Shang Yin

dblp:285/3398 · DBLP profile ↗
← Back
9ranked-venue papers
0as first author
8since 2021 · last 2023
0000-0002-5099-1370ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 since 2021Security and privacy · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2023 An optimized feature extraction algorithm for abnormal network traffic detection
Jinfu Chen 0001, Saihua Cai, Shang Yin, Lingling Zhao, Zikang Zhang
Future Gener. Comput. Syst.4
2023 A novel detection model for abnormal network traffic based on bidirectional temporal convolutional network
Jinfu Chen 0001, Tianxiang Lv, Saihua Cai, Luo Song, Shang Yin
Inf. Softw. Technol.5
2023 TLS-MHSA: An Efficient Detection Model for Encrypted Malicious Traffic based on Multi-Head Self-Attention Mechanism
abstract
In recent years, the use of TLS (Transport Layer Security) protocol to protect communication information has become increasingly popular as users are more aware of network security. However, hackers have also exploited the salient features of the TLS protocol to carry out covert malicious attacks, which threaten the security of network space. Currently, the commonly used traffic detection methods are not always reliable when applied to the problem of encrypted malicious traffic detection due to their limitations. The most significant problem is that these methods do not focus on the key features of encrypted traffic. To address this problem, this study proposes an efficient detection model for encrypted malicious traffic based on transport layer security protocol and a multi-head self-attention mechanism called TLS-MHSA. Firstly, we extract the features of TLS traffic during pre-processing and perform traffic statistics to filter redundant features. Then, we use a multi-head self-attention mechanism to focus on learning key features as well as generate the most important combined features to construct the detection model, thereby detecting the encrypted malicious traffic. Finally, we use a public dataset to verify the effectiveness and efficiency of the TLS-MHSA model, and the experimental results show that the proposed TLS-MHSA model has high precision, recall, F1-measure, AUC-ROC as well as higher stability than seven state-of-the-art detection models.
Jinfu Chen 0001, Luo Song, Saihua Cai, Haodi Xie, Shang Yin
ACM Trans. Priv. Secur.5
2022 A novel classification approach for Android malware based on feature fusion and natural language processing
abstract
The growing use of Android software has made mobile devices the main platform for information services such as mobile social media and financial services. Mobile software provides great convenience but also brings challenges to the software community. For example, mobile malware, a malicious software specifically designed to target mobile devices, creates security concerns for the business network and the data stored on it. Therefore, it is becoming more and more important to effectively identify and classify malware. Most of the current malware-classification methods rely on the specific (static/dynamic) behaviour information from Android software for improved malware-detection capability. Nevertheless, these methods cannot detect new types of fraud software due to the limited generalisability. To address these issues, this paper proposes the AMC-FN, i.e. an Android-based malware classification method using feature fusion and natural language processing technologies. The proposed AMC-FN aims to improve the dimension and performance of classification and also some specific functions of natural language processing, i.e. mutual information method, n-gram word segmentation and feature mapping. The AMC-FN framework improves the classification dimensions by leveraging the information from Android APK permission, API calls and realistic network traffic. Moreover, the framework also contains a novel multi-level feature fusion algorithm (MFFA) designed to improve the weighted feature fusion. To obtain better fine granularity and generalisability, the fusion features are used by the optimized SVM (Support Vector Machine) classifier for training. Our experimental measurements and comparisons show the improved performance based on the proposed AMC-FN framework.
Jinfu Chen 0001, Zian Zhao, Xiao Chen 0003, Saihua Cai, Shang Yin, Luo Song
Internetware5
2021 L-KPCA: an efficient feature extraction method for network intrusion detection
abstract
Network intrusion detection identifies malicious activity in the network by analyzing the behavior of network traffic. As an important part of network intrusion detection, feature extraction plays a crucial role in improving the performance of intrusion detection. This research proposes a novel secondary feature extraction method called L-KPCA based on the Liner Discriminant Analysis (LDA) and Kernel Principal Component Analysis (KPCA), to provide efficient features for network intrusion detection. While maintaining the effectiveness of processing nonlinear data in network traffic, the use of LDA effectively compensates for the problem that KPCA only focuses on the analysis of features in terms of variance and ignores the performance of features in terms of mean. Extensive experimental results verify that the use of the proposed, L-KPCA can make the intrusion detection classification model perform better in terms of recognition accuracy and recall.
Jinfu Chen 0001, Shang Yin, Saihua Cai, Lingling Zhao, Shengran Wang
MSN2
2021 An Efficient Network Intrusion Detection Model Based on Temporal Convolutional Networks
abstract
Network intrusion detection plays an important role in the network security, but the increasingly complex network environment brings a serious challenge to intrusion detection. Although the existing efficient Convolutional Neural Network (CNN)-based network traffic intrusion detection models do not require manual design of the traffic features, but they do not make full use of the structured information of network traffic. In this paper, we propose a novel network intrusion detection model based on Temporal Convolutional Networks (TCN), it extracts the key features in the dataset through exploiting the characteristics of byte sequence in the network traffic packets. Compared with traditional recurrent neural networks (RNN), TCN shows a better performance in sequence modeling tasks and it can process the sequences in parallel for faster training. To solve the problem of poor detection accuracy caused by the “death” of some neurons on ReLU during the training stage, we use the ELU activation function in the TCN instead of ReLU. Finally, we compare our proposed TCN-based intrusion detection model with the state-of-the-art methods on the CTU public dataset, and the experimental results show that the use of TCN can obtain higher performance within less time consumption, in terms of higher average accuracy, higher average recall and higher average F1-measure.
Jinfu Chen 0001, Shang Yin, Saihua Cai, Chi Zhang 0046, Yemin Yin
QRS2
2021 An efficient anomaly detection method for uncertain data based on minimal rare patterns with the consideration of anti-monotonic constraints
Saihua Cai, Jinfu Chen 0001, Haibo Chen 0005, Chi Zhang 0046, Qian Li 0042, Rexford Nii Ayitey Sosu, Shang Yin
Inf. Sci.7
2021 An efficient outlier detection method for data streams based on closed frequent patterns by considering anti-monotonic constraints
Saihua Cai, Rubing Huang, Jinfu Chen 0001, Chi Zhang 0046, Bo Liu 0048, Shang Yin, Ye Geng
Inf. Sci.6
2020 An Automatic Vulnerability Scanner for Web Applications
abstract
With the progressive development of web applications and the urgent requirement of web security, vulnerability scanner has been particularly emphasized, which is regarded as a fundamental component for web security assurance. Various scanners are developed with the intention of that discovering the possible vulnerabilities in advance to avoid malicious attacks. However, most of them only focus on the vulnerability detection with single target, which fail in satisfying the efficiency demand of users. In this paper, an effective web vulnerability scanner that integrates the information collection with the vulnerability detection is proposed to verify whether the target web application is vulnerable or not. The experimental results show that, by guiding the detection process with the useful collected information, our tool achieves great web vulnerability detection capability with a large scanning scope.
Haibo Chen 0005, Junzuo Chen, Jinfu Chen 0001, Shang Yin, Yiming Wu 0012, Jiaping Xu
TrustCom4