VLDB 2026 Research / reviewers in the wild / expert
Weili Han
dblp:42/179
· DBLP profile ↗
66ranked-venue papers
15as first author
32since 2021 · last 2027
0000-0001-8663-436XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 36 · 9 first-author · 17 since 2021Databases, data management, data science and information retrieval · 9 · 6 since 2021Computer networks · 8 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Human-computer interaction and ubiquitous computing · 3Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | LETAGNN: Label-enhanced time-aware graph neural network for phishing detection on Ethereum
Changhao Wu, Jitao Wang, Wenke Zhu, Weili Han, Hongfeng Chai |
Expert Syst. Appl. | 5 |
| 2026 | PII-Bench: Evaluating Query-Aware Privacy Protection SystemsabstractThe widespread adoption of Large Language Models (LLMs) has raised significant privacy concerns regarding the exposure of personally identifiable information (PII) in user prompts.To address this challenge, we propose a queryunrelated PII masking strategy and introduce PII-Bench, the first comprehensive evaluation framework for assessing privacy protection systems.PII-Bench comprises 2,842 test samples across 7 PII types with 55 fine-grained subcategories, featuring diverse scenarios from singlesubject descriptions to complex multi-party interactions.Each sample is carefully crafted with a user query, context description, and standard answer indicating query-relevant PII.Our empirical evaluation reveals that while current models perform adequately in basic PII detection, they show significant limitations in determining PII query relevance.Even advanced LLMs struggle with this task, particularly in handling complex multi-subject scenarios, indicating substantial room for improvement in achieving intelligent PII masking. Zhouhong Gu, Haokai Hong, Weili Han, Hongfeng Chai |
ACL (1) | 4 |
| 2026 | MoPE: A Mixture of Password Experts for Improving Password GuessingabstractTextual passwords remain a predominant authentication mechanism in web security. To evaluate their strength, existing research has proposed several data-driven models across various scenarios. However, these models generally treat passwords uniformly, neglecting the structural differences among passwords. This typically results in biased training that favors frequent password structural patterns. To mitigate the biased training, we argue that passwords, as a type of complex short textual data, should be processed in a structure-aware manner by identifying their structural patterns and routing them to specialized models accordingly. In this paper, we propose MoPE, a Mixture of Password Experts framework, specifically designed to leverage the structural patterns in passwords to improveguessing performance. Motivated by the observation that passwords with similar structural patterns (e.g., fixed-length numeric strings) tend to cluster in high-density regions within the latent space, our MoPE introduces: (1) a novel structure-based method for generating specialized expert models; (2) a lightweight gate method to select appropriate expert models to output reliable guesses, better aligned with the high computational frequency of password guessing tasks. Our evaluation shows that MoPE significantly outperforms existing state-of-the-art baselines in both offline and online guessing scenarios, achieving up to 38.80% and 9.27% improvement in cracking rate, respectively, showcasing that MoPE can effectively exploit the capabilities of data-driven models for password guessing. Additionally, we implement a real-time Password Strength Meter (PSM) based on offline MoPE, assisting users in choosing stronger passwords more precisely with millisecond-level response latency. Mingjian Duan, Weili Han |
SP | 4 |
| 2026 | ARuleCon: Agentic Security Rule ConversionabstractThe real-time demand for web security makes Security Information and Event Management (SIEM) platforms and their applied security rule an integral part of the intrusion detection life-cycle. However, the heterogeneity of vendor-specific rules (e.g., Splunk SPL, Microsoft KQL, IBM AQL, Google YARA-L, and RSA ESA) makes cross-platform rule reuse extremely difficult, requiring deep domain knowledge for reliable conversion. As a result, an autonomous and accurate rule conversion framework can significantly lead to effort savings, preserving the value of existing rules. In this paper, we propose ARuleCon, an agentic SIEM-rule conversion approach. Using ARuleCon, the security professionals do not need to distill the source rules' logic and re-map it to target vendors, instead, they provide the source rules, the documentation of the target rules and ARuleCon can purposely convert to the target vendors without more intervention. To achieve this, ARuleCon is equipped with intermediate representation (IR) that aligns core detection logic into vendor-neutral layer, agentic RAG pipeline that retrieves authoritative official vendor documentation to address the convension/schema mismatches, and Python-based consistency check that running both source and target rules in controlled test environments to mitigate subtle semantic drifts. We present a comprehensive evaluation of ARuleCon ranging from textual alignment between the source and target rules, and the execution success of target rules, showcasing ARuleCon can convert rules with higher fidelity, outperforming the baseline LLM models by 15% averagely. Finally, we perform a case study and interview with our industry collaborators 1, which showcases that ARuleCon can significantly save the expert's time on understanding the cross-SIEM's documentation and remapping the logic. Ming Xu 0006, Hongtai Wang, Yanpei Guo, Zhengmin Yu, Weili Han, Hoon Wei Lim, Jin Song Dong 0001, Jiaheng Zhang |
WWW | 5 |
| 2026 | ETTracker: A fund tracking framework for anti-money laundering on Ethereum
Changhao Wu, Kai Wang 0062, Weili Han, Hongfeng Chai |
Expert Syst. Appl. | 4 |
| 2026 | SharedRXC: A Trustless Privacy-Preserving Asset Cross-Chain Scheme by Liability EqualizationabstractCross-chain technology, as a key driver for enhancing interoperability of blockchains, enables asset transfer and exchange between different blockchains. At present, cross-chain models based on light clients are widely adopted due to their fully decentralized nature and applicability to diverse scenarios. However, the rapid advancement of on-chain analysis techniques, such as address linkage and fund flow tracking, has significantly increased risks of de-anonymization in cross-chain transactions, posing serious privacy challenges. In this paper, we propose SharedRXC, a privacy-preserving asset cross-chain scheme for the light-client cross-chain model, which guarantees address unlinkability without extra privacy trust assumptions. First, to hide cross-chain addresses during interchain transmission, we propose the Ring Account (RA) to replace a single address for sending or receiving funds. In addition, we propose a zero-knowledge proof-based method to verify virtual identity ownership, allowing the virtual identity to track fund balances without exposing the addresses. Second, to prevent the exposure of the link between an address and its virtual identity caused by fund amount differences during deposits or withdrawals, which would compromise address unlinkability, we propose the Shared Burn/Mint method to obscure on chain fund change differences. Based on the liability equalization mechanism, we design two privacy-preserving cross-chain protocols: the cross-chain asset transfer (SharedRXC.T) and exchange (SharedRXC.E) protocols. Finally, we evaluateSharedRXC.TandSharedRXC.E, which reduce gas costs by 30% to 40% compared to zkCross and achieve execution times in the millisecond range. Therefore, SharedRXC provides a practical privacy-preserving solution for cross-chain financial applications in the multi-chain ecosystem. Jitao Wang, Nong Tang, Weili Han |
IEEE Internet Things J. | 5 |
| 2026 | privXCA: An efficient and privacy-preserving auditing architecture for cross-chain transfers
Jitao Wang, Changhao Wu, Yakun Chen, Weili Han |
J. Syst. Archit. | 4 |
| 2026 | Bifrost: A Much Simpler Secure Two-Party Data Join Protocol for Secure Data Analytics
Mingxun Zhou, Guopeng Lin, Weili Han |
Proc. VLDB Endow. | 5 |
| 2025 | On the Account Security Risks Posed by Password Strength Meters
Ming Xu 0006, Weili Han, Jitao Yu, Yun Lin 0001, Jin Song Dong 0001 |
AsiaCCS | 2 |
| 2025 | Kona: An Efficient Privacy-Preservation Framework for KNN Classification by Communication OptimizationabstractK-nearest neighbors (KNN) classification plays a significant role in various applications due to its interpretability. The accuracy of KNN classification relies heavily on large amounts of high-quality data, which are often distributed among different parties and contain sensitive information. Dozens of privacy-preserving frameworks have been proposed for performing KNN classification with data from different parties while preserving data privacy. However, existing privacy-preserving frameworks for KNN classification demonstrate communication inefficiency in the online phase due to two main issues: (1) They suffer from huge communication size for secure Euclidean square distance computations. (2) They require numerous communication rounds to select the $k$ nearest neighbors. In this paper, we present $\texttt{Kona}$, an efficient privacy-preserving framework for KNN classification. We resolve the above communication issues by (1) designing novel Euclidean triples, which eliminate the online communication for secure Euclidean square distance computations, (2) proposing a divide-and-conquer bubble protocol, which significantly reduces communication rounds for selecting the $k$ nearest neighbors. Experimental results on eight real-world datasets demonstrate that $\texttt{Kona}$ significantly outperforms the state-of-the-art framework by $1.1\times \sim 3121.2\times$ in communication size, $16.7\times \sim 5783.2\times$ in communication rounds, and $1.1\times \sim 232.6\times$ in runtime. Guopeng Lin, Ruisheng Zhou, Weili Han, Wenjing Fang |
ICML | 4 |
| 2025 | Is MPC Secure? Leveraging Neural Network Classifiers to Detect Data Leakage Vulnerabilities in MPC ImplementationsabstractDue to the emerging privacy-protection laws and regulations (e.g. GDPR in the EU) in recent years, dozens of multi-party computation (MPC for short) protocols have been proposed and widely applied by companies and institutions. These MPC protocols enable companies and institutions to perform joint analyses and machine learning on their private data while protecting their data's privacy. However, due to the complexity of MPC protocols, their implementations of-ten contain data leakage vulnerabilities, which can critically undermine the intended privacy protection. Additionally, most existing security analyses of MPC protocols rely on theoretical proofs, neglecting to detect possible vulnerabilities in MPC im-plementations. Therefore, detecting data leakage vulnerabilities in MPC implementations is an urgent necessity. In this paper, we propose MPCGuard, a practical frame-work for detecting data leakage vulnerabilities in MPC imple-mentations. Different from traditional memory vulnerabilities, data leakage vulnerabilities in MPC implementations cannot be identified by existing sanitizers. To resolve this challenge, we first establish a leakage identifier in MPCGuard with two neural network classifiers to identify whether an MPC implementation contains data leakage vulnerabilities. To enhance identification effectiveness, the structures of neural network classifiers are designed according to the characteristics of MPC protocols. After identifying a data leakage vulnerability, we employ a delta method to assist in locating the vulnerability. To demonstrate the effectiveness of MPCGuard, we apply MPCGuard to test 29 commonly-used MPC implementations in three main-stream MPC frameworks, i.e. Crypten, TF-Encrypted, and MP-SPDZ. We discover that 12 out of 29 implementations contain data leakage vulnerabilities, some of which can lead to the reconstruction of raw data. Until the moment this paper is written, all vulnerabilities, two of which have been assigned with CVE-IDs, have been confirmed. To the best of our knowledge, these two CVE-IDs are the first CVE-IDs assigned for data leakage vulnerabilities in MPC implementations. Guopeng Lin, Xiaoning Du 0001, Lushan Song, Weili Han, Junming Ma, Wenjing Fang |
SP | 4 |
| 2025 | HawkEye: Statically and Accurately Profiling the Communication Cost of Models in Multi-party Learning
Wenqiang Ruan, Ruisheng Zhou, Guopeng Lin, Weili Han |
USENIX Security Symposium | 6 |
| 2025 | Suda: An Efficient and Secure Unbalanced Data Alignment Framework for Vertical Privacy-Preserving Machine Learning
Lushan Song, Qizhi Zhang 0007, Daode Zhang, Weili Han, Jue Hong, Quanwei Cai 0003 |
USENIX Security Symposium | 7 |
| 2025 | Using Parallel Techniques to Accelerate PCFG-Based Password Cracking AttacksabstractTextual passwords play an important role among access-control mechanisms and are usually stored as ciphertext in the server. However, an attacker may attempt to hash a large number of candidate passwords to find the match of the target hash of a password database. To crack the password database, attackers in industry usually use the cracking software like Hashcat. Academic researchers recently proposed many data-driven probabilistic models, in which the Probabilistic Context-free Grammars (PCFG, for short) stand out. Despite the great cracking efficiency, the data-driven models are seldom used by industrial practice due to the significant slow generation speed of password candidates. To bridge the gap and promote the efficient data-driven models being practically used in industry, we propose that using parallel techniques to accelerate the candidate password generation, enabling the integration of PCFG models into the practically-used Hashcat tool. To this end, we mainly propose two algorithms to accelerate the password generation for PCFG-based models: first, we design a storage structure with the memory load balance strategy to more evenly store the data structures used to generate passwords; second, we design an algorithm to produce candidate passwords in parallel by different threads. Based on the two algorithms, we proposeParallel_PCFG, and implementParallel_PCFGupon Hashcat based on its built-in GPU kernel. We comprehensively evaluateParallel_PCFGagainst state-of-the-art data-driven models, and find thatParallel_PCFGonly takes 14.33% of time to achieve the same cracking rates compared with the best-performing models, paving a way about the integration between PCFG-based models and Hashcat. Ming Xu 0006, Kai Zhang 0006, Jitao Yu, Luwei Cheng, Weili Han |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2024 | Ents: An Efficient Three-party Training Framework for Decision Trees by Communication OptimizationabstractMulti-party training frameworks for decision trees based on secure multi-party computation enable multiple parties to train high-performance models on distributed private data with privacy preservation. The training process essentially involves frequent dataset splitting according to the splitting criterion (e.g. Gini impurity). However, existing multi-party training frameworks for decision trees demonstrate communication inefficiency due to the following issues: (1) They suffer from huge communication overhead in securely splitting a dataset with continuous attributes. (2) They suffer from huge communication overhead due to performing almost all the computations on a large ring to accommodate the secure computations for the splitting criterion. Guopeng Lin, Weili Han, Wenqiang Ruan, Ruisheng Zhou, Lushan Song, Bingshuai Li, Yunfeng Shao 0001 |
CCS | 2 |
| 2024 | Exploring Unconfirmed Transactions for Effective Bitcoin Address ClusteringabstractThe advancement of clustering heuristics has demonstrated that the addresses of Bitcoin, which are protected by their anonymous mechanisms, can be de-anonymized. While the state-of-the-art (SOTA) clustering heuristics focus on confirmed transactions stored in the blockchain, they ignore unconfirmed transactions in the mempool. These unconfirmed transactions contain information about transactions before being stored in the blockchain, covering additional address associations that can improve Bitcoin address clustering. Kai Wang 0062, Yakun Cheng, Michael Wen Tong, Zhenghao Niu, Jun Pang 0001, Weili Han |
WWW | 6 |
| 2024 | BFTDiagnosis: An automated security testing framework with malicious behavior injection for BFT protocols
Jitao Wang, Kai Wang 0062, Weili Han |
Comput. Networks | 5 |
| 2024 | Ruyi: A Configurable and Efficient Secure Multi-Party Learning Framework With Privileged PartiesabstractSecure multi-party learning (MPL) enables multiple parties to train machine learning models with privacy preservation. MPL frameworks typically follow the peer-to-peer architecture, where each party has the same chance to handle the results. However, the cooperative parties in business scenarios usually have unequal statuses. Thus, Song et al. (CCS’22) presentedpMPL, a hierarchical MPL framework with a privileged party. Nonetheless,pMPLhas two limitations: (i) it has limited configurability requiring manually finding a public matrix that satisfies four constraints, which is difficult when the number of parties increases, and (ii) it is inefficient due to the huge online communication overhead. In this paper, we are motivated to proposeRuyi, a configurable and efficient MPL framework with privileged parties. Firstly, we reduce the public matrix constraints from four to two while ensuring the same privileged guarantees by extending the standard resharing paradigm to vector space secret sharing in order to implement the share conversion protocol and performing all the computations over a prime field rather than a ring. This enhances the configurability so that the Vandermonde matrix can always satisfy the public matrix constraints when given the number of parties, including privileged parties, assistant parties, and assistant parties allowed to drop out. Secondly, we reduce the online communication overhead by adapting the masked evaluation paradigm to vector space secret sharing. Experimental results demonstrate thatRuyiis configurable with multiple parties and outperformspMPLby up to$ 53.87 \times $,$13.91 \times $, and$2.76 \times $for linear regression, logistic regression, and neural networks, respectively. Lushan Song, Zhexuan Wang, Guopeng Lin, Weili Han |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | XRAD: Ransomware Address Detection Method based on Bitcoin Transaction RelationshipsabstractRecently, there is a surge in ransomware activities that encrypt users’ sensitive data and demand bitcoins for ransom payments to conceal the criminal’s identity. It is crucial for regulatory agencies to identify as many ransomware addresses as possible to accurately estimate the impact of these ransomware activities. However, existing methods for detecting ransomware addresses rely primarily on time-consuming data collection and clustering heuristics, and they face two major issues: (1) The features of an address itself are insufficient to accurately represent its activity characteristics, and (2) the number of disclosed ransomware addresses is extremely less than the number of unlabeled addresses. These issues lead to a significant number of ransomware addresses being undetected, resulting in a substantial underestimation of the impact of ransomware activities. To solve the above two issues, we propose an optimized ransomware address detection method based on Bitcoin transaction relationships, named XRAD , to detect more ransomware addresses with high performance. To address the first one, we present a cascade feature extraction method for Bitcoin transactions to aggregate features of related addresses after exploring transaction relationships. To address the second one, we build a classification model based on Positive-unlabeled learning to detect ransomware addresses with high performance. Extensive experiments demonstrate that XRAD significantly improves average accuracy, recall, and F1 score by 15.07%, 19.71%, and 34.83%, respectively, compared to state-of-the-art methods. In total, XRAD detects 120,335 ransomware activities from 2009 to 2023, revealing a development trend and average ransom payment per year that aligns with three reports by FinCEN, Chainalysis, and Coveware. Kai Wang 0062, Michael Wen Tong, Jun Pang 0001, Jitao Wang, Weili Han |
ACM Trans. Web | 5 |
| 2023 | Private, Efficient, and Accurate: Protecting Models Trained by Multi-party Learning with Differential PrivacyabstractSecure multi-party computation-based machine learning, referred to as multi-party learning (MPL for short), has become an important technology to utilize data from multiple parties with privacy preservation. While MPL provides rigorous security guarantees for the computation process, the models trained by MPL are still vulnerable to attacks that solely depend on access to the models. Differential privacy could help to defend against such attacks. However, the accuracy loss brought by differential privacy and the huge communication overhead of secure multi-party computation protocols make it highly challenging to balance the 3-way trade-off between privacy, efficiency, and accuracy.In this paper, we are motivated to resolve the above issue by proposing a solution, referred to as PEA (Private, Efficient, Accurate), which consists of a secure differentially private stochastic gradient descent (DPSGD for short) protocol and two optimization methods. First, we propose a secure DPSGD protocol to enforce DPSGD, which is a popular differentially private machine learning algorithm, in secret sharing-based MPL frameworks. Second, to reduce the accuracy loss led by differential privacy noise and the huge communication overhead of MPL, we propose two optimization methods for the training process of MPL: (1) the data-independent feature extraction method, which aims to simplify the trained model structure; (2) the local data-based global model initialization method, which aims to speed up the convergence of the model training. We implement PEA in two open-source MPL frameworks: TF-Encrypted and Queqiao. The experimental results on various datasets demonstrate the efficiency and effectiveness of PEA. E.g. when ϵ = 2, we can train a differentially private classification model with an accuracy of 88% for CIFAR-10 within 7 minutes under the LAN setting. This result significantly outperforms the one from CryptGPU, one state-of-the-art MPL framework: it costs more than 16 hours to train a non-private deep neural network model on CIFAR-10 with the same accuracy. Wenqiang Ruan, Mingxin Xu, Wenjing Fang, Li Wang 0056, Lei Wang 0152, Weili Han |
SP | 6 |
| 2023 | Improving Real-world Password Guessing Attacks via Bi-directional Transformers
Ming Xu 0006, Jitao Yu, Chuanwang Wang, Haoqi Wu, Weili Han |
USENIX Security Symposium | 7 |
| 2023 | Towards Understanding the fairness of differentially private margin classifiers
Wenqiang Ruan, Mingxin Xu, Yinan Jing, Weili Han |
World Wide Web (WWW) | 4 |
| 2022 | pMPL: A Robust Multi-Party Learning Framework with a Privileged PartyabstractIn order to perform machine learning among multiple parties while protecting the privacy of raw data, privacy-preserving machine learning based on secure multi-party computation (MPL for short) has been a hot spot in recent. The configuration of MPL usually follows the peer-to-peer architecture, where each party has the same chance to reveal the output result. However, typical business scenarios often follow a hierarchical architecture where a powerful, usuallyprivileged party, leads the tasks of machine learning. Only theprivileged party can reveal the final model even if otherassistant parties collude with each other. It is even required to avoid the abort of machine learning to ensure the scheduled deadlines and/or save used computing resources when part ofassistant parties drop out. Lushan Song, Zhexuan Wang, Xinyu Tu, Guopeng Lin, Wenqiang Ruan, Haoqi Wu, Weili Han |
CCS | 8 |
| 2022 | #Segments: A Dominant Factor of Password Security to Resist against Data-driven Guessing
Chuanwang Wang, Ming Xu 0006, Weili Han |
Comput. Secur. | 5 |
| 2022 | A Large-scale Empirical Analysis of Ransomware Activities in BitcoinabstractExploiting the anonymous mechanism of Bitcoin, ransomware activities demanding ransom in bitcoins have become rampant in recent years. Several existing studies quantify the impact of ransomware activities, mostly focusing on the amount of ransom. However, victims’ reactions in Bitcoin that can well reflect the impact of ransomware activities are somehow largely neglected. Besides, existing studies track ransom transfers at the Bitcoin address level, making it difficult for them to uncover the patterns of ransom transfers from a macro perspective beyond Bitcoin addresses. In this article, we conduct a large-scale analysis of ransom payments, ransom transfers, and victim migrations in Bitcoin from 2012 to 2021. First, we develop a fine-grained address clustering method to cluster Bitcoin addresses into users, which enables us to identify more addresses controlled by ransomware criminals. Second, motivated by the fact that Bitcoin activities and their participants already formed stable industries, such as Darknet and Miner , we train a multi-label classification model to identify the industry identifiers of users. Third, we identify ransom payment transactions and then quantify the amount of ransom and the number of victims in 63 ransomware activities. Finally, after we analyze the trajectories of ransom transferred across different industries and track victims’ migrations across industries, we find out that to obscure the purposes of their transfer trajectories, most ransomware criminals (e.g., operators of Locky and Wannacry) prefer to spread ransom into multiple industries instead of utilizing the services of Bitcoin mixers. Compared with other industries, Investment is highly resilient to ransomware activities in the sense that the number of users in Investment remains relatively stable. Moreover, we also observe that a few victims become active in the Darknet after paying ransom. Our findings in this work can help authorities deeply understand ransomware activities in Bitcoin. While our study focuses on ransomware, our methods are potentially applicable to other cybercriminal activities that have similarly adopted bitcoins as their payments. Kai Wang 0062, Jun Pang 0001, Dingjie Chen, Dapeng Huang, Chen Chen 0112, Weili Han |
ACM Trans. Web | 7 |
| 2021 | Digit Semantics based Optimization for Practical Password Cracking ToolsabstractUsers usually create their passwords with meaningful digits, i.e. digit semantics, which can be partially exploited by probabilistic password guessing models with a data-driven methodology for better efficiency. However, these semantics are largely ignored by current practical password cracking tools, like John the Ripper (JtR) and Hashcat. Chuanwang Wang, Wenqiang Ruan, Ming Xu 0006, Weili Han |
ACSAC | 6 |
| 2021 | Chunk-Level Password Guessing: Towards Modeling Refined Password Composition RepresentationsabstractTextual password security hinges on the guessing models adopted by attackers, in which a suitable password composition representation is an influential factor. Unfortunately, the conventional models roughly regard a password as a sequence of characters, or natural-language-based words, which are password-irrelevant. Experience shows that passwords exhibit internal and refined patterns, e.g., "4ever, ing or 2015", varying significantly among periods and regions. However, the refined representations and their security impacts could not be automatically understood by state-of-the-art guessing models (e.g., Markov). Ming Xu 0006, Chuanwang Wang, Jitao Yu, Kai Zhang 0006, Weili Han |
CCS | 6 |
| 2021 | Temporal Networks Based Industry Identification for Bitcoin Users
Weili Han, Dingjie Chen, Jun Pang 0001, Kai Wang 0062, Chen Chen 0112, Dapeng Huang, Zhijie Fan |
WASA (1) | 1 |
| 2021 | Efficiently answering top-k frequent term queries in temporal-categorical range
Zhenying He, Chang Lu 0004, Yinan Jing, Kai Zhang 0006, Weili Han, Jianxin Li 0001, Chengfei Liu, Xiaoyang Sean Wang |
Inf. Sci. | 6 |
| 2021 | Understanding Offline Password-Cracking Methods: A Large-Scale Empirical StudyabstractResearchers proposed several data-driven methods to efficiently guess user-chosen passwords for password strength metering or password recovery in the past decades. However, these methods are usually evaluated under ad hoc scenarios with limited data sets. Thus, this motivates us to conduct a systematic and comparative investigation with a very large-scale data corpus for such state-of-the-art cracking methods. In this paper, we present the large-scale empirical study on password-cracking methods proposed by the academic community since 2005, leveraging about 220 million plaintext passwords leaked from 12 popular websites during the past decade. Specifically, we conduct our empirical evaluation in two cracking scenarios, i.e., cracking under extensive-knowledge and limited-knowledge. The evaluation concludes that no cracking method may outperform others from all aspects in these offline scenarios. The actual cracking performance is determined by multiple factors, including the underlying model principle along with dataset attributes such as length and structure characteristics. Then, we perform further evaluation by analyzing the set of cracked passwords in each targeting dataset. We get some interesting observations that make sense of many cracking behaviors and come up with some suggestions on how to choose a more effective password-cracking method under these two offline cracking scenarios. Ruixin Shi, Yongbin Zhou, Weili Han |
Secur. Commun. Networks | 4 |
| 2021 | A Smart Framework for Fine-Grained Microphone Acoustic Permission ManagementabstractMicrophones attracted a lot of attentions from attackers due to the sensitivity of voice data: attackers may control devices through abusing their microphones, fingerprint devices by measuring their microphones, or directly monitor the microphone readings to steal users’ private data. Nevertheless, OS developers failed to address the severe consequences. While the current security mechanism only offers a coarse-grained access control over the usage of microphones: recording all sound or shutting off, it is necessary to redesign the microphone security mechanism to enforce fine-grained restrictions over the usage of microphones. In this article, we propose a fine-grained microphone access control scheme on Android platform, referred to asFMC(Finer Microphone Controller). In our scheme, microphone acoustic permissions are granted with three finer policies:treble policy,timbre policyandexclusion policy, with which most of the attacks mentioned above can be defended against. In addition, to ease user’s policy management, we employ a smart policy recommendation method, avoiding additional manual policy approvals. The results in our experiments show that a negligible 1.06 percent performance overhead is incurred during policy enforcement. Besides, the policy recommendation system inFMCpromises an accuracy of 82.82 percent averagely. We believe that our work is a practical defense scheme against attacks exploiting microphone acoustic permissions and should be employed by OS developers. Weili Han, Zhe Zhou 0001, Shize Chen, Lingqi Huang, Xiaoyang Sean Wang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | TransPCFG: Transferring the Grammars From Short Passwords to Guess Long Passwords EffectivelyabstractLong passwords are gaining popularity in password policy recommendations; however, data-driven guessing studies are woefully inadequate in adapting to long passwords, lacking in both guessing efficiency and their composition guidelines. For state-of-the-art data-driven password guessing methods such as PCFGs (Probabilistic Context-free Grammars), their guessing efficiency is limited by the presence of a large scale training data, or the lack thereof. Given that long passwords leaked in the real world are typically scarce, coupled with the fact that the data-driven methods’ performance depends on training data, obtaining good performance on long passwords has become a key challenge. To overcome the dataset limitation, we propose a frameworkTransPCFG, that transfers the knowledge, (i.e., grammars in PCFGs), from short passwords to facilitate long password guessing. We further perform an empirical evaluation based on three real-world datasets and the results demonstrate superior performance over the state-of-the-art data-driven guessing methods under${10}^{14}$offline guesses. For passwords with 16 characters,TransPCFGcan compromise an average of 23.30% of the passwords, outperforming PCFG_v4.1 by 56.10%. Additionally,for better password-composition guidelines, we find that long password-composition policies requiring more segments are more resistant to guessing attacks. For the segment, the password12zxcvbnword1997has four segments since it follows the template${Digit}_{2}{Keyboard}_{6}{Letter}_{4}{Year}_{4}$. We thus recommend users to create long passwords with four or more segments instead of the widely recommended more character classes for security. Weili Han, Ming Xu 0006, Chuanwang Wang, Kai Zhang 0006, Xiaoyang Sean Wang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | BinDex: A Two-Layered Index for Fast and Robust ScansabstractIn modern analytical database systems, the performance of the data scan operation is of key importance to the performance of query execution. Existing approaches may be categorized into index scan and sequential scan. However, both approaches have inherent inefficiencies. Indeed, sequential scan may need to access a large amount of unneeded data, especially for queries with low selectivity. Instead, index scan may involve a large number of expensive random memory accesses when the query selectivity is high. Moreover, with the growing complexities in database query workloads, it has become hard to predict which approach is better for a particular query. In order to obtain fast and robust scans under all selectivities, this paper proposes BinDex, a two-layered index structure based on binned bitmaps that can be used to significantly accelerate the scan operations for in-memory column stores. The first layer of BinDex consists of a set of binned bitmaps which filter out most unneeded values in a column. The second layer provides some auxiliary information to correct the bits that have incorrect values. By varying the number of bit vectors in the first layer, BinDex can make a tradeoff between memory space and performance. Experimental results show that BinDex outperforms the state-of-the-art approaches with less memory than a B+-tree would use. And by enlarging the memory space, BinDex can achieve up to 2.9 times higher performance, eliminating the need for making a choice between sequential or index scans. Kai Zhang 0006, Jiading Guo, Zhenying He, Yinan Jing, Weili Han, Xiaoyang Sean Wang |
SIGMOD Conference | 7 |
| 2020 | Automated Enforcement of the Principle of Least Privilege over Data Source AccessabstractThe state-of-the-art database-backed web applications usually assign full privileges to connections between applications and data sources. This phenomenon, which would enable a malicious attacker to easily compromise the applications through arbitrarily manipulating the data sources without the restriction of privileges, seriously breaks the principle of least privilege (PLP), a fundamental law of system security. Motivated to counter this problem, we propose a framework PDA (PLP over Data source Access) to automatically enforce this principle over data source access based on application-driven privilege separation. Our proposed PDA contributes from the following aspects: i) PDA achieves the privilege separation by intercepting database queries and enforcing privileged connections to database for each database query; ii) PDA can effectively defend against SQL-based vulnerabilities including buggy queries and SQL injection attacks. Lastly, we evaluate PDA on a widely used application platform, JForum, to demonstrate the effectiveness of PDA with a promising performance overhead of 8.13%. Haoqi Wu, Zhengxuan Yu, Dapeng Huang, Weili Han |
TrustCom | 5 |
| 2020 | Decentralized data access control over consortium blockchains
Yaoliang Chen, Jiao Liang, Lance Feagan, Weili Han, Xiaoyang Sean Wang |
Inf. Syst. | 5 |
| 2020 | senDroid: Auditing Sensor Access in Android System-WideabstractSensors are widely used in modern mobile devices (e.g., smartphones, watches) and may gather abundant information from environments as well as about users, e.g., photos, sounds and locations. The rich set of sensor data enables various applications (e.g., health monitoring) and personalized apps as well. However, the powerful sensing abilities provide opportunities for attackers to steal both personal sensitive data and commercial secrets like never before. Unfortunately, the current design of smart devices only provides a coarse access control on sensors and does not have the capability to audit sensing. We argue that knowing how often the sensors are accessed and how much sensor data are collected is the first-line defense against sensor data breach. Such an ability is yet to be designed. In this paper, we propose a framework that allows users to acquire sensor data usages. In particular, we leverage a hook-based track method to track sensor accesses. Thus, with no need to change the source codes of the Android system and applications, we can intercept sensing operations to graphic sensors, audio sensors, location sensors, and standard sensors, and audit them from four aspects: flow audit, frequency audit, duration audit and invoker audit. Then, we implement a prototype, referred to as senDroid, which visually shows the quantitative usages of these sensors in real time at a performance overhead of [0.04-8.05] percent. senDroid allows Android users to audit the applications even when they bypass the Android framework via JNI invocations or when the malicious codes are dynamically loaded from the server side. Our empirical study on 1,489 popular apps in three well-known Android app markets shows that 26.32 percent apps access sensors when the apps are launched, and 11.01 percent apps access sensors while the apps run in the background. Furthermore, we analyze the relevance between sensor usage patterns and third-party libraries, and reverse-engineering on suspicious third-party libraries shows that 77.27 percent apps access sensors via third-party libraries. Our results call attentions to address the users' privacy concerns caused by sensor access. Weili Han, Hao Chen 0003, Dong Li 0024, Zheran Fang, Wenyuan Xu 0001, Xiaoyang Sean Wang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | Cyberspace-Oriented Access Control: A Cyberspace Characteristics-Based Model and its PoliciesabstractWith wide development of various information technologies, our daily activities are becoming deeply dependent on cyberspace. People often use handheld devices (e.g., mobile phones or laptops) to publish social messages, facilitate remote e-health diagnosis, or monitor a variety of surveillance. However, security insurance for these activities remains as a significant challenge. Representation of security purposes and their enforcement are two main issues in security of cyberspace. To address these challenging issues, we propose a cyberspace-oriented access control model (CoAC) for cyberspace whose typical usage scenario is as follows. Users leverage devices via network of networks to access sensitive objects with temporal and spatial limitations. We generalize subjects and objects in cyberspace and propose scene-based access control. To enforce security purposes, we argue that all operations on information in cyberspace are combinations of atomic operations. If every single atomic operation is secure, then the cyberspace is secure. Taking applications in the browser-server architecture as an example, we present seven atomic operations for these applications. A number of cases demonstrate that operations in these applications are combinations of introduced atomic operations. We also design a series of security policies for each atomic operation. Finally, we demonstrate both feasibility and flexibility of our CoAC model by examples. Fenghua Li 0001, Zifu Li, Weili Han, Ting Wu 0001, Yunchuan Guo, Jinjun Chen |
IEEE Internet Things J. | 3 |
| 2019 | An Explainable Password Strength Meter Addon via Textual Pattern RecognitionabstractTextual passwords are still dominating the authentication of remote file sharing and website logins, although researchers recently showed several vulnerabilities about this authentication mechanism. When a user creates or changes a password, a website usually leverages a password strength meter (PSM for short) to show the strength of the password. When the password is evaluated as a weak one, the user may replace the password with a stronger or securer one. However, the user is usually confused when the password, especially a frequently used password, is shown as a weak one. We argue that an explainable password strength meter addon, which could show the reasons of weak, may help users to more effectively create a secure password. Unfortunately, we find few sites in Alexa global top 100 showing these details. Motivated to help users with an explainable PSM, this paper proposes an addon to PSMs providing feedbacks in the form of pattern passwords explaining why a password is weak. This PSM addon can detect twelve types of patterns, which cover a very large proportion among 70 million of leaked real passwords from high-profile websites. According to our evaluation and user study, our PSM addon, which leverages textual pattern passwords, can effectively detect these popular patterns and effectively help users create securer passwords. Ming Xu 0006, Weili Han |
Secur. Commun. Networks | 2 |
| 2018 | DESC: enabling secure data exchange based on smart contracts
Jiao Liang, Weili Han, Zeqing Guo, Yaoliang Chen, Xiaoyang Sean Wang, Fenghua Li 0001 |
Sci. China Inf. Sci. | 2 |
| 2018 | Shadow Attacks Based on Password Reuses: A Quantitative Empirical AnalysisabstractWith the proliferation of websites, the security level of password-protected accounts is no longer purely determined by individual ones. Users may register multiple accounts on the same site or across multiple sites, and these passwords from the same users are likely to be the same or similar. As a result, an adversary can compromise the account of a user on a web forum, then guess the accounts of the same user in sensitive accounts, e.g., online banking services, whose accounts could have the same or even stronger passwords. We name this attack as the shadow attack on passwords. To understand the situation, we examined the state-ofthe-art Intra-Site Password Reuses (ISPR) and Cross-Site Password Reuses (CSPR) based on the leaked passwords from the biggest Internet user group (i.e., 668 million members in China). With a collection of about 70 million real-world web passwords across four large websites in China, we obtained around 4.6 million distinct users who have multiple accounts on the same site or across different sites. We found that for the users with multiple accounts in a single website, 59.72 percent reused their passwords and for the users with multiple accounts on multiple websites, 33.16 + 8.91 percent reused their passwords across websites. For the users that have multiple accounts but different passwords, the set of passwords of the same user exhibits patterns that can help password guessing: a leaked weak password reveals partial information of a strong one, which degrades the strength of the strong one. Given the aforementioned findings, we conducted an experiment and achieved a 39.38 percent improvement of guessing success rate with John the Ripper guessing tool. To the best of our knowledge, we are the first to provide a large-scale, empirical, and quantitative measurement of web password reuses, especially ISPR, and shed light on the severity of such threat in the real world. Weili Han, Zhigong Li, Minyue Ni, Guofei Gu, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | Application-Specific Digital Forensics Investigative Model in Internet of Things (IoT)abstractBesides its enormous benefits to the industry and community the Internet of Things (IoT) has introduced unique security challenges to its enablers and adopters. As the trend in cybersecurity threats continue to grow, it is likely to influence IoT deployments. Therefore it is eminent that besides strengthening the security of IoT systems we develop effective digital forensics techniques that when breaches occur we can track the sources of attacks and bring perpetrators to the due process with reliable digital evidence. The biggest challenge in this regard is the heterogeneous nature of devices in IoT systems and lack of unified standards. In this paper we investigate digital forensics from IoT perspectives. We argue that besides traditional digital forensics practices it is important to have application-specific forensics in place to ensure collection of evidence in context of specific IoT applications. We consider top three IoT applications and introduce a model which deals with not just traditional forensics but is applicable in digital as well as application-specific forensics process. We believe that the proposed model will enable collection, examination, analysis and reporting of forensically sound evidence in an IoT application-specific digital forensics investigation. Tanveer A. Zia, Peng Liu 0005, Weili Han |
ARES | 3 |
| 2017 | Does #like4like indeed provoke more likes?abstractHashtags, created by social network users, have gained a huge popularity in recent years. As a kind of metatag for organizing information, hashtags in online social networks, especially in Instagram, have greatly facilitated users' interactions. In recent years, academia starts to use hashtags to reshape our understandings on how users interact with each other. #like4like is one of the most popular hashtags in Instagram with more than 290 million photos appended with it, when a publisher uses #like4like in one photo, it means that he will like back photos of those who like this photo. Different from other hashtags, #like4like implies an interaction between a photo's publisher and a user who likes this photo, and both of them aim to attract likes in Instagram. In this paper, we study whether #like4like indeed serves the purpose it is created for, i.e., will #like4like provoke more likes? We first perform a general analysis of #like4like with 1.8 million photos collected from Instagram, and discover that its quantity has dramatically increased by 1,300 times from 2012 to 2016. Then, we study whether #like4like will attract likes for photo publishers; results show that it is not #like4like but actually photo contents attract more likes, and the lifespan of a #like4like photo is quite limited. In the end, we study whether users who like #like4like photos will receive likes from #like4like publishers. However, results show that more than 90% of the publishers do not keep their promises, i.e., they will not like back others who like their #like4like photos; and for those who keep their promises, the photos which they like back are often randomly selected. Yang Zhang 0016, Minyue Ni, Weili Han, Jun Pang 0001 |
WI | 3 |
| 2017 | Socialized policy administration
Zeqing Guo, Weili Han, Liangxing Liu, Wenyuan Xu 0001, Minyue Ni, Yunlei Zhao, Xiaoyang Sean Wang |
Comput. Secur. | 2 |
| 2017 | Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of PasswordsabstractIn this paper, we conduct a large-scale study on the crackability, correlation, and security of 145 million real world passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of 145 million real world passwords against 6+ state-of-the-art password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial password strength meters (e.g., Google, QQ) and the security impacts of username/email leakage on passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both password users and system administrators to gain a deeper understanding of the vulnerability of real passwords against state-of-the-art password cracking algorithms, as well as to shed light on future password security research topics. Shouling Ji, Shukun Yang, Xin Hu 0001, Weili Han, Zhigong Li, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2016 | revDroid: Code Analysis of the Side Effects after Dynamic Permission Revocation of Android AppsabstractDynamic revocation of permissions of installed Android applications has been gaining popularity, because of the increasing concern of security and privacy in the Android platform. However, applications often crash or misbehave when their permissions are revoked, rendering applications completely unusable. Even though Google has officially introduced the new permission mechanism in Android 6.0 to explicitly support dynamic permission revocation, the issue still exists. In this paper, we conduct an empirical study to understand the latest application practice post Android 6.0. Specifically, we design a practical tool, referred to as revDroid, to help us to empirically analyze how often the undesirable side effects, especially application crash, can occur in off-the-shelf Android applications. From the analysis of 248 popular applications from Google Play Store, revDroid finds out that 70% applications and 46% permission-relevant calls do not appropriately catch exceptions caused by permission revocation, while third-party libraries pay much more attention to permission revocation. We also use revDroid to analyze 132 recent malware samples. The result shows that only 27% malwares and 36% permission-relevant API calls of malwares fail to consider the permission revocation. In fact, many of them perform specialized handling of permission revocation to keep the core malicious logic running. Finally, revDroid can be used to help developers uncover the unhandled permission revocations during development time and greatly improve the application quality. Zheran Fang, Weili Han, Dong Li 0024, Zeqing Guo, Danhao Guo, Xiaoyang Sean Wang, Zhiyun Qian, Hao Chen 0003 |
AsiaCCS | 2 |
| 2016 | Camera-Recognizable and Human-Invisible Labelling for Privacy ProtectionabstractModern mobile devices, especially smartphones, are widely equipped with cameras, which enable their owners to capture every memorable moment or scenery, such as parties with friends. However, significant privacy concerns are posed by the potential possibility of revealing a large amount of privacy contained by photos, e.g., portrait of a person. World Driven Access Control (WDAC) [1], which triggered by environment signs rather than user operations, provides a privacy access control mechanism for photographed objects (including people and other objects containing sensitive information). WDAC supports several policy label forms which either have impact on the normal appearance of objects or rely on sensors other than camera to sense policy labels. This paper proposes an approach of labelling with a Near Infrared (NIR) label which relies only on camera and has no influence on normal appearance of objects. When an object wears a NIR label, surrounding people are unaware of the existence of the labels. Meanwhile, we design and implement a policy label recognition and policy enforcement system based on Android. The system is able to recognize NIR labels binding to objects, and then enforce privacy policies, such as Gaussian Blur, on these objects to protect their privacy. Dong Li 0024, Danhao Guo, Weili Han, Hao Chen 0003, Xiaoyang Sean Wang |
MSN | 3 |
| 2016 | An Empirical Study on User Access Control in Online Social NetworksabstractIn recent years, access control in online social networks has attracted academia a considerable amount of attention. Previously, researchers mainly studied this topic from a formal perspective. On the other hand, how users actually use access control in their daily social network life is left largely unexplored. This paper presents the first large-scale empirical study on users' access control usage on Twitter and Instagram. Based on the data of 150k users on Twitter and 280k users on Instagram collected consecutively during three months in New York, we have conducted both static and dynamic analysis on users' access control usage. Our findings include: female users, young users and Asian users are more concerned about their privacy; users who enable access control setting are less active and have smaller online social circles; global events and important festivals can influence users to change their access control setting. Furthermore, we exploit machine learning classifiers to perform an access control setting prediction. Through experiments, the predictor achieves a fair performance with the AUC equals to 0.70, indicating whether a user enables her access control setting or not can be predicted to a certain extent. Minyue Ni, Yang Zhang 0016, Weili Han, Jun Pang 0001 |
SACMAT | 3 |
| 2016 | Unique on the Road: Re-identification of Vehicular Location-Based Metadata
Cheng Wang 0001, Weili Han, Changjun Jiang 0002 |
SecureComm | 3 |
| 2016 | Regional Patterns and Vulnerability Analysis of Chinese Web PasswordsabstractCurrent research on password security pays much attention on users who speak Indo-European languages (English, Spanish, and so on), and thus the countermeasures are heavily influenced by Indo-European speakers' choices as well. However, languages have a strong impact on passwords. Analysis without considering other languages (e.g., Chinese) might lead to some biased results, such as Chinese passwords are one of the most difficult ones to guess. We believe that such a conclusion could be biased because, to the best of our knowledge, little empirical study has examined the regional differences of passwords at a large scale, especially on Chinese passwords. In this paper, we comprehensively study the differences between passwords from Chinese and English-dominant users, leveraging over 100 million leaked and publicly available passwords from Chinese and international websites in recent years. We find that Chinese prefer digits when composing their passwords, while English-dominant users prefer letters, especially lowercase letters. However, their strength against password guessing is similar. Second, we observe that both groups of users prefer to use the patterns that they are familiar with, e.g., Chinese Pinyins for Chinese and English words for English-dominant users. In particular, since multiple input methods require various sequences of letters to enter the same Chinese characters, we evaluate the impacts of various Chinese input methods, in addition to Pinyin. Third, we observe that both Chinese and English-dominant users prefer their conventional format when they use dates to construct passwords. Based on these observations, we improve two password guessing methods: 1) probabilistic context-free grammar (PCFG)-based password guessing method and 2) Markov model-based password guessing method. For the PCFG-based method, the guessing efficiency increases by up to 48% after inserting Pinyins (about 2.3% more entries) into the attack dictionary and inserting the observed composition rules into the guessing rule set. For the Markov-model-based method, the guessing efficiency increases by up to 4.7% after we increase the percentage of Pinyins in the training set. Our research sheds light on understanding the impact of regional patterns on passwords. Weili Han, Zhigong Li, Lang Yuan, Wenyuan Xu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | SPA: Inviting Your Friends to Help Set Android AppsabstractMore and more powerful personal smart devices take users, especially the elder, into a disaster of policy administration where users are forced to set personal management policies in these devices. Considering a real case of this issue in the Android security, it is hard for users, even some programmers, to generally identify malicious permission requests when they install a third-party application. Motivated by the popularity of mutual assistance among friends (including family members) in the real world, we propose a novel framework for policy administration, referring to Socialized Policy Administration (SPA for short), to help users manage the policies in widely deployed personal devices. SPA leverages a basic idea that a user may invite his or her friends to help set the applications. Especially, when the size of invited friends increases, the setting result can be more resilient to a few malicious or unprofessional friends. We define the security properties of SPA, and propose an enforcement framework where users' friends can help users set applications without the leakage of friends' preferences with the supports of a privacy preserving mechanism. In our prototype, we only leverage partially homomorphic encryption cryptosystems to implement our framework, because the fully homomorphic encryption is not acceptable to be deployed in a practical service at the moment. Based on our prototype and performance evaluation, SPA is promising to support major types of policies in current popular applications with acceptable performance. Zeqing Guo, Weili Han, Liangxing Liu, Wenyuan Xu 0001, Ruiqi Bu, Minyue Ni |
SACMAT | 2 |
| 2015 | Fine-Grained Business Data Confidentiality Control in Cross-Organizational TrackingabstractWith the support of the Internet of Things (IoT for short) technologies, tracking systems are being widely deployed in many companies and organizations in order to provide more efficient and trustworthy delivery services. Such systems usually support easy-to-use interfaces, by which users can visualize the shipping status and progress of merchandise, according to business data which are collected directly from the merchandise through sensing technologies. However, these business data may include sensitive business information, which should be strongly protected in cross-organizational scenarios. Thus, it is critical for suppliers that the disclosure of such data to unauthorized users is prevented in the context of the open environment of these tracking systems. As business data from different suppliers and organizations are usually associated together with merchandise being shipped, it is also important to support fine-grained confidentiality control. In this paper, we articulate the problem of fine-grained business data confidentiality control in IoT-enabled cross-organizational tracking systems. We then propose a fine-grained confidentiality control mechanism, referred to as xCP-ABE, to address the problem in the context of open environment. The xCP-ABE mechanism is a novel framework which makes suppliers in tracking systems able to selectively authorize specific sets of users to access their sensitive business data and satisfies the confidentiality of transmission path of goods. We develop a prototype of the xCP-ABE mechanism, and then evaluate its performance. We also carry out a brief security analysis of our proposed mechanism. Our evaluation and analysis show that our framework is an effective and efficient solution to ensure the confidentiality of business data in cross-organizational tracking systems. Weili Han, Zeqing Guo, Elisa Bertino |
SACMAT | 1 |
| 2014 | A Large-Scale Empirical Analysis of Chinese Web Passwords
Zhigong Li, Weili Han |
USENIX Security Symposium | 2 |
| 2014 | Permission based Android security: Issues and countermeasures
Zheran Fang, Weili Han, Yingjiu Li |
Comput. Secur. | 2 |
| 2014 | Dynamic combination of authentication factors based on quantified risk and benefitabstractABSTRACT By combining multiple factors during authentication, a service can provide better assurance of security. However, the users are likely to feel inconvenient, or even discard the service. This paper, therefore, addresses this issue and introduces a novel method, referred to as the Quantified riSk and Benefit adaptive Authentication Factors combination (QSBAF). QSBAF balances the requirements for both security and usability in the authentication of an information system and improves the system's ability to respond quickly to emerging risky events. In QSBAF, the authentication factors can be dynamically combined on the basis of quantified risk, benefit measurements, and combination policies. Furthermore, QSBAF provides an adaptive mechanism, which is driven by history data to justify the measurements of risk and benefit. In this paper, we use the online banking system as a typical scenario to demonstrate the usage of QSBAF. We also implement a prototype of QSBAF to evaluate the performance of its feasibility in real application scenarios. Copyright © 2013 John Wiley & Sons, Ltd. Weili Han, Chenguang Shen, Chang Lei, Sean Shen |
Secur. Commun. Networks | 1 |
| 2014 | Security of e-systemsabstractIn recent years, the dependence of people on electronic systems (e-systems) has increased tremendously.Examples of e-systems widely used in everyday life include stand-alone computers, wired and wireless networks, cellular telephony networks, corporate Web sites, electronic service, e-commerce and e-payment systems, and e-government systems.Because of the aforementioned spread of e-systems, many corporations and businesses rely heavily on the effective, proper, and secure operation of them.In most cases, such systems are used for storing, transmitting, and exchanging sensitive and confidential information, unauthorized access of which entails loss of money and credibility as well as the release of confidential information to competitors or enemies.This security is a crucial factor for these systems; however, its implementation must be cost-efficient so as to enable their widespread use.The aim of this special issue of the Journal of Security and Communication Networks is to highlight recent research in the broad area of e-systems security.We hope that this issue will be a useful reference for current and future trends in the very active area of wireless sensor networking.We received 10 papers from all over the world.Each paper was reviewed by at least two qualified reviewers.We have accepted six papers; thus, the acceptance rate for this issue is 60%.The articles in this special issue are organized as follows.The first article is entitled "A Hybrid NFC-Bluetooth Secure Protocol for Credit Transfer Among Mobile Phones" and is authored by Mohammad S. Obaidat, Petros Nicopolitidis, Weili Han |
Secur. Commun. Networks | 3 |
| 2014 | Collaborative Policy AdministrationabstractPolicy-based management is a very effective method to protect sensitive information. However, the overclaim of privileges is widespread in emerging applications, including mobile applications and social network services, because the applications' users involved in policy administration have little knowledge of policy-based management. The overclaim can be leveraged by malicious applications, then lead to serious privacy leakages and financial loss. To resolve this issue, this paper proposes a novel policy administration mechanism, referred to as collaborative policy administration (CPA for short), to simplify the policy administration. In CPA, a policy administrator can refer to other similar policies to set up their own policies to protect privacy and other sensitive information. This paper formally defines CPA and proposes its enforcement framework. Furthermore, to obtain similar policies more effectively, which is the key step of CPA, a text mining-based similarity measure method is presented. We evaluate CPA with the data of Android applications and demonstrate that the text mining-based similarity measure method is more effective in obtaining similar policies than the previous category-based method. Weili Han, Zheran Fang, Laurence T. Yang, Gang Pan 0001, Zhaohui Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Efficient General Policy Decision by Using Mutable Variable Aware CacheabstractPerformance is a key issue in the implementation of tools for policy-based management of large and complex networked systems. When a system is characterized by millions of policies, the policy decision point is usually a performance bottleneck for the whole system. Although a few researchers have proposed cache-based methods to improve the efficiency of the policy decision point, the mutable variables, e.g., time, location, and temperature, are usually hard to be dealt with. The reason is that when applicable policies contain mutable variables, the policy decision point has to re-evaluate conditions in policies for events with the same targets. This paper thus proposes a novel Mutable Variable Aware Cache mechanism, by which the entries in the cache are aware of the mutable variables. The conditions or sub-conditions that do not contain mutable variables in the applicable policies will be evaluated once during the life cycle of a policy decision point for specific events, and the evaluation results will be appended to the cache. This optimization can greatly reduce the cost of fetching the values of mutable variables and evaluating the conditions or sub-conditions. It can, therefore, improve the performance of the policy decision point. We classify the possible situations and propose key algorithms. We also conduct a performance evaluation, which shows that the Mutable Variable Aware Cache mechanism can significantly improve the efficiency of a policy decision point. Liangxing Liu, Weili Han, Elisa Bertino |
COMPSAC | 2 |
| 2012 | A survey on policy languages in network and security management
Weili Han, Chang Lei |
Comput. Networks | 1 |
| 2012 | Using automated individual white-list to protect web digital identities
Weili Han, Elisa Bertino, Jianming Yong |
Expert Syst. Appl. | 1 |
| 2011 | Poster: collaborative policy administration
Weili Han, Zheran Fang, Chang Lei |
CCS | 1 |
| 2011 | Poster: using quantified risk and benefit to strengthen the security of information sharing
Weili Han, Chenguang Shen, Yuliang Yin, Yun Gu, Chen Chen 0112 |
CCS | 1 |
| 2010 | Specify and enforce the policies of quantified risk adaptive access controlabstractXACML and its reference implementation can not directly support quantified risk adaptive access control, because there are several special requirements to specify and enforce the policies in risk adaptive access control: the elements in these policies, such as risk, risk level, are not covered; and risk in quantified risk adaptive access control would be mutable, accumulated and required to be continuously controlled. This paper, therefore, extends XACML and its reference implementation to support quantified risk adaptive access control. This paper makes two contributions: design a risk adaptive policy language extended from XACML; and propose a framework to enforce the policies. To the best of our knowledge, this paper is the first research work to discuss this topic. Chen Chen 0112, Weili Han, Jianming Yong |
CSCWD | 2 |
| 2010 | A trusted decentralized access control framework for the client/server architecture
Weili Han, Guofu Li |
J. Netw. Comput. Appl. | 1 |
| 2008 | Process-context aware matchmaking for web service composition
Weili Han, Xingdong Shi, Ronghua Chen |
J. Netw. Comput. Appl. | 1 |
| 2002 | Research on an Event Specification for Event-Based Collaboration Support Software ArchitectureabstractIn this paper, we propose an event specification language for event-based collaboration support software architecture, which incorporates some basic concepts, four event operators and four event-occurrence operators to conveniently allow complex event descriptions. The semantics of the language is also studied In the event specification language, we distinguish between event and event occurrence, identify primitive events, and introduce a small number of event operators for constructing composite (or complex) events. The novel aspect of our work lies in supporting a rich set of events and event expressions. Ping-Peng Yuan, Gang Chen 0001, Jinxiang Dong, Weili Han |
CSCWD | 4 |
| 2001 | An Event and Service Interacting Model and Event Detection Based on the Broker/Service ModelabstractIn distributed systems based on B/SM, events and event-condition-action rules are the fundamental metaphors for defining and enforcing the system. Processing entities execute behavior by reacting to and generating new events. It is important that event semantics is explicit. Although a lot of research has concentrated on event semantics, there still exists potential semantic ambiguity which is unacceptable in some circumstances. We propose an event model and incorporate an interaction group identifier into it. We emphasize that the semantics is a key to capture the actual meaning of events in real life, in which the same composite event patterns may imply totally different semantic meanings. Based on this observation, a graph-ESIG (Event and Service Interacting Graph) and ESIC (Event and Service Interacting Chain), which are constructed according to ECA-Rules, are proposed to trace events. ESIG greatly enhanced the expressive power to allow event detection correctly, which matches situations in reality. Finally, we develop a event detection algorithm that uses ESIG and ESIC. Ping-Peng Yuan, Gang Chen 0001, Jinxiang Dong, Weili Han |
CSCWD | 4 |