Van Tong

dblp:192/3657 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
13since 2021 · last 2025
0000-0003-2050-994XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 5 first-author · 9 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 POSTER: Multimodal Graph Networks for Systematic Generalization in Code Clone Detection
Cuong Dao, Van Tong, Hai Anh Tran
AsiaCCS2
2025 Zero Trust: Deep Learning and NLP for HTTP Anomaly Detection in IDS
abstract
Web applications have become integral to daily life due to the migration of applications and data to cloud-based platforms, increasing their vulnerability to attacks. This paper addresses the need for robust intrusion detection systems by proposing a system grounded in Zero Trust architecture, which mandates continuous monitoring and multi-layered defenses. The Zero Trust principles ensure ongoing threat assessment and comprehensive protection against various attack vectors. Building on these foundational Zero Trust principles, our study introduces a system designed to not only distinguish normal HTTP requests from well-known attack patterns but also detect emerging types of anomalous attacks. Our system consists of two models that integrate Natural Language Processing approaches, Deep Learning techniques, and Transfer Learning strategies. The first model is employed to detect new anomalous HTTP requests that differ from normal requests. HTTP requests identified as anomalous are transmitted to the second model in charge of classifying specific categories of both well-known and novel attacks. Experiments show that our end-to-end system achieves the average F1-score of 89% on the combination of the CAPEC dataset and the zero-shot CSIC dataset. The proposed system proves also to be able to identify anomalous requests with a minimal latency of 4.8 milliseconds in production settings.
Manh-Tien-Anh Nguyen, Van Tong, Sondes Bannour Souihi, Sami Souihi
IEEE J. Sel. Areas Commun.2
2025 Encrypted Traffic Classification Through Deep Domain Adaptation Network With Smooth Characteristic Function
abstract
Encrypted network traffic classification has become a critical task with the widespread adoption of protocols such as HTTPS and QUIC. Deep learning-based methods have proven to be effective in identifying traffic patterns, even within encrypted data streams. However, these methods face significant challenges when confronted with new applications that were not part of the original training set. To address this issue, knowledge transfer from existing models is often employed to accommodate novel applications. As the complexity of network traffic increases, particularly at higher protocol layers, the transferability of learned features diminishes due to domain discrepancies. Recent studies have explored Deep Adaptation Networks (DAN) as a solution, which extends deep convolutional neural networks to better adapt to target domains by mitigating these discrepancies. Despite its potential, the computational complexity of discrepancy metrics, such as Maximum Mean Discrepancy, limits DAN’s scalability, especially when applied to large datasets. In this paper, we propose a novel DAN architecture that incorporates Smooth Characteristic Functions (SCFs), specifically SCF-unNorm (Unnormalized SCF) and SCF-pInverse (Pseudo-inverse SCF). These functions are designed to enhance feature transferability in task-specific layers, effectively addressing the limitations posed by domain discrepancies and computational complexity. The proposed mechanism provides a means to efficiently handle situations with limited labeled data or entirely unlabeled data for new applications. The aim is to limit the target error by incorporating a domain discrepancy between the source and target distributions along with the source error. Two statistics classes, SCF-unNorm and SCF-pInverse, are used to minimize this domain discrepancy in traffic classification. The experimental results demonstrate that our proposed mechanism outperforms existing benchmarks in terms of accuracy, enabling real-time traffic classification in network systems. Specifically, we achieve up to 99% accuracy with an execution time of only three milliseconds in the considered scenarios.
Van Tong, Cuong Dao, Hai Anh Tran, Huynh Thi Thanh Binh, Nam-Thang Hoang, Truong X. Tran
IEEE Trans. Netw. Serv. Manag.1
2024 POSTER: Multi-Block Fusion Mechanism for Multi-label Vulnerability Detection in Smart Contracts
abstract
Ethereum smart contracts offer innovative ways to automate transactions and execute agreements within blockchain systems. However, its inherent complexity can lead to exploitable vulnerabilities. With the advent of large language models, many studies put a special focus on identifying vulnerabilities using these models. Nonetheless, language models are ineffective with the lengthy input sequences. To overcome this limitation, this work proposes a novel multi-label vulnerability detection mechanism using pre-trained language model CodeT5+ combined with a unique multi-block fusion. The results demonstrate that the proposed mechanism can achieve up to 0.998 F1-score and require only 0.39 ms of processing time on a collected dataset comprising 421,266 contracts from Ethereum.
Van Tong, Cuong Dao, Thep Dong, Hai Anh Tran, Truong X. Tran
AsiaCCS1
2024 Troubleshooting solution for traffic congestion control
Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk
J. Netw. Comput. Appl.1
2024 Boosted regression for predicting CPU utilization in the cloud with periodicity
Khanh Nguyen Quoc, Van Tong, Cuong Dao, Ngoc Tuyen Le
J. Supercomput.2
2023 Deep Learning in NLP for Anomalous HTTP Requests Detection
abstract
Techniques for Deep Learning (DL) and Natural Language Processing (NLP) are rapidly advancing. In addition, we notice that the access and utilisation of web applications is expanding in almost all fields in conjunction with related technologies. Web applications include a wide range of use cases involving personal, financial, military, and political data. This renders web-based applications a desirable target for cyber-attacks. To address this problem, we propose, in this study, a novel model capable of differentiating normal HTTP requests from different types of anomalous HTTP requests. Our model combines NLP techniques, the Bidirectional Encoder Representations from Transformers (BERT) model, and DL techniques. The pre-trained BERT model is able to operate on unprocessed data and therefore does not require manually extracted features. Our experimental results show that the proposed method achieves an F1 score of more than 98.90% in the classification of multiple categories of anomalous requests and normal requests on CAPEC dataset. Furthermore, we leverage Transfer Learning in order to detect new types of anomalous requests or new attack patterns that are similar to training anomalous patterns. With Transfer Learning techniques, our proposed model achieves an F1-score of 61.50% on unseen types of anomalous HTTP requests.
Manh-Tien-Anh Nguyen, Van Tong, Sondes Bannour Souihi, Sami Souihi
CNSM2
2023 An Adaptive Sharding-based Blockchain for Network Slicing in 5G
abstract
Fifth-generation wireless technology, or 5G, promises increased data speeds, lower latency and greater capacity for mobile communications, enabling the growth of the Internet of Things (IoT). Network slicing is an advantageous feature of 5G that enables the creation of multiple virtual networks to meet the performance, security, and reliability needs of different services. This feature, combined with blockchain technology, provides secure and transparent data sharing between devices and networks. In addition, blockchain-enabled network slicing improves 5G network management and creates new business models for industries such as healthcare, transportation, and manufacturing. However, most current blockchain systems are limited in their ability to handle high throughput, which is not equivalent to what 5G can do. Therefore, sharding-based blockchain is proposed as a possible solution to improve the scalability and throughput of blockchain networks. By dividing the network into parts or shards, transactions can be processed simultaneously, allowing for faster transaction verification times and increased network capacity. Although current sharding-based blockchain networks have some limitations, such as static sharding policies that cannot cope with the dynamic blockchain environment, an adaptive sharding blockchain system using Deep Reinforcement Learning (DRL) methods has been proposed to address this situation. The approach allows the system to change or adapt the shard specifications, such as shard size or block size, whenever necessary to ensure maximum throughput while maintaining the security and integrity of the blockchain network.
Quang Huy Do, Sami Souihi, Van Tong, Hai Anh Tran, Sara Tucci Piergiovanni
GLOBECOM3
2023 Server and Route Selection Optimization for Knowledge-Defined Distributed Network Based on Gambling Theory and LSTM Neural Networks
abstract
Server and route selection (SARS) optimization is a critical aspect of traffic engineering to allocate network resources to meet diverse service requirements effectively. Existing studies have primarily focused on finding profitable or optimal solutions for the SARS problem within current time steps, considering specific constraints. However, they often have failed to address the dynamic and uncertainty of future network states. To address this gap, this paper proposes an algorithm named GAL to optimize server costs and response time while accounting for future network dynamics. GAL combines a server selection inspired by the gambling theory and a network routing based on Long Short-Term Memory Networks (LSTM). The server selection method is formulated as a gambling problem and solved using the decision-making Tug-of-War (TOW) dynamic algorithm. The routing mechanism is optimized based on predictions of future network states made by LSTM neural networks, which excel in capturing long-term dependencies. We have implemented GAL through a distributed software-defined networking (SDN) system and obtained good evaluation results regarding average response time and server cost compared to benchmark methods. These results demonstrate that GAL can effectively tackle the SARS optimization problem by considering present constraints and future network dynamics. This study can advance traffic engineering and lays a foundation for more robust resource allocation strategies in dynamic network environments.
Son Duong, Nam-Thang Hoang, Van Tong, Hai Anh Tran, Abdelhamid Mellouk, Truong X. Tran
GLOBECOM4
2023 Multi Service-Oriented Routing Mechanism for Heterogeneous Multi-Domain Software-Defined Networking
abstract
Software-defined networking (SDN) is a novel net-working paradigm for network management and autonomous systems. However, SDN has some challenges with scalability and quality of services (QoS) in distributed multi-domain scenarios due to the unprecedented growth of heterogeneous characteristics services. There is a current gap in a standard routing mechanism for satisfying various service requirements in distributed SDN. Most existing works design a homogeneous routing strategy for heterogeneous services, which might need to be more scalable and efficient for the future of rising heterogeneous online services. This study proposes a multi service-oriented routing mechanism for multi-domain SDN, which aims to help Internet service providers (ISPs) achieve high QoS and service-level agreements (SLAs). The mechanism utilizes a service classification (through a deep learning model) and optimizes network routing (using a new cost function containing both QoS and the server load). The mechanism has been integrated into the Knowledge-defined heterogeneous network architecture and tested on four prevalent considered services: E-commerce, Interactive Data, Video On-demand, and Bulk Data Transfer. The experimental results indicate that the proposed service-oriented routing mechanism outperforms the benchmark in terms of faster server response time while reducing up to 25% of the network congestion.
Hoang Ngo, Trung Pham, Nam-Thang Hoang, Van Tong, Hai Anh Tran, Abdelhamid Mellouk, Truong X. Tran
GLOBECOM5
2023 Fully-Decentralized Federated Learning for QoE Estimation
abstract
In the past, Quality of Service (QoS) was taken into account to evaluate the performance of multimedia services (e.g., video streaming, file transfer, etc.). However, it cannot reflect the user's perception, which is considered a crucial consideration by these services nowadays. Therefore, the emergence of Quality of Experience (QoE) is a potential solution. QoE can be measured via many parameters provided by Internet Service Providers (ISP), Application Service Providers (ASP), or end-users. However, privacy concerns hinder data sharing between the parties involved. To address these limitations, this paper proposes a QoE estimation mechanism that leverages Federated Learning. This mechanism aims to guarantee data privacy when no party needs to disclose their data to others. Moreover, the proposed mechanism incorporates the concept of a Decentralized Autonomous Organization (DAO) to mitigate the risk of a single point of failure in the centralized architecture of Federated Learning. It enables all participants to evaluate and select the model efficiently. The experimental results illustrate that the proposal surpasses the centralized solutions and guarantees data privacy.
Van Tong, Sami Souihi, Abdelhamid Mellouk
GLOBECOM2
2023 Enhancing Encrypted Traffic Classification with Deep Adaptation Networks
abstract
Network traffic management is crucial in Computer Networks and the Internet of Things. Indeed, classifying network traffic is the foundation for enhancing the quality of management mechanisms. However, traditional traffic classification methods, such as port-based, deep packet inspection, and statistic-based, are limited in identifying new encrypted traffic characteristics. Deep Learning-based classification approaches that consider packet-based features have been explored to address this challenge. Along with other deep learning methods, Transfer Learning, where a new model can inherit knowledge previously learned by a base model, is commonly used to increase classification performance in low data resources. Unfortunately, feature transferability may decline in transfer learning. This paper proposes an encrypted traffic classification mechanism that leverages the Deep Adaptation Network architecture with Mean Embedding Test to overcome this limitation. Our experimental results show that the proposed mechanism surpasses existing benchmarks’ accuracy and can classify encrypted traffic in real-time.
Cuong Dao, Van Tong, Nam-Thang Hoang, Hai Anh Tran, Truong X. Tran
LCN2
2021 Machine Learning based Root Cause Analysis for SDN Network
abstract
Nowadays, the rapid growth of the Internet makes network management more complex due to various and com-plicated network problems. In the past, network administrators implemented troubleshooting approaches (e.g., ping, traceroute, etc.) manually to identify the root cause of problems. However, it is not effective due to human intervention and an increase of network devices. Consequently, the root cause analysis is considered by the research community. There are existing studies for the root cause analysis without human intervention (e.g., statistical approaches, heuristic algorithms, etc.). However, these approaches show limited performance (e.g., due to complex threshold identifcation, etc.). The emerging of machine learning (ML) and deep learning is a potential solution to overcome this obstacle, offering an opportunity to develop an effective root cause analysis approach. Therefore, in this paper, we propose a root cause analysis approach using ML and time-series network parameters to identify the root cause of problems in the network. In this approach, we consider balancing the accuracy and the time complexity of ML algorithms to select an appropriate ML technique. Moreover, we contribute troubleshooting datasets to identify three kinds of root causes including link failure, switch failure and buffer overload. The experimental results show that the proposal can achieve approximately 97 percent of precision, recall and f1-score in considered scenarios and require less processing time (only require 0.00143 ms for a sample) in comparison with other ML algorithms.
Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk
GLOBECOM1
2020 Service-centric Segment Routing Mechanism using Reinforcement Learning for Encrypted Traffic
abstract
For the past decade, IP (Internet Protocol) routing approaches utilize TCAM (Ternary Content Addressable Memory) for the rule matching in the switches. These approaches are expensive and require more power consumption. Fortunately, the emerging of segment routing can resolve this drawback by encoding a routing path into the packet header to forward the packets to a destination. However, the standard segment routing algorithm has encountered a main problem. Using the shortest path to forward the packets can lead to a high traffic load on these paths and a performance reduction. It results in a decrease in user's perception and some negative economic impacts for ISPs (Internet Service Providers). Therefore, in this paper, we propose a novel service-centric segment routing mechanism using reinforcement learning in the context of encrypted traffic. Our proposal aims to help ISPs to decrease the influence of the network problems and meet the strict user's requirement related to QoE (Quality of Experience). The obtained results under the considered conditions demonstrate that our approach out-performs the standard segment routing algorithm and requires reasonable computational cost.
Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk
CNSM1
2019 Quality Estimation Framework for Encrypted Traffic (Q2ET)
abstract
In the coming years, the development of the Internet of Things (IoT) will have relevance for transport, environment, health care, smart cities and also multimedia services (Multimedia Internet of Things (MIoT)). Nowadays, many ISP (Internet Service Provider) encrypt the data to make it secure during the transmission. However, it imposes some obstacles for the NSP (Network Service Provider) because of the lack of visibility for operators into network traffic. To resolve these issues, we proposed the Quality Estimation Framework for Encrypted Traffic (Q2ET) containing a classification module and a QoE assessment module. The first module inherited from our previous research works to classify the encrypted network traffic using CNN (Convolutional Neural Network). The second one applies the objective and subjective methods based on the statistical analysis and machine learning methods that combine application and network parameters to calculate user's QoE (Quality of Experience) in terms of MOS (Mean Opinion Score). The Q2ET allows the NSP to monitor the user's QoE to take the appropriate decisions when the QoE degradation happens in the network systems.
Lamine Amour, Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk
GLOBECOM2
2018 A Novel QUIC Traffic Classifier Based on Convolutional Neural Networks
abstract
Nowadays, network traffic classification plays an important role in many fields including network management, intrusion detection system, malware detection system, etc. Most of the previous research works concentrate on features extracted in the non-encrypted network traffic. However, these features are not compatible with all kind of traffic characterization. Google's QUIC protocol (Quick UDP Internet Connection protocol) is implemented in many services of Google. Nevertheless, the emergence of this protocol imposes many obstacles for traffic classification due to the reduction of visibility for operators into network traffic, so the port and payload- based traditional methods cannot be applied to identify the QUIC- based services. To address this issue, we proposed a novel technique for traffic classification based on the convolutional neural network which combines the feature extraction and classification phase into one system. The proposed method uses the flow and packet-based features to improve the performance. In comparison with current methods, the proposed method can detect some kind of QUIC-based services such as Google Hangout Chat, Google Hangout Voice Call, YouTube, File transfer and Google play music. Besides, the proposed method can achieve the microaveraging F1-score of 99.24 percent.
Van Tong, Hai Anh Tran, Sami Souihi, Abdelhamid Mellouk
GLOBECOM1
2018 Empirical study for Dynamic Adaptive Video Streaming Service based on Google Transport QUIC protocol
abstract
Quick UDP Internet Connections (QUIC) is a new transport protocol developed by Google in 2012. QUIC is considered as a combination of TCP, TLS and HTTP on the top of UDP with some advantages such as reducing connection establishment time, improving congestion control, multiplexing without heads of line blocking and connection migration. In video streaming, Dynamic Adaptive Streaming over HTTP (DASH) is tied with TCP in many years, but the video streaming using HTTP on TCP has some disadvantages in terms of head of line blocking, connection migration, etc. The emergence of QUIC resolves these drawbacks and provides some solutions to reduce the latency and improve the quality of network service with respect to QoE. Therefore, in this paper, we investigate and evaluate the performance of QUIC and traditional transport protocols in the context of video streaming using DASH services. Some QUIC parameters such as maximum congestion window, buffer size and number of emulated connections are considered to choose the appropriate parameters for video streaming. Besides, we compare the performance of QUIC with TCP in terms of some network parameters and some DASH parameters. The experimental results showed that the performance of QUIC with 2 emulated connections is not as good as TCP. When the number of emulated connections is set to 6, the number of changes in quality level and stalling events are lower than the figure for TCP. Consequently, the quality level of QUIC with 6 emulated connections is better than TCP. Moreover, the QoE score of QUIC with 6 emulated connections is higher than the figure for QUIC with 2 emulated connections and TCP.
Van Tong, Hai Anh Tran, Sami Souihi, Abdelhamid Mellouk
LCN1
2018 Mining Frequent Patterns for Scalable and Accurate Malware Detection System in Android
abstract
Nowadays, the high interest of Android applications makes them the target of a huge number of malware. To detect this severe increase of Android malware and help end-users make a better evaluation of apps at install time, several approaches have been proposed such as statistic and dynamic approaches. However, these approaches cannot detect with high accuracy unfamiliar malware types. That inspired us to find a new approach for recognizing a malware basing on the anomalous set of permission it requests. To actualize that idea, we used the theory of frequent patterns, a data mining technique, for mining the frequent combination of requested permissions. We also compare the performance of the proposed system to other malware detection applications. Experimental results show that the proposed system yielded high accuracy with approximately 97 percent of normal applications and 86 percent of abnormal applications.
Thi-Tra-My Nguyen, Dong-Son Nguyen, Van Tong, Hai Anh Tran, Abdelhamid Mellouk
PIMRC3
2018 A LSTM based framework for handling multiclass imbalance in DGA botnet detection
Hieu Mac, Van Tong, Hai Anh Tran, Linh Giang Nguyen
Neurocomputing3