploration in dynamic network environments. This paper addresses a noteworthy challenge in developing autonomous agents for real-world applications, particularly focusing on scenarios marked by environmental changes. Such alterations necessitate autonomous agents to continuously monitor environmental characteristics, and adapt, and adjust learned actions to ensure the system’s effective operation. Consequently, the paper proposes an automated reinforcement learning-based penetration testing scheme tailored for dynamic network scenarios, named DynPen. DynPen captures observed changes in the scenario, aiding the penetration testing agent in decision-making based on historical experiences. Simulation results demonstrate the proposed scheme’s efficacy in significantly expediting the convergence speed of the penetration testing agent using reinforcement learning algorithms. Furthermore, the scheme successfully maintains the learning agility and adaptability of the agent in dynamic network scenarios. Qianyu Li 0001, Dong Li 0054, Fan Shi 0003, Min Zhang 0054, Anupam Chattopadhyay, Yi Shen 0012, Yang Li 0215 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | An Intelligent Penetration Testing Method Using Human FeedbackabstractPenetration testing is widely acknowledged as the foremost method for evaluating network security. However, three challenges impede the generation of strategies that align with human expectations. In this article, we present, for the first time, a method based on human feedback to enhance strategy generation. Our approach comprises two components: agent training and decision-making. During agent training, we establish a hierarchical framework to decompose tasks and a knowledge base to offer advice for improving data efficiency. We then impose constraints on the action space to mitigate ineffective exploration. Finally, we train a reward model based on human feedback and fine tune the model guided by this reward model. In decision-making, we process the model output to enhance decision accuracy. We crafted scenarios based on real-world networks, and the results demonstrate the effectiveness of our method in generating penetration testing strategies that align more closely with human intentions. Qianyu Li 0001, Min Zhang 0054, Fan Shi 0003, Yi Shen 0012, Bingyang Guo, Chengxi Xu |
IEEE Trans. Ind. Informatics | 5 |
| 2023 | IoT Malicious Traffic Detection Based on Federated Learning
Yi Shen 0012, Yuwei Li 0002, Wanmeng Ding, Cheng Huang 0003 |
ICDF2C (1) | 1 |
| 2023 | In-band Network Telemetry Manipulation Attacks and Countermeasures in Programmable NetworksabstractIn-band Network Telemetry (INT) is a widely used monitoring framework in modern large-scale networks that provides fine-grained visibility into network conditions by inserting telemetry data into packets. However, this mechanism also introduces new vulnerabilities that malicious attackers can exploit. In this paper, we present four In-band Network Telemetry Manipulation Attacks that take advantage of INT's weakness, demonstrating that attackers can cause severe damage with little effort by manipulating INT packets. To address this issue, we design SecureINT, a novel INT prototype that ensures confidentiality and integrity for INT packets. To meet the stringent computational requirements of programmable switches, we comprehensively analyze possible attacks on the deployed encryption/hash algorithms and modify them accordingly without compromising their security. According to the experiments, SecureINT can be deployed on programmable switches using a single pipeline, providing encryption and integrity verification for INT packets with minimal overhead. Dezhang Kong, Zhengyan Zhou, Yi Shen 0012, Xiang Chen 0017, Qiumei Cheng, Dong Zhang 0010, Chunming Wu 0001 |
IWQoS | 3 |
| 2023 | Vulnerabilities and Attacks of Inter-device Coordination in Programmable NetworksabstractIn programmable networks, some networking systems coordinate data plane switches to realize in-network functions (e.g., in-band network telemetry). However, the vulnerabilities of inter-device coordination are still largely unknown and neglected, which is highly concerning given the increasing popularity of this paradigm. In this paper, we identify three attack scenarios built upon such vulnerabilities, where attackers mislead the behaviors of networking systems that exploit inter-device coordination to execute in-network functions. We implement 20 existing networking systems on Tofino-based switches and a simulator, and attack these systems with the identified attacks. The experimental results indicate that our attacks significantly interfere with the normal operations of the selected networking systems, e.g., the cache hit rate of NetCache drops 38%. Our analysis also demonstrates that none of existing methods can fully mitigate our attacks since they fail to verify the packets for inter-device coordination. Hongyan Liu 0001, Xiang Chen 0017, Yi Shen 0012, Qun Huang 0001, Zhengyan Zhou, Dong Zhang 0010, Chunming Wu 0001 |
IWQoS | 3 |
| 2023 | Optimizing Program Deployment with libopl in Programmable NetworksabstractDeploying data plane programs on programmable switches involves complex optimization problems that make the optimal deployment decisions. However, existing deployment frameworks only focus on deploying programs in specific domains (i.e., supporting fixed optimization requirements), resulting in poor scalability. To this end, our goal is to simplify program deployment through general high-level abstractions that capture optimization requirements. In this paper, we present libopl, a generic library that enables administrators to express various optimization requirements when deploying programs and further calculates the optimal deployment plans. Existing frameworks can also use libopl to extend their functionalities to fit more deployment scenarios. To evaluate libopl, we build a Tofino-based testbed and a simulator. Our experimental results show that libopl exhibits comparable or better scalability than stateof-the-art frameworks and only introduces negligible overhead. Hongyan Liu 0001, Xiang Chen 0017, Yi Shen 0012, Dong Zhang 0010, Chunming Wu 0001 |
SECON | 3 |
| 2023 | A hierarchical deep reinforcement learning model with expert prior knowledge for intelligent penetration testing
Qianyu Li 0001, Min Zhang 0054, Yi Shen 0012, Yang Li 0215 |
Comput. Secur. | 3 |
| 2023 | SecTKG: A Knowledge Graph for Open-Source Security ToolsabstractAs the complexity of cyberattacks continues to increase, multistage combination attacks have become the primary method of attack. Attackers plan and organize a series of attack steps, using various attack tools to achieve specific goals. Extracting knowledge about these tools is of great significance for both defense and tracing of attacks. We have noticed that there is a wealth of security tool‐related knowledge within the open‐source community, but research in this area is limited. It is challenging to achieve large‐scale automated security tool information extraction. To address this, we propose automated knowledge graph construction architecture, named SecTKG, for open‐source security tools. Our approach involves designing a security tool ontology model to describe tools, users, and relationships, which guides the extraction of security tool knowledge. In addition, we develop advanced entity recognition and classification methods, ensuring efficient and accurate knowledge extraction. As far as we know, this work is the first to construct the large‐scale security tool knowledge graph, containing 4 million entities and 10 million relationships. Furthermore, we investigate the tendencies and particularities of security tools based on the SecTKG and developed a security tool influence‐measuring application. The research fills a gap in the field of automated security tools’ knowledge extraction and provides a foundation for future research and practical applications. Cheng Huang 0003, Tiejun Wu, Yi Shen 0012 |
Int. J. Intell. Syst. | 4 |
| 2023 | Combination Attacks and Defenses on SDN Topology DiscoveryabstractThe topology discovery service in Software-Defined Networking (SDN) provides the controller with a global view of the substrate network topology, allowing for central management of the entire network. Unfortunately, emerging topology attacks can poison the network topology and result in unforeseeable disasters. Although researchers have made great efforts to mitigate this problem, security hazards still exist. In this paper, we propose Invisible Assailant Attack (IAA), the first combination topology attack capable of injecting and maintaining fake links even when 12 existing defense strategies are deployed simultaneously. IAA consists of 14 attack phases that apply multiple attack strategies. Attackers skillfully disguise the attack traffic in each phase so that it looks like normal network traffic, and perform these phases in a well-planned sequence, thereby bypassing existing defenses step by step. To mitigate this attack, we propose a Route Path Verification (RPV) mechanism that orchestrates multiple defense strategies to identify fake links. According to the experiments, RPV can successfully detect IAA with low overhead: its detection completes within 1 ms while its per-flow storage consumption is only a few KB. Dezhang Kong, Yi Shen 0012, Xiang Chen 0017, Qiumei Cheng, Hongyan Liu 0001, Dong Zhang 0010, Xuan Liu 0006, Shuangxi Chen, Chunming Wu 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2022 | TableGuard: A Novel Security Mechanism Against Flow Table Overflow Attacks in SDNabstractOne of the most important components of Software-Defined Networking (SDN) is the flow table. It receives flow rules from the controller and uses them to handle network traffic. However, a flow table can only store a few thousand flow rules, which makes it an attractive target for table overflow attacks. These attacks force the controller to populate the flow table with a large number of meaningless flow rules, which prevents normal flows from finding matching rules and therefore having to be reported to the controller. It results in a significant latency overhead, degrading the performance of the whole network. In this paper, we present a key characteristic of table overflow attacks: even though attackers can change some critical attack parameters (e.g., attack speed) to avoid detection, proactive flows from the attacked port always occupy a stable proportion in the flow table regardless of the attack form. In light of this finding, we propose TableGuard, a novel security mechanism that uses the proactive flow rule number as the detection metric and applies a statistical approach to help filter malicious flows. The experiments demonstrate that TableGuard can mitigate both high-rate and low-rate table overflow attacks. Compared with existing defenses, TableGuard has the best mitigation performance and the minimal overhead on normal flows. Dezhang Kong, Chunming Wu 0001, Yi Shen 0012, Xiang Chen 0017, Hongyan Liu 0001, Dong Zhang 0010 |
GLOBECOM | 3 |
| 2022 | DeepThrottle: Deep Reinforcement Learning for Router Throttling to Defend Against DDoS Attack in SDNabstractThe router throttling mechanism provides us a chance to prevent DDoS attack proactively through rate-limiting suspicious traffic before effective detection mechanism. The existing search-based and learning-based studies are highly customized to server load and can hardly cope with the constantly changing server load and unseen scenarios. To address the problem above, we design a self-evolutionary DDoS defense system, DeepThrottle, based on deep reinforcement learning (DRL) and router throttling mechanism in software defined network (SDN). The experimental results demonstrate that the DeepThrottle improves the passing ratio of normal traffic to the victim server, and reduces the server load under unseen attack scenarios compared with the state-of-the-art RL-based method. Shuhan Chen, Congqi Shen, Chunming Wu 0001, Yi Shen 0012 |
IPCCC | 4 |
| 2021 | Webshell Detection Based on Executable Data Characteristics of PHP CodeabstractA webshell is a malicious backdoor that allows remote access and control to a web server by executing arbitrary commands. The wide use of obfuscation and encryption technologies has greatly increased the difficulty of webshell detection. To this end, we propose a novel webshell detection model leveraging the grammatical features extracted from the PHP code. The key idea is to combine the executable data characteristics of the PHP code with static text features for webshell classification. To verify the proposed model, we construct a cleaned data set of webshell consisting of 2,917 samples from 17 webshell collection projects and conduct extensive experiments. We have designed three sets of controlled experiments, the results of which show that the accuracy of the three algorithms has reached more than 99.40%, the highest reached 99.66%, the recall rate has been increased by at least 1.8%, the most increased by 6.75%, and the F1 value has increased by 2.02% on average. It not only confirms the efficiency of the grammatical features in webshell detection but also shows that our system significantly outperforms several state‐of‐the‐art rivals in terms of detection accuracy and recall rate. Zulie Pan, Yuanchao Chen, Yu Chen 0053, Yi Shen 0012, Xuanzhen Guo |
Wirel. Commun. Mob. Comput. | 4 |
| 2020 | TPDD: A Two-Phase DDoS Detection System in Software-Defined NetworkingabstractDistributed Denial of Service (DDoS) attack is one of the most severe threats to the current network security. As a new network architecture, Software-Defined Networking (SDN) draws notable attention from both industry and academia. The characteristics of SDN such as centralized management and flow-based traffic monitoring make it an ideal platform to defend against DDoS attacks. When designing a network intrusion detection system (NIDS) in SDN, how to obtain fine-grained flow information with minimal overhead to the SDN architecture is a problem to be solved. In this paper, we propose TPDD, a two-phase DDoS detection system to detect DDoS attacks in SDN. In the first phase, we utilize the characteristics of SDN to collect coarse-grained flow information from the core switches and locate the potential victim. Then we monitor the edge switches located close to the potential victim to obtain finer-grained traffic information in the second phase. The collection method of each phase fully considers the impact on the bandwidth between the controller and switches. Without modifying the existing flow rules, the collection module can obtain sufficient information about traffic. By using entropy-based and machine learning-based methods, the detection module can effectively detect anomalies and identify whether the potential victim marked in the first phase is the target of attacks. Experimental results show that TPDD can effectively detect DDoS attacks with little overhead. Yi Shen 0012, Chunming Wu 0001, Dezhang Kong |
ICC | 1 |