VLDB 2026 Research / reviewers in the wild / expert
Zhishen Zhu
dblp:293/1193
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Tunnel User Behavior Identification Based on Self-Supervised Pre-TrainingabstractWith the widespread use of tunnel technology, the volume of encrypted tunnel traffic is rapidly increasing. Malicious users can transmit harmful information secretly through tunnels to bypass firewall censorship. Therefore, developing effective techniques to identify tunnel user behaviors is crucial. However, current efforts in tunnel traffic classification primarily focus on coarse-grained application identification and encounter the problem of insufficient extraction of tunnel traffic feature information. In this paper, we refine the previous tunnel traffic identification granularity from prevalent application identification to behavior identification, and propose TF-Net, a novel deep learning framework for fine-grained identification of tunnel user behaviors. TF-Net extracts features from raw bytes, packet length sequence, packet time interval sequence of tunnel traffic. It employs self-supervised pre-training to learn contextual distributions of raw bytes from unlabeled datasets, thereby enhancing the model’s ability to characterize packets in a tunnel flow. Moreover, we fine-tune the model based on the classification objectives of different tasks to achieve more versatile and accurate tunnel identification. Comprehensive experiments are conducted on three real-world encrypted tunnel traffic datasets, demonstrating that TF-Net achieves outstanding performance and outperforms state-of-the-art methods. Lingyun Ye, Zhishen Zhu, Gaopeng Gou, Gang Xiong 0001, Mingxin Cui |
HPCC | 2 |
| 2024 | User Behavior Forensics on Encrypted Traffic in the Industrial Internet of Things
Zhishen Zhu, Gaopeng Gou, Chonghua Wang, Gang Xiong 0001 |
IFIP Int. Conf. Digital Forensics | 1 |
| 2022 | Anomaly Detection in Encrypted Identity Resolution Traffic based on Machine LearningabstractIdentity resolution is an emerging network resource widely applied in Industrial Internet of Things. Although encryption improves the privacy of identity resolution, it also challenges DPI-based anomaly detection. Therefore, it is imperative to recognize and supplement the encrypted information of IDS. In this paper, we design a machine learning-based framework to automatically extract critical information of identity resolution system from network traffic. According to the characteristics of traffic, we use the hybrid feature of statistics and sequences to describe encrypted traffic. Besides, a supervised classification algorithm is applied to explore the effective classification of two communication processes, which are service attribution information for node addressing and operation behavior for data management. We tested this method based on the encrypted traffic collected from a realistic identity resolution system. The results indicate that our approach exhibits good performance, outperforms related works, and can be applied in resource-constrained industrial scenario. This is the first work analysing the identity resolution system from the perspective of traffic analysis. Zhishen Zhu, Qingya Yang, Chonghua Wang, Zhen Li 0011 |
QRS | 1 |
| 2022 | MCFM: Discover Sensitive Behavior from Encrypted Traffic in Industrial Control SystemabstractTo tackle with advanced persistent threats against industrial control system, Siemens has developed S7CommPlus- TLS, a new version of the encrypted protocol challenging traditional DPI-based anomaly detection methods. However, the communication mode of industrial control system leads to the overlapping of periodic traffic and sensitive behavior traffic, and thus makes mainstream encrypted traffic classification methods exhibit a poor performance in S7CommPlus-TLS protocol. Therefore, we design a multiple clustering framework called MCFM, which can automatically extract sensitive behavior of S7CommPlus-TLS from network traffic. The first-clustering is used as a pre-processing model to separate and remove periodic traffic from overlapping flows according to the communication mode of industrial control system. Besides, we employ the second- clustering as a generator to extract the fingerprint of sensitive behaviors. Our comprehensive experiments on the simulation dataset covering six sensitive behaviors indicate that MCFM achieves an excellent performance, and outperforms present cutting-edge methods. To the best of our knowledge, this is the first work analyzing industrial control system from the perspective of encrypted traffic analysis. Zhishen Zhu, Junzheng Shi, Chonghua Wang, Gang Xiong 0001, Zhiqiang Hao, Gaopeng Gou |
TrustCom | 1 |