VLDB 2026 Research / reviewers in the wild / expert
Zonghua Zhang
dblp:42/3079
· DBLP profile ↗
75ranked-venue papers
17as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 7 first-author · 5 since 2021Computer networks · 18 · 5 first-author · 5 since 2021Systems, architecture and hardware · 9 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 8 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7Databases, data management, data science and information retrieval · 3Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Radio Frequency Identification Sensing Techniques and Systems for Structural Health Monitoring: A Review of the State of the ArtabstractThe structural damages of metallic structure components in many critical facilities and equipment may result in disasters that endanger human life. Existing Structural Health Monitoring (SHM) solutions commonly suffer from the limitations of bulky equipment, poor environmental adaptability, and high costs, which raise challenges for detection efficiency and large-scale multi-target monitoring. Radio Frequency Identification (RFID) sensing technology, featuring Non-Line-of-Sight (NLoS), flexible and pasteable, and easy deployment, show great promise for SHM. Recent studies have demonstrated the potential of RFID sensors for structural damage sensing including cracks, strain, and corrosion of metal structures, along with the analysis of parameters like crack width, structural deformation, and corrosion depth. This study provides a survey and in-depth analysis of recent technical progress in RFID sensor-based SHM. The main contributions include: (1) Classification of the novel sensing techniques and systems based on the functional model of RFID backscatter sensing; (2) Summarization of the common structural damage types and the feature extraction techniques of RFID sensing for SHM; (3) Survey of the recent progresses of the techniques, methods, and applications for RFID-based SHM; (4) Analysis of the challenges facing the state-of-the-art, including characterization and quantification of structure damage parameters and the impact of environmental factors, followed with an outlook of the future work. This study provides a timely reference for the innovation and practice of RFID sensing techniques in the field of SHM. Zhaozong Meng, Zhen Li 0066, Haichao Liu 0002, Nan Gao 0002, Zonghua Zhang |
IEEE Internet Things J. | 6 |
| 2026 | Universally composable multi-factor authentication scheme for rail control systems
Xiaoya Hu, Zonghua Zhang, Qingxuan Wang |
J. Syst. Archit. | 4 |
| 2025 | ARTMAN '25: Third Workshop on Recent Advances in Resilient and Trustworthy MAchine learning-driveN systemsabstractThe ARTMAN workshop aims to bring together academic researchers and industry practitioners from diverse domains, primarily security & privacy and machine learning, but also various application fields, to collaboratively explore and discuss resilient and trustworthy machine learning-powered applications and systems. This workshop focuses on AI/ML application domains and welcomes contributions on both foundational and applied aspects of ML across various industries, including transportation, aerospace, healthcare, energy, and finance, among others, showcasing AI-driven advances in performance and efficiency. This workshop also seeks contributions on the application of reliable and secure AI/ML algorithms, especially knowledge-informed approaches, to improve resilience and trust, particularly in human-machine partnerships and interactions within such scenarios. Gregory Blanc, Takeshi Takahashi 0001, Zonghua Zhang |
CCS | 3 |
| 2025 | GET-AID: Graph-Enhanced Transformer for Provenance-Based Advanced Persistent Threats Investigation and Detection
Fengyuan Xu, Jiahong Yang 0003, Wenting Li 0002, Zonghua Zhang, Chenbin Zhang, Meng Ma 0001, Ping Wang 0003 |
ESORICS (4) | 5 |
| 2025 | Transformer-based monocular depth estimation with hybrid attention fusion and progressive regression
Peng Liu 0072, Zonghua Zhang, Zhaozong Meng, Nan Gao 0002 |
Neurocomputing | 2 |
| 2025 | Single-Antenna SAR RFID System for Simultaneous Orientation and Position Sensing in IIoT ApplicationsabstractFor the advantages of non-contact sensing, inventory identification, and cost-effective deployment, Radio Frequency Identification (RFID) localization has become a promising solution for some industrial Internet of Things (IoT) applications. However, its efficacy is often constrained by multi-antenna dependency, motion-induced phase distortions, and the inherent phase coupling between position and orientation, all of which hinder simultaneous detection of orientation and position in high accuracy. To overcome these issues, this investigation proposes a novel phase-decoupling model specifically designed for a single-antenna synthetic aperture radar (SAR) RFID system. The key contributions include: 1) Design and implementation of an adaptive dynamic phase compensation (ADPC) mechanism for decoupling motion-induced parameters from target backscatter signatures, effectively mitigating phase offsets caused by non-steady-state antenna trajectories; 2) Establishment of a novel phase-orientation model and a differential phase-adaptive peak detection (DPAPD) framework, which integrates differential measurements with threshold-optimized peak identification, achieving sub-degree angular resolution; 3) Development of a 3D SAR localization method incorporating phase decoupling and Particle Filter (PF) which achieves robust and consistent 3D localization with acceptable accuracy. This investigation provides a high-accuracy and cost-effective dynamic monitoring solution for RFID-based smart shelves, enabling advanced applications such as inventory tracking and tilt detection for fragile goods in automated warehouses. Haichao Liu 0002, Zhaozong Meng, Zhen Li 0066, Yubo Ni, Nan Gao 0002, Zonghua Zhang |
IEEE Internet Things J. | 7 |
| 2024 | Comparative Studies of Security Assessment Methods for Railway Control SystemsabstractAs one of the typical Industrial Control System (ICS), railway control systems nowadays are faced with many security risks during its digital transformation empowered by various Information and Communications Technology (ICT), e.g., AI, 5G/6G. In addition to ensuring safety, the fundamental property of railway control system, it is important to conduct comprehensive security assessment during their design, development, deployment, and maintenance. But how to select and apply the most appropriate and efficient assessment methods is not straightforward and deserves careful studies. This paper firstly provides an in-depth analysis of the existing standards•1 for secure design and security assessment of railway control systems, in order to clarify the relationship between safety and security. It then comparatively studies the qualitative, quantitative, and simulation-based security assessment methods, along with their application scenarios, with an objective to obtaining an effective combination of these methods for railway control systems. By taking into account the specific security requirements and system characteristics of rail control systems, we finally propose a comprehensive security assessment framework for rail control systems. Hongxue Chen, Xiaoya Hu, Weihong Ma, Zonghua Zhang |
PRDC | 4 |
| 2024 | Simultaneous Detection of the Orientation and Position of Moving Objects With Simple RFID Array for Industrial IoT ApplicationsabstractRadio-Frequency Identification (RFID) positioning promises a prospective future for industrial automation and Industrial Internet of Things (IIoT) applications. However, the radio waves carry multiple parameters including position, orientation, and ambient environment factors, which raises challenges in simultaneous detection of position and orientation of product objects. This investigation proposes a simple RFID array-based position and orientation simultaneous detection technique for moving object in industrial chain. The main contributions of this investigation include: (1) Theoretical analysis and integrated model of position and orientation variation with the antenna parameters and interrogation variables in RF backscatter coupling-based sensing. (2) Development of an innovative simple RFID array-based phase separation technique with differential sensing, which determines the position-and orientation-induced phase without their mutual coupling impact. (3) Proposal of a simultaneous detection technique for moving objects’ position and orientation by integrating the Multiple Signal Classification (MUSIC) algorithm and hyperbolic positioning algorithm. In the experimental verification with a range from -75 cm to 75cm, the average error of position and orientation estimation is 4.29 cm and 4.89 degrees. Haichao Liu 0002, Zhaozong Meng, Jingren Xu, Zhen Li 0066, Nan Gao 0002, Zonghua Zhang |
IEEE Internet Things J. | 7 |
| 2023 | ARTMAN '23: First Workshop on Recent Advances in Resilient and Trustworthy ML Systems in Autonomous NetworksabstractThe increasing integration of machine learning (ML) approaches into the operation and management (O&M) of modern networks has led researchers to address various problems such as performance optimization, anomaly detection, traffic prediction, root-cause analysis and incident troubleshooting. Autonomous networks leverage the wealth of both business and operations data to achieve fully intelligent and automated O&M for various telecommunications applications. However, their high level of service requires the closest scrutiny as such applications depend on their resilience and trustworthiness, especially in the face of motivated attackers that aim at abusing their underlying ML models. This workshop fosters the close collaboration between researchers and practitioners at the intersection of security, networks and ML communities to improve the security of ML applications in autonomous networks together. Gregory Blanc, Takeshi Takahashi 0001, Zonghua Zhang |
CCS | 3 |
| 2023 | Adaptive Threshold-Based ZUPT for Single IMU-Enabled Wearable Pedestrian LocalizationabstractWithout dependence on external anchors, the micro-electro-mechanical system inertial measurement unit (MIMU) allowing autonomous localization has promised great potential in wearable IoT applications, including kinematic analysis in sports, medical treatment, elderly care, and disaster rescue. However, the miniaturization of devices for unobtrusive sensing, algorithms minimizing the inherent accumulative errors of inertial devices, and the adaptivity of algorithms for various motion modalities are the key challenges. The removal of accumulative error in the continuous gait cycles with adaptive algorithms is a critical issue regarding localization accuracy, especially for low-cost devices. This investigation proposes an adaptive threshold-based zero-velocity update (ZUPT) algorithm to separate the timing of gait cycle phases and compensate for the residual velocity with a linear fitting approximation. The key contributions include: 1) a lightweight threshold-based zero-velocity detection algorithm to split the gait cycle phases of continuous walking; 2) a quaternion-based extended Kalman filter (EKF) algorithm to reduce the errors of the nonlinear operations for attitude prediction; 3) a linear fitting method for compensating the residual velocity in each gait cycle of continuous walking; and 4) the design of a miniature single-MIMU-based foot-mountable wearable device and the corresponding experimental studies to verify the proposed methods. Results show that the relative error is less than 3.0% for 2-D and 3-D trajectories, and the tests with different locomotion patterns demonstrate the adaptivity of the proposed algorithm compared to its peers. The results show that the presented techniques are capable of handling accumulative errors for low-cost MIMU-based systems with good adaptivity. Haichao Liu 0002, Zhen Li 0066, Zhaozong Meng, Nan Gao 0002, Zonghua Zhang |
IEEE Internet Things J. | 7 |
| 2022 | PDR-Net: Progressive depth reconstruction network for color guided depth map super-resolution
Peng Liu 0072, Zonghua Zhang, Zhaozong Meng, Nan Gao 0002 |
Neurocomputing | 2 |
| 2022 | Deformable Enhancement and Adaptive Fusion for Depth Map Super-ResolutionabstractDepth map super-resolution (DMSR) is an effective solution to improve the quality of depth maps captured by low-cost depth sensors. Most existing methods introduce guidance from the RGB images of the same scene and achieve significant improvements. However, how to utilize the RGB information is still an open challenge because of the structure inconsistencies between RGB images and depth maps. In this letter, we present a novel convolutional neural network with deformable enhancement and adaptive fusion, termed DEAF-Net, to further improve the performance of DMSR. Specifically, we design a deformable convolution enhancement module, in which sufficient color features are used for enhancing depth features. An adaptively feature fusion module is exploited to improve the efficiency of fully connected feature fusion. Experimental results on two benchmark datasets demonstrate the effectiveness of the proposed method. Peng Liu 0072, Zonghua Zhang, Zhaozong Meng, Nan Gao 0002 |
IEEE Signal Process. Lett. | 2 |
| 2021 | Leveraging Network Functions Virtualization Orchestrators to Achieve Software-Defined Access Control in the CloudsabstractNetwork Functions Virtualization (NFV) has been widely recognized as an effective way to implement and consolidate hardware-based network functions by using software-based approaches, with a potential to significantly reducing CAPEX and OPEX. In particular, NFV orchestrators (e.g., Tacker, Cloudify, and ONAP) play a vital role in managing and orchestrating various virtualized network resources (e.g., VMs, Virtualized Network Functions), and TOSCA is one of the standard data models to fulfil such a role. However, it remains unclear how the security mechanisms can be seamlessly integrated into the entire lifecycle of those virtualized network assets. Starting with a comparative analysis on the available NFV orchestrators, we extend the TOSCA model to incorporate security attributes of interest, and leverage the extended model to create access control policies at cloud scale. Specifically, a security orchestrator is developed, which contains a TOSCA-parser and a novel tenant-specific access control paradigm. One of the salient features of our security orchestrator is that it allows to dynamically generate access control models and policies for different tenant domains, resulting in a flexible and scalable protection coverage that is across different NFV layers and multiple data centers. To validate its feasibility and effectiveness, we develop a security orchestrator prototype and test its performance with respect to throughput, scalability, and adaptability. The experimental results demonstrate that all the desirable properties can be achieved, and the throughput of our security orchestrator can be maintained at a satisfactory level regardless of the varying number of tenants, users, or objects that are deployed in the cloud. Montida Pattaranantakul, Ruan He, Zonghua Zhang, Ahmed Meddahi, Ping Wang 0003 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | On Achieving Trustworthy Service Function ChainingabstractService Function Chaining (SFC) has recently received considerable attentions from both industry and academia, due to its potential for improving the flexibility of provisioning and composition of Virtualized Network Functions (VNFs) to suit application-specific needs. From a security perspective, there is a gap between high-level SFC policy specification and its enforcement in the data plane. It cannot guarantee that the deployed VNFs are always chained in an expected manner, or the packet flows of a particular service chain are sequentially forwarded to the intended and legitimate VNFs strictly compliant with the specified SFC policy. This lack of assurance leaves the door open for attackers to maliciously manipulate the service chain by evading from security functions such as firewall, Deep Packet Inspection (DPI), etc., or deviating the packet flows from their original service function path, ultimately leading to the violation of SFC policy. It is therefore important to have an efficient self-checking mechanism in place, ensuring the SFC to be implemented in a secure and dependable way. This paper presents a new security primitive - Lite Identity-based Ordered Multisignature scheme (ChainSign in short), which enforces all intended VNFs in a particular service chain to sequentially sign the packet received. Then the last hop of the chain will verify the signature, so as to validate whether all of them work as expected and have not been compromised, while satisfying the security properties of concern (i.e., the consistency in VNF chaining, their authenticities and sequences in a service chain). In addition to the implementation, we leverage the IETF Network Service Header (NSH) to carry the signature generated from our proposed scheme. The experiments show that ChainSign can preserve all identified security properties with minimal overhead. Montida Pattaranantakul, Qipeng Song, Yanmei Tian, Zonghua Zhang, Ahmed Meddahi, Chalee Vorakulpipat |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2020 | Lightweight Authentication Scheme for Internet of ThingsabstractThe Internet of Things world is in urgent need of practical solutions for its security. In this paper, we propose a new approach to extend existing authentication protocols, using Physical Layer Radio Frequency Fingerprinting to provide efficient hybrid authentication mechanisms. Our approach uses a hybrid protocol, that can save energy and computation time on the IoT devices side, proportionally to the accuracy of the Radio Frequency Fingerprinting used, having a measurable gain while keeping an acceptable security level. Arie Haenel, Yoram Haddad 0001, Zonghua Zhang |
CCNC | 3 |
| 2020 | Generative Deep Learning for Internet of Things Network Traffic GenerationabstractThe rapid development of the Internet of Things (IoT) has prompted a recent interest into realistic IoT network traffic generation. Security practitioners need IoT network traffic data to develop and assess network-based intrusion detection systems (NIDS). Emulating realistic network traffic will avoid the costly physical deployment of thousands of smart devices. From an attacker's perspective, generating network traffic that mimics the legitimate behavior of a device can be useful to evade NIDS. As network traffic data consist of sequences of packets, the problem is similar to the generation of sequences of categorical data, like word by word text generation. Many solutions in the field of natural language processing have been proposed to adapt a Generative Adversarial Network (GAN) to generate sequences of categorical data. In this paper, we propose to combine an autoencoder with a GAN to generate sequences of packet sizes that correspond to bidirectional flows. First, the autoencoder is trained to learn a latent representation of the real sequences of packet sizes. A GAN is then trained on the latent space, to learn to generate latent vectors that can be decoded into realistic sequences. For experimental purposes, bidirectional flows produced by a Google Home Mini are used, and the autoencoder is combined with a Wassertein GAN. Comparison of different network characteristics shows that our proposed approach is able to generate sequences of packet sizes that behave closely to real bidirectional flows. We also show that the synthetic bidirectional flows are close enough to the real ones that they can fool anomaly detectors into labeling them as legitimate. Mustafizur R. Shahid, Gregory Blanc, Houda Jmila, Zonghua Zhang, Hervé Debar |
PRDC | 4 |
| 2020 | AutoMAP: Diagnose Your Microservice-based Web Applications AutomaticallyabstractThe high complexity and dynamics of the microservice architecture make its application diagnosis extremely challenging. Static troubleshooting approaches may fail to obtain reliable model applies for frequently changing situations. Even if we know the calling dependency of services, we lack a more dynamic diagnosis mechanism due to the existence of indirect fault propagation. Besides, algorithm based on single metric usually fail to identify the root cause of anomaly, as single type of metric is not enough to characterize the anomalies occur in diverse services. In view of this, we design a novel tool, named AutoMAP, which enables dynamic generation of service correlations and automated diagnosis leveraging multiple types of metrics. In AutoMAP, we propose the concept of anomaly behavior graph to describe the correlations between services associated with different types of metrics. Two binary operations, as well as a similarity function on behavior graph are defined to help AutoMAP choose appropriate diagnosis metric in any particular scenario. Following the behavior graph, we design a heuristic investigation algorithm by using forward, self, and backward random walk, with an objective to identify the root cause services. To demonstrate the strengths of AutoMAP, we develop a prototype and evaluate it in both simulated environment and real-work enterprise cloud system. Experimental results clearly indicate that AutoMAP achieves over 90% precision, which significantly outperforms other selected baseline methods. AutoMAP can be quickly deployed in a variety of microservice-based systems without any system knowledge. It also supports introduction of various expert knowledge to improve accuracy. Meng Ma 0001, Jingmin Xu, Pengfei Chen 0002, Zonghua Zhang, Ping Wang 0003 |
WWW | 5 |
| 2020 | 3D palmprint identification using blocked histogram and improved sparse representation-based classifier
Zhaozong Meng, Nan Gao 0002, Zonghua Zhang, David Zhang 0001 |
Neural Comput. Appl. | 4 |
| 2020 | Design and feasibility study of roots-type power machine rotor based on numerical simulation
Xuan Kong, Zonghua Zhang, Yanchun Xiao |
Neural Comput. Appl. | 4 |
| 2019 | Anomalous Communications Detection in IoT Networks Using Sparse AutoencodersabstractNowadays, IoT devices have been widely deployed for enabling various smart services, such as, smart home or e-healthcare. However, security remains as one of the paramount concern as many IoT devices are vulnerable. Moreover, IoT malware are constantly evolving and getting more sophisticated. IoT devices are intended to perform very specific tasks, so their networking behavior is expected to be reasonably stable and predictable. Any significant behavioral deviation from the normal patterns would indicate anomalous events. In this paper, we present a method to detect anomalous network communications in IoT networks using a set of sparse autoencoders. The proposed approach allows us to differentiate malicious communications from legitimate ones. So that, if a device is compromised only malicious communications can be dropped while the service provided by the device is not totally interrupted. To characterize network behavior, bidirectional TCP flows are extracted and described using statistics on the size of the first N packets sent and received, along with statistics on the corresponding inter-arrival times between packets. A set of sparse autoencoders is then trained to learn the profile of the legitimate communications generated by an experimental smart home network. Depending on the value of N, the developed model achieves attack detection rates ranging from 86.9% to 91.2%, and false positive rates ranging from 0.1% to 0.5%. Mustafizur R. Shahid, Gregory Blanc, Zonghua Zhang, Hervé Debar |
NCA | 3 |
| 2019 | Footprints: Ensuring Trusted Service Function Chaining in the World of SDN and NFV
Montida Pattaranantakul, Qipeng Song, Yanmei Tian, Zonghua Zhang, Ahmed Meddahi |
SecureComm (2) | 5 |
| 2019 | SCTSC: A Semicentralized Traffic Signal Control Mode With Attribute-Based Blockchain in IoVsabstractAssisting traffic control is one of the most important applications on the Internet of Vehicles (IoVs). Traffic information provided by vehicles is desired since drivers or vehicle sensors are sensitive in perceiving or detecting nuances on roads. However, the availability and privacy preservation of this information are critical while conflicted with each other in the vehicular communication. In this paper, we propose a semicentralized mode with attribute-based blockchain in IoVs to balance the tradeoff between the availability and the privacy preservation. In this mode, a method of control-by-vehicles is used to control signals of traffic lights to increase traffic efficiency. Users are grouped their attributes such as locations and directions before starting the communication. The users reach an agreement on determining a temporary signal timing by interacting with each other without leaking privacy. Final decisions are verifiable to all users, even if they have no a priori agreement and processes of consensus. The mode not only achieves the aim of privacy preservation but also supports responsibility investigation for historical agreements via ciphertext-policy attribute-based encryption (CP-ABE) and blockchain technology. Extensive experimental results demonstrated that our mode is efficient and practical. Lichen Cheng, Jiqiang Liu, Guangquan Xu, Zonghua Zhang, Hao Wang 0003, Hongning Dai, Yulei Wu, Wei Wang 0012 |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2018 | IoT Devices Recognition Through Network Traffic AnalysisabstractThe growing Internet of Things (IoT) market introduces new challenges for network activity monitoring. Legacy network monitoring is not tailored to cope with the huge diversity of smart devices. New network discovery techniques are necessary in order to find out what IoT devices are connected to the network. In this context, data analysis techniques can be leveraged to find out specific patterns that can help to recognize device types. Indeed, contrary to desktop computers, IoT devices perform very specific tasks making their networking behavior very predictable. In this paper, we present a machine learning based approach in order to recognize the type of IoT devices connected to the network by analyzing streams of packets sent and received. We built an experimental smart home network to generate network traffic data. From the generated data, we have designed a model to describe IoT device network behaviors. By leveraging the t-SNE technique to visualize our data, we are able to differentiate the network traffic generated by different IoT devices. The data describing the network behaviors are then used to train six different machine learning classifiers to predict the IoT device that generated the network traffic. The results are promising with an overall accuracy as high as 99.9% on our test set achieved by Random Forest classifier. Mustafizur R. Shahid, Gregory Blanc, Zonghua Zhang, Hervé Debar |
IEEE BigData | 3 |
| 2018 | Roundtable Gossip Algorithm: A Novel Sparse Trust Mining Method for Large-Scale Recommendation Systems
Guangquan Xu, Jun Zhang 0010, Rajan Shankaran, James Xi Zheng, Zonghua Zhang |
ICA3PP (4) | 7 |
| 2018 | CreditCoin: A Privacy-Preserving Blockchain-Based Incentive Announcement Network for Communications of Smart VehiclesabstractThe vehicular announcement network is one of the most promising utilities in the communications of smart vehicles and in the smart transportation systems. In general, there are two major issues in building an effective vehicular announcement network. First, it is difficult to forward reliable announcements without revealing users' identities. Second, users usually lack the motivation to forward announcements. In this paper, we endeavor to resolve these two issues through proposing an effective announcement network called CreditCoin, a novel privacy-preserving incentive announcement network based on Blockchain via an efficient anonymous vehicular announcement aggregation protocol. On the one hand, CreditCoin allows nondeterministic different signers (i.e., users) to generate the signatures and to send announcements anonymously in the nonfully trusted environment. On the other hand, with Blockchain, CreditCoin motivates users with incentives to share traffic information. In addition, transactions and account information in CreditCoin are tamper-resistant. CreditCoin also achieves conditional privacy since Trace manager in CreditCoin traces malicious users' identities in anonymous announcements with related transactions. CreditCoin thus is able to motivate users to forward announcements anonymously and reliably. Extensive experimental results show that CreditCoin is efficient and practical in simulations of smart transportation. Jiqiang Liu, Lichen Cheng, Shuo Qiu, Wei Wang 0012, Xiangliang Zhang 0001, Zonghua Zhang |
IEEE Trans. Intell. Transp. Syst. | 7 |
| 2018 | An automatically vetting mechanism for SSL error-handling vulnerability in android hybrid Web apps
Yang Liu 0165, Chaoshun Zuo, Zonghua Zhang, Shanqing Guo, Xin-Shun Xu |
World Wide Web | 3 |
| 2018 | Editorial: Special Issue on Security and Privacy of IoT
Hua Wang 0002, Zonghua Zhang, Tarek Taleb |
World Wide Web | 2 |
| 2017 | Controller DAC: Securing SDN controller with dynamic access controlabstractSoftware-Defined Networking (SDN), as a new network paradigm, has the advantages of centralizing control and global visibility over the whole network. However, security issues remain to be a significant concern and impede SDN from being widely adopted. The most straightforward approach to mitigate the threat from malicious OpenFlow applications (OF app) is using permission set for controlling access from OF app to SDN controller. Unfortunately, most of them, if not all, adopt simply static permission control. In this paper, we will address the app-to-control threats along with the four permission categories: READ, ADD, UPDATE and REMOVE on four open source SDN controllers, including OpenDaylight, ONOS, Floodlight, and Ryu. We found that malicious OF app still can infect SDN controllers which are even hardened by the static permission control. Therefore, we present Controller DAC (SDN Controller Dynamic Access Control System), which is a controller-independent dynamic access control system for protecting SDN controllers against API abuse. In our implementation, Controller DAC requires low deployment complexity for securing SDN controllers, and most of time its operation is independent from underlying SDN controller. The preliminary experimental results show that Controller DAC can prevent SDN controllers from API abuse with less than 0.5% performance overhead. Yuchia Tseng, Montida Pattaranantakul, Ruan He, Zonghua Zhang, Farid Naït-Abdesselam |
ICC | 4 |
| 2017 | SDAC: A New Software-Defined Access Control Paradigm for Cloud-Based Systems
Ruan He, Montida Pattaranantakul, Zonghua Zhang, Thomas Duval |
ICICS | 3 |
| 2017 | A novel topolgoy of multi-level converters using split wound coupled inductorsabstractThe modular multilevel converters (MMC) has been investigated for a long time and has attracted increasingly more attentions due to its special topology. In order to generate more voltage levels with less power semiconductors for the MMC, this paper presented a novel topology of modular multilevel converters. There are two innovations for the proposed topology. 1. The current limiting inductance in each bridge arm is replaced by a split wound coupled inductor; 2. The sub-modules of the MMC is redesigned to further improve the performance of the system. Compare to the traditional sub-modules, the number of power semiconductors used in the newly designed sub-modules is reduced by half. The theoretical analysis shows that the number of output voltage levels of the proposed topology is increased from five levels to thirteen levels, thus the slew rate of the voltage (dv/dt) is suppressed and the total harmonic distortion (THD) is reduced. The simulation is also conducted in the paper which verified the correctness of the theoretical analysis. Xiangfeng Li, Hui Liao, Zonghua Zhang |
IECON | 5 |
| 2017 | An improved multi-level converter with a novel sub-module circuitabstractThe modular multilevel converters (MMC) has become an attractive research subject of power electronics due to its special topology. In this paper, a novel sub-module circuit for the MMC is proposed. Compared with the traditional sub-module circuits, the number of power semiconductors used in the proposed circuit is reduced by a quarter. Then, an improved three-phase multilevel topology is also constructed with the proposed sub-module circuit, accordingly, appropriate control logic is designed. The theoretical analysis shows that the line voltage of the proposed multilevel topology is increased from five levels to nine levels, thus suppressed the slew rate of the voltage (dv/dt). The simulation is also conducted in the paper which verified the correctness of the theoretical analysis. Xiangfeng Li, Hui Liao, Zonghua Zhang |
IECON | 5 |
| 2017 | A novel MMC sub-module based on controllability theoryabstractA novel sub-module circuit is proposed in this paper based on the controllability theory. At first, traditional full bridge sub-modules (FBSM) of the MMC is modeled as a switched linear system, then controllability of the switched linear system model of the sub-module circuit is studied. It is found that the sub-module circuit is state controllable with only four operation modes adopted in the model. Therefore, a novel MMC sub-module circuit is designed to implement the required functionality of the MMC by removing the redundant power semiconductors. At last, the theoretic analysis and simulation results verified that the new MMC with the novel sub-modules is a 3n+1 level converter while the MMC with the traditional FBSM is only a n level converter. Hence the total harmonic distortion (THD) of the proposed MMC topology is much lower than the traditional one. Moreover, since the negative voltage states of the FBSMs are adopted to extend the output voltage range, the maximum output voltage of the MMC topology presented in this paper are increased by two hundred percent such that the dc voltage utilization ratio is improved. More importantly, the approach proposed in this paper can be easily used to redesign and simplify other power converter circuits. Xiangfeng Li, Zonghua Zhang, Hui Liao |
IECON | 3 |
| 2017 | ArOMA: An SDN based autonomic DDoS mitigation framework
Rishikesh Sahay, Gregory Blanc, Zonghua Zhang, Hervé Debar |
Comput. Secur. | 3 |
| 2017 | PTRS: A privacy-preserving trust-based relay selection scheme in VANETs
Hao Hu 0017, Rongxing Lu, Cheng Huang 0001, Zonghua Zhang |
Peer-to-Peer Netw. Appl. | 4 |
| 2017 | TPSQ: Trust-based platoon service query via vehicular communications
Hao Hu 0017, Rongxing Lu, Zonghua Zhang |
Peer-to-Peer Netw. Appl. | 3 |
| 2017 | 3D palmprint identification combining blocked ST and PCA
Nan Gao 0002, Zonghua Zhang, David Zhang 0001 |
Pattern Recognit. Lett. | 3 |
| 2016 | Novel Constructions of Cramer-Shoup Like Cryptosystems Based on Index Exchangeable FamilyabstractThe Cramer-Shoup cryptosystem has attracted much attention from the research community, mainly due to its efficiency in encryption/decryption, as well as the provable reductions of security against adaptively chosen ciphertext attacks in the standard model. At TCC 2005, Vasco et al. proposed a method for building Cramer-Shoup like cryptosystem over non-abelian groups and raised an open problem for finding a secure instantiation. Based on this work, we present another general framework for constructing Cramer-Shoup like cryptosystems. We firstly propose the concept of index exchangeable family (IEF) and an abstract construction of Cramer-Shoup like encryption scheme over IEF. The concrete instantiations of IEF are then derived from some reasonable hardness assumptions over abelian groups as well as non-abelian groups, respectively. These instantiations ultimately lead to simple yet efficient constructions of Cramer-Shoup like cryptosystems, including new non-abelian analogies that can be potential solutions to Vasco et al.'s open problem. Moreover, we propose a secure outsourcing method for the encryption of the non-abelian analog based on the factorization problem over non-commutative groups. The experiments clearly indicate that the computational cost of our outsourcing scheme can be significantly reduced thanks to the load sharing with cloud datacenter servers. Jing Li 0045, Licheng Wang 0004, Zonghua Zhang, Xinxin Niu |
AsiaCCS | 3 |
| 2016 | ControllerSEPA: A Security-Enhancing SDN Controller Plug-in for OpenFlow ApplicationsabstractSoftware-defined networking (SDN), as a new network paradigm, has the advantage of centralizing control and global visibility over a network. However, security issues remain a major concern and prevent SDN from being widely adopted. One of the challenges is the prevention of malicious OpenFlow application (OF app) access to the SDN controller as it opens a programmable northbound interface for third party applications. In this paper, we address app-to-control security issues with focus on five main attack vectors: unauthorized access, illegal function calling, malicious rules injection, resources exhausting and manin-the-middle attack. Based on the identified threat models, we develop a light-weight plug-in, which is called ControllerSEPA, by using RESTful API to defend SDN controller against malicious OF apps. Specifically, ControllerSEPA can provide the services including OF app-based AAA control (unlike OpenDaylight and ONOS which offer user-based or role-based AAA control), rule conflict resolution, OF app isolation, fine-grained access control and encryption. Furthermore, we study the feasibility of deploying ControllerSEPA on five open source SDN controllers: OpenDaylight, ONOS, Floodlight, Ryu and POX. Results show that the deployment operates with very low complexity, and most of time the modification of source codes is unnecessary. In our implementations, the repacked services in ControllerSEPA create negligible latency (0.1% to 0.3%) and can provide more rich services to OF apps. Yuchia Tseng, Zonghua Zhang, Farid Naït-Abdesselam |
PDCAT | 2 |
| 2016 | Achieving Probabilistic Anonymity in a Linear and Hybrid Randomization ModelabstractThe randomization methods that are applied for privacy-preserving data mining are commonly subject to reconstruction, linkage, and semantic-related attacks. Some existing works employed random noise addition to realize probabilistic anonymity, aiming only at linkage attacks. Random noise addition is vulnerable to reconstruction attacks, and is unable to achieve semantic closeness, particularly on high-dimensional data, to prevent semantic-related attacks. For linkage attacks, the main security vulnerability of their proposed probabilistic anonymity lies in the assumption that the attacker had a priori knowledge of the quasi-identifiers of all individuals. When only some individuals leak their quasi-identifiers, the proposed model will become incapable, because the attacker can deploy a different linkage attack that has not been studied before. This type of attack is much easier to deploy and is thus very harmful. In this paper, we propose new frameworks of probabilistic (1, k)and (k, k)-anonymity to defend against all these linkage attacks, and realize the frameworks on a hybrid randomization model. The model is also secure against reconstruction attacks. We further achieve statistical semantic closeness of high-dimensional data to prevent semantic-related attacks on the model. The frameworks also allow us to re-design the traditional K-nearest neighbor algorithm to leverage the introduced data uncertainty and improve the mining results. This paper demonstrates the promising applications in large-scale and high-dimensional data mining in clouds, by providing high efficiency and security to protect data privacy, guaranteeing high data utility for mining purposes, on-time processing, and non-interactive data publishing. Yingpeng Sang, Hong Shen 0001, Hui Tian 0001, Zonghua Zhang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Next Road Rerouting: A Multiagent System for Mitigating Unexpected Urban Traffic CongestionabstractDuring peak hours in urban areas, unpredictable traffic congestion caused by en route events (e.g., vehicle crashes) increases drivers' travel time and, more seriously, decreases their travel time reliability. In this paper, an original and highly practical vehicle rerouting system, which is called Next Road Rerouting (NRR), is proposed to aid drivers in making the most appropriate next road choice to avoid unexpected congestions. In particular, this heuristic rerouting decision is made upon a cost function that takes into account the driver's destination and local traffic conditions. In addition, the newly designed multiagent system architecture of NRR allows the positive rerouting impacts on local traffic to be disseminated to a larger area through the natural traffic flow propagation within connected local areas. The simulation results based on both synthetic and realistic urban scenarios demonstrate that, compared with the existing solutions, NRR can achieve a lower average travel time while guaranteeing a higher travel time reliability in the face of unexpected congestion. The impacts of NRR on the travel time of both rerouted and nonrerouted vehicles are also assessed, and the corresponding results reveal its higher practicability. Shen Wang 0006, Soufiene Djahel, Zonghua Zhang, Jennifer McManis |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2015 | Secure PUFs-Based Cipher Suite for Enabling TLS to Authenticate Hardware DevicesabstractDespite the promising properties of Physical Unclonable Functions (PUFs), its integration with Transport Layer Security (TLS), has not been explored yet. We then present a PUF based machine to machine (M2M) authentication extension for TLS. An Authenticated Key Exchange (AKE) protocol termed DHZKP based on PUF is designed. We develop this protocol as a TLS extension, and prove its security. Paul-Edmond Berthier, Stéphane Cauchie, Zonghua Zhang |
AsiaCCS | 3 |
| 2015 | VTrust: A Robust Trust Framework for Relay Selection in Hybrid Vehicular CommunicationsabstractAs one of the essential components of Intelligent Transport Systems (ITS), Vehicular Ad Hoc Network (VANET) plays a significant role in enabling various on-road applications, most of which primarily rely on two-top Vehicle-To-Vehicle communications. To make such communications reliable and secure, it is significant to ensure that the trustworthy vehicles are selected as relays. To tackle this challenge, this paper proposes a robust trust framework, called VTrust, which systematically integrates a set of unique features of VANET, e.g., hybrid architecture, high dynamics, social attributes, into the traditional reputation system, with an objective to effectively differentiate the trust levels of the vehicles meanwhile preserve high scalability and robustness. The digital signature and multisignature techniques are also applied to enhance the security of VTrust. To validate the performance of the framework, an in-depth security analysis is conducted, which shows that it is secure and robust against several sophisticated attacks in VANETs. Also, a set of extensive simulations is carried out, demonstrating its effectiveness, accuracy, and scalability. Hao Hu 0017, Rongxing Lu, Zonghua Zhang |
GLOBECOM | 3 |
| 2015 | Enabling security functions with SDN: A feasibility study
Changhoon Yoon, Taejune Park, Seungsoo Lee 0001, Heedo Kang, Seungwon Shin 0001, Zonghua Zhang |
Comput. Networks | 6 |
| 2015 | A comprehensive study of flooding attack consequences and countermeasures in Session Initiation Protocol (SIP)abstractAbstract Session Initiation Protocol (SIP) is widely used as a signaling protocol to support voice and video communication in addition to other multimedia applications. However, it is vulnerable to several types of attacks because of its open nature and lack of a clear defense line against the increasing spectrum of security threats. Among these threats, flooding attack, known by its destructive impact, targets both of SIP User Agent Server (UAS) and User Agent Client (UAC), leading to a denial of service in Voice over IP applications. In particular, INVITE message is considered as one of the major root causes of flooding attacks in SIP. This is due to the fact that an attacker may send numerous INVITE requests without waiting for responses from the UAS or the proxy in order to exhaust their respective resources. Most of the devised solutions to cope with the flooding attack are either difficult to deploy in practice or require significant changes in the SIP servers implementation. Apart from these challenges, flooding attacks are much more diverse in nature, which makes the task of defeating them a real challenge. In this survey, we present a comprehensive study of flooding attack against SIP, by addressing its different variants and analyzing its consequences. We also classify the existing solutions according to the different flooding behaviors they are dealing with, their types, and targets. Moreover, we conduct a thorough investigation of the main strengths and weaknesses of these solutions and deeply analyze the underlying assumptions of each of them for better understanding of their limitations. Finally, we provide some recommendations for enhancing the effectiveness of the surveyed solutions and address some open challenges. Copyright © 2015 John Wiley & Sons, Ltd. Intesab Hussain, Soufiene Djahel, Zonghua Zhang, Farid Naït-Abdesselam |
Secur. Commun. Networks | 3 |
| 2015 | Towards cross-layer approaches to coping with misbehavior in mobile ad hoc networks: an anatomy of reputation systemsabstractAbstract In mobile ad hoc networks (MANETs), the nodes need to cooperate each other to establish multi‐hop routes for out‐of‐range wireless communication. However, some of them may not always behave normally, either behaving selfishly for saving computational resource or maliciously for compromising communication protocols. Regardless of intents, such misbehavior would lead to the degradation of network performance. It is therefore important to design appropriate mechanisms to ensure that network performance could be maintained at an acceptable level in the presence of misbehaving nodes. But the open nature of MANETs makes such designs challenging. Reputation system has been widely recognized as an effective approach, which associates the behavior of nodes with its reputation, which is calculated by specifying and quantifying the observations of interest with respect to predefined performance metrics. More interestingly, the observations can be obtained and integrated from multiple layers, facilitating cross‐layer analysis. This paper intends to take a deep look into several well‐studied reputation systems and examine their operational characteristics in terms of modeling approaches and redemption techniques, with an objective to identify their capabilities in terms of misbehavior detection coverage and blind spots. Furthermore, such an anatomy allows us to better understand the failure curses of the deployment and operation of reputation systems in MANETs, so as to improve their performance by adopting effective countermeasures.Copyright © 2014 John Wiley & Sons, Ltd. Shuzhen Wang, Zonghua Zhang, Farid Naït-Abdesselam |
Secur. Commun. Networks | 2 |
| 2014 | Certificateless Remote Anonymous Authentication Schemes for WirelessBody Area NetworksabstractWireless body area network (WBAN) has been recognized as one of the promising wireless sensor technologies for improving healthcare service, thanks to its capability of seamlessly and continuously exchanging medical information in real time. However, the lack of a clear in-depth defense line in such a new networking paradigm would make its potential users worry about the leakage of their private information, especially to those unauthenticated or even malicious adversaries. In this paper, we present a pair of efficient and light-weight authentication protocols to enable remote WBAN users to anonymously enjoy healthcare service. In particular, our authentication protocols are rooted with a novel certificateless signature (CLS) scheme, which is computational, efficient, and provably secure against existential forgery on adaptively chosen message attack in the random oracle model. Also, our designs ensure that application or service providers have no privilege to disclose the real identities of users. Even the network manager, which serves as private key generator in the authentication protocols, is prevented from impersonating legitimate users. The performance of our designs is evaluated through both theoretic analysis and experimental simulations, and the comparative studies demonstrate that they outperform the existing schemes in terms of better trade-off between desirable security properties and computational overhead, nicely meeting the needs of WBANs. Zonghua Zhang, Xiaofeng Chen 0001, Kyung Sup Kwak |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Exploring attack graph for cost-benefit security hardening: A probabilistic approach
Shuzhen Wang, Zonghua Zhang, Youki Kadobayashi |
Comput. Secur. | 2 |
| 2012 | Boosting Logical Attack Graph for Efficient Security ControlabstractThis paper reports an approach, which is termed AG-HMM, to achieve cost-effective security control by exploring logical attack graph to represent network observations, and Hidden Markov Model (HMM) to estimate attack states. One advantage of our approach is to construct a probabilistic mapping between network observations and attack states, potentially revealing the most significant vulnerabilities and allowing security administrators (SA) to efficiently deal with them through cost-benefit analysis. A preliminary experiment is conducted to evaluate our approach in a typical enterprise network. Zonghua Zhang, Shuzhen Wang |
ARES | 1 |
| 2012 | An efficient certificateless remote anonymous authentication scheme for wireless body area networksabstractWireless body area network (WBAN) is one of the most promising wireless sensor technologies, significantly enhancing the quality of service of healthcare. But the potential users' worries about privacy leakage impede its wider application. To alleviate such worries, we present a remote anonymous authentication protocol to enable client terminals/application to securely access WBAN services. In particular, our protocol is rooted in a novel certificateless cryptosystem, which has negligible computational cost and a number of security properties that are especially desirable in WBANs. Our protocol ensures that even the application providers (APs) cannot recover the user's real identity given all the session information. Also, the network manager (NM), who plays the role of private key generator (PKG), can be prevented from impersonating any legitimate users. We theoretically validate that our protocol can achieve a better tradeoff than most of existing schemes in terms of essential security properties and computational overhead. Zonghua Zhang, Kyung Sup Kwak |
ICC | 2 |
| 2012 | HPM: A novel hierarchical Peer-to-Peer model for lookup acceleration with provision of physical proximity
Mourad Amad, Ahmed Meddahi, Djamil Aïssani, Zonghua Zhang |
J. Netw. Comput. Appl. | 4 |
| 2011 | HASVC: An Efficient Hybrid Authentication Scheme for Vehicular CommunicationabstractThe emerging vehicular communications will enable a variety of applications for safety, traffic efficiency, driver assistance and infotainment. Due to high vehicular speed, sporadic connection, limited communication range, and large volume of data that need to be transmitted, vehicular communications have the crucial requirements of fast authentication and encryption/decryption. This paper addresses the new and special challenges related to vehicular communications, such as large overhead and latency, presents our Hybrid scheme HASVC to address the authentication issue, and evaluates its performance so as to meet the stringent requirement of real time vehicular communications. The experimental results show that our authentication protocol can securely protect the exchanged information with less overhead and less authentication latency. Huaqun Guo, Zonghua Zhang, Lawrence Wai-Choong Wong, Maode Ma, Yongdong Wu |
ICC | 3 |
| 2011 | Practical network traffic analysis in P2P environmentabstractRecent statistical studies on telecommunication networks outline that peer-to-peer (P2P) file-sharing is keeping increasing and it now contributes about 50-80% of the overall Internet traffic. Moreover, more and more network applications such as streaming media, internet telephony, and instant messaging are taking a form of P2P telecommunication. The bandwidth intensive nature of P2P applications suggests that P2P traffic can have significant impact on the underlying network. Therefore, analyzing and characterizing this kind of traffic is an essential step to develop workload models towards efficient amelioration in network traffic engineering and capacity planning. In this paper, we first introduce an adaptive system for handy P2P trace capturing and analysis. By using virtualization technology, the system can efficiently organize limited resources to build a reliable and tractable network that supports adjustable experimental study and practical performance tuning. Then the proposed system is applied to traffic characterization of File Sharing P2P (FSP2P) applications. To avoid excessive computing cost of payload information inspection, we proposed a more light-weighted analytical scheme which makes use of meta features extracted from packet headers. With carefully selected system parameters, we show that satisfactory prediction accuracy on differentiating FSP2P applications from ordinary network applications could be achieved with acceptable computing costs. The proposed scheme supports performance tuning between monitoring cost and the system response time, which enables its adaption to network environments with different specifications. Tao Ban, Shanqing Guo, Zonghua Zhang, Ruo Ando, Youki Kadobayashi |
IWCMC | 3 |
| 2011 | Toward cost-sensitive self-optimizing anomaly detection and response in autonomic networks
Zonghua Zhang, Farid Naït-Abdesselam, Pin-Han Ho, Youki Kadobayashi |
Comput. Secur. | 1 |
| 2011 | Discrete logarithm based additively homomorphic encryption and secure data aggregation
Licheng Wang 0004, Lihua Wang 0001, Zonghua Zhang, Yixian Yang |
Inf. Sci. | 4 |
| 2010 | RADAR: A reputation-driven anomaly detection system for wireless mesh networks
Zonghua Zhang, Pin-Han Ho, Farid Naït-Abdesselam |
Wirel. Networks | 1 |
| 2009 | A Dynamic Protection System of Web Server in Virtual Cluster Using Live MigrationabstractVirtual machine monitor provides the drastic improvement of isolation, consolidation and flexibility in running virtual machine. Also, virtual cluster becomes one of the hot topics for the combination of capacity planning, HPC (high performance computing) and virtualization technologies. In this paper we propose a dynamic protection system of Web server in virtual cluster using live migration. VMM (virtual machine monitor) makes it possible to save, suspend and move VM running mission critical service without sustaining sessions. Our system runs in virtual cluster as protection module for making Web server reliable and available against DoS attacks. Proposed system can respond the rapid increase of utilization caused by DoS attacks without stopping sessions and services using live migration. For dynamic protection, an interruptive-notification mechanism is inserted into Web daemon, kernel space and VMM layer to activate the real-time mitigation of DoS by migrating and re-distributing VM on different physical machines. Experiment shows that our system is successful for mitigating DoS attacks without suspending sessions by reducing and distributing utilizations of the resources of VM providing mission critical Web services. We can conclude that our dynamic protection system using inter-VM notification and live migration can make virtualized Web server more reliable and available for DoS attacks. Ruo Ando, Zonghua Zhang, Youki Kadobayashi, Yoichi Shinoda |
DASC | 2 |
| 2009 | On Achieving Cost-Sensitive Anomaly Detection and Response in Mobile Ad Hoc NetworksabstractIn Mobile Ad Hoc Networks (MANET), anomaly detection and response system (ADRS) plays a paramount role in diagnosing anomalous events, which are resulted by both accidental system errors and intentional attacks. While a variety of ADRS is ready for deployment, there lacks a sound and formal way to examine their operational characteristics for selecting the most appropriate ones with particular concerns. To that end, this paper develops a decision-theoretical framework to identify the fundamental tradeoffs between the key evaluation metrics of ADRS in MANET, along with a formal method to optimize the overall performance of ADRS in terms of those metrics of concern. In particular, each ADRS sensor is treated as an autonomous agent, making its decision as the local operational environment and a global signal that estimates the performance of ADRS as a whole, in terms of detection performance (detection accuracy and false positive rate) and operational cost (detection cost and response cost). The theoretical framework then serves as a basis for developing policy gradient algorithms for practically and automatically inferring the optimal behavior of ADRS sensors. A set of simulations is conducted for validating the feasibility and evaluating the performance of our proposed framework. Zonghua Zhang, Pin-Han Ho, Farid Naït-Abdesselam |
ICC | 1 |
| 2009 | Discrete-Log-Based Additively Homomorphic Encryption and Secure WSN Data Aggregation
Licheng Wang 0004, Lihua Wang 0001, Zonghua Zhang, Yixian Yang |
ICICS | 4 |
| 2009 | Measuring IDS-estimated attack impacts for rational incident response: A decision theoretic approach
Zonghua Zhang, Pin-Han Ho, Liwen He |
Comput. Secur. | 1 |
| 2009 | Janus: A dual-purpose analytical model for understanding, characterizing and countermining multi-stage collusive attacks in enterprise networks
Zonghua Zhang, Pin-Han Ho |
J. Netw. Comput. Appl. | 1 |
| 2009 | M-AID: An adaptive middleware built upon anomaly detectors for intrusion detection and rational responseabstractAnomaly-based intrusion detection is about the discrimination of malicious and legitimate behaviors on the basis of the characterization of system normality in terms of particular observable subjects. As the system normality is constructed solely from an observed sample of normally occurring patterns, anomaly detectors always suffer excessive false alerts. Adaptability is therefore a desirable feature that enables an anomaly detector to alleviate, if not eliminate, such annoyance. To achieve that, we either design self-learning anomaly detectors to capture the drifts of system normality or develop postprocessing mechanisms to deal with the outputs. As the former methodology is usually scenario- and application-specific, in this article, we focus on the latter one. In particular, our design starts from three key observations: (1) most of anomaly detectors are threshold based and parametric, that is, configurable by a set of parameters; (2) anomaly detectors differ in operational environment and operational capability in terms of detection coverage and blind spots; (3) an intrusive anomaly may leave traces across multiple system layers, incurring different observable events of interest. Firstly, we present a statistical framework to formally characterize and analyze the basic behaviors of anomaly detectors by examining the properties of their operational environments. The framework then serves as a theoretical basis for developing an adaptive middleware, which is called M-AID, to optimally integrate a number of observation-specific parameterizable anomaly detectors. Specifically, M-AID treats these fine-grained anomaly detectors as a whole and casts their collective behaviors in a framework which is formulated as a Multiagent Partially Observable Markov Decision Process (MPO-MDP). The generic anomaly detection models of M-AID are thus automatically inferred via a reinforcement learning algorithm which dynamically adjusts the behaviors of anomaly detectors in accordance with a reward signal that is defined and quantified by a suit of evaluation metrics. Fundamentally, the distributed and autonomous architecture enables M-AID to be scalable, dependable, and adaptable, and the reward signal allows security administrators to specify cost factors and take into account the operational context for taking rational response. Finally, a host-based prototype of M-AID is developed, along with comprehensive experimental evaluation and comparative studies. Zonghua Zhang, Hong Shen 0001 |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2008 | Boosting Markov Reward Models for Probabilistic Security Evaluation by Characterizing Behaviors of Attacker and DefenderabstractWhile Markov reward models (MRMs) have been widely used for system dependability evaluation, their application for evaluating security still poses as a challenge. It is observed that attacker behavior plays a key role in causing models of security evaluation to be complicated. Another observation is that representing attacker behavior in terms of attack effects instead of attack itself enables the system security to be indirectly evaluated by identifying families of attacks rather than individual instantiations. Furthermore, an attacker behavior tends to be affected by defense mechanisms (we say defender) due to their close interactions. These observations motivate us to boost MRMs to the security context by extracting the behaviors of attacker and defender. To do that, we present a general yet simple state- based approach to characterizing and inferring the behaviors of attackers and defenders in typical network attacks. It specifically contributes in two folds: 1) two objective-oriented models are developed to measure the attacker's and defender's behaviors, respectively; 2) the objectives, actions, and the resultant effects by the attacker and defender, along with the underlying system states, are then integrated and formulated as partially observable Markov decision processes. The developed models and analysis allow the behaviors of attacker and defender to be characterized in a fine-grained way, and specific attack-defense strategies to be inferred approximately via existing model-based algorithms. The system security hereby can be indirectly validated on the basis of the aggregated effects resulted from the interactive behaviors of attacker and defender. A real trace study is conducted to show feasibility and effectiveness of our proposed approach. Zonghua Zhang, Farid Naït-Abdesselam, Pin-Han Ho |
ARES | 1 |
| 2008 | Hardening Botnet by a Rational Botmaster
Zonghua Zhang, Ruo Ando, Youki Kadobayashi |
Inscrypt | 1 |
| 2008 | Balancing energy consumption for uniform data gathering wireless sensor networksabstractNo abstract available. Haibo Zhang 0001, Hong Shen 0001, Yawen Chen 0001, Zonghua Zhang |
PODC | 4 |
| 2008 | RADAR: A ReputAtion-Based Scheme for Detecting Anomalous Nodes in WiReless Mesh NetworksabstractAs one of the backup measures of intrusion prevention techniques, intrusion detection system (IDS) plays a paramount role in the second defense line of computer networks. Due to the special infrastructure and communication mode, intrusion detection in wireless mesh networks (WMNs) is especially challenging and requires particular design considerations. In this paper, we propose a novel anomaly detection scheme, called RADAR, to detect anomalous mesh nodes in WMNs. Firstly, we introduce a general concept of reputation to characterize and quantify the mesh node's behavior/status in terms of fine-grained performance metrics. This enables us to construct a robust baseline for leveraging and measuring the derivation between normal and anomalous behavior of each mesh node. Secondly, based on reputation management, we develop a cooperative anomaly detection scheme by fully exploring the spatio-temporal properties of mesh nodes' behavior. Our current scheme is specified and implemented with a reactive routing protocol, aiming at detecting malicious mesh nodes which intentionally violate normal routing mechanisms. The simulation results show that our scheme performs well in terms of detection accuracy, false positive rate, computational overhead, and scalability. Zonghua Zhang, Farid Naït-Abdesselam, Pin-Han Ho, Xiaodong Lin 0001 |
WCNC | 1 |
| 2008 | Defending against packet dropping attack in vehicular ad hoc networksabstractAbstract Vehicularad hocnetworks (VANETs) are becoming very popular and a promising application of the so‐called mobilead hocnetworks (MANET) technology. It has attracted recently an increasing attention from many car manufacturers as well as the wireless communication research community. Despite its tremendous potential to enhance road safety and to facilitate traffic management, VANET suffers from a variety of security and privacy issues which may dramatically limit their applications. In this paper, we address the problem of packet dropping attack launched against routing protocol's control packets, which represents one of the most aggressive attacks in MANET. The aim of this attack is to force nodes in the network to choose hostile nodes as relays to disseminate the partial topological information, thereby exploiting the functionality of the routing protocol to retain control packets. In particular, in optimized link state routing (OLSR) protocol, if a collusive packet dropping attack is launched during the propagation of the topology control (TC) packets, the topology information will fail in being disseminated to the entire network, which finally results in routing disruption. This paper focuses on the packet dropping attack, launched against OLSR, where two malicious multipoint relay (MPR) nodes collude to disrupt the topology discovery process. Based on the analysis of the attacker's behavior and the attack's consequence, we propose an acknowledgement‐based mechanism as a countermeasure to enhance the security of OLSR. This mechanism helps the OLSR protocol to be less vulnerable to such attack by detecting and then isolating malicious nodes in the network. The simulation results of the proposed scheme show high detection rate under various scenarios. Copyright © 2008 John Wiley & Sons, Ltd. Soufiene Djahel, Farid Naït-Abdesselam, Zonghua Zhang, Ashfaq Khokhar 0001 |
Secur. Commun. Networks | 3 |
| 2008 | Special Issue on "Security and Privacy Preservation in Vehicular Communications" Wiley's Security and Communication Networks JournalabstractAbstract It has been witnessed that the car manufacturers and telecommunication industries gear up to equip each car with the latest wireless communication technologies, most notably the short‐range communication systems and/or networks (vehicle‐vehicle or vehicle‐roadside) based on IEEE 802.11p. The short‐range vehicular communication technologies are expected to evolve into VANETs (Vehicular Ad‐hoc NETworks), which will be supporting various safety and commercial applications that significantly improve the driving experiences and safety. The merits of launching VANETs are obvious; however, it comes with a set of challenges, especially in the aspects of security and privacy preservation, in which any malicious behavior of users, such as a modification and replay attack with respect to the disseminated messages, could be fatal to the other users. In addition, the issues on VANET security become more challenging due to the unique features of such network scenarios, including high‐speed mobility and large amount of network entities (i.e., the vehicles). Furthermore, conditional privacy preservation must be achieved in a sense that the user related privacy information, including the driver's name, the license plate, speed, position, and traveling routes along with their relationships, has to be protected; while the authorities should be able to reveal the identities of message senders in the event of a traffic dispute, such as a crime/car accident scene investigation. This special issue aims to address the aforementioned issues by collecting six technical papers through a peer‐review process, hoping to contribute to the state‐of‐the‐art progress of secure and privacy preserving vehicular communications. Copyright © 2008 John Wiley & Sons, Ltd. Pin-Han Ho, Zonghua Zhang, Rongxing Lu |
Secur. Commun. Networks | 2 |
| 2007 | 3D Periodic Human Motion Reconstruction from 2D Motion SequencesabstractWe present and evaluate a method of reconstructing three-dimensional (3D) periodic human motion from two-dimensional (2D) motion sequences. Using Fourier decomposition, we construct a compact representation for periodic human motion. A low-dimensional linear motion model is learned from a training set of 3D Fourier representations by means of principal components analysis. Two-dimensional test data are projected onto this model with two approaches: least-square minimization and calculation of a maximum a posteriori probability using the Bayes' rule. We present two different experiments in which both approaches are applied to 2D data obtained from 3D walking sequences projected onto a plane. In the first experiment, we assume the viewpoint is known. In the second experiment, the horizontal viewpoint is unknown and is recovered from the 2D motion data. The results demonstrate that by using the linear model, not only can missing motion data be reconstructed, but unknown view angles for 2D test data can also be retrieved. Zonghua Zhang, Nikolaus F. Troje |
Neural Comput. | 1 |
| 2005 | Constructing Multi-Layered Boundary to Defend Against Intrusive Anomalies: An Autonomic Detection CoordinatorabstractAn autonomic detection coordinator is developed in this paper, which constructs a multi-layered boundary to defend against host-based intrusive anomalies by correlating several observation-specific anomaly detectors. Two key observations facilitate the model formulation: first, different anomaly detectors have different detection coverage and blind spots; second, diverse operating environments provide different kinds of information to reveal anomalies. After formulating the cooperation between basic detectors as a partially observable Markov decision process, a policy-gradient reinforcement learning algorithm is applied to search in an optimal cooperation manner, with the objective to achieve broader detection coverage and fewer false alerts. Furthermore, the coordinator's behavior can be adjusted easily by setting a reward signal to meet the diverse demands of changing system situations. A preliminary experiment is implemented, together with some comparative studies, to demonstrate the coordinator's performance in terms of admitted criteria. Zonghua Zhang, Hong Shen 0001 |
DSN | 1 |
| 2005 | A Brief Observation-Centric Analysis on Anomaly-Based Intrusion Detection
Zonghua Zhang, Hong Shen 0001 |
ISPEC | 1 |
| 2005 | An Efficient Protocol for the Problem of Secure Two-party Vector DominanceabstractThe problem of secure two-party vector dominance requires the comparison of two vectors in an "all-or-nothing" way. In this paper we provide a solution to this problem based on the semi-honest model. It is reduced to the problem of privacy preserving prefix test, and an additive threshold homomorphic encryption is used to protect those privacies while computing the results of all of the prefix tests. Our solution has advantages of efficiency and security in comparison with other solutions. Yingpeng Sang, Hong Shen 0001, Zonghua Zhang |
PDCAT | 3 |
| 2005 | A Brief Comparative Study on Analytical Models of Computer System Dependability and SecurityabstractAs two different research topics with much overlap, dependability and security of computer/communication systems have respective long and rich history. The development of the techniques for their modeling and analysis thus have followed distinct but convergent paths. In essence, diverse attributes and the fundamental difference between the nature of the failures bring in different concerns for dependability and security analysis during their modeling process. Taking the understanding of the basic concepts/attributes as a point of departure, this paper intend to carry out a comparative study on the analytical models of computer system dependability and security. Also, by examining the state-of-the-art quantitative techniques and sound modeling methodologies for dependability evaluation, e.g., combinatorial and stochastic methods, we attempt to explore why and how those methods can be extended to evaluate computer system security. Furthermore, we take our developed autonomic detection coordinator (for intrusion detection) as a case study to conduct the comparative analysis. Zonghua Zhang, Hong Shen 0001, Xavier Défago, Yingpeng Sang |
PDCAT | 1 |
| 2005 | Application of online-training SVMs for real-time intrusion detection with different considerations
Zonghua Zhang, Hong Shen 0001 |
Comput. Commun. | 1 |
| 2005 | View-independent person identification from human gait
Zonghua Zhang, Nikolaus F. Troje |
Neurocomputing | 1 |
| 2004 | Online Training of SVMs for Real-time Intrusion DetectionabstractTo break the strong assumption that most of the training data for intrusion detectors are readily available with high quality, conventional SVM, Robust SVM and one-class SVM are modified respectively in virtue of the idea from Online Support Vector Machine (OSVM) in this paper, and their performances are compared with that of the original algorithms.Preliminary experiments with 1998 DARPA BSM data set indicate that the modified SVMs can be trained online and the results outperform the original ones with less support vectors(SVs) and training time without decreasing detection accuracy.Both of these achievements benefit an effective online intrusion detection system significantly. Zonghua Zhang, Hong Shen 0001 |
AINA (1) | 1 |