Sencun Zhu

dblp:40/2231 · DBLP profile ↗
← Back
134ranked-venue papers
12as first author
13since 2021 · last 2025
0000-0002-1047-7967ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 63 · 4 first-author · 7 since 2021Computer networks · 44 · 6 first-author · 2 since 2021Software engineering, systems software and programming languages · 8 · 1 since 2021Systems, architecture and hardware · 7 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 since 2021Databases, data management, data science and information retrieval · 5Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2025 Antitoxin: A Framework for Controlling Persistent Backdoors in Federated Learning
Neeraj Karamchandani, Piyush Nagasubramaniam, Dinghao Wu, Sencun Zhu
SecureComm (5)5
2024 PPTFI: Patch Presence Test for Function-Irrelevant Patches
abstract
In the past decades, downstream manufacturers often failed to timely adopt the security patches, resulting in some discovered vulnerabilities still posing serious risks. In the currently popular field of blockchain smart contracts, this is also a thorny issue. Although some new methods have been proposed to update and patch smart contracts deployed in blockchain networks, the binary codes of most vulnerable smart contracts are still being executed without patching. To detect the unpatched binaries as soon as possible, signature based patch presence tests and software similarity based patch presence tests have been proposed to check whether a certain patch is applied to the released software binaries. However, a large number of bug-fix patches are irrelevant to functions. They are small in size and only modify program entities other than functions. Existing signature-based patch detection methods and software similarity-based tools have limitations in detecting such patches. In this paper, we propose PPTFI, a patch presence test for function-irrelevant patches. PPTFI understands these patches and extracts code and data information as patch signatures for scanning target binaries. Being evaluated on 62 different versions of 31 real-world function-irrelevant patches and 512 binaries across 16 various compilation environments, PPTFI achieves an accuracy of 77.54%, significantly outperforming existing techniques.
Daojing He, Juzheng Zhang, Sencun Zhu, Sammy Chan
MSN4
2024 Automatically Identifying CVE Affected Versions With Patches and Developer Logs
abstract
While vulnerability databases are important sources of information for software security, it is known that information in these databases is inconsistent. How to rectify these incorrect data is a challenging issue. In this article, we employ developer logs and patches to automatically identify vulnerable source code versions that each CVE really affects. Our tool organizes all versions of a piece of software into a version tree, and identifies the first vulnerable version, and the last vulnerable versions in the version tree trunk and branches. For evaluation, we took Linux Kernel as the case study and quantified the error rate of the vulnerable versions reported by the NVD. The total number of vulnerable Linux Kernel versions reported by the NVD was 43,727 (as of September 2020), of which the total number of false positives reached 2,497 and the total number of false negatives reached 9,330, accounting for 5.7% and 21.34%, respectively. In addition, we compare our tool with two vulnerability detection tools and show that our tool could achieve high detection accuracy.
Sencun Zhu, Wei Wang 0012, Qiang Li 0007
IEEE Trans. Dependable Secur. Comput.3
2023 Password Cracking by Exploiting User Group Information
Beibei Zhou, Daojing He, Sencun Zhu, Sammy Chan
SecureComm (1)3
2023 HoneyIoT: Adaptive High-Interaction Honeypot for IoT Devices Through Reinforcement Learning
abstract
As IoT devices are becoming widely deployed, there exist many threats to IoT-based systems due to their inherent vulnerabilities. One effective approach to improving IoT security is to deploy IoT honeypot systems, which can collect attack information and reveal the methods and strategies used by attackers. However, building high-interaction IoT honeypots is challenging due to the heterogeneity of IoT devices. Vulnerabilities in IoT devices typically depend on specific device types or firmware versions, which encourages attackers to perform pre-attack checks to gather device information before launching attacks. Moreover, conventional honeypots are easily detected because their replying logic differs from that of the IoT devices they try to mimic.To address these problems, we develop an adaptive high-interaction honeypot for IoT devices, called em HoneyIoT. We first build a real device based attack trace collection system to learn how attackers interact with IoT devices. We then model the attack behavior through markov decision process and leverage reinforcement learning techniques to learn the best responses to engage attackers based on the attack trace. We also use differential analysis techniques to mutate response values in some fields to generate high-fidelity responses.HoneyIoT has been deployed on the public Internet. Experimental results show that HoneyIoT can effectively bypass the pre-attack checks and mislead the attackers into uploading malware. Furthermore, HoneyIoT is covert against widely used reconnaissance and honeypot detection tools.
Chongqi Guan, Heting Liu, Guohong Cao, Sencun Zhu, Thomas La Porta
WISEC4
2023 Enforcing Privacy Preservation on Edge Cameras Using Lightweight Video Frame Scrambling
abstract
Privacy protecting is a very challenging task in a highly surveilled world with zillions of surveillance cameras deployed. The difficulty mainly lies in the facts: (i) there is not a distinctively defined boundary between usability and privacy, (ii) video frames indiscriminately created and collected by the edge cameras could be abused and intercepted, and (iii) it is difficult to enforce the commonly used compute-intensive standard techniques as-is on the edge cameras because of limited computational resources. In this paper, we propose a lightweight and secure scheme to Enforce Privacy-preservation on Edge Cameras (EnPEC) using deep learning and a sinusoidal chaotic-map. The proposed EnPEC architecture comprises a lightweight frame classifier designed to label frames as offensive and harmless depending on their content to ensure the practice of selective surveillance following a frame approximation process and a novel sinusoidal-map-based chaotic image scrambling technique that enciphers frames color-channel wise to ensure end-to-end privacy of frame contents. The extensive analysis of the functionality, performance and security of the EnPEC scheme, and comparison with related works verify that the EnPEC scheme is more feasible, robust and secure when it runs in real-time on edge cameras equipped with computational power equivalent to the Raspberry PI 4.
Alem Fitwi, Yu Chen 0002, Sencun Zhu
IEEE Trans. Serv. Comput.3
2022 Toward Cleansing Backdoored Neural Networks in Federated Learning
abstract
Malicious clients can attack federated learning systems using compromised data during the training phase, including backdoor samples. The compromised global model will perform well on the validation dataset designed for the task, but a small subset of data with backdoor patterns may trigger the model to make a wrong prediction. In this work, we propose a new and effective method to mitigate backdoor attacks in federated learning after the training phase. Through federated pruning method, we remove redundant neurons and "backdoor neurons", which trigger misbehavior upon recognizing backdoor patterns while keeping silent when the input data is clean. The second optional fine-tuning process is designed to recover the pruning damage to the test accuracy on benign datasets. In the last step, we eliminate backdoor attacks by limiting the extreme values of inputs and neural network neurons’ weights. Experiments using our defenses mechanism against the state-of-the-art Distributed Backdoor Attacks on CIFAR-10 show promising results; the averaged attack success rate drops more than 70% with less than 2% loss of test accuracy on the validation dataset. Our defense method has also outperformed the state-of-the-art pruning defense against backdoor attacks in the federated learning scenario.
Xian Yang 0007, Sencun Zhu, Prasenjit Mitra 0001
ICDCS3
2022 ZoomP3: Privacy-Preserving Publishing of Online Video Conference Recordings
abstract
The COVID-19 epidemic has made online video conferencing extremely popular throughout the world, with many schools, companies and government sectors using video conferencing applications (e.g., Zoom, Google Meet) in a daily basis. These applications also provide local or cloud recording services, which allow the replay or sharing of video conference recordings (VCRs) in a later time. Such convenience, however, can easily cause infringement of privacy as meeting participants’ personally identifiable information (e.g., face, name, voice) may be exposed to the public without their awareness or consent. While privacy regulation and training can help relieve the situation, efficient and effective tools are also highly desired to protect the privacysensitive users in the VCRs before their public releases. In this work, we propose the first Privacy-Preserving Publishing system (ZoomP3 ) that automatically processes video and audio information in VCRs for privacy protection. Besides leveraging and integrating multiple state-of-the-art computer vision and audio processing tools seamlessly into our system, a number of optimization algorithms are proposed to improve the scalability of the system, enabling it to protect the privacy of long video conferences. We have conducted various tests with short and long videos, and the results (with online demos) verified that ZoomP3 system is suitable for largescale use. It may be applied as an online service, e.g., by Zoom, or by large organizations such as universities, research institutes and government sectors.
Yuanyi Sun, Sencun Zhu, Yu Chen 0002
Proc. Priv. Enhancing Technol.2
2021 Recompose Event Sequences vs. Predict Next Events: A Novel Anomaly Detection Approach for Discrete Event Logs
abstract
One of the most challenging problems in the field of intrusion detection is anomaly detection for discrete event logs. While most earlier work focused on applying unsupervised learning upon engineered features, most recent work has started to resolve this challenge by applying deep learning methodology to abstraction of discrete event entries. Inspired by natural language processing, LSTM-based anomaly detection models were proposed. They try to predict upcoming events, and raise an anomaly alert when a prediction fails to meet a certain criterion. However, such a predict-next-event methodology has a fundamental limitation: event predictions may not be able to fully exploit the distinctive characteristics of sequences. This limitation leads to high false positives (FPs). It is also critical to examine the structure of sequences and the bi-directional causality among individual events. To this end, we propose a new methodology: Recomposing event sequences as anomaly detection. We propose DabLog, a LSTM-based Deep Autoencoder-Based anomaly detection method for discrete event Logs. The fundamental difference is that, rather than predicting upcoming events, our approach determines whether a sequence is normal or abnormal by analyzing (encoding) and reconstructing (decoding) the given sequence. Our evaluation results show that our new methodology can significantly reduce the numbers of FPs, hence achieving a higher F1 score.
Lun-Pin Yuan, Peng Liu 0005, Sencun Zhu
AsiaCCS3
2021 Time-Window Based Group-Behavior Supported Method for Accurate Detection of Anomalous Users
abstract
Autoencoder-based anomaly detection methods have been used in identifying anomalous users from large-scale enterprise logs with the assumption that adversarial activities do not follow past habitual patterns. Most existing approaches typically build models by reconstructing single-day and individual-user behaviors. However, without capturing long-term signals and group-correlation signals, the models cannot identify low-signal yet long-lasting threats, and will wrongly report many normal users as anomalies on busy days, which, in turn, lead to high false positive rate. In this paper, we propose ACOBE, an Anomaly detection method based on COmpound BEhavior, which takes into consideration long-term patterns and group behaviors. ACOBE leverages a novel behavior representation and an ensemble of deep autoencoders and produces an ordered investigation list. Our evaluation shows that ACOBE outperforms prior work by a large margin in terms of precision and recall, and our case study demonstrates that ACOBE is applicable in practice for cyberattack detection.
Lun-Pin Yuan, Euijin Choo, Ting Yu 0001, Issa M. Khalil, Sencun Zhu
DSN5
2021 A Large-Scale Study of Android Malware Development Phenomenon on Public Malware Submission and Scanning Platform
abstract
With the steady growth of Android malware, we suspect that, during the malware development phase, some Android malware writers use the popular public scanning services (e.g., VirusTotal) for testing the evasion capability of their malware samples, which we name Android malware development cases (AMDs). In this work, we design an AMD hunter in the context of VirusTotal to hunt for AMDs and reveal new threats for Android. First, the AMD hunter sifts through millions of file submissions on VirusTotal efficiently and alert more suspicious submission traces. Second, it performs package level analysis, static code and dynamic analyses on the APKs of the suspicious submissions to validate the AMDs. The implemented hunter has been used in a leading security company for 4 months, which processed 153 million of submissions on VirusTotal, and identified 1,623 AMDs with 13,855 samples from 83 countries. We also performed case studies on 890 malware samples selected from the identified AMDs, which revealed lots of new threats, including the development cases of fake system/banking phishing app, new rooting exploits, new JavaScript based threats, new evasions and AV probing malware. We wrote industry research articles about some AMDs and notified other security vendors to help patch their false negatives. Besides raising the awareness of the existence of AMDs, more importantly, our research provides the first systematic and efficient way to study the malware development phenomenon on VirusTotal. We will share all the samples of the identified AMDs with the research community.
Heqing Huang 0001, Cong Zheng, Junyuan Zeng, Sencun Zhu, Peng Liu 0005, Ian M. Molloy, Suresh Chari, Ce Zhang 0001, Quanlong Guan
IEEE Trans. Big Data5
2021 Towards Automatic Detection of Nonfunctional Sensitive Transmissions in Mobile Applications
abstract
While mobile apps often need to transmit sensitive information out to support various functionalities, they may also abuse the privilege by leaking the data to unauthorized third parties. This makes us question: Is the given transmission required to fulfill the app functionality? In this paper, we make the first attempt to automatically identify suspicious transmissions from app visual interfaces, including app names, descriptions, and user interfaces. We design and implement a novel framework called FlowIntent to detect nonfunctional transmissions at both software and network levels. During the exercising of the given apps, FlowIntent automatically detects privacy-sharing transmissions and determines their purposes by utilizing the fact that mobile users rely on visible app interface to perceive the functionality of the app at certain context. The characterizations of nonfunctional network traffic are then summarized to provide network level protection. FlowIntent not only reduces the false alarms caused by traditional taint analysis, but also captures the sensitive transmissions missed by widely-used taint analysis system TaintDroid. Evaluation using 2125 sharing flows collected from more than a thousand running instances shows that our approach achieves about 94 percent accuracy in detecting nonfunctional transmissions.
Hao Fu 0003, Pengfei Hu 0001, Zizhan Zheng, Aveek K. Das, Parth H. Pathak, Tianbo Gu, Sencun Zhu, Prasant Mohapatra
IEEE Trans. Mob. Comput.7
2021 Dynamic Control of Fraud Information Spreading in Mobile Social Networks
abstract
Mobile social networks (MSNs) provide real-time information services to individuals in social communities through mobile devices. However, due to their high openness and autonomy, MSNs have been suffering from rampant rumors, fraudulent activities, and other types of misuses. To mitigate such threats, it is urgent to control the spread of fraud information. The research challenge is: how to design control strategies to efficiently utilize limited resources and meanwhile minimize individuals' losses caused by fraud information? To this end, we model the fraud information control issue as an optimal control problem, in which the control resources consumption for implementing control strategies and the losses of individuals are jointly taken as a constraint called total cost, and the minimum total cost becomes the objective function. Based on the optimal control theory, we devise the optimal dynamic allocation of control strategies. Besides, a dynamics model for fraud information diffusion is established by considering the uncertain mental state of individuals, we investigate the trend of fraud information diffusion and the stability of the dynamics model. Our simulation study shows that the proposed optimal control strategies can effectively inhibit the diffusion of fraud information while incurring the smallest total cost. Compared with other control strategies, the control effect of the proposed optimal control strategies is about 10% higher.
Yaguang Lin, Xiaoming Wang 0001, Fei Hao 0001, Yichuan Jiang, Yulei Wu, Geyong Min, Daojing He, Sencun Zhu, Wei Zhao 0001
IEEE Trans. Syst. Man Cybern. Syst.8
2020 Backdoor Embedding in Convolutional Neural Network Models via Invisible Perturbation
abstract
Deep learning models have consistently outperformed traditional machine learning models in various classification tasks, including image classification. As such, they have become increasingly prevalent in many real world applications including those where security is of great concern. Such popularity, however, may attract attackers to exploit the vulnerabilities of the deployed deep learning models and launch attacks against security-sensitive applications. In this paper, we focus on a specific type of data poisoning attack, which we refer to as a \em backdoor injection attack. The main goal of the adversary performing such attack is to generate and inject a backdoor into a deep learning model that can be triggered to recognize certain embedded patterns with a target label of the attacker's choice. Additionally, a backdoor injection attack should occur in a stealthy manner, without undermining the efficacy of the victim model. Specifically, we propose two approaches for generating a backdoor that is hardly perceptible yet effective in poisoning the model. We consider two attack settings, with backdoor injection carried out either before model training or during model updating. We carry out extensive experimental evaluations under various assumptions on the adversary model, and demonstrate that such attacks can be effective and achieve a high attack success rate (above 90%) at a small cost of model accuracy loss with a small injection rate, even under the weakest assumption wherein the adversary has no knowledge either of the original training data or the classifier model.
Haoti Zhong, Cong Liao, Anna Cinzia Squicciarini, Sencun Zhu, David J. Miller 0001
CODASPY4
2020 Hybrid Intrusion Detection Mechanisms for Integrated Electronic Systems
abstract
While integrated electronic systems (IESs) are widely used in military and civilian applications, their security issues are barely studied. By analyzing the architecture of the system and the characteristics of bus communication, this paper proposes an intrusion detection method based on the message sequence and behavioral rules of subsystems. According to the bus protocol, messages are divided into periodic and aperiodic messages. For the previous, we adopt sequence analysis and propose an algorithm that extract the sequence intelligently to determine if there are anomalies. For aperiodic messages, we detect the anomalies by modeling the system behaviors as decision trees. Through implementing experiments on our simulation system, we demonstrate that the proposed detection is more accurate than the existing schemes while incurring both lower false negative rate and lower false positive rate.
Qi Qiao, Daojing He, Sencun Zhu, Jiahao Gao, Sammy Chan
SECON4
2020 TLP-IDS: A Two-layer Intrusion Detection System for Integrated Electronic Systems
abstract
With the increasing applications of integrated electronic systems (IESs), especially in security critical application scenarios like satellites and aircraft, new vulnerabilities and attacks have emerged recently. To detect the attacks, we propose TLP-IDS, a real-time intrusion detection system (IDS). TLP-IDS includes two layers of detection modules, one based on time and sequence logic and the other based on historical data. For the modules in the first layer, periodic and aperiodic messages are distinguished based on variations of message intervals, and we learnd from the idea of Markov decision process (MDP) in reinforcement learning (RL) to automatically learn the logical relationship between sequences. In the second layer, an online sequence extreme learning machine (OS-ELM) method is deployed to fit the data and further combined with the Weibull distribution function for prediction and detection. To evaluate our system, we implement several attack scenarios on a test bed, and measure the detection performance. Experimental results show that our system can quickly and effectively detect various attacks.
Daojing He, Sencun Zhu, Sammy Chan
SRDS4
2020 iRyP: a purely edge-based visual privacy-respecting system for mobile cameras
abstract
With the growing popularity of mobile devices that have built-in cameras, capturing images has become a trivial job for ordinary people, who share the images with their friends or the public online. However, such digital images are often taken without the consent of some photographed persons, hence leading to privacy concerns. In this paper, we propose iRyP, a purely edge-based privacy-respecting system for mobile cameras. In order to meet the requirements of efficiency and usability, we propose to piggyback privacy policies in the advertising messages of Bluetooth Low Energy (BLE), which has been widely deployed in most mobile devices. As such, privacy policies of people in a photo view can be delivered timely and automatically. Moreover, we propose to use a perceptual hashing algorithm for fast face matching. To improve detection accuracy, we also design several new techniques for face-related image processing. We implement and evaluate a prototype system purely based on the Android platform. Our experiments show that iRyP can meet our design requirements and is practical and ready to use.
Yuanyi Sun, Shiqing Chen, Sencun Zhu, Yu Chen 0002
WISEC3
2020 Understanding the Manipulation on Recommender Systems through Web Injection
abstract
Recommender systems have been increasingly used in a variety of web services, providing a list of recommended items in which a user may have an interest. While important, recommender systems are vulnerable to various malicious attacks. In this paper, we study a new security vulnerability in recommender systems caused byweb injection, through which malicious actors stealthily tamper any unprotected in-transit HTTP webpage content and force victims to visit specific items in some web services (even running HTTPS),e.g., YouTube. By doing so, malicious actors can promote their targeted items in those web services. To obtain a deeper understanding on the recommender systems of our interest (including YouTube, Yelp, Taobao, and 360 App market), we first conduct a measurement-based analysis on several real-world recommender systems by leveraging machine learning algorithms. Then, web injection is implemented in three different types of devices (i.e., computer, router, and proxy server) to investigate the scenarios where web injection could occur. Based on the implementation of web injection, we demonstrate that it is feasible and sometimes effective to manipulate the real-world recommender systems through web injection. We also present several countermeasures against such manipulations.
Yubao Zhang, Jidong Xiao, Shuai Hao 0001, Haining Wang 0001, Sencun Zhu, Sushil Jajodia
IEEE Trans. Inf. Forensics Secur.5
2020 Privacy Risk Analysis and Mitigation of Analytics Libraries in the Android Ecosystem
abstract
While much effort has been made to detect and measure the privacy leakage caused by the advertising (ad) libraries integrated in mobile applications, analytics libraries, which are also widely used in mobile apps have not been systematically studied for their privacy risks. Different from ad libraries, the main function of analytics libraries is to collect users' in-app actions. Hence, by design analytics libraries are more likely to leak users' private information. In this work, we study what information is collected by the analytics libraries integrated in popular Android apps. We design and implement a framework called “Alde”. Given an app, Alde employs both static analysis and dynamic analysis to detect the users' in-app actions collected by analytics libraries. We also study what private information can be leaked by the apps that use the same analytics library. Moreover, we analyze apps' privacy policies to see whether app developers have notified the users that their in-app action data is collected by analytics libraries. Finally, we select eight widely used analytics libraries to study and apply our method to 300 popular apps downloaded from both Chinese app markets and Google play. Our experimental results show that some apps indeed leak users' personal information through analytics libraries even though their genuine purposes of using analytics services are legal. To mitigate such threats, we have developed an app named “ALManager” that leverages the Xposed framework to manage analytics libraries in other apps.
Jiqiang Liu, Sencun Zhu, Wei Wang 0012, Xiangliang Zhang 0001
IEEE Trans. Mob. Comput.3
2019 Errors, Misunderstandings, and Attacks: Analyzing the Crowdsourcing Process of Ad-blocking Systems
abstract
Ad-blocking systems such as Adblock Plus rely on crowdsourcing to build and maintain filter lists, which are the basis for determining which ads to block on web pages. In this work, we seek to advance our understanding of the ad-blocking community as well as the errors and pitfalls of the crowdsourcing process. To do so, we collected and analyzed a longitudinal dataset that covered the dynamic changes of popular filter-list EasyList for nine years and the error reports submitted by the crowd in the same period.
Mshabab Alrizah, Sencun Zhu, Xinyu Xing 0001, Gang Wang 0011
Internet Measurement Conference2
2019 Keeping Context In Mind: Automating Mobile App Access Control with User Interface Inspection
abstract
Recent studies observe that app foreground is the most striking component that influences the access control decisions in mobile platform, as users tend to deny permission requests lacking visible evidence. However, none of the existing permission models provides a systematic approach that can automatically answer the question: Is the resource access indicated by app foreground? In this work, we present the design, implementation, and evaluation of COSMOS, a context-aware mediation system that bridges the semantic gap between foreground interaction and background access, in order to protect system integrity and user privacy. Specifically, COSMOS learns from a large set of apps with similar functionalities and user interfaces to construct generic models that detect the outliers at runtime. It can be further customized to satisfy specific user privacy preference by continuously evolving with user decisions. Experiments show that COSMOS achieves both high precision and high recall in detecting malicious requests. We also demonstrate the effectiveness of COSMOS in capturing specific user preferences using the decisions collected from 24 users and illustrate that COSMOS can be easily deployed on smartphones as a real-time guard with a very low performance overhead.
Hao Fu 0003, Zizhan Zheng, Sencun Zhu, Prasant Mohapatra
INFOCOM3
2019 Towards Large-Scale Hunting for Android Negative-Day Malware
Lun-Pin Yuan, Ting Yu 0001, Peng Liu 0005, Sencun Zhu
RAID5
2019 Protecting mobile devices from physical memory attacks with targeted encryption
abstract
Sensitive data in a process could be scattered over the memory of a computer system for a prolonged period of time. Unfortunately, DRAM chips were proven insecure in previous studies. The problem becomes worse in the mobile environment, in which users' smartphones are easily lost or stolen. The powered-on phones may contain sensitive data in the vulnerable DRAM chips. In this paper, we propose MemVault, a mechanism to protect sensitive data in Android devices against physical memory attacks. MemVault keeps track of the propagation of well-marked sensitive data sources, and selectively encrypts tainted sensitive memory contents in the DRAM chip. When a tainted object is accessed, MemVault redirects the access to the internal RAM (iRAM), where the cipher-text object is decrypted transparently. iRAM is a system-on-chip (SoC) component which is by nature immune to physical memory exploits. We have implemented a MemVault prototype system, and have evaluated it with extensive experiments. Our results validate that MemVault effectively eliminates the occurrences of clear-text sensitive objects in DRAM chips, and imposes acceptable overheads.
Le Guan, Chen Cao 0004, Sencun Zhu, Jingqiang Lin 0001, Peng Liu 0005, Yubin Xia, Bo Luo
WiSec3
2019 Automated Hybrid Analysis of Android Malware through Augmenting Fuzzing with Forced Execution
abstract
Automatically triggering malicious behaviors is an essential step to understand malware for developing effective solutions. Existing automated dynamic analysis approaches usually try to trigger the malicious behaviors by relying on simple fuzzing or complex input generation techniques (e.g., concolic execution). However, advanced malware often adopt various evasion techniques to hide malicious behaviors, e.g., by introducing complex condition checks which are very hard to trigger. In this paper, we propose a new approach named DirectDroid, which bypasses related checks through on-demand forced execution while adopting fuzzingto feed the necessary program input. In this way, many hidden malicious behaviors can be successfully triggered. To ensure the normal execution towards the malicious behaviors, DirectDroid also largely handles potential program crashes caused by forced execution. Finally, we implement a prototype of DirectDroid and evaluate it against 951 recent malware samples. Our experiment results show that DirectDroid can trigger many more malicious behaviors than several previous works, even when crashes happened. Our further analysis shows that DirectDroid has a low false positive rate even though it adopts forced execution.
Xiaolei Wang 0003, Yuexiang Yang, Sencun Zhu
IEEE Trans. Mob. Comput.3
2018 Server-Based Manipulation Attacks Against Machine Learning Models
abstract
Machine learning approaches have been increasingly applied to various applications for data analytics (e.g. spam filtering, image classification). Further, with the growing adoption of cloud computing, various cloud services have provided an efficient way for users to train, store or deploy machine learning algorithms in an easy-to-use manner. However, the models deployed in the cloud may be exposed to potential malicious attacks launched at the server side. Attackers with access to the server can stealthily manipulate a machine learning model so as to enable misclassification or introduce bias. In this work, we study the problem of manipulation attacks as they occur at the server side. We consider not only traditional supervised learning models but also state-of-the-art deep learning models. In particular, a simple but effective gradient descent based approach is presented to exploit Logistic Regression (LR) and Convolutional Neural Networks (CNN) [16] models. We evaluate manipulation attacks against machine learning or deep learning systems using both Enron email text and MINIST image dataset [17]. Experimental results have demonstrated such attacks can manipulate the model that allows malicious samples to evade detection easily without compromising the overall performance of the systems.
Cong Liao, Haoti Zhong, Sencun Zhu, Anna Cinzia Squicciarini
CODASPY3
2018 Assessing Attack Impact on Business Processes by Interconnecting Attack Graphs and Entity Dependency Graphs
Chen Cao 0004, Lun-Pin Yuan, Anoop Singhal, Peng Liu 0005, Xiaoyan Sun 0003, Sencun Zhu
DBSec6
2018 Android STAR: An Efficient Interaction-Preserving Record-Replay System For Messenger App Usage Surveillance
abstract
Messenger apps on smart phones are widely used for easy communication in a collaborative workplace. However, the use of messengers increases risks to both the organization and the collaborators. For example, an employee may receive proprietary information from one app and then accidentally leak it with another app, but neither the employer nor the employee can effectively prove or disprove what has happened inside messengers. To prove mental elements in a lawsuit, the capability of inspecting the use of messengers in a workplace is desirable to both parties: one can prove misconduct and the other can prove innocence. Yet, guilty intention is subtle if not literally described, and how to prove whether there was a guilty intention has not yet been resolved. To provide new kind of evidence, we propose Android STAR, an inspection-purposed record-and-replay service that replays conversation histories and user interactions with apps. We assume that the employer has obtained consents of employees, and the employees have installed Android STAR in their company devices. The challenge to app-usage inspection includes app variety and evidence veracity. We evaluate STAR with 10 popular messenger apps (including Telegram, LINE, and WeChat). Our results show that while STAR can replay in high-fidelity, it only introduces small performance overhead.
Lun-Pin Yuan, Peng Liu 0005, Sencun Zhu
WISEC3
2018 Android single sign-on security: Issues, taxonomy and directions
Jiqiang Liu, Wei Wang 0012, Sencun Zhu
Future Gener. Comput. Syst.4
2017 Droid-AntiRM: Taming Control Flow Anti-analysis to Support Automated Dynamic Analysis of Android Malware
abstract
While many test input generation techniques have been proposed to improve the code coverage of dynamic analysis, they are still inefficient in triggering hidden malicious behaviors protected by anti-analysis techniques. In this work, we design and implement Droid-AntiRM, a new approach seeking to tame anti-analysis automatically and improve automated dynamic analysis. Our approach leverages three key observations: 1) Logic-bomb based anti-analysis techniques control the execution of certain malicious behaviors; 2) Anti-analysis techniques are normally implemented through condition statements; 3) Anti-analysis techniques normally have no dependence on program inputs. Based on these observations, Droid-AntiRM uses various techniques to detect anti-analysis in malware samples, and rewrite the condition statements in anti-analysis cases through bytecode instrumentation, thus forcing the hidden behavior to be executed at runtime. Through a study of 3187 malware samples, we find that 32.50% of them employ various anti-analysis techniques. Our experiments demonstrate that Droid-AntiRM can identify anti-analysis instances from 30 malware samples with a true positive rate of 89.15% and zero false negative. By taming the identified anti-analysis, Droid-AntiRM can greatly improve the automated dynamic analysis, successfully triggering 44 additional hidden malicious behaviors from the 30 samples. Further performance evaluation shows that Droid-AntiRM has good efficiency to perform large-scale analysis.
Xiaolei Wang 0003, Sencun Zhu, Dehua Zhou, Yuexiang Yang
ACSAC2
2017 Toward Detecting Collusive Ranking Manipulation Attackers in Mobile App Markets
abstract
Incentivized by monetary gain, some app developers launch fraudulent campaigns to boost their apps' rankings in the mobile app stores. They pay some service providers for boost services, which then organize large groups of collusive attackers to take fraudulent actions such as posting high app ratings or inflating apps' downloads. If not addressed timely, such attacks will increasingly damage the healthiness of app ecosystems. In this work, we propose a novel approach to identify attackers of collusive promotion groups in an app store. Our approach exploits the unusual ranking change patterns of apps to identify promoted apps, measures their pairwise similarity, forms targeted app clusters (TACs), and finally identifies the collusive group members. Our evaluation based on a dataset of Apple's China App store has demonstrated that our approach is able and scalable to report highly suspicious apps and reviewers. App stores may use our techniques to narrow down the suspicious lists for further investigation.
Daojing He, Sencun Zhu, Jingshun Yang
AsiaCCS3
2017 WindowGuard: Systematic Protection of GUI Security in Android
Chuangang Ren, Peng Liu 0005, Sencun Zhu
NDSS3
2017 A software assignment algorithm for minimizing worm damage in networked systems
Chu Huang, Sencun Zhu, Quanlong Guan
J. Inf. Secur. Appl.2
2017 Semantics-Based Obfuscation-Resilient Binary Code Similarity Comparison with Applications to Software and Algorithm Plagiarism Detection
abstract
Existing code similarity comparison methods, whether source or binary code based, are mostly not resilient to obfuscations. Identifying similar or identical code fragments among programs is very important in some applications. For example, one application is to detect illegal code reuse. In the code theft cases, emerging obfuscation techniques have made automated detection increasingly difficult. Another application is to identify cryptographic algorithms which are widely employed by modern malware to circumvent detection, hide network communications, and protect payloads among other purposes. Due to diverse coding styles and high programming flexibility, different implementation of the same algorithm may appear very distinct, causing automatic detection to be very hard, let alone code obfuscations are sometimes applied. In this paper, we propose a binary-oriented, obfuscation-resilient binary code similarity comparison method based on a new concept, longest common subsequence of semantically equivalent basic blocks , which combines rigorous program semantics with longest common subsequence based fuzzy matching. We model the semantics of a basic block by a set of symbolic formulas representing the input-output relations of the block. This way, the semantic equivalence (and similarity) of two blocks can be checked by a theorem prover. We then model the semantic similarity of two paths using the longest common subsequence with basic blocks as elements. This novel combination has resulted in strong resiliency to code obfuscation. We have developed a prototype. The experimental results show that our method can be applied to software plagiarism and algorithm detection, and is effective and practical to analyze real-world software.
Lannan Luo, Jiang Ming 0002, Dinghao Wu, Peng Liu 0005, Sencun Zhu
IEEE Trans. Software Eng.5
2016 You can promote, but you can't hide: large-scale abused app detection in mobile app stores
Sencun Zhu, Qing Li 0063
ACSAC2
2016 Android malware development on public malware scanning platforms: A large-scale data-driven study
abstract
Android malware scanning services (e.g., VirusTotal) are websites that users submit suspicious Android programs and get an array of malware detection results. With the growing popularity of such websites, we suspect that, these services are not only used by innocent users, but also, malware writers for testing the evasion capability of their malware samples. May this hypothesis be true, it not only provides interesting insight on Android malware development (AMD), but also provides opportunities for important security applications such as zero-day sample detection. In this work, we first validate this hypothesis with massive data; then design a system AMDHunter to hunt for AMDs on VirusTotal that reveals new threats for Android that has never been revealed before. This is the first systematic study of the malware development phenomenon on VirusTotal, and the first system to automatically detect such malware development cases. AMDHunter has been used in a leading security company for months. Our study is driven by the large amount of data on VirusTotal- We analyzed 153 million submissions collected on VirusTotal during 102 days. Our system identifies 1,623 AMDs with 13,855 samples from 83 countries. We also performed case studies on 890 malware samples selected from the identified AMDs, which revealed lots of new threats, e.g., the development cases of fake system/banking phishing malware, new rooting exploits and etc.
Heqing Huang 0001, Cong Zheng, Junyuan Zeng, Sencun Zhu, Peng Liu 0005, Suresh Chari, Ce Zhang 0001
IEEE BigData5
2016 Repackage-Proofing Android Apps
abstract
App repackaging has become a severe threat to theAndroid ecosystem. While various protection techniques, such as watermarking and repackaging detection, have been proposed, a defense that stops repackaged apps from working on user devices, i.e., repackage-proofing, is missing. We propose a technique that builds a reliable and stealthy repackage-proofing capability into Android apps. A large number of detection nodes are inserted into the original app without incurring much overhead, each is woven into the surrounding code to blur itself. Once repackaging is detected, a response node injects a failure in the form of delayed malfunctions, making it difficult to trace back. The response nodes and detection nodes form high-degree connections and communicate through stealthy communication channels, such that upon detection several of the many response nodes are selected stochastically to take actions, which further obfuscates and enhances the protection. We have built a prototype. The evaluation shows that the technique is effective and efficient.
Lannan Luo, Dinghao Wu, Sencun Zhu, Peng Liu 0005
DSN4
2016 Alde: Privacy Risk Analysis of Analytics Libraries in the Android Ecosystem
Sencun Zhu, Wei Wang 0012, Jiqiang Liu
SecureComm2
2016 Improving sensor network immunity under worm attacks: A software diversity approach
Yi Yang 0002, Sencun Zhu, Guohong Cao
Ad Hoc Networks2
2016 Deviation-Based Obfuscation-Resilient Program Equivalence Checking With Application to Software Plagiarism Detection
abstract
Software plagiarism, an act of illegally copying others' code, has become a serious concern for honest software companies and the open source community. Considerable research efforts have been dedicated to searching the evidence of software plagiarism. In this paper, we continue this line of research and propose LoPD, a deviation-based program equivalence checking approach, which is an ideal fit for the whole-program plagiarism detection. Instead of directly comparing the similarity between two programs, LoPD searches for any dissimilarity between two programs by finding an input that will cause these two programs to behave differently, either with different output states or with semantically different execution paths. As long as we can find one dissimilarity, the programs are semantically different; but if we cannot find any dissimilarity, it is more likely a plagiarism case. We leverage dynamic symbolic execution to capture the semantics of execution paths and to find path deviations. Compared to the existing detection approaches, LoPD's formal program semantics-based method is more resilient to automatic obfuscation schemes. Our evaluation results indicate that LoPD is effective in detecting whole-program plagiarism. Furthermore, we demonstrate that LoPD can be applied to partial software plagiarism detection as well. The encouraging experiment results show that LoPD is an appealing complement to existing software plagiarism detection approaches.
Jiang Ming 0002, Fangfang Zhang 0005, Dinghao Wu, Peng Liu 0005, Sencun Zhu
IEEE Trans. Reliab.5
2015 Towards Discovering and Understanding Unexpected Hazards in Tailoring Antivirus Software for Android
abstract
In its latest comparison of Android Virus Detectors (AVDs), the independent lab AV-TEST reports that they have around 95% malware detection rate. This only indicates that current AVDs on Android have good malware signature databases. When the AVDs are deployed on the fast-evolving mobile system, their effectiveness should also be measured on their runtime behavior. Therefore, we perform a comprehensive analysis on the design of top 30 AVDs tailored for Android. Our new understanding of the AVDs' design leads us to discover the hazards in adopting AVD solutions for Android, including hazards in malware scan (malScan) mechanisms and the engine update (engineUpdate). First, the malScan mechanisms of all the analyzed AVDs lack comprehensive and continuous scan coverage. To measure the seriousness of the identified hazards, we implement targeted evasions at certain time (e.g., end of the scan) and locations (certain folders) and find that the evasions can work even under the assumption that the AVDs are equipped with "complete" virus definition files. Second, we discover that, during the engineUpdate, the Android system surprisingly nullifies all types of protections of the AVDs and renders the system for a period of high risk. We confirmed the presence of this vulnerable program logic in all versions of Google Android source code and other vendor customized system images.
Heqing Huang 0001, Kai Chen 0012, Chuangang Ren, Peng Liu 0005, Sencun Zhu, Dinghao Wu
AsiaCCS5
2015 From System Services Freezing to System Server Shutdown in Android: All You Need Is a Loop in an App
abstract
The Android OS not only dominates 78.6% of the worldwide smartphone market in 2014, but importantly has been widely used for mission critical tasks (e.g., medical devices, auto/aircraft navigators, embedded in satellite project). The core of Android, System Server (SS), is a multi-threaded process that contains most of the system services and provides the essential functionalities to support applications (apps). Considering the complicated design of the SS and its easily-accessible system services (e.g., via Android APIs), we conjecture that the SS may face DoS attacks. As the SS plays the important role in Android, serious DoS attacks could cause single-point-of-failure to the phone system. By studying the source code, we discovered a general design trait in the concurrency control mechanism of the SS that could be vulnerable to DoS attacks. To validate our hypothesis, we design a tool to cost efficiently explore high-risk methods in the SS. After a systematic analysis of 2,154 candidate-risky methods, we found four unknown vulnerabilities in critical services (e.g., the ActivityManager and the WindowManager), which are named the Android Stroke Vulnerabilities ({\it ASVs}). Exploiting the ASVs would continuously block all other requests for system services, followed by killing the SS and soft-rebooting the OS. Results of a further threat analysis show that by writing a loop to invoke Android APIs in an app, an attacker can continually freeze (reboot) the device at targeted critical moments (e.g., when patching vulnerable apps). Furthermore, ASVs can be exploited to enhance malware with anti-removal capability or to design the ransomware by putting the devices into continuous DoS loops. After being informed, Google confirmed our findings promptly. We also proposed to their Android framework team several improvements in their concurrency control design and a fine-grained failure recovery mechanism for the SS.
Heqing Huang 0001, Sencun Zhu, Kai Chen 0012, Peng Liu 0005
CCS2
2015 SemaDroid: A Privacy-Aware Sensor Management Framework for Smartphones
abstract
While mobile sensing applications are booming, the sensor management mechanisms in current smartphone operating systems are left behind -- they are incomprehensive and coarse-grained, exposing a huge attack surface for malicious or aggressive third party apps to steal user's private information through mobile sensors.
Zhi Xu 0004, Sencun Zhu
CODASPY2
2015 DroidJust: automated functionality-aware privacy leakage analysis for Android applications
abstract
Android applications (apps for short) can send out users' sensitive information against users' intention. Based on the stats from Genome and Mobile-Sandboxing, 55.8% and 59.7% Android malware families feature privacy leakage. Prior approaches to detecting privacy leakage on smartphones primarily focused on the discovery of sensitive information flows. However, Android apps also send out users' sensitive information for legitimate functions. Due to the fuzzy nature of the privacy leakage detection problem, we formulate it as a justification problem, which aims to justify if a sensitive information transmission in an app serves any purpose, either for intended functions of the app itself or for other related functions. This formulation makes the problem more distinct and objective, and therefore more feasible to solve than before. We propose DroidJust, an automated approach to justifying an app's sensitive information transmission by bridging the gap between the sensitive information transmission and application functions. We also implement a prototype of DroidJust and evaluate it with over 6000 Google Play apps and over 300 known malware collected from VirusTotal. Our experiments show that our tool can effectively and efficiently analyze Android apps w.r.t their sensitive information flows and functionalities, and can greatly assist in detecting privacy leakage.
Sencun Zhu
WISEC2
2015 AppWatcher: unveiling the underground market of trading mobile app reviews
abstract
Driven by huge monetary reward, some mobile application (app) developers turn to the underground market to buy positive reviews instead of doing legal advertisements. These promotion reviews are either directly posted in app stores like iTunes and Google Play, or published on some popular websites that have many app users. Until now, a clear understanding of this app promotion underground market is still lacking. In this work, we focus on unveiling this underground market and statistically analyzing the promotion incentives, characteristics of promoted apps and suspicious reviewers. To collect promoted apps, we built an automatic data collection system, AppWatcher, which monitored 52 paid review service providers for four months and crawled all the app metadata from their corresponding app stores. Finally, AppWatcher exposes 645 apps promoted in app stores and 29, 680 apps promoted in some popular websites. The current underground market is then reported from various perspectives (e.g., service price, app volume). We identified some interesting features of both promoted apps and suspicious reviewers, which are significantly different from those of randomly chosen apps. Finally, we built a simple tracer to narrow down the suspect list of promoted apps in the underground market.
Sencun Zhu
WISEC2
2015 Program Characterization Using Runtime Values and Its Application to Software Plagiarism Detection
abstract
Illegal code reuse has become a serious threat to the software community. Identifying similar or identical code fragments becomes much more challenging in code theft cases where plagiarizers can use various automated code transformation or obfuscation techniques to hide stolen code from being detected. Previous works in this field are largely limited in that (i) most of them cannot handle advanced obfuscation techniques, and (ii) the methods based on source code analysis are not practical since the source code of suspicious programs typically cannot be obtained until strong evidences have been collected. Based on the observation that some critical runtime values of a program are hard to be replaced or eliminated by semantics-preserving transformation techniques, we introduce a novel approach to dynamic characterization of executable programs. Leveraging such invariant values, our technique is resilient to various control and data obfuscation techniques. We show how the values can be extracted and refined to expose the critical values and how we can apply this runtime property to help solve problems in software plagiarism detection. We have implemented a prototype with a dynamic taint analyzer atop a generic processor emulator. Our value-based plagiarism detection method (VaPD) uses the longest common subsequence based similarity measuring algorithms to check whether two code fragments belong to the same lineage. We evaluate our proposed method through a set of real-world automated obfuscators. Our experimental results show that the value-based method successfully discriminates 34 plagiarisms obfuscated by SandMark, plagiarisms heavily obfuscated by KlassMaster, programs obfuscated by Thicket, and executables obfuscated by Loco/Diablo.
Yoon-chan Jhi, Xiaoqi Jia, Sencun Zhu, Peng Liu 0005, Dinghao Wu
IEEE Trans. Software Eng.4
2014 Toward Software Diversity in Heterogeneous Networked Systems
Chu Huang, Sencun Zhu, Robert F. Erbacher
DBSec2
2014 Program Logic Based Software Plagiarism Detection
abstract
Software plagiarism, an act of illegally copying others' code, has become a serious concern for honest software companies and the open source community. In this paper, we propose LoPD, a program logic based approach to software plagiarism detection. Instead of directly comparing the similarity between two programs, LoPD searches for any dissimilarity between two programs by finding an input that will cause these two programs to behave differently, either with different output states or with semantically different execution paths. As long as we can find one dissimilarity, the programs are semantically different, but if we cannot find any dissimilarity, it is likely a plagiarism case. We leverage symbolic execution and weakest precondition reasoning to capture the semantics of execution paths and to find path dissimilarities. LoPD is more resilient to current automatic obfuscation techniques, compared to the existing detection mechanisms. In addition, since LoPD is a formal program semantics-based method, it can provide a guarantee of resilience against many known obfuscation attacks. Our evaluation results indicate that LoPD is both effective and efficient in detecting software plagiarism.
Fangfang Zhang 0005, Dinghao Wu, Peng Liu 0005, Sencun Zhu
ISSRE4
2014 GlobalTrust: An attack-resilient reputation system for tactical networks
abstract
In a military tactical network where a trust authority (e.g., a commander) makes a decision during a mission, assessing the trustworthiness of participating entities accurately is critical to mission success. In this work, we propose a trust-based reputation management scheme, called GlobalTrust, for minimizing false decisions on the reputation of nodes in the network. In the proposed scheme, nodes may be compromised and provide incorrect opinions to the trust authority, who conducts reputation evaluation towards all nodes based on the provided opinions. GlobalTrust achieves three goals: (1) maintaining a consistent global view towards each node; (2) obtaining high resiliency against various attack patterns; and (3) attaining highly accurate reputation values of nodes. Through extensive simulations comparing GlobalTrust with other existing schemes, we show that GlobalTrust minimizes false decisions while maintaining high resilience against various attack behaviors. Specifically, under various attacks, GlobalTrust can achieve a highly accurate consistent view on nodes' reputations even when the number of malicious nodes is up to 40% of all participating nodes.
Jin-Hee Cho, Sencun Zhu
SECON3
2014 Uncovering the Dilemmas on Antivirus Software Design in Modern Mobile Platforms
Heqing Huang 0001, Kai Chen 0012, Peng Liu 0005, Sencun Zhu, Dinghao Wu
SecureComm (2)4
2014 Semantics-based obfuscation-resilient binary code similarity comparison with applications to software plagiarism detection
abstract
Existing code similarity comparison methods, whether source or binary code based, are mostly not resilient to obfuscations. In the case of software plagiarism, emerging obfuscation techniques have made automated detection increasingly difficult. In this paper, we propose a binary-oriented, obfuscation-resilient method based on a new concept, longest common subsequence of semantically equivalent basic blocks, which combines rigorous program semantics with longest common subsequence based fuzzy matching. We model the semantics of a basic block by a set of symbolic formulas representing the input-output relations of the block. This way, the semantics equivalence (and similarity) of two blocks can be checked by a theorem prover. We then model the semantics similarity of two paths using the longest common subsequence with basic blocks as elements. This novel combination has resulted in strong resiliency to code obfuscation. We have developed a prototype and our experimental results show that our method is effective and practical when applied to real-world software.
Lannan Luo, Jiang Ming 0002, Dinghao Wu, Peng Liu 0005, Sencun Zhu
SIGSOFT FSE5
2014 GroupTie: toward hidden collusion group discovery in app stores
abstract
The current centralized application (or app) markets provide convenient ways to distribute mobile apps. Their vendors maintain rating systems, which allow customers to leave ratings and reviews. Since positive ratings and reviews can lead to more downloads/installations and hence more monetary benefit, the rating systems have become a target of manipulation by some collusion groups hired by app developers. In this paper, we thoroughly analyze the features of hidden collusion groups and propose a novel method called \emph{GroupTie} to narrow down the suspect list of collusive reviewers for further investigation by app stores. As members of a hidden collusion group have to work together more frequently and their ratings often deviate more from apps' quality, collusive actions will enhance their relation over time. We build a relation graph named \emph{tie graph} and detect collusion groups by applying graph clustering. Simulation results show that the precision of GroupTie approaches to $99.70\%$ and the recall is about $91.50\%$. We also apply our method to detect hidden collusion groups among the reviewers of $89$ apps in Apple's China App Store. A large number of reviewers are discovered belonging to a large collusion group and several small groups.
Sencun Zhu
WISEC2
2014 ViewDroid: towards obfuscation-resilient mobile application repackaging detection
abstract
In recent years, as mobile smart device sales grow quickly, the development of mobile applications (apps) keeps accelerating, so does mobile app repackaging. Attackers can easily repackage an app under their own names or embed advertisements to earn pecuniary profits. They can also modify a popular app by inserting malicious payloads into the original app and leverage its popularity to accelerate malware propagation. In this paper, we propose ViewDroid, a user interface based approach to mobile app repackaging detection. Android apps are user interaction intensive and event dominated, and the interactions between users and apps are performed through user interface, or views. This observation inspires the design of our new birthmark for Android apps, namely, feature view graph, which captures users' navigation behavior across app views. Our experimental results demonstrate that this birthmark can characterize Android apps from a higher level abstraction, making it resilient to code obfuscation. ViewDroid can detect repackaged apps at a large scale, both effectively and efficiently. Our experiments also show that the false positive and false negative rates of ViewDroid are both very low.
Fangfang Zhang 0005, Heqing Huang 0001, Sencun Zhu, Dinghao Wu, Peng Liu 0005
WISEC3
2013 JStill: mostly static detection of obfuscated malicious JavaScript code
abstract
The dynamic features of the JavaScript language not only promote various means for users to interact with websites through Web browsers, but also pose serious security threats to both users and websites. On top of this, obfuscation has become a popular technique among malicious JavaScript code that tries to hide its malicious purpose and to evade the detection of anti-virus software. To defend against obfuscated malicious JavaScript code, in this paper we propose a mostly static approach called JStill. JStill captures some essential characteristics of obfuscated malicious code by function invocation based analysis. It also leverages the combination of static analysis and lightweight runtime inspection so that it can not only detect, but also prevent the execution of the obfuscated malicious JavaScript code in browsers. Our evaluation based on real-world malicious JavaScript samples as well as Alexa top 50,000 websites demonstrates high detection accuracy (all in our experiment) and low false positives of JStill. Meanwhile, JStill only incurs negligible performance overhead, making it a practical solution to preventing obfuscated malicious JavaScript code.
Fangfang Zhang 0005, Sencun Zhu
CODASPY3
2013 Permlyzer: Analyzing permission usage in Android applications
abstract
As one of the most popular mobile platforms, the Android system implements an install-time permission mechanism to provide users with an opportunity to deny potential risky permissions requested by an application. In order for both users and application vendors to make informed decisions, we designed and built Permlyzer, a general-purpose framework to automatically analyze the uses of requested permissions in Android applications. Permlyzer leverages the combination of runtime analysis and static examination to perform an accurate and in-depth analysis. The call stack-based analysis in Permlyzer can provide fine-grained information of the permission uses from various aspects include location, cause and purpose. More importantly, Permlyzer can automatically explore the functionality of an application and analyze the permission uses. Our evaluation using 51 malware/spyware families and over 110,000 Android applications demonstrates that Permlyzer can provide detailed permission use analysis and discover the characteristics of the permission uses in both benign and malicious applications.
Fangfang Zhang 0005, Sencun Zhu
ISSRE3
2013 Zigzag: Partial mutual revocation based trust management in tactical ad hoc networks
abstract
One of the key challenges in operational trust management is to continually monitor the behavior of a node and update its trust score accordingly - evidently, both speed and accuracy is of great importance here. To achieve these goals, several papers have explored the concept of mutual revocation (sometimes termed suicide) wherein the trust value of both the accuser and the accused node are temporarily set to zero without involving a quorum. In this paper we explore a partial mutual revocation approach wherein we design a class of trust update functions to temporarily punish both the accuser and accused node (without involving a quorum) - however, the trust update function does not essentially set their trust values to zero; instead it partially lowers the trust values of both the accuser and the accused. In addition, we allow a trusted authority or a quorum may (periodically) review such partial mutual revocations and update the trust values of the accuser and the accused nodes accordingly (e.g., reward the accuser and punish the accused if the accusation was deemed true). We present a detailed design of the trust update functions for partial mutual revocation. Through both analysis and simulations, we evaluate the effectiveness of partial revocation under different attack strategies and report its performance in terms of revocation immediacy, revocation accuracy and abuse resistance.
Harshal Patankar, Sencun Zhu, Mudhakar Srivatsa, Jeff Opper
SECON3
2013 Is this app safe for children?: a comparison study of maturity ratings on Android and iOS applications
abstract
There is a rising concern among parents who have experienced unreliable content maturity ratings for mobile applications (apps) that result in inappropriate risk exposure for their children and adolescents. In reality, there is no consistent maturity rating policy for mobile applications. The maturity ratings of Android apps are provided purely by developers' self-disclosure and are rarely verified. While Apple's iOS app ratings are considered to be more accurate, they can also be inconsistent with Apple's published policies. To address these issues, this research aims to systematically uncover the extent and severity of unreliable maturity ratings for mobile apps. Specifically, we develop mechanisms to verify the maturity ratings of mobile apps and investigate possible reasons behind the incorrect ratings. We believe that our findings have important implications for platform providers (e.g., Google or Apple) as well as for regulatory bodies and application developers.
Yilu Zhou, Sencun Zhu
WWW4
2013 To Lie or to Comply: Defending against Flood Attacks in Disruption Tolerant Networks
abstract
Disruption Tolerant Networks (DTNs) utilize the mobility of nodes and the opportunistic contacts among nodes for data communications. Due to the limitation in network resources such as contact opportunity and buffer space, DTNs are vulnerable to flood attacks in which attackers send as many packets or packet replicas as possible to the network, in order to deplete or overuse the limited network resources. In this paper, we employ rate limiting to defend against flood attacks in DTNs, such that each node has a limit over the number of packets that it can generate in each time interval and a limit over the number of replicas that it can generate for each packet. We propose a distributed scheme to detect if a node has violated its rate limits. To address the challenge that it is difficult to count all the packets or replicas sent by a node due to lack of communication infrastructure, our detection adopts claim-carry-and-check: each node itself counts the number of packets or replicas that it has sent and claims the count to other nodes; the receiving nodes carry the claims when they move, and cross-check if their carried claims are inconsistent when they contact. The claim structure uses the pigeonhole principle to guarantee that an attacker will make inconsistent claims which may lead to detection. We provide rigorous analysis on the probability of detection, and evaluate the effectiveness and efficiency of our scheme with extensive trace-driven simulations.
Wei Gao 0006, Sencun Zhu, Guohong Cao
IEEE Trans. Dependable Secur. Comput.3
2013 Towards statistically strong source anonymity for sensor networks
abstract
For sensor networks deployed to monitor and report real events, event source anonymity is an attractive and critical security property, which unfortunately is also very difficult and expensive to achieve. This is not only because adversaries may attack against sensor source privacy through traffic analysis, but also because sensor networks are very limited in resources. As such, a practical trade-off between security and performance is desirable. In this article, for the first time we propose the notion of statistically strong source anonymity , under a challenging attack model where a global attacker is able to monitor the traffic in the entire network. We propose a scheme called FitProbRate , which realizes statistically strong source anonymity for sensor networks. We demonstrate the robustness of our scheme under various statistical tests that might be employed by the attacker to detect real events. Our analysis and simulation results show that our scheme, besides providing source anonymity, can significantly reduce real event reporting latency compared to two baseline schemes. However, the degree of source anonymity in the FitProbRate scheme might decrease as real message rate increases. We propose a dynamic mean scheme which has better performance under high real message rates. Simulation results show that the dynamic mean scheme is capable of increasing the attacker's false positive rate and decreasing the attacker's Bayesian detection rate significantly even under high-rate continuous real messages.
Yi Yang 0002, Sencun Zhu, Guohong Cao
ACM Trans. Sens. Networks3
2012 An Algorithm for Jammer Localization in Wireless Sensor Networks
abstract
In wireless sensor networks (WSNs), jamming attacks have become a great concern recently. Finding the location of a jamming device is important so as to take security actions against the jammer and restore the network communication. In this paper, we take a comprehensive study on the jammer localization problem, and propose a simple while effective algorithm called Double Circle Localization (DCL). DCL is based on minimum bounding circle (MBC) and maximum inscribed circle (MIC). We implement and evaluate DCL under different conditions, including different node densities, jammer's transmission powers and antenna orientations, and compare it with three existing jammer localization algorithms through both simulation and experiments. Our evaluation results have demonstrated that, compared with all other approaches, DCL achieves the best accuracy in jammer localization.
Tianzhen Cheng, Ping Li 0028, Sencun Zhu
AINA3
2012 Semantics-Aware Storage and Replication of Trust Metadata in Mobile Ad-hoc Networks
abstract
Cooperation between nodes is essential for the functionality of a mobile ad-hoc network (MANET). However, since the nodes in a MANET are generally resource limited, some nodes could refuse service to other nodes to conserve their resources, thereby exhibiting selfish behavior. Also, since a MANET is often deployed in uncontrolled environments, some nodes could be compromised by an adversary and directed to act maliciously. A trust management framework in a MANETis useful to infer if nodes behave in a selfish or malicious manner, so that appropriate action could be taken, in order to maximize network performance. In this paper, we propose a scalable trust management scheme to partition and store an information network of trust metadata of nodes in a MANET. The simplicity of our scheme for trust metadata propagation and retrieval and its robustness to node failures, membership changes and mobility, make it a promising choice for trust management in a MANET. Simulation results that evaluate our scheme based on the trust management metrics we have defined demonstrate its performance benefits.
Vivek Natarajan, Sencun Zhu, Mudhakar Srivatsa, Jeff Opper
AINA2
2012 Towards Trusted Services: Result Verification Schemes for MapReduce
abstract
Recent development in Internet-scale data applications and services, combined with the proliferation of cloud computing, has created a new computing model for data intensive computing best characterized by the MapReduce paradigm. The MapReduce computing paradigm, pioneered by Google in its Internet search application, is an architectural and programming model for efficiently processing massive amount of raw unstructured data. With the availability of the open source Hadoop tools, applications built based on the MapReduce computing model are rapidly growing. In this work, we focus on a unique security concern on the MapReduce architecture. Given the potential security risks from lazy or malicious servers involved in a MapReduce task, we design efficient and innovative mechanisms for detecting cheating services under the MapReduce environment based on watermark injection and random sampling methods. The new detection schemes are expected to significantly reduce the cost of verification overhead. Finally, extensive analytical and experimental evaluation confirms the effectiveness of our schemes in MapReduce result verification.
Chu Huang, Sencun Zhu, Dinghao Wu
CCGRID2
2012 A first step towards algorithm plagiarism detection
abstract
In this work, we address the problem of algorithm plagiarism, which occurs when a plagiarist, violating intellectual property rights, steals others' algorithms and covertly implements them. In contrast to software plagiarism, which has been extensively studied, limited attention has been paid to algorithm plagiarism. In this paper, we propose two dynamic value-based approaches, namely N-version and annotation, for algorithm plagiarism detection. Our approaches are motivated by the observation that there exist some critical runtime values which are irreplaceable and uneliminatable for all implementations of the same algorithm. The N-version approach extracts such values by filtering out non-core values. The annotation approach leverages auxiliary information to flag important variables which contain core values. We also propose a value dependence graph based similarity metric in addition to the longest common subsequence based one, in order to address the potential value reordering attack. We have implemented a prototype and evaluated the proposed schemes on various algorithms. The results show that our approaches to algorithm plagiarism detection are practical, effective and resilient to many automatic obfuscation techniques.
Fangfang Zhang 0005, Yoon-chan Jhi, Dinghao Wu, Peng Liu 0005, Sencun Zhu
ISSTA5
2012 AK-PPM: An Authenticated Packet Attribution Scheme for Mobile Ad Hoc Networks
Zhi Xu 0004, Hung-Yuan Hsu, Sencun Zhu, Ali R. Hurson
RAID4
2012 TapLogger: inferring user inputs on smartphone touchscreens using on-board motion sensors
abstract
Today's smartphones are shipped with various embedded motion sensors, such as the accelerometer, gyroscope, and orientation sensors. These motion sensors are useful in supporting the mobile UI innovation and motion-based commands. However, they also bring potential risks of leaking user's private information as they allow third party applications to monitor the motion changes of smartphones.
Zhi Xu 0004, Sencun Zhu
WISEC3
2012 A routing protocol for socially selfish delay tolerant networks
Wei Gao 0006, Sencun Zhu, Guohong Cao
Ad Hoc Networks3
2011 A Specification Based Intrusion Detection Framework for Mobile Phones
Ashwin Chaugule, Zhi Xu 0004, Sencun Zhu
ACNS3
2011 Value-based program characterization and its application to software plagiarism detection
abstract
Identifying similar or identical code fragments becomes much more challenging in code theft cases where plagiarizers can use various automated code transformation techniques to hide stolen code from being detected. Previous works in this field are largely limited in that (1) most of them cannot handle advanced obfuscation techniques; (2) the methods based on source code analysis are less practical since the source code of suspicious programs is typically not available until strong evidences are collected; and (3) those depending on the features of specific operating systems or programming languages have limited applicability.
Yoon-chan Jhi, Xiaoqi Jia, Sencun Zhu, Peng Liu 0005, Dinghao Wu
ICSE4
2011 Distributed privacy-preserving access control in a single-owner multi-user sensor network
abstract
A distributed access control module in wireless sensor networks (WSNs) allows the network to authorize and grant user access privileges for in-network data access. Prior research mainly focuses on designing such access control modules for WSNs, but little attention has been paid to protect user's identity privacy when a user is verified by the network for data accesses. Often, a user does not want the WSN to associate his identity to the data he requests, particularly in a single-owner multi-user WSN. In this paper, we present the design, implementation, and evaluation of a novel approach, Priccess, to ensure privacy-preserving access control. In addition to the theoretical analysis that demonstrates the security properties of Priccess, this paper also reports the experimental results of Priccess in a network of Imote2 motes, which show the efficiency of Priccess in practice.
Daojing He, Jiajun Bu, Sencun Zhu, Mingjian Yin, Yi Gao 0001, Sammy Chan, Chun Chen 0001
INFOCOM3
2011 Resource-misuse attack detection in delay-tolerant networks
abstract
In a Delay-Tolerant Network (DTN), data originating from a source node may be delivered to the destination node, despite the non-existence of end-to-end connectivity between them at all times. In an adversarial environment such as a battlefield, DTN nodes could be compromised to launch Denial-of-Service (DoS) attacks by generating excess data, to cause an overflow of the limited resources of the legitimate nodes, hence decreasing the network throughput. A node may also display selfish behavior by generating more data than allowed, to increase its throughput and to decrease the latency of its data packets. In this paper, we term such a DoS attack and selfish data generation behavior, a resource-misuse attack. We study two types of resource-misuse attacks, breadth attacks and depth attacks. Accordingly, we propose different schemes to detect these attacks. Trace-driven simulations using both a synthetic and a real-world trace show that our detection schemes have low average detection latency and additionally, probabilistic detection of the depth attack has low false positive and false negative rates.
Vivek Natarajan, Yi Yang 0002, Sencun Zhu
IPCCC3
2011 Replacement Attacks on Behavior Based Software Birthmark
Zhi Xin, Huiyu Chen, Xinche Wang, Peng Liu 0005, Sencun Zhu, Bing Mao 0001, Li Xie 0001
ISC5
2011 Context-Related Access Control for Mobile Caching
Zhi Xu 0004, Sencun Zhu, Leslie S. Liu 0002, Randy Moulic
SecureComm3
2011 Distributed Access Control with Privacy Support in Wireless Sensor Networks
abstract
A distributed access control module in wireless sensor networks (WSNs) allows the network to authorize and grant user access privileges for in-network data access. Prior research mainly focuses on designing such access control modules for WSNs, but little attention has been paid to protect user's identity privacy when a user is verified by the network for data accesses. Often, a user does not want the WSN to associate his identity to the data he requests. In this paper, we present the design, implementation, and evaluation of a novel approach, Priccess, to ensure distributed privacy-preserving access control. In Priccess, users who have similar access privileges are organized into the same group by the network owner. A network user signs a query command on behalf of his group and then sends the signed query to the sensor nodes of his interest. The signature can be verified by its recipient as coming from someone authorized without exposing the actual signer. In addition to the theoretical analysis that demonstrates the security properties of Priccess, this paper also reports the experimental results of Priccess in a network of Imote2 motes, which show the efficiency of Priccess in practice.
Daojing He, Jiajun Bu, Sencun Zhu, Sammy Chan, Chun Chen 0001
IEEE Trans. Wirel. Commun.3
2011 Compromise-resilient anti-jamming communication in wireless sensor networks
Wenhui Hu, Sencun Zhu, Guohong Cao
Wirel. Networks3
2010 COP: A Step toward Children Online Privacy
Sencun Zhu
ACNS2
2010 Toward worm detection in online social networks
abstract
Worms propagating in online social networking (OSN) websites have become a major security threat to both the websites and their users in recent years. Since these worms exhibit unique propagation vectors, existing Internet worm detection mechanisms cannot be applied to them. In this work, we propose an early warning OSN worms detection system, which leverages both the propagation characteristics of these worms and the topological properties of online social networks. Our system can effectively monitor the entire social graph by keeping only a small number of user accounts under surveillance. Moreover, the system applies a two-level correlation scheme to reduce the noise from normal user communications such that infected user accounts can be identified with a higher accuracy. Our evaluation on the real social graph data obtained from Flickr indicates that by monitoring five hundreds users out of 1.8 million users, the proposed detection system can detect the burst of an OSN worm when less than 0.13% of total user accounts are infected. Besides, by adopting simple countermeasures, the detection system is also shown to be very helpful for worm containment.
Fangfang Zhang 0005, Sencun Zhu
ACSAC3
2010 A hotspot-based protocol for attack traceback in mobile ad hoc networks
abstract
Based on the principle of divide and conquer, in this paper we propose an efficient traceback protocol for mobile ad hoc networks, The protocol is capable of detecting a hotspot where the attacker resides. It works by dividing the forwarding path of every packet into multiple interweaving fragments and each reachable fragment is individually reconstructed during a traceback process. Through simulations in theoretical mobility models as well as real mobility traces, we show that each traceback of our scheme can attribute to a very small hotspot and the attacker can be accurately identified after a number of traceback operations.
Hung-Yuan Hsu, Sencun Zhu, Ali R. Hurson
AsiaCCS2
2010 Compromise-Resilient Anti-jamming for Wireless Sensor Networks
Wenhui Hu, Sencun Zhu, Guohong Cao
ICICS3
2010 Routing in Socially Selfish Delay Tolerant Networks
abstract
Existing routing algorithms for Delay Tolerant Networks(DTNs) assume that nodes are willing to forward packets for others. In the real world, however, most people are socially selfish; i.e., they are willing to forward packets for nodes with whom they have social ties but not others, and such willingness varies with the strength of the social tie. Following the philosophy of design for user, we propose a Social Selfishness Aware Routing (SSAR) algorithm to allow user selfishness and provide better routing performance in an efficient way. To select a forwarding node, SSAR considers both users' willingness to forward and their contact opportunity, resulting in a better forwarding strategy than purely contact-based approaches. Moreover, SSAR formulates the data forwarding process as a Multiple Knapsack Problem with Assignment Restrictions (MKPAR) to satisfy user demands for selfishness and performance. Trace-driven simulations show that SSAR allows users to maintain selfishness and achieves better routing performance with low transmission cost.
Sencun Zhu, Guohong Cao
INFOCOM2
2010 VAN: Vehicle-assisted shortest-time path navigation
abstract
Traffic congestion is a very serious problem in large cities. With the number of vehicles increasing rapidly, especially in cities whose economy is booming, the situation is getting even worse. In this paper, by leveraging the techniques of Vehicular Ad hoc Networks (VANETs) we present a dynamic navigation protocol called VAN for individual vehicles to find the shortest-time paths toward their given destinations. Specifically, a vehicle initiates a number of queries, which are routed by VANETs along different paths toward its destination. During query forwarding, the real-time road traffic information in each road segment is aggregated from multiple participating vehicles and returned to the source after the query reaches the destination. This information enables the source to calculate the shortest-time path. We also propose two forwarding optimization methods to reduce communication costs and an error handling mechanism to deal with abnormal circumstances. To evaluate its performance, we use the real traffic data of Beijing, including 2,308 road segments at two different times. Our simulation results demonstrate that our protocol, on average, could save around 30% driving time, compared to traveling along the shortest distance paths.
Wenping Chen, Sencun Zhu, Deying Li 0001
MASS2
2010 Mirroring Smartphones for Good: A Feasibility Study
Bo Zhao 0009, Zhi Xu 0004, Caixia Chi, Sencun Zhu, Guohong Cao
MobiQuitous4
2010 SAS: Semantics Aware Signature Generation for Polymorphic Worm Detection
Deguang Kong, Yoon-chan Jhi, Sencun Zhu, Peng Liu 0005, Hongsheng Xi
SecureComm4
2010 pBMDS: a behavior-based malware detection system for cellphone devices
abstract
Computing environments on cellphones, especially smartphones, are becoming more open and general-purpose, thus they also become attractive targets of malware. Cellphone malware not only causes privacy leakage, extra charges, and depletion of battery power, but also generates malicious traffic and drains down mobile network and service capacity. In this work we devise a novel behavior-based malware detection system named pBMDS, which adopts a probabilistic approach through correlating user inputs with system calls to detect anomalous activities in cellphones. pBMDS observes unique behaviors of the mobile phone applications and the operating users on input and output constrained devices, and leverages a Hidden Markov Model (HMM) to learn application and user behaviors from two major aspects: process state transitions and user operational patterns. Built on these, pBDMS identifies behavioral differences between malware and human users. Through extensive experiments on major smartphone platforms, we show that pBMDS can be easily deployed to existing smartphone hardware and it achieves high detection accuracy and low false positive rates in protecting major applications in smartphones.
Liang Xie 0002, Xinwen Zhang, Jean-Pierre Seifert, Sencun Zhu
WISEC4
2010 SigFree: A Signature-Free Buffer Overflow Attack Blocker
abstract
We propose SigFree, an online signature-free out-of-the-box application-layer method for blocking code-injection buffer overflow attack messages targeting at various Internet services such as Web service. Motivated by the observation that buffer overflow attacks typically contain executables whereas legitimate client requests never contain executables in most Internet services, SigFree blocks attacks by detecting the presence of code. Unlike the previous code detection algorithms, SigFree uses a new data-flow analysis technique called code abstraction that is generic, fast, and hard for exploit code to evade. SigFree is signature free, thus it can block new and unknown buffer overflow attacks; SigFree is also immunized from most attack-side code obfuscation methods. Since SigFree is a transparent deployment to the servers being protected, it is good for economical Internet-wide deployment with very low deployment and maintenance cost. We implemented and tested SigFree; our experimental study shows that the dependency-degree-based SigFree could block all types of code-injection attack packets (above 750) tested in our experiments with very few false positives. Moreover, SigFree causes very small extra latency to normal client requests when some requests contain exploit code.
Chi-Chun Pan, Peng Liu 0005, Sencun Zhu
IEEE Trans. Dependable Secur. Comput.4
2009 Detecting Software Theft via System Call Based Birthmarks
abstract
Along with the burst of open source projects, software theft (or plagiarism) has become a very serious threat to the healthiness of software industry. Software birthmark, which represents the unique characteristic of a program, can be used for software theft detection. We propose two system call based software birthmarks: SCSSB (system call short sequence birthmark) and IDSCSB (input dependant system call subsequence birthmark), and examine how well they reflect unique behavioral characteristics of a program. To our knowledge, our detection system based on SCSSB and IDSCSB is the first one that is capable of software component theft detection where only partial code is stolen. We demonstrate the strength of our birthmarks against various evasion techniques, including those based on different compilers and different compiler optimization levels as well as those based on very powerful obfuscation techniques supported by SandMark. Unlike the existing work that were evaluated through small or toy software, we also evaluate our birthmarks on a set of large software (Web browsers). Our results show that system call based birthmarks are very practical and effective in detecting software theft that even adopts advanced evasion techniques.
Yoon-chan Jhi, Sencun Zhu, Peng Liu 0005
ACSAC3
2009 Behavior based software theft detection
abstract
Along with the burst of open source projects, software theft (or plagiarism) has become a very serious threat to the healthiness of software industry. Software birthmark, which represents the unique characteristics of a program, can be used for software theft detection. We propose a system call dependence graph based software birthmark called SCDG birthmark, and examine how well it reflects unique behavioral characteristics of a program. To our knowledge, our detection system based on SCDG birthmark is the first one that is capable of detecting software component theft where only partial code is stolen. We demonstrate the strength of our birthmark against various evasion techniques, including those based on different compilers and different compiler optimization levels as well as two state-of-the-art obfuscation tools. Unlike the existing work that were evaluated through small or toy software, we also evaluate our birthmark on a set of large software. Our results show that SCDG birthmark is very practical and effective in detecting software theft that even adopts advanced evasion techniques.
Yoon-chan Jhi, Sencun Zhu, Peng Liu 0005
CCS3
2009 A Chain Reaction DoS Attack on 3G Networks: Analysis and Defenses
abstract
The IP multimedia subsystem (IMS) is being deployed in the third generation (3G) networks since it supports many kinds of multimedia services. However, the security of IMS networks has not been fully examined. This paper presents a novel DoS attack against IMS. By congesting the presence service, a core service of IMS, a malicious attack can cause chained automatic reaction of the system, thus blocking all the services of IMS. Because of the low-volume nature of this attack, an attacker only needs to control several clients to paralyze an IMS network supporting one million users. To address this DoS attack, we propose an online early defense mechanism, which aims to first detect the attack, then identify the malicious clients, and finally block them. We formulate this problem as a change-point detection problem, and solve it based on the non-parametric GRSh test. Through trace-driven experiments, we demonstrate that our defense mechanism can throttle this DoS attack within a short defense time window while generating few false alarms.
Bo Zhao 0009, Caixia Chi, Wei Gao 0006, Sencun Zhu, Guohong Cao
INFOCOM4
2009 A Social Network Based Patching Scheme for Worm Containment in Cellular Networks
abstract
Recently, cellular phone networks have begun allowing third-party applications to run over certain open-API phone operating systems such as Windows Mobile, Iphone and Google's Android platform. However, with this increased openness, the fear of rogue programs written to propagate from one phone to another becomes ever more real. This paper proposes a counter-mechanism to contain the propagation of a mobile worm at the earliest stage by patching an optimal set of selected phones. The counter-mechanism continually extracts a social relationship graph between mobile phones via an analysis of the network traffic. As people are more likely to open and download content that they receive from friends, this social relationship graph is representative of the most likely propagation path of a mobile worm. The counter mechanism partitions the social relationship graph via two different algorithms, balanced and clustered partitioning and selects an optimal set of phones to be patched first as those which have the capability to infect the most number of other phones. The performance of these partitioning algorithms is compared against a benchmark random partitioning scheme. Through extensive trace-driven experiments using real IP packet traces from one of the largest cellular networks in the US, we demonstrate the efficacy of our proposed counter-mechanism in containing a mobile worm.
Guohong Cao, Sencun Zhu, Supranamaya Ranjan, Antonio Nucci
INFOCOM3
2009 Cross-layer Enhanced Source Location Privacy in Sensor Networks
abstract
Source location privacy is an important issue in sensor network monitoring applications. It is difficult to be addressed by traditional security mechanisms, because an external attacker may perform simple traffic analysis to trace back to the event source. Solutions such as flooding or using dummy messages have the drawback of introducing a large amount of message overhead. In this paper, we avoid using network-wide dummy messages by utilizing beacons at the MAC layer. Beacons are sent out regularly, which essentially forms a constant-rate of dummy messages. Using beacons to replace the dummy messages may increase the delivery delay of event information because beacons are only sent out at the predefined beacon interval, but this latency can be controlled. To do this, we propose a cross- layer solution in which the event information is first propagated several hops through a MAC-layer beacon. Then, it is propagated at the routing layer to the destination to avoid further beacon delays. Simulation results show that our cross-layer solutions can maintain low message overhead and high privacy, while controlling delay.
Wenhui Hu, Sencun Zhu, Guohong Cao, Srikanth V. Krishnamurthy, Thomas La Porta
SECON3
2009 An Active Global Attack Model for Sensor Source Location Privacy: Analysis and Countermeasures
Yi Yang 0002, Sencun Zhu, Guohong Cao, Thomas La Porta
SecureComm2
2009 Designing System-Level Defenses against Cellphone Malware
abstract
Cellphones are increasingly becoming attractive targets of various malware, which not only cause privacy leakage, extra charges, and depletion of battery power, but also introduce malicious traffic into networks. In this work, we seek system-level solutions to handle these security threats. Specifically, we propose a mandatory access control-based defense to blocking malware that launch attacks through creating new processes for execution. To combat more elaborated malware which redirect program flows of normal applications to execute malicious code within a legitimate security domain, we further propose using artificial intelligence (AI) techniques such as Graphic Turing test. Through extensive experiments based on both Symbian and Linux smartphones, we show that both our system-level countermeasures effectively detect and block cellphone malware with low false positives, and can be easily deployed on existing smartphone hardware.
Liang Xie 0002, Xinwen Zhang, Ashwin Chaugule, Trent Jaeger, Sencun Zhu
SRDS5
2009 Predistribution and local collaboration-based group rekeying for wireless sensor networks
Wensheng Zhang 0001, Sencun Zhu, Guohong Cao
Ad Hoc Networks2
2009 Editorial for special issue on privacy and security in wireless sensorand ad hoc networks
Wensheng Zhang 0001, Sencun Zhu, Guohong Cao
Ad Hoc Networks2
2009 pDCS: Security and Privacy Support for Data-Centric Sensor Networks
abstract
The demand for efficient data dissemination/access techniques to find relevant data from within a sensor network has led to the development of data-centric sensor (DCS) networks, where the sensor data instead of sensor nodes are named based on attributes such as event type or geographic location. However, saving data inside a network also creates security problems due to the lack of tamper resistance of the sensor nodes and the unattended nature of the sensor network. For example, an attacker may simply locate and compromise the node storing the event of his interest. To address these security problems, we present pDCS, a privacy-enhanced DCS network which offers different levels of data privacy based on different cryptographic keys. pDCS also includes an efficient key management scheme to facilitate the management of multiple types of keys used in the system. In addition, we propose several query optimization techniques based on Euclidean Steiner tree and keyed bloom filter (KBF) to minimize the query overhead while preserving query privacy. Finally, detailed analysis and simulations show that the KBF scheme can significantly reduce the message overhead with the same level of query delay and maintain a very high level of query privacy.
Sencun Zhu, Wensheng Zhang 0001, Guohong Cao, Yi Yang 0002
IEEE Trans. Mob. Comput.2
2008 On the Effectiveness of Internal Patching Against File-Sharing Worms
Liang Xie 0002, Sencun Zhu
ACNS3
2008 STILL: Exploit Code Detection via Static Taint and Initialization Analyses
abstract
We propose STILL, a generic defense based on Static Taint and Initialization analyses, to detect exploit code embedded in data streams/requests targeting at various Internet services such as Web services. STILL first blindly disassembles each request, generates a (probably partial) control flow graph, and then uses novel static taint and initialization analysis algorithms to determine if strong evidence of self-modifying (including polymorphism) and/or indirect jump code obfuscation behavior can be collected. If such evidence exists, STILL will raise an alarm and block the request; otherwise, STILL will perform another form of static taint analysis to check whether unobfuscated or other types of obfuscated exploit code (e.g., metamorphism, etc) is embedded in the request. To the best of our knowledge, compared with existing static analysis approaches developed for the same purpose, STILL is (a) the first one that can detect self-modifying code and indirect jump, and (b) a more comprehensive static analysis solution in defending against anti-signature, anti-static-analysis and anti-emulation code obfuscation (for all the code obfuscation techniques we are aware of, STILL is robust to all but one).
Yoon-chan Jhi, Sencun Zhu, Peng Liu 0005
ACSAC3
2008 Detecting Remote Exploits Using Data Mining
Mohammad M. Masud 0001, Latifur Khan, Bhavani Thuraisingham, Peng Liu 0005, Sencun Zhu
IFIP Int. Conf. Digital Forensics6
2008 Towards Statistically Strong Source Anonymity for Sensor Networks
abstract
For sensor networks deployed to monitor and report real events, event source anonymity is an attractive and critical security property, which unfortunately is also very difficult and expensive to achieve. This is not only because adversaries may attack against sensor source privacy through traffic analysis, but also because sensor networks are very limited in resources. As such, a practical tradeoff between security and performance is desirable. In this paper, for the first time we propose the notion of statistically strong source anonymity, under a challenging attack model where a global attacker is able to monitor the traffic in the entire network. We propose a scheme called FitProbRate, which realizes statistically strong source anonymity for sensor networks. We also demonstrate the robustness of our scheme under various statistical tests that might be employed by the attacker to detect real events. Our analysis and simulation results show that our scheme, besides providing source anonymity, can significantly reduce real event reporting latency compared to two baseline schemes.
Yi Yang 0002, Sencun Zhu, Guohong Cao
INFOCOM3
2008 SVATS: A Sensor-Network-Based Vehicle Anti-Theft System
abstract
Today vehicle theft rate is very high, thus tracking/alarming systems are being deployed with an increasingly popularity. These systems however bear some limitations such as high cost, high false-alarm rate, and easy to be disabled. This paper describes the design, implementation and evaluation of a Sensor-network-based Vehicle Anti-Theft System (SVATS) to address these limitations. In this system, the sensors in the vehicles that are parked within the same parking area first form a sensor network, then monitor and identify possible vehicle thefts by detecting unauthorized vehicle movement. When an unauthorized movement is detected, an alert will be reported to a base station in the parking area, which sends warning messages to the security office. This paper focuses on the technical issues specific to the system such as topology management, theft detection, and intra-vehicle networking.
Sencun Zhu, Guohong Cao
INFOCOM2
2008 Improving sensor network immunity under worm attacks: a software diversity approach
abstract
Because of cost and resource constraints, sensor nodes do not have a complicated hardware architecture or operating system to protect program safety. Hence, the notorious buffer-overflow vulnerability that has caused numerous Internet worm attacks could also be exploited to attack sensor networks. We call the malicious code that exploits a buffer-overflow vulnerability in a sensor program sensor worm. Clearly, sensor worm will be a serious threat, if not the most dangerous one, when an attacker could simply send a single packet to compromise the entire sensor network. Despite its importance, so far little work has been focused on sensor worms.
Yi Yang 0002, Sencun Zhu, Guohong Cao
MobiHoc2
2008 A cross-layer dropping attack in video streaming over ad hoc networks
abstract
Significant progress has been made to achieve video streaming over wireless ad hoc networks. However, there is not much work on providing security. Is existing security solution good enough for securing video streaming over ad hoc networks? In this paper, we discover a cross-layer dropping attack against video streaming. We first identify a general IP layer dropping attack and then reveal its destructive impact by leveraging the application layer information (e.g., video streaming). Through simulations, we quantify the impact of this attack as a function of several performance parameters such as delivery ratio, hop number and the number of attackers. The surprising result with this attack is that with a 94% delivery ratio, the receiver still cannot watch the video! We also propose several possible solutions to address the dropping attacks. Due to the unique characteristics of this attack, as long as malicious nodes exist, the network will suffer from this dropping attack.
Sencun Zhu, Guohong Cao, Thomas La Porta, Prasant Mohapatra
SecureComm2
2008 Towards event source unobservability with minimum network traffic in sensor networks
abstract
Sensors deployed to monitor the surrounding environment report such information as event type, location, and time when a real event of interest is detected. An adversary may identify the real event source through eavesdropping and traffic analysis. Previous work has studied the source location privacy problem under a local adversary model. In this work, we aim to provide a stronger notion: event source unobservability, which promises that a global adversary cannot know whether a real event has ever occurred even if he is capable of collecting and analyzing all the messages in the network at all the time. Clearly, event source unobservability is a desirable and critical security property for event monitoring applications, but unfortunately it is also very difficult and expensive to achieve for resource-constrained sensor network.
Yi Yang 0002, Sencun Zhu, Bhuvan Urgaonkar, Guohong Cao
WISEC3
2008 Protecting web services from remote exploit code: a static analysis approach
abstract
We propose STILL, a signature-free remote exploit binary code injection attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation.
Yoon-chan Jhi, Sencun Zhu, Peng Liu 0005
WWW3
2008 A systematic approach for cell-phone worm containment
abstract
Cell phones are increasingly becoming attractive targets of various worms, which cause the leakage of user privacy, extra service charges and depletion of battery power. In this work, we study propagation of cell-phone worms, which exploit Multimedia Messaging Service (MMS) and/or Bluetooth for spreading. We then propose a systematic countermeasure against the worms. At the terminal level, we adopt Graphic Turing test and identity-based signature to block unauthorized messages from leaving compromised phones; at the network level, we propose a push-based automated patching scheme for cleansing compromised phones. Through experiments on phone devices and a wide variety of networks, we show that cellular systems taking advantage of our defense can achieve a low infection rate (e.g., less than 3% within 30 hours) even under severe attacks.
Liang Xie 0002, Trent Jaeger, Sencun Zhu
WWW4
2008 Message Dropping Attacks in Overlay Networks: Attack Detection and Attacker Identification
abstract
Overlay multicast networks are used by service providers to distribute contents such as Web pages, static and streaming multimedia data, or security updates to a large number of users. However, such networks are extremely vulnerable to message-dropping attacks by malicious or selfish nodes that intentionally drop the packets they are required to forward to others. It is difficult to detect such attacks both efficiently and effectively and to further identify the attackers, especially when members in the overlay switch between online/offline statuses frequently. In this article, we consider various attacking strategies of an attacker and propose an optimal sampling-based scheme to detect such attacks in the overlay network. We analyze the detection problem from a game-theoretical viewpoint and show that our scheme outperforms a random sampling-based scheme in terms of detection rate. In addition, based on a reputation system, we propose a sampling-based path-resolving scheme to identify compromised or selfish nodes. Unlike other existing approaches, our schemes do not assume global knowledge of the overlay hierarchy and work for dynamic overlay networks as well. Extensive analysis and simulation results show that besides being band width efficient, our schemes have high detection and identification rates and low false-positive rates.
Liang Xie 0002, Sencun Zhu
ACM Trans. Inf. Syst. Secur.2
2008 SDAP: A Secure Hop-by-Hop Data Aggregation Protocol for Sensor Networks
abstract
Hop-by-hop data aggregation is a very important technique for reducing the communication overhead and energy expenditure of sensor nodes during the process of data collection in a sensor network. However, because individual sensor readings are lost in the per-hop aggregation process, compromised nodes in the network may forge false values as the aggregation results of other nodes, tricking the base station into accepting spurious aggregation results. Here a fundamental challenge is how can the base station obtain a good approximation of the fusion result when a fraction of sensor nodes are compromised? To answer this challenge, we propose SDAP, a Secure Hop-by-hop Data Aggregation Protocol for sensor networks. SDAP is a general-purpose secure data aggregation protocol applicable to multiple aggregation functions. The design of SDAP is based on the principles of divide-and-conquer and commit-and-attest . First, SDAP uses a novel probabilistic grouping technique to dynamically partition the nodes in a tree topology into multiple logical groups (subtrees) of similar sizes. A commitment-based hop-by-hop aggregation is performed in each group to generate a group aggregate. The base station then identifies the suspicious groups based on the set of group aggregates. Finally, each group under suspect participates in an attestation process to prove the correctness of its group aggregate. The aggregate by the base station is calculated over all the group aggregates that are either normal or have passed the attestation procedure. Extensive analysis and simulations show that SDAP can achieve the level of efficiency close to an ordinary hop-by-hop aggregation protocol while providing high assurance on the trustworthiness of the aggregation result. Last, prototype implementation on top of TinyOS shows that our scheme is practical on current generation sensor nodes such as Mica2 motes.
Yi Yang 0002, Sencun Zhu, Guohong Cao
ACM Trans. Inf. Syst. Secur.3
2008 Least privilege and privilege deprivation: Toward tolerating mobile sink compromises in wireless sensor networks
abstract
Mobile sinks are needed in many sensor network applications for efficient data collection, data querying, localized sensor reprogramming, identifying, and revoking compromised sensors, and other network maintenance. Employing mobile sinks however raises a new security challenge: if a mobile sink is given too many privileges, it will become very attractive for attack and compromise. Using a compromised mobile sink, an adversary may easily bring down or even take over the sensor network. Thus, security mechanisms that can tolerate mobile sink compromises are essential. In this article, based on the principle of least privilege , we first propose an efficient scheme to restrict the privilege of a mobile sink without impeding its ability to carry out any authorized operations for an assigned task. In addition, we present an extension to allow conditional trajectory change due to unexpected events. To further reduce the possible damage caused by a compromised mobile sink, we propose efficient message forwarding schemes for deleting the privilege assigned to a compromised mobile sink immediately after its compromise has been detected. Through detailed analysis, simulation, and real implementation, we show that our schemes are secure and efficient, and are highly practical for sensor networks consisting of the current generation of sensors.
Sencun Zhu, Wensheng Zhang 0001, Guohong Cao
ACM Trans. Sens. Networks2
2007 pDCS: Security and Privacy Support for Data-Centric Sensor Networks
abstract
The demand for efficient data dissemination/access techniques to find the relevant data from within a sensor network has led to the development of data-centric sensor networks (DCS), where the sensor data as contrast to sensor nodes are named based on attributes such as event type or geographic location. However, saving data inside a network also creates security problems due to the lack of tamper-resistance of the sensor nodes and the unattended nature of the sensor network. For example, an attacker may simply locate and compromise the node storing the event of his interest. To address these security problems, we present pDCS, a privacy-enhanced DCS network which offers different levels of data privacy based on different cryptographic keys. In addition, we propose several query optimization techniques based on Euclidean Steiner Tree and Keyed Bloom Filter to minimize the query overhead while providing certain query privacy. Finally, detailed analysis and simulations show that the Keyed Bloom Filter scheme can significantly reduce the message overhead with the same level of query delay and maintain a very high level of query privacy.
Sencun Zhu, Wensheng Zhang 0001, Guohong Cao
INFOCOM2
2007 Sensor node compromise detection: the location perspective
abstract
Node compromise is a serious security threat that hinders the successful deployment of large-scale wireless sensor networks. A node compromise often consists of three stages: physically obtaining and compromising the sensors, redeploying the compromised sensors, and compromised nodes launching attacks after their rejoining the network. By far, all the proposed compromise detection schemes address this problem at the third stage. In this paper, we make the first attempt to detect node compromise at the second stage. Our motivation is that for some applications an attacker may not be able to precisely deploy the compromised sensors back into their original positions. Thus, the detection of location change will become an indication of a potential node compromise. We name this node redeployment detection problem. We propose two approaches to detect node redeployment, based on the change of node neighborship and the change of measured distances between nodes, respectively. Our simulation study shows that both schemes can detect node redeployment effectively (with low false positive rate and high detection rate).
Liang Xie 0002, Sencun Zhu, Guohong Cao
IWCMC3
2007 A random perturbation-based scheme for pairwise key establishment in sensor networks
abstract
A prerequisite for secure communications between two sensor nodes is that these nodes exclusively share a pairwise key. Although numerous pairwise key establishment (PKE) schemes have been proposed in recent years, most of them have no guarantee for direct key establishment, no resilience to a large number of node compromises, no resilience to dynamic network topology, or high overhead. To address these limitations, we propose a novel random perturbation-based (RPB) scheme in this paper. The scheme guarantees that any two nodes can directly establish a pairwise key without exposing any secret to other nodes. Even after a large number of nodes have been compromised, the pairwise keys shared by non-compromised nodes remain highly secure. Moreover, the scheme adapts to changes in network topology and incurs low computation and communication overhead. To the best of our knowledge, the RPB scheme is the only one that provides all these salient features without relying on public key cryptography. Through prototype-based evaluation, we show that the RPB scheme is highly efficient and practical for current generation of sensor nodes. In particular, to support a sensor network with up to 216 nodes, establishing a pairwise key of 80 bits between any two 8-bit, 7.37-MHz MICA2 motes only requires about 0.13 second of CPU time, 0.33 KB RAM space, and 15 KB ROM space per node.
Wensheng Zhang 0001, Sencun Zhu, Guohong Cao
MobiHoc3
2007 A Feasibility Study on Defending Against Ultra-Fast TopologicalWorms
abstract
Copyright and Reprint Permissions: Abstracting is permitted with credit to the source. Libraries may photocopy beyond the limits of US copyright law, for private use of patrons, those articles in this volume that carry a code at the bottom of the first page, provided that the per-copy fee indicated in the code is paid through the Copyright Clearance Center. The papers in this book comprise the proceedings of the meeting mentioned on the cover and title page. They reflect the authors' opinions and, in the interests of timely dissemination, are published as presented and without change. Their inclusion in this publication does not necessarily constitute endorsement by the editors or the Institute of Electrical and Electronics Engineers, Inc.
Liang Xie 0002, Sencun Zhu
Peer-to-Peer Computing2
2007 Distributed Software-based Attestation for Node Compromise Detection in Sensor Networks
abstract
Sensors that operate in an unattended, harsh or hostile environment are vulnerable to compromises because their low costs preclude the use of expensive tamper-resistant hardware. Thus, an adversary may reprogram them with malicious code to launch various insider attacks. Based on verifying the genuineness of the running program, we propose two distributed software-based attestation schemes that are well tailored for sensor networks. These schemes are based on a pseudorandom noise generation mechanism and a lightweight block-based pseudorandom memory traversal algorithm. Each node is loaded with pseudorandom noise in its empty program memory before deployment, and later on multiple neighbors of a suspicious node collaborate to verify the integrity of the code running on this node in a distributed manner. Our analysis and simulation show that these schemes achieve high detection rate even when multiple compromised neighbors collude in an attestation process.
Yi Yang 0002, Sencun Zhu, Guohong Cao
SRDS3
2007 Attack-resilient time synchronization for wireless sensor networks
Sencun Zhu, Guohong Cao
Ad Hoc Networks2
2007 Efficient security mechanisms for overlay multicast based content delivery
Sencun Zhu, Donggang Liu, Sanjeev Setia, Sushil Jajodia
Comput. Commun.1
2007 Efficient Hybrid Security Mechanisms for Heterogeneous Sensor Networks
abstract
Many applications that make use of sensor networks require secure communication. Because asymmetric-key solutions are difficult to implement in such a resource-constrained environment, symmetric-key methods coupled with a priori key distribution schemes have been proposed to achieve the goals of data secrecy and integrity. These approaches typically assume that all nodes are similar in terms of capabilities and, hence, deploy the same number of keys in all sensors in a network to provide the aforementioned protections. In this paper, we demonstrate that a probabilistic unbalanced distribution of keys throughout the network that leverages the existence of a small percentage of more capable sensor nodes can not only provide an equal level of security, but also reduce the consequences of node compromise. To fully characterize the effects of the unbalanced key management system, we design, implement, and measure the performance of a complementary suite of key establishment protocols known as LIGER. Using their predeployed keys, nodes operating in isolation from external networks can securely and efficiently establish keys with each other. Should resources such as a backhaul link to a key distribution center (KDC) become available, networks implementing LIGER automatically incorporate and benefit from such facilities. Detailed experiments demonstrate that the unbalanced distribution in combination with the multimodal LIGER suite offers a robust and practical solution to the security needs in sensor networks
Patrick Traynor, Raju Kumar, Heesook Choi, Guohong Cao, Sencun Zhu, Thomas La Porta
IEEE Trans. Mob. Comput.5
2007 Interleaved hop-by-hop authentication against false data injection attacks in sensor networks
abstract
Sensor networks are often deployed in unattended environments, thus leaving these networks vulnerable to false data injection attacks in which an adversary injects false data into the network with the goal of deceiving the base station or depleting the resources of the relaying nodes. Standard authentication mechanisms cannot prevent this attack if the adversary has compromised one or a small number of sensor nodes. We present three interleaved hop-by-hop authentication schemes that guarantee that the base station can detect injected false data immediately when no more than t nodes are compromised, where t is a system design parameter. Moreover, these schemes enable an intermediate forwarding node to detect and discard false data packets as early as possible. Our performance analysis shows that our scheme is efficient with respect to the security it provides, and it also allows a tradeoff between security and performance. A prototype implementation of our scheme indicates that our scheme is practical and can be deployed on the current generation of sensor nodes.
Sencun Zhu, Sanjeev Setia, Sushil Jajodia, Peng Ning
ACM Trans. Sens. Networks1
2006 Establishing Pair-Wise Keys in Heterogeneous Sensor Networks
abstract
Abstract — Many applications that make use of sensor networks require secure communication. Because asymmetric-key solutions are difficult to implement in such a resource-constrained environment, symmetric-key methods coupled with a priori key distribution schemes have been proposed to achieve the goals of data secrecy and integrity. These approaches typically assume that all sensors are similar in terms of capabilities, and hence deploy the same number of keys in all sensors in a network to provide the aforementioned protections. In this paper we demonstrate that a probabilistic unbalanced distribution of keys throughout the network that leverages the existence of a small percentage of more capable sensor nodes can not only provide an equal level of security but also reduce the consequences of node compromise. We demonstrate the effectiveness of this approach on small networks using a variety of trust models and then demonstrate the application of this method to very large systems. The approach and analysis presented in this paper can be applied to all protocols that use probabilistic keys including those that employ broadcast mechanisms, hash functions or polynomials for the generation of keys.
Patrick Traynor, Heesook Choi, Guohong Cao, Sencun Zhu, Thomas La Porta
INFOCOM4
2006 SDAP: : a secure hop-by-Hop data aggregation protocol for sensor networks
abstract
Hop-by-hop data aggregation is a very important technique for reducing the communication overhead and energy expenditure of sensor nodes during the process of data collection in a sensor network. However, because individual sensor readings are lost in the per-hop aggregation process, compromised nodes in the network may forge false values as the aggregation results of other nodes, tricking the base station into accepting spurious aggregation results. Here a fundamental challenge is: how can the base station obtain a good approximation of the fusion result when a fraction of sensor nodes are compromised.To answer this challenge, we propose SDAP, a Secure Hop-by-hop Data Aggregation Protocol for sensor networks. The design of SDAP is based on the principles of divide-and-conquer and commit-and-attest. First, SDAP uses a novel probabilistic grouping technique to dynamically partition the nodes in a tree topology into multiple logical groups (subtrees) of similar sizes. A commitment-based hop-by-hop aggregation is performed in each group to generate a group aggregate. The base station then identifies the suspicious groups based on the set of group aggregates. Finally, each group under suspect participates in an attestation process to prove the correctness of its group aggregate. Our analysis and simulations show that SDAP can achieve the level of efficiency close to an ordinary hop-by-hop aggregation protocol while providing certain assurance on the trustworthiness of the aggregation result. Moreover, SDAP is a general-purpose secure aggregation protocol applicable to multiple aggregation functions.
Yi Yang 0002, Sencun Zhu, Guohong Cao
MobiHoc3
2006 SigFree: A Signature-free Buffer Overflow Attack Blocker
Chi-Chun Pan, Peng Liu 0005, Sencun Zhu
USENIX Security Symposium4
2006 LHAP: A lightweight network access control protocol for ad hoc networks
Sencun Zhu, Shouhuai Xu, Sanjeev Setia, Sushil Jajodia
Ad Hoc Networks1
2006 Looking into the seeds of time: Discovering temporal patterns in large transaction sets
Yingjiu Li, Sencun Zhu, Xiaoyang Sean Wang, Sushil Jajodia
Inf. Sci.2
2006 GKMPAN: An Efficient Group Rekeying Scheme for Secure Multicast in Ad-Hoc Networks
abstract
We present GKMPAN, an efficient and scalable group rekeying protocol for secure multicast in ad hoc networks. Our protocol exploits the property of ad hoc networks that each member of a group is both a host and a router, and distributes the group key to member nodes via a secure hop-by-hop propagation scheme. A probabilistic scheme based on pre-deployed symmetric keys is used for implementing secure channels between members for group key distribution. GKMPAN also includes a novel distributed scheme for efficiently updating the pre-deployed keys. GKMPAN has three attractive properties. First, it is significantly more efficient than group rekeying schemes that were adapted from those proposed for wired networks. Second, GKMPAN has the property of partial statelessness; that is, a node can decode the current group key even if it has missed a certain number of previous group rekeying operations. This makes it very attractive for ad hoc networks where nodes may lose packets due to transmission link errors or temporary network partitions. Third, in GKMPAN the key server does not need any information about the topology of the ad hoc network or the geographic location of the members of the group. We study the security and performance of GKMPAN through detailed analysis and simulation; we have also implemented GKMPAN in a sensor network testbed.
Sencun Zhu, Sanjeev Setia, Shouhuai Xu, Sushil Jajodia
J. Comput. Secur.1
2006 LEAP+: Efficient security mechanisms for large-scale distributed sensor networks
abstract
We describe LEAP+ (Localized Encryption and Authentication Protocol), a key management protocol for sensor networks that is designed to support in-network processing, while at the same time restricting the security impact of a node compromise to the immediate network neighborhood of the compromised node. The design of the protocol is motivated by the observation that different types of messages exchanged between sensor nodes have different security requirements, and that a single keying mechanism is not suitable for meeting these different security requirements. LEAP+ supports the establishment of four types of keys for each sensor node: an individual key shared with the base station, a pairwise key shared with another sensor node, a cluster key shared with multiple neighboring nodes, and a global key shared by all the nodes in the network. LEAP+ also supports (weak) local source authentication without precluding in-network processing. Our performance analysis shows that LEAP+ is very efficient in terms of computational, communication, and storage costs. We analyze the security of LEAP+ under various attack models and show that LEAP+ is very effective in defending against many sophisticated attacks, such as HELLO flood attacks, node cloning attacks, and wormhole attacks. A prototype implementation of LEAP+ on a sensor network testbed is also described.
Sencun Zhu, Sanjeev Setia, Sushil Jajodia
ACM Trans. Sens. Networks1
2005 Efficient Security Mechanisms for Overlay Multicast-Based Content Distribution
Sencun Zhu, Donggang Liu, Sanjeev Setia, Sushil Jajodia
ACNS1
2005 Defending against packet injection attacks unreliable ad hoc networks
abstract
Ad hoc networks are usually unreliable and have limited bandwidth resources. In such networks, packet injection attacks can cause serious denial-of-service via wireless channel contention and network congestion. To defend against this type of injection attacks, we propose SAF, an efficient and effective Source Authentication Forwarding protocol. The protocol can either immediately filter out injected junk packets with very high probability or expose the true identity of an injector. Differing from other forwarding defenses, this protocol is designed to fit in the unreliable environment of ad hoc networks. Our simulation shows that SAF incurs very lightweight overhead in communication and computation.
Qijun Gu, Peng Liu 0005, Sencun Zhu, Chao-Hsien Chu
GLOBECOM3
2005 Attack-resilient time synchronization for wireless sensor networks
abstract
The existing time synchronization schemes in sensor networks were not designed with security in mind, thus leaving them vulnerable to security attacks. In this paper, we first identify various attacks that are effective to several representative time synchronization schemes, and then focus on a specific type of attack called delay attack, which cannot be addressed by cryptographic techniques. Next we propose two approaches to detect and accommodate the delay attack. Our first approach uses the generalized extreme studentized deviate (GESD) algorithm to detect multiple outliers introduced by the compromised nodes; our second approach uses a threshold derived using a time transformation technique to filter out the outliers. Finally we show the effectiveness of these two schemes through extensive simulations
Sencun Zhu, Guohong Cao
MASS2
2005 Least privilege and privilege deprivation: towards tolerating mobile sink compromises in wireless sensor networks
abstract
Mobile sinks are needed in many sensor network applications for efficient data collection, data querying, localized sensor reprogramming, identifying and revoking compromised sensors, and other network maintenance. Employing mobile sinks however raises a new security challenge: if a mobile sink is given too many privileges, it will become very attractive for attack and compromise. Using a compromised mobile sink, an adversary may easily bring down or even take over the sensor network. Thus, security mechanisms that can tolerate mobile sink compromises are essential. In this paper, based on the principle of least privilege, we first propose several efficient schemes to restrict the privilege of a mobile sink without impeding its capability of carrying out any authorized operations for an assigned task. To further reduce the possible damages caused by a compromised mobile sink, we then propose efficient message forwarding schemes for depriving the privilege assigned to a compromised mobile sink immediately after its compromise has been detected. Through detailed analysis and simulations, we show that our schemes are secure and efficient, and are highly practical for sensor networks consisting of the current generation of sensors.
Wensheng Zhang 0001, Sencun Zhu, Guohong Cao
MobiHoc3
2005 Practical Broadcast Authentication in Sensor Networks
abstract
Broadcast authentication is a critical security service in sensor networks; it allows a sender to broadcast messages to multiple nodes in an authenticated way. /spl mu/TESLA and multi-level /spl mu/TESLA have been proposed to provide such services for sensor networks. However, none of these techniques are scalable in terms of the number of senders. Though multi-level /spl mu/TESLA schemes can scale up to large sensor networks (in terms of receivers), they either use substantial bandwidth and storage at sensor nodes, or require significant resources at senders to deal with DOS attacks. This paper presents efficient techniques to support a potentially large number of broadcast senders using /spl mu/TESLA instances as building blocks. The proposed techniques are immune to the DOS attacks. This paper also provides two approaches, a revocation tree based scheme and a proactive distribution based scheme, to revoke the broadcast authentication capability from compromised senders. The proposed techniques are implemented, and evaluated through simulation on TinyOS. The analysis and experiment show that these techniques are efficient and practical, and can achieve better performance than the previous approaches.
Donggang Liu, Peng Ning, Sencun Zhu, Sushil Jajodia
MobiQuitous3
2004 GKMPAN: An Efficient Group Rekeying Scheme for Secure Multicast in Ad-Hoc Networks
abstract
We present GKMPAN, an efficient and scalable group rekeying protocol for secure multicast in ad hoc networks. Our protocol exploits the property of ad hoc networks that each member of a group is both a host and a router, and distributes the group key to member nodes via a secure hop-by-hop propagation scheme. A probabilistic scheme based on predeployed symmetric keys is used for implementing secure channels between members for group key distribution. GKMPAN also includes a novel distributed scheme for efficiently updating the predeployed keys. GKMPAN has three attractive properties. First, it is significantly more efficient than group rekeying schemes that were adapted from those proposed for wired networks. Second, GKMPAN has the property of partial statelessness; that is, a node can decode the current group key even if it has missed a certain number of previous group rekeying operations. This makes it very attractive for ad hoc networks where nodes may lose packets due to transmission link errors or temporary network partitions. Third, in GKMPAN the key server does not need any information about the topology of the ad hoc network or the geographic location of the members of the group. We study the security and performance of GKMPAN through detailed analysis and simulation.
Sencun Zhu, Sanjeev Setia, Shouhuai Xu, Sushil Jajodia
MobiQuitous1
2004 An Interleaved Hop-by-Hop Authentication Scheme for Filtering of Injected False Data in Sensor Networks
abstract
Sensor networks are often deployed in unattended environments, thus leaving these networks vulnerable to false data injection attacks in which an adversary injects false data into the network with the goal of deceiving the base station or depleting the resources of the relaying nodes. Standard authentication mechanisms cannot prevent this attack if the adversary has compromised one or a small number of sensor nodes. In this paper, we present an interleaved hop-by-hop authentication scheme that guarantees that the base station will detect any injected false data packets when no more than a certain number t nodes are compromised. Further, our scheme provides an upper bound B for the number of hops that a false data packet could be forwarded before it is detected and dropped, given that there are up to t colluding compromised nodes. We show that in the worst case B is O(t/sup 2/). Through performance analysis, we show that our scheme is efficient with respect to the security it provides, and it also allows a tradeoff between security and performance.
Sencun Zhu, Sanjeev Setia, Sushil Jajodia, Peng Ning
S&P1
2003 LEAP: efficient security mechanisms for large-scale distributed sensor networks
abstract
In this paper, we describe LEAP (Localized Encryption and Authentication Protocol), a key management protocol for sensor networks that is designed to support in-network processing, while at the same time restricting the security impact of a node compromise to the immediate network neighborhood of the compromised node. The design of the protocol is motivated by the observation that different types of messages exchanged between sensor nodes have different security requirements, and that a single keying mechanism is not suitable for meeting these different security requirements. LEAP supports the establishment of four types of keys for each sensor node -- an individual key shared with the base station, a pairwise key shared with another sensor node, a cluster key shared with multiple neighboring nodes, and a group key that is shared by all the nodes in the network. The protocol used for establishing and updating these keys is communication- and energy-efficient, and minimizes the involvement of the base station. LEAP also includes an efficient protocol for inter-node traffic authentication based on the use of one-way key chains. A salient feature of the authentication protocol is that it supports source authentication without precluding in-network processing and passive participation. We analyze the performance and the security of our scheme under various attack models and show our schemes are very efficient in defending against many attacks.
Sencun Zhu, Sanjeev Setia, Sushil Jajodia
CCS1
2003 Performance Optimizations for Group Key Management Scheme
abstract
Recently, many group key management approaches based on the use of logical key trees have been proposed to address the issue of scalable group rekeying that is needed to support secure communications for large and dynamic groups. In this paper, we present two optimizations for logical key tree organizations that utilize information about the characteristics of group members to further reduce the overhead of group rekeying. First, we propose a partitioned key tree organization that exploits the temporal patterns of group member joins and departures to reduce the overhead of rekeying. Using an analytic model, we show that our optimization can achieve up to 31.4% reduction in key server bandwidth overhead over the unoptimized scheme. Second, we propose an approach under which the key tree is organized based on the loss probabilities of group members. Our analysis shows this optimization can reduce the rekeying overhead by up to 12.1%.
Sencun Zhu, Sanjeev Setia, Sushil Jajodia
ICDCS1
2003 Establishing Pairwise Keys for Secure Communication in Ad Hoc Networks: A Probabilistic Approach
abstract
A prerequisite for a secure communication between two nodes in an ad hoc network is that the nodes share a key to bootstrap their trust relationship. In this paper, we present a scalable and distributed protocol that enables two nodes to establish a pairwise shared key on the fly, without requiring the use of any on-line key distribution center. The design of our protocol is based on a novel combination of two techniques - probabilistic key sharing and threshold secret sharing. Our protocol is scalable since every node only needs to possess a small number of keys, independent of the network size, and it is computationally efficient because it only relies on symmetric key cryptography based operations. We show that a pairwise key established between two nodes using our protocol is secure against a collusion attack by up to a certain number of compromised nodes. We also show through a set of simulations that our protocol can be parameterized to meet the desired levels of performance, security and storage for the application under consideration.
Sencun Zhu, Shouhuai Xu, Sanjeev Setia, Sushil Jajodia
ICNP1
2003 LEAP - efficient security mechanisms for large-scale distributed sensor networks
abstract
In this paper, we describe LEAP (Localized Encryption and Authentication Protocol), a key management protocol for sensor networks that is designed to support in-network processing techniques such as passive participation. LEAP includes support for multiple symmetric keying mechanisms including individual keys, pairwise shared keys, cluster keys, and a group key. This design is based on the observation that different types of messages exchanged between sensor nodes have different security requirements, and a single keying mechanism is not suitable for meeting these different security requirements.
Sencun Zhu, Sanjeev Setia, Sushil Jajodia
SenSys1
2002 A comparative performance analysis of reliable group rekey transport protocols for secure multicast
Sanjeev Setia, Sencun Zhu, Sushil Jajodia
Perform. Evaluation2