Zhongqiang Chen

dblp:45/3140 · DBLP profile ↗
← Back
11ranked-venue papers
9as first author
0since 2021 · last 2012
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 5 · 5 first-authorSoftware engineering, systems software and programming languages · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorComputer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Software testing · 77% Program analysis · 23%
Databases, data mining, and information retrieval
1 paper
Transaction processing and concurrency control · 100%

Topics — the 2 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software testing › database testing
database application testing
0.012003
Testing Database Transaction Concurrency · ASE 2003
Program analysis
data flow analysis
0.012003
Testing Database Transaction Concurrency · ASE 2003

Methods — techniques the papers use, named apart from their topics

dataflow analysis · 0.0data flow analysis · 0.0
YearPublicationVenuePosition
2012 Malware characteristics and threats on the internet ecosystem
Zhongqiang Chen, Mema Roussopoulos, Zhanyan Liang, Zhongrong Chen, Alex Delis
J. Syst. Softw.1
2010 A Categorization Framework for Common Computer Vulnerabilities and Exposures
abstract
The dictionary of common vulnerabilities and exposures (CVEs) is a compilation of known security loopholes whose objective is to both facilitate the exchange of security-related information and expedite vulnerability analysis of computer systems. Its lack of categorization and generalization capability renders the dictionary ineffective when it comes to developing defense strategies for clustered vulnerabilities instead of individual exploits. To address this issue, we propose a CVE categorization framework termed CVE Classifier that transforms the dictionary into a classifier that not only categorizes CVEs with respect to diverse taxonomic features but can also evaluate general trends in the evolution of vulnerabilities. With the help of support vector machines, CVE Classifier builds learning models for taxonomic features based on training data automatically extracted from pertinent vulnerability databases including BID, X-Force and Secunia, and CVE entries containing telltale keywords unique to taxonomic features. We use word-stemming and stopword-removal techniques to reduce the dimensions of the feature space formed by CVEs and develop a data fusion and cleansing process to eliminate data inconsistencies to improve classification performance. The CVE classification produced by the proposed framework reveals that the majority of the Internet security loopholes are harbored by a small set of services. Moreover, it becomes evident that the widespread deployment of security devices provides many additional attack points as such devices demonstrate a great mount of vulnerabilities. Finally, the CVE Classifier points out that remotely exploitable security loopholes continue to dominate the CVEs landscape.
Zhongqiang Chen, Zhongrong Chen
Comput. J.1
2009 A Pragmatic Methodology for Testing Intrusion Prevention Systems
abstract
Intrusion prevention systems (IPSs) not only attempt to detect attacks but also block malicious traffic and pro-actively tear down pertinent network connections. To effectively thwart attacks, IPSs have to operate both in real-time and inline fashion. This dual mode renders the design/implementation and more importantly the testing of IPSs a challenge. In this paper, we propose an IPS testing framework termed IPS Evaluator which consists of a trace-driven inline simulator-engine, mechanisms for generating and manipulating test cases, and a comprehensive series of test procedures. The engine features attacker and victim interfaces which bind to the external and internal ports of an IPS-under-testing (IUT). Our engine employs a bi-directional injection policy to ensure that replayed packets are subject to security inspection by the IUT before they are forwarded. Furthermore, the send-and-receive mechanism of our engine allows for the correlation of engine-replayed and IUT-forwarded packets as well as the verification of IUT actions on detected attacks. Using dynamic addressing and routing techniques, our framework rewrites both source and destination addresses for every replayed packet on-the-fly. In this way, replayed packets conform to the specific features of the IUT. We propose algorithms to partition attacker/victim-emanated packets so that they are subjected to security inspections by the IUT and in addition, we offer packet manipulation operations to shape replayed traces. We discuss procedures that help verify the IUT's detection and prevention accuracy, attack coverage and behavior under diverse traffic patterns. Finally, we evaluate the strengths of our framework by mainly examining the open-source IPS Snort-Inline. IPS deficiencies revealed during testing help establish the effectiveness of our approach.
Zhongqiang Chen, Alex Delis, Peter Wei
Comput. J.1
2009 A Digest and Pattern Matching-Based Intrusion Detection Engine
abstract
Intrusion detection/prevention systems (IDSs/IPSs) heavily rely on signature databases and pattern matching (PM) techniques to identify network attacks. The engines of such systems often employ traditional PM algorithms to search for telltale patterns in network flows. The observations that real-world network traffic is largely legitimate and that telltales manifested by exploits rarely appear in network streams lead us to the proposal of Fingerprinter. This framework integrates fingerprinting and PM methods to rapidly distinguish well-behaved from malicious traffic. Fingerprinter produces concise digests or fingerprints for attack signatures during its programming phase. In its querying phase, the framework quickly identifies attack-free connections by transforming input traffic into its fingerprint space and matching its digest against those of attack signatures. If the legitimacy of a stream cannot be determined by fingerprints alone, our framework uses the Boyer–Moore algorithm to ascertain whether attack signatures appear in the stream. To reduce false matches, we resort to multiple fingerprinting techniques including Bloom–Filter and Rabin–Fingerprint. Experimentation with a prototype and a variety of traces has helped us establish that Fingerprinter significantly accelerates the attack detection process.
Zhongqiang Chen, Zhongrong Chen, Alex Delis
Comput. J.1
2009 Adaptive neighborhood selection in peer-to-peer networks based on content similarity and reputation
Ioannis Pogkas, Vassil Kriakov, Zhongqiang Chen, Alex Delis
Peer-to-Peer Netw. Appl.3
2008 Identification and Management of Sessions Generated by Instant Messaging and Peer-to-Peer Systems
abstract
Sessions generated by Instant Messaging and Peer-to-Peer systems (IM/P2Ps) not only consume considerable bandwidth and computing resources but also dramatically change the characteristics of data flows affecting both the operation and performance of networks. Most IM/P2Ps have known security loopholes and vulnerabilities making them an ideal platform for the dissemination of viruses, worms, and other malware. The lack of access control and weak authentication on shared resources further exacerbates the situation. Should IM/P2Ps be deployed in production environments, performance of conventional applications may significantly deteriorate and enterprise data may be contaminated. It is therefore imperative to identify, monitor and finally manage IM/P2P traffic. Unfortunately, this task cannot be easily attained as IM/P2Ps resort to advanced techniques to hide their traces including multiple channels to deliver services, port hopping, message encapsulation and encryption. In this paper, we propose an extensible framework that not only helps to identify and classify IM/P2P-generated sessions in real time but also assists in the manipulation of such traffic. Consisting of four modules namely, session manager, traffic assembler, IM/P2P dissector, and traffic arbitrator, our proposed framework uses multiple techniques to improve its traffic classification accuracy and performance. Through fine-tuned splay and interval trees that help organize IM/P2P sessions and packets in data streams, we accomplish stateful inspection, traffic re-assembly, data stream correlation, and application layer analysis that combined will boost the framework's identification precision. More importantly, we introduce IM/P2Ps "plug-and-play" protocol analyzers that inspect data streams according to their syntax and semantics; these analyzers render our framework easily extensible. Identified IM/P2P sessions can be shaped, blocked, or disconnected, and corresponding traffic can be stored for forensic analysis and threat evaluation. Experiments with our prototype show high IM/P2Ps detection accuracy rates under diverse settings and excellent overall performance in both controlled and real-world environments.
Zhongqiang Chen, Alex Delis, Peter Wei
Int. J. Cooperative Inf. Syst.1
2008 Catching Remote Administration Trojans (RATs)
abstract
Abstract A Remote Administration Trojan (RAT) allows an attacker to remotely control a computing system and typically consists of a server invisibly running and listening to specificTCP/UDPports on a victim machine as well as a client acting as the interface between the server and the attacker. The accuracy of host and/or network‐based methods often employed to identifyRATshighly depends on the quality of Trojan signatures derived from static patterns appearing inRATprograms and/or their communications. Attackers may also obfuscate such patterns by havingRATsuse dynamic ports, encrypted messages, and even changing Trojan banners. In this paper, we propose a comprehensive framework termedRAT Catcher, which reliably detects and ultimately blocksRATmalicious activities even when Trojans use multiple evasion techniques. Employing network‐based methods and functioning ininlinemode to inspect passing packets in real time, ourRAT Catchercollects and maintains status information for every connection and conducts session correlation to greatly improve detection accuracy. TheRAT Catcherre‐assembles packets in each data stream and dissects the resulting aggregation according to known Trojan communication protocols, further enhancing its traffic classification. By scanning not only protocol headers but also payloads,RAT Catcheris a truly application‐layer inspector that performs a range of corrective actions on identified traffic including alerting, packet dropping, and connection termination. We show the effectiveness and efficiency ofRAT Catcherwith experimentation in both laboratory and real‐world settings. Copyright © 2007 John Wiley & Sons, Ltd.
Zhongqiang Chen, Peter Wei, Alex Delis
Softw. Pract. Exp.1
2007 An Inline Detection and Prevention Framework for Distributed Denial of Service Attacks
abstract
By penetrating into a large number of machines and stealthily installing malicious pieces of code, a distributed denial of service (DDoS) attack constructs a hierarchical network and uses it to launch coordinated assaults. DDoS attacks often exhaust the network bandwidth, processing capacity and information resources of victims, thus, leading to unavailability of computing systems services. Various defense mechanisms for the detection, mitigation and/or prevention of DDoS attacks have been suggested including resource redundancy, traceback of attack origins and identification of programs with suspicious behavior. Contemporary DDoS attacks employ sophisticated techniques including formation of hierarchical networks, one-way communication channels, encrypted messages, dynamic ports allocation and source address spoofing to hide the attackers' identities; such techniques make both detection and tracing of DDoS activities a challenge and render traditional DDoS defense mechanisms ineffective. In this paper, we propose the DDoS Container, a comprehensive framework that uses network-based detection methods to overcome the above complex and evasive types of attacks; the framework operates in ‘inline’ mode to inspect and manipulate ongoing traffic in real-time. By keeping track of connections established by both potential DDoS attacks and legitimate applications, the suggested DDoS Container carries out stateful inspection on data streams and correlates events among sessions. The framework performs stream re-assembly and dissects the resulting aggregations against protocols followed by various known DDoS attacks facilitating their identification. The traffic pattern analysis and data correlation of the framework further enhance its detection accuracy on DDoS traffic camouflaged with encryption. Actions available on identified DDoS traffic range from simple alerting to message blocking and proactive session termination. Experimentation with the prototype of our DDoS Container shows its effectiveness in classifying DDoS traffic.
Zhongqiang Chen, Zhongrong Chen, Alex Delis
Comput. J.1
2004 Building Footprint Simplification Techniques and Their Effects on Radio Propagation Predictions
abstract
Building footprint simplification is of critical importance to radio propagation predictions in wireless communication systems as the prediction time is closely related to the number of both buildings and vertices involved. Intuitively, if the complexity of footprints (i.e. the number of vertices in the footprints) is reduced, predictions can be generated more quickly. However, such reductions often affect the accuracy of results as the simplification error constrains the efficiency that can be achieved. To achieve a good vertex reduction rate for the footprints involved and at the same time preserve the shapes of footprints in terms of their areas, orientations and centroids, we propose a number of efficient single-pass methods to simplify building footprints. To satisfy constraints on edges, areas and centroids of simplified footprints, multi-pass methods are suggested. Hybrid methods take advantage of complementary properties exhibited by different footprint simplification methods. We assess the baseline effectiveness of our proposed techniques, and carry out an extensive comparative evaluation with real geographic information system data from different municipalities. Through experimentation, we find that hybrid methods deliver the best performance in both vertex reduction rate and simplification error. We examine the effects that these footprint simplification methods have on the ray-tracing based radio propagation prediction systems in terms of processing time and prediction accuracy. Our experiments show that footprint simplification methods indeed reduce prediction time up to three-fold, and maintain prediction accuracy with high confidence as well. We also investigate the relationship between footprint simplification error and the prediction accuracy. We find that the prediction accuracy is sensitive to the distortion (i.e. change of shape) of building footprints. This helps us to better understand the trade-off between precision of the building database and the accuracy of predictions generated by ray-tracing based radio propagation prediction systems.
Zhongqiang Chen, Alex Delis, Henry L. Bertoni
Comput. J.1
2004 Radio-wave propagation prediction using ray-tracing techniques on a network of workstations (NOW)
Zhongqiang Chen, Alex Delis, Henry L. Bertoni
J. Parallel Distributed Comput.1
2003 Testing Database Transaction Concurrency
abstract
Database application programs are often designed to be executed concurrently by many users. By grouping related database queries into transactions, DBMS (database management system) can guarantee that each transaction satisfies the well-known ACID properties: atomicity, consistency, isolation, and durability. However, if a database application is decomposed into transactions in an incorrect manner, the application may fail when executed concurrently due to potential offline concurrency problems. This paper presents a dataflow analysis technique for identifying schedules of transaction execution aimed at revealing concurrency faults of this nature, along with techniques for controlling the DBMS or the application so that execution of transaction sequences follows generated schedules. The techniques have been integrated into AGENDA, a tool set for testing relational database application programs. Preliminary empirical evaluation is presented.
Yuetang Deng, Phyllis G. Frankl, Zhongqiang Chen
ASE3