VLDB 2026 Research / reviewers in the wild / expert
Shen Su
dblp:36/10365
· DBLP profile ↗
51ranked-venue papers
6as first author
28since 2021 · last 2026
0000-0003-2744-3584ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19 · 3 first-author · 10 since 2021Security and privacy · 7 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 4 since 2021Systems, architecture and hardware · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Software engineering, systems software and programming languages · 3Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | C2graph: A Compression-Collaboration Algorithm for CPU-GPU Hybrid Weighted Graph Traversals
Ning Wang 0026, Huaibei Li, Shen Su, Yu Gu 0002, Ge Yu 0001, Zhigang Wang 0001, Dawei Zhao 0001, Hui Lu 0005, Zhihong Tian 0001 |
ICDE | 3 |
| 2026 | Pruning Attention Heads Based on Semantic and Code Structure for Smart Contract Vulnerability DetectionabstractAlong with the sustained occurrence of black swan events in the decentralized application ecosystem, smart contract security is a growing concern. Traditional solutions mainly rely on predefined rules, while highly accurate, require intensive manual code analysis. Machine learning methods (mainly based on BERT) leverage semantic and contextual information, but overlook crucial code structure features, which are critical for identifying vulnerability. Furthermore, the presence of useless or harmful attention heads in the BERT model leads to less robust predictions and slows down processing speeds. We propose a novel method named Pruning attention Heads based on Semantic and Code Structure (PHSCS) for Smart Contract Vulnerability Detection. Specifically, we introduce a new structure-aware pre-training programming language task, Variable Edge Prediction, which bypasses the use of data flow nodes as input and directly predicts data flow edges between variables, aiming to efficiently learn code structure while ensuring the ability to process extensive code. Additionally, we present a pruning strategy to optimize BERT, tailored to the semantic and structural peculiarities of code. By employing Taylor Expansion for evaluating attention heads' significance and guiding their pruning, iteratively refined the BERT model. Experiment results on 8 vulnerability types illustrate that the PHSCS method surpasses state-of-the-art methods. Siyu Jiang, Teng Ouyang, Shen Su |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | H$^{4}$4: A Software-Defined Deception Defense System in Safeguard Defense ModeabstractIn the battlefield of cyberspace, sophisticated attackers often operate by following meticulously designed cyber kill chains, enabling them to maintain a persistent presence within victim systems while evading conventional detection mechanisms. Traditional honeypot-based deception defenses aim to uncover such threats by luring attackers into exposing their malicious activities through decoy systems. However, advanced attackers are frequently able to identify and avoid these traps, making it increasingly challenging to detect and engage them effectively. To overcome this challenge, this study proposes a novel defensive paradigm named as the safeguard mode, which emphasizes the covert identification of attackers rather than solely preventing initial breaches. By proactively recognizing potential threats in a hidden manner, victim systems can be better protected through early threat intelligence. Based on the propsoed safeguard mode concept, we propose$Honey^{4}$, abbreviated as$H^{4}$, a comprehensive framework designed to systematically entrap advanced threats.$H^{4}$comprises four core components: Honeypoint, Honeyproxy, Honeytrace, and Honeycenter, which work in concert to deceive, monitor, and analyze attacker behavior. Furthermore, we explore how Artificial Intelligence Generated Content (AIGC) techniques can enhance$H^{4}$'s capabilities, particularly as attackers themselves begin to leverage AI-driven tactics. The practical efficacy of the proposed safeguard mode and the$H^{4}$framework has been validated through being deployed in real scenarios including the 19th Asian Games and the Canton Fairs, and$H^{4}$has successfully captured a significant number of threatening IP addresses and malicious behavioral patterns, generating actionable cyber threat intelligence that fundamentally safeguards system defense. Rui Wang 0007, Yuan Liu 0002, Yanbin Sun, Shen Su, Binxing Fang, Zhihong Tian 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | A Deep Dynamic Graph Generative Framework for Blockchain Phishing DetectionabstractBlockchain phishing scams cause billions in annual losses, yet extreme data imbalance severely hampers existing detection algorithms. Current dynamic graph generation methods fragment structures and generate erroneous connections, failing to capture local dynamic patterns vital for node classification. This raises critical questions: Can models minimize isolated subgraph generation? How can they learn and replicate structured, recurring interaction patterns? To answer these questions, we introduce GraphFlowGen, an end-to-end deep generative framework. To minimize isolated subgraph generation, GraphFlowGen employs a novel preprocessing module that jointly extracts structural and temporal contexts from transaction data, preventing fragmentation and information loss. To learn and replicate structured interaction patterns, it incorporates a Transformer encoder with Graph Attention Networks (GAT) to capture node connection dynamics and temporal evolution. To ensure high fidelity while reducing erroneous links, a reinforcement learning (RL) mechanism iteratively refines generated graph structures. Empirical validation on three real-world datasets demonstrates the effectiveness of our algorithm in local dynamic graph generation and its utility for downstream phishing detection tasks. Siyi Xiao, Lejun Zhang, Xinwei Zhang 0002, Sen Zhang 0002, Shen Su, Jing Qiu 0002, Haibo Hu 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Adversarial Adaptation and Data Selection-Based Smart Contract Vulnerability Detection
Siyu Jiang, Teng Ouyang, Yangkai Wang, Zhihong Tian 0001, Shen Su |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | iAudit: Toward Efficient Pixel-Level Dynamic Image Auditing in Decentralized StorageabstractDecentralized storage auditing approaches are designed to ensure data security in dishonest decentralized storage providers. However, the need for data updates introduces new challenges to the design of decentralized storage auditing approaches. Existing approaches can support dynamic auditing for updated files. Unfortunately, they can only deal with block-level updating, which is counter-intuitive and requires conversion from semantic changes to binary changes. Furthermore, existing dynamic auditing approaches require the recalculation of auxiliary auditing information (e.g., auditing authenticators) in data owners, which imposes unnecessary additional burdens on data owners, particularly those with constrained resources in decentralized storage environments. In this paper, we focus on image files and propose iAudit, an efficient pixel-level dynamic image auditing approach in decentralized storage. We first design a novel image authenticator with image pixels for efficient dynamic auditing, which combines convolution operations and polynomial commitment in authenticator construction. Additionally, we build an owner-free dynamic mechanism in dynamic decentralized storage auditing approach by utilizing zero-knowledge proof techniques. In this way, the dynamic operation overheads incurred by auditing can be completely eliminated from the data owners. A prototype of iAudit is implemented, and extensive experimental results demonstrate that iAudit outperforms state-of-the-art works, achieving over a 210× speedup for data owner in dynamic update phase. Haiyang Yu 0001, Yinglong Gao, Shen Su, Zhen Yang 0004, Yuwen Chen 0002, Shui Yu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | 6Global: Dynamic IPv6 Active Address Scanning Assisted by Global PerspectiveabstractNetwork scanning is crucial for both network management and cybersecurity. However, due to the vast address space of IPv6, brute-force scanning is infeasible. Seed-based target generation algorithms have recently attracted considerable research attention. However, existing target generation algorithms lack a deeper exploration of patterns, leading to poor capture of dense regions and consequently low hitrate. To address this issue, we propose 6Global, a dynamic IPv6 active address scanning method assisted by global perspective. 6Global first performs rapid clustering of seed addresses based on their descriptive attributes. Then, for each cluster, patterns are generated in a bottom-up manner based on entropy, using subranges to represent patterns and resulting in denser patterns. Finally, dynamic scanning is conducted using these patterns. During scanning, the reward of each pattern is dynamically adjusted based on its active density and global statistics, which enhances the capability in capturing dense regions. Experimental results on six seed datasets show that 6Global overall outperforms seven baseline methods and demonstrates significant advantages across multiple datasets. Junqing Wang, Lejun Zhang, Zhihong Tian 0001, Kejia Zhang 0002, Shen Su, Jing Qiu 0002, Yanbin Sun |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | FML-TFP: A Federated Meta-Learning Approach for Distributed Traffic Flow PredictionabstractAs a cornerstone for enabling intelligent transportation systems, traffic flow prediction provides a technical basis for urban planning, traffic management and travel management. Federated learning (FL) is frequently employed in traffic flow prediction to meet privacy requirements. However, the traditional FL paradigm is subject to several limitations, including data heterogeneity, unbalanced data volume, and limited available resources. To address these problems, we propose a three-tiered hierarchical federated meta-learning framework. Firstly, the client will use a soft gap sampler (SGS) to sample personalized parameters, thereby alleviating bandwidth pressure and obtaining the gradients required for backpropagation of the global model on the query set. Secondly, these parameters and gradients are respectively used in the regional server and the global server to obtain regional parameters with regional awareness ability and global parameters with learning ability. Finally, the regional server will fuse the two parameters for the initial parameters in the prediction stage. A large number of experiments prove that the proposed framework can cope with the integration of cross-regional models, the adaptation of models in data-scarce regions, and different bandwidth limitations of clients. Pulun Gao, Qijian Fan, Yujie Liang, Guiping Li, Shen Su, Lei Liu 0031 |
GLOBECOM | 6 |
| 2025 | From one-one to one-many: ORCA enables scalable and revocable group covert communication on blockchainabstractThe decentralized and immutable nature of blockchainprovides a resilient foundation for covert communication in adversarial and untrusted environments, specifically in scenarios requiring unobservable multi-recipient messaging. Most existing schemes, however, are limited to one-to-one transmission and lack mechanisms to handle untrusted receivers, which constrains their scalability and security. To address these challenges, we propose ORCA (Orthogonal Covert Architecture), a group covert communication framework based on strictly orthogonal, integer-valued codewords. ORCA selects codewords from a Hadamard matrix and applies secret column permutations to ensure decoding isolation and resistance against inference attacks. Each receiver recovers only its assigned message through projection, without coordination or leakage. This encoding structure supports scalable embedding, seamless receiver revocation, and clean integration with standard transaction fields. In contrast to prior work, we analyze the impact of imperfect orthogonality and provide theoretical bounds on decoding interference. Extensive experiments on real-world Bitcoin blockchain data and comparative evaluation against representative covert communication schemes confirm ORCA’s robustness, high embedding capacity, and statistical indistinguishability from normal blockchain activity. These results establish ORCA as a scalable and secure solution for multi-recipient covert communication in adversarial environments. Zhujun Wang 0003, Lejun Zhang, Shen Su, Jing Qiu 0002, Tie Qiu 0001 |
Comput. Networks | 4 |
| 2025 | Pheromone-based graph embedding algorithm for Ethereum phishing detection
Siyi Xiao, Lejun Zhang, Zhihong Tian 0001, Shen Su, Jing Qiu 0002 |
Comput. Networks | 4 |
| 2025 | A blockchain-oriented covert communication technology with controlled security level based on addressing confusion ciphertext
Lejun Zhang, Zhujun Wang 0003, Guopeng Wang, Jing Qiu 0002, Shen Su, Yuan Liu 0002, Guangxia Xu, Zhihong Tian 0001, Sergey Gataullin |
Frontiers Comput. Sci. | 7 |
| 2025 | LGTDA: Bandwidth exhaustion attack on Ethereum via dust transactions
Qunhong Sun, Shen Su, Ting Cui |
Future Gener. Comput. Syst. | 4 |
| 2025 | Hops Can be Constrained: Efficient Distance Queries on Large Time-Dependent Road NetworksabstractWith the increasing complexity of urban transportation systems and the growing demand for dynamic, real-time responsiveness, Time-Dependent Minimum Travel Time Queries (TD-MTTQs) in time-dependent road networks have become a core challenge in intelligent transportation system research. To address the trade-offs between preprocessing complexity and query efficiency in existing index-based methods for large-scale road network applications, this paper proposes a 4-hop index method, TD-TNR-CH. The core methodology involves establishing local indexes from each node to its nearest critical nodes (named transit nodes) through strategic critical node selection, while simultaneously constructing query tables associated with candidate sets between these critical nodes. This architecture enables rapid computation of medium-to-long distance queries through efficient index lookups, while ensuring high responsiveness for short-distance queries via TCH-based local searches. Extensive experimental results on large-scale real-world road networks demonstrate that our method exhibits superior scalability, achieving query efficiency of up to 103 times that of the fastest existing algorithms. Furthermore, it shows exceptional stability across queries of varying distances. Additionally, leveraging its parallelized architecture, TD-TNR-CH requires only approximately 30 minutes of preprocessing time for large-scale networks, significantly outperforming comparable methods in terms of preprocessing efficiency. Weihao Yu 0007, Dian Ouyang, Fan Zhang 0036, Xiang Zhao 0002, Shen Su, Xuemin Lin 0001, Zhihong Tian 0001 |
Proc. ACM Manag. Data | 5 |
| 2025 | BPFGuard: Multi-Granularity Container Runtime Mandatory Access ControlabstractThe adoption of container-based cloud computing services has been prevalent, especially with the introduction of Kubernetes, which enables the automated deployment, scaling, and administration of applications in containers, hence boosting the popularity of containers. As a result, researchers have placed greater emphasis on container runtime security, notably investigating the efficacy of traditional techniques such as Capabilities, Seccomp, and Linux security modules in guaranteeing container security. However, due to the limitations imposed by the container environment, the results have been unsatisfactory. In addition, eBPF-based solutions face the problem of being unable to quickly load policies and affect real-time operations when faced with newer kernel vulnerabilities. This paper investigates the limitations of existing container security mechanisms. Additionally, it examines the specific constraints of these mechanisms in Kubernetes environments. The paper classifies container monitoring and obligatory access control into three distinct categories: system call access control, LSM hook access control, and kernel function access control. Therefore, we propose a technique for regulating container access with a variety of granularity levels. This technique is executed using eBPF and is tightly integrated with Kubernetes to collect relevant meta-information. In addition, we suggest implementing a consolidated routing method and employing function tail call chaining to overcome the limitation of eBPF in enforcing mandatory access control for containers. Lastly, we conducted a series of experiment to verify the effectiveness of the system's security using CVE-2022-0492 and to benchmark the system that had BPFGuard enabled. The results indicate that the average performance loss increased merely by 2.16%, demonstrating that there are no adverse effects on the container services. This suggests that greater security can be achieved at a minimal cost. Hui Lu 0005, Xiaojiang Du, Dawei Hu, Shen Su, Zhihong Tian 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2025 | Unraveling the Deception of Web3 Phishing Scams: Dynamic Multiperspective Cascade Graph Approach for Ethereum Phishing DetectionabstractEthereum, as one of the most active cryptocurrency trading platforms, has garnered significant academic interest due to its transparent and accessible transaction data. In recent years, phishing scams have emerged as a serious criminal activity on Ethereum. Although most studies model Ethereum account transactions as networks and analyze them using traditional machine learning or network representation learning techniques, these approaches often rely solely on the latest static transaction records or use manually designed features while neglecting transaction histories, thus failing to fully capture the dynamic interactions and potential trading patterns between accounts. This article introduces an innovative multiperspective cascaded dynamic graph neural network model named DMPCG, which extracts phishing transaction data from authoritative databases like blockchain explorers to construct transaction network graphs. The model elevates the analysis from the microscopic features of nodes to the macroscopic dynamics of the entire network, integrating the attributes of static snapshot graphs with the evolution of dynamic trading networks, significantly enhancing the accuracy of phishing detection. Experimental results demonstrate that the DMPCG method achieves an impressive precision of 92.6% and an F1-score of 90.9%, outperforming existing baseline models and traditional subgraph sampling techniques. Lejun Zhang, Xucan Zhang, Siyi Xiao, Shen Su, Jing Qiu 0002, Zhihong Tian 0001 |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2025 | DART: Distributed Zero Knowledge Data Auditing With Retrievability for Blockchain-Based Decentralized Storage Networks
Haiyang Yu 0001, Yurun Chen 0002, Shen Su, Jian Su 0001, Yuwen Chen 0002, Zhen Yang 0004 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | FELEMN: Toward Efficient Feature-Level Machine Unlearning for Exact Privacy ProtectionabstractData privacy protection legislation around the world has increasingly enforced the “right to be forgotten” regulation, generating a surge in research interest in machine unlearning (MU), which aims to remove the impact of training data from machine learning models upon receiving revocation requests from data owners. There exist two major challenges for the performance of MU: the execution efficiency and the inference interference. The former requires minimizing the computational overhead for each execution of the MU mechanism, while the latter calls for reducing the execution frequency to minimize interference with normal inference services. Nowadays most MU studies focus on the sample-level unlearning setting, leaving the other paramount feature-level setting under-explored. Adapting these existing techniques to the latter turns out to be non-trivial. The only known feature-level work achieves anapproximateunlearning guarantee, but suffers from degraded model accuracy and still leaves the inference interference challenge unsolved. We are therefore motivated to propose FELEMN, the first FEature-Level Exact Machine uNlearning method that overcomes both of the above-mentioned hurdles. For the MU execution efficiency challenge, we explore the impact of different feature partitioning strategies on the preservation of semantic relationships for maintaining model accuracy and MU efficiency. For the inference interference challenge, we propose two batching mechanisms to combine as many individual unlearning requests to be processed together as possible, while avoiding potential privacy issues coming with falsely postponing unlearning requests, which is grounded on theoretical analysis. Experiments on five real datasets show that our FELEMN outperforms up-to-date competitors with up to$3\times$speedup for each MU execution, and 50% runtime reduction by mitigating inference interference. Zhigang Wang 0001, Yizhen Yu, Jian Lou 0001, Ning Wang 0026, Yu Gu 0002, Shen Su, Yuan Liu 0002, Hui Jiang 0015, Zhihong Tian 0001 |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2025 | Proof: Pre-Training Model of Malware Family Classification Based on Active DefenseabstractMalware acts as a critical component in network attack and defense mechanisms. As Malware threats become more complex and diverse, timely automatic malware classification is urgently needed. Take into account consistency and system resource consumption, malware classification should be compatible with other security devices to form a comprehensive defense system. In this study, we proposed a pre-training framework Proof based on malware behavior captured by honeypoints inside and outside the protected system, and the framework’s performance in the categorization of malware families is evaluated. To describe malware, a structure called Malware Behavior Instruction Set (MBIS) was designed by selecting a subset of all behaviors captured by honeypoints. Then, a self-supervised pre-training model MBI2vec is applied to learn the internal mode of malicious code to guide the downstream malicious code family classification model composed of Bi-LSTM and attention mechanism. Finally, the Proof framework evaluated 846 malware samples from five malware families that we captured in the real world, and the f1-score of the classification result was 0.9554. Hao Liu 0058, Shen Su, Zhihong Tian 0001 |
IEEE Trans. Sustain. Comput. | 4 |
| 2024 | Data tampering detection and recovery scheme based on multi-branch target extraction for internet of vehicles
Mianjie Li, Qihan Pei, Chun Shan, Shen Su, Yuan Liu 0002, Zhihong Tian 0001 |
Comput. Networks | 4 |
| 2024 | BlockSC: A Blockchain Empowered Spatial Crowdsourcing Service in Metaverse While Preserving User Location PrivacyabstractSpatial crowdsourcing (SC) has become a fundamental and emerging technology in Metaverse, facilitating the creation of immersive experiences through location-based services. In these systems, a central SC server leverages SC workers who physically travel to task locations to gather spatiotemporal environment data. However, conventional SC systems face two significant challenges: (1) the SC server, functioning as a centralized authority, can sometimes be unreliable, either due to intentional or unintentional misconduct, (2) to ensure efficient task assignment and validation, the location privacy of tasks and workers is openly accessible. In this study, we formally define location privacy preserved proof generation and verification problem (LP-PGVP) within an SC task matching scenario, with the aim to the above two challenges. Our proposed solution is a blockchain-based SC system (BlockSC), which provides a decentralized platform for task requesters and workers in the Metaverse context through calling smart contracts. We also introduce a ciphertext-based task matching scheme where task location access is granted only to eligible workers executing a task, benefiting from the design of geographic coordinate transformation and bilinear mapping methodology. To further demonstrate the task matching scheme’s operation and impact, we present an easy-to-understand case study. Our evaluation findings confirm that the proposed system effectively maintains location privacy for both SC workers and task requesters, without a considerable sacrifice in task matching efficiency. Yuan Liu 0002, Shen Su, Lejun Zhang, Xiaojiang Du, Mohsen Guizani, Zhihong Tian 0001 |
IEEE J. Sel. Areas Commun. | 3 |
| 2023 | Smart Contract Firewall: Protecting the on-Chain Smart Contract ProjectsabstractThe burgeoning landscape of blockchain technology has made the security of deployed smart contracts an imperative concern. While existing security measures excel in pre-deployment testing, they fall short in protecting smart contracts once they are deployed, leaving them susceptible to malicious attacks. In this paper, we propose a novel Smart Contract Firewall framework designed to bridge this security gap. Functioning as a dynamic gateway, the framework employs real-time transaction inspection through adaptable filtering rules, enabling the identification and rollback of malicious transactions as they occur. Our empirical analysis demonstrates the framework's efficacy in mitigating a majority of existing vulnerabilities in the deployed smart contracts. Although the added layer of security comes at a cost, we prove that the increased gas expenses could be limited to 30 % -50 % for most transactions. This trade-off, we argue, is a small price to pay for significantly enhanced security. Shen Su, Yue Xue, Liansheng Lin, Hui Lu 0005, Jing Qiu 0002, Yanbin Sun, Yuan Liu 0002, Zhihong Tian 0001 |
GLOBECOM | 1 |
| 2023 | Improving Precision of Detecting Deserialization Vulnerabilities with Bytecode AnalysisabstractTraditional static taint analysis based on bytecode analysis such as GadgetInspector to detect deserialization vulnerabilities always faced precision problems. For example, missing the fact that taints flowing to members in called methods, type confusion, and chaotic inheritance relationships when detecting deserialization vulnerabilities, which would lead to many error results. To alleviate these problems, this paper considers three measures of improving precision of detecting deserialization vulnerabilities, including cross-function members data flow tracking, local variables and arguments types inference, and call chain subject inference based on inheritance relationships. Weicheng Li, Hui Lu 0005, Yanbin Sun, Shen Su, Jing Qiu 0002, Zhihong Tian 0001 |
IWQoS | 4 |
| 2023 | A covert channel over blockchain based on label tree without long waiting times
Zhujun Wang 0003, Lejun Zhang, Guopeng Wang, Jing Qiu 0002, Shen Su, Yuan Liu 0002, Guangxia Xu, Zhihong Tian 0001 |
Comput. Networks | 6 |
| 2023 | Prediction of venting gas explosion overpressure based on a combination of explosive theory and machine learning
Shen Su, Jinkun Men, Geliang Li |
Expert Syst. Appl. | 3 |
| 2021 | Smart healthcare-oriented online prediction of lower-limb kinematics and kinetics based on data-driven neural signal decoding
Chunzhi Yi, Feng Jiang 0001, Md. Zakirul Alam Bhuiyan, Chifu Yang, Xianzhong Gao, Hao Guo 0015, Jiantao Ma, Shen Su |
Future Gener. Comput. Syst. | 8 |
| 2021 | IoT root union: A decentralized name resolving system for IoT based on blockchain
Shen Su, Zhihong Tian 0001, Jinxi Deng, Lihua Yin, Xiaojiang Du, Mohsen Guizani |
Inf. Process. Manag. | 1 |
| 2021 | Secure Data Sharing Framework via Hierarchical Greedy Embedding in Darknets
Yanbin Sun, Mohan Li, Shen Su, Zhihong Tian 0001, Wei Shi 0001 |
Mob. Networks Appl. | 3 |
| 2021 | Honeypot Identification in Softwarized Industrial Cyber-Physical SystemsabstractIn softwarized industrial networking, honeypot identification is very important for both the attacker and the defender. Existing honeypot identification relies on simple features of honeypot. There exist two challenges: The simple feature is easily simulated, which causes inaccurate results, whereas the advanced feature relies on high interactions, which lead to security risks. To cope with these challenges, in this article, we propose a secure fuzzy testing approach for honeypot identification inspired by vulnerability mining. It utilizes error handling to distinguish honeypots and real devices. Specifically, we adopt a novel identification architecture with two steps. First, a multiobject fuzzy testing is proposed. It adopts mutation rules and security rules to generate effective and secure probe packets. Then, these probe packets are used for scanning and identification. Experiments show that the fuzzy testing is effective and corresponding probe packet can acquire more features than other packets. These features are helpful for honeypot identification. Yanbin Sun, Zhihong Tian 0001, Mohan Li, Shen Su, Xiaojiang Du, Mohsen Guizani |
IEEE Trans. Ind. Informatics | 4 |
| 2020 | LGMal: A Joint Framework Based on Local and Global Features for Malware DetectionabstractWith the gradual advancement of smart city construction, various information systems have been widely used in smart cities. In order to obtain huge economic benefits, criminals frequently invade the information system, which leads to the increase of malware. Malware attacks not only seriously infringe on the legitimate rights and interests of users, but also cause huge economic losses. Signature-based malware detection algorithms can only detect known malware, and are susceptible to evasion techniques such as binary obfuscation. Behavior-based malware detection methods can solve this problem well. Although there are some malware behavior analysis works, they may ignore semantic information in the malware API call sequence. In this paper, we design a joint framework based on local and global features for malware detection to solve the problem of network security of smart cities, called LGMal, which combines the stacked convolutional neural network and graph convolutional networks. Specially, the stacked convolutional neural network is used to learn API call sequence information to capture local semantic features and the graph convolutional networks is used to learn API call semantic graph structure information to capture global semantic features. Experiments on Alibaba Cloud Security Malware Detection datasets show that the joint framework gets better results. The experimental results show that the precision is 87.76%, the recall is 88.08%, and the F1-measure is 87.79%. We hope this paper can provide a useful way for malware detection and protect the network security of smart city. Yuhan Chai, Jing Qiu 0002, Shen Su, Chunsheng Zhu, Lihua Yin, Zhihong Tian 0001 |
IWCMC | 3 |
| 2020 | Wearable-sensors Based Activity Recognition for Smart Human Healthcare Using Internet of ThingsabstractWith the growing of chronic diseases, strain on public healthcare systems becomes a critical problem of our society. Internet of Things (IoT) technology [1]–[3], as a hot topic, has attracted more and more attention recently due to its potential ability to reduce the strain on public healthcare systems. In IoT based healthcare system, the information of patients can be automatically obtained via various sensors and the physical condition of patients can be analyzed via those obtained data. In this work, we present a IoT and blockchain based healthcare system for human activity recognition via monitoring vital/non-vital signals collected from wearable-sensors remotely. On the one hand, the IoT technology is used for data acquisition and transmission [4]. On the other hand, the blockchain technology is used for data encryption. An incremental learning strategy based on covariance matrix is designed to recognize the activity done by a patient under care and determine whether there is an emergency for the patient under care. In such a manner, necessary feedback or programmable alarms can be made during or after the activity. Shen Su, Chang Tang, Lulu Wang 0003 |
IWCMC | 2 |
| 2020 | A Survey on Access Control in the Age of Internet of ThingsabstractWith the development of Internet-of-Things (IoT) technology, various types of information, such as social resources and physical resources, are deeply integrated for different comprehensive applications. Social networking, car networking, medical services, video surveillance, and other forms of the IoT information service model gradually change people's daily lives. Facing the vast amounts of IoT information data, the IoT search technology is used to quickly find accurate information to meet the real-time search needs of users. However, IoT search requires using a large amount of user private information, such as personal health information, location information, and social relations information, to provide personalized services. Employing private information from users will encounter security problems if an effective access control mechanism is missing during the IoT search process. An access control mechanism can effectively monitor the access activities of resources and ensure that authorized users access information resources under legitimate conditions. This survey examines the growing literature on access control for an IoT search. Problems and challenges of access control mechanisms are analyzed to facilitate the adoption of access control solutions in real-life settings. This article aims to provide theoretical, methodological, and technical guidance for IoT search access control mechanisms in large-scale dynamic heterogeneous environments. Based on a literature review, we also analyzed the future development direction of access control in the age of IoT. Jing Qiu 0002, Zhihong Tian 0001, Chunlai Du, Qi Zuo, Shen Su, Binxing Fang |
IEEE Internet Things J. | 5 |
| 2020 | Vcash: A Novel Reputation Framework for Identifying Denial of Traffic Service in Internet of Connected VehiclesabstractTrust management of the Internet of Connected Vehicles has been a hot topic in recent years with the rapid development of UGV technologies. However, existing resolutions based on trustworthiness verification among vehicles make the traffic event transmission quite inefficient. In this article, we assume that the deployed roadside units (RSUs) can provide efficient communication between any pair of RSU and vehicle and propose vehicle cash (Vcash), a reputation framework for identifying denial of traffic service, to resolve the trustworthiness problem in the application level of the Internet of Connected Vehicles. In our reputation framework, every vehicle communicates with the RSU directly for traffic event verification, and spreads verified traffic event notification. We borrow the idea of market trading, and set up trading rules to restrict the malicious vehicle's spread of false message, and to encourage vehicles to contribute to the traffic event monitoring and verification. To evaluate the effectiveness of our reputation framework, we conduct a simulation experimental. Our experiment results indicate that our proposal manages to avoid bogus event spread, and a vehicle in our framework has to contribute to the traffic event detection to normally employ the traffic service. Zhihong Tian 0001, Xiangsong Gao, Shen Su, Jing Qiu 0002 |
IEEE Internet Things J. | 3 |
| 2020 | Nei-TTE: Intelligent Traffic Time Estimation Based on Fine-Grained Time Derivation of Road Segments for Smart CityabstractWith the development of the Internet of Things and big data technology, the intelligent transportation system is becoming the main development direction of future transportation systems. The time required for a given trajectory in a transportation system can be accurately estimated using the trajectory data of the taxis in a city. This is a very challenging task. Although historical data have been used in existing research, excessive use of trajectory information in historical data or inaccurate neighbor trajectory information does not allow for a better prediction accuracy of the query trajectory. In this article, we propose a deep learning method based on neighbors for travel time estimation (TTE), called the Nei-TTE method. We divide the entire trajectory into multiple disjoint segments and use the historical trajectory data approximated at the time level. Our model captures the characteristics of each segment and utilizes the trajectory characteristics of adjacent segments as the road network topology and speed interact. We use velocity features to effectively represent adjacent segment structures. The experiments on the Porto dataset show that the experimental results of our model are significantly better than those of the existing models. Jing Qiu 0002, Dongwen Zhang, Shen Su, Zhihong Tian 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2019 | Preserving Location Privacy in Mobile Edge ComputingabstractThe burgeoning technology of Mobile Edge Computing (MEC) is attracting the traditional Location-Based Service (LBS) and Location Service (LS) to deploy due to its nature characters such as low latency and location awareness. Although this transplant will avoid the location privacy threat from the central cloud provider, there still exist the privacy concerns in the LS of MEC scenario. Location privacy threat arises during the procedure of the fingerprint localization, and the previous studies on location privacy are ineffective because of the different threat model and information semantic. To address the location privacy in MEC environment, we designed LoPEC, a novel and effective scheme for protecting location privacy for the MEC devices. By the proper model of the Radio Access Network (RAN) access points, we proposed the noise-addition method for the fingerprint data, and successfully induce the attacker from recognizing the real location. Our evaluation proves that LoPEC effectively prevents the attacker from obtaining the user's location precisely in both single-point and trajectory scenarios. Yuhang Wang 0029, Zhihong Tian 0001, Shen Su, Yanbin Sun, Chunsheng Zhu |
ICC | 3 |
| 2019 | A data-driven method for future Internet route decision modeling
Zhihong Tian 0001, Shen Su, Wei Shi 0001, Xiaojiang Du, Mohsen Guizani |
Future Gener. Comput. Syst. | 2 |
| 2019 | Block-DEF: A secure digital evidence framework using blockchain
Zhihong Tian 0001, Mohan Li, Meikang Qiu, Yanbin Sun, Shen Su |
Inf. Sci. | 5 |
| 2019 | Real-Time Lateral Movement Detection Based on Evidence Reasoning Network for Edge Computing EnvironmentabstractEdge computing provides high-class intelligent services and computing capabilities at the edge of the networks. The aim is to ease the backhaul impacts and offer an improved user experience. However, the edge artificial intelligence exacerbates the security of the cloud computing environment due to the dissociation of data, access control, and service stages. In order to prevent users from carrying out lateral movement attacks in an edge-cloud computing environment, in this paper we propose a real-time lateral movement detection method, named CloudSEC, based on an evidence reasoning network for the edge-cloud environment. First, the concept of vulnerability correlation is introduced. Based on the vulnerability knowledge and environmental information of the network system, the evidence reasoning network is constructed, and the lateral movement reasoning ability provided by the evidence reasoning network is then used. The experiment results show that CloudSEC provides a strong guarantee for the rapid and effective evidence investigation, as well as real-time attack detection. Zhihong Tian 0001, Wei Shi 0001, Yuhang Wang 0029, Chunsheng Zhu, Xiaojiang Du, Shen Su, Yanbin Sun, Nadra Guizani |
IEEE Trans. Ind. Informatics | 6 |
| 2018 | Automatically Traceback RDP-Based Targeted Ransomware AttacksabstractWhile various ransomware defense systems have been proposed to deal with traditional randomly‐spread ransomware attacks (based on their unique high‐noisy behaviors at hosts and on networks), none of them considered ransomware attacks precisely aiming at specific hosts, e.g., using the common Remote Desktop Protocol (RDP). To address this problem, we propose a systematic method to fight such specifically targeted ransomware by trapping attackers via a network deception environment and then using traceback techniques to identify attack sources. In particular, we developed various monitors in the proposed deception environment to gather traceable clues about attackers, and we further design an analysis system that automatically extracts and analyze the collected clues. Our evaluations show that the proposed method can trap the adversary in the deception environment and significantly improve the efficiency of clue analysis. Furthermore, it also helps us trace back RDP‐based ransomware attackers and ransomware makers in the practical applications. Chaoge Liu, Jing Qiu 0002, Zhihong Tian 0001, Xiang Cui, Shen Su |
Wirel. Commun. Mob. Comput. | 6 |
| 2017 | Extracting Log Patterns Based on Association Analysis for Power Quality Disturbance DetectionabstractTo detect anomalies according to system log is a hot topic recently. For the harmonic monitoring system of the power grid, the common practice of anomaly detection is to conduct machine learning. The learning model is trained with the historical anomaly data, and used for online detection. The premise of this method is to predefine a set of indicators as the input features of the machine learning model. However, existing methods rely mainly on business experience to extract such indicators, which limits the scope of the indicators used for data analysis, but also limits the accuracy of power quality perturbation analysis. In this paper, we propose an algorithm for power quality disturbance detection which investigates the correlation among the harmonic monitoring indicators, and extract the frequently concurrent abnormal indicators as the features to locate power quality disturbance detection. With the verification of the historical disturbance records, we prove that our algorithm can effectively detect the power quality disturbing events. Dandan Feng, Tongxun Wang, Chen Liu 0007, Shen Su |
WISA | 4 |
| 2017 | A Proactive Data Service Model to Encapsulating Stream Sensor Data into ServiceabstractAbnormality Detection in power plant is a typical IoT application which aims to identify anomalies in these routinely collected monitoring sensor data; intend to help detect possible faults in the equipment. However, on the development of abnormality detection, we find that there are three challenges. The first one is the lack of cooperation between sensors. It means that the physical sensors cannot share and interact with each other. Secondly, the rapid increase in volume of sensor data and dynamic situation of production result in challenges to predefine all possible associations between sensors. Thirdly, it is difficult to build IoT application for developers who have little or no professional knowledge about production process. In this paper, we proposed a proactive data service model to encapsulate stream sensor data into services. We spread events among the proactive data services. By analysis of event correlations, we have realized service hyperlinks which help to offer the proactive real-time interaction with services. Real application and experiments verified that our proactive data service based method is more effective compare with traditional rule-based methods to detect abnormalities in power plant. Shouli Zhang, Chen Liu 0007, Shen Su, Yanbo Han, Dandan Feng |
WISA | 3 |
| 2017 | Curve-Registration-Based Feature Extraction for Predictive Maintenance of Industrial Equipment
Shouli Zhang, Xiaohong Li 0001, Jianwu Wang 0001, Shen Su |
CollaborateCom | 4 |
| 2017 | An Approach to Modeling and Discovering Event Correlation for Service Collaboration
Meiling Zhu, Chen Liu 0007, Jianwu Wang 0001, Shen Su, Yanbo Han |
ICSOC | 4 |
| 2017 | A Service-Based Approach to Situational Correlation and Analyses of Stream Sensor DataabstractIoT service and service composition provide an effective means to develop IoT applications based on correlating multiple sensor data. The change of specific sensor data can cause others' changes under uncertain situations. It makes difficult for defining service composition plan in advance to build IoT application. This paper proposes a data-driven service composition method based on our previous proactive data service model. We regard service events frequently happen together with given service event as its situation, and the service events happen next as reacted actions under the situation. We analyze two kinds of correlation among service events via an improved FP-tree algorithm, and realize the service composition at runtime based on the real-time service events. Based on the real sensor data set in a coal-fired power plant, a series of experiments demonstrate that our method can effectively detect new service events based on current service events. Zhongmei Zhang, Xiaohong Li 0001, Chen Liu 0007, Shen Su, Yanbo Han |
ICWS | 4 |
| 2017 | Service Hyperlink: Modeling and Reusing Partial Process Knowledge by Mining Event Dependencies among Sensor Data ServicesabstractIn an IoT environment, process analysis becomes more difficult as a process usually spans over a set of autonomous and distributed sensors. This paper consummates our previous service hyperlink model, to encapsulate dependencies among events generated from services. To effectively discover service hyperlinks, we transform the service hyperlink discovery problem into a frequent sequence mining problem. Existing frequent sequence mining algorithms cannot be directly used because they do not take the temporal constraints in event dependencies into consideration. Based on the dataset from a real power plant as well as several synthetic datasets, we do lots of experiments to verify the effectiveness and efficiency of our algorithm. Meiling Zhu, Chen Liu 0007, Jianwu Wang 0001, Shen Su, Yanbo Han |
ICWS | 4 |
| 2016 | A Lightweight Model for Stream Sensor Data Service
Shen Su, Chen Liu 0007, Zhongmei Zhang, Yanbo Han |
APSCC | 1 |
| 2016 | CFWatcher: A novel target-based real-time approach to monitor critical files using VMIabstractProtecting critical files in file systems is very important to computer systems. To protect critical files, the VMI-based Real-time File-system Monitor tools are promising options. However, these tools are always operation-based and introduce high overhead. The operation-based approaches intercept some kind of file operation to monitor critical files. The selected file operation is intercepted by the monitor whenever it is being executed. As file operation are high-frequency, the operation-based methods always result in the high performance degradation. In this paper, we present a VMI-based low overhead real-time critical file monitor method, CFWatcher, to meet the performance requirements of real-time monitor tools. CFWatcher is a target-based monitor tool which means it only intercepts the file operations accessing the user-defined critical files, and then obtains enough information to check the rules. The overhead of CFWatcher is related to the frequency of the target being accessed. Besides monitoring critical files, CFWatcher can take actions to prevent the illegal access if there is any rule violation. We implemented the prototype of CFWatcher and then evaluated the performance. Experimental results show that the overhead of our approach is low. Dongyang Zhan, Binxing Fang, Xiaojiang Du, Shen Su |
ICC | 5 |
| 2015 | Towards real-time route leak events detectionabstractMalicious attack and misconfiguration can cause unreachable websites, network outages, and other damages. Such incidents are usually observed together with anomalous AS paths which violate a “valley-free” policy. Existing techniques to infer routing policy cannot satisfy industrial demand of real-time route leak detection because they are very likely to trigger false positives. In this paper, we propose an online detection scheme dedicated to detect route leak AS paths. Based on long-lived routing paths, and route anomalous concurrency, we manage to filter possible false positives in online scenarios. Applying this scheme to Oregon's routing data from 2009 to 2013, we detect 136 route leak events. Our evaluation shows that our scheme triggers no false positives, and most of these events are previously unknown to the research and operation communities at large. Shen Su, Beichuan Zhang 0001, Hongli Zhang 0001, Nathan Yee |
ICC | 1 |
| 2014 | Contention-based adaptive position update for intermittently connected VANETsabstractPosition information of nodes in vehicular ad hoc networks (VANETs) plays a key role in geographic routing. A sender or intermediate node employs position information of its neighbors and destination node to make routing decision. Under a greedy forwarding algorithm, the neighboring node closest to the destination node is selected as the next hop. Hence, it is critical in geographic routing to ensure that the selected next hop has a better position than other neighboring nodes. Position information is usually propagated to local nodes through periodical beaconing. In most geographic routing protocols, each node broadcasts beacons in a fixed interval, but this method can not always achieve both position accuracy and low overhead. In this paper, we propose a contention-based adaptive position update (CAPU) scheme for intermittently connected VANETs. CAPU concentrates on the position accuracy of the next hop when data transmission happens. If the position deviation of the next hop is greater than the permitted deviation range, the next hop updates its position. A special next hop timeout approach is proposed to find and delete the unreachable next hop as soon as possible. CAPU can find key nodes in local topology for greedy forwarding and intermittent connectivity. In addition, contention beacons broadcasted by key nodes maintain the local topology. Experimental results show that the proposed approach provides key position information for routing decision and exhibits better routing performance with acceptable overhead. Hongli Zhang 0001, Xiaojiang Du, Shen Su |
GLOBECOM | 5 |
| 2014 | Quantifying AS-level routing policy changesabstractTo study Internet's routing behavior on the granularity of Autonomous Systems (ASes), one needs to understand inter-domain routing policy. Routing policy changes over time, and may cause route oscillation, network congestion, and other problems. However, there are few works on routing policy changes and their impact on BGP's routing behaviors. In this paper, we model inter-domain routing policy as the preference to neighboring ASes, noted as neighbor preference, and propose an algorithm for quantifying routing policy changes based on neighbor preference. As a further analysis, we study the routing policy changes for the year of 2012, and find that generally an AS may experience a routing policy change for at least 20% prefixes within 6 months. An AS changes its routing policy mainly by exchanging two neighboring ASes' preference. In most cases, an AS changes a stable fraction of its prefixes' routing policy, but non-tier1 ASes may endure a large scale routing policy changing event. We also analyse the main reasons of routing policy changes, and exclude the possibilities of AS business relationship changes and topology changes. Shen Su, Hongli Zhang 0001, Binxing Fang |
ICC | 1 |
| 2014 | Online Detection of Concurrent Prefix Hijacks
Shen Su, Beichuan Zhang 0001, Binxing Fang |
SecureComm (2) | 1 |
| 2011 | A Framework to Quantify the Pitfalls of Using Traceroute in AS-Level Topology MeasurementabstractAlthough traceroute has the potential to discover AS links that are invisible to existing BGP monitors, it is well known that the common approach for mapping router IP addresses to AS numbers based on BGP routing tables is highly error-prone. We develop a systematic framework to quantify the potential errors of traceroute measurement in AS-level topology inference. In comparing traceroute-derived AS paths with BGP AS paths, we take a novel approach to identifying mismatched path segments and then inferring the causes of these mismatches through a set of tests. Our results show that about 60% of mismatches are due to routers using IP addresses belonging to peering neighbors. This result helps settle a debate in previous works regarding the major cause of errors in traceroute measurement. With the approximate ground truth of the ASes with BGP monitors inside, we identify the inaccuracy of publicly available traceroute-derived topology datasets and find that between 8% and 42% of AS adjacencies on the monitored ASes are false. With a new method to characterize AS links, we show that the derived (false) links between Tier-1/large ISPs and their customers' customers appear more frequently than real links do. Yu Zhang 0036, Ricardo V. Oliveira, Yangyang Wang 0001, Shen Su, Baobao Zhang, Jun Bi, Hongli Zhang 0001, Lixia Zhang 0001 |
IEEE J. Sel. Areas Commun. | 4 |