VLDB 2026 Research / reviewers in the wild / expert
Yating Hsu
dblp:75/6887
· DBLP profile ↗
5ranked-venue papers
4as first author
0since 2021 · last 2011
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 first-authorSoftware engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Theoretical computer science
3 papers |
Automata and formal languages · 36% Automated reasoning and model checking · 32% Approximation and online algorithms · 32% | |
| Network and information security
3 papers |
Network security · 66% Cryptographic protocols and secure computation · 34% |
Topics — the 5 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › intrusion detection and prevention › intrusion detection › attack detection
machine learning-based detection |
0.1 | 1 | 2011 | Machine learning for implanted malicious code detection with incompletely specified system implementations · ICNP 2011 |
Cryptographic protocols and secure computation
security protocol analysis |
0.1 | 1 | 2010 | Authentication and authorization protocol security property analysis with trace inclusion transformation and online minimization · ICNP 2010 |
Approximation and online algorithms › online algorithms
online minimization |
0.1 | 1 | 2010 | Authentication and authorization protocol security property analysis with trace inclusion transformation and online minimization · ICNP 2010 |
Automated reasoning and model checking › model checking
state space reduction |
0.1 | 1 | 2010 | Authentication and authorization protocol security property analysis with trace inclusion transformation and online minimization · ICNP 2010 |
Automata and formal languages › finite automata › sequential machines
finite state machine synthesis |
0.1 | 1 | 2008 | A model-based approach to security flaw detection of network protocol implementations · ICNP 2008 |
Methods — techniques the papers use, named apart from their topics
state machine inference · 0.2machine learning · 0.2model checking · 0.2formal verification · 0.2state space reduction · 0.2black-box testing · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2011 | Machine learning for implanted malicious code detection with incompletely specified system implementationsabstractIn 2009 UnrealIRCd 3.2.8.1, an IRC (Internet Relay Chat) server, was replaced by a version with a backdoor at its mirror sites. It was not detected until seven months later and it had caused irrevocable damages in IRC services. It is of vital importance and also a challenge to detect implanted malicious code in newly developed systems before their deployment. We apply machine learning to uncover a system implementation structure that includes its normal functions from the design, as well as the hidden malicious behaviors. Published works with machine learning often assume that systems are completely specified. Unfortunately, practical system implementations are usually incompletely specified and the prevalent algorithms do not apply. We design generalized and efficient machine learning algorithms for incompletely specified protocol system implementations for detecting implanted malicious code. We further extend the results where machine learning starts from an approximate model instead of an empty conjecture - a usual approach of machine learning algorithms, and our approach learns an implementation structure more efficiently than the known algorithms. We implement and apply our method to two case studies: an IRC server with backdoor and an MSN client with message flooder. Experiments show that our procedures successfully and efficiently detect the implanted malicious behaviors. Yating Hsu |
ICNP | 1 |
| 2010 | Authentication and authorization protocol security property analysis with trace inclusion transformation and online minimizationabstractA major hurdle of formal analysis of protocol security properties is the well-known state explosion - a protocol system usually contains infinitely many or a formidable number of states. As a result, most of the analysis resorts to heuristics, such as state space pruning. Given the temporal property of authentication and authorization protocols, we introduce trace inclusion transformation of protocol specification to reduce significantly the state space. We further cut down the number of states by online minimization for obtaining a model of a manageable size for a formal and rigorous analysis. However, the two state space reduction procedures may result in false negative and false positives. We show that our trace inclusion transformation and online minimization do not introduce any false negative. On the other hand, we design an efficient algorithm for ruling out all the possible false positives. Therefore, our analysis is sound and complete. For a case study, we analyze OAuth, a standardization of API authentication protocols. Our automated analysis identifies a number of attacks in the original specification, including the one that has been detected. We also analyze the second version of OAuth and prove it is secure if the API interface is secure. Yating Hsu |
ICNP | 1 |
| 2008 | Detecting Communication Protocol Security Flaws by Formal Fuzz Testing and Machine Learning
Guoqiang Shu, Yating Hsu, David Lee 0001 |
FORTE | 2 |
| 2008 | A model-based approach to security flaw detection of network protocol implementationsabstractA lot of efforts have been devoted to the analysis of network protocol specification for reliability and security properties using formal techniques. However, faults can also be introduced during system implementation; it is indispensable to detect protocol implementation flaws, yet due to the black-box nature of protocol implementation and the unavailability of protocol specification most of the approaches resort to random or manual testing. In this paper we propose a model-based approach for security flaw detection of protocol implementation with a high fault coverage, measurability, and automation. Our approach first synthesizes an abstract behavioral model from a protocol implementation and then uses it to guide the testing process for detecting security and reliability flaws. For protocol specification synthesis we reduce the problem a trace minimization with a finite state machine model and an efficient algorithm is presented for state space reduction. Our method is implemented and applied to real network protocols. Guided by the synthesized model our testing tool reveals a number of unknown reliability and security issues by automatically crashing the implementations of the Microsoft MSN instant messaging (MSNIM) protocol. Analytical comparison between our model-based and prevalent syntax-based flaw detection schemes is also provided with the support of experimental results. Yating Hsu, Guoqiang Shu, David Lee 0001 |
ICNP | 1 |
| 2006 | Walker's Buddy: An Ultrasonic Dangerous Terrain Detection SystemabstractThis paper presents a system prototype to help elder persons being aware of changes in terrain ahead of them. Ultrasonic signal is used for the detection of terrain changes because of its stability in air transmission speed and its simplicity and cost in hardware designs. The prototype is designed and built using commercial-off-the-shelf (COTS) components with an 8051 microprocessor. It can detect obstacles of heights no more than 10 cm three steps away. Yating Hsu, S.-F. Hsiao, C.-E. Chiang, Y.-H. Chien, Hsueh-Wen Tseng, Ai-Chun Pang, Tei-Wei Kuo, K.-H. Chiang |
SMC | 1 |