VLDB 2026 Research / reviewers in the wild / expert
Hui Yin 0001
dblp:47/3229-1
· DBLP profile ↗
32ranked-venue papers
11as first author
16since 2021 · last 2026
0000-0001-8960-887XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 12 · 6 first-author · 5 since 2021Computer networks · 9 · 2 first-author · 6 since 2021Security and privacy · 7 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Breaking the Accuracy-Latency Trade-Off in Sketch Compression for Network Measurement
Tao Zhang 0019, Siyuan Fan, Yunsheng Liu, Linfei Dong, Haozhi Tang, Hui Yin 0001, Fangmin Li |
IWQoS | 10 |
| 2026 | Switch-Transparent Load Balancing for RDMA Data Centers: A Host-Only Approach
Tao Zhang 0019, Haozhi Tang, Linfei Dong, Siyuan Fan, Hui Yin 0001, Fangmin Li |
IWQoS | 9 |
| 2026 | Match on My Own: Fine-Grained Bilateral Access Control With Self-Constrained Matching for Online Social Networks
Letian Sha, Hui Yin 0001, Zheng Qin 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Mitigating Hash Polarization with Flow-Level Load Balancing in Leaf-Spine Data Center Network
Siyuan Fan, Tao Zhang 0019, Linfei Dong, Xidao Luan, Hui Yin 0001 |
ICA3PP (4) | 7 |
| 2025 | SMAR: Short-Flow Multi-path Adaptive Routing for Heterogeneous RDMA Workloads
Tao Zhang 0019, Xidao Luan, Hui Yin 0001, Jyoti Sahni, Winston Khoon Guan Seah |
ICA3PP (8) | 6 |
| 2025 | Privacy-Preservation Enhanced and Efficient Attribute-Based Access Control for Smart Health in Cloud-Assisted Internet of ThingsabstractThe deep integration of Internet of Things (IoT) and cloud computing promotes a wide deployment of body area networks (BANs) for smart health services. The data security raises new challenges when patients’ health records (HRs) are uploaded into the cloud server by BAN. The attribute-based encryption (ABE) primitive is a potential option to ensure HRs security, which provides the data confidentiality guarantee and fine-grained access control simultaneously via cryptographic means. However, most ABE schemes are unsuitable to be deployed in smart health application as access policies associated with encrypted HRs reveal patient’s privacies. Though the recently proposed ABE with partially hidden access policy based on composite order can alleviate the privacy leakage by only disclosing the attribute names and concealing the practical attribute values, the exposed attribute names still leak individual privacies. In this article, we put forward a privacy-enhanced and efficient ABE construction with fully hidden access policy over prime order group based on the prominent ABE construction due to Bethencourt et al.. Our scheme hides the sensitive attributes in the access structure by several nontrivial designs without compromising the correctness and security. Moreover, our scheme’s performance is far superior to the attribute partially hidden schemes. Extensive experiments demonstrate the conclusion. Hui Yin 0001, Lu Ou, Zheng Qin 0001, Keqin Li 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Leveraging Packet Cloning to Achieve Fast Flow-Transmission for Data Center Load BalancingabstractModern data center network often possesses multiple end-to-end parallel paths, which undertake the crucial task of transmitting vast heterogeneous data traffic generated by a wide variety of applications. To fully utilize the offered super high bisection network bandwidth thus benefiting application performance, many data center load balancing schemes are proposed to improve path utilization for avoiding network congestion hot-spot. However, these schemes are naturally agnostic to data center traffic pattern and the diverse requirements on flow-transmission, leading to the sub-optimal network transmission performance. To address this issue, this paper presents a new data center load balancing scheme, called PCLB, which selectively generates Clone Packets by considering both flow-transmission phases and path states, thereby helping different types of flows choose more appropriate paths for speeding up their data transmission. Experimental results of numerous NS2 simulations show that PCLB significantly reduces the average and tail flow completion time for delay-sensitive flows, while the performance of throughput-oriented flows can be always maintained at high level. Haotian Jing, Tao Zhang 0019, Shaojun Zou, Xidao Luan, Hui Yin 0001, Fangmin Li |
ISPA | 7 |
| 2024 | Toward Fine-Grained and Forward-Secure Access Control in Cloud-Assisted IoTabstractWith an increasing amount of data produced by pervasive and ubiquitous smart devices, many Internet of Things (IoT) applications adopt the cloud platform to store and process data. To protect data security and privacy, attribute-based encryption (ABE) has been widely used in cloud-assisted IoT systems. However, most ABE schemes usually require a central authority to distribute decryption keys for all users, which may raise security and efficiency concerns; in addition, the exposure of decryption keys would severely damage the data privacy. In this article, we introduce a novel notion of decentralized attribute-based puncturable encryption (DABPE). DABPE allows data owner to generate public and secret keys by himself, without relying on any central authority. When outsourcing data to the cloud, the data owner can encrypt data with an access policy; moreover, the data owner could issue particular keys for different data users and only those users whose keys satisfy the access policy can access the data. To achieve a flexible forward security, the data owner and data user can update their keys with some tags such that the data specified by the tags would not be revealed even if the keys are disclosed. We design a concrete DABPE scheme and prove its security in the standard model, and also conduct extensive experiments to show the efficiency of the proposed scheme. Hui Yin 0001, Zheng Qin 0001, Lu Ou, Fangmin Li, Ningchao Ge |
IEEE Internet Things J. | 2 |
| 2023 | An Attribute-Based Searchable Encryption Scheme for Cloud-Assisted IIoTabstractThe searchable encryption (SE) is a particular case of structured encryption, which has been intensively researched in the secure cloud storage system. By constructing a structured secure index, such as encrypted multimaps (EMMs), encrypted inverted index (EII), etc., SE can achieve efficient keyword search over the encrypted data set. However, existing SE constructions do not take search permissions into consideration, resulting in the lack of a mechanism of the data access control, which may not be suitable for Industrial Internet of Things (IIoT) applications, since an integrated industrial system contains all kinds of data with rigorous access permissions. In this article, we construct an attribute-based SE (ABSE) construction for a cloud-assisted IIoT application scenario. By designing the novel access policy-based structured secure index and the attribute-based search token, our construction achieves fine-grained keyword search privilege control over encrypted IIoT data as well as the same search complexity as the traditional SE. To the best of our knowledge, this is the first ABSE construction. We provide the correctness and security proofs for our construction. Experimental evaluation results in a real-world data set show the correctness and the practical search efficiency of the proposed ABSE. Hui Yin 0001, Wei Zhang 0074, Zheng Qin 0001, Keqin Li 0001 |
IEEE Internet Things J. | 1 |
| 2023 | An Attribute-Based Keyword Search Scheme for Multiple Data Owners in Cloud-Assisted Industrial Internet of ThingsabstractThe cloud-assisted industrial Internet of Things (IIoT) architecture can sustain highly available computation and massive storage services for modern industrial systems. When data owners store IIoT data to remote cloud platforms, the data security will face tough challenges. Cryptographic technologies endow an ability to guarantee data confidentiality. However, traditional encryption techniques make data access control and data searching malfunctioning. Recently emerging attribute-based keyword search (ABKS) primitive achieves fine-grained access control and effective data searching over ciphertexts. However, existing ABKS schemes only consider single data owner scenarios and may be an inappropriate choice for IIoT applications, where there exists multiple data owners for an integrated industrial system. Directly extending state-of-the-art single owner schemes to ones for multiowner environment will impose a complicated key management issue. We present an ABKS scheme for multiowners in the cloud-assisted IIoT architecture. By designing a novel master key generation and private key aggregation mechanism with desired communication overheads, our scheme eliminates the complex key management issue in the multiowner model. Formal security proof demonstrates that our scheme is secure against the cloud server. Experimental evaluations also demonstrate its correctness and practicality. Hui Yin 0001, Yangfan Li 0001, Wei Zhang 0074, Zheng Qin 0001, Keqin Li 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2023 | Practical and Dynamic Attribute-Based Keyword Search Supporting Numeric Comparisons Over Encrypted Cloud DataabstractThe attribute-based keyword search (ABKS), which simultaneously achieves searching and fine-grained access control over encrypted data, is frequently applied in cloud computing environments characterized by data storage and sharing. Recently, inspired by attribute-based encryption (ABE) and searchable encryption (SE) primitives, several ABKS schemes have been presented. However, almost all existing ABKS schemes actually only provide an attribute-based keyword equality match function and do not have a structural index to support practical search efficiency and dynamic data updates in real-world applications. To the best of our knowledge, this study is the first to realize an attribute-based keyword search construction supporting numerical comparison expressions with the practical search efficient and dynamic data update capacity (ABKS-NICEST), based on our proposed attribute-based keyword secure search scheme supporting numerical comparison expressions (ABKS-NICE) and anexclusive OR-chain-based inverted index structure. To the best of our knowledge, ABKS-NICEST is the first attributed-based keyword search scheme with practical search efficiency and dynamic data update capacity. In addition, numerical values are an important and common attribute, so providing comparison expressions among numerical values can greatly enhance the expressivity of access policy. Therefore, we use the prefix membership verification technique to design a method to support any numeric comparison expression in a flexible and uniform manner. Through theoretical and experimental evaluations, we determine that ABKS-NICEST is the most efficient ABKS scheme. Hui Yin 0001, Yangfan Li 0001, Wei Zhang 0074, Zheng Qin 0001, Keqin Li 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | An efficient and access policy-hiding keyword search and data sharing scheme in cloud-assisted IoT
Hui Yin 0001, Yangfan Li 0001, Fangmin Li, Wei Zhang 0074, Keqin Li 0001 |
J. Syst. Archit. | 1 |
| 2022 | Policy-Based Broadcast Access Authorization for Flexible Data Sharing in CloudsabstractCloud storage services allow data owners to outsource their potentially sensitive data (e.g., private genome data) to remote cloud servers in a ciphertext form. To enable data owners to further share the data encrypted in ciphertexts, many proxy re-encryption (PRE) schemes are proposed. However, most schemes only support single-recipient or coarse-grained re-encryption, which may limit the flexibility for data sharing. To address this issue, we propose a Policy-based Broadcast Access Authorization (PBAA) scheme by introducing the well-established identity-based broadcast encryption (IBBE) and key-policy attribute-based encryption into PRE. In our PBAA scheme, a data owner can apply IBBE to encrypt his data to a group of recipients. More importantly, the data owner can generate a delegation key with an access policy, and send this key to the cloud such that it can convert any initial ciphertext satisfying the access policy into a new ciphertext for a new group of recipients. With these features, cloud users can share their remote data in a secure and flexible way. Security analysis and performance evaluation show that the PBAA scheme is secure and efficient, respectively. Jixin Zhang, Zheng Qin 0001, Qianhong Wu, Hui Yin 0001, Aniello Castiglione |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Revocable Attribute-Based Data Storage in Mobile CloudsabstractIt is becoming fashionable for people to access data outsourced to clouds with mobile devices. To protect data security and privacy, attribute-based encryption (ABE) has been widely used in cloud storage systems. However, one of the main efficiency drawbacks of ABE is the high computation overheads at mobile devices during user revocation and file access. To address this issue, we propose a revocable attribute-based data storage (RADS) scheme equipped with several attracting features. First, our RADS scheme achieves a fine-grained access control mechanism, by which file owners do not need to explicitly specify authorized visitors to their outsourced files. Second, our RADS scheme allows mobile users to authorize the cloud service provider (CSP) to share costly computations in file access, without exposing the file content. Third, our RADS scheme offloads the operations of access-credential update and file re-encryption during revocation process to CSP, leaving all non-revoked users undisturbed. The revocation of RADS achieves a strong data protection, i.e., revoked users can access neither newly uploaded files nor old ones. The security and efficiency of the RADS scheme are validated via both analysis and experimental results. Zheng Qin 0001, Qianhong Wu, Zhenyu Guan 0002, Hui Yin 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2021 | Understanding and Modeling of WiFi Signal-Based Indoor Privacy ProtectionabstractExisting WiFi recognition schemes are capable of discovering patterns of indoor semantics, such as human activity, identity, indoor environment, and so on. We note that channel state information (CSI) presents an opportunity for hackers to learn indoor privacy, however, currently there is a lack of security research on CSI. In this article, we are the first to discuss and define the security problem of CSI signals, which is further extended to the problems of nontargeted protection and targeted protection. To solve them, we present two types of adversarial autoencoder networks (AAENs). Through replacing the original signals with the generated adversarial ones, the protected semantic features are modified, and the significant features of the other semantics required to be recognized are reserved. Intensive evaluations demonstrate that with the proposed AAENs, the recognition accuracy of the protected semantic can be significantly decreased, while still maintaining the other semantics to be identified correctly. Wei Zhang 0074, Siwang Zhou, Dan Peng, Liang Yang 0001, Fangmin Li, Hui Yin 0001 |
IEEE Internet Things J. | 6 |
| 2021 | Achieving Secure, Universal, and Fine-Grained Query Results Verification for Secure Search Scheme Over Encrypted Cloud DataabstractSecure search techniques over encrypted cloud data allow an authorized user to query data files of interest by submitting encrypted query keywords to the cloud server in a privacy-preserving manner. However, in practice, the returned query results may be incorrect or incomplete in the dishonest cloud environment. For example, the cloud server may intentionally omit some qualified results to save computational resources and communication overhead. Thus, a well-functioning secure query system should provide a query results verification mechanism that allows the data user to verify results. In this paper, we design a secure, easily integrated, and fine-grained query results verification mechanism, by which, given an encrypted query results set, the query user not only can verify the correctness of each data file in the set but also can further check how many or which qualified data files are not returned if the set is incomplete before decryption. The verification scheme is loose-coupling to concrete secure search techniques and can be very easily integrated into any secure query scheme. We achieve the goal by constructing secure verification object for encrypted cloud data. Furthermore, a short signature technique with extremely small storage cost is proposed to guarantee the authenticity of verification object and a verification object request technique is presented to allow the query user to securely obtain the desired verification object. Performance evaluation shows that the proposed schemes are practical and efficient. Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Keqin Li 0001 |
IEEE Trans. Cloud Comput. | 1 |
| 2020 | A Flexible Privacy-Preserving Data Sharing Scheme in Cloud-Assisted IoTabstractCloud-assisted Internet of Things (IoT) has become an increasingly popular technological trend as the performance of IoT applications can be greatly improved by delegating the cloud to manage massive IoT data. To protect the confidentiality of data outsourced from IoT devices to the cloud, cryptographic mechanisms are usually employed to encrypt the data in such a way that only the user designated by the data owner can decrypt the data. However, in the IoT multiuser environment, the encrypted data may also need to be shared with more users beyond the initially designated one. In this article, we propose a flexible privacy-preserving data sharing (FPDS) scheme in cloud-assisted IoT. With the FPDS scheme, an IoT user can encrypt data to a recipient by using identity-based encryption. More importantly, the IoT user can specify a fine-grained access policy to generate a delegation credential, and then send this credential to the cloud so that it can convert all the encrypted data satisfying the access policy into new ciphertexts that are readable to a new recipient. In this way, IoT users can share the data outsourced to the cloud in a flexible and privacy-preserving manner. Detailed security analysis shows that the FPDS scheme is secure against semitrusted cloud and malicious IoT users. Thorough theoretical and experimental analyses demonstrate the high efficiency of the scheme. Zheng Qin 0001, Letian Sha, Hui Yin 0001 |
IEEE Internet Things J. | 4 |
| 2020 | Privacy-preserving range query over multi-source electronic health records in public clouds
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Jixin Zhang, Hui Yin 0001, Keqin Li 0001 |
J. Parallel Distributed Comput. | 5 |
| 2020 | A fine-grained authorized keyword secure search scheme with efficient search permission update in cloud computing
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Fangmin Li, Keqin Li 0001 |
J. Parallel Distributed Comput. | 1 |
| 2019 | A feature-hybrid malware variants detection using CNN based opcode embedding and BPNN based API embedding
Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Kehuan Zhang |
Comput. Secur. | 3 |
| 2019 | Secure conjunctive multi-keyword ranked search over encrypted cloud data for multiple data owners
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Fangmin Li, Keqin Li 0001 |
Future Gener. Comput. Syst. | 1 |
| 2019 | EPLC: An Efficient Privacy-Preserving Line-Loss Calculation Scheme for Residential Areas of Smart GridabstractRecently, smart grid is considered as the next generation of power grid by introducing information and communication technologies. Line-loss is an important synthetic indicator which can directly reflect the energy efficiency and power management level of smart grid enterprises. In order to obtain all residential areas, line-loss requires obtaining electricity consumption of each user. However, data about users’ electricity consumption could reveal sensitive information; a sophisticated adversary can use some data analysis methods to deduce economic situation, habits, lifestyles, etc. In order to solve the problem, we propose an Efficient Privacy-preserving scheme for Line-loss Calculation, named EPLC. In our scheme, a data item is reading from one smart meter which implies the energy consumption in a time period of the user who owns it, and each user lives in a residential area. For each user, we encrypt user’s data based on Paillier cryptosystem by using two Horner parameters, by leveraging homomorphism, and each residential area gateway calculates relevant data about corresponding line-loss and control center hides the area-level polynomial into the final output for representing line-loss of all residential areas which are both in the form of ciphertext. Finally, we can still recover each residential area line-loss with possessing private keys and Horner parameters. Moreover, EPLC adopts the batch verification technique to lower authentication cost. Finally, our analysis indicates that EPLC is not only efficient but also can protect individual user’s electricity consumption privacy, and the flexibility and expansibility of EPLC are very suitable for smart grid. Yinqiao Xiong, Peidong Zhu, Zhizhu Liu, Hui Yin 0001, Tiantian Deng |
Secur. Commun. Networks | 4 |
| 2018 | Sensitive system calls based packed malware variants detection using principal component initialized MultiLayers neural networksabstractMalware detection has become mission sensitive as its threats spread from computer systems to Internet of things systems. Modern malware variants are generally equipped with sophisticated packers, which allow them bypass modern machine learning based detection systems. To detect packed malware variants, unpacking techniques and dynamic malware analysis are the two choices. However, unpacking techniques cannot always be useful since there exist some packers such as private packers which are hard to unpack. Although dynamic malware analysis can obtain the running behaviours of executables, the unpacking behaviours of packers add noisy information to the real behaviours of executables, which has a bad affect on accuracy. To overcome these challenges, in this paper, we propose a new method which first extracts a series of system calls which is sensitive to malicious behaviours, then use principal component analysis to extract features of these sensitive system calls, and finally adopt multi-layers neural networks to classify the features of malware variants and legitimate ones. Theoretical analysis and real-life experimental results show that our packed malware variants detection technique is comparable with the the state-of-art methods in terms of accuracy. Our approach can achieve more than 95.6\% of detection accuracy and 0.048 s of classification time cost. Jixin Zhang, Kehuan Zhang, Zheng Qin 0001, Hui Yin 0001, Qixin Wu |
Cybersecur. | 4 |
| 2018 | An Efficient and Privacy-Preserving Multiuser Cloud-Based LBS Query SchemeabstractLocation-based services (LBSs) are increasingly popular in today’s society. People reveal their location information to LBS providers to obtain personalized services such as map directions, restaurant recommendations, and taxi reservations. Usually, LBS providers offer user privacy protection statement to assure users that their private location information would not be given away. However, many LBSs run on third-party cloud infrastructures. It is challenging to guarantee user location privacy against curious cloud operators while still permitting users to query their own location information data. In this paper, we propose an efficient privacy-preserving cloud-based LBS query scheme for the multiuser setting. We encrypt LBS data and LBS queries with a hybrid encryption mechanism, which can efficiently implement privacy-preserving search over encrypted LBS data and is very suitable for the multiuser setting with secure and effective user enrollment and user revocation. This paper contains security analysis and performance experiments to demonstrate the privacy-preserving properties and efficiency of our proposed scheme. Lu Ou, Hui Yin 0001, Zheng Qin 0001, Sheng Xiao, Yupeng Hu 0004 |
Secur. Commun. Networks | 2 |
| 2017 | MPOPE: Multi-provider Order-Preserving Encryption for Cloud Data Privacy
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Jixin Zhang, Hui Yin 0001, Keqin Li 0001 |
SecureComm | 5 |
| 2017 | A query privacy-enhanced and secure search scheme over encrypted data in cloud computing
Hui Yin 0001, Zheng Qin 0001, Lu Ou, Keqin Li 0001 |
J. Comput. Syst. Sci. | 1 |
| 2016 | Malware Variant Detection Using Opcode Image Recognition with Small Training SetsabstractMalware detection becomes mission critical as its threats spread from personal computers to industrial control systems. Modern malware generally equips with sophisticated anti-detection mechanisms such as code-morphism, which allows the malware to evolve into many variants and bypass traditional code feature based detection systems. In this paper, we propose to disassemble binary executables into opcodes sequences, and then convert the opcodes into images. By comparing the opcode images generated from binary targets with the opcode images generated from known malware sample codes, we can detect if the target binary executables contain variants of these known malwares. Theoretical analysis and real-life experiments results show that malware detection using visualized analysis is comparable in terms of accuracy, our approach can significantly improve 15\% of detection accuracy when the detection set contains a large quantity of binaries and the training set is small. Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Sheng Xiao, Yupeng Hu 0004 |
ICCCN | 3 |
| 2016 | Multi-User Location Correlation Protection with Differential PrivacyabstractIn the big data era, with the rapid development of location-based applications, GPS enabled devices and big data institutions, location correlation privacy raises more and more people's concern. Because adversaries may combine location correlations with their background knowledge to guess users' privacy, such correlation should be protected to preserve users' privacy. In order to deal with the location disclosure problem, location perturbation and generalization have been proposed. However, most proposed approaches depend on syntactic privacy models without rigorous privacy guarantee. Furthermore, many approaches only consider perturbing the locations of one user without considering multi-user location correlations, so these techniques cannot prevent various inference attacks well. Currently, differential privacy has been regarded as a standard for privacy protection, but there are new challenges for applying differential privacy in the location correlations protection. The privacy protection not only should meet the needs of users who request location-based services, but also should protect location correlation among multiple users. In this paper, we propose a systematic solution to protect location correlations privacy among multiple users with rigorous privacy guarantee. First of all, we propose a novel definition, private candidate sets which are obtained by hidden Markov models. Then, we quantify the location correlation between two users by using the similarity of hidden Markov models. Finally, we present a private trajectory releasing mechanism which can preserve the location correlations among users who move under hidden Markov models in a period of time. Experiments on real-world datasets also show that multi-user location correlation protection is efficient. Lu Ou, Zheng Qin 0001, Yonghe Liu, Hui Yin 0001, Yupeng Hu 0004, Hao Chen 0051 |
ICPADS | 4 |
| 2016 | Secure Conjunctive Multi-Keyword Search for Multiple Data Owners in Cloud ComputingabstractRecently, secure search over encrypted cloud data has become a hot research spot and challenging task. Some secure search schemes have been proposed to try to meet this challenge. In this paper, we propose a conjunctive multi-keyword secure search scheme for multiple data owners. To guarantee data security and system flexibility in the multiple data owners environment, we design an ingenious secure query scheme that allows each data owner to adopt randomly chosen temporary keys to build secure indexes for different data files. An authorized data user does not need to know these temporary keys of constructing indexes and can instead randomly choose another temporary query keys to encrypt query keywords while the cloud can correctly perform keywords matching over encrypted data files. Extensive experiments demonstrate the correctness and practicality of the proposed scheme. Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Wenjie Li 0005, Lu Ou, Yupeng Hu 0004, Keqin Li 0001 |
ICPADS | 1 |
| 2016 | IRMD: Malware Variant Detection Using Opcode Image RecognitionabstractMalware detection becomes mission critical as its threats spread from personal computers to industrial control systems. Modern malware generally equips with sophisticated anti-detection mechanisms such as code-morphism, which allows the malware to evolve into many variants and bypass traditional code feature based detection systems. In this paper, we propose to disassemble binary executables into opcodes sequences, and then convert the opcodes into images. By using convolutional neural network to compare the opcode images generated from binary targets with the opcode images generated from known malware sample codes, we can detect if the target binary executables is malicious. Theoretical analysis and real-life experiments results show that malware detection using visualized analysis is comparable in terms of accuracy, our approach can significantly improve 15% of detection accuracy when the detection set contains a large quantity of binaries and the training set is much smaller. Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Yupeng Hu 0004 |
ICPADS | 3 |
| 2016 | An Approach to Rule Placement in Software-Defined NetworksabstractSoftware-Defined Networks (SDN) is a trend of research in networks. Rule placement, a common operation for network administrators, has become more complicated due to the capacity limitation of devices in which the large number of rules are deployed. Prior works on rule placement mostly consider the influence on rule placement incurred by the rules in a single device. However, the position relationships between neighbor devices have influences on rule placement. Our basic idea is to classify the position relationships into two categories: the serial relationship and the parallel relationship, and we present a novel strategy for rule placement based on the two different position relationships. There are two challenges of implementing our strategies: to check whether a rule is contained by a rule set or not and to check whether a rule can be merged by other rules or not.To overcome the challenges, we propose a novel data structure called OPTree to represent the rules, which is convenient to check whether a rule is covered by other rules. We design the insertion algorithm and search algorithm for OPTree. Extensive experiments show that our approach can effectively reduce the number of rules while ensuring placed rules work. On the other hand, the experimental results also demonstrate that it is necessary to consider the position relationships between neighbor devices when placing rules. Wenjie Li 0005, Zheng Qin 0001, Hui Yin 0001, Rui Li 0020, Lu Ou |
MSWiM | 3 |
| 2015 | A Secure and Fine-Grained Query Results Verification Scheme for Private Search Over Encrypted Cloud Data
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Yupeng Hu 0004, Huigui Rong |
ICA3PP (3) | 1 |