VLDB 2026 Research / reviewers in the wild / expert
Qixu Liu
dblp:66/1298
· DBLP profile ↗
71ranked-venue papers
5as first author
45since 2021 · last 2026
0000-0003-0895-9585ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 2 first-author · 23 since 2021Computer networks · 12 · 2 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 5 since 2021Human-computer interaction and ubiquitous computing · 7 · 7 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CBR-PAR: LLM-Augmented Case-Based Reasoning for Provenance-Based Alert Reduction
Canhua Chen, Yaqin Cao, Xinyu Li 0001, Baihang Liu, Qixu Liu |
ICCBR | 7 |
| 2026 | IA-VulD: LLM-based Web Vulnerability Attack Detection via Instruction-Aware Embedding
Juxin Xiao, Baihang Liu, Xingchen Chen, Qixu Liu |
ICIC (2) | 7 |
| 2026 | C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS Cognito
Ze Jin, Le Gong, Xiangyi Zeng, Qixu Liu |
SP | 6 |
| 2026 | TGNN: Enhancing Pixel Tracking Detection via LLM-driven Annotation and GAT-powered Structural RepresentationabstractWeb tracking is increasingly pervasive, raising serious concerns about user privacy and security. Among existing techniques, pixel tracking is particularly stealthy and cost-effective, embedding invisible images that exfiltrate user activities to third-party servers. Current defenses, including filter list blocking and conventional machine learning, often fail to capture the cross-site associations that enable pixel tracking to evade detection. Shenping Xiong, Xutong Wang, Ze Jin, Xinyu Liu 0019, Haoqiang Wang, Ru Tan, Qixu Liu |
WWW | 8 |
| 2026 | TLBAC: a zero-trust based cloud-edge-endpoint access control system using trusted labelsabstractAbstract With the rapid development of cloud computing, enterprises have increasingly migrated their servers and services from internal networks to cloud environments. Traditional boundary-based protection mechanisms are no longer sufficient for addressing the security requirements of modern cloud-based systems. As cyberattacks continue to evolve, ensuring the long-term, secure, and reliable operation of increasingly complex IT systems has become a significant challenge. Consequently, researchers have proposed various fine-grained access control approaches. Fine-grained access control remains a significant challenge in complex cloud-edge-endpoint collaboration scenarios. Existing approaches often rely on intricate policy definitions to achieve granular control, which can lead to increased computational overhead and degraded system performance. In this paper, we propose a lightweight, Zero-Trust-based Cloud-Edge-Endpoint Access Control System—TLBAC. By embedding trusted labels into TCP packets at the security endpoint (Endpoint), TLBAC enables traffic blocking and forwarding through access control policies issued by the Security Cloud Brain (Cloud) via the Edge Decision Gateway (Edge). This framework achieves fine-grained access control through trusted labels in a cloud-edge-endpoint architecture. To evaluate the effectiveness of TLBAC, four experiments are designed. The first experiment examines the impact of trusted labels insertion on TCP traffic packet transmission behavior. The experimental results show that even under high-latency, significant jitter, and high packet loss conditions in an LTE network, TCP packets with embedded trusted labels maintain stable and reliable data transmission. The second experiment assesses the resource consumption of TLBAC, focusing on CPU and memory overhead. The experimental results indicate that TLBAC’s resource consumption rate is only ± 0.2%. The third experiment simulates a realistic attack environment by launching attacks against the protected system from an adversarial perspective to validate TLBAC’s defensive capabilities. The experimental results demonstrate that TLBAC successfully detected and blocked all attacks in over thirty vulnerability cases involving different components, versions, and exploitation methods. The fourth experiment evaluates the practical operational capability of TLBAC in a multi-tenant environment. The results show that TLBAC can achieve connection-oriented fine-grained access control with low latency, while maintaining policy accuracy and isolation in multi-tenant scenarios. Ru Tan, Baihang Liu, Yaqin Cao, Qixu Liu |
Cybersecur. | 8 |
| 2025 | ExtFPDet: A CNN-Based Detection Framework for Browser Extensions FingerprintingabstractWith the widespread use of modern browser extensions, user experience has been significantly enhanced via embedding ancillary functionality into the original webpage. The rapid development of Web tracking technology has raised privacy and security concerns, as it generates a unique identifier for users according to the diversity of installed extensions and further prompts the profiling of users. However, due to the ignorance of potential privacy risks, there is no effective method to detect browser extension fingerprinting. In this paper, we propose ExtFPDet, a CNN-based detection framework to recognize browser extension fingerprinting in websites, which fills the gap in this area. Based on the preliminary investigation, the approaches to fingerprint browser extensions can be summarized into 2 categories according to the distinctive behaviors, including resource traversing and side-channel exploring. In order to extract effective features to reflect extensions fingerprinting, ExtFPDet focuses on the structure and content in the program dependency graph of Javascript files. The generated feature vector assists the CNN-based classification model to detect the extension fingerprinting, for which we perform a systematic detection on Tranco top 10K websites. Eventually, the result is evaluated by randomly sampling and manually checking, which shows superior detection capabilities of ExtFPDet. Wei Liu 0243, Xiaoxi Wang, Yun Feng 0003, Xinyu Liu 0019, Le Gong, Kerui Huang, Yaqin Cao, Qixu Liu |
CSCWD | 8 |
| 2025 | DAB-LLM: Detection of Anomalies in API Call Behavior Based on Large Language ModelabstractAPIs are now central to digital transformation, carrying the core business logic and sensitive data of enterprises. Attackers can gain access to important information systems and sensitive data by attacking APIs, allowing them to steal high-value data. Besides being vulnerable to traditional attacks, APIs also face unique threats tailored to their characteristics, such as attacks targeting API business logic threats. This type of API attacks are complex, and the attack requests are very similar to legitimate traffic, making them difficult to distinguish from benign requests. Therefore, traditional single-request detection methods are ineffective against such complex attacks. By employing intelligent context-aware natural language processing techniques, we can understand API call behavior and establish a baseline of normal API call behavior to identify anomalies. In this paper, we propose DAB-LLM, a model for Detecting Anomalies in API call Behavior based on Large Language Model. Our approach utilizes extraction and representation methods for API call chains and API call graphs, prompt optimization algorithm, and LoRA fine-tuning technique to enable the model to deeply understand of API call behavior and enhance detection capabilities. Experimental results indicate that DAB-LLM excels in detecting attack behaviors and anomalies in API calls, achieving an f1-score of 97.35% along with significant improvements in recall rate, accuracy and precision. The overall performance of the model shows that our proposed model significantly outperforms other models in API call behavior anomaly detection. Fangjiao Zhang, Baihang Liu, Baoxu Liu, Qixu Liu |
CSCWD | 6 |
| 2025 | VulKiller: Java Web Vulnerability Detection with Code Property Graph and Large Language ModelsabstractIn recent years, web application development has become more efficient, yet vulnerabilities still pose significant risks. Traditional static and dynamic detection techniques are prone to false positives and negatives, making it challenging for small and medium-sized developers with limited security knowledge to accurately assess the results. To address these challenges, we introduced VulKiller, an automated vulnerability detection tool powered by large language models (LLM). VulKiller leverages static analysis to convert application code into Code Property Graphs (CPG) and utilizes Neo4j to identify high-risk method call chains. By designing structured interactions with ChatGPT, these call chains and corresponding code are transformed into Proofs of Concept (PoCs), which are then parsed into attack payloads and evaluated by a vulnerability monitor for effectiveness. In comparison with traditional tools, VulKiller excels in reducing false positives and negatives. Additionally, in zero-day vulnerability detection experiments, VulKiller identified 12 zero-day vulnerabilities. Our results offer significant encouragement for using LLM to enhance vulnerability detection. Xingchen Chen, Baizhu Wang, Mengjun Zhang, Yaqin Cao, Qixu Liu |
ICASSP | 5 |
| 2025 | Hidden and Lost Control: on Security Design Risks in IoT User-Facing Matter Controller
Haoqiang Wang, Yiwei Fang, Ze Jin, Emma Delph, Xiaojiang Du, Qixu Liu, Luyi Xing |
NDSS | 7 |
| 2025 | RBAClock: Contain RBAC Permissions through Secure SchedulingabstractKubernetes has emerged as the de facto standard for container orchestration. However, existing container scheduling strategies prioritize QoS, leading to the co-location of pods with varying permission levels on the same node. This not only introduces risks of privilege escalation but also facilitates the spread of pods with risky permissions across the cluster, exacerbating the potential for attackers to elevate their privileges. In this work, our goal is to mitigate permission disparity among pods on each node, thereby reducing the risk of privilege escalation from co-location attack and curbing the spread of high-risk permissions across the cluster. We introduce a novel metric, Extraneous Risk Privileges (ERP), to quantify additional privileges derived from the combination of RBAC permissions and cluster parameters that are utilized by other pods on the node but not by the target pod itself. The RBAClock scheduling framework is designed to minimize ERP increase during pod placement, prioritizing the aggregation of pods with similar risk profiles and isolation of those with divergent privileges. Experimental evaluations across 24 CNCF applications demonstrate that, compared to the default scheduler, RBAClock alone achieves an average reduction of 41.46% in aggregated privileges in cluster, 64.63% in privilege escalation risk, and 34.59% in high-privilege nodes proportion, with an 8% performance tradeoff. Notably, our investigation uncovered privilege escalation risks in the Kubernetes services of two major cloud providers, Alibaba Cloud and Tencent Cloud, and demonstrated that RBAClock can effectively mitigate these threats. Qingwang Chen, Ru Tan, Yuqi Shu, Zhou Tong, Haoqiang Wang, Ze Jin, Qixu Liu |
RAID | 8 |
| 2025 | DEPHP: A Source Code Recovery Method for PHP Bytecode with Improved Structural AnalysisabstractOver the past decade, PHP has consistently been one of the most popular server-side programming languages among developers for web development. To protect intellectual property, various PHP source code obfuscation and encryption methods have been developed, which has led to difficulties in performing security analysis on PHP source code. Previous work has demonstrated the feasibility of recovering source code by extracting bytecode from PHP during dynamic execution. However, there is still a lack of a universal decompilation method for this kind of bytecode, tailored to PHP’s unique syntax. Thus, we propose a systematic decompilation framework for PHP bytecode. First, we design a unified intermediate representation that eliminates the differences between bytecodes from different PHP versions. Then, we introduce a structural analysis algorithm specifically for PHP syntax, improving upon existing methods to better accommodate PHP’s unique syntax. We use over 3 million lines of PHP code as a dataset and compiled it into PHP bytecode. After decompiling it with our method, we successfully recovered 92% of the classes and 85% of the methods. Furthermore, from the encrypted dataset containing 37 SQL injection and 31 XSS vulnerability patterns, we fully restored the original vulnerability patterns and reconstructed the exploitation chains. Furthermore, we identified a series of vulnerabilities in real-world projects and were assigned 6 new CVE IDs1, demonstrating the correctness of our method and its ability to assist in static analysis for vulnerability discovery.1CVE-2025-45046, CVE-2025-45047, CVE-2025-45048, CVE-2025-45049, CVE-2025-45050, CVE-2025-45052 Shiwu Zhao, Ningjun Zheng, Ruizhi Feng, Xingchen Chen, Ru Tan, Qixu Liu |
RAID | 7 |
| 2025 | Implicit Device Tracking Under the Multimedia Technology WaveabstractThe proliferation of Android multimedia applications highlights the critical role of mobile sensors. Inherent manufacturing defects enable implicit device identification without consent, facilitating covert tracking. This bolsters security through reliable malicious actor tracking, unlike spoof-vulnerable explicit methods. However, prior sensor-based identification suffers from signal noise and device degradation, compromising robustness.In this paper, we propose AMSensorFP, a novel Android implicit device tracking framework. We develop an application to collect device information and multi-sensor data to construct device fingerprints. Subsequently, we build a dataset by performing pairwise difference calculations on the collected fingerprints. And then enhance the dataset with Gaussian noise to improve data diversity and robustness. An autoencoder reduces feature dimensionality, and the processed features are fed into a BiLSTM model with a multi-head attention mechanism, enabling effective fingerprint recognition. Experimental results show that AMSensorFP achieves 99.88% accuracy and 97.34% true positive rate(TPR), significantly outperforming existing methods. Ablation analysis further highlights the contributions of each module and feature in the framework. AMSensorFP delivers a reliable solution for device tracking and security enhancement. Xiaoxi Wang, Kerui Huang, Chunyang Zheng, Jinhe Ren, Qixu Liu |
SMC | 8 |
| 2025 | CTF: Hybrid Multi-scale Contrastive Transformer for Website Fingerprinting AttackabstractWebsite Fingerprinting (WF) attacks, a methodology that allows observers to infer visited websites through encrypted traffic analysis, are usually employed for evaluating the security of anonymous networks like Tor. Although deep learning-based methods have demonstrated significant success in recent studies, existing approaches exhibit limitations. They are insufficient in modeling the intricate characteristics of traffic patterns, which leads to compromised accuracy in identifying challenging samples. To address these limitations, we propose CTF, a novel WF attack comprising three key components: (1) extraction of Hybrid Multi-scale Traffic Features (HMTF) integrating spatio-temporal information, (2) a novel deep learning framework that synergizes CNN for spatial pattern recognition and Transformer for temporal dependency modeling within HMTF, and (3) a supervised contrastive learning mechanism to enhance discriminative capability across website fingerprints. Experimental evaluations across multiple benchmark datasets reveal that CTF achieves 99.09% accuracy in Closed-World scenarios, showing enhanced robustness against four SOTA WF defense mechanisms. Juxin Xiao, Yanhui Chen, Qixu Liu |
SMC | 7 |
| 2025 | PROV-LLM: Advanced Persistent Threat Detection Based on Process Behavior Subgraphs Using Large Language ModelsabstractAdvanced Persistent Threats (APTs) pose significant cybersecurity challenges through stealthy, multi-stage attacks that leverage zero-day exploits and evasive tactics. While provenance graph-based methods show promise for APT detection, existing approaches face three critical limitations: (i) inappropriate granularity levels, (ii) insufficient critical context, and (iii) lack of interpretable output. To address these challenges, we propose Prov-LLM, a novel LLM-enhanced detection system that leverages process-centric behavioral subgraphs. Our approach first decomposes large provenance graphs into process-centered graphs, enriching them with key attributes such as process names, execution paths, and command-line arguments. Prov-LLM then utilizes a Retrieval-Augmented Generation (RAG) framework to establish a baseline of benign behavior, enabling LLMs to perform context-aware anomaly detection via semantic reasoning. Finally, the system reconstructs anomalous process behavior subgraphs and generates human-readable explanations of attacks, offering security analysts intuitive insights for investigation. We evaluate Prov-LLM on three DARPA OPTC attack datasets: Plain PowerShell Empire, Custom PowerShell Empire, and Malicious Upgrade. Results demonstrate that Prov-LLM outperforms state-of-the-art methods in accuracy, precision, and recall. Notably, the synergy between process behavior subgraphs and LLMs significantly reduces analysts’ workload during attack investigations. Canhua Chen, Qixu Liu |
TrustCom | 7 |
| 2025 | Chaos of Functionalities: Understanding Security Risks in Heterogeneity of IoT Matter ControllersabstractThe Matter protocol has rapidly become the new standard for secure and interoperable IoT connectivity, adopted by major industry players and integrated into millions of devices. A core feature of Matter is its ability to support device sharing across users and controllers. However, as vendors independently implement Matter and blend it with their proprietary ecosystems, significant inconsistencies emerge. These inconsistencies result in heterogeneous user capabilities depending on which Matter Controller (MC) or OEM app is used, introducing a new and largely unexplored class of security risks. In this work, we present the first systematic study on security risks stemming from heterogeneous Matter controller implementations in shared device environments. We analyze 18 major IoT vendors and uncover a novel category of vulnerabilities, which we term MCG (Matter Controller Gaps), where differences in controller capabilities can enable unauthorized access or stealthy device manipulation. To uncover these flaws at scale, we develop MCG-Checker, a semi-automated analysis tool that combines large language models and UI automation to detect control disparities across Matter controllers and OEM apps. Using MCG-Checker, we evaluate 14 Matter controllers and 8 OEM apps, discovering 5 previously unknown attack vectors affecting top vendors such as Google, Apple, and Amazon Alexa. Our work reveals critical design and implementation issues in current Matter deployments. We offer concrete recommendations for protocol designers, vendors, and end users to address these gaps, contributing to more secure and predictable IoT ecosystems. Yiwei Fang, Haoqiang Wang, Ze Jin, Qixu Liu |
TrustCom | 4 |
| 2025 | Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integrationabstractAbstract As cloud-native technologies continue to evolve, containerization and orchestration have become fundamental for deploying microservices. However, this advancement introduces significant security vulnerabilities, particularly due to vulnerabilities and misconfigurations that grant attackers excessive control over clusters. Existing works, including model-based learning and static rule-based approaches, suffer from limitations such as false positives and maintenance overhead, which pose significant challenges to cloud-native security. To mitigate intrusion targeting container orchestration, we present ShadowKube, an innovative active defense framework tailored for Kubernetes. ShadowKube integrates behavioral monitoring with shadow honeypots to effectively detect and neutralize anomalous behavior. By establishing behavioral baselines to identify deviations and converting compromised nodes into honeypots, ShadowKube isolates and traps attackers, thereby mitigating the threats they pose. Comprehensive evaluations demonstrate ShadowKube’s ability to detect and migrate exploitations across 43 severe CVEs and 7 common misconfiguration types. Deployment in a live environment further validates its effectiveness, with ShadowKube identifying 635 attack attempts, successfully decoying 23 active attacks. Additionally, ShadowKube could isolate attackers and convert affected nodes into honeypots within seconds. These results highlight ShadowKube’s efficacy as a robust solution for enhancing security in Kubernetes clusters, offering a proactive defense mechanism against both current and emerging threats. Qingwang Chen, Ru Tan, Ze Jin, Juxin Xiao, Fangjiao Zhang, Qixu Liu |
Cybersecur. | 8 |
| 2025 | WTDetect: a third-party website tracking detection framework for android applicationsabstractAbstract With the development of HTML5, tracking technologies have evolved dramatically and gradually moved from cookies to browser fingerprinting. Previous research has shown that there are more serious privacy threats associated with tracking behavior on third-party websites. However, by focusing on third-party websites that are loaded in the browser, the researchers overlooked the fact that third-party websites are also present in Android applications, where tracking is easy to perform and definitely covert to detect. In this study, we propose WTDetect, an Android third-party website tracking detection framework. Based on the parsing of view tree and the generation of function call stack, WTDetect automatically locates and captures the source code of third-party websites. To explore the direction of sensitive data flow, WTDetect performs static taint analysis on the program dependency graph for each JavaScript file. Finally, a fine-grained classification model is used to detect the tracking behavior. WTDetect is used to perform a measurement study of tracking behavior on 1090 captured Android third-party websites. The result outlines that 14.68% of third-party websites in Android applications tracking users without any access warnings and user authorization, which directly leads to the risk of privacy leakage. Wei Liu 0243, Xinyu Liu 0019, Yun Feng 0003, Kerui Huang, Ze Jin, Yaqin Cao, Qixu Liu |
Cybersecur. | 8 |
| 2025 | LLM4TDG: test-driven generation of large language models based on enhanced constraint reasoningabstractAbstract With the evolution of modern software development paradigms, component reuse, and low-code approaches have emerged as mainstream in software development. However, developers often lack an in-depth understanding of reused code. The inability of components to operate autonomously leads to insufficient testing of software functionalities and security, further exacerbating the contradiction between the increasing complexity of software architectures and the demand for accurate and efficient software automation testing. This, in turn, increases the frequency of software supply chain security incidents. This paper proposes a test-driven generation framework, LLM4TDG, based on large language models (LLMs). By formally defining the constraint dependency graph and converting it into context constraints, LLMs’ ability to understand natural language descriptions such as test requirements and documents is enhanced. Constraint reasoning and backtracking mechanisms are then used to generate test drivers that satisfy the defined constraints automatically. Using the EvalPlus dataset, we evaluate the comprehensive capabilities of LLM4TDG in test case generation using four general-domain LLMs and five code-generation-domain LLMs. The experimental results indicate that our approach significantly enhances LLMs’ ability to comprehend constraints in testing objectives, achieving a 47.62% increase in constraint understanding across 147 testing tasks. Employing LLM4TDG significantly improves the average pass@k metric of all LLMs by 10.41%. The pass@k metric for CodeQwen-chat has improved by up to 18.66%. The metric surpasses the state-of-the-art GPT-4, with a performance of 92.16% on HUMANEVAL and 87.14% on HUMANEVAL+, which enhances the error correction and functional correctness in test-driven code generation. Meanwhile, Our experiments were conducted on a dataset of Python third-party libraries containing malicious behavior in the context of security testing tasks, validating the effectiveness of our method in real-world applications and its generalization capabilities. Jingqiang Liu, Ruigang Liang, Xiaoxi Zhu, Qixu Liu |
Cybersecur. | 6 |
| 2025 | XFP-recognizer: detecting cross-file browser fingerprintingabstractAbstract In recent years, the evolving browser fingerprinting technology has posed significant challenges and constant demands on detection methods. Research related to malicious code shows that cross-file techniques, which disperse code into multiple files, can resist current detection methods. To address this challenge, we introduce cross-file tracking technology into browser fingerprinting, constructing cross-file browser fingerprinting (XFP). The dispersion of files and features in XFP effectively circumvents detection methods that primarily focus on single-file tracking. In this paper, we propose XFP-Recognizer, a Random Forest-based detection method for identifying XFP behaviors. XFP-Recognizer aggregates code files and dynamic APIs by constructing function call relationship graphs (FCRgraphs). It extracts dynamic and static features to train random forest models for detecting and classifying the aggregated files, and then backtracks based on FCRgraphs to mark original scripts. To validate our method, we implement a code-splitting algorithm and constructed a cross-file tracking dataset to address the lack of XFP in real-world scenarios. We combine this dataset with the dataset of Alexa Top-10K websites in different proportions to verify the effectiveness of XFP-Recognizer. The results show that XFP-Recognizer achieved an Accuracy of 92.25%, a Precision of 97.01% and an AUC of 0.9152 in recognizing browser fingerprinting, demonstrating superior performance in both single-file and cross-file tracking. XFP-Recognizer complements existing detection methods, and the constructed split dataset also serves as a foundational resource for future research. Xiaoxi Wang, Zhenxu Liu, Chunyang Zheng, Xinyu Liu 0019, Wei Liu 0243, Qixu Liu |
Cybersecur. | 7 |
| 2024 | SDM-GAT: StylisticFP Detection Method Based on Graph Attention Network
Xiaoxi Wang, Chunyang Zheng, Yaqin Cao, Qixu Liu |
ADMA (3) | 6 |
| 2024 | MemAPIDet: A Novel Memory-resident Malware Detection Framework Combining API Sequence and Memory FeaturesabstractMemory-resident malware has become a huge threat to cybersecurity. They perform malicious operations only in memory and are difficult to detect by existing technologies. Existing malware detection solutions fail to effectively extract API sequence’s semantic features and memory data features related to malicious behaviors in memory dumps. This research paper presents a novel detection framework to address these limitations. It first extracts intrinsic semantic features of API sequences from memory data using a fine-tuned BERT, then extracts executable data features from memory dumps using a pre-trained ResNet34 neural network. It then splices the two features to train a deep neural network-based detection model. We created a high-quality dataset with 2180 benign programs and 1897 recent memory-resident malware samples. We implement MemAPIDet for Windows 10. It performs better than the state-of-the-art methods with a prediction accuracy of 97.78% Kezhen Huang, Yun Feng 0003, Canhua Chen, Jinli Zhang, Yuqi Shu, Xing Tian, Qixu Liu |
CSCWD | 8 |
| 2024 | MalPolymer: A Threat Identification System Utilizing Cognate Malicious Login Behavior DetectionabstractAccurate attribution and tracing of cyber attacks require a comprehensive understanding of the resources employed by malicious actors. However, Indicators of Compromise (IoCs) can only reveal a portion of the attacker’s assets. To enhance the capability of clue expansion, this study introduces a novel approach to associating attack sources, facilitating the identification of additional IP addresses and subnets that may correspond to a single malicious actor. We focus on the scenario of compromised email accounts and utilize login logs as foundational data. We employ Gaussian Mixture Models (GMM) to construct a reference model that captures known malicious behaviors. Then, we utilize a genetic algorithm to filter and select candidate subnets that exhibit the attack patterns outlined by the reference model. Through evaluation on real-world data, we demonstrate the effectiveness of our proposed method in successfully attributing multiple attack sources to a single attacker, thereby providing valuable insights for manual investigations. Ru Tan, Yaqin Cao, Xutong Wang, Qixu Liu, Xiang Cui |
CSCWD | 5 |
| 2024 | TaDFusion: Infrared and Visible Image Fusion Network Based on The Target Detection Task-driven MethodabstractThe combination of visible and infrared images is intended to facilitate complex vision tasks by combining target information and rich texture. By focusing solely on visual perception enhancement, current fusion algorithms do not take into account performance on high-level vision tasks. As a solution to these problems, this research develops a high-level vision task-driven image fusion network (TaDFusion) that combines image fusion and target identification tasks. Through cascading of the image fusion and target detection modules we can significantly improve the performance of advanced vision tasks by using detection loss to guide the information back to the image fusion module. Our algorithm provides better texture preservation and pixel intensity distribution than existing methods based on extensive comparisons and generalization experiments. Besides our framework demonstrates the greatest advantages in facilitating advanced vision tasks by not only generating visually appealing fused images but also detecting higher mAPs than state-of-the-art methods, according to a comparison of the performance of various fusion algorithms in target detection tasks. Shaohui Jin, Qixu Liu, Hao Liu 0125, Mingliang Xu 0001 |
IJCNN | 2 |
| 2024 | TAD-LLM: API Traffic Anomaly Detection Based on Large Language ModelabstractAPIs are increasingly prevalent in application environments, carrying the core business logic and sensitive data of enterprises, and have increasingly become the target of cyber attackers. The proportion of web attacks targeting APIs has exceeded half. The widespread use of APIs has expanded the attack surface, posing serious security challenges. Security risks, such as unauthorized access, misuse of business logic, data breaches, and complex cyber attacks, have intensified. Tr aditional security measures have proven inadequate in addressing API threats. There is an urgent demand for a more contextually aware and intelligent security mechanism capable of effectively mitigating API attacks. We proposed a novel model TAD-LLM based on Large Language Model for anomaly detection in API traffic. By using S2GS data transformation method, prompt optimization algorithm and LoRA fine-tuning technique, enables the model to acquire a profound comprehension of domain-specific knowledge in more elaborate detail, thereby enhancing the overall detection capability. Experimental results demonstrate that the proposed model TAD-LLM makes a significant advancement in securing APIs against cyber threats. The average f1-score of TAD-LLM reaches 99.27% in complex API attack scenarios. There are also notable improvements in precision, recall, and accuracy. Moreover, the overall performance of the model indicates that the model we proposed outperforms other models significantly and exhibits superior capability in handling complex API attack scenarios and advanced API attack techniques. It is worth noting that our model also shows strong performance on CSIC 2010, a widely used common http traffic dataset. Baoxu Liu, Jingqiang Liu, Fangjiao Zhang, Qixu Liu |
MSN | 6 |
| 2024 | A comprehensive analysis of website fingerprinting defenses on Tor
Xi Xiao 0001, Le Yu 0002, Bin Zhang 0048, Qixu Liu, Xiapu Luo |
Comput. Secur. | 6 |
| 2024 | Dissecting zero trust: research landscape and its implementation in IoTabstractAbstract As a progressive security strategy, the zero trust model has attracted notable attention and importance within the realm of network security, especially in the context of the Internet of Things (IoT). This paper aims to evaluate the current research regarding zero trust and to highlight its practical applications in the IoT sphere through extensive bibliometric analysis. We also delve into the vulnerabilities of IoT and explore the potential role of zero trust security in mitigating these risks via a thorough review of relevant security schemes. Nevertheless, the challenges associated with implementing zero trust security are acknowledged. We provide a summary of these issues and suggest possible pathways for future research aimed at overcoming these challenges. Ultimately, this study aims to serve as a strategic analysis of the zero trust model, intending to empower scholars in the field to pursue deeper and more focused research in the future. Chunwen Liu, Ru Tan, Yun Feng 0003, Ze Jin, Fangjiao Zhang, Qixu Liu |
Cybersecur. | 8 |
| 2023 | ANDetect: A Third-party Ad Network Libraries Detection Framework for Android ApplicationsabstractThird-party advertising libraries, which furnish mobile applications with ads, offer a revenue stream for Android application developers. However, the loaded ads potentially expose application users to privacy infringements and security threats. For instance, tracking scripts embedded in third-party ads monitor user behavior and can entice users into downloading malicious files. Therefore, the detection of advertising libraries in mobile applications is crucial for mobile security protection and serves as the foundation for preventing third-party ads from compromising user privacy. Xinyu Liu 0019, Ze Jin, Wei Liu 0243, Xiaoxi Wang, Qixu Liu |
ACSAC | 6 |
| 2023 | AAP: Defending Against Website Fingerprinting Through Burst Obfuscation
Xi Xiao 0001, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Qixu Liu |
ADMA (5) | 6 |
| 2023 | DeepCall: A Fast and Robust Malware Classification System with DGCNN and Function Call GraphabstractMalware has been researched hot off the press in cyber security for a long time. With the rise of machine learning algorithms, many research works attempt to apply machine learning-based methods in malware classification. However, existing machine learning-based malware classification methods rely on many various features extracted from malware samples, which may make their system lose processing speed and generality between different operational environments. These methods can not cope with massive malware samples. To improve generality and speed of classification system, we proposed a new model to classify malware with function call graphs (FCGs) extracted from their assembly code. According to previous studies, FCG is a generic feature and it is stable against metamorphic malware. Moreover, FCG extraction is not a time-consuming process. We select DGCNN (Deep Graph Convolutional Neural Network) to embed structural information inherent in FCGs for malware classification. It can make the best of the structure information stored in FCGs and make the results more convincing and accurate compared with other methods using traditional features. We use two large datasets from different operational environments containing nearly 20K malware samples to evaluate our proposed model. The experimental results show that it can classify malware represented as FCG with satisfactory accuracy and faster processing speed. Yanhui Chen, Yun Feng 0003, Chengchun Wang, Qixu Liu |
CSCWD | 5 |
| 2023 | Tabby: Automated Gadget Chain Detection for Java Deserialization VulnerabilitiesabstractJava is one of the preferred options of modern developers and has become increasingly more prominent with the prevalence of the open-source culture. Thanks to the serialization and deserialization features, Java programs have the flexibility to transmit object data between multiple components or systems, which significantly facilitates development. However, the features may also allow the attackers to construct gadget chains and lead to Java deserialization vulnerabilities. Due to the highly flexible and customizable nature of Java deserialization, finding an exploitable gadget chain is complicated and usually costs researchers a great deal of effort to confirm the vulnerability. To break such a dilemma, in this paper, we introduced Tabby, a highly accurate framework that leverages the Soot framework and Neo4j graph database for finding Java deserialization gadget chains. We leveraged Tabby to analyze 248 Jar files, found 80 practical gadget chains, and received 7 CVE-IDs from Xstream and Apache Dubbo. They both improved the security design to deal with potential security risks. Xingchen Chen, Baizhu Wang, Ze Jin, Yun Feng 0003, Xincheng Feng, Qixu Liu |
DSN | 7 |
| 2023 | IMaler: An Adversarial Attack Framework to Obfuscate Malware Structure Against DGCNN-Based Classifier via Reinforcement LearningabstractInspired by the success of graph neural network in graph data classification, graph neural networks have been widely used in malware classification and they have been proven to be the state-of-the-art malware classification models. However, most of existing adversarial samples generation techniques against machine learning-based malware classification models modify malware samples by inserting dead codes or modifying binaries directly, which is less effective against graph neural network-based malware classification models. In this paper, we propose an adversarial attack framework powered by reinforcement learning to spoof the deep graph convolutional neural network (DGCNN)-based malware classifiers called Intelligent Malware Evader (IMaler). We construct functionality-preserved manipulations based on traditional obfuscation techniques that can modify both node features and structural features of malware. The reinforcement learning agent can make optimal decisions on how to obfuscate malware with functionality-preserved manipulations. We use a large dataset with more than 10,000 samples to evaluate the performance of IMaler and use a random agent attack as a baseline attack. The experiment results show that IMaler can achieve a significantly higher evasion rate (88.26%) than the random agent attack with fewer query times. Yanhui Chen, Yun Feng 0003, Zhi Wang 0018, Chengchun Wang, Qixu Liu |
ICC | 6 |
| 2023 | SWDNet: Stealth Web Shell Detection Technology based on Triplet NetworkabstractAmid escalating cyber threats, websites have emerged as predominant targets for attackers employing web shells to maintain extended control. Web shells, frequently used by Advanced Persistent Threat (APT) groups, often result in significant damage, despite the conspicuous lack of focused academic research on their detection. This paper illuminates the stealth variant of the web shell, covertly embedded within benign files, and addresses the unique detection challenges presented by their covert nature and the dearth of targeted datasets. In response to these challenges, we construct three datasets: small web shells, benign files, and stealth web shells, subsequently proposing an innovative triplet network detection model for the stealth web shell. This model excels in differentiating stealth web shells from benign files while simultaneously aligning them more closely with small web shells, thereby refining classification precision. Our methodology transforms samples into opcode sequences through a series of processing steps, and then integrates them into the specially designed triplet network. Benchmarked against a cutting-edge deep learning network model and recognized detection tools, our detection methodology yields superior performance, delivering a high accuracy of 92.56% and a robust F1-score of 89.17%. These results substantiate the potency of our approach in countering the mounting threat posed by stealth web shells. Jinli Zhang, Yaqin Cao, Ru Tan, Xiang Cui, Qixu Liu |
MSN | 6 |
| 2023 | Phish2vec: A Temporal and Heterogeneous Network Embedding Approach for Detecting Phishing Scams on EthereumabstractThe exponential growth of Ethereum transactions has resulted in a significant increase in phishing scams, leading to substantial financial losses in recent years. Current machine/deep learning-based approaches for classification have been found to be inadequate for large-scale and label-imbalanced Ethereum scenarios. To address this issue, we propose Phish2vec, a novel network embedding approach that takes into account the transaction temporality and heterogeneity in detecting phishing scams on Ethereum. Our approach begins by producing a transaction sub-network through data collection and preprocessing, which includes a novel Statistics-Based Sampling (SBS) method to address label leakage. To generate sequences that contain more comprehensive information, we then utilize two different types of sequences generators: Temporal-based Sequences Generator (TSG) and Heterogeneous-based Sequences Generator (HSG). By concatenating the sequences generated by TSG and HSG together, and feeding them into Word2vec and Fully Connected neural network (FC), our approach can identify phishing accounts with an Fl-score as high as 82.05%, which significantly outperforms classic schemes such as DeepWalk (67.29%), Trans2vec (74.78%), and Node2vec (70.91%). Zhutian Lin, Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qixu Liu, Xiapu Luo |
SECON | 5 |
| 2023 | BehavSniffer: Sniff User Behaviors from the Encrypted Traffic by Traffic Burst GraphsabstractWith the increasing popularity of encryption pro-tocols in application and the rapid development of network applications, traffic classification has become a major challenge for mobile service providers. The failure of traditional classification methods and low classification accuracy are the problems that need to be solved urgently in traffic classification research. Therefore, we propose the scheme of BehavSniffer to sniff user behaviors from the encrypted traffic. The core idea is to propose Traffic Burst Graph (TBG) for extracting multidimensional features from bidirectional interactive data flows, and do feature fusion based on Kernel Principal Component Analysis (KPCA) and Deep Neural Network (DNN). In this way, BehavSniffer can learn both high and low-order combined structural features from traffic patterns of user behavior. Meanwhile, we propose the user behavior dataset, named WWT, from three widely used social media applications (WeChat, WhatsApp, Telegram). Experimental results show that BehavSniffer outperforms stateof-the-art methods, with AUC of 0.987 and accuracy of 99.8%, respectively. Tiru Wu, Xi Xiao 0001, Qing Li 0006, Qixu Liu, Guangwu Hu, Xiapu Luo, Yong Jiang 0001 |
SECON | 4 |
| 2023 | TFE-GNN: A Temporal Fusion Encoder Using Graph Neural Networks for Fine-grained Encrypted Traffic ClassificationabstractEncrypted traffic classification is receiving widespread attention from researchers and industrial companies. However, the existing methods only extract flow-level features, failing to handle short flows because of unreliable statistical properties, or treat the header and payload equally, failing to mine the potential correlation between bytes. Therefore, in this paper, we propose a byte-level traffic graph construction approach based on point-wise mutual information (PMI), and a model named Temporal Fusion Encoder using Graph Neural Networks (TFE-GNN) for feature extraction. In particular, we design a dual embedding layer, a GNN-based traffic graph encoder as well as a cross-gated feature fusion mechanism, which can first embed the header and payload bytes separately and then fuses them together to obtain a stronger feature representation. The experimental results on two real datasets demonstrate that TFE-GNN outperforms multiple state-of-the-art methods in fine-grained encrypted traffic classification tasks. Haozhen Zhang, Le Yu 0002, Xi Xiao 0001, Qing Li 0006, Francesco Mercaldo, Xiapu Luo, Qixu Liu |
WWW | 7 |
| 2023 | MRm-DLDet: a memory-resident malware detection framework based on memory forensics and deep neural networkabstractAbstract Cyber attackers have constantly updated their attack techniques to evade antivirus software detection in recent years. One popular evasion method is to execute malicious code and perform malicious actions only in memory. Malicious programs that use this attack method are called memory-resident malware, with excellent evasion capability, and have posed huge threats to cyber security. Traditional static and dynamic methods are not effective in detecting memory-resident malware. In addition, existing memory forensics detection solutions perform unsatisfactorily in detection rate and depend on massive expert knowledge in memory analysis. This paper proposes MRm-DLDet, a state-of-the-art memory-resident malware detection framework, to overcome these drawbacks. MRm-DLDet first builds a virtual machine environment and captures memory dumps, then creatively processes the memory dumps into RGB images using a pre-processing technique that combines deduplication and ultra-high resolution image cropping, followed by our neural network MRmNet in MRm-DLDet to fully extract high-dimensional features from memory dump files and detect them. MRmNet receives the labeled sub-images of the cropped high-resolution RGB images as input of ResNet-18, which extracts the features of the sub-images. Then trains a network of gated recurrent units with an attention mechanism. Finally, it determines whether a program is memory-resident malware based on the detection results of each sub-image through a specially designed voting layer. We created a high-quality dataset consisting of 2,060 benign and memory-resident programs. In other words, the dataset contains 1,287,500 labeled sub-images cut from the MRm-DLDet transformed ultra-high resolution RGB images. We implement MRm-DLDet for Windows 10, and it performs better than the latest methods, with a detection accuracy of up to 98.34 $$\%$$ % . Moreover, we measured the effects of mimicry and adversarial attacks on MRm-DLDet, and the experimental results demonstrated the robustness of MRm-DLDet. Yun Feng 0003, Xinyu Liu 0019, Qixu Liu |
Cybersecur. | 5 |
| 2023 | Detecting compromised email accounts via login behavior characterizationabstractAbstract The illegal use of compromised email accounts by adversaries can have severe consequences for enterprises and society. Detecting compromised email accounts is more challenging than in the social network field, where email accounts have only a few interaction events (sending and receiving). To address the issue of insufficient features, we propose a novel approach to detecting compromised accounts by combining time zone differences and alternate logins to identify abnormal behavior. Based on this approach, we propose a compromised email account detection framework that relies on widely available and less sensitive login logs and does not require labels. Our framework characterizes login behaviors to identify logins that do not belong to the account owner and outputs a list of account-subnet pairs ranked by their likelihood of having abnormal login relationships. This approach reduces the number of account-subnet pairs that need to be investigated and provides a reference for investigation priority. Our evaluation demonstrates that our method can detect most email accounts that have been accessed by disclosed malicious IP addresses and outperforms similar research. Additionally, our framework has the capability to uncover undisclosed malicious IP addresses. Yaqin Cao, Xiang Cui, Qixu Liu |
Cybersecur. | 7 |
| 2023 | BugRadar: Bug localization by knowledge graph link prediction
Xi Xiao 0001, Renjie Xiao, Qing Li 0006, Jianhui Lv, Shunyan Cui, Qixu Liu |
Inf. Softw. Technol. | 6 |
| 2022 | P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesabstractModern IoT device manufacturers are taking advantage of the managed Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) IoT clouds (e.g., AWS IoT, Azure IoT) for secure and convenient IoT development/deployment. The IoT access control is achieved by manufacturer-specified, cloud-enforced IoT access policies (cloud-standard JSON documents, called IoT Policies) stating which users can access which IoT devices/resources under what constraints. In this paper, we performed a systematic study on the security of cloud-based IoT access policies on modern PaaS/IaaS IoT clouds. Our research shows that the complexity in the IoT semantics and enforcement logic of the policies leaves tremendous space for device manufacturers to program a flawed IoT access policy, introducing convoluted logic flaws which are non-trivial to reason about. In addition to challenges/mistakes in the design space, it is astonishing to find that mainstream device manufacturers also generally make critical mistakes in deploying IoT Policies thanks to the flexibility offered by PaaS/IaaS clouds and the lack of standard practices for doing so. Our assessment of 36 device manufacturers and 310 open-source IoT projects highlights the pervasiveness and seriousness of the problems, which once exploited, can have serious impacts on IoT users' security, safety, and privacy. To help manufacturers identify and easily fix IoT Policy flaws, we introduce P-Verifier, a formal verification tool that can automatically verify cloud-based IoT Policies. With evaluated high effectiveness and low performance overhead, P-Verifier will contribute to elevating security assurance in modern IoT deployments and access control. We responsibly reported all findings to affected vendors and fixes were deployed or on the way. Ze Jin, Luyi Xing, Yiwei Fang, Yan Jia 0009, Bin Yuan 0002, Qixu Liu |
CCS | 6 |
| 2022 | DeepC2: AI-Powered Covert Command and Control on OSNs
Zhi Wang 0018, Chaoge Liu, Xiang Cui, Qixu Liu |
ICICS | 7 |
| 2022 | CPGBERT: An Effective Model for Defect Detection by Learning Program Semantics via Code Property GraphabstractWith the increasing complexity of software composition, code defects have become a long-term problem in software security. Traditional static analysis techniques cannot exhaustively enumerate all unsafe modes, and problems such as low path coverage rate brought by dynamic detection techniques make software security vulnerability detection inefficient. Methods based on Natural Language Processing have promoted the research of code defect detection tasks; however, there are problems of insufficient code semantic learning and limited data processing by pre-trained models. To solve these problems, from the perspective of enriching model input semantics and improving the model’s ability to process data, based on the Transformer model, we propose a hierarchical compression encoder model CPGBERT to detect whether the target function has defects. By using the regularity of the program context and structure, the program code is sliced for the input-output variables related to the objective function and dependencies on the codes’ propagation paths. Extract multiple code property graph information on rich semantics from the sliced program code for graph fusion, and embed the fused code property graph into the model by grouping. During the learning process, the independent hidden layer features are compressed and aggregated to make the model focus on the deep semantic learning of the objective function. The experiment uses the CodeXGLUE benchmark dataset and compares 6 kinds of code defect detection models having better performance to perform defect detection and effect evaluation on actual engineering code. The results show that the accuracy of the CPGBERT detection model is 67.97%, which is 5.89% higher than the CodeBERT model proposed by Microsoft and 1.35% higher than the state-of-the-art model CoTexT. Jingqiang Liu, Xiaoxi Zhu, Chaoge Liu, Xiang Cui, Qixu Liu |
TrustCom | 5 |
| 2022 | A lightweight DDoS detection scheme under SDN contextabstractAbstract Software-defined networking (SDN), a novel network paradigm, separates the control plane and data plane into different network equipment to realize the flexible control of network traffic. Its excellent programmability and global view present many new opportunities. DDoS detection under the SDN context is an important and challenging research field. Some previous works attempted to collect and analyze statistics related to flows, usually recorded in switches, to address DDoS threats. In contrast, other works applied machine learning-based solutions to identify DDoS and achieved promising results. Generally, most previous works need to periodically request flow rules or packets to obtain flow statistics or features to detect stealthy exceptions. Nevertheless, the request for flow rules is very time-consuming and CPU-consuming; moreover may congest the communication channel between the controller and the switches. Therefore, we present FORT, a lightweight DDoS detection scheme, which spreads the rule-based detection algorithm at edge switches and determines whether to start it by periodically retrieving the ports state. A time-series algorithm, ARIMA, is utilized to determine the port statistics adaptively, and an SVM algorithm is applied to detect whether a DDoS attack does occur. Representative experiments demonstrate that FORT can significantly reduce the controller load and provide a reliable detection accuracy. Referring to the false alarm rate of 1.24% in the comparison scheme, the false alarm rate of this scheme is only 0.039%, which significantly reduces the probability of false alarm. Besides, by introducing the alarm mechanism, this scheme can reduce the load of the southbound channel by more than 60% in the normal state. Chaoge Liu, Qixu Liu, Jiazhi Liu, Feng Liu 0005 |
Cybersecur. | 3 |
| 2021 | GAN-Based Adversarial Patch for Malware C2 Traffic to Bypass DL Detector
Qixu Liu, Chaoge Liu |
ICICS (1) | 2 |
| 2021 | Crafting Adversarial Example to Bypass Flow-&ML- based Botnet Detector via RLabstractMachine learning(ML)-based botnet detection methods have become mainstream in corporate practice. However, researchers have found that ML models are vulnerable to adversarial attacks, which can mislead the models by adding subtle perturbations to the sample. Due to the complexity of traffic samples and the special constraints that to keep malicious functions, no substantial research of adversarial ML has been conducted in the botnet detection field, where the evasion attacks caused by carefully crafted adversarial examples may directly make ML-based detectors unavailable and cause significant property damage. In this paper, we propose a reinforcement learning(RL) method for bypassing ML-based botnet detectors. Specifically, we train an RL agent as a functionality-preserving botnet flow modifier through a series of interactions with the detector in a black-box scenario. This enables the attacker to evade detection without modifying the botnet source code or affecting the botnet utility. Experiments on 14 botnet families prove that our method has considerable evasion performance and time performance. Qixu Liu, Xiang Cui |
RAID | 2 |
| 2021 | Automated Honey Document Generation Using Genetic Algorithm
Yun Feng 0003, Baoxu Liu, Jinli Zhang, Chaoge Liu, Qixu Liu |
WASA (3) | 6 |
| 2020 | CoinBot: A Covert Botnet in the Cryptocurrency Network
Xiang Cui, Chaoge Liu, Qixu Liu, Zhi Wang 0018 |
ICICS | 4 |
| 2019 | Medical Protocol Security: DICOM Vulnerability Mining Based on Fuzzing TechnologyabstractDICOM is an international standard for medical images and related information, and is a medical image format that can be used for data exchange. The agreement is widely used in medical fields such as radiology and cardiovascular imaging. However, since DICOM libraries have less security considerations in protocol implementation, they have a large number of security risks. Aiming at the security issue of DICOM libraries, the paper conducts research on vulnerability mining technology for DICOM open source libraries, proposes a vulnerability mining framework based on Fuzzing technology, and implements a prototype system named DICOM-Fuzzer, which includes initialization, test case generation, automatic test, exception monitoring and other modules. Finally, the open source library DCMTK was selected for testing, and it was found that data overflow would occur when the content of the received file was greater than 7080 lines. Found that there is a vulnerability that causes the PACS system to refuse service. In conclusion, the DICOM protocol does have risks, and its information security needs to be further improved. Zhiqiang Wang 0006, Quanqi Li, Yazhe Wang, Qixu Liu |
CCS | 6 |
| 2019 | Evading Machine Learning Botnet Detection Models via Deep Reinforcement LearningabstractBotnets are one of predominant threats to Internet security. To date, machine learning technology has wide application in botnet detection because that it is able to summarize the features of existing attacks and generalize to never-before-seen botnet families. However, recent works in adversarial machine learning have shown that attackers are able to bypass the detection model by constructing specific samples, which due to many algorithms are vulnerable to almost imperceptible perturbations of their inputs. According to the degree of adversaries' knowledge about the model, adversarial attacks can be classified into several groups, such as gradient- and score-based attacks. In this paper, we propose a more general framework based on deep reinforcement learning (DRL), which effectively generates adversarial traffic flows to deceive the detection model by automatically adding perturbations to samples. Throughout the process, the target detector will be regarded as a black box and more close to realistic attack circumstance. A reinforcement learning agent is equipped for updating the adversarial samples by combining the feedback from the target model (i.e. benign or malicious) and the sequence of actions, which is able to change the temporal and spatial features of the traffic flows while maintaining the original functionality and executability. The experiment results show that the evasion rates of adversarial botnet flows are significantly improved. Furthermore, with the perspective of defense, this research can help the detection model spot its defect and thus enhance the robustness. Binxing Fang, Qixu Liu, Xiang Cui |
ICC | 4 |
| 2019 | WSLD: Detecting Unknown Webshell Using Fuzzy Matching and Deep Learning
Qixu Liu, Zhi Wang 0018, Xianda Wu |
ICICS | 2 |
| 2018 | An Empirical Study of OAuth-Based SSO System on Web
Kaili Qiu, Qixu Liu, Jingqiang Liu |
WASA | 2 |
| 2018 | An adaptive system for detecting malicious queries in web attacks
Yuqing Zhang 0001, Qianru Wu, Qixu Liu |
Sci. China Inf. Sci. | 5 |
| 2017 | A static technique for detecting input validation vulnerabilities in Android apps
Zhejun Fang, Qixu Liu, Yuqing Zhang 0001, Zhiqiang Wang 0006, Qianru Wu |
Sci. China Inf. Sci. | 2 |
| 2017 | Driving Android apps to trigger target API invocations based on activity and GUI filtering
Hongzhou Yue, Yuqing Zhang 0001, Qixu Liu |
Sci. China Inf. Sci. | 4 |
| 2016 | A Machine Learning Approach for Detecting Third-Party Trackers on the Web
Qianru Wu, Qixu Liu, Yuqing Zhang 0001, Peng Liu 0005, Guanxing Wen |
ESORICS (1) | 2 |
| 2015 | IVDroid: Static Detection for Input Validation Vulnerability in Android Inter-component Communication
Zhejun Fang, Qixu Liu, Yuqing Zhang 0001, Zhiqiang Wang 0006 |
ISPEC | 2 |
| 2015 | XAS: Cross-API scripting attacks in social ecosystems
Yuqing Zhang 0001, Qixu Liu, Qihan Luo, Xiali Wang |
Sci. China Inf. Sci. | 2 |
| 2015 | TrackerDetector: A system to detect third-party trackers through machine learning
Qianru Wu, Qixu Liu, Yuqing Zhang 0001, Guanxing Wen |
Comput. Networks | 2 |
| 2014 | POSTER: Recommendation-based Third-Party Tracking Monitor to Balance Privacy with PersonalizationabstractThird-party tracking has proliferated across the whole Internet in recent years. To protect Web users, much effort has been spent and almost all of them merely choose to stop third-party service to prevent tracking. However, users should be in total charge of their personal information and it does not mean that every user would like to give up personalization service to protect privacy in any case. In this poster, we present a new approach to make a balance between privacy and personalization through recommendation system, which can help users judge the level of privacy threat so that users can choose between privacy and personalization in a reasonable way. Qixu Liu, Qianru Wu, Yuqing Zhang 0001, Xiali Wang |
CCS | 1 |
| 2014 | Function Escalation Attack
Chen Cao 0004, Yuqing Zhang 0001, Qixu Liu |
SecureComm (1) | 3 |
| 2014 | Static detection of logic vulnerabilities in Java web applicationsabstractABSTRACT This paper concerns about logic vulnerabilities that result from faulty logic of a web application. Logic vulnerabilities typically accompany with the exposure of unexpected functionalities and lead to the bypass of the intended constraints. From a semantic perspective, logic vulnerabilities occur when mistakes arise in the control flows guarding the processes of invoking critical functionalities. In this paper, we propose the first lightweight static analysis approach to automatically detect logic vulnerabilities in Java web applications. Logic errors in our approach are characterized as erroneous invocations of functionalities. Program‐slicing technique has been leveraged to capture the processes of invoking critical functionalities. A back‐tracing algorithm is originally designed to extract control flows guarding functionality‐invocation processes. Finally, logic vulnerability detection is transformed into mining abnormal functionality‐invocation processes in a cluster of similar ones by comparing these processes' control flows. We implemented our approach in a prototype tool named logic vulnerability detector and evaluated it on seven real‐world applications scaled from thousands to million lines of code. The evaluation results show that our approach achieves bigger coverage with acceptable cost and better scalability than previous approaches. Copyright © 2013 John Wiley & Sons, Ltd. Zhejun Fang, Yuqing Zhang 0001, Qixu Liu |
Secur. Commun. Networks | 4 |
| 2013 | trend of online flash XSS vulnerabilitiesabstractFlash objects are widely embedded in web pages, supporting Rich Internet Applications using ActionScript. However, according to our survey, many Flash objects are seriously exposed to Cross-site Scripting vulnerabilities as they are usually coded without proper sanitization of their inputs. This becomes a potential danger for cyber users. In this paper, we analyze XSS in online Flash and present an engine FXD (Flash XSS Detector) for automatically scrambling Flash files in web pages and checking whether or not they are vulnerable to XSS. We call vulnerable ActionScript functions "key functions" and divide them into four categories by its functionality. The usability of FXD is further evaluated by disposing it in real-world websites. Our results reveal that at least 48 Flash applications in 18% of Alexa top 100 sites on the web are vulnerable to XSS. Each of these vulnerable Flash objects has been verified and confirmed of their XSS flaws. Finally, we discuss a new trend of Flash XSS, nowadays it is mainly caused by combination of key functions in different categories. Qixu Liu, Yuqing Zhang 0001 |
CCS | 1 |
| 2013 | Fuzzing the ActionScript virtual machineabstractFuzz testing is an automated testing technique where random data is used as an input to software systems in order to reveal security bugs/vulnerabilities. Fuzzed inputs must be binaries embedded with compiled bytecodes when testing against ActionScript virtual machines (AVMs). The current fuzzing method for JavaScript-like virtual machines is very limited when applied to compiler-involved AVMs. The complete source code should be both grammatically and semantically valid to allow execution by first passing through the compiler. In this paper, we present ScriptGene, an algorithmic approach to overcome the additional complexity of generating valid ActionScript programs. First, nearly-valid code snippets are randomly generated, with some controls on instruction flow. Second, we present a novel mutation method where the former code snippets are lexically analyzed and mutated with runtime information of the AVM, which helps us to build context for undefined behaviours against compiler-check and produce a high code coverage. Accordingly, we have implemented and evaluated ScriptGene on three different versions of Adobe AVMs. Results demonstrate that ScriptGene not only covers almost all the blocks of the official test suite (Tamarin), but also is capable of nearly twice the code coverage. The discovery of six bugs missed by the official test suite demonstrates the effectiveness, validity and novelty of ScriptGene. Guanxing Wen, Yuqing Zhang 0001, Qixu Liu, Dingning Yang |
AsiaCCS | 3 |
| 2013 | IKE vulnerability discovery based on fuzzingabstractABSTRACT Internet Key Exchange (IKE) protocol is widely applied on the Internet to protect confidentiality of the Internet communication. However, there are many high‐risk security vulnerabilities in various IKE implementations. Traditional fuzzing approaches with the aim of discovering vulnerabilities have some blind spots, such as time‐consuming, low efficiency, and low degree of automation. This paper introduces a new vulnerability discovering approach based on fuzzing and applies the approach to the IKE protocol. Through summarizing the most comprehensive vulnerable points of IKE protocol and proposing a two‐stage test cases library, an IKE protocol vulnerability discovering tool called IKEProFuzzer is designed and implemented. It is a network protocol fuzzing framework with extensibility and automated Monitor/Debugger designed by ourselves. In the experiments, IKEProFuzzer has discovered 14 vulnerabilities, including nine released vulnerabilities and five unreleased ones, which affect many kinds of routers and applications. The evaluation results prove the feasibility, efficiency, and extensibility of the approach compared with the existing approaches. Copyright © 2012 John Wiley & Sons, Ltd. Yuqing Zhang 0001, Yupu Hu, Qixu Liu |
Secur. Commun. Networks | 4 |
| 2012 | Static Detection of Logic Vulnerabilities in Java Web ApplicationsabstractLogic vulnerabilities occur when mistakes arise in the control flow associated to critical functionalities. We propose a lightweight static analysis approach to detect logic vulnerabilities in Java Web applications. The core idea of our approach is to discover deviant behaviors among duplication samples. Program slicing technique is leveraged to extract duplicated invocations targeted similar functionalities. Subsequently, path exploration is conducted to split slices into several path sensitive slices. Then we make comparison between any two similar slices on their path condition, and report the slices with abnormal path condition as logic vulnerabilities. We implemented our approach in a prototype tool named LVD (Logic Vulnerability Detector), and evaluated it on seven real world applications scaled from thousands to million lines of code. The evaluation results show that our approach achieves bigger coverage with acceptable cost and better scalability than previous approaches. Yuqing Zhang 0001, Zhejun Fang, Qixu Liu |
TrustCom | 4 |
| 2012 | BlendFuzz: A Model-Based Framework for Fuzz Testing Programs with Grammatical InputsabstractFuzz testing has been widely used in practice to detect software vulnerabilities. Traditional fuzzing tools typically use blocks to model program input. Despite the demonstrated success of this approach, its effectiveness is inherently limited when applied to test programs that process grammatical inputs, where the input data are mainly human-readable text with complex structures that are specified by a formal grammar. In this paper we present BlendFuzz, a fuzz testing framework that is grammar-aware. It works by breaking a set of existing test cases into units of grammar components, then using these units as variants to restructure existent test data, resulting in a wider range of test cases that have the potential to explore previously uncovered corner cases when used in testing. We've implemented this framework along with two language fuzzers on top of it. Experiments with these fuzzers have shown improved code coverage, and field testing has revealed over two dozens of previously unreported bugs in real-world applications, with seven of them being medium or high risk zero-day vulnerabilities. Dingning Yang, Yuqing Zhang 0001, Qixu Liu |
TrustCom | 3 |
| 2012 | Dealing with dishonest recommendation: The trials in reputation management court
Shenlong Chen, Yuqing Zhang 0001, Qixu Liu, Jingyu Feng |
Ad Hoc Networks | 3 |
| 2012 | Improving VRSS-based vulnerability prioritization using analytic hierarchy process
Qixu Liu, Yuqing Zhang 0001, Qianru Wu |
J. Syst. Softw. | 1 |
| 2011 | A New Tree Structure for Weighted Dynamic Programming Based Stereo AlgorithmabstractIn recent years, several kinds of tree structures for dynamic programming have been proposed. All the former trees only include pixels of the image. While in this paper, a new type of tree, which includes all the edges in the image, is constructed. In addition, weighted dynamic programming is proposed in order to improve the conventional dynamic programming. The weighted dynamic programming here is used to optimize the energy function of the new tree structure. Experiments show that our algorithm produces quite smooth and reasonable disparity maps which are close to the state-of-art. Evaluation on the Middlebury dataset shows that our method rank top in all the dynamic programming based stereo matching algorithms, even better than the algorithms that apply segmentation. Tingbo Hu, Tao Wu 0001, Jinze Song, Qixu Liu |
ICIG | 4 |
| 2011 | VRSS: A new system for rating and scoring vulnerabilities
Qixu Liu, Yuqing Zhang 0001 |
Comput. Commun. | 1 |
| 2010 | Eliminating Human Specification in Static Analysis
Yuqing Zhang 0001, Qixu Liu |
RAID | 3 |
| 2008 | TFTP vulnerability finding technique based on fuzzing
Qixu Liu, Yuqing Zhang 0001 |
Comput. Commun. | 1 |