Bo Li 0005

dblp:50/3402-5 · DBLP profile ↗
← Back
69ranked-venue papers
11as first author
23since 2021 · last 2026
0000-0002-6297-712XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 20 · 6 first-author · 1 since 2021Security and privacy · 19 · 2 first-author · 9 since 2021Artificial intelligence and machine learning · 12 · 7 since 2021Databases, data management, data science and information retrieval · 7 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 2 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Cross-Attention-Based Multi-scale Local-Global Feature Fusion for Deepfake Detection
ZhiWen Gu, Bo Li 0005
KSEM (4)2
2026 DynMD: Energy-Based Dynamic Graph Representation Learning for Malware Detection
Chen Liu 0039, Bo Li 0005, Yidong Wu, Xudong Liu 0001, Jianxin Li 0002, Chunpei Li
IEEE Trans. Dependable Secur. Comput.2
2025 MBSM-Net: A Multi-Branch Structure Model for Pneumoconiosis Screening and Grading of Chest X-Ray Images
abstract
ABSTRACT Convolutional neural network (CNN)‐based auxiliary diagnostic systems have been widely proposed. However, CNNs have limitations in perceiving global features and more subtle features, which makes existing methods unable to achieve ideal accuracy in tasks such as pneumoconiosis screening. To overcome these limitations, we propose MBSM‐Net, a new multi‐branch structure‐enhanced model for pneumoconiosis screening and grading based on X‐ray images. MBSM‐Net introduces an adaptive feature selection and fusion module to achieve synchronous extraction and hierarchical fusion of global and local features. In the local feature extraction module, we designed a CNN‐Mamba module. This module integrates prior information through a detailed enhancement module to compensate for the shortcomings of traditional convolutions and significantly enhances the expression of subtle lesion information. Meanwhile, the Mamba module simulates pixel‐level long‐range dependencies to extract finer‐grained texture features. In the global feature extraction module, we cleverly utilize the windowed multi‐head self‐attention (W‐MSA) mechanism, enabling the model to better understand the overall distribution and degree of fibrosis of pulmonary lesions. We validated the MBSM‐Net model on 1,760 real anonymized patient X‐ray chest films. The results showed that the accuracy of the MBSM‐Net model reached 78.6%, and the F 1 score reached 79%, both of which are superior to existing models.
Shuzhi Su, Zekuan Yu, Bo Li 0005
IET Image Process.7
2024 A Few-Shot Network Flow Attack Classification via Graph Contrastive Learning
abstract
Accurately identifying network attacks is crucial for maintaining network security. However, these attacks are often hide within massive volumes of network traffic, posing significant challenges for traditional detection methods. Supervised learning approaches require substantial labeled data and struggle to adapt to unknown attack types, while unsupervised methods face difficulties in accurately pinpointing specific attack categories. To address these limitations, we propose a novel fewshot learning model for network flow attack classification based on graph contrastive learning. Our model leverages contrastive learning to enhance feature representation and generalization capabilities, enabling high-accuracy attack detection even with limited training data. Specifically, we first construct a multi- graph representation of network traffic and segment the data into snapshots. Then, we perform graph data augmentation within each snapshot to generate augmented sample pairs, which are used to pre-train the model via contrastive learning. Finally, we fine-tune the model parameters to achieve multi-class attack classification, leveraging the learned feature representations to identify various attack types, even those unseen during training. Experimental results demonstrate that our model exhibits excellent generalization ability and achieves high attack detection performance, even with limited training data.
Binbin Ge, Bo Li 0005, Xudong Mou, Jun Zhao 0017, Xudong Liu 0001
CSCloud2
2024 Empowering smart city situational awareness via big mobile data
abstract
Smart city situational awareness has recently emerged as a hot topic in research societies, industries, and governments because of its potential to integrate cutting-edge information technology and solve urgent challenges that modern cities face. For example, in the latest five-year plan, the Chinese government has highlighted the demand to empower smart city management with new technologies such as big data and Internet of Things, for which situational awareness is normally the crucial first step. While traditional static surveillance data on cities have been available for decades, this review reports a type of relatively new yet highly important urban data source, i.e., the big mobile data collected by devices with various levels of mobility representing the movement and distribution of public and private agents in the city. We especially focus on smart city situational awareness enabled by synthesizing the localization of hundreds of thousands of mobile software Apps using the Global Positioning System (GPS). This technique enjoys advantages such as a large penetration rate (∼50% urban population covered), uniform spatiotemporal coverage, and high localization precision. We first discuss the pragmatic requirements for smart city situational awareness and the challenges faced. Then we introduce two suites of empowering technologies that help fulfill the requirements of (1) cybersecurity insurance for smart cities and (2) spatiotemporal modeling and visualization for situational awareness, both via big mobile data. The main contributions of this review lie in the description of a comprehensive technological framework for smart city situational awareness and the demonstration of its feasibility via real-world applications.
Zhiguang Shan, Lei Shi 0002, Bo Li 0005, Yanqiang Zhang, Wei Chen 0001
Frontiers Inf. Technol. Electron. Eng.3
2024 Evolving malware detection through instant dynamic graph inverse reinforcement learning
Chen Liu 0039, Bo Li 0005, Xudong Liu 0001, Chunpei Li, Jingru Bao
Knowl. Based Syst.2
2024 MalAF : Malware Attack Foretelling From Run-Time Behavior Graph Sequence
abstract
Foretelling ongoing malware attacks in real time is challenging due to the stealthy and polymorphic nature of their executive behavior patterns. In this paper, we present MalAF, a novelMalwareAttackForetelling framework that utilizes run-time behavior (i.e., sequences of API events) of malware to foretell the attack that has not yet executed. MalAF first samples suspicious API events by assessing the sensitivity of the parameters of each API event and dividing them into multiple attack time slots by calculating the strong correlation. Following that, MalAF employs dynamic heterogeneous graph sequences to incrementally model contextual semantics for each attack time slot, generating malware state sequences in real time. Moreover, MalAF proposes a greedy adaptive dictionary (GAD)-optimized IRL preference learning method to automate the capture of families' intrinsic attack preferences, which achieves higher performance than the existing inverse reinforcement learning (IRL). Additionally, with the guidance of families' attack preferences, MalAF trains an LSTM to foretell the future path of the target malware. Finally, MalAF matches the identified APIs' paths with a malicious capability base and reports the comprehensible attacks to an analyst. The experiments on real-world datasets demonstrate that our proposed MalAF outperforms the state-of-the-art methods, which improves the baseline by 3.01%$\sim$4.73% of accuracy in terms of path foretell.
Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Xudong Liu 0001, Chunpei Li
IEEE Trans. Dependable Secur. Comput.2
2024 TAPFed: Threshold Secure Aggregation for Privacy-Preserving Federated Learning
abstract
Federated learning is a computing paradigm that enhances privacy by enabling multiple parties to collaboratively train a machine learning model without revealing personal data. However, current research indicates that traditional federated learning platforms are unable to ensure privacy due to privacy leaks caused by the interchange of gradients. To achieve privacy-preserving federated learning, integrating secure aggregation mechanisms is essential. Unfortunately, existing solutions are vulnerable to recently demonstrated inference attacks such as the disaggregation attack. This paper proposesTAPFed, an approach for achieving privacy-preserving federated learning in the context of multiple decentralized aggregators with malicious actors.TAPFeduses a proposed threshold functional encryption scheme and allows for a certain number of malicious aggregators while maintaining security and privacy. We provide formal security and privacy analyses ofTAPFedand compare it to various baselines through experimental evaluation. Our results show thatTAPFedoffers equivalent performance in terms of model quality compared to state-of-the-art approaches while reducing transmission overhead by 29%-45% across different model training scenarios. Most importantly,TAPFedcan defend against recently demonstrated inference attacks caused by curious aggregators, which the majority of existing approaches are susceptible to.
Runhua Xu, Bo Li 0005, Chao Li 0023, James B. D. Joshi, Shuai Ma 0001, Jianxin Li 0002
IEEE Trans. Dependable Secur. Comput.2
2024 A2-CLM: Few-Shot Malware Detection Based on Adversarial Heterogeneous Graph Augmentation
abstract
Malware attacks, especially “few-shot” malware, have profoundly harmed the cyber ecosystem. Recently, malware detection models based on graph neural networks have achieved remarkable success. However, these efforts over-rely on sufficient labeled data for model training and thus may be brittle in few-shot malware detection because of the label scarcity. To this end, we propose a self-supervised malware detection framework based on graph contrastive learning and adversarial augmentation, termed A2-CLM, to address the challenge of few-shot malware detection. Particularly, A2-CLM first depicts the malware execution context with a sensitivity heterogeneous graph by assessing the security semantic of each behavior. Afterwards, A2-CLM designs multiple adversarial attacks to generate more practical contrastive pairs, including the PGD attack, attribute masking attack, meta-graph-guide sampling attack, direct system calls attack, and obfuscation attack, which is beneficial to strengthening the model’s effectiveness and robustness. To alleviate the training workload of contrastive learning, we introduce a momentum strategy to train the multiple graph encoders in A2-CLM. Especially on 1-shot detection tasks, A2-CLM achieves performance gains of up to 24.63% and 4.58% against supervised and self-supervised detection methods, respectively.
Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Weiwei Feng, Xudong Liu 0001, Chunpei Li
IEEE Trans. Inf. Forensics Secur.2
2023 Deep Autoencoding One-Class time Series Anomaly Detection
abstract
Time-series Anomaly Detection(AD) is widely used in monitoring and security applications in various industries and has become a hot spot in the field of deep learning. Normality-representation-based methods perform well in certain scenarios but may ignore some aspects of the overall normality. Feature-extraction-based methods always take a process of pre-training, whose target differs from AD, leading to a decline in AD performance. In this paper, we propose a new AD method called deep Autoencoding One-Class (AOC), which learns features with AutoEncoder(AE). Meanwhile, the normal context vectors from AE are constrained into a hypersphere small enough, similar to one-class methods. With an objective function that optimizes the two assumptions simultaneously, AOC learns various aspects of normality, which is more effective for AD. Experiments on public datasets show that our method outperforms existing baseline approaches.
Xudong Mou, Rui Wang 0118, Tiejun Wang 0002, Jie Sun 0035, Bo Li 0005, Tianyu Wo, Xudong Liu 0001
ICASSP5
2023 WaRoNav: Warehouse Robot Navigation Based on Multi-view Visual-Inertial Fusion
Yinlong Zhang, Bo Li 0005, Wei Liang 0001
PRCV (3)2
2023 A novel hierarchical attention-based triplet network with unsupervised domain adaptation for network intrusion detection
Jinghong Lan, Xudong Liu 0001, Bo Li 0005, Jun Zhao 0017
Appl. Intell.3
2023 TI-MVD: A temporal interaction-enhanced model for malware variants detection
Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Ziyang Zhen, Weiwei Feng, Xudong Liu 0001
Knowl. Based Syst.2
2023 eHotSnap: An Efficient and Hot Distributed Snapshots System for Virtual Machine Cluster
abstract
With the popularity of IaaS clouds, many distributed and networked applications are running in virtual machine cluster (VMC). The distributed snapshots of VMC are a practical approach to guarantee system reliability. It rewinds the system to an intermediate state from failures so that the applications can continue execution from a point near the failure. However, the applications running in the VMC suffer from long disruption and significant performance degradation due to the heavy cost distributed snapshots, especially when designed to guarantee global consistency of VMC snapshots. This article presents eHotSnap, which takes distributed snapshots of a VMC efficiently. eHotSnap divides the native snapshot into light cost transient snapshot and heavy cost memory snapshot and then coordinates the VM snapshots immediately after transient snapshots. In this way, it decouples coordination from heavy cost snapshots so that the distributed snapshots are taken (completed in logic) within a second. Then, it performs memory snapshot and optimizes it with a two-layer optimization, which first employs de-duplication to reduce the amount of snapshot data and then leverages priority queue to serve guest write operations preferentially. In addition to presenting eHotSnap, we have implemented a prototype on QEMU/KVM. The experimental results demonstrate the effectiveness and efficiency of the proposed approach.
Bo Li 0005, Lei Cui 0003, Zhiyu Hao, Yongji Liu, Yongnan Li
IEEE Trans. Parallel Distributed Syst.1
2022 MATTER: A Multi-Level Attention-Enhanced Representation Learning Model for Network Intrusion Detection
abstract
Network Intrusion Detection Systems (NIDSs) play a crucial role in safeguarding the security of protected computer networks. Although numerous machine learning algorithms, especially deep learning algorithms, have achieved remarkable results, their generalization ability is limited due to the following critical challenges. First, most of existing methods heavily rely on the handcrafted features extracted from packets or network flows. Second, few studies have been devoted to adaptively highlighting the characteristics of certain traffic features and thus extracting discriminative representations from input network data. In this paper, we propose a Multi-level ATTention-enhanced rEpresentation leaRning model (MATTER) to address the aforementioned challenges. Specifically, a multi-scale Convolutional Neural Network (CNN) is employed to extracted representations from the raw packet content of a network flow. Then, a multi-level attention module with spatial, channel and temporal attention mechanisms is leveraged to enhance the discrimination of the extracted features. Extensive experiments on two benchmark datasets demonstrate that our proposed MATTER is superior to other state-of-the-art approaches in terms of both accuracy and F1 score.
Jinghong Lan, Bo Li 0005, Xudong Liu 0001
TrustCom3
2022 DarknetSec: A novel self-attentive deep learning method for darknet traffic classification and application identification
Jinghong Lan, Xudong Liu 0001, Bo Li 0005, Tongtong Geng
Comput. Secur.3
2022 MEMBER: A multi-task learning model with hybrid deep features for network intrusion detection
Jinghong Lan, Xudong Liu 0001, Bo Li 0005, Jie Sun 0035, Beibei Li 0002, Jun Zhao 0017
Comput. Secur.3
2022 Cyber threat prediction using dynamic heterogeneous graph learning
Jun Zhao 0017, Minglai Shao 0001, Hong Wang 0015, Xiaomei Yu, Bo Li 0005, Xudong Liu 0001
Knowl. Based Syst.5
2022 Prediction of Vertical Profile of NO₂ Using Deep Multimodal Fusion Network Based on the Ground-Based 3-D Remote Sensing
abstract
The vertical distribution profiles of NO2are essential for understanding the mechanisms, detecting near-surface emissions, and tracking pollutant transportation at high altitude. However, most of the published NO2studies are based on the surface 2-D measurements. The ground-based 3-D remote-sensing stations were recently built to measure vertical distribution profiles of NO2. However, the stations were spatially sparse due to the high cost and could not make the measurements without sunlight. In this study, we first developed a multimodel fusion network (MF-net) based on the sparse vertical observations from the Jing-Jin-Ji region. We achieved the 3-D profile prediction of NO2in the range of 39.005–41.405N and 115.005–117.905E with 24-h coverage. The MF-net significantly surpassed the conventional WRF-CHEM model and provided a more accurate evaluation of the NO2transmission between Beijing and the neighboring cities. Besides, the MF-net covers the monitoring of NO2to the whole study area and extends the monitoring time to the entire day (24 h), making it serviceable for continuous spatial-temporal estimation of NO2and its transmission in pollution events. The MF-net provides more robust data support to formulate reasonable and effective pollution prevention and control measures.
Shulin Zhang, Bo Li 0005, Lei Liu 0029, Qihou Hu, Yizhi Zhu, Mingzhai Sun, Cheng Liu 0005
IEEE Trans. Geosci. Remote. Sens.2
2021 MG-DVD: A Real-time Framework for Malware Variant Detection Based on Dynamic Heterogeneous Graph Learning
abstract
Detecting the newly emerging malware variants in real time is crucial for mitigating cyber risks and proactively blocking intrusions. In this paper, we propose MG-DVD, a novel detection framework based on dynamic heterogeneous graph learning, to detect malware variants in real time. Particularly, MG-DVD first models the fine-grained execution event streams of malware variants into dynamic heterogeneous graphs and investigates real-world meta-graphs between malware objects, which can effectively characterize more discriminative malicious evolutionary patterns between malware and their variants. Then, MG-DVD presents two dynamic walk-based heterogeneous graph learning methods to learn more comprehensive representations of malware variants, which significantly reduces the cost of the entire graph retraining. As a result, MG-DVD is equipped with the ability to detect malware variants in real time, and it presents better interpretability by introducing meaningful meta-graphs. Comprehensive experiments on large-scale samples prove that our proposed MG-DVD outperforms state-of-the-art methods in detecting malware variants in terms of effectiveness and efficiency.
Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Ming Su, Xudong Liu 0001
IJCAI2
2021 Automatically predicting cyber attack preference with attributed heterogeneous attention networks and transductive learning
Jun Zhao 0017, Xudong Liu 0001, Qiben Yan 0001, Bo Li 0005, Minglai Shao 0001, Hao Peng 0001, Lichao Sun 0001
Comput. Secur.4
2021 Porn2Vec: A robust framework for detecting pornographic websites based on contrastive learning
Jun Zhao 0017, Minglai Shao 0001, Hao Peng 0001, Hong Wang 0015, Bo Li 0005, Xudong Liu 0001
Knowl. Based Syst.5
2021 Hierarchical Taxonomy-Aware and Attentional Graph Capsule RCNNs for Large-Scale Multi-Label Text Classification
abstract
CNNs, RNNs, GCNs, and CapsNets have shown significant insights in representation learning and are widely used in various text mining tasks such as large-scale multi-label text classification. Most existing deep models for multi-label text classification consider either the non-consecutive and long-distance semantics or the sequential semantics. However, how to coherently take them into account is still far from studied. In addition, most existing methods treat output labels as independent medoids, ignoring the hierarchical relationships among them, which leads to a substantial loss of useful semantic information. In this paper, we propose a novel hierarchical taxonomy-aware and attentional graph capsule recurrent CNNs framework for large-scale multi-label text classification. Specifically, we first propose to model each document as a word order preserved graph-of-words and normalize it as a corresponding word matrix representation preserving both the non-consecutive, long-distance and local sequential semantics. Then the word matrix is input to the proposed attentional graph capsule recurrent CNNs for effectively learning the semantic features. To leverage the hierarchical relations among the class labels, we propose a hierarchical taxonomy embedding method to learn their representations, and define a novel weighted margin loss by incorporating the label representation similarity. Extensive evaluations on three datasets show that our model significantly improves the performance of large-scale multi-label text classification by comparing with state-of-the-art approaches.
Hao Peng 0001, Jianxin Li 0002, Senzhang Wang, Qiran Gong, Renyu Yang, Bo Li 0005, Philip S. Yu, Lifang He 0001
IEEE Trans. Knowl. Data Eng.7
2020 Cyber Threat Intelligence Modeling Based on Heterogeneous Graph Convolutional Network
Jun Zhao 0017, Qiben Yan 0001, Xudong Liu 0001, Bo Li 0005, Guangsheng Zuo
RAID4
2020 TIMiner: Automatically extracting and analyzing categorized cyber threat intelligence from social data
Jun Zhao 0017, Qiben Yan 0001, Jianxin Li 0002, Minglai Shao 0001, Zuti He, Bo Li 0005
Comput. Secur.6
2020 Multi-attributed heterogeneous graph convolutional network for bot detection
Jun Zhao 0017, Xudong Liu 0001, Qiben Yan 0001, Bo Li 0005, Minglai Shao 0001, Hao Peng 0001
Inf. Sci.4
2020 Towards a distributed local-search approach for partitioning large-scale social networks
Liu Ouyang, Chong Chang, Bo Li 0005, Tefeng Chen, Hao Peng 0001
Inf. Sci.6
2019 Uncovering Specific-Shape Graph Anomalies in Attributed Graphs
Wenjun Wang 0002, Feng Chen 0001, Jianxin Li 0002, Bo Li 0005, Jinpeng Huai
AAAI5
2019 Denoising Convolutional Autoencoder Based B-mode Ultrasound Tongue Image Feature Extraction
abstract
B-mode ultrasound tongue imaging is widely used in the speech production field. However, efficient interpretation is in a great need for the tongue image sequences. Inspired by the recent success of unsupervised deep learning approach, we explore unsupervised convolutional network architecture for the feature extraction in the ultrasound tongue image, which can be helpful for the clinical linguist and phonetics. By quantitative comparison between different unsupervised feature extraction approaches, the denoising convolutional autoencoder (DCAE)-based method outperforms the other feature extraction methods on the reconstruction task and the 2010 silent speech interface challenge. A Word Error Rate of 6.17% is obtained with DCAE, compared to the state-of-the-art value of 6.45% using Discrete cosine transform as the feature extractor. Our codes are available at https://github.com/DeePBluE666/Source-code1.
Bo Li 0005, Kele Xu, Haibo Mi, Huaimin Wang 0001
ICASSP1
2019 Incorporating URL embedding into ensemble clustering to detect web anomalies
Bo Li 0005, Guiqin Yuan, Ruoyi Zhang, Yiyang Yao
Future Gener. Comput. Syst.1
2019 Modeling and clustering attacker activities in IoT through machine learning techniques
Peiyuan Sun, Jianxin Li 0002, Md. Zakirul Alam Bhuiyan, Bo Li 0005
Inf. Sci.5
2019 A Nonparametric Approach to Uncovering Connected Anomalies by Tree Shaped Priors
abstract
The area of anomaly detection has recently been expanded in the graph-based data. Anomalous vertices are often exhibited as a connected subgraph. Few works, however, have focused on connected anomalous subgraph detection because of the challenge of optimizing graph functionals under connectivity constraints. We employ Non-Parametric Graph Scan (NPGS) statistics for detecting anomalies within graph-based data. Based on the NPGS statistics, we proposed an efficient approximate approach to the connected anomalous subgraph detection problem that provides provable guarantees on performance and quality. In particular, we first decompose the problem into a sequence of subproblems, each of which can be reduced to a Budget Price-Collecting Steiner Tree (BPCST) problem, and then develop efficient exact and approximate algorithms for a special category of graphs in which the anomalous subgraphs can be reformulated in a fixed tree topology. Our method has a wide variety of applications, such as disease outbreak detection, road traffic congestion detection, and event detection in social media, because the NPGS statistics is free of distribution assumptions and can be applied to heterogeneous graph data.
Feng Chen 0001, Jianxin Li 0002, Jinpeng Huai, Baojian Zhou, Bo Li 0005, Naren Ramakrishnan
IEEE Trans. Knowl. Data Eng.6
2019 SPFC: An Effective Optimization for Vertex-Centric Graph Processing Systems
abstract
The real-world demands of mining big data and smart data of graph structure have led to an active research of distributed graph processing. Many distributed graph processing systems [19], [22], [23] adopt a vertex-centric programming paradigm. In these systems, messages are passed between vertices to propagate the latest states. The communication efficiency and the high overhead of synchronization are two key considerations of these systems [8], [12]. In this paper, we propose a Slow Passing Fast Consuming (SPFC) approach which can effectively improve the overall performance of vertex-centric graph processing systems. In our approach, the message passing is slow but the consuming is fast. More specifically, at the message sender side, priority is given to those smart messages which contribute more to the algorithm convergence, and at the message receiver side, messages are consumed right after arriving without any delay and intermediate buffer. Besides, by using a two-phase termination check protocol, the global synchronous barrier can be completely eliminated. In addition, based on the slow message passing strategy, further performance improvement can be achieved with some accuracy loss by eliminating those messages which are less useful for algorithm convergence. We implement our approach based on Apache Giraph [1] and evaluate it on a 12-machine cluster. The experimental results show that our method can effectively reduce the amount of message traffic and achieve up to an order of magnitude performance improvement compared with Giraph and GraphLab [3].
Jianxin Li 0002, Yingjie Cao, Yangyang Zhang 0001, Md. Zakirul Alam Bhuiyan, Bo Li 0005
IEEE Trans. Sustain. Comput.5
2018 Multi-scale DenseNet-Based Electricity Theft Detection
Bo Li 0005, Kele Xu, Xiaoyan Cui, Xinbo Ai, Yanbo Wang 0003
ICIC (1)1
2018 ShadowMonitor: An Effective In-VM Monitoring Framework with Hardware-Enforced Isolation
Bin Shi 0003, Lei Cui 0003, Bo Li 0005, Xudong Liu 0001, Zhiyu Hao, Haiying Shen
RAID3
2018 FluteDB: An efficient and scalable in-memory time series database for sensor-cloud
Chen Li 0046, Bo Li 0005, Md. Zakirul Alam Bhuiyan, Jinghui Si, Guanyu Wei, Jianxin Li 0002
J. Parallel Distributed Comput.2
2017 A Human-Machine Collaborative Detection Model for Identifying Web Attacks
Bo Li 0005, Weijing Ye, Guiqin Yuan
CollaborateCom2
2017 IoT Eye An Efficient System for Dynamic IoT Devices Auto-discovery on Organization Level
abstract
Internet of Things (IoT) serves not only as an essential part of the new generation information technology but as an important development stage in the information era. IoT devices such as unmanned aerial vehicles, robots and wearable equipments have been widely used in recent years. For most organizations' inner networks, innumerable dynamic connections with Internet accessible IoT devices occur at many parts all the time. It is usually these temporal links that arise potential threats to the security of the whole intranet. In this paper, we propose a new system named IoT Eye, which automatically discovers the IoT devices in real time. The IoT Eye detects all the potential IoT target hosts using an innovative two-stage architecture: (1) Scanning suspicious IP segments with stateless TCP SYN scan model and zero copy TCP stack; (2) Identifying each IoT device on various protocols using PI-AC, which is a novel high-performance multi-pattern matching algorithm. The preceding model ensures the IoT Eye searching each newly connected device out in rather small time delay, which minimizes the missing and wrong detection rates. Related intelligence on the active IoT devices linked with the organization's intranets are of great importance to the professionals. Since it can help them: (1) re-examine the borders of large intranets; (2) reduce non-essential device access; (3) fix security vulnerabilities timely.
Ying Li 0128, Bo Li 0005, Hanteng Chen, Jianxin Li 0002
CSCloud3
2017 Query-Driven Discovery of Anomalous Subgraphs in Attributed Graphs
abstract
For a detection problem, a user often has some prior knowledge about the structure-specific subgraphs of interest, but few traditional approaches are capable of employing this knowledge. The main technical challenge is that few approaches can efficiently model the space of connected subgraphs that are isomorphic to a query graph. We present a novel, efficient approach for optimizing a generic nonlinear cost function subject to a query-specific structural constraint. Our approach enjoys strong theoretical guarantees on the convergence of a nearly optimal solution and a low time complexity. For the case study, we specialize the nonlinear function to several well-known graph scan statistics for anomalous subgraph discovery. Empirical evidence demonstrates that our method is superior to state-of-the-art methods in several real-world anomaly detection tasks.
Feng Chen 0001, Jianxin Li 0002, Jinpeng Huai, Bo Li 0005
IJCAI5
2017 A deep learning enabled subspace spectral ensemble clustering approach for web anomaly detection
abstract
With the development of the Internet, it is vital for the security of the Internet to detect web-based anomalies. Clustering based on feature extraction by manually has been verified as a significant way to detect new anomalies. But the presentations of these features can't express semantic information of the URLs. In addition, few studies try to cluster the anomalies into specific types like SQL-injection. In order to solve these two problems, we provide a deep learning enabled subspace spectral ensemble clustering approach for web anomaly detection called DEP-SSEC. This approach has three steps. Firstly, an ensemble clustering model is applied to separate anomalies from normal samples. Then we use word2vec to get the semantical presentations of anomalies. Finally, another multi-clustering approach clusters anomalies into specific types. Our approach is run on a real-life dataset. The result achieves about 0.8321 NMI and 0.8691 Rn, which demonstrates that our model has the ability to cluster anomalies into appropriate types.
Guiqin Yuan, Bo Li 0005, Yiyang Yao
IJCNN2
2017 Towards a multi-layers anomaly detection framework for analyzing network traffic
abstract
Summary Anomaly detection plays a crucial part in identifying unforeseen attacks for network and information security. However, the accuracy of existing network anomaly detection approaches is limited because of the lack of sufficient and high‐quality features. Most research works only take information from one network layer into account, which leads to a situation that some key features of other network layers are omitted. To address this issue, we propose a novel approach, named Multi‐Layers Anomaly Detection, which extracts and combines features from different network layers. In order to reduce redundancy and noise derived from the combination of multiple layers, an algorithm called RanPF is designed by applying principal components analysis (PCA) into random forest (RF) algorithm. RanPF uses features selected by PCA to decide the height of every tree in RF and provides a method to select which features for tree nodes to use according to the weights of principal components. To obtain high‐quality features, we adopt an attribute learning mechanism. Naive Bayes is used to characterize the attribute information, which is fast and simple compared with other learning algorithms such as SVM. In addition, a series of experiments conducted on two real‐life datasets demonstrate that our approach outperforms the state‐of‐the‐art methods in terms of detection rate and false alarm rate. MLAD achieves about 99%detection rate and about 0.6%false alarm rate on average when the ratio of the training set is 60%. Copyright © 2016 John Wiley & Sons, Ltd.
Bo Li 0005, Ke Li 0013
Concurr. Comput. Pract. Exp.1
2017 Towards an efficient snapshot approach for virtual machines in clouds
Jianxin Li 0002, Yangyang Zhang 0001, Jingsheng Zheng, Bo Li 0005, Jinpeng Huai
Inf. Sci.5
2017 Multi-Task Learning for Intrusion Detection on web logs
Bo Li 0005
J. Syst. Archit.1
2016 CloudAuditor: A Cloud Auditing Framework Based on Nested Virtualization
abstract
Recent years witness the successful adoption of Cloud computing. However, security remains the top concern for cloud users. The fundamental issue is that cloud providers cannot convince cloud users the trustworthiness of cloud platforms. In this paper, we propose a cloud auditing framework, named CloudAuditor, to examine the behaviors of cloud platforms. By leveraging nested virtualization technology, CloudAuditor could identify the stealthy memory and disk access from cloud platforms to users' virtual machines and can support the mainstream IaaS platforms such as VMware, Xen and KVM. We evaluate the effectiveness and efficiency of CloudAuditor through comprehensive experiments. The results show that CloudAuditor can identify the suspicious behaviors of cloud platforms with acceptable performance overhead.
Bin Shi 0003, Bo Li 0005
CSCloud5
2016 A Remote Backup Approach for Virtual Machine Images
abstract
Recent years witness the successful application of Cloud computing. Virtualization plays a key role in cloud computing and greatly facilitates application deployment and migration. Tenants' applications are hosted by virtual machines. The security and safety of user applications receive much attention from academia and industry. However, fault tolerance and availability issues of cloud applications are overlooked. In this paper, we focus on the high availability issue of virtual machines. We propose a remote backup approach, named LiveRB, for saving the running states of virtual machines in an online manner. The backup process operates in background and is transparent to the applications hosted in virtual machines. Live migration technique is used to save the running states of virtual machines. A virtual block device is designed to cache I/O operations in memory and save incremental virtual disk data of the virtual machine to a remote server. We implement LiveRB on KVM virtualization platform. We evaluate the effectiveness and efficiency of LiveRB through comprehensive experiments. The results show that LiveRB can lively backup a virtual machine to a remote server with only slight performance penalty.
Bin Shi 0003, Bo Li 0005
CSCloud5
2016 Controlling a Car Through OBD Injection
abstract
Internet of vehicles(IOV) is an application of Internet of things in Intelligent Transport System, and has attracted high attention of researchers. IOV brings network connectivity to traditional vehicles, while also introduces security risks. This paper presents experimental analysis on the security of vehicles with Internet connections and propose an approach to Controlling a Car Through OBD Injection. In the experiments, we successfully penetrated several types of cars in a wireless way. We also put out a multi-level safety model of cars, which divides cars into different groups and gives analysis and explanations of each group. All of these things are done for indicating a point of view that traditional cars are not safe enough on information security. It is surely risky to put a car without the ability to resist the attack of informational ways into the Internet of vehicles.
Yu Zhang 0097, Binbin Ge, Bin Shi 0003, Bo Li 0005
CSCloud5
2016 Toward a flexible and fine-grained access control framework for infrastructure as a service clouds
abstract
Abstract Cloud computing, as an emerging computing paradigm, greatly facilitates resource sharing and enables providing computing power as services over the Internet. However, it also brings new challenges for security and access control, especially in infrastructure as a service clouds. The introduction of virtualization layer increases new security risks, which should be restricted and confined by more stringent access control techniques. In this paper, we propose a flexible and fine‐grained access control framework, named IaaS‐oriented Hybrid Access Control (iHAC), which combines the advantages of both the role‐based access control and type enforcement model. We consider access control issues from the perspective of virtual machines. A permission transition model is designed to dynamically assign permissions to virtual machines. A Virtual Machine Monitor (VMM)‐based access control mechanism is presented to confine the virtual machine's behaviors in a fine‐grained manner. A VMM‐enabled network access control approach is proposed to regulate the communication among virtual machines. iHAC is successfully implemented in the Internet based Virtual Computing Infrastructure (iVIC) platform, and several experiments are conducted to evaluate its effectiveness and efficiency. The results show that iHAC can make correct access control decisions with low performance overhead. Copyright © 2015 John Wiley & Sons, Ltd.
Bo Li 0005, Jianxin Li 0002, Lu Liu 0001
Secur. Commun. Networks1
2016 Information Theoretic Subspace Clustering
abstract
This paper addresses the problem of grouping the data points sampled from a union of multiple subspaces in the presence of outliers. Information theoretic objective functions are proposed to combine structured low-rank representations (LRRs) to capture the global structure of data and information theoretic measures to handle outliers. In theoretical part, we point out that group sparsity-induced measures (ℓ2,1-norm, ℓα-norm, and correntropy) can be justified from the viewpoint of halfquadratic (HQ) optimization, which facilitates both convergence study and algorithmic development. In particular, a general formulation is accordingly proposed to unify HQ-based group sparsity methods into a common framework. In algorithmic part, we develop information theoretic subspace clustering methods via correntropy. With the help of Parzen window estimation, correntropy is used to handle either outliers under any distributions or sample-specific errors in data. Pairwise link constraints are further treated as a prior structure of LRRs. Based on the HQ framework, iterative algorithms are developed to solve the nonconvex information theoretic loss functions. Experimental results on three benchmark databases show that our methods can further improve the robustness of LRR subspace clustering and outperform other state-of-the-art subspace clustering methods.
Ran He 0001, Liang Wang 0001, Zhenan Sun, Yingya Zhang, Bo Li 0005
IEEE Trans. Neural Networks Learn. Syst.5
2015 A Novel Anomaly Detection Approach for Mitigating Web-Based Attacks Against Clouds
abstract
In recent years, web-based attacks increase and become the top threat in cloud environments. To detect unknown web-based attacks, many studies resort to anomaly detection through analyzing web logs. This paper presents an anomaly detection approach, which includes a transforming model and a classifier model. The transforming model converts every entry into a vector, and every value in vector is obtained by training extracted features in statistical techniques and Naive Bayes, which can analyze URI or URL without query in web logs and establish a unified normal standard for different websites. A big real-life dataset of about 50.1GB web logs has been used to verify the effectiveness of our approach, and the experimental results show that our approach can achieve detection rate over 98% and false alarm rate less than 1.5%.
Bo Li 0005, Jianxin Li 0002
CSCloud2
2015 Lightweight Virtual Machine Checkpoint and Rollback for Long-running Applications
Lei Cui 0003, Zhiyu Hao, Haiqiang Fei, Zhenquan Ding, Bo Li 0005, Peng Liu 0044
ICA3PP (3)6
2015 PARS: A Page-Aware Replication System for Efficiently Storing Virtual Machine Snapshots
abstract
Virtual machine (VM) snapshot enhances the system availability by saving the running state into stable storage during failure-free execution and rolling back to the snapshot point upon failures. Unfortunately, the snapshot state may be lost due to disk failures, so that the VM fails to be recovered. The popular distributed file systems employ replication technique to tolerate disk failures by placing redundant copies across disperse disks. However, unless user-specific personalization is provided, these systems consider the data in the file as of same importance and create identical copies of the entire file, leading to non-trivial additional storage overhead.
Lei Cui 0003, Tianyu Wo, Bo Li 0005, Jianxin Li 0002, Bin Shi 0003, Jinpeng Huai
VEE3
2015 iMIG: Toward an Adaptive Live Migration Method for KVM Virtual Machines
abstract
With the energy and power costs increasing alongside the growth of the IT infrastructures, achieving workload concentration and high availability in cloud computing environments is becoming more and more complex. Virtual machine (VM) migration has become an important approach to address this issue, particularly; live migration of the VMs across the physical servers facilitates dynamic workload scheduling of the cloud services as per the energy management requirements, and also reduces the downtime by allowing the migration of the running instances. However, migration is a complex process affected by several factors such as bandwidth availability, application workload and operating system configurations, which in turn increases the complications in predicting the migration time in order to negotiate the service-level agreements in a real datacenter. In this paper, we propose an adaptive approach named improved MIGration (iMIG), in which we characterize some of the key metrics of the live migration performance, and conduct several experiments to study the impacts of the investigated metrics on the Kernel-based VM (KVM) functionalities, as well as the energy consumed by both the destination and the source hosts. Our results reveal the importance of the configured parameters: speed limit, TCP buffer size and max downtime, along with the VM properties and also their corresponding impacts on the migration process. Improper setting of these parameters may either incur migration failures or causes excess energy consumption. We witness a few bugs in the existing Quick EMUlator (QEMU)/KVM parameter computation framework, which is one of most widely used KVM frameworks based on QEMU. Based on our observations, we develop an analytical model aimed at better predictions of both the migration time and the downtime, during the process of VM deployment. Finally, we implement a suite of profiling tools in the adaptive mechanism based on the qemu-kvm-0.12.5 version, and our experiment results prove the efficiency of our approach in improving the live migration performance. In comparison with the default migration approach, our approach achieves a 40% reduction in the migration latency and a 45% reduction in the energy consumption.
Jianxin Li 0002, Lei Cui 0003, Bo Li 0005, Lu Liu 0001, John Panneerselvam
Comput. J.5
2015 CloudMon: a resource-efficient IaaS cloud monitoring system based on networked intrusion detection system virtual appliances
abstract
Summary The networked intrusion detection system virtual appliance (NIDS‐VA), also known as virtualized NIDS, plays an important role in the protection and safeguard of IaaS cloud environments. However, it is nontrivial to guarantee both of the performance of NIDS‐VA and the resource efficiency of cloud applications because both are sharing computing resources in the same cloud environment. To overcome this challenge and trade‐off, we propose a novel system, named CloudMon, which enables dynamic resource provision and live placement for NIDS‐VAs in IaaS cloud environments. CloudMon provides two techniques to maintain high resource efficiency of IaaS cloud environments without degrading the performance of NIDS‐VAs and other virtual machines (VMs). The first technique is a virtual machine monitor based resource provision mechanism, which can minimize the resource usage of a NIDS‐VA with given performance guarantee. It uses a fuzzy model to characterize the complex relationship between performance and resource demands of a NIDS‐VA and develops an online fuzzy controller to adaptively control the resource allocation for NIDS‐VAs under varying network traffic. The second one is a global resource scheduling approach for optimizing the resource efficiency of the entire cloud environments. It leverages VM migration to dynamically place NIDS‐VAs and VMs. An online VM mapping algorithm is designed to maximize the resource utilization of the entire cloud environment. Our virtual machine monitor based resource provision mechanism has been evaluated by conducting comprehensive experiments based on Xen hypervisor and Snort NIDS in a real cloud environment. The results show that the proposed mechanism can allocate resources for a NIDS‐VA on demand while still satisfying its performance requirements. We also verify the effectiveness of our global resource scheduling approach by comparing it with two classic vector packing algorithms, and the results show that our approach improved the resource utilization of cloud environments and reduced the number of in‐use NIDS‐VAs and physical hosts. Copyright © 2013 John Wiley & Sons, Ltd.
Bo Li 0005, Jianxin Li 0002, Lu Liu 0001
Concurr. Comput. Pract. Exp.1
2014 Web Service Recommendation via Exploiting Temporal QoS Information
Wancai Zhang, Bo Li 0005
ICA3PP (1)3
2014 dIRIEr: Distributed Influence Maximization in social network
abstract
In this paper, for the first time, we tackle the scalability problem of Influence Maximization (IM) via distributed computing. First, we propose a distributed IM algorithm based on IRIE, one of the most state-of-the-art IM algorithms. Then an incremental updating method is proposed to reduce the overhead of repeated computation. Furthermore, based on some new insights, we redesign our algorithm with a strategy, which we call reservoir, to accumulate increments and delay exchange between machines. Experiments on real-world and synthetic networks show our redesigned algorithm, i.e. dIRIEr (distributed IRIE with Reservoir), reduces communication traffic dramatically and speeds up continuously as more machines are added in. dIRIEr can handle giant networks with hundreds of millions of nodes where centralized algorithms become infeasible.
Zhou Zong, Bo Li 0005, Chunming Hu
ICPADS2
2014 HotRestore: A Fast Restore System for Virtual Machine Cluster
Lei Cui 0003, Jianxin Li 0002, Tianyu Wo, Bo Li 0005, Renyu Yang, Yinglie Cao, Jinpeng Huai
LISA4
2014 A fixed point model for rate control and routing in cloud data center networks
abstract
ABSTRACT This paper addresses the issues of rate control and routing for cloud data center networks. Based on the theory of the supply–demand equilibrium, we propose a fixed point model for formulating cloud network equilibrium problems in which the equilibrium conditions are given by nonlinear equations. We show that the network equilibrium point is the optimal solution of a nonlinear programming problem by utilizing the tools of the variational inequality and convex optimization. The augmented Lagrangian multiplier algorithm is used to solve the nonlinear programming problem for computing the network equilibrium point. Further consideration is given to the equilibrium problems of a cloud network with multirate multicast sessions. We evaluate our approach on some random networks with unicast and multicast sessions, and the results show the effectiveness of our approach in finding the optimal equilibrium rates. We further evaluate the performance of our approach through cloud data center network simulation under various parameter settings, and the results show that the performance of our algorithm can be tuned and improved by choosing appropriate parameter values. Copyright © 2013 John Wiley & Sons, Ltd.
Bo Li 0005, Xuefeng Ma, Jianming Li, Zhou Zong
Secur. Commun. Networks1
2013 HotSnap: A Hot Distributed Snapshot System For Virtual Machine Cluster
Lei Cui 0003, Bo Li 0005, Yangyang Zhang 0001, Jianxin Li 0002
LISA2
2013 VMScatter: migrate virtual machines to many hosts
abstract
Live virtual machine migration is a technique often used to migrate an entire OS with running applications in a non-disruptive fashion. Prior works concerned with one-to-one live migration with many techniques have been proposed such as pre-copy, post-copy and log/replay. In contrast, we propose VMScatter, a one-to-many migration method to migrate virtual machines from one to many other hosts simultaneously. First, by merging the identical pages within or across virtual machines, VMScatter multicasts only a single copy of these pages to associated target hosts for avoiding redundant transmission. This is impactful practically when the same OS and similar applications running in the virtual machines where there are plenty of identical pages. Second, we introduce a novel grouping algorithm to decide the placement of virtual machines, distinguished from the previous schedule algorithms which focus on the workload for load balance or power saving, we also focus on network traffic, which is a critical metric in data-intensive data centers. Third, we schedule the multicast sequence of packets to reduce the network overhead introduced by joining or quitting the multicast groups of target hosts. Compared to traditional live migration technique in QEMU/KVM, VMScatter reduces 74.2% of the total transferred data, 69.1% of the total migration time and achieves the network traffic reduction from 50.1% to 70.3%.
Lei Cui 0003, Jianxin Li 0002, Bo Li 0005, Jinpeng Huai, Chunming Hu, Tianyu Wo, Hussain Al-Aqrabi, Lu Liu 0001
VEE3
2012 Software Aging in Virtualized Environments: Detection and Prediction
abstract
Software aging has been cited in many scenarios including Operating System, Web Servers, Real-time Systems. However, few studies have been conducted in long running virtualized environments where more and more software is being delivered as a service. Furthermore, state-of-the-art methods lack the ability to deal with miscellaneous upper applications and underlying systems transparently in virtualized scenarios. In this paper, we detect aging phenomenon by conducting experiments in physical and virtual machines and identify the differences between the two, and propose a feature code-based methodology for failure prediction through system call, then implement a prototype in virtual machine manager layer to predict failure time and rejuvenate transparently, which is suitable in virtualized scenarios. The evaluation shows the prediction deviation against reality is less than 10%.
Lei Cui 0003, Bo Li 0005, Jianxin Li 0002, James Hardy, Lu Liu 0001
ICPADS2
2012 A Remote USB Architecture for Virtual Machine Oriented Device Sharing and Transparent Mgration
abstract
IaaS cloud environments which are driven by virtualization technologies enable managing applications and resources in a cost-efficient way and become the main operating environments of modern data centers. While, in such environments, how to use remote peripheral devices in a virtual machine (VM) becomes a key research problem, and the problem is aggravated when facing VM migration. The state of the art migration technologies lack for the consideration of peripheral devices, which can result in data loss. To address these two problems, the paper presents a remote USB architecture, which consists of two parts: the virtual machine oriented USB device sharing (VMDS) and transparent virtual USB device migration (TVDM). VMDS is used to share locally attached USB devices to remote virtual machines, and TVDM supports continuous accessing to remote devices during virtual machine live migration. A system based on Linux and KVM is implemented to demonstrate the ideas. Experimental evaluations illustrate the system's excellent usability and performance.
Ye Jiao, Tianyu Wo, Bo Li 0005
ICPADS3
2012 iROW: An Efficient Live Snapshot System for Virtual Machine Disk
abstract
The high-availiablity of mission-critical data and services hosted in a virtual machine (VM) is one of the top concerns in a cloud computing environment. The live disk snapshot is an emerging technology to save the whole state and the data of a VM at a specific point of time, and be used for quick disaster recovery. However, the existing VM disk snapshot systems suffer from long operation time and I/O performance degradation problems during snapshots creating and managing, and thereby affecting the performance of the VM and its services. To address such issues, we designed an efficient VM disk snapshot system, named iROW (improved Redirect-on-Write). In iROW, a bitmap based light-weight index scheme is adopted to replace the existing multi-level index tree structure to reduce query cost. Additionally, through a combination of Redirect-on-Write (ROW) and Copy-on-Demand (COD) schema to avoid extra copy operation on the first write after snapshot with Copy-on-Write (COW) schema, and the file fragmentation problem caused by ROW snapshot after long-term using. Finally, iROW gives a unified disk space allocation function by the host machine's file system. We have implemented iROW in qemu-kvm 0.12.5 and conducted some experiments. The implementation of iROW completely obey the interfaces of the block device driver in QEMU, so it is transparent to the upper system or applications and original disk image formats can be also supported. The experimental results show that iROW has obvious performance advantages in snapshot creating and management operations. Compared with the existing qcow2 disk image in KVM, when the VM disk size is 50GB, and the cluster size is 64KB (the default cluster size of qcow2), the snapshot creation and rollback time is only about 6% and 3% of original qcow2's. With the increasing of the VM disk size, iROW has more performance advantages on snapshot creation and rollback operations. In addition, the I/O performance of iROW is better than qcow2. When the cluster size is 64 KB, typically the iROW's performance loss is 10% less than qcow2's, and its first write performance after snapshot creation is about 250% of qcow2's.
Jianxin Li 0002, Lei Cui 0003, Bo Li 0005, Tianyu Wo
ICPADS4
2012 Models and algorithms for elastic-demand network equilibrium problems in communication networks with multicast sessions
abstract
We consider the problem of elastic-demand network equilibrium in communication networks which support both multirate multicast sessions and unicast sessions. Extending existing work for unicast sessions, we first present the elastic-demand network equilibrium models in different multicast sessions, which can be formulated as a convex programming problem. To solve the convex programming problem we use the augmented Lagrangian multiplier algorithm in which the attractive features of the exterior penalty with primal-dual methods and Lagrangian multipliers concepts are combined while curtailing the disadvantage of both. Some numerical results about unicast sessions and multirate multicast sessions are demonstrated through efficient implementations of the augmented Lagrangian multiplier algorithm.
Xuefeng Ma, Jinpeng Huai, Bo Li 0005, Ye Jiao
LCN3
2012 Reliability-aware automatic composition approach for web services
Mu Li 0004, Bo Li 0005, Jinpeng Huai
Sci. China Inf. Sci.2
2012 CyberGuarder: A virtualization security assurance architecture for green cloud computing
Jianxin Li 0002, Bo Li 0005, Tianyu Wo, Chunming Hu, Jinpeng Huai, Lu Liu 0001
Future Gener. Comput. Syst.2
2010 A VMM-Based System Call Interposition Framework for Program Monitoring
abstract
System call interposition is a powerful method for regulating and monitoring program behavior. A wide variety of security tools have been developed which use this technique. However, traditional system call interposition techniques are vulnerable to kernel attacks and have some limitations on effectiveness and transparency. In this paper, we propose a novel approach named VSyscall, which leverages virtualization technology to enable system call interposition outside the operating system. A system call correlating method is proposed to identify the coherent system calls belonging to the same process from the system call sequence. We have developed a prototype of VSyscall and implemented it in two mainstream virtual machine monitors, Qemu and KVM, respectively. We also evaluate the effectiveness and performance overhead of our approach by comprehensive experiments. The results show that VSyscall achieves effectiveness with a small overhead, and our experiments with six real-world applications indicate its practicality.
Bo Li 0005, Jianxin Li 0002, Tianyu Wo, Chunming Hu
ICPADS1
2010 A Prefetching Framework for the Streaming Loading of Virtual Software
abstract
In recent years, the Software as a Service, largely enabled by the Internet, has become an innovative software delivery model. During the streaming execution of virtualization software, the execution will wait until the missing data was downloaded, which greatly influences the user experience. In this paper, we present a block-level prefetching framework for streaming delivery of software based on N-Gram prediction model and an incremental data mining algorithm. The prefetching framework uses the historical block access logs for data mining, then dynamically updates and polishes the prefetching rules. The experimental results show that this prefetching framework achieves a launch time reduced by 10% to 50%, as well as hit rate between 81% and 97%.
Junbin Kang, Chunming Hu, Tianyu Wo, Haibing Zheng, Bo Li 0005
ICPADS6
2010 CloudVO: Building a Secure Virtual Organization for Multiple Clouds Collaboration
abstract
Cloud computing has become a popular computing paradigm in which virtualized and scalable resources are consolidated to provide services over Internet. However, the resource capability of a single cloud is generally limited, and some applications often require various cloud centers over Internet to deliver services together. Therefore, a Virtual Organization (VO) will be a promising approach to integrate services and users across multiple autonomous clouds. However, how to build a secure virtual organization to achieve the collaboration goals is a critical problem, and some issues such as membership agreement, policy conflict and trust management should be adequately addressed. In this paper, we present a framework CloudVO which based on security policies and trust management techniques to provide some flexible and dynamic VO management protocols for clouds. Therefore, CloudVO can achieve inter-cloud collaboration without destroying a cloud's local policies. Based on previous VO security management experiences, we have conducted some preliminary simulations to verify the effectiveness our approaches for cloud computing environments.
Jianxin Li 0002, Bo Li 0005, Zongxia Du, Linlin Meng
SNPD2
2009 EnaCloud: An Energy-Saving Application Live Placement Approach for Cloud Computing Environments
abstract
With the increasing prevalence of large scale cloud computing environments, how to place requested applications into available computing servers regarding to energy consumption has become an essential research problem, but existing application placement approaches are still not effective for live applications with dynamic characters. In this paper, we proposed a novel approach named EnaCloud, which enables application live placement dynamically with consideration of energy efficiency in a cloud platform. In EnaCloud, we use a Virtual Machine to encapsulate the application, which supports applications scheduling and live migration to minimize the number of running machines, so as to save energy. Specially, the application placement is abstracted as a bin packing problem, and an energy-aware heuristic algorithm is proposed to get an appropriate solution. In addition, an over-provision approach is presented to deal with the varying resource demands of applications. Our approach has been successfully implemented as useful components and fundamental services in the iVIC platform. Finally, we evaluate our approach by comprehensive experiments based on virtual machine monitor Xen and the results show that it is feasible.
Bo Li 0005, Jianxin Li 0002, Jinpeng Huai, Tianyu Wo, Qin Li 0014
IEEE CLOUD1