Hao Fu 0003

dblp:64/3069-3 · DBLP profile ↗
← Back
15ranked-venue papers
4as first author
6since 2021 · last 2024
0000-0002-8003-0212ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 4 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Towards System-Level Security Analysis of IoT Using Attack Graphs
abstract
Most IoT systems involve IoT devices, communication protocols, remote cloud, IoT applications, mobile apps, and the physical environment. However, existing IoT security analyses only focus on a subset of all the essential components, such as device firmware or communication protocols, and ignore IoT systems' interactive nature, resulting in limited attack detection capabilities. In this work, we proposeIota, a logic programming-based framework to perform system-level security analysis for IoT systems.Iotagenerates attack graphs for IoT systems, showing all of the system resources that can be compromised and enumerating potential attack traces. In buildingIota, we design novel techniques to scan IoT systems for individual vulnerabilities and further create generic exploit models for IoT vulnerabilities. We also identify and model physical dependencies between different devices as they are unique to IoT systems and are employed by adversaries to launch complicated attacks. In addition, we utilize NLP techniques to extract IoT app semantics based on app descriptions.Iotaautomatically translates vulnerabilities, exploits, and device dependencies to Prolog clauses and invokes MulVAL to construct attack graphs. To evaluate vulnerabilities' system-wide impact, we propose three metrics based on the attack graph, which provide guidance on hardening IoT systems. Evaluation on 127 IoT CVEs (Common Vulnerabilities and Exposures) shows thatIota's exploit modeling module achieves over 80% accuracy in predicting vulnerabilities' preconditions and effects. We applyIotato 37 synthetic smart home IoT systems based on real-world IoT apps and devices. Experimental results show that our framework is effective and highly efficient. Among 27 shortest attack traces revealed by the attack graphs, 62.8% are not anticipated by the system administrator. It only takes 1.2 seconds to generate and analyze the attack graph for an IoT system consisting of 50 devices.
Zheng Fang 0009, Hao Fu 0003, Tianbo Gu, Pengfei Hu 0001, Jinyue Song, Trent Jaeger, Prasant Mohapatra
IEEE Trans. Mob. Comput.2
2023 Integrity and Junkiness Failure Handling for Embedding-based Retrieval: A Case Study in Social Network Search
abstract
Embedding based retrieval has seen its usage in a variety of search applications like e-commerce, social networking search etc. While the approach has demonstrated its efficacy in tasks like semantic matching and contextual search, it is plagued by the problem of uncontrollable relevance. In this paper, we conduct an analysis of embedding-based retrieval launched in early 2021 on our social network search engine, and define two main categories of failures introduced by it, integrity and junkiness. The former refers to issues such as hate speech and offensive content that can severely harm user experience, while the latter includes irrelevant results like fuzzy text matching or language mismatches. Efficient methods during model inference are further proposed to resolve the issue, including indexing treatments and targeted user cohort treatments, etc. Though being simple, we show the methods have good offline NDCG and online A/B tests metrics gain in practice. We analyze the reasons for the improvements, pointing out that our methods are only preliminary attempts to this important but challenging problem. We put forward potential future directions to explore.
Yunxi Guo, Chiyao Shen, Guangdeng Liao, Hao Fu 0003, Pramodh Karanth Prabhakar
SIGIR6
2022 TraceDroid: Detecting Android Malware by Trace of Privacy Leakage
Yueqing Wu, Hao Fu 0003, Minghui Xu 0001, Yifei Zou, Xiaotao Feng, Pengfei Hu 0001
WASA (1)2
2021 Blockchain Meets COVID-19: A Framework for Contact Information Sharing and Risk Notification System
abstract
COVID-19 is a severe global epidemic in human history. Even though there are particular medications and vaccines to curb the epidemic, tracing and isolating the infection source is the best option to slow the virus spread and reduce infection and death rates. There are three disadvantages to the existing contact tracing system: 1. User data is stored in a centralized database that could be stolen and tampered with, 2. User’s confidential personal identity may be revealed to a third party or organization, 3. Existing contact tracing systems [1][2] only focus on information sharing from one dimension, such as location-based tracing, which significantly limits the effectiveness of such systems.We propose a global COVID-19 information sharing and risk notification system that utilizes the Blockchain, Smart Contract, and Bluetooth. To protect user privacy, we design a novel Blockchain-based platform that can share consistent and non-tampered contact tracing information from multiple dimensions, such as location-based for indirect contact and Bluetooth-based for direct contact. Hierarchical smart contract architecture is also designed to achieve global agreements from users about how to process and utilize user data, thereby enhancing the data usage transparency. Furthermore, we propose a mechanism to protect user identity privacy from multiple aspects. More importantly, our system can notify the users about the exposure risk via smart contracts. We implement a prototype system to conduct extensive measurements to demonstrate the feasibility and effectiveness of our system.
Jinyue Song, Tianbo Gu, Zheng Fang 0009, Xiaotao Feng, Yunjie Ge, Hao Fu 0003, Pengfei Hu 0001, Prasant Mohapatra
MASS6
2021 A model checking-based security analysis framework for IoT systems
abstract
IoT systems are revolutionizing our life by providing ubiquitous computing, inter-connectivity, and automated control. However, the increasing system complexity poses huge challenges for security as IoT devices are distributed, highly heterogeneous, and can directly interact with the physical environment. In IoT systems, bugs in device firmware, defects in network protocols, and design flaws in automation rules can lead to system breach or failure. The challenge gets even more escalated as the possible attacks may be chained together in a long sequence across multiple layers, rendering the existing vulnerability analysis frameworks inapplicable. In this paper, we present ForeSee, a model checking-based framework to comprehensively evaluate IoT system security. It builds a multi-layer IoT hypothesis graph by simultaneously modeling all of the essential components in IoT systems, including the physical environment, devices, communication protocols, and applications. The model checker can then analyze the generated hypothesis graph to validate system security properties or generate attack paths if there are any violations. An optimization algorithm is further introduced to reduce the computational complexity of our analysis. Our framework verifies hypothesis graphs with millions of nodes in less than 100 seconds. The illustrative case studies show that our framework can detect more potential threats than the existing approaches.
Zheng Fang 0009, Hao Fu 0003, Tianbo Gu, Zhiyun Qian, Trent Jaeger, Pengfei Hu 0001, Prasant Mohapatra
High Confid. Comput.2
2021 Towards Automatic Detection of Nonfunctional Sensitive Transmissions in Mobile Applications
abstract
While mobile apps often need to transmit sensitive information out to support various functionalities, they may also abuse the privilege by leaking the data to unauthorized third parties. This makes us question: Is the given transmission required to fulfill the app functionality? In this paper, we make the first attempt to automatically identify suspicious transmissions from app visual interfaces, including app names, descriptions, and user interfaces. We design and implement a novel framework called FlowIntent to detect nonfunctional transmissions at both software and network levels. During the exercising of the given apps, FlowIntent automatically detects privacy-sharing transmissions and determines their purposes by utilizing the fact that mobile users rely on visible app interface to perceive the functionality of the app at certain context. The characterizations of nonfunctional network traffic are then summarized to provide network level protection. FlowIntent not only reduces the false alarms caused by traditional taint analysis, but also captures the sensitive transmissions missed by widely-used taint analysis system TaintDroid. Evaluation using 2125 sharing flows collected from more than a thousand running instances shows that our approach achieves about 94 percent accuracy in detecting nonfunctional transmissions.
Hao Fu 0003, Pengfei Hu 0001, Zizhan Zheng, Aveek K. Das, Parth H. Pathak, Tianbo Gu, Sencun Zhu, Prasant Mohapatra
IEEE Trans. Mob. Comput.1
2020 IoTGaze: IoT Security Enforcement via Wireless Context Analysis
abstract
Internet of Things (IoT) has become the most promising technology for service automation, monitoring, and interconnection, etc. However, the security and privacy issues caused by IoT arouse concerns. Recent research focuses on addressing security issues by looking inside platform and apps. In this work, we creatively change the angle to consider security problems from a wireless context perspective. We propose a novel framework called IoTGaze, which can discover potential anomalies and vulnerabilities in the IoT system via wireless traffic analysis. By sniffing the encrypted wireless traffic, IoTGaze can automatically identify the sequential interaction of events between apps and devices. We discover the temporal event dependencies and generate the Wireless Context for the IoT system. Meanwhile, we extract the IoT Context, which reflects user's expectation, from IoT apps' descriptions and user interfaces. If the wireless context does not match the expected IoT context, IoTGaze reports an anomaly. Furthermore, IoTGaze can discover the vulnerabilities caused by the inter-app interaction via hidden channels, such as temperature and illuminance. We provide a proof-of-concept implementation and evaluation of our framework on the Samsung SmartThings platform. The evaluation shows that IoTGaze can effectively discover anomalies and vulnerabilities, thereby greatly enhancing the security of IoT systems.
Tianbo Gu, Zheng Fang 0009, Allaukik Abhishek, Hao Fu 0003, Pengfei Hu 0001, Prasant Mohapatra
INFOCOM4
2020 Towards Learning-automation IoT Attack Detection through Reinforcement Learning
abstract
As a massive number of the Internet of Things (IoT) devices are deployed, the security and privacy issues in IoT arouse more and more attention. The IoT attacks are causing tremendous loss to the IoT networks and even threatening human safety. Compared to traditional networks, IoT networks have unique characteristics, which make the attack detection more challenging. First, the heterogeneity of platforms, protocols, software, and hardware exposes various vulnerabilities. Second, in addition to the traditional high-rate attacks, the low-rate attacks are also extensively used by IoT attackers to obfuscate the legitimate and malicious traffic. These low-rate attacks are challenging to detect and can persist in the networks. Last, the attackers are evolving to be more intelligent and can dynamically change their attack strategies based on the environment feedback to avoid being detected, making it more challenging for the defender to discover a consistent pattern to identify the attack. In order to adapt to the new characteristics in IoT attacks, we propose a reinforcement learning-based attack detection model that can automatically learn and recognize the transformation of the attack pattern. Therefore, we can continuously detect IoT attacks with less human intervention. In this paper, we explore the crucial features of IoT traffics and utilize the entropy-based metrics to detect both the high-rate and low-rate IoT attacks. Afterward, we leverage the reinforcement learning technique to continuously adjust the attack detection threshold based on the detection feedback, which optimizes the detection and the false alarm rate. We conduct extensive experiments over a real IoT attack data set and demonstrate the effectiveness of our IoT attack detection framework.
Tianbo Gu, Allaukik Abhishek, Hao Fu 0003, Huanle Zhang, Debraj Basu 0002, Prasant Mohapatra
WoWMoM3
2019 Keeping Context In Mind: Automating Mobile App Access Control with User Interface Inspection
abstract
Recent studies observe that app foreground is the most striking component that influences the access control decisions in mobile platform, as users tend to deny permission requests lacking visible evidence. However, none of the existing permission models provides a systematic approach that can automatically answer the question: Is the resource access indicated by app foreground? In this work, we present the design, implementation, and evaluation of COSMOS, a context-aware mediation system that bridges the semantic gap between foreground interaction and background access, in order to protect system integrity and user privacy. Specifically, COSMOS learns from a large set of apps with similar functionalities and user interfaces to construct generic models that detect the outliers at runtime. It can be further customized to satisfy specific user privacy preference by continuously evolving with user decisions. Experiments show that COSMOS achieves both high precision and high recall in detecting malicious requests. We also demonstrate the effectiveness of COSMOS in capturing specific user preferences using the decisions collected from 24 users and illustrate that COSMOS can be easily deployed on smartphones as a real-time guard with a very low performance overhead.
Hao Fu 0003, Zizhan Zheng, Sencun Zhu, Prasant Mohapatra
INFOCOM1
2019 ForeSee: A Cross-Layer Vulnerability Detection Framework for the Internet of Things
abstract
The exponential growth of Internet-of-Things (IoT) devices not only brings convenience but also poses numerous challenging safety and security issues. IoT devices are distributed, highly heterogeneous, and more importantly, directly interact with the physical environment. In IoT systems, the bugs in device firmware, the defects in network protocols, and the design flaws in system configurations all may lead to catastrophic accidents, causing severe threats to people's lives and properties. The challenge gets even more escalated as the possible attacks may be chained together in a long sequence across multiple layers, rendering the current vulnerability analysis inapplicable. In this paper, we present ForeSee, a cross-layer formal framework to comprehensively unveil the vulnerabilities in IoT systems. ForeSee generates a novel attack graph that depicts all of the essential components in IoT, from low-level physical surroundings to high-level decision-making processes. The corresponding graph-based analysis then enables ForeSee to precisely capture potential attack paths. An optimization algorithm is further introduced to reduce the computational complexity of our analysis. The illustrative case studies show that our multilayer modeling can capture threats ignored by the previous approaches.
Zheng Fang 0009, Hao Fu 0003, Tianbo Gu, Zhiyun Qian, Trent Jaeger, Prasant Mohapatra
MASS2
2017 LeakSemantic: Identifying abnormal sensitive network transmissions in mobile applications
abstract
Mobile applications (apps) often transmit sensitive data through network with various intentions. Some transmissions are needed to fulfill the app's functionalities. However, transmissions with malicious receivers may lead to privacy leakage and tend to behave stealthily to evade detection. The problem is twofold: how does one unveil sensitive transmissions in mobile apps, and given a sensitive transmission, how does one determine if it is legitimate? In this paper, we propose LeakSemantic, a framework that can automatically locate abnormal sensitive network transmissions from mobile apps. LeakSemantic consists of a hybrid program analysis component and a machine learning component. Our program analysis component combines static analysis and dynamic analysis to precisely identify sensitive transmissions. Compared to existing taint analysis approaches, LeakSemantic achieves better accuracy with fewer false positives and is able to collect runtime data such as network traffic for each transmission. Based on features derived from the runtime data, machine learning classifiers are built to further differentiate between the legal and illegal disclosures. Experiments show that LeakSemantic achieves 91% accuracy on 2279 sensitive connections from 1404 apps.
Hao Fu 0003, Zizhan Zheng, Somdutta Bose, Matt Bishop, Prasant Mohapatra
INFOCOM1
2016 FlowIntent: Detecting Privacy Leakage from User Intention to Network Traffic Mapping
abstract
The exponential growth of mobile devices has raised concerns about sensitive data leakage. In this paper, we make the first attempt to identify suspicious location-related HTTP transmission flows from the user's perspective, by answering the question: Is the transmission user-intended? In contrast to previous network-level detection schemes that mainly rely on a given set of suspicious hostnames, our approach can better adapt to the fast growth of app market and the constantly evolving leakage patterns. On the other hand, compared to existing system-level detection schemes built upon program taint analysis, where all sensitive transmissions as treated as illegal, our approach better meets the user needs and is easier to deploy. In particular, our proof-of- concept implementation (FlowIntent) captures sensitive transmissions missed by TaintDroid, the state-of-the-art dynamic taint analysis system on Android platforms. Evaluation using 1002 location sharing instances collected from more than 20,000 apps shows that our approach achieves about 91% accuracy in detecting illegitimate location transmissions.
Hao Fu 0003, Zizhan Zheng, Aveek K. Das, Parth H. Pathak, Pengfei Hu 0001, Prasant Mohapatra
SECON1
2015 ColorBars: increasing data rate of LED-to-camera communication using color shift keying
abstract
LED-to-camera communication allows LEDs deployed for illumination purposes to modulate and transmit data which can be received by camera sensors available in mobile devices like smartphones, wearable smart-glasses etc. Such communication has a unique property that a user can visually identify a transmitter (i.e. LED) and specifically receive information from the transmitter. It can support a variety of novel applications such as augmented reality through mobile devices, navigation using smart signs, fine-grained location specific advertisement etc. However, the achievable data rate in current LED-to-camera communication techniques remains very low (≈ 12 bytes per second) to support any practical application. In this paper, we present ColorBars, an LED-to-camera communication system that utilizes Color Shift Keying (CSK) to modulate data using different colors transmitted by the LED. It exploits the increasing popularity of Tri-LEDs (RGB) that can emit a wide range of colors. We show that commodity cameras can efficiently and accurately demodulate the color symbols. ColorBars ensures flicker-free and reliable communication even in the presence of inter-frame loss and diversity of rolling shutter cameras. We implement ColorBars on embedded platform and evaluate it with Android and iOS smartphones as receivers. Our evaluation shows that ColorBars can achieve a data rate of 5.2 Kbps on Nexus 5 and 2.5 Kbps on iPhone 5S, which is significantly higher than previous approaches. It is also shown that lower CSK modulations (e.g. 4 and 8 CSK) provide extremely low symbol error rates (< 10--3), making them a desirable choice for reliable LED-to-camera communication.
Pengfei Hu 0001, Parth H. Pathak, Xiaotao Feng, Hao Fu 0003, Prasant Mohapatra
CoNEXT4
2015 Dynamic defense strategy against advanced persistent threat with insiders
abstract
The landscape of cyber security has been reformed dramatically by the recently emerging Advanced Persistent Threat (APT). It is uniquely featured by the stealthy, continuous, sophisticated and well-funded attack process for long-term malicious gain, which render the current defense mechanisms inapplicable. A novel design of defense strategy, continuously combating APT in a long time-span with imperfect/incomplete information on attacker's actions, is urgently needed. The challenge is even more escalated when APT is coupled with the insider threat (a major threat in cyber-security), where insiders could trade valuable information to APT attacker for monetary gains. The interplay among the defender, APT attacker and insiders should be judiciously studied to shed insights on a more secure defense system. In this paper, we consider the joint threats from APT attacker and the insiders, and characterize the fore-mentioned interplay as a two-layer game model, i.e., a defense/attack game between defender and APT attacker and an information-trading game among insiders. Through rigorous analysis, we identify the best response strategies for each player and prove the existence of Nash Equilibrium for both games. Extensive numerical study further verifies our analytic results and examines the impact of different system configurations on the achievable security level.
Pengfei Hu 0001, Hao Fu 0003, Derya Cansever, Prasant Mohapatra
INFOCOM3
2014 Provenance logic: Enabling multi-event based trust in mobile sensing
abstract
With the proliferation of sensor-embedded mobile computing devices, mobile sensing is becoming a popular paradigm to collect information from participating mobile users. Unlike the well-calibrated and well-tested sensor networks, mobile sensing relies on participants with unknown reliability. Data collected from mobile users may be untrustworthy. There are various solutions proposed in the literature for assessing the trustworthiness of the sensing data that describe an individual event or observation. In addition to single-event based trust models, we propose the concept of Provenance Logic, to reason about the logical relations between multiple events by jointly recognizing and linking events from successive sensing observations. We propose an approach that combines logical reasoning and statistical learning techniques. To the best of our knowledge, our work is the first attempt for trust evaluation based on the logical relation among multiple events in the mobile sensing context. We motivate and illustrate our approach with a use case of traffic monitoring mobile sensing. Performance validation has shown that improved trust assessment can be achieved efficiently and effectively on top of single-event based analysis.
Xinlei (Oscar) Wang, Hao Fu 0003, Chao Xu 0009, Prasant Mohapatra
IPCCC2