Jinpeng Wei

dblp:52/5640 · DBLP profile ↗
← Back
39ranked-venue papers
15as first author
11since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 6 first-author · 5 since 2021Systems, architecture and hardware · 9 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 2 first-authorComputer networks · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 CryptMove: Moving Stealthily through Legitimate and Encrypted Communication Channels
abstract
To move laterally inside an enterprise environment, Advanced Persistent Threat (APT) attacks have used multiple techniques. Due to the arms race between the attacks and the defenses, such techniques have evolved over time, with the latest one capable of reusing existing network connections for stealthy lateral movement. However, this technique has limited impact because it cannot reuse encrypted connections that are becoming the norm. In this paper, we present CryptMove, a novel technique that can abuse existing and encrypted channels for lateral movement. CryptMove secretly accesses the memory of the target process to duplicate the security context that is used by the target process to perform encryption/decryption; it also secretly duplicates sockets owned by the target process and injects encrypted malicious commands through these sockets into the encrypted communication channels. Since the location of the security context is specific to the target application, CryptMove employs automated analysis of the target application's binary code, in order to learn a path to reach the security context via a sequence of memory accesses. To demonstrate the feasibility of CryptMove, we built PoC attack tools (on both Windows and Linux) that successfully attacked popular applications (e.g., OpenSSH, PuTTY, WinSCP and WinRM) under 63 different cipher-protocol combinations. We also confirmed that the CryptMove PoC is not detectable by several popular Antivirus and Endpoint Detection and Response systems.
Md Rabbi Alam, Jinpeng Wei, Qingyang Wang 0001
CODASPY2
2025 SVFFNet: A Scale-Aware Voxel Flow Fusion Network for video prediction
Jinpeng Wei, Xueyong Zhang, Yusong Zhai
Comput. Vis. Image Underst.2
2025 Dynamic interactive robust consensus reaching framework for maximum experts considering uncertain cost and adjustment strategy
Jinpeng Wei, Qiuhan Wang, Xiaoxia Xu 0004, Chengwei Zhao 0001, Francisco Javier Cabrerizo
Expert Syst. Appl.1
2025 A dynamic interactive consensus deviation correction system driven by hybrid intelligence and its application to NEV policies
Jinpeng Wei, Qiuhan Wang
Expert Syst. Appl.1
2024 Grunt Attack: Exploiting Execution Dependencies in Microservices
abstract
Loosely-coupled and lightweight microservices running in containers are likely to form complex execution dependencies inside the system. The execution dependency arises when two execution paths partially share component microservices, resulting in potential runtime blocking effects. In this paper, we present Grunt Attack - a novel low-volume DDoS attack that takes advantage of the execution dependencies of microservice applications. Grunt Attack utilizes legitimate HTTP requests to accurately profile the internal pairwise dependencies of all supported execution paths in the target system. By grouping and characterizing all the execution paths based on their pairwise dependencies, the Grunt attacker can target only a few execution paths to launch a low-volume DDoS attack that achieves large performance damage to the entire system. To increase the attack stealthiness, the Grunt attacker avoids creating a persistent bottleneck by alternating the target execution paths within their dependency group. We validate the effectiveness of Grunt attack through experiments of open-source microservices benchmark applications on real clouds (e.g., EC2, Azure) equipped with state-of-the-art IDS/IPS systems and live attack scenarios. Our results show that Grunt attack consumes less than 20% additional CPU resource of the target system while increasing its average response time by over 10x.
Xuhang Gu, Qingyang Wang 0001, Jianshu Liu, Jinpeng Wei
DSN4
2024 Prompting LLM to Enforce and Validate CIS Critical Security Control
abstract
Proper security control enforcement reduces the attack surface and protects the organizations against attacks. Organizations like NIST and CIS (Center for Internet Security) provide critical security controls (CSCs) as a guideline to enforce cyber security. Automated enforcement and measurability mechanisms for these CSCs still need to be developed. Analyzing the implementations of security products to validate security control enforcement is non-trivial. Moreover, manually analyzing and developing measures and metrics to monitor, and implementing those monitoring mechanisms are resource-intensive tasks and massively dependent on the security analyst's expertise and knowledge. To tackle those problems, we use large language models (LLMs) as a knowledge base and reasoner to extract measures, metrics, and monitoring mechanism implementation steps from security control descriptions to reduce the dependency on security analysts. Our approach used few-shot learning with chain-of-thought (CoT) prompting to generate measures and metrics and generated knowledge prompting for metrics implementation. Our evaluation shows that prompt engineering to extract measures, metrics, and monitoring implementation mechanisms can reduce dependency on humans and semi-automate the extraction process. We also demonstrate metric implementation steps using generated knowledge prompting with LLMs.
Jinpeng Wei, Ehab Al-Shaer
SACMAT2
2023 The Novel Data-Driven Robust Maximum Expert Mixed Integer Consensus Models Under Multirole's Opinions Uncertainty by Considering Noncooperators
abstract
In group decision-making, ignoring the existence of uncertain factors causes the decision-making problem to lose its practical significance. Based on the maximum expert consensus model (MECM), we considered the uncertainty of the opinions of the three participating roles by introducing noncooperators. Additionally, three different opinion uncertainty sets were constructed to describe the characteristics of opinion uncertainty more accurately. Furthermore, by applying a robust optimization (RO) method to process uncertain sets, we propose mixed-integer robust MECMs, which reduce the risk of uncertain opinions to decision-makers (DMs). Moreover, numerical experiments used in the passenger satisfaction survey of the Shanghai Metro verified the validity of the models proposed in this article. The characteristics of the models were revealed through sensitivity analysis. Finally, to overcome the relatively highly conservative results of the classic RO method, we construct data-driven opinion uncertainty sets and propose data-driven RO models. Hence, DMs with different risk preferences can choose RO models with different risk levels according to the situation.
Jinpeng Wei, Qiuhan Wang, Dongqing Luan
IEEE Trans. Comput. Soc. Syst.1
2023 symbSODA: Configurable and Verifiable Orchestration Automation for Active Malware Deception
abstract
Malware is commonly used by adversaries to compromise and infiltrate cyber systems in order to steal sensitive information or destroy critical assets. Active Cyber Deception (ACD) has emerged as an effective proactive cyber defense against malware to enable misleading adversaries by presenting fake data and engaging them to learn novel attack techniques. However, real-time malware deception is a complex and challenging task because (1) it requires a comprehensive understanding of the malware behaviors at technical and tactical levels in order to create the appropriate deception ploys and resources that can leverage this behavior and mislead malware, and (2) it requires a configurable yet provably valid deception planning to guarantee effective and safe real-time deception orchestration. This article presents symbSODA, a highly configurable and verifiable cyber deception system that analyzes real-world malware using multipath execution to discover API patterns that represent attack techniques/tactics critical for deception, enables users to create their own customized deception ploys based on the malware type and objectives, allows for constructing conflict-free Deception Playbooks , and finally automates the deception orchestration to execute the malware inside a deceptive environment. symbSODA extracts Malicious Sub-graphs (MSGs) consisting of WinAPIs from real-world malware and maps them to tactics and techniques using the ATT&CK framework to facilitate the construction of meaningful user-defined deception playbooks. We conducted a comprehensive evaluation study on symbSODA using 255 recent malware samples. We demonstrated that the accuracy of the end-to-end malware deception is 95% on average, with negligible overhead using various deception goals and strategies. Furthermore, our approach successfully extracted MSGs with a 97% recall, and our MSG-to-MITRE mapping achieved a top-1 accuracy of 88.75%. Our study suggests that symbSODA can serve as a general-purpose Malware Deception Factory to automatically produce customized deception playbooks against arbitrary malware behavior.
Md Sajidul Islam Sajid, Jinpeng Wei, Ehab Al-Shaer, Qi Duan, Basel Abdeen, Latifur Khan
ACM Trans. Priv. Secur.2
2022 IoTMonitor: A Hidden Markov Model-based Security System to Identify Crucial Attack Nodes in Trigger-action IoT Platforms
abstract
With the emergence and fast development of trigger-action platforms in IoT settings, security vulnerabilities caused by the interactions among IoT devices become more prevalent. The event occurrence at one device triggers an action in another device, which may eventually contribute to the creation of a chain of events in a network. Adversaries exploit the chain effect to compromise IoT devices and trigger actions of interest remotely just by injecting malicious events into the chain. To address security vulnerabilities caused by trigger-action scenarios, existing research efforts focus on validation of the security properties of devices, or verification of the occurrence of certain events based on their physical fingerprints on a device. We propose IoTMonitor, a security analysis system that discerns the underlying chain of event occurrences with the highest probability by observing a chain of physical evidence collected by sensors. We use the Baum-Welch algorithm to estimate transition and emission probabilities and the Viterbi algorithm to discern the event sequence. We can then identify the crucial nodes in the trigger-action sequence whose compromise allows attackers to reach their final goals. The experiment results of our designed system upon the PEEVES datasets show that we can rebuild the event occurrence sequence with high accuracy from the observations and identify the crucial nodes on the attack paths.
Md. Morshed Alam, Md Sajidul Islam Sajid, Weichao Wang, Jinpeng Wei
WCNC4
2022 Coordinating Fast Concurrency Adapting With Autoscaling for SLO-Oriented Web Applications
abstract
Cloud providers tend to support dynamic computing resources reallocation (e.g., Autoscaling) to handle the bursty workload for web applications (e.g., e-commerce) in the cloud environment. Nevertheless, we demonstrate that directly scaling a bottleneck server without quickly adjusting its soft resources (e.g., server threads and database connections) can cause significant response time fluctuations of the target web application. Since soft resources determine the request processing concurrency of each server in the system, simply scaling out/in the bottleneck service can unintentionally change the concurrency level of related services, inducing either under- or over-utilization of the critical hardware resource. In this paper, we propose the Scatter-Concurrency-Throughput (SCT) model, which can rapidly identify the near-optimal soft resource allocation of each server in the system using the measurement of each server’s real-time throughput and concurrency. Furthermore, we implement a Concurrency-aware autoScaling (ConScale) framework that integrates the SCT model to quickly reallocate the soft resources of the key servers in the system to best utilize the new hardware resource capacity after the system scaling. Based on extensive experimental comparisons with two widely used hardware-only scaling mechanisms for web applications: EC2-AutoScaling (VM-based autoscaler) and Kubernetes HPA (container-based autoscaler), we show that ConScale can successfully mitigate the response time fluctuations over the system scaling phase in both VM-based and container-based environments.
Jianshu Liu, Shungeng Zhang, Qingyang Wang 0001, Jinpeng Wei
IEEE Trans. Parallel Distributed Syst.4
2021 SODA: A System for Cyber Deception Orchestration and Automation
abstract
Active Cyber Deception (ACD) has emerged as an effective proactive cyber defense technique that can mislead adversaries by presenting falsified data and allow opportunities for engaging with them to learn novel attack techniques. Adversaries often implement their attack techniques within malware and use it as the medium to steal valuable information. Comprehensive malware analysis is required to understand the malware behaviors at technical and tactical levels to create the honey resources and appropriate ploys that can leverage this behavior and mislead malware and APT adversaries. This paper presents SODA, a cyber deception orchestration system that analyzes real-world malware, discovers attack techniques, creates Deception Playbooks, a set of deception actions, and finally orchestrates the environment to deceive malware. SODA extracts Malicious Sub-graphs (MSGs) consisting of WinAPIs from real-world malware and maps them to MITRE ATT&CK techniques. This MSG-to-MITRE mapping describes how ATT&CK techniques are implemented in malware and, as a result, guides the construction of appropriate deception actions. We conducted comprehensive evaluations on SODA with 255 recent malware samples to demonstrate end-to-end deception effectiveness. We observed an average accuracy of 95% in deceiving the malware with negligible overhead for specified deception goals and strategies. Furthermore, our approach successfully extracted MSGs with a 97% recall and our MSG-to-MITRE mapping achieved a top-1 accuracy of 88.75%. More importantly, SODA can serve as a general purpose malware deception factory to automatically produce customized deception playbooks against arbitrary malware.
Md Sajidul Islam Sajid, Jinpeng Wei, Basel Abdeen, Ehab Al-Shaer, Md. Mazharul Islam 0001, Walter Diong, Latifur Khan
ACSAC2
2020 Mitigating Large Response Time Fluctuations through Fast Concurrency Adapting in Clouds
abstract
Dynamically reallocating computing resources to handle bursty workloads is a common practice for web applications (e.g., e-commerce) in clouds. However, our empirical analysis on a standard n-tier benchmark application (RUBBoS) shows that simply scaling an n-tier application by reallocating hardware resources without fast adapting soft resources (e.g., server threads, connections) may lead to large response time fluctuations. This is because soft resources control the workload concurrency of component servers in the system: adding or removing hardware resources such as Virtual Machines (VMs) can implicitly change the workload concurrency of dependent servers, causing either under- or over-utilization of the critical hardware resource in the system. To quickly identify the optimal soft resource allocation of each server in the system and stabilize response time fluctuation, we propose a novel Scatter-Concurrency-Throughput (SCT) model based on the monitoring of each server's real-time concurrency and throughput. We then implement a Concurrency-aware system Scaling (ConScale) framework which integrates the SCT model to fast adapt the soft resource allocations of key servers during the system scaling process. Our experiments using six realistic bursty workload traces show that ConScale can effectively mitigate the response time fluctuations of the target web application compared to the state-of-the-art cloud scaling strategies such as EC2-AutoScaling.
Jianshu Liu, Shungeng Zhang, Qingyang Wang 0001, Jinpeng Wei
IPDPS4
2020 ShadowMove: A Stealthy Lateral Movement Strategy
Amirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang 0001, Bei-tseng Chu
USENIX Security Symposium2
2019 Tail Amplification in n-Tier Systems: A Study of Transient Cross-Resource Contention Attacks
abstract
Fast response time becomes increasingly important for modern web applications (e.g., e-commerce) due to intense competitive pressure. In this paper, we present a new type of Denial of Service (DoS) Attacks in the cloud, MemCA, with the goal of causing performance uncertainty (the long-tail response time problem) of the target n-tier web application while keeping stealthy. MemCA exploits the sharing nature of public cloud computing platforms by co-locating the adversary VMs with the target VMs that host the target web application, and causing intermittent and short-lived cross-resource contentions on the target VMs. We show that these short-lived cross-resource contentions can cause transient performance interferences that lead to large response time fluctuations of the target web application, due to complex resource dependencies in the system. We further model the attack scenario in n-tier systems based on queuing network theory, and analyze cross-tier queue overflow and tail response time amplification under our attacks. Through extensive benchmark experiments in both private and public clouds (e.g., Amazon EC2), we confirm that MemCA can cause significant performance uncertainty of the target n-tier system while keeping stealthy. Specifically, we show that MemCA not only bypasses the cloud elastic scaling mechanisms, but also the state-of-the-art cloud performance interference detection mechanisms.
Shungeng Zhang, Huasong Shan, Qingyang Wang 0001, Jianshu Liu, Qiben Yan 0001, Jinpeng Wei
ICDCS6
2018 A Natural Language Processing Based Trend Analysis of Advanced Persistent Threat Techniques
abstract
Advanced Persistent Threats (APTs) continue to be a major security problem in today's cyberspace. Understanding APT techniques is necessary for implementing an effective defense against APT attacks. In this paper, we first present a new information retrieval system, called SECCMiner, to assist cybersecurity professionals to more efficiently obtain actionable knowledge regarding APTs from a collected set of unstructured APT reports written in a natural language. It relies on a set of natural language processing and information retrieval techniques to identify adversarial techniques and tactics in given input reports. We then used SECCMiner to conduct a systematic study of existing APT techniques based on a repository of 445 technical reports, containing more than 1.9 million words, on recent APTs. The result includes trend analysis of common APT techniques since 2008, their inter-relationship, and the latest APT techniques that may become influential in the near future (e.g., using PowerShell scripts).
Amirreza Niakanlahiji, Jinpeng Wei, Bei-tseng Chu
IEEE BigData2
2017 The Design of Cyber Threat Hunting Games: A Case Study
abstract
Cyber Threat Hunting is an emerging cyber security activity. Recent studies show that, although similar actions like threat hunting are being actively practiced in some organization, security administrator and policy makers are far from being satisfied with their effectiveness. Most security professionals lack expertise in data analytics while most people with data analytics skills lack security knowledge. To understand the necessity of threat hunting education at university level, we organized a \textit{Threat Hunting Competition} on campus with generated logs. In this paper, we identify skills needed for cyber threat hunting, describe the data generation process as well as the usage of logs to teach threat hunting at universities.
Md. Nazmus Sakib Miazi, Mir Mehedi Ahsan Pritom, Mohamed Shehab, Bill Chu, Jinpeng Wei
ICCCN5
2016 Toward integrity assurance of outsourced computing - a game theoretic perspective
Yongzhi Wang 0001, Jinpeng Wei, Shaolei Ren, Yulong Shen 0001
Future Gener. Comput. Syst.2
2015 MOSE: Live Migration Based On-the-Fly Software Emulation
abstract
Software emulation has been proven useful in many scenarios, such as software testing, malware analysis, and intrusion response. However, fine-grained software emulation (e.g., at the instruction level) incurs considerable execution overhead (about 8x performance degradation), which hampers its use in production settings. In this paper, we propose MOSE (Live Migration based On-the-fly Software Emulation) that combines the performance advantages of hardware virtualization and the fine-grained analysis capability (comprehensiveness) of whole-system software emulation. Namely, a system can run as normal on a hardware-virtualized platform at near native speed, but when needed, it can be live-migrated to an emulator, not necessarily running on the same physical system, for in-depth analysis and triage; when the analysis is complete, the virtual machine can be migrated back to benefit from full hardware-virtualization again. In this way, the performance degradation is only experienced during analysis and triage. To demonstrate this new capability, we built a proof of concept on-the-fly software emulation system, based on QEMU/KVM and DECAF, the Dynamic Executable Code Analysis Framework. We also perform three case studies: automated kernel panic triage, live-patching a security vulnerability, and on-demand symbolic execution, to illustrate on-demand instruction level analysis.
Jinpeng Wei, Lok K. Yan, Muhammad Azizul Hakim
ACSAC1
2015 Toward protecting control flow confidentiality in cloud-based computation
Yongzhi Wang 0001, Jinpeng Wei
Comput. Secur.2
2015 An adaptive middleware design to support the dynamic interpretation of domain-specific models
Karl A. Morris, Mark Allison, Fábio M. Costa, Jinpeng Wei, Peter J. Clarke
Inf. Softw. Technol.4
2014 Bring your own device security issues and challenges
abstract
As mobile devices become prevalent in workplaces, it also creates a unique environment, Bring Your Own Device, in enterprise networks. BYODs are extensions of corporate networks and thus it is essential to secure BYODs to protect enterprise networks. Security tools such as firewalls, anti-virus software, and anti-spam software have been widely used to protect corporate networks. Similar tools are also desired to protect BYODs. BYODs have many advantages, such as reducing companies' cost and increasing users' productivity. However, they also raise many security issues and challenges due to their unique security requirements. This paper summarizes threats and attacks on BYODs and reveals their security issues and challenges. The paper further compares existing BYOD solutions and presents a BYOD security framework that provides guidance for enterprises when adopting BYODs.
Yong Wang 0045, Jinpeng Wei, Karthik Vangury
CCNC2
2014 Static analysis based invariant detection for commodity operating systems
Jinpeng Wei
Comput. Secur.2
2013 Result Integrity Check for MapReduce Computation on Hybrid Clouds
abstract
Large scale adoption of MapReduce computations on public clouds is hindered by the lack of trust on the participating virtual machines, because misbehaving worker nodes can compromise the integrity of the computation result. In this paper, we propose a novel MapReduce framework, Cross Cloud MapReduce (CCMR), which overlays the MapReduce computation on top of a hybrid cloud: the master that is in control of the entire computation and guarantees result integrity runs on a private and trusted cloud, while normal workers run on a public cloud. In order to achieve high accuracy, CCMR proposes a result integrity check scheme on both the map phase and the reduce phase, which combines random task replication, random task verification, and credit accumulation, and CCMR strives to reduce the overhead by reducing cross-cloud communication. We implement our approach based on Apache Hadoop MapReduce and evaluate our implementation on Amazon EC2. Both theoretical and experimental analysis show that our approach can guarantee high result integrity in a normal cloud environment while incurring non-negligible performance overhead (e.g., when 16.7% workers are malicious, CCMR can guarantee at least 99.52% of accuracy with 33.6% of overhead when replication probability is 0.3 and the credit threshold is 50).
Yongzhi Wang 0001, Jinpeng Wei, Mudhakar Srivatsa
IEEE CLOUD2
2013 Constructing E-Tourism platform based on service value broker: A knowledge management perspective
abstract
In our previous work, we have introduced various service value broker (SVB) patterns which integrate business modeling, knowledge management and economic analysis. In this paper, working towards the target of maximizing the potential usage of available resource to achieve the optimization of the satisfaction on both the service provider side and the service consumer side under the guidance of the public administrative, we propose to build the E-Tourism platform based on SVB. This paper demonstrates the mechanism for SVB based E-Tourism framework. The advantages of employing SVB include that the SVB can help to increase the value added in a realtime and balanced manner which conforms to the economical goal of both long run and short run. An experiment is shown using a personnel recommendation system.
Yucong Duan, Yongzhi Wang 0001, Jinpeng Wei, Ajay Kattepur, Wencai Du
IEEE BigData3
2013 IntegrityMR: Integrity assurance framework for big data analytics and management applications
abstract
Big data analytics and knowledge management is becoming a hot topic with the emerging techniques of cloud computing and big data computing model such as MapReduce. However, large-scale adoption of MapReduce applications on public clouds is hindered by the lack of trust on the participating virtual machines deployed on the public cloud. In this paper, we extend the existing hybrid cloud MapReduce architecture to multiple public clouds. Based on such architecture, we propose IntegrityMR, an integrity assurance framework for big data analytics and management applications. We explore the result integrity check techniques at two alternative software layers: the MapReduce task layer and the applications layer. We design and implement the system at both layers based on Apache Hadoop MapReduce and Pig Latin, and perform a series of experiments with popular big data analytics and management applications such as Apache Mahout and Pig on commercial public clouds (Amazon EC2 and Microsoft Azure) and local cluster environment. The experimental result of the task layer approach shows high integrity (98% with a credit threshold of 5) with non-negligible performance overhead (18% to 82% extra running time compared to original MapReduce). The experimental result of the application layer approach shows better performance compared with the task layer approach (less than 35% of extra running time compared with the original MapReduce).
Yongzhi Wang 0001, Jinpeng Wei, Mudhakar Srivatsa, Yucong Duan, Wencai Du
IEEE BigData2
2013 KQguard: Binary-Centric Defense against Kernel Queue Injection Attacks
Jinpeng Wei, Feng Zhu 0015, Calton Pu
ESORICS1
2012 Software Persistent Memory
Jorge Guerra, Leonardo Mármol, Daniel Campello, Carlos Crespo, Raju Rangaswami, Jinpeng Wei
USENIX ATC6
2012 Toward a general defense against kernel queue hooking attacks
Jinpeng Wei, Calton Pu
Comput. Secur.1
2011 VIAF: Verification-Based Integrity Assurance Framework for MapReduce
abstract
MapReduce, a cloud computing paradigm, is gaining popularity. However, like all open distributed computing frameworks, MapReduce suffers from the integrity assurance vulnerability: it takes merely one malicious worker to render the overall computation result useless. Existing solutions are effective in defeating the malicious behavior of non-collusive workers, but are futile in detecting collusive workers. In this paper, we focus on the mappers, which typically constitute the majority of workers, and propose the Verification-based Integrity Assurance Framework (VIAF) to detect both non-collusive and collusive mappers. The basic idea of VIAF is to combine task replication with non-deterministic verification, in which consistent but malicious results from collusive mappers can be detected by a trusted verifier. We have implemented VIAF in Hadoop, an open source MapReduce implementation. Our theoretical analysis and experimental result show that VIAF can achieve high task accuracy while imposing acceptable overhead.
Jinpeng Wei
IEEE CLOUD2
2011 Static analysis based invariant detection for commodity operating systems
abstract
The recent interest in runtime attestation requires modeling of a program’s runtime behavior to formulate its integrity properties. In this paper, we study the possibility of employing static source code analysis to derive integrity models of a commodity operating systems kernel. We develop a precis
Jinpeng Wei, Feng Zhu 0015, Yasushi Shinjo
CollaborateCom1
2010 WS-GraphMatching: a web service tool for graph matching
abstract
Some emerging applications deal with graph data and relie on graph matching and mining. The service-oriented graph matching and mining tool has been required. In this demo we present the web service tool WS-GraphMatching which supports the efficient and visualized matching of polytrees, series-parallel graphs, and arbitrary graphs with bounded feedback vertex set. Its embedded matching algorithms take in account the similarity of vertex-to-vertex and graph structures, allowing path contraction, vertex deletion, and vertex insertions. It provides one-to-one matching queries as well as queries in batch modes including one-to-many matching mode and many-to-many matching mode. It can be used for predicting unknown structured information, comparing and finding conserved patterns, and resolving ambiguous identification of vertices.
Qiong Cheng, Mitsunori Ogihara, Jinpeng Wei, Alex Zelikovsky
CIKM3
2010 Modeling the Runtime Integrity of Cloud Servers: A Scoped Invariant Perspective
abstract
One of the underpinnings of Cloud Computing security is the runtime integrity of individual Cloud servers. Due to the on-going discovery of runtime software vulnerabilities like buffer overflows, it is critical to be able to gauge the integrity of a Cloud server as it operates. In this paper, we propose scoped invariants as a primitive for analyzing the software system for its integrity properties. We report our experience with the modeling and detection of scoped invariants. The Xen Virtual Machine Manager is used for a case study. Our research detects a set of essential scoped invariants that are critical to the runtime integrity of Xen. One such property, that the addressable memory limit of a guest OS must not include Xen's code and data, is indispensable for Xen's guest isolation mechanism. The violation of this property demonstrates that the attacker only needs to modify a single byte in the Global Descriptor Table to achieve his goal.
Jinpeng Wei, Calton Pu, Carlos V. Rozas, Anand Rajan, Feng Zhu 0015
CloudCom1
2010 Modeling and preventing TOCTTOU vulnerabilities in Unix-style file systems
Jinpeng Wei, Calton Pu
Comput. Secur.1
2008 Soft-Timer Driven Transient Kernel Control Flow Attacks and Defense
abstract
A new class of stealthy kernel-level malware, called transient kernel control flow attacks, uses dynamic soft timers to achieve significant work while avoiding any persistent changes to kernel code or data. We demonstrate that soft timers can be used to implement attacks such as a stealthy key logger and a CPU cycle stealer. To defend against these attacks, we propose an approach based on static analysis of the entire kernel, which identifies and catalogs all legitimate soft timer interrupt requests (STIR) in a database. At run-time, a reference monitor in a trusted virtual machine compares each STIR with the database, only allowing the execution of known good STIRs. Our defensive technique has no false negatives because it mediates every STIR execution and prevents execution of all unknown, illegitimate STIRs, and no false positives because the relevant kernel code analyzed was unambiguous. The overhead for this additional security is less than 7% for each of our benchmarks.
Jinpeng Wei, Bryan D. Payne, Jonathon Giffin, Calton Pu
ACSAC1
2008 A Secure Information Flow Architecture for Web Service Platforms
abstract
Current Web service platforms (WSPs) often perform all Web services-related processing, including security-sensitive information handling, in the same protection domain. Consequently, the entire WSP may have access to security-sensitive information, forcing us to trust a large and complex piece of software. To address this problem, we propose ISO-WSP, a new information flow architecture that decomposes current WSPs into a small trusted T-WSP to handle security-sensitive data and a large, legacy untrusted U-WSP that provides the normal WSP functionality. To achieve end-to-end security, the application code is also decomposed into a small trusted part and the remaining untrusted code. The trusted part encapsulates all accesses to security-sensitive data through a secure functional interface (SFI). To ease the migration of legacy applications to ISO-WSP, we developed tools to translate direct manipulations of security-sensitive data by the untrusted part into SFI invocations. Using a prototype implementation based on the Apache Axis2 WSP, we show that ISO-WSP reduces software complexity of trusted components by a factor of five, while incurring a modest performance overhead of few milliseconds per request. We also show that existing applications can be migrated to run on ISO-WSP with a few tens of lines of new and modified code.
Jinpeng Wei, Lenin Singaravelu, Calton Pu
IEEE Trans. Serv. Comput.1
2007 Multiprocessors May Reduce System Dependability under File-Based Race Condition Attacks
abstract
Attacks exploiting race conditions have been considered rare and "low risk". However, the increasing popularity of multiprocessors has changed this situation: instead of waiting for the victim process to be suspended to carry out an attack, the attacker can now run on a dedicated processor and actively seek attack opportunities. This change from fortuitous encountering to active exploiting may greatly increase the success probability of race condition attacks. This point is exemplified by studying the TOCTTOU (Time-of- Check-to-Time-of-Use) race condition attacks in this paper. We first propose a probabilistic model for predicting TOCTTOU attack success rate on both uniprocessors and multiprocessors. Then we confirm the applicability of this model by carrying out TOCTTOU attacks against two widely used utility programs: vi and gedit. The success probability of attacking vi increases from low single digit percentage on a uniprocessor to almost 100% on a multiprocessor. Similarly, the success rate of attacking gedit jumps from almost zero to 83%. These case studies suggest that our model captures the sharply increased risks, and hence the decreased dependability of our systems, represented by race condition attacks such as TOCTTOU on the next generation multiprocessors.
Jinpeng Wei, Calton Pu
DSN1
2007 Towards Scalable and High Performance I/O Virtualization - A Case Study
Jinpeng Wei, Jeffrey R. Jackson, John A. Wiegert
HPCC1
2007 Guarding Sensitive Information Streams through the Jungle of Composite Web Services
abstract
Complex and dynamic web service compositions may introduce unpredictable and unintentional sharing of security-sensitive data (e.g., credit card numbers) as well as unexpected vulnerabilities that cause information leak. This paper describes a fine-grain access policy specification of security-sensitive data items for each component web service. We propose the SF-Guard architecture to enforce these access policies at component web services. A prototype implementation of SF-Guard (on Apache Axis2) and its evaluation show that effective protection of security-sensitive information can be achieved at low overhead (a few percent addition to response time) while preserving the functionality of flexible web service composition.
Jinpeng Wei, Lenin Singaravelu, Calton Pu
ICWS1
2005 TOCTTOU Vulnerabilities in UNIX-Style File Systems: An Anatomical Study
Jinpeng Wei, Calton Pu
FAST1