Hui Yin 0001

dblp:47/3229-1 · DBLP profile ↗
← Back
32ranked-venue papers
11as first author
16since 2021 · last 2026
0000-0001-8960-887XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 12 · 6 first-author · 5 since 2021Computer networks · 9 · 2 first-author · 6 since 2021Security and privacy · 7 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Breaking the Accuracy-Latency Trade-Off in Sketch Compression for Network Measurement
Tao Zhang 0019, Siyuan Fan, Yunsheng Liu, Linfei Dong, Haozhi Tang, Hui Yin 0001, Fangmin Li
IWQoS10
2026 Switch-Transparent Load Balancing for RDMA Data Centers: A Host-Only Approach
Tao Zhang 0019, Haozhi Tang, Linfei Dong, Siyuan Fan, Hui Yin 0001, Fangmin Li
IWQoS9
2026 Match on My Own: Fine-Grained Bilateral Access Control With Self-Constrained Matching for Online Social Networks
Letian Sha, Hui Yin 0001, Zheng Qin 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Mitigating Hash Polarization with Flow-Level Load Balancing in Leaf-Spine Data Center Network
Siyuan Fan, Tao Zhang 0019, Linfei Dong, Xidao Luan, Hui Yin 0001
ICA3PP (4)7
2025 SMAR: Short-Flow Multi-path Adaptive Routing for Heterogeneous RDMA Workloads
Tao Zhang 0019, Xidao Luan, Hui Yin 0001, Jyoti Sahni, Winston Khoon Guan Seah
ICA3PP (8)6
2025 Privacy-Preservation Enhanced and Efficient Attribute-Based Access Control for Smart Health in Cloud-Assisted Internet of Things
abstract
The deep integration of Internet of Things (IoT) and cloud computing promotes a wide deployment of body area networks (BANs) for smart health services. The data security raises new challenges when patients’ health records (HRs) are uploaded into the cloud server by BAN. The attribute-based encryption (ABE) primitive is a potential option to ensure HRs security, which provides the data confidentiality guarantee and fine-grained access control simultaneously via cryptographic means. However, most ABE schemes are unsuitable to be deployed in smart health application as access policies associated with encrypted HRs reveal patient’s privacies. Though the recently proposed ABE with partially hidden access policy based on composite order can alleviate the privacy leakage by only disclosing the attribute names and concealing the practical attribute values, the exposed attribute names still leak individual privacies. In this article, we put forward a privacy-enhanced and efficient ABE construction with fully hidden access policy over prime order group based on the prominent ABE construction due to Bethencourt et al.. Our scheme hides the sensitive attributes in the access structure by several nontrivial designs without compromising the correctness and security. Moreover, our scheme’s performance is far superior to the attribute partially hidden schemes. Extensive experiments demonstrate the conclusion.
Hui Yin 0001, Lu Ou, Zheng Qin 0001, Keqin Li 0001
IEEE Internet Things J.1
2024 Leveraging Packet Cloning to Achieve Fast Flow-Transmission for Data Center Load Balancing
abstract
Modern data center network often possesses multiple end-to-end parallel paths, which undertake the crucial task of transmitting vast heterogeneous data traffic generated by a wide variety of applications. To fully utilize the offered super high bisection network bandwidth thus benefiting application performance, many data center load balancing schemes are proposed to improve path utilization for avoiding network congestion hot-spot. However, these schemes are naturally agnostic to data center traffic pattern and the diverse requirements on flow-transmission, leading to the sub-optimal network transmission performance. To address this issue, this paper presents a new data center load balancing scheme, called PCLB, which selectively generates Clone Packets by considering both flow-transmission phases and path states, thereby helping different types of flows choose more appropriate paths for speeding up their data transmission. Experimental results of numerous NS2 simulations show that PCLB significantly reduces the average and tail flow completion time for delay-sensitive flows, while the performance of throughput-oriented flows can be always maintained at high level.
Haotian Jing, Tao Zhang 0019, Shaojun Zou, Xidao Luan, Hui Yin 0001, Fangmin Li
ISPA7
2024 Toward Fine-Grained and Forward-Secure Access Control in Cloud-Assisted IoT
abstract
With an increasing amount of data produced by pervasive and ubiquitous smart devices, many Internet of Things (IoT) applications adopt the cloud platform to store and process data. To protect data security and privacy, attribute-based encryption (ABE) has been widely used in cloud-assisted IoT systems. However, most ABE schemes usually require a central authority to distribute decryption keys for all users, which may raise security and efficiency concerns; in addition, the exposure of decryption keys would severely damage the data privacy. In this article, we introduce a novel notion of decentralized attribute-based puncturable encryption (DABPE). DABPE allows data owner to generate public and secret keys by himself, without relying on any central authority. When outsourcing data to the cloud, the data owner can encrypt data with an access policy; moreover, the data owner could issue particular keys for different data users and only those users whose keys satisfy the access policy can access the data. To achieve a flexible forward security, the data owner and data user can update their keys with some tags such that the data specified by the tags would not be revealed even if the keys are disclosed. We design a concrete DABPE scheme and prove its security in the standard model, and also conduct extensive experiments to show the efficiency of the proposed scheme.
Hui Yin 0001, Zheng Qin 0001, Lu Ou, Fangmin Li, Ningchao Ge
IEEE Internet Things J.2
2023 An Attribute-Based Searchable Encryption Scheme for Cloud-Assisted IIoT
abstract
The searchable encryption (SE) is a particular case of structured encryption, which has been intensively researched in the secure cloud storage system. By constructing a structured secure index, such as encrypted multimaps (EMMs), encrypted inverted index (EII), etc., SE can achieve efficient keyword search over the encrypted data set. However, existing SE constructions do not take search permissions into consideration, resulting in the lack of a mechanism of the data access control, which may not be suitable for Industrial Internet of Things (IIoT) applications, since an integrated industrial system contains all kinds of data with rigorous access permissions. In this article, we construct an attribute-based SE (ABSE) construction for a cloud-assisted IIoT application scenario. By designing the novel access policy-based structured secure index and the attribute-based search token, our construction achieves fine-grained keyword search privilege control over encrypted IIoT data as well as the same search complexity as the traditional SE. To the best of our knowledge, this is the first ABSE construction. We provide the correctness and security proofs for our construction. Experimental evaluation results in a real-world data set show the correctness and the practical search efficiency of the proposed ABSE.
Hui Yin 0001, Wei Zhang 0074, Zheng Qin 0001, Keqin Li 0001
IEEE Internet Things J.1
2023 An Attribute-Based Keyword Search Scheme for Multiple Data Owners in Cloud-Assisted Industrial Internet of Things
abstract
The cloud-assisted industrial Internet of Things (IIoT) architecture can sustain highly available computation and massive storage services for modern industrial systems. When data owners store IIoT data to remote cloud platforms, the data security will face tough challenges. Cryptographic technologies endow an ability to guarantee data confidentiality. However, traditional encryption techniques make data access control and data searching malfunctioning. Recently emerging attribute-based keyword search (ABKS) primitive achieves fine-grained access control and effective data searching over ciphertexts. However, existing ABKS schemes only consider single data owner scenarios and may be an inappropriate choice for IIoT applications, where there exists multiple data owners for an integrated industrial system. Directly extending state-of-the-art single owner schemes to ones for multiowner environment will impose a complicated key management issue. We present an ABKS scheme for multiowners in the cloud-assisted IIoT architecture. By designing a novel master key generation and private key aggregation mechanism with desired communication overheads, our scheme eliminates the complex key management issue in the multiowner model. Formal security proof demonstrates that our scheme is secure against the cloud server. Experimental evaluations also demonstrate its correctness and practicality.
Hui Yin 0001, Yangfan Li 0001, Wei Zhang 0074, Zheng Qin 0001, Keqin Li 0001
IEEE Trans. Ind. Informatics1
2023 Practical and Dynamic Attribute-Based Keyword Search Supporting Numeric Comparisons Over Encrypted Cloud Data
abstract
The attribute-based keyword search (ABKS), which simultaneously achieves searching and fine-grained access control over encrypted data, is frequently applied in cloud computing environments characterized by data storage and sharing. Recently, inspired by attribute-based encryption (ABE) and searchable encryption (SE) primitives, several ABKS schemes have been presented. However, almost all existing ABKS schemes actually only provide an attribute-based keyword equality match function and do not have a structural index to support practical search efficiency and dynamic data updates in real-world applications. To the best of our knowledge, this study is the first to realize an attribute-based keyword search construction supporting numerical comparison expressions with the practical search efficient and dynamic data update capacity (ABKS-NICEST), based on our proposed attribute-based keyword secure search scheme supporting numerical comparison expressions (ABKS-NICE) and anexclusive OR-chain-based inverted index structure. To the best of our knowledge, ABKS-NICEST is the first attributed-based keyword search scheme with practical search efficiency and dynamic data update capacity. In addition, numerical values are an important and common attribute, so providing comparison expressions among numerical values can greatly enhance the expressivity of access policy. Therefore, we use the prefix membership verification technique to design a method to support any numeric comparison expression in a flexible and uniform manner. Through theoretical and experimental evaluations, we determine that ABKS-NICEST is the most efficient ABKS scheme.
Hui Yin 0001, Yangfan Li 0001, Wei Zhang 0074, Zheng Qin 0001, Keqin Li 0001
IEEE Trans. Serv. Comput.1
2022 An efficient and access policy-hiding keyword search and data sharing scheme in cloud-assisted IoT
Hui Yin 0001, Yangfan Li 0001, Fangmin Li, Wei Zhang 0074, Keqin Li 0001
J. Syst. Archit.1
2022 Policy-Based Broadcast Access Authorization for Flexible Data Sharing in Clouds
abstract
Cloud storage services allow data owners to outsource their potentially sensitive data (e.g., private genome data) to remote cloud servers in a ciphertext form. To enable data owners to further share the data encrypted in ciphertexts, many proxy re-encryption (PRE) schemes are proposed. However, most schemes only support single-recipient or coarse-grained re-encryption, which may limit the flexibility for data sharing. To address this issue, we propose a Policy-based Broadcast Access Authorization (PBAA) scheme by introducing the well-established identity-based broadcast encryption (IBBE) and key-policy attribute-based encryption into PRE. In our PBAA scheme, a data owner can apply IBBE to encrypt his data to a group of recipients. More importantly, the data owner can generate a delegation key with an access policy, and send this key to the cloud such that it can convert any initial ciphertext satisfying the access policy into a new ciphertext for a new group of recipients. With these features, cloud users can share their remote data in a secure and flexible way. Security analysis and performance evaluation show that the PBAA scheme is secure and efficient, respectively.
Jixin Zhang, Zheng Qin 0001, Qianhong Wu, Hui Yin 0001, Aniello Castiglione
IEEE Trans. Dependable Secur. Comput.5
2022 Revocable Attribute-Based Data Storage in Mobile Clouds
abstract
It is becoming fashionable for people to access data outsourced to clouds with mobile devices. To protect data security and privacy, attribute-based encryption (ABE) has been widely used in cloud storage systems. However, one of the main efficiency drawbacks of ABE is the high computation overheads at mobile devices during user revocation and file access. To address this issue, we propose a revocable attribute-based data storage (RADS) scheme equipped with several attracting features. First, our RADS scheme achieves a fine-grained access control mechanism, by which file owners do not need to explicitly specify authorized visitors to their outsourced files. Second, our RADS scheme allows mobile users to authorize the cloud service provider (CSP) to share costly computations in file access, without exposing the file content. Third, our RADS scheme offloads the operations of access-credential update and file re-encryption during revocation process to CSP, leaving all non-revoked users undisturbed. The revocation of RADS achieves a strong data protection, i.e., revoked users can access neither newly uploaded files nor old ones. The security and efficiency of the RADS scheme are validated via both analysis and experimental results.
Zheng Qin 0001, Qianhong Wu, Zhenyu Guan 0002, Hui Yin 0001
IEEE Trans. Serv. Comput.5
2021 Understanding and Modeling of WiFi Signal-Based Indoor Privacy Protection
abstract
Existing WiFi recognition schemes are capable of discovering patterns of indoor semantics, such as human activity, identity, indoor environment, and so on. We note that channel state information (CSI) presents an opportunity for hackers to learn indoor privacy, however, currently there is a lack of security research on CSI. In this article, we are the first to discuss and define the security problem of CSI signals, which is further extended to the problems of nontargeted protection and targeted protection. To solve them, we present two types of adversarial autoencoder networks (AAENs). Through replacing the original signals with the generated adversarial ones, the protected semantic features are modified, and the significant features of the other semantics required to be recognized are reserved. Intensive evaluations demonstrate that with the proposed AAENs, the recognition accuracy of the protected semantic can be significantly decreased, while still maintaining the other semantics to be identified correctly.
Wei Zhang 0074, Siwang Zhou, Dan Peng, Liang Yang 0001, Fangmin Li, Hui Yin 0001
IEEE Internet Things J.6
2021 Achieving Secure, Universal, and Fine-Grained Query Results Verification for Secure Search Scheme Over Encrypted Cloud Data
abstract
Secure search techniques over encrypted cloud data allow an authorized user to query data files of interest by submitting encrypted query keywords to the cloud server in a privacy-preserving manner. However, in practice, the returned query results may be incorrect or incomplete in the dishonest cloud environment. For example, the cloud server may intentionally omit some qualified results to save computational resources and communication overhead. Thus, a well-functioning secure query system should provide a query results verification mechanism that allows the data user to verify results. In this paper, we design a secure, easily integrated, and fine-grained query results verification mechanism, by which, given an encrypted query results set, the query user not only can verify the correctness of each data file in the set but also can further check how many or which qualified data files are not returned if the set is incomplete before decryption. The verification scheme is loose-coupling to concrete secure search techniques and can be very easily integrated into any secure query scheme. We achieve the goal by constructing secure verification object for encrypted cloud data. Furthermore, a short signature technique with extremely small storage cost is proposed to guarantee the authenticity of verification object and a verification object request technique is presented to allow the query user to securely obtain the desired verification object. Performance evaluation shows that the proposed schemes are practical and efficient.
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Keqin Li 0001
IEEE Trans. Cloud Comput.1
2020 A Flexible Privacy-Preserving Data Sharing Scheme in Cloud-Assisted IoT
abstract
Cloud-assisted Internet of Things (IoT) has become an increasingly popular technological trend as the performance of IoT applications can be greatly improved by delegating the cloud to manage massive IoT data. To protect the confidentiality of data outsourced from IoT devices to the cloud, cryptographic mechanisms are usually employed to encrypt the data in such a way that only the user designated by the data owner can decrypt the data. However, in the IoT multiuser environment, the encrypted data may also need to be shared with more users beyond the initially designated one. In this article, we propose a flexible privacy-preserving data sharing (FPDS) scheme in cloud-assisted IoT. With the FPDS scheme, an IoT user can encrypt data to a recipient by using identity-based encryption. More importantly, the IoT user can specify a fine-grained access policy to generate a delegation credential, and then send this credential to the cloud so that it can convert all the encrypted data satisfying the access policy into new ciphertexts that are readable to a new recipient. In this way, IoT users can share the data outsourced to the cloud in a flexible and privacy-preserving manner. Detailed security analysis shows that the FPDS scheme is secure against semitrusted cloud and malicious IoT users. Thorough theoretical and experimental analyses demonstrate the high efficiency of the scheme.
Zheng Qin 0001, Letian Sha, Hui Yin 0001
IEEE Internet Things J.4
2020 Privacy-preserving range query over multi-source electronic health records in public clouds
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Jixin Zhang, Hui Yin 0001, Keqin Li 0001
J. Parallel Distributed Comput.5
2020 A fine-grained authorized keyword secure search scheme with efficient search permission update in cloud computing
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Fangmin Li, Keqin Li 0001
J. Parallel Distributed Comput.1
2019 A feature-hybrid malware variants detection using CNN based opcode embedding and BPNN based API embedding
Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Kehuan Zhang
Comput. Secur.3
2019 Secure conjunctive multi-keyword ranked search over encrypted cloud data for multiple data owners
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Fangmin Li, Keqin Li 0001
Future Gener. Comput. Syst.1
2019 EPLC: An Efficient Privacy-Preserving Line-Loss Calculation Scheme for Residential Areas of Smart Grid
abstract
Recently, smart grid is considered as the next generation of power grid by introducing information and communication technologies. Line-loss is an important synthetic indicator which can directly reflect the energy efficiency and power management level of smart grid enterprises. In order to obtain all residential areas, line-loss requires obtaining electricity consumption of each user. However, data about users’ electricity consumption could reveal sensitive information; a sophisticated adversary can use some data analysis methods to deduce economic situation, habits, lifestyles, etc. In order to solve the problem, we propose an Efficient Privacy-preserving scheme for Line-loss Calculation, named EPLC. In our scheme, a data item is reading from one smart meter which implies the energy consumption in a time period of the user who owns it, and each user lives in a residential area. For each user, we encrypt user’s data based on Paillier cryptosystem by using two Horner parameters, by leveraging homomorphism, and each residential area gateway calculates relevant data about corresponding line-loss and control center hides the area-level polynomial into the final output for representing line-loss of all residential areas which are both in the form of ciphertext. Finally, we can still recover each residential area line-loss with possessing private keys and Horner parameters. Moreover, EPLC adopts the batch verification technique to lower authentication cost. Finally, our analysis indicates that EPLC is not only efficient but also can protect individual user’s electricity consumption privacy, and the flexibility and expansibility of EPLC are very suitable for smart grid.
Yinqiao Xiong, Peidong Zhu, Zhizhu Liu, Hui Yin 0001, Tiantian Deng
Secur. Commun. Networks4
2018 Sensitive system calls based packed malware variants detection using principal component initialized MultiLayers neural networks
abstract
Malware detection has become mission sensitive as its threats spread from computer systems to Internet of things systems. Modern malware variants are generally equipped with sophisticated packers, which allow them bypass modern machine learning based detection systems. To detect packed malware variants, unpacking techniques and dynamic malware analysis are the two choices. However, unpacking techniques cannot always be useful since there exist some packers such as private packers which are hard to unpack. Although dynamic malware analysis can obtain the running behaviours of executables, the unpacking behaviours of packers add noisy information to the real behaviours of executables, which has a bad affect on accuracy. To overcome these challenges, in this paper, we propose a new method which first extracts a series of system calls which is sensitive to malicious behaviours, then use principal component analysis to extract features of these sensitive system calls, and finally adopt multi-layers neural networks to classify the features of malware variants and legitimate ones. Theoretical analysis and real-life experimental results show that our packed malware variants detection technique is comparable with the the state-of-art methods in terms of accuracy. Our approach can achieve more than 95.6\% of detection accuracy and 0.048 s of classification time cost.
Jixin Zhang, Kehuan Zhang, Zheng Qin 0001, Hui Yin 0001, Qixin Wu
Cybersecur.4
2018 An Efficient and Privacy-Preserving Multiuser Cloud-Based LBS Query Scheme
abstract
Location-based services (LBSs) are increasingly popular in today’s society. People reveal their location information to LBS providers to obtain personalized services such as map directions, restaurant recommendations, and taxi reservations. Usually, LBS providers offer user privacy protection statement to assure users that their private location information would not be given away. However, many LBSs run on third-party cloud infrastructures. It is challenging to guarantee user location privacy against curious cloud operators while still permitting users to query their own location information data. In this paper, we propose an efficient privacy-preserving cloud-based LBS query scheme for the multiuser setting. We encrypt LBS data and LBS queries with a hybrid encryption mechanism, which can efficiently implement privacy-preserving search over encrypted LBS data and is very suitable for the multiuser setting with secure and effective user enrollment and user revocation. This paper contains security analysis and performance experiments to demonstrate the privacy-preserving properties and efficiency of our proposed scheme.
Lu Ou, Hui Yin 0001, Zheng Qin 0001, Sheng Xiao, Yupeng Hu 0004
Secur. Commun. Networks2
2017 MPOPE: Multi-provider Order-Preserving Encryption for Cloud Data Privacy
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Jixin Zhang, Hui Yin 0001, Keqin Li 0001
SecureComm5
2017 A query privacy-enhanced and secure search scheme over encrypted data in cloud computing
Hui Yin 0001, Zheng Qin 0001, Lu Ou, Keqin Li 0001
J. Comput. Syst. Sci.1
2016 Malware Variant Detection Using Opcode Image Recognition with Small Training Sets
abstract
Malware detection becomes mission critical as its threats spread from personal computers to industrial control systems. Modern malware generally equips with sophisticated anti-detection mechanisms such as code-morphism, which allows the malware to evolve into many variants and bypass traditional code feature based detection systems. In this paper, we propose to disassemble binary executables into opcodes sequences, and then convert the opcodes into images. By comparing the opcode images generated from binary targets with the opcode images generated from known malware sample codes, we can detect if the target binary executables contain variants of these known malwares. Theoretical analysis and real-life experiments results show that malware detection using visualized analysis is comparable in terms of accuracy, our approach can significantly improve 15\% of detection accuracy when the detection set contains a large quantity of binaries and the training set is small.
Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Sheng Xiao, Yupeng Hu 0004
ICCCN3
2016 Multi-User Location Correlation Protection with Differential Privacy
abstract
In the big data era, with the rapid development of location-based applications, GPS enabled devices and big data institutions, location correlation privacy raises more and more people's concern. Because adversaries may combine location correlations with their background knowledge to guess users' privacy, such correlation should be protected to preserve users' privacy. In order to deal with the location disclosure problem, location perturbation and generalization have been proposed. However, most proposed approaches depend on syntactic privacy models without rigorous privacy guarantee. Furthermore, many approaches only consider perturbing the locations of one user without considering multi-user location correlations, so these techniques cannot prevent various inference attacks well. Currently, differential privacy has been regarded as a standard for privacy protection, but there are new challenges for applying differential privacy in the location correlations protection. The privacy protection not only should meet the needs of users who request location-based services, but also should protect location correlation among multiple users. In this paper, we propose a systematic solution to protect location correlations privacy among multiple users with rigorous privacy guarantee. First of all, we propose a novel definition, private candidate sets which are obtained by hidden Markov models. Then, we quantify the location correlation between two users by using the similarity of hidden Markov models. Finally, we present a private trajectory releasing mechanism which can preserve the location correlations among users who move under hidden Markov models in a period of time. Experiments on real-world datasets also show that multi-user location correlation protection is efficient.
Lu Ou, Zheng Qin 0001, Yonghe Liu, Hui Yin 0001, Yupeng Hu 0004, Hao Chen 0051
ICPADS4
2016 Secure Conjunctive Multi-Keyword Search for Multiple Data Owners in Cloud Computing
abstract
Recently, secure search over encrypted cloud data has become a hot research spot and challenging task. Some secure search schemes have been proposed to try to meet this challenge. In this paper, we propose a conjunctive multi-keyword secure search scheme for multiple data owners. To guarantee data security and system flexibility in the multiple data owners environment, we design an ingenious secure query scheme that allows each data owner to adopt randomly chosen temporary keys to build secure indexes for different data files. An authorized data user does not need to know these temporary keys of constructing indexes and can instead randomly choose another temporary query keys to encrypt query keywords while the cloud can correctly perform keywords matching over encrypted data files. Extensive experiments demonstrate the correctness and practicality of the proposed scheme.
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Wenjie Li 0005, Lu Ou, Yupeng Hu 0004, Keqin Li 0001
ICPADS1
2016 IRMD: Malware Variant Detection Using Opcode Image Recognition
abstract
Malware detection becomes mission critical as its threats spread from personal computers to industrial control systems. Modern malware generally equips with sophisticated anti-detection mechanisms such as code-morphism, which allows the malware to evolve into many variants and bypass traditional code feature based detection systems. In this paper, we propose to disassemble binary executables into opcodes sequences, and then convert the opcodes into images. By using convolutional neural network to compare the opcode images generated from binary targets with the opcode images generated from known malware sample codes, we can detect if the target binary executables is malicious. Theoretical analysis and real-life experiments results show that malware detection using visualized analysis is comparable in terms of accuracy, our approach can significantly improve 15% of detection accuracy when the detection set contains a large quantity of binaries and the training set is much smaller.
Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Yupeng Hu 0004
ICPADS3
2016 An Approach to Rule Placement in Software-Defined Networks
abstract
Software-Defined Networks (SDN) is a trend of research in networks. Rule placement, a common operation for network administrators, has become more complicated due to the capacity limitation of devices in which the large number of rules are deployed. Prior works on rule placement mostly consider the influence on rule placement incurred by the rules in a single device. However, the position relationships between neighbor devices have influences on rule placement. Our basic idea is to classify the position relationships into two categories: the serial relationship and the parallel relationship, and we present a novel strategy for rule placement based on the two different position relationships. There are two challenges of implementing our strategies: to check whether a rule is contained by a rule set or not and to check whether a rule can be merged by other rules or not.To overcome the challenges, we propose a novel data structure called OPTree to represent the rules, which is convenient to check whether a rule is covered by other rules. We design the insertion algorithm and search algorithm for OPTree. Extensive experiments show that our approach can effectively reduce the number of rules while ensuring placed rules work. On the other hand, the experimental results also demonstrate that it is necessary to consider the position relationships between neighbor devices when placing rules.
Wenjie Li 0005, Zheng Qin 0001, Hui Yin 0001, Rui Li 0020, Lu Ou
MSWiM3
2015 A Secure and Fine-Grained Query Results Verification Scheme for Private Search Over Encrypted Cloud Data
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Yupeng Hu 0004, Huigui Rong
ICA3PP (3)1