Xingshu Chen

dblp:43/1479 · DBLP profile ↗
← Back
66ranked-venue papers
0as first author
51since 2021 · last 2026
0000-0002-8705-2617ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 10 since 2021Computer networks · 17 · 15 since 2021Artificial intelligence and machine learning · 15 · 14 since 2021Databases, data management, data science and information retrieval · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Systems, architecture and hardware · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ${\mathsf{KubeSec}} $KubeSec: Automatic Detection of Takeover Risks Introduced by Third-Party Apps in the Kubernetes Ecosystem
abstract
Third-party applications (TPAs) are integral components of managed Kubernetes clusters, but are also frequently exploited in takeover attacks. Recent incidents have demonstrated that TPAs can be weaponized to gain control over clusters. Given their critical role within the Kubernetes ecosystem, it is essential to explore the potential attack surfaces associated with various types of TPAs. To address this, we propose${\sf KubeSec}$, a framework that systematically investigates these risks by analyzing application permission configurations and component code dependencies. This investigation revealed a significant number of insecure RBAC binding patterns, uncovering 562 such patterns and identifying 375 vulnerabilities linked to 134 CVEs. These vulnerabilities impact millions of users, with an average remediation time exceeding 10 months. All findings have been reported to the relevant teams, leading to the assignment of 21 new CVEs by the community. These results highlight substantial security risks associated with TPAs in Kubernetes clusters and emphasize the urgent need for further research to develop more secure cluster management practices.
Qiyu Hou, Hao Ren 0001, Xingshu Chen, Gelei Deng, Tianwei Zhang 0004, Guowen Xu, Hongwei Li 0001
IEEE Trans. Dependable Secur. Comput.4
2025 PrivDNFIS: Privacy-preserving and Efficient Deep Neuro-Fuzzy Inference System
abstract
Deep Neuro-Fuzzy Inference Systems (DNFIS) seamlessly fuse neural networks with the fuzzy inference system enabling intricate decision-making and knowledge representation, while upholding a commendable degree of adaptability and interpretability. However, the challenge of privacy-preserving inference (PI) over DNFIS has remained largely uncharted, with no prior research addressing this critical issue. In this paper, we embark on an exploration of this issue. We introduce an efficient and secure PI framework for DNFIS, named PrivDNFIS, which leverages the post-quantum lattice-based homomorphic encryption to implement secure computation protocols for PI over DNFIS. Our work incorporates several non-trivial performance enhancements. Firstly, it consolidates multiple elements of input feature vectors into a single message, reducing encryption/decryption overhead. Secondly, building upon this novel encoding approach, PrivDNFIS can perform ciphertext aggregation and vector-vector inner production without necessitating time-consuming ciphertext rotation operations. Thirdly, we replace the softmax function in the DNFIS layer with a quadratic function to further enhance inference efficiency, without compromising the inference accuracy. Under the given threat model, we provide formal security proof for PrivDNFIS. In comprehensive experimental results, PrivDNFIS demonstrates an approximately 1.9 to 4.4 times reduction in end-to-end time cost compared to the benchmark.
Hao Ren 0001, Xiao Lan, Rui Tang 0020, Xingshu Chen
AAAI4
2025 PPNA: Enabling Privacy-Preserving and Efficient Social Network Alignment
abstract
Social network alignment has made significant progress in social network analysis, with representative applications such as cross-domain recommendation and community detection. However, existing approaches require institutions to share raw user data, raising significant privacy concerns. To address this issue, we propose a Privacy-Preserving Network Alignment (PPNA) scheme that eliminates the need for raw data sharing. In concrete, PPNA leverages homomorphic encryption to enable computation over the ciphertext domain without decryption. It ensures provable data privacy. PPNA also presents a secure multiparty computation protocol to eliminate reliance on trusted third-party servers, which is often impractical in real-world scenarios. Furthermore, its well-designed iterative update mechanism is well-suited for iterative alignment algorithms. Comprehensive experimental results have demonstrated that PPNA improves performance compared to the scenario where raw data sharing is unfeasible due to privacy concerns. It achieves an average F1-score increase of 1.65 times and up to 2.28 times. The performance gain is more pronounced in decentralized settings, highlighting PPNA’s practicality in real-world scenarios when multi-institution collaboration is imperative.
Rui Tang 0020, Hao Ren 0001, Haizhou Wang 0001, Xingshu Chen, Meng Li 0006, Hongwei Li 0001
GLOBECOM5
2025 TKA-MIL: Top-K Attention Multiple Instance Learning for Whole Slide Image Classification and Instance Probability Derivation
abstract
Multiple instance learning (MIL) has been increasingly applied to the classification of histopathology whole slide images (WSI). While many classic attention-based MIL algorithms have achieved good classification performance, they do not account for the relationships between instances. Using transformers in MIL can effectively capture these relationships but requires substantial computational resources. To address the trade-off between performance and computational cost, we propose a new simplified attention-based MIL model—TKA-MIL, which only capture the relationships between all instances and critical instances. Additionally, we derive the probability of an instance being positive based on the attention weights of TKA-MIL. Experiments on the Camelyon16 and TCGA Lung Cancer datasets demonstrate that our approach achieves an optimal balance between classification performance and model complexity, and the derived instance probabilities are more accurate compared to directly using normalized attention weights.
Sicheng Yu, Xingshu Chen, Fangzhou Cao, Ting Tian
ICASSP2
2025 VuldiffFinder: Discovering inconsistencies in unstructured vulnerability information
Qindong Li, Wenyi Tang, Xingshu Chen, Hao Ren 0001
Comput. Secur.3
2025 An efficient and commercial proof of storage scheme supporting dynamic data updates
Zhenwu Xu, Xingshu Chen, Liangguo Chen, Xiao Lan, Hao Ren 0001, Changxiang Shen
Comput. Secur.2
2025 ReZG: Retrieval-augmented zero-shot counter narrative generation for hate speech
Shuyu Jiang, Wenyi Tang, Xingshu Chen, Rui Tang 0020, Haizhou Wang 0001, Wenxian Wang
Neurocomputing3
2025 Decomposition, Synthesis, and Attack: A Multi-Instruction Fusion Method for Jailbreaking LLMs
abstract
Large language models (LLMs) can transform natural language instructions into executable commands for IoT devices like unmanned aerial vehicles (UAVs), creating new development opportunities. However, safety concerns about LLMs translating commands into machine or program control instructions cannot be overlooked. Currently, jailbreak instructions used to test the LLM security are often restricted to specific modes or tasks, resulting in a lack of diversity and leaving some tasks unexplored. To address this issue, we introduce a Multi-Instruction Fusion (MIF) method that can automatically fuse harmful prompts and various task instructions into jailbreaks. Firstly, we adopt a reverse decomposition strategy to acquire sufficient supervised data for fusing harmful prompts and instructions into jailbreaks and construct a task instruction synthesizer based on it. Then, to determine the optimal instruction combinations in the vast combination space, we propose a representative-node-based selection strategy, ReNB, to rank and filter the instruction combinations on a few representative samples, thereby accelerating the identification of the valid ones. Experimental results demonstrate that MIF significantly improves the attack success rate, achieving over 90% on GPT-4o-mini, LLaMa2-70B and Qwen2-7B models, outperforming the state-of-the-art baselines.
Shuyu Jiang, Xingshu Chen, Kaiyu Xu, Liangguo Chen, Hao Ren 0001, Rui Tang 0020
IEEE Internet Things J.2
2025 Distributed Data Grading With Privacy Enhanced in Internet of Unmanned Agent: A Federated Hybrid Deep Learning Approach
abstract
The Internet of unmanned agents (IUAs) has emerged as a transformative technology, driven by advancements in unmanned devices and 5G communications, leading to significant progress in autonomous systems and distributed networks. Despite these advancements, IUA faces significant challenges in data security, privacy preservation, and distributed learning, particularly in grading sensitive data and efficient distributed grade model training across diverse unmanned devices within IUA context. To address these issues, this article proposes a novel scheme, FedHDL-IUA, a privacy-enhanced distributed data grading scheme designed specifically for the IUA context. This scheme leverages a federated learning (FL) framework, ensuring the privacy of local sensitive data while optimizing the performance of distributed data grading models. By combining bidirectional long short-term memory (BiLSTM) and residual networks (ResNets), the scheme can effectively capture feature dependencies in diverse network traffic data, thereby enhancing the accuracy and efficiency of the data grading model. The simulation experiments are conducted using two open-source datasets and a private dataset, and the results show that FedHDL-IUA can efficiently and effectively grade the traffic data in both centralized and FL modes and outperforms other existing schemes and traditional deep learning models in terms of performance.
Yunxiang Qiu, Xinlong Wu, Liangguo Chen, Xingshu Chen
IEEE Internet Things J.5
2025 A Toxic Euphemism Detection framework for online social network based on Semantic Contrastive Learning and dual channel knowledge augmentation
Haizhou Wang 0001, Wenxian Wang, Shuyu Jiang, Rui Tang 0020, Xingshu Chen
Inf. Process. Manag.7
2025 A metadata-aware detection model for fake restaurant reviews based on multimodal fusion
Yifei Jian, Xiaoda Wang, Xingshu Chen, Xiao Lan, Wenxian Wang, Haizhou Wang 0001
Neural Comput. Appl.5
2025 Reinforcement learning-driven temporal knowledge graph reasoning for secure data provenance in distributed networks
Yunxiang Qiu, Yuting Tang, Liangguo Chen, Shuyu Jiang, Xingshu Chen
Peer Peer Netw. Appl.6
2025 Compact network alignment with mitigated sensitive information exposing in P2P networks: a community partition-based approach
Rui Tang 0020, Yiming Peng, Jingxi Li, Xingshu Chen, Xian Mo
Peer Peer Netw. Appl.4
2025 Efficient privacy-preserving federated logistic regression with poor-quality users
Xingshu Chen, Hao Ren 0001, Changxiang Shen
Peer Peer Netw. Appl.3
2025 Enhancing the Availability and Security of Attestation Scheme for Multiparty-Involved DLaaS: A Circular Approach
abstract
In this paper, we propose a remote attestation approach based on multiple verifiers named CARE. CARE aims to enhance the practicality and efficiency of remote attestation while addressing trust issues within environments involving multiple stakeholders. Specifically, CARE adopts the concept of swarm verification, and employs a circular collaboration model with multiple verifiers to collect and validate evidence, thereby resolving trust issues and enhancing verification efficiency. Moreover, CARE introduces a meticulously designed filtering mechanism to address the issue of false positives in verification outcomes non-invasively. CARE utilizes a multiway tree structure to construct the baseline value library, which enhances the flexibility and fine-grained management capability of the system. Security analysis indicates that CARE can effectively resist collusion attacks. Further, detailed simulation experiments have validated its capability to convincingly attest to the trustworthiness of the dynamically constructed environment. Notably, CARE is also suitable for the remote attestation of large-scale virtual machines, achieving an efficiency 9 times greater than the classical practice approach. To the best of our knowledge, CARE is the first practical solution to address inaccuracies in remote attestation results caused by the activation of Integrity Measurement Architecture (IMA) at the application layer.
Guosheng Huang, Honghai Chen, Yongyi Liao, Qixu Wang, Xingshu Chen
IEEE Trans. Cloud Comput.6
2025 Gupacker: Generalized Unpacking Framework for Android Malware
abstract
Android malware authors often use packers to evade analysis. Although many unpacking tools have been proposed, they face two significant challenges: 1) They are easily impeded by anti-analysis techniques employed by packers, preventing efficient collection of hidden Dex data. 2) They are typically designed to unpack a specific packer and cannot handle malware packed with mixed packers. Consequently, many packed malware samples evade detection. To bridge this gap, we propose Gupacker, a novel generalized unpacking framework. Gupacker offers a generic solution for first-generation holistic packer by customizing the Android system source code. It identifies the type of packer and selects an appropriate unpacking function, constructs a deeper active call chain to achieve generic unpacking of second-generation function extraction packers, and usesJNIfunction and instruction monitoring to handle third-generation virtual obfuscation packer. On this basis, we counteract a diverse array of anti-analysis techniques. We conduct extensive experiments on 5K packed Android malware samples, comparing Gupacker with 2 commercial and 4 state-of-the-art academic unpacking tools. The results demonstrate that Gupacker significantly improves the efficiency of Android malware unpacking with acceptable system overhead. We analyze real packed applications based on Gupacker and found several are second-packed by attackers, including WPS for Android, with tens of millions of users. We receive and responsibly report 13 0day vulnerabilities and also assist in the remediation of all vulnerabilities.
Qiyu Hou, Xingshu Chen, Hao Ren 0001, Meng Li 0006, Hongwei Li 0001, Changxiang Shen
IEEE Trans. Inf. Forensics Secur.3
2024 Comprehensive vulnerability aspect extraction
Qindong Li, Wenyi Tang, Xingshu Chen, Lizhi Wang 0003
Appl. Intell.3
2024 Empowering Data Owners: An Efficient and Verifiable Scheme for Secure Data Deletion
Zhenwu Xu, Xingshu Chen, Xiao Lan, Rui Tang 0020, Shuyu Jiang, Changxiang Shen
Comput. Secur.2
2024 An anomaly behavior characterization method of network traffic based on Spatial Pyramid Pool (SPP)
abstract
APT attacks have the characteristics of low frequency, stealth, and persistence. Achieving attack objectives and preventing trace-back often involve diverse tactics, various tools, and changing processes and patterns. Additionally, the goals of APT attacks are diverse. Apart from service disruptions or network outages, the main goals include remotely penetrating target hosts through the network to steal information, unauthorized encryption, and destructive wiping. Existing methods for characterizing attack features lack sufficient research on the communication methods and data transmission patterns used in attacks. In particular, due to the non-associated addresses, low frequency, fragmentation, and silent requirements of attacks, the features exhibited in a single session are increasingly minimal. Traditional approaches are no longer sufficient to address these challenges that relying solely on single-sample statistical features and "packet-sniffing" windowed traffic grouping detection methods. To tackle these issues, we propose a innovative approach to characterize network attack traffic based on Spatial Pyramid Pooling (SPP) by analyzing the attack communication methods and data transmission patters in the network session traffic of APT attacks with the remote information theft. Specifically, it employs derived feature attributes that integrate mean, total, and concentration characteristics to longitudinally extract multi-level spatiotemporal correlated behavioral features from aggregated multi-session sets. These features are then fused with single-session characteristics, ensuring that each session sample possesses both current traffic features and correlated properties of contextual session traffic. Additionally, this approach meets the requirements of fixed-length input for heterogeneous data in deep learning. Extensive experiments have been conducted to demonstrate that this method enhances the effective detection of APT attacks by deep learning models. Experiments results show that this approach exhibits superior timeliness, precision, and specificity when compared to Principal Component Analysis (PCA) artificial feature engineering methods and other methods based on fixed-length deep learning for raw data.
Xingshu Chen, Qindong Li
Comput. Secur.2
2024 A novel framework for Chinese personal sensitive information detection
abstract
With the rapid development of social networks, the harm caused by the leakage of personal sensitive information is becoming increasingly serious.In order to detect and identify personal sensitive information, existing methods build matching rules to detect specific sensitive entities and use machine learning methods to classify sensitive text.These methods face challenges in context analysis and adapting to Chinese language characteristics.This paper proposes CPSID, a method for detecting Chinese personal sensitive information.On the one hand, CPSID utilises rule matching to detect specific personal sensitive information only containing letters and numbers.More importantly, CPSID constructs a sequence labelling model named EBC (ELECTRA-BiLSTM-CRF) to detect more complex personal sensitive information that consist of Chinese characters.The EBC model uses the latest ELECTRA algorithm to implement word embedding, and uses BiLSTM and CRF models to extract personal sensitive information, which can detect Chinese sensitive entities accurately by analysing context information.The model achieves an F1 score of 94.09% on Chinese datasets, outperforming other similar models.Additionally, experiments on real data show CPSID has a better detection result than individual methods (rule matching or sequence labelling).
Chenglong Ren, Xiao Lan, Xingshu Chen, Yonggang Luo, Shuhua Ruan
Connect. Sci.3
2024 A deep semantic-aware approach for Cantonese rumor detection in social networks with graph convolutional network
Yifei Jian, Liang Ke, Yunxiang Qiu, Xingshu Chen, Yunya Song, Haizhou Wang 0001
Expert Syst. Appl.5
2024 A novel cross-domain adaptation framework for unsupervised criminal jargon detection via pre-trained contextual embedding of darknet corpus
Liang Ke, Shui Yu 0001, Xingshu Chen, Haizhou Wang 0001
Expert Syst. Appl.5
2024 Enhancing TinyML-Based Container Escape Detectors With Systemcall Semantic Association in UAVs Networks
abstract
The adoption of lightweight container technology enables the cross-architecture deployment of Tiny Machine Learning (TinyML) models, while the implementation of container escape detectors ensures the security of both models and applications. However, a significant challenge faced by TinyML-based detectors is model aging, which leads to a substantial decline in their effectiveness as attack patterns evolve. Most existing approaches address this issue by retraining models through the labeling of new samples. However, this process can be costly and challenging to implement for updating models in resource-constrained UAVs networks. In this paper, we begin by analyzing the correlation of threat data and observe that throughout evolution, different versions of container escape attacks tend to maintain semantically identical or similar system calls. This observation prompts us to approach the model aging problem from a novel perspective: if the model can acquire knowledge of these fundamental system calls, it will be capable of effectively detecting emerging new attacks. Based on this perspective, we have developed sysE to capture system call data that remains unchanged or exhibits similarities to container escape attacks during evolution. This augmentation complements six TinyML-based detectors. Experimental results obtained from a large-scale evolving dataset demonstrate that our proposed approach effectively mitigates the aging rate of these models, reducing it from 7.3% to 21.5%. Additionally, it significantly decreases the labeling effort required from 28.06% to 65.47%.
Yunxiang Qiu, Yundan Zheng, Qixu Wang, Xingshu Chen
IEEE Internet Things J.5
2024 A green computing method for encrypted IoT traffic recognition based on traffic fingerprint graphs
Xingshu Chen, Wenyi Tang, Bingyu Chen 0006
Peer Peer Netw. Appl.2
2024 Detecting Offensive Language Based on Graph Attention Networks and Fusion Features
abstract
The pervasiveness of offensive language on social networks has caused adverse effects on society, such as abusive behavior online. It is urgent to detect offensive language and curb its spread. In the popular datasets, the distribution of users and tweets is imbalanced, which limits the generalization ability of the model. In addition, existing research shows that methods with community information extracted from the social graphs effectively improve the performance of offensive language detection. However, the existing models deal with social graphs independently, which seriously affects the effectiveness of detection models. In this article, we release a new dataset with users and social relationships. To encode community information, we construct the social graphs based on the user historical behavior information and social relationships. Moreover, we propose a model based on graph attention networks (GATs) and fusion features for offensive language detection (GF-OLD). Specifically, the community information is directly captured by the GAT module, and the text embeddings are taken from the last hidden layer of bidirectional encoder representation from transformer (BERT). Attention mechanisms and position encoding are used to fuse these features. Our method outperforms baselines with the F1-score of 89.94%. The results show that our model effectively learns the potential information of social graphs and text, and user historical behavior information is more suitable for user attribute in the social graphs.
Zhenxiong Miao, Xingshu Chen, Haizhou Wang 0001, Rui Tang 0020, Tiemai Huang, Wenyi Tang
IEEE Trans. Comput. Soc. Syst.2
2024 Detecting Spam Movie Review Under Coordinated Attack With Multi-View Explicit and Implicit Relations Semantics Fusion
abstract
Spam reviews have long polluted review systems, undermining their industries. Detecting spam movie reviews faces some brand-new challenges compared to traditional spam detection. These include coordinated spamming attacks during premieres or at advance screenings. However, most of existing studies only use inherent relations among reviews, movies, and users, they do not fully exploit explicit and implicit relations between reviews in coordinated spamming attacks. To address these novel challenges, we propose a spam movie review detection method based on mining explicit and implicit relation semantics and fusing multi-view semantics. To the best of our knowledge, we are the first to enhance spam movie review detection by exploiting both explicit and implicit relations between reviews in coordinated spamming attacks. First, we build an explicit relation movie-review graph with movie synopses and high-quality external reviews. We extract movie factual knowledge embeddings using a Heterogeneous Graph Transformer (HGT) network. Next, we input the factual knowledge embeddings with corresponding review embeddings into a contrastive network to get review credibility features. Additionally, we build an implicit relation graph between reviews using metadata and semantic similarities. We extract relation-enhanced review semantics via another HGT network. Finally, we fuse the three review semantic features through an attention layer before making classification. Experiments show our method achieves higher performance and robustness over state-of-the-art methods.
Yicheng Cai, Haizhou Wang 0001, Wenxian Wang, Lei Zhang 0103, Xingshu Chen
IEEE Trans. Inf. Forensics Secur.6
2024 RESTLess: Enhancing State-of-the-Art REST API Fuzzing With LLMs in Cloud Service Computing
abstract
REST API Fuzzing is an emerging approach for automated vulnerability detection in cloud services. However, existing SOTA fuzzers face challenges in generating lengthy sequences comprising high-semantic requests, so that they may hardly trigger hard-to-reach states within a cloud service. To overcome this problem, we propose RESTLess, a flexible and efficient approach with hybrid optimization strategies for REST API fuzzing enhancement. Specifically, to pass the cloud gateway syntax semantic checking, we construct a dataset of valid parameters of REST API with Large Language Model named RTSet, then utilize it to develop an efficient REST API specification semantic enhancement approach. To detect vulnerability hidden under complex API operations, we design a flexible parameter rendering order optimization algorithm to increase the length and type of request sequences. Evaluation results highlight that RESTLess manifests noteworthy enhancements in the semantic quality of generated sequences in comparison to existing tools, thereby augmenting their capabilities in detecting vulnerabilities effectively. We also apply RESTLess to nine real-world cloud service such as Microsoft Azure, Amazon Web Services, Google Cloud, etc., and detecte 38 vulnerabilities, of which 16 have been confirmed and fixed by the relevant vendors.
Jinqiao Dai, Shuyu Jiang, Xingshu Chen, Changxiang Shen
IEEE Trans. Serv. Comput.5
2023 ANTI: An Adaptive Network Traffic Indexing Algorithm for High-Speed Networks
abstract
Network packets record communication behaviors and details, which is important for security audits, attack detection, and forensic analysis. For the effectiveness and timeliness of security analysis, it is necessary to fully store network packets and build an efficient packet index. However, the existing packet indexing algorithms based on the radix tree ignore the distribution characteristics of network traffic and use internal nodes with the same capacity for index construction, resulting in wasted disk space and poor retrieval performance. As a solution,$w$e propose ANTI, an adaptive network traffic indexing algorithm similar to Adaptive Radix Tree, which can adaptively switch internal nodes with different capacity according to the density of network traffic and compress the common prefix and distinct suffix of traffic attributes to balance the index construction performance and space utilization. We also implement a packet-aware network traffic archiving and indexing system to achieve full packet archival, efficient indexing, and fast retrieval. Finally, we empirically evaluate ANTI in IPv4 (IPv6) traffic scenarios, and the results confirm the effectiveness of ANTI as well as the benefit of adopting ANTI for enhancing indexing and retrieval performance compared with other state-of-art algorithms.
Xingshu Chen, Liangguo Chen, Xiao Lan, Yonggang Luo
GLOBECOM2
2023 DKCS: A Dual Knowledge-Enhanced Abstractive Cross-Lingual Summarization Method Based on Graph Attention Networks
Shuyu Jiang, Dengbiao Tu, Xingshu Chen, Rui Tang 0020, Wenxian Wang, Haizhou Wang 0001
ICONIP (13)3
2023 Identifying Cantonese rumors with discriminative feature integration in online social networks
Haizhou Wang 0001, Liang Ke, Zhipeng Lu 0001, Hanjian Su, Xingshu Chen
Expert Syst. Appl.6
2023 Listen carefully to experts when you classify data: A generic data classification ontology encoded from regulations
Xingshu Chen, Liuyan Tan, Xiao Lan, Yonggang Luo
Inf. Process. Manag.2
2023 Laws and Regulations tell how to classify your data: A case study on higher education
Liuyan Tan, Xingshu Chen, Yonggang Luo, Zhenwu Xu, Xiao Lan
Inf. Process. Manag.3
2023 Unveiling Qzone: A measurement study of a large-scale online social network
Haizhou Wang 0001, Yixuan Fang, Shuyu Jiang, Xingshu Chen, Xiaohui Peng 0007, Wenxian Wang
Inf. Sci.4
2023 Review on the application of deep learning in network attack detection
abstract
With the development of new technologies such as big data, cloud computing, and the Internet of Things, network attack technology is constantly evolving and upgrading, and network attack detection technology is forced to undergo corresponding iterative evolution. Three main problems are associated with these technologies: the automatic representation of heterogeneous and complex network traffic data, the uneven network attack samples, and the contradiction between the accuracy of the anomaly detection model and the continuous evolution of attacks. Researchers have proposed several network attack detection techniques based on deep learning to address these problems. This study reviews and analyzes the studies aimed at dealing with such problems, considering multiple factors, such as models, traffic representation and feature extraction, threat detection model training, and model robustness improvement. Finally, the existing problems and challenges associated with the current research are analyzed with respect to data category imbalance, high-dimensional massive data processing, concept distribution drift, real-time interpretability of the detection model, and the security of the model.
Xingshu Chen, Weijing Ge, Zhenhui Han
J. Netw. Comput. Appl.2
2023 DockerWatch: a two-phase hybrid detection of malware using various static features in container cloud
Qixu Wang, Xingshu Chen, Bangzhou Xin
Soft Comput.4
2023 Interlayer Link Prediction in Multiplex Social Networks Based on Multiple Types of Consistency Between Embedding Vectors
abstract
Online users are typically active on multiple social media networks (SMNs), which constitute a multiplex social network. With improvements in cybersecurity awareness, users increasingly choose different usernames and provide different profiles on different SMNs. Thus, it is becoming increasingly challenging to determine whether given accounts on different SMNs belong to the same user; this can be expressed as an interlayer link prediction problem in a multiplex network. To address the challenge of predicting interlayer links, feature or structure information is leveraged. Existing methods that use network embedding techniques to address this problem focus on learning a mapping function to unify all nodes into a common latent representation space for prediction; positional relationships between unmatched nodes and their common matched neighbors (CMNs) are not utilized. Furthermore, the layers are often modeled as unweighted graphs, ignoring the strengths of the relationships between nodes. To address these limitations, we propose a framework based on multiple types of consistency between embedding vectors (MulCEVs). In MulCEV, the traditional embedding-based method is applied to obtain the degree of consistency between the vectors representing the unmatched nodes, and a proposed distance consistency index based on the positions of nodes in each latent space provides additional clues for prediction. By associating these two types of consistency, the effective information in the latent spaces is fully utilized. In addition, MulCEV models the layers as weighted graphs to obtain representation. In this way, the higher the strength of the relationship between nodes, the more similar their embedding vectors in the latent representation space will be. The results of our experiments on several real-world and synthetic datasets demonstrate that the proposed MulCEV framework markedly outperforms current embedding-based methods, especially when the number of training iterations is small.
Rui Tang 0020, Zhenxiong Miao, Shuyu Jiang, Xingshu Chen, Haizhou Wang 0001, Wei Wang 0070
IEEE Trans. Cybern.4
2022 vTPM-SM: An Application Scheme of SM2/SM3/SM4 Algorithms Based on Trusted Computing in Cloud Environment
abstract
Numbers of applications and businesses are hosted on cloud computing platforms, and it is essential for cloud tenants to protect their data through encryption or other methods. When tenants use encryption algorithms provided by software, they are bound to face the defect that keys are not protected by hardware. Trusted computing technology can securely store the key in the hardware device. However, the hardware TPM cannot provide services for multiple VMs simultaneously. The virtual trusted computing technology virtualizes the TPM and can assign vTPM to each VM. Currently, vTPM only supports RSA, ECDSA, SHA256, and AES algorithms, et al. Relevant studies have shown that SM2/SM3/SM4 algorithms are more secure than ECDSA/SHA256/AES. In order to cope with the limitations of the cryptographic algorithms supported by vTPM, we design the vTPM-SM scheme to provide a secure and reliable SM2/SM3/SM4 algorithm application method for cloud environments. Experiments show that vTPM-SM can effectively realize the VM using Chinese commercial cryptographic algorithms through vTPM. Compared with the existing scheme, using SM2/SM3/SM4 algorithm reduces the time overhead by about 31.6%, 83.3% and 15.5%, respectively.
Mingxing Zhou, Shuhua Ruan, Xingshu Chen, Qixu Wang
CLOUD4
2022 Fake Restaurant Review Detection Using Deep Neural Networks with Hybrid Feature Fusion Method
Yifei Jian, Xingshu Chen, Haizhou Wang 0001
DASFAA (3)2
2022 ApkClassiFy: Identification and Classification of packed Android Malicious Applications
abstract
There are becoming increasingly common for Android malware with packer protection, which can effectively evade malware detection. Thus the packed identification is very required. However, current packers identification schemes cannot efficiently deal with mixed packers and fail to provide a suitable unpacking scheme. In this paper, we propose a new method called ApkClassiFy. By constructing a fingerprint feature library and classification mapping library, ApkClassiFy can accurately identify and classify Android-packed malware, effectively identifying mixed packing applications and providing a corresponding unpacking scheme. To further verify the performance of ApkClassiFy, we constructed the Android malware dataset MalApk and the packed Android malware classification dataset OmixShell. The experimental results show ApkClassiFy has higher accuracy and lower false positives in detecting packed Android malware than other packed identification schemes. Besides, ApkClassiFy can also classify packers to identify mixed packers and help analysts choose the appropriate unpacking scheme.
Xingshu Chen, Qixu Wang, Zhijie Hu
GLOBECOM3
2022 Autoscaling cracker: an efficient asymmetric DDoS attack on serverless functions
abstract
Serverless computing has brought new changes to cloud computing. The decoupled serverless functions have more flexible scheduling methods and use resources efficiently with the help of autoscaling. However, it exposes more attack surfaces. If an insecure function becomes a serverless function, a significant security risk will be brought to its service. This paper analyzes the risk of asymmetric DDoS attacks faced by insecure serverless functions. These attacks can occupy a large amount of CPU or memory resources without redundant connections. They can affect the quality of service, delay response time, or even interrupt the service. Autoscaling lacks resilience to such attacks. We test the effects of these attacks in experimental environments and Alibaba Cloud's serverless application engine (SAE). In SAE, we increase the response time from 0.2 seconds to 25 seconds or crash the target function within 6 seconds. Compared with traditional DDoS attacks, asymmetric DDoS attacks are more effective for serverless applications. Finally, we design solutions to mitigate asymmetric DDoS attacks for applications with long and short response times in serverless environments.
Dengzhe Wang, Xingshu Chen, Qixu Wang, Shengkai Wang, Feiyu Xu 0002
GLOBECOM2
2022 Unsupervised Anomaly Detection for Container Cloud Via BILSTM-Based Variational Auto-Encoder
abstract
The appearance of container technology has profoundly changed the development and deployment of multi-tier distributed applications. However, the imperfect system resource isolation features and the kernel-sharing mechanism will introduce significant security risks to the container-based cloud. In this paper, we propose a real-time unsupervised anomaly detection system for monitoring system calls in container cloud via BiLSTM-based variational auto-encoder (VAE). Our proposed BiLSTM-based VAE network leverages the generative characteristics of VAE to learn the robust representations of normal patterns by reconstruction probabilities while being sensitive to long-term dependencies. Our evaluations using real-world datasets show that the BiLSTM-based VAE network achieves excellent detection performance without introducing significant running performance overhead to the container platform.
Xingshu Chen, Qixu Wang, Bangzhou Xin
ICASSP2
2022 Interlayer link prediction based on multiple network structural attributes
Rui Tang 0020, Xingshu Chen, Chuancheng Wei, Qindong Li, Wenxian Wang, Haizhou Wang 0001, Wei Wang 0070
Comput. Networks2
2022 Enhancing Trustworthiness of Internet of Vehicles in Space-Air-Ground-Integrated Networks: Attestation Approach
abstract
The integration of the space–air–ground-integrated network and the Internet of Vehicles (IoV) enables the IoV to achieve full network coverage and better network performance. However, the large scale of the network and the complex cooperation mechanism make the credibility of the nodes in the network and the service delivery questioned. In this article, the hardware trusted module is used as the root of trust to build the trust chain and the trusted running environment and provide protection and trusted state attestation for services. In order to overcome the large-scale and high-concurrency performance bottlenecks in the remote verification of trusted states in the IoV, a novel batch remote approach for trusted states is proposed. The simulation results show that the proposed approach can effectively attest to the trusted state of each network node and virtual service in the IoV and enhance the trustworthiness of the network.
Qixu Wang, Xingshu Chen, Xiang Li 0076, Dajiang Chen
IEEE Internet Things J.2
2022 Network structural perturbation against interlayer link prediction
Rui Tang 0020, Shuyu Jiang, Xingshu Chen, Wenxian Wang, Wei Wang 0070
Knowl. Based Syst.3
2022 ContainerGuard: A Real-Time Attack Detection System in Container-Based Big Data Platform
abstract
As a lightweight, flexible, and high-performance operating system virtualization, containers are used to speed up the big data platform. However, due to the imperfection of the resource isolation mechanism and the property of shared kernel, the meltdown and spectre attacks can lead to information leakage of kernel space and coresident containers. In this article, a noise-resilient and real-time detection system, named ContainerGuard, is proposed to detect meltdown and spectre attacks in the container-based big data platform. ContainerGuard uses a nonintrusive manner to collect lifecycle multivariate time-series performance event data of processes in containers and then uses ensemble of variational autoencoders as generative neural networks to learn the robust representations of normal patterns. Therefore, ContainerGuard meets the urgent need for information protection in the container-based big data platform. Our evaluations using real-world datasets show that ContainerGuard achieves excellent detection performance and only introduces about 4.5% of running performance overhead to the platform.
Qixu Wang, Xingshu Chen, Dajiang Chen, Xiaojie Fang, Mingyong Yin, Ning Zhang 0007
IEEE Trans. Ind. Informatics3
2022 Contrastive Learning Enhanced Intrusion Detection
abstract
With the continuous development of network technology, the diversity of network traffic constantly increased (intra-class diversity). Nevertheless, the boundary between malicious and benign actions became even ambiguous (inter-class similarity), causing lots of false detection and hindering the further optimization of the detection model. Focusing on challenges brought by intra-class diversity and inter-class similarity, we proposed a novel approach to enhance intrusion detection based on contrastive learning, which can make the right decision while disentangling samples from different classes. First, to bridge the gap when applying contrastive learning to intrusion detection data, we proposed a heuristic method to build contrastive tasks based on random masking of network packet sequences, which can reflect semantic relationships among samples. Then contrastive loss can be calculated to measure the inter-class and intra-class distances. Second, contrastive cross-entropy loss was proposed, which was a combination of contrastive loss and classification loss. Together with a dual branch deep structure, we can optimize the detection and sample distance requirements at the same time. Thirdly, experiments were conducted on diverse real-world and benchmark datasets using different model architectures under various parameter settings. Results on real-world dataset showed that our methods could stable experience a 5% increase in accuracy, and an 8% improvement in detection rate on those easily misdetected scenarios. To verify the method’s effectiveness on different traffic representations, we further conducted experiments on NSL-KDD and UNSW-NB15, which achieved a 7% accuracy improvement on NSL-KDD and a 6% accuracy improvement on UNSW-NB15. Extensive comparison with state of art intrusion detection models in recent five years showed that the proposed methods could effectively improve the accuracy of detection models.
Yawei Yue, Xingshu Chen, Zhenhui Han, Xuemei Zeng
IEEE Trans. Netw. Serv. Manag.2
2021 End-to-end attack on text-based CAPTCHAs based on cycle-consistent generative adversarial network
Xingshu Chen, Haizhou Wang 0001, Peiming Wang, Wenxian Wang
Neurocomputing2
2021 Improving adversarial robustness of deep neural networks by using semantic information
Xingshu Chen, Rui Tang 0020, Yawei Yue, Xuemei Zeng, Wei Wang 0070
Knowl. Based Syst.2
2021 Corrigendum to "BNRDT: When Data Transmission Meets Blockchain"
Hongjian Jin, Xingshu Chen, Xiao Lan, Qi Cao 0004
Secur. Commun. Networks2
2021 PurExt: Automated Extraction of the Purpose-Aware Rule from the Natural Language Privacy Policy in IoT
abstract
The extensive data collection performed by the Internet of Things (IoT) devices can put users at risk of data leakage. Consequently, IoT vendors are legally obliged to provide privacy policies to declare the scope and purpose of the data collection. However, complex and lengthy privacy policies are unfriendly to users, and the lack of a machine-readable format makes it difficult to check policy compliance automatically. To solve these problems, we first put forward a purpose-aware rule to formalize the purpose-driven data collection or use statement. Then, a novel approach to identify the rule from natural language privacy policies is proposed. To address the issue of diversity of purpose expression, we present the concepts of explicit and implicit purpose, which enable using the syntactic and semantic analyses to extract purposes in different sentences. Finally, the domain adaption method is applied to the semantic role labeling (SRL) model to improve the efficiency of purpose extraction. The experiments that are conducted on the manually annotated dataset demonstrate that this approach can extract purpose-aware rules from the privacy policies with a high recall rate of 91%. The implicit purpose extraction of the adapted model significantly improves the F1-score by 11%.
Xingshu Chen, Yonggang Luo, Xiao Lan
Secur. Commun. Networks2
2021 User Identification Based on Integrating Multiple User Information across Online Social Networks
abstract
User identification can help us build more comprehensive user information. It has been attracting much attention from academia. Most of the existing works are profile-based user identification and relationship-based user identification. Due to user privacy settings and social network restrictions on user data crawl, user data may be missing or incomplete in real social networks. User data include profiles, user-generated contents (UGCs), and relationships. The features extracted in previous research may be sparse. In order to reduce the impact of the above problems on user identification, we propose a multiple user information user identification framework (MUIUI). Firstly, we develop multiprocess crawlers to obtain the user data from two popular social networks, Twitter and Facebook. Secondly, we use named entity recognition and entity linking to obtain and integrate locations and organizations from profiles and UGCs. We also extract URLs from profiles and UGCs. We apply the locations jointly with the relationships and develop several algorithms to measure the similarity of the display name, all locations, all organizations, location in profile, all URLs, following organizations, and user ID, respectively. Afterward, we propose a fusion classifier machine learning-based user identification method. The results show that the F1 score of MUIUI reaches 86.46% on the dataset. It proves that MUIUI can reduce the impact of user data that are missing or incomplete.
Wenjing Zeng, Rui Tang 0020, Haizhou Wang 0001, Xingshu Chen, Wenxian Wang
Secur. Commun. Networks4
2020 An efficient scheme for SDN state consistency verification in cloud computing environment
abstract
Summary Software‐defined networking (SDN) decouples the control and data planes to simplify network management and function deployment. SDN provides a solution for managing large‐scale virtual networks in the cloud environment. However, in the process of SDN network update, various attacks can lead to network state inconsistency. In this paper, a comprehensive and efficient verification scheme is proposed to defend the security threats and guarantee the network state consistency in the cloud environment. The scheme verifies the consistency of network update from two stages of network update request and response. Firstly, the flow path model and the security space are abstracted to quickly verify whether the network request is allowed. Then, a novel forwarding path probing and verification method is designed to validate the actual forwarding path and locate the abnormal path in real time. With the two‐stage verification, the scheme can prevent the spread of illegal flow rules and ensure the correct delivery and execution of flow rules. Finally, we carry out a series of experiments in OpenStack. The results show that the proposed scheme can detect security threats and label the abnormal forwarding path in real time to ensure the network state consistency, while introducing negligible performance overhead.
Xingshu Chen, Long Ge
Concurr. Comput. Pract. Exp.2
2020 BTCAS: A Blockchain-Based Thoroughly Cross-Domain Authentication Scheme
Xingshu Chen, Xiao Lan, Hongjian Jin, Qi Cao 0004
J. Inf. Secur. Appl.2
2020 Interlayer link prediction in multiplex social networks: An iterative degree penalty algorithm
Rui Tang 0020, Shuyu Jiang, Xingshu Chen, Haizhou Wang 0001, Wenxian Wang, Wei Wang 0070
Knowl. Based Syst.3
2020 BNRDT: When Data Transmission Meets Blockchain
abstract
Data transmission exists in almost all the Internet-based applications, while few of them consider the property of nonrepudiation as part of data security. If a data transmission scheme is performed without the endorsement of a trusted third party (TTP) or a central server, it is easy to raise disputes while transmitting valuable data, especially digital goods, because a dishonest participant can deny the fact of particular data transmission instance. The above problem can be solved by signing and encrypting. However, digital signature schemes usually assume public key infrastructure (PKI), increasing the burden on certificate management and are not suitable for distributed networks without TTP such as blockchain. To solve the above problems, we propose two new schemes for nonrepudiation data transmission based on blockchain (we call it BNRDT): one for short message transmission and the other for large file transmission. In BNRDT schemes, nonrepudiation evidence of data transmission is generated and stored on the blockchain to satisfy both the properties of nonrepudiation (including nonrepudiation of origin and nonrepudiation of receipt) and data confidentiality. We implement and test the schemes on Hyperledger Fabric. The experimental results show that the proposed schemes can provide appealing performance.
Hongjian Jin, Xingshu Chen, Xiao Lan, Qi Cao 0004
Secur. Commun. Networks2
2020 An Android Malware Detection Model Based on DT-SVM
abstract
In order to improve the accuracy and efficiency of Android malware detection, an Android malware detection model based on decision tree (DT) with support vector machine (SVM) algorithm (DT-SVM) is proposed. Firstly, the original opcode, Dalvik opcode, is extracted by reversing Android software, and the eigenvector of the sample is generated by using the n-gram model. Then, a decision tree is generated via training the sample and updating decision nodes as SVM nodes from the bottom up according to the evaluation result of the test set in the decision path. The model effectively combines DT with SVM. Under the premise of maintaining a high-accuracy decision path, SVM is used to effectively reduce the overfitting problem in DT and thus improve the generalization ability, and maintain the superiority of SVM for the small sample training set. Finally, to test our approach, several simulation experiments are carried out, and the results demonstrate that the improved algorithm has better accuracy and higher speed as compared with other malware detection approaches.
Xingshu Chen, Yonggang Luo
Secur. Commun. Networks2
2020 Extension of Research on Security as a Service for VMs in IaaS Platform
abstract
To satisfy security concerns including infrastructure as a service (IaaS) security framework, security service access, network anomaly detection, and virtual machine (VM) monitoring, a layered security framework is built which composes of a physical layer, a virtualization layer, and a security management layer. Then, two security service access methods are realized for various security tools from the perspective of whether security tools generate communication traffic. One without generating traffic employs the VM traffic redirection technology and the other leveraged the mechanism of multitasking process access. Moreover, a stacked LSTM-based network anomaly detection agentless method is proposed, which has advantages of a higher ratio of precision and recall. Finally, a Hypervisor-based agentless monitoring method for VMs based on dynamic code injection is proposed, which has benefits of high security of the external monitoring method and good context analysis of the internal monitoring mechanism. The experimental results demonstrate the effectiveness of the proposed protection framework and the corresponding security mechanisms, respectively.
Xueyuan Yin, Xingshu Chen
Secur. Commun. Networks2
2020 Deep Learning Hierarchical Representation From Heterogeneous Flow-Level Communication Data
abstract
The success of a detection model depends heavily on feature engineering. Deep learning has been successfully applied in numerous research fields as a universal representation learning method. However, the heterogeneity of flow-level communication data obstructs the application of deep learning to communication representation learning, and research on this problem is still lacking. To cope with this problem, we propose a heterogeneous communication data-encoding approach to extract fixed-size encoding data to apply deep learning to heterogeneous communication data by preserving the spatiotemporal characteristics of the data. Then, we propose a feature extractor based on deep learning to automatically learn hierarchical and robust communication representations without expert knowledge. We show that the proposed approach can replicate and optimize the key steps of feature engineering well and learn hierarchical representations directly from heterogeneous communication data. Moreover, compared with features extracted with principal component analysis (PCA), manifold learning and manually crafted methods, the features extracted by deep learning are more robust and are characterized by their better adaptability to various classifiers and datasets. To the best of our knowledge, the initial work here is the first to apply deep learning techniques to heterogeneous flow-level data; consequently, the heterogeneous communication data processing method can provide technical means for the application of deep learning in other communication-related research fields.
Guo-lin Shao, Xingshu Chen, Xuemei Zeng
IEEE Trans. Inf. Forensics Secur.2
2019 Detecting Proxy User Based on Communication Behavior Portrait
abstract
Abstract Proxies can help users to bypass the network filtering system, leaving the network open to banned content, and can also enable users to anonymize themselves for terminal security protection. Proxies are widely used in the current network environment. However, certain spy proxies record user information for privacy theft. In addition, attackers can use such technologies to anonymize malicious behaviors and hide identities. Such behaviors have posed serious challenges to the internal defense and security threat assessment of an organization; however, the anonymity of the proxy makes it consistent with normal network communication, and general network traffic identification methods are not able to detect it. To accurately and effectively discover proxy users in the organization based on s, a proxy user detection method based on communication behavior portrait offers the following: (1) analysis of the communication behavior from the perspective of the portrait. Based on not abandoning the effective information of the traffic itself, the label system is established by introducing exogenous data to identify the difference between proxy communication and normal communication. (2) Construction of the portrait feature set of proxy user detection based on the traffic file and external data by studying the differences between the attribute sets of communication behavior labels for proxy users and non-proxy users. (3) Design and implementation a data-driven machine learning method to supply guidance for automatic recognition of such behavior. The experimental results show that, compared with state-of-the-art methods, the detection accuracy for the proxy user exceeds 95%, and that of real network traffic environment exceeds 85%. These results indicate that the detection method proposed in this paper can accurately distinguish proxy communication and normal communication and thus achieves precise proxy user detection.
Zhenhui Han, Xingshu Chen, Xuemei Zeng, Mingyong Yin
Comput. J.2
2019 Dynamics on Hybrid Complex Network: Botnet Modeling and Analysis of Medical IoT
abstract
With the rapid development of Internet of things technology, the application of intelligent devices in the medical industry has become ubiquitous. Connected devices have revolutionized clinicians and patient care but also made modern hospitals vulnerable to cyber attacks. Among the security risks, botnets are of particular concern, which can be used to control thousands of devices for remote data theft and equipment destruction. In this paper, we propose a non-Markovian spread dynamics model to understand the effects of botnet propagation, which can characterize the hybrid contagion situation in reality. Based on the Susceptible-Adopted-Recovered model, we introduce nonredundant memory spread mechanism for global propagation, as a tuner to adjust spreading rate difference. For describing the proposed model, we extend a heterogeneous edge-based compartmental theory. Through extensive numerical simulations, we reveal that the growth pattern of the final adoption size versus the information transmission probability is discontinuous and how the final adoption size is affected by hybrid ratio α, global scope control factor ϵ, accumulated received information threshold T, and other parameters on ER network. Furthermore, we give the theory and simulation result on BA network and also compare the two hybrid methods—single infection in one time slice and double infections in one time slice—to evaluate the influence on final adoption size. We found in SIOT hybrid contagion scenario the final adoption size shows the phenomenon of a decline followed by an increase versus different hybrid ratio, and it is both verified in theory and numerical simulation. Through validation by thousands of experiments, our developed theory agrees well with the numerical simulations.
Mingyong Yin, Xingshu Chen, Qixu Wang, Wei Wang 0070
Secur. Commun. Networks2
2018 Content pollution propagation in the overlay network of peer-to-peer live streaming systems: modelling and analysis
abstract
In the past few years, peer‐to‐peer (P2P) live streaming systems have gained great commercial success and have become a popular way to deliver multimedia content over the Internet, which received more and more attentions from both industry and academia globally. However, the dramatic rise in popularity makes these systems more likely to be vulnerable targets. In this study, mesh‐pull infrastructure architecture and pollution attack principle for P2P live streaming systems were presented firstly, and then the various user behaviours under the pollution attack were analysed. Subsequently, the authors proposed an analytical modelling framework of content pollution attack for P2P live streaming systems. Different from the existing content pollution propagation models, it considers the impact of user behaviours in the attack. Furthermore, to ensure the availability and accuracy of the model, the real‐world experimental attack data for a popular commercial system was used to verify it. The results showed that the model is a feasible and efficient tool to analyse and predict content pollution propagation in real‐world P2P live streaming systems. The authors' work can provide an in‐depth understanding of the content pollution propagation in P2P live streaming systems, and evaluation of restraining illegal content distribution for copyright holders and government.
Haizhou Wang 0001, Xingshu Chen, Wenxian Wang, Mei Ya Chan
IET Commun.2
2018 SCCAF: A Secure and Compliant Continuous Assessment Framework in Cloud-Based IoT Context
abstract
The Internet of Things (IoT) offers a wide variety of benefits to our daily lives in many ways, ranging from smart wearable devices to industrial systems. However, it also brings well‐known security and compliance concerns, especially in the physical layer. In addition, due to numerous IoT architectures which have been developed and deployed based on the cloud, the security and compliance of IoT depend on the cloud thoroughly. In this paper, a secure and compliant continuous assessment framework (SCCAF) is proposed to evaluate the security and compliance levels of cloud services in life‐cycle. The SCCAF facilitates cloud service to customers to select an optimal cloud service provider (CSP) which satisfies their desired security requirements. Moreover, it also enables cloud service customers to evaluate the compliance of the selected CSP in the process of using cloud services. To evaluate the performance and availability of SCCAF, we carry out a series of experiments with case study and real‐world scenario datasets. Experimental results show that SCCAF can assess the security and compliance of CSPs efficiently and effectively.
Xiang Li 0076, Qixu Wang, Xingshu Chen
Wirel. Commun. Mob. Comput.5
2017 Research and implementation of a high performance parallel computing digital down converter on graphics processing unit
abstract
Summary Digital down converter (DDC) is a time‐intensive and data‐intensive computing task and considered as the key technology in software defined radio. This paper proposes a high‐performance implementation of DDC on a graphics processing unit (GPU) using CUDA, which is composed of a numerically controlled oscillator stage, a cascaded integrator‐comb (CIC) decimation filter stage, and a finite impulse response (FIR) filter stage. The GPU implementation and optimizing of all the stages are studied in detail. Additionally, for handling a long‐duration signal, the signal data sequence is truncated into segments; the overlap‐save and overlap‐add mechanisms were applied in CIC stage and FIR stage, respectively. Finally, experiments were conducted to evaluate the performance of GPU‐based DDC with respect to a sequential version CPU implementation and an OpenMP implementation (16 threads). Experimental results demonstrate that the DDC achieves significant improvements on the GPU; the maximum speed ups in numerically controlled oscillator stage, CIC stage, and FIR stage can achieve more than 1242, 527, and 179 times, including data‐transfer, kernel execution, and other processing operations; the overall speed up of DDC can achieve more than 180. In the meantime, the speed ups of GPU implementation are far above the OpenMP implementation (about 2.5‐6.4 times).
Guo-lin Shao, Xingshu Chen
Concurr. Comput. Pract. Exp.2
2016 A fuzzy detection approach toward different speed port scan attacks based on Dempster-Shafer evidence theory
abstract
Abstract Port scan detection is one of the important topics in network security and has received lots of attention by researchers; however a slow port scan attack can deceive most of the existing IDS. Besides, it is unreasonable in typical detection to decide whether it is a probe based on the precise threshold especially when the feature values are around the threshold without taking the uncertainty into consideration. To address these problems, a novel approach was proposed by collecting traffic statistics information called access port set (APS) for each IP address in time windows; several traffic features are extracted from APS which are considered as multiple evidences to indicate a probe. For each evidence, three probabilities are concerned to evaluate the likelihood of the probe occurring which include the probabilities of support, nonsupport and uncertainty. The comprehensive evidence can be obtained from the combination of multiple evidences to evaluate the probe threaten. Several experiments were performed to evaluate the approach with DARPA/MIT datasets and our own generated attack datasets; the experimental results show the feasibility of our approach in terms of detection accuracy and effectiveness. The mechanism can be applied not only in port scan detection but also other precise threshold based situations such as traffic abnormal analysis and intrusion detection. Copyright © 2016 John Wiley & Sons, Ltd.
Guo-lin Shao, Xingshu Chen, Xueyuan Yin, Xiaoming Ye
Secur. Commun. Networks2
2013 Accelerated k-nearest neighbors algorithm based on principal component analysis for text categorization
abstract
Text categorization is a significant technique to manage the surging text data on the Internet. The k -nearest neighbors (kNN) algorithm is an effective, but not efficient, classification model for text categorization. In this paper, we propose an effective strategy to accelerate the standard kNN, based on a simple principle: usually, near points in space are also near when they are projected into a direction, which means that distant points in the projection direction are also distant in the original space. Using the proposed strategy, most of the irrelevant points can be removed when searching for the k -nearest neighbors of a query point, which greatly decreases the computation cost. Experimental results show that the proposed strategy greatly improves the time performance of the standard kNN, with little degradation in accuracy. Specifically, it is superior in applications that have large and high-dimensional datasets.
Xingshu Chen
J. Zhejiang Univ. Sci. C2
2008 Constrained k-closest pairs query processing based on growing window in crime databases
abstract
Spatial analysis in crime databases has recently been an active research topic. To solve the problem of finding the closest pairs of objects within a given spatial region, as required in crime geo-data applications, this paper proposes an efficient constrained k-closest pairs query processing algorithm based on growing window. It expands the window gradually instead of searching the whole workspace for multiple types of spatial objects. It employs a density-based range estimation approach to calculate the square query range and an optimized R-tree to store the index entities. In addition, a distance threshold T for the closest pair of objects is introduced to prune tree nodes. Experiments evaluate the effect of three important factors, i.e., the portion of overlapping between the workspaces of two data sets, the value of k, and the size of buffer. The results show that the new algorithm outperforms the heap-based approach.
Shaojie Qiao, Changjie Tang, Huidong Jin 0001, Shucheng Dai, Xingshu Chen
ISI5