Julian Jang

dblp:20/4659 · also Julian Jang-Jaccard · DBLP profile ↗
← Back
32ranked-venue papers
7as first author
7since 2021 · last 2023
0000-0002-1002-057XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 6 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 first-authorSystems, architecture and hardware · 1Computer networks · 1Databases, data management, data science and information retrieval · 1Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2023 Improving Multilayer-Perceptron(MLP)-based Network Anomaly Detection with Birch Clustering on CICIDS-2017 Dataset
abstract
The network intrusion threats are increasingly severe with the application of computer supported coorperative work. Machine learning algorithms have been widely used in intrusion detection systems, including Multi-layer Perceptron (MLP). In this study, we proposed a two-stage model that combines the Birch clustering algorithm and MLP classifier to improve the performance of network anomaly multi-classification. In our proposed method, we first apply Birch or K-means as an unsupervised clustering algorithm to the CICIDS-2017 dataset to pre-group the data. The generated pseudo-label is then added as an additional feature to the training of the MLP-based classifier. The experimental results show that using Birch and K-Means clustering for data pre-grouping can improve intrusion detection system performance. Our method can achieve 99.73% accuracy in multi-classification using Birch clustering, which is better than similar researches using a stand-alone MLP model.
Yuhua Yin, Julian Jang, Fariza Sabrina, Jin Kwak
CSCWD2
2023 Evolving malice scoring models for ransomware detection: An automated approach by utilising genetic programming and cooperative coevolution
abstract
Malice scoring is a technique that is present throughout the literature to quantify a software malignance through the assignment of a malice score. However, the majority of existing malice scoring models are synthesised using manually selected features and weights, where a domain specialist is needed. Hence, this paper aim at utilising Genetic Programming and cooperative coevolution to automatically evolve an ensemble of symbolic regression functions to assign a malice score to an instance of software data. Using a publicly available dataset, the effectiveness of the proposed method is assessed and compared to that of the state-of-the-art malice scoring method. The experimental results show that the proposed method has significantly outperformed the benchmark method and exhibits the best-performing model that produces an overall balanced accuracy of 95.80%, correctly classifying 94.21% and 97.39% of unseen malicious and benign instances, respectively. Furthermore, various aspects of the proposed method and experimental results have been analysed in-depth to provide insight into the evolutionary process and some of the automatically evolved models.
Taran Cyriac John, Muhammad Shabbir Abbasi, Harith Al-Sahaf, Ian Welch, Julian Jang
Comput. Secur.5
2022 PassImg: A Secure Password Generation and Management Scheme without Storing
abstract
Text password is an important authentication method for computer supported cooperative systems and is usually required to be memorable, strong, and non-reusable. Some password managers can help users manage site-specific passwords locally or on the cloud. However, existing solutions still have a single point of failure risk if the password management scheme is breached. To address the risks identified in current password managers, we proposed a password generation and management scheme called PassImg that can generate consistent passwords through hashing a master password with a user-specified salt image. In this scheme, a weak master password is also allowed while not affecting the security of the scheme. We’ve also proposed a solution for offline parameters synchronization, which would decrease online attack vectors. The user-recognizable image as a parameter can be configured on different devices and synchronized through a QR code. PassImg can ensure password usability and security through an offline managing process without storing any data on the server.
Yuhua Yin, Julian Jang, Nilufar Baghaei
CSCWD2
2022 A few-shot meta-learning based siamese neural network using entropy features for ransomware classification
Jinting Zhu, Julian Jang, Amardeep Singh, Ian Welch, Harith Al-Sahaf, Seyit Ahmet Çamtepe
Comput. Secur.2
2022 A Novel Hybrid Approach for Multi-Dimensional Data Anonymization for Apache Spark
abstract
Multi-dimensional data anonymization approaches (e.g., Mondrian) ensure more fine-grained data privacy by providing a different anonymization strategy applied for each attribute. Many variations of multi-dimensional anonymization have been implemented on different distributed processing platforms (e.g., MapReduce, Spark) to take advantage of their scalability and parallelism supports. According to our critical analysis on overheads, either existing iteration-based or recursion-based approaches do not provide effective mechanisms for creating the optimal number of and relative size of resilient distributed datasets (RDDs), thus heavily suffer from performance overheads. To solve this issue, we propose a novel hybrid approach for effectively implementing a multi-dimensional data anonymization strategy (e.g., Mondrian) that is scalable and provides high-performance. Our hybrid approach provides a mechanism to create far fewer RDDs and smaller size partitions attached to each RDD than existing approaches. This optimal RDD creation and operations approach is critical for many multi-dimensional data anonymization applications that create tremendous execution complexity. The new mechanism in our proposed hybrid approach can dramatically reduce the critical overheads involved in re-computation cost, shuffle operations, message exchange, and cache management.
Sibghat Ullah Bazai, Julian Jang, Hooman Alavizadeh
ACM Trans. Priv. Secur.2
2021 Evaluating the effectiveness of shuffle and redundancy MTD techniques in the cloud
Hooman Alavizadeh, Jin B. Hong, Dong Seong Kim 0001, Julian Jang
Comput. Secur.4
2021 Joint Spectral Clustering based on Optimal Graph and Feature Selection
Jinting Zhu, Julian Jang, Tong Liu 0016, Jukai Zhou
Neural Process. Lett.2
2020 Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
abstract
The cloud model allows many enterprises able to outsource computing resources at an affordable price without having to commit the expense upfront. Although the cloud providers are responsible for the security of the cloud, there are still many security concerns due to inherently complex model the cloud providers operate on (e.g.,multi-tenancy). In addition, the enterprises whose services have migrated into the cloud have a preference for their own cybersecurity situation awareness capability on top of the security mechanisms provided by the cloud providers. In this way, the enterprises can monitor the performance of the security offerings of the cloud and have a choice to decide and select potential response strategies more appropriate to the enterprise in the presence of the attack where the defense provided by the cloud doesn't work for them. However, some response strategies, such as Moving Target Defense (MTD) techniques shown to be effective to secure cloud, cannot be deployed by the enterprise themselves. In this paper, we propose a framework that enables better collaboration between enterprises and cloud providers. Our proposed framework, which offers more in-depth security analysis based on the set of most advanced security metrics, allows the security experts of the enterprise to obtain better situational awareness in the cloud. With better and more effective situation awareness of cloud security, our framework can support better decision-making and further allows to deploy more appropriate threat responses to protect the outsourced resources. We also propose a secure protocol which can facilitate more secure communication between the enterprises and cloud provider. Using our proposed secure protocol, which is based on authentication and key exchange mechanism, the enterprises can send a secure request to the cloud provider to perform a selected defensive strategy.
Hootan Alavizadeh, Hooman Alavizadeh, Julian Jang
TrustCom3
2020 Model-based evaluation of combinations of Shuffle and Diversity MTD techniques on the cloud
Hooman Alavizadeh, Dong Seong Kim 0001, Julian Jang
Future Gener. Comput. Syst.3
2019 The Inadequacy of Entropy-Based Ransomware Detection
Timothy R. McIntosh, Julian Jang, Paul A. Watters, Teo Susnjak
ICONIP (5)2
2019 SparkDA: RDD-Based High-Performance Data Anonymization Technique for Spark Platform
Sibghat Ullah Bazai, Julian Jang
NSS2
2018 Large Scale Behavioral Analysis of Ransomware Attacks
Timothy R. McIntosh, Julian Jang, Paul A. Watters
ICONIP (6)2
2018 Privacy Issues in Big Data Mining Infrastructure, Platforms, and Applications
Xuyun Zhang, Julian Jang, Lianyong Qi, Md. Zakirul Alam Bhuiyan, Chang Liu 0001
Secur. Commun. Networks2
2017 A Secure Server-Based Pseudorandom Number Generator Protocol for Mobile Devices
Hooman Alavizadeh, Hootan Alavizadeh, Kudakwashe Dube, Dong Seong Kim 0001, Julian Jang, Hans W. Guesgen
ISPEC5
2017 Effective Security Analysis for Combinations of MTD Techniques on Cloud Computing (Short Paper)
Hooman Alavizadeh, Dong Seong Kim 0001, Jin B. Hong, Julian Jang
ISPEC4
2016 Towards privacy-preserving classification in neural networks
abstract
The requirement for data privacy is limiting to exploit the full potential of what modern data analytic capability could offer. To address such privacy concern, a number of techniques based on homomorphic encryption (HE) have been proposed to allow analytic computation, such as classification based on machine learning techniques, to run on encrypted data. However, these HE-based techniques suffer from a heavy computation overhead due to cryptographic computations having to be done on the encrypted data. We propose a non-colluding dual cloud system that utilizes Paillier cryptosystem. We illustrate how our proposal could reduce inherent computation overhead many similar techniques suffer. Such reduction could make our proposed system to be an ideal solution to use in the real world application.
Mehmood Baryalai, Julian Jang, Dongxi Liu
PST2
2014 A survey of emerging threats in cybersecurity
Julian Jang, Surya Nepal
J. Comput. Syst. Sci.1
2013 Security analysis of mobile applications: A case study of a collaboration tool in healthcare
abstract
Mobile-based collaboration tools are increasingly used for communication and information sharing in delivering healthcare services that need collaboration across different geographical locations. Some of the typical features found in the collaboration tools include video conferencing facility, image
Julian Jang, Jane Li, Surya Nepal, Leila Alem
CollaborateCom1
2013 Data architecture for telehealth services research: A case study of home tele-monitoring
abstract
Telehealth services research projects often require to access a variety of data sources under different data access policies and privacy constrains. There is a need to link these clinical and administrative records from different data custodians and produce a research data for analytics. One of the
Surya Nepal, Julian Jang, Branko G. Celler, Leila Alem
CollaborateCom2
2012 Portable key management service for cloud storage
abstract
Cloud storage services provide highly scalable, available and pay-as-you-go storage space for individual and enterprise users. Cloud storage services are inherently insecure as the management of the data in the cloud storage is controlled by third parties beyond the reach of the data owner. To addre
Julian Jang, Avnish Manraj, Surya Nepal
CollaborateCom1
2012 Hardware Security Device Facilitated Trusted Energy Services
John Zic, Martin de Groot, Dongxi Liu, Julian Jang, Chen Wang 0008
Mob. Networks Appl.4
2011 Biometric Enabled Portable Trusted Computing Platform
abstract
Existing proposals to address trusted end-to-end communication tend to focus on attestation between client applications and their enterprise servers. These proposals have given little or no consideration to the vulnerabilities between client applications and their users, resulting in identity thefts or impersonator. To address this problem, we propose a biometric enabled portable Trusted Computing Platform (portable TCP). The proposed platform coordinates two stage authentication and subsequent integrity check to provide trusted pathways amongst users, applications, and enterprise servers. We describe the proposed solution and its implementation.
Julian Jang, Hon Hwang, Surya Nepal
TrustCom1
2010 Hardware security device facilitated trusted residential energy services
abstract
We report on our experiences in developing a hardware based security solution for a demonstration prototype of a novel, smart-grid enabled energy services delivery model. This model is based on establishing and maintaining trusted, secure dynamic collaborations with agreed, policy driven usage and b
John Zic, Julian Jang, Dongxi Liu, Chen Wang 0008, Martin de Groot
CollaborateCom2
2010 A Cloud Architecture of Virtual Trusted Platform Modules
abstract
We propose and implement a cloud architecture of virtual TPMs. In this architecture, TPM instances can be obtained from the TPM cloud on demand. Hence, the TPM functionality is available for applications that do not have TPM chips in their local platforms. Moreover, users can access their keys and data in the same TPM instance even if they move to other platforms. The TPM functionality in cloud is easy to access for applications developed in different languages since cloud computing delivers services in standard protocols. The functionality of the TPM cloud is demonstrated by using it to implement the Needham-Schroeder public-key protocol for web authentication.
Dongxi Liu, Jack Lee, Julian Jang, Surya Nepal, John Zic
EUC3
2010 Trusted Computing Platform in Your Pocket
abstract
The mechanism of establishing trust in a computing platform is tightly coupled with the characteristics of a specific machine. This limits the portability and mobility of trust as demanded by many emerging applications that go beyond the organizational boundaries. In order to address this problem, we propose a trusted computing platform in a form of a USB device. First, we describe the design and implementation of the hardware and software architectures of the device. We then demonstrate the capabilities of the proposed device by developing a trusted application.
Surya Nepal, John Zic, Dongxi Liu, Julian Jang
EUC4
2007 Isolation Support for Service-based Applications: A Position Paper
Paul Greenfield, Alan D. Fekete, Julian Jang, Dean Kuo, Surya Nepal
CIDR3
2007 Delivering Promises for Web Services Applications
abstract
Among the problems facing designers of complex multi-participant Web services-based applications is dealing with the consequences of the lack of suitable isolation mechanisms. This deficiency means that concurrent applications can interfere with each other, resulting in race conditions and lost updates. This paper considers a proposed solution to this problem based on 'promises' and shows that this model can be implemented in practice. We consider implementation issues that need to be handled in promise-based systems and discuss a proof of concept prototype that supports promise-based isolation without requiring changes to existing applications and resources.
Julian Jang, Alan D. Fekete, Paul Greenfield
ICWS1
2007 Anitya: An Ephemeral Data Management Service and Secure Data Access Protocols for Dynamic Collaborations
abstract
Dynamic collaborations are the means by which a group of autonomous entities (possibly competing) collaborate to achieve a common objective by sharing resources that may be owned and managed both privately or jointly. Our focus in this paper is on controlling jointly owned shared data that is inherently ephemeral, as it does not exist outside the period of the collaboration. This paper explores the application of the ephemerizer concept as a means to control the access to shared collaboration data. Towards this, we first define a service-oriented architecture Anitya that enables the development of a third party service for managing ephemeral data in dynamic collaborations. We then extend the pair wise secure communication protocol used in the ephemerizer and propose three different multiparty secure group communication protocols for sharing collaboration data under the defined architecture. We also discuss the design, implementation, and evaluation of the architecture and protocols.
Surya Nepal, Julian Jang, John Zic
PDCAT2
2006 An Event-Driven Workflow Engine for Service-based Business Systems
abstract
This paper discusses a novel implementation of a workflow engine that supports service-based applications. The applications are defined according to the GAT model, which is an event-based programming model using conditional guards to determine when both normal and exception-handling activities are to be executed. We propose implementation techniques for key features of GAT. These include implementing control flow based on the evaluation of guards, the management and distribution of events, and enforcing atomicity across the evaluation of guards and the execution of the corresponding activities. We have built an engine following this approach which uses available technologies to support translating GAT models into executable applications
Julian Jang, Alan D. Fekete, Paul Greenfield, Surya Nepal
EDOC1
2003 Just What Could Possibly Go Wrong In B2B Integration?
abstract
One important trend in enterprise-scale IT has been the increasing use of business-business integration (B2Bi) technologies to automate business processes that cross organizational boundaries, such as the interactions between partner companies along a supply chain. It is relatively easy to describe a pattern of interaction, or choreography, in the case where everything proceeds smoothly. However, the abnormal cases, such as where a process fails or a message is lost, are much more complicated, and risk introducing data and process inconsistencies into computer-based systems. Current B2Bi technologies do not supply an infrastructure that can provide reliability without considerable sophistication from the architects and developers. As a first step towards guiding architects to the design of B2Bi systems that maintain consistency despite failures, this paper describes a variety of types of failure that can arise in practice, based on a realistic e-procurement scenario. We describe these failures in terms of the different types of state that naturally occur within the distributed system. Understanding the types of failure that need to be handled, or prevented, is essential to an architect or developer who must design and write handlers for all the exceptions that can occur in their workflows.
Dean Kuo, Alan D. Fekete, Paul Greenfield, Julian Jang, Doug Palmer
COMPSAC4
2003 Compensation is Not Enough
abstract
An important problem in designing infrastructure to support business-to-business integration (B2Bi) is how to cancel a long-running interaction (either because the user has changed their mind, or in response to an unrecoverable failure). We review the fault-handling and compensation mechanism that is now used in most workflow products and business process modeling standards. We then use an e-procurement case-study to extract a set of requirements for an effective cancellation mechanism, and we show that the standard approach using fault-handling, and compensation transactions is not adequate to meet these requirements.
Paul Greenfield, Alan D. Fekete, Julian Jang, Dean Kuo
EDOC3
2003 Expressiveness of Workflow Description Languages
Julian Jang, Alan D. Fekete, Paul Greenfield, Dean Kuo
ICWS1