VLDB 2026 Research / reviewers in the wild / expert
Maochao Xu
dblp:22/8506
· DBLP profile ↗
7ranked-venue papers
1as first author
2since 2021 · last 2022
0000-0002-7529-1469ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Determination of ransomware payment based on Bayesian game models
Rui Fang 0001, Maochao Xu, Peng Zhao 0012 |
Comput. Secur. | 2 |
| 2021 | A Framework for Predicting Data Breach Risk: Leveraging Dependence to Cope With SparsityabstractData breach is a major cybersecurity problem that has caused huge financial losses and compromised many individuals' privacy (e.g., social security numbers). This calls for deeper understanding about the data breach risk. Despite the substantial amount of attention that has been directed toward the issue, many fundamental problems are yet to be investigated. In this article, we initiate the study of modeling and predicting risk in enterprise-level data breaches. This problem is challenging because of the sparsity of breaches experienced by individual enterprises over time, which immediately disqualifies standard statistical models because there are not enough data to train such models. As a first step towards tackling the problem, we propose an innovative statistical framework to leverage the dependence between multiple time series. In order to validate the framework, we apply it to a dataset of enterprise-level breach incidents. Experimental results show its effectiveness in modeling and predicting enterprise-level breach incidents. Zijian Fang, Maochao Xu, Shouhuai Xu, Taizhong Hu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | A deep learning framework for predicting cyber attacks ratesabstractLike how useful weather forecasting is, the capability of forecasting or predicting cyber threats can never be overestimated. Previous investigations show that cyber attack data exhibits interesting phenomena, such as long-range dependence and high nonlinearity, which impose a particular challenge on modeling and predicting cyber attack rates. Deviating from the statistical approach that is utilized in the literature, in this paper we develop a deep learning framework by utilizing the bi-directional recurrent neural networks with long short-term memory, dubbed BRNN-LSTM. Empirical study shows that BRNN-LSTM achieves a significantly higher prediction accuracy when compared with the statistical approach. Maochao Xu, Shouhuai Xu, Peng Zhao 0012 |
EURASIP J. Inf. Secur. | 2 |
| 2019 | Modeling Network Systems Under Simultaneous Cyber-AttacksabstractModeling cyber-attacks is a very attractive area of research because of its practical importance. However, most of the related research in the literature does not consider the simultaneous (or coordinated) attacks, which, in fact, is an important attack instrument in practice. This is mainly because of the complicated evolution of cyber-attacks over networks. In this paper, we propose a novel model, which can accommodate different types of simultaneous attacks with possible heterogeneous compromise probabilities. Our results show that simultaneous attacks have a significant effect on the reliability/dynamics of network systems. In particular, we present a sufficient condition for the epidemics dying out over the network, and upper bounds for the time to extinction. We also provide upper bounds for compromise probabilities of network systems when the evolution enters the quasi-equilibrium state. The effects of strength of simultaneous attacks and heterogeneity among successful attack probabilities on epidemic spreading are studied as well. The theoretical results are further validated by the simulation evidence. Gaofeng Da, Maochao Xu, Peng Zhao 0012 |
IEEE Trans. Reliab. | 2 |
| 2018 | Modeling and Predicting Cyber Hacking BreachesabstractAnalyzing cyber incident data sets is an important method for deepening our understanding of the evolution of the threat situation. This is a relatively new research topic, and many studies remain to be done. In this paper, we report a statistical analysis of a breach incident data set corresponding to 12 years (2005-2017) of cyber hacking activities that include malware attacks. We show that, in contrast to the findings reported in the literature, both hacking breach incident inter-arrival times and breach sizes should be modeled by stochastic processes, rather than by distributions because they exhibit autocorrelations. Then, we propose particular stochastic process models to, respectively, fit the inter-arrival times and the breach sizes. We also show that these models can predict the inter-arrival times and the breach sizes. In order to get deeper insights into the evolution of hacking breach incidents, we conduct both qualitative and quantitative trend analyses on the data set. We draw a set of cybersecurity insights, including that the threat of cyber hacks is indeed getting worse in terms of their frequency, but not in terms of the magnitude of their damage. Maochao Xu, Kristin M. Schweitzer, Raymond M. Bateman, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Predicting Cyber Attack Rates With Extreme ValuesabstractIt is important to understand to what extent, and in what perspectives, cyber attacks can be predicted. Despite its evident importance, this problem was not investigated until very recently, when we proposed using the innovative methodology of gray-box prediction. This methodology advocates the use of gray-box models, which accommodate the statistical properties/phenomena exhibited by the data. Specifically, we showed that gray-box models that accommodate the long-range dependence phenomenon can predict the attack rate (i.e., the number of attacks per unit time) 1-h ahead-of-time with an accuracy of 70.2%-82.1%. To the best of our knowledge, this is the first result showing the feasibility of prediction in this domain. We observe that the prediction errors are partly caused by the models' incapability in predicting the large attack rates, which are called extreme values in statistics. This motivates us to analyze the extreme-value phenomenon, using two complementary approaches: 1) the extreme value theory (EVT) and 2) the time series theory (TST). In this paper, we show that EVT can offer long-term predictions (e.g., 24-h ahead-of-time), while gray-box TST models can predict attack rates 1-h ahead-of-time with an accuracy of 86%-87.9%. We explore connections between the two approaches, and point out future research directions. Although our prediction study is based on specific cyber attack data, our methodology can be equally applied to analyze any cyber attack data of its kind. Zhenxin Zhan, Maochao Xu, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Characterizing Honeypot-Captured Cyber Attacks: Statistical Framework and Case StudyabstractRigorously characterizing the statistical properties of cyber attacks is an important problem. In this paper, we propose the first statistical framework for rigorously analyzing honeypot-captured cyber attack data. The framework is built on the novel concept of stochastic cyber attack process, a new kind of mathematical objects for describing cyber attacks. To demonstrate use of the framework, we apply it to analyze a low-interaction honeypot dataset, while noting that the framework can be equally applied to analyze high-interaction honeypot data that contains richer information about the attacks. The case study finds, for the first time, that long-range dependence (LRD) is exhibited by honeypot-captured cyber attacks. The case study confirms that by exploiting the statistical properties (LRD in this case), it is feasible to predict cyber attacks (at least in terms of attack rate) with good accuracy. This kind of prediction capability would provide sufficient early-warning time for defenders to adjust their defense configurations or resource allocations. The idea of “gray-box” (rather than “black-box”) prediction is central to the utility of the statistical framework, and represents a significant step towards ultimately understanding (the degree of) the predictability of cyber attacks. Zhenxin Zhan, Maochao Xu, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 2 |