VLDB 2026 Research / reviewers in the wild / expert
Linqi Ruan
dblp:294/2236
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2022
0000-0003-1934-3057ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Conan: A Practical Real-Time APT Detection System With High Accuracy and EfficiencyabstractAdvanced Persistent Threat (APT) attacks have caused serious security threats and financial losses worldwide. Various real-time detection mechanisms that combine context information and provenance graphs have been proposed to defend against APT attacks. However, existing real-time APT detection mechanisms suffer from accuracy and efficiency issues due to inaccurate detection models and the growing size of provenance graphs. To address the accuracy issue, we propose a novel and accurate APT detection model that removes unnecessary phases and focuses on the remaining ones with improved definitions. To address the efficiency issue, we propose a state-based framework in which events are consumed as streams and each entity is represented in an FSA-like structure without storing historic data. Additionally, we reconstruct attack scenarios by storing just one in a thousand events in a database. Finally, we implement our design, calledConan, on Windows and conduct comprehensive experiments under real-world scenarios to show thatConancan accurately and efficiently detect all attacks within our evaluation. The memory usage and CPU efficiency ofConanremain constant over time (1-10 MB of memory and hundreds of times faster than data generation), makingConana practical design for detecting both known and unknown APT attacks in real-world scenarios. Chun-lin Xiong, Tiantian Zhu 0001, Weihao Dong, Linqi Ruan, Runqing Yang, Yueqiang Cheng, Yan Chen 0004, Xutong Chen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | RATScope: Recording and Reconstructing Missing RAT Semantic Behaviors for Forensic Analysis on WindowsabstractRemote Access Trojan (RAT) attacks have become an extensively prevailing and serious threat to enterprise security. A forensic system targeting RAT attacks is needed to record and reconstruct fine-grained semantic behaviors of RATs. However, existing forensic systems suffer from various issues such as intrusive instrumentation, nontrivial recording overhead, and RAT behavior blindness. In this article, we first conduct a large-scale study of a representative set of real-world RAT families active from 1999 to 2016. This is the first study to understand the landscape of RATs in the literature. Based on the study, we then proposeRATScope, an instrumentation-free RAT forensic system targeting Windows platform. Specifically,RATScopeoffers an audit logging module to efficiently record system logs by leveraging Event Tracing for Windows (ETW), and provides a novel program behavior modeling technique to reconstruct semantic behaviors of RATs accurately. We implement a prototype ofRATScopeand evaluate the recording overhead and the behavior identification accuracy. The results show that the audit logging module only incurs 3.7 percent runtime overhead on average. Our system can achieve around 90 percent true positive rate in the cross-family experiment, around 80 percent true positive rate in the two-year spanning temporal experiment, and nearzerofalse positive rate. Runqing Yang, Xutong Chen, Haitao Xu 0002, Yueqiang Cheng, Chun-lin Xiong, Linqi Ruan, Mohammad Kavousi, Zhenyuan Li, Liheng Xu, Yan Chen 0004 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | General, Efficient, and Real-Time Data Compaction Strategy for APT Forensic AnalysisabstractThe damage caused by Advanced Persistent Threat (APT) attacks to governments and large enterprises is gradually escalating. Once an attack event is detected, forensic analysis will use the dependencies between system audit logs to rapidly locate intrusion points and determine the impact of the attacks. Due to the high persistence of APT attacks, huge amounts of data will be stored to meet the needs of forensic analysis, which not only brings great storage overhead, but also sharply increases the computing costs. To compact data without affecting forensic analysis, several methods have been proposed. However, in real-world scenarios, we meet the problems of weak cross-platform capability, large data processing overhead, and poor real-time performance, rendering existing data compaction methods difficult to meet the usability and universality requirements jointly. To overcome these difficulties, this paper proposes a general, efficient, and real-time data compaction method at the system log level; it does not involve internal analysis of the program or depend on the specific operating system type, and it includes two strategies: 1) data compaction of maintaining global semantics (GS), which determines and deletes redundant events that do not affect global dependencies, and 2) data compaction based on suspicious semantics (SS). Given that the purpose of forensic analysis is to restore the attack chain, SS performs context analysis on the remaining events from GS and further deletes the parts that are not related to the attack. The results of the real-world experiments show that the compaction ratios of our method to system events are as high as$4.36\times $to$13.18\times $and$7.86\times $to$26.99\times $on GS and SS, respectively, which is better than state-of-the-art studies. Tiantian Zhu 0001, Linqi Ruan, Chun-lin Xiong, Jinkai Yu, Yaosheng Li, Yan Chen 0004, Mingqi Lv, Tieming Chen |
IEEE Trans. Inf. Forensics Secur. | 3 |