VLDB 2026 Research / reviewers in the wild / expert
Shouhuai Xu
dblp:78/2715
· DBLP profile ↗
102ranked-venue papers
15as first author
27since 2021 · last 2025
0000-0001-8034-0942ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 60 · 11 first-author · 15 since 2021Systems, architecture and hardware · 11 · 2 first-author · 1 since 2021Computer networks · 8 · 2 since 2021Artificial intelligence and machine learning · 6 · 1 since 2021Software engineering, systems software and programming languages · 5 · 4 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 3Theory of computation · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Characterizing Event-themed Malicious Web Campaigns: A Case Study on War-themed WebsitesabstractCybercrimes such as online scams and fraud have become prevalent. Cybercriminals often abuse various global or regional events as themes of their fraudulent activities to breach user trust and attain a higher attack success rate. These attacks attempt to manipulate and deceive innocent people into interacting with meticulously crafted websites with malicious payloads, phishing, or fraudulent transactions. To deepen our understanding of the problem, this paper investigates how to characterize event-themed malicious website-based campaigns, with a case study on war-themed websites. We find that attackers tailor their attacks by exploiting the unique aspects of events, as evidenced by activities such as fundraising, providing aid, collecting essential supplies, or seeking updated news. We use explainable unsupervised clustering methods to draw further insights, which could guide the design of effective early defenses against various event-themed malicious web campaigns. Maraz Mia, Mir Mehedi Ahsan Pritom, Tariqul Islam 0001, Shouhuai Xu |
PST | 4 |
| 2025 | SoK: Space Infrastructures Vulnerabilities, Attacks and DefensesabstractSpace infrastructures are becoming increasingly important to the global society and economy. However, their cybersecurity is understudied despite previous endeavors. This motivates the present SoK, which is based on a novel methodology of five elements: space infrastructures model, missions, vulnerabilities, attacks, and defenses. The methodology establishes an “anatomy” of space infrastructures via the innovative notions of mission control flows and mission data flows, which are respectively inspired by the notions of control flows and data flows in program analysis. We show how the space infrastructure vulnerabilities, attacks, and defenses studied in the literature can be mapped to space mission control flows and mission data flows, leading to insights such as: improper memory allocation and lack of authentication are the two most exploited vulnerabilities reported; Global Navigation Satellite Systems (GNSS) security is most studied, mainly via physical layer security; and the most effective approach to attack the space segment is to pivot through the ground segment. Jose L. C. Remy, Ekzhin Ear, Caleb Chang, Antonia Feffer, Shouhuai Xu |
SP | 5 |
| 2025 | SoK: Automated Vulnerability Repair: Methods, Tools, and Assessments
Zhen Li 0027, Kedie Shu, Shenghua Guan, Deqing Zou, Shouhuai Xu, Bin Yuan 0002, Hai Jin 0001 |
USENIX Security Symposium | 6 |
| 2025 | MalPacDetector: An LLM-Based Malicious NPM Package DetectorabstractThe Node Package Manager (NPM) registry contains millions of JavaScript packages widely shared between worldwide developers. However, NPM has also been abused by attackers to spread malicious packages, highlighting the importance of detecting malicious NPM packages. Existing malicious NPM package detectors suffer from, among other things, high false positives and/or high false negatives. In this paper, we propose a novel Malicious NPM Package Detector (MalPacDetector), which leverages Large Language Model (LLM) to automatically and dynamically generate features (rather than asking experts to manually define them). To evaluate the effectiveness of Mal-PacDetector and existing detectors, we construct a new NPM package dataset, which overcomes the weaknesses of existing datasets (e.g., a small number of examples and a high repetition rate of malicious fragments). The experimental results show that MalPacDetector outperforms existing detectors by achieving a false positive rate of 1. 3% and a false negative rate of 7. 5%. In particular, MalPacDetector detects 39 previously unknown malicious packages, which are confirmed by the NPM security team. Zhen Li 0027, Jixiang Qu, Deqing Zou, Shouhuai Xu, Ziteng Xu, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Jamming-Resistant Communications Via Cryptographic Secret SharingabstractWireless communications, including satellite communications, rely on the electromagnetic spectrum (EMS) and networking systems for a variety of tasks. But these wireless systems are found to be vulnerable to attacks. In this paper we focus on coping with the jamming attack and propose a new jamming-resistant communication scheme by leveraging the idea of cryptographic secret sharing, which can be further used together with existing defenses such as direct sequence spread spectrum (DSSS) and frequency hopping spread spectrum (FHSS). We characterize the effectiveness of the resulting schemes, leading to a number of findings. James Turner, Shouhuai Xu |
ICC | 3 |
| 2024 | On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural VulnerabilitiesabstractSoftware vulnerabilities are a major cyber threat and it is important to detect them. One important approach to detecting vulnerabilities is to use deep learning while treating a program function as a whole, known as function-level vulnerability detectors. However, the limitation of this approach is not understood. In this paper, we investigate its limitation in detecting one class of vulnerabilities known as inter-procedural vulnerabilities, where the to-be-patched statements and the vulnerability-triggering statements belong to different functions. For this purpose, we create the first Inter-Procedural Vulnerability Dataset (InterPVD) based on C/C++ open-source software, and we propose a tool dubbed VulTrigger for identifying vulnerability-triggering statements across functions. Experimental results show that VulTrigger can effectively identify vulnerability-triggering statements and inter-procedural vulnerabilities. Our findings include: (i) inter-procedural vulnerabilities are prevalent with an average of 2.8 inter-procedural layers; and (ii) function-level vulnerability detectors are much less effective in detecting to-be-patched functions of inter-procedural vulnerabilities than detecting their counterparts of intra-procedural vulnerabilities. Zhen Li 0027, Ning Wang 0098, Deqing Zou, Ruqian Zhang, Shouhuai Xu, Chao Zhang 0008, Hai Jin 0001 |
ICSE | 6 |
| 2024 | Internet-Based Social Engineering Psychology, Attacks, and Defenses: A SurveyabstractInternet-based social engineering (SE) attacks are a major cyber threat. These attacks often serve as the first step in a sophisticated sequence of attacks that target, among other things, victims’ credentials and can cause financial losses. The problem has received mounting attention in recent years, with many publications proposing defenses against SE attacks. Despite this, the situation has not improved. In this article, we aim to understand and explain this phenomenon by investigating the root cause of the problem. To this end, we examine Internet-based SE attacks and defenses through a unique lens based on psychological factors (PFs) and psychological techniques (PTs). We find that there is a key discrepancy between attacks and defenses: SE attacks have deliberately exploited 46 PFs and 16 PTs in total, but existing defenses have only leveraged 16 PFs and seven PTs in total. This discrepancy may explain why existing defenses have achieved limited success and prompt us to propose a systematic roadmap for future research. Theodore Tangie Longtchi, Rosana Montañez Rodriguez, Laith Al-Shawaf, Adham Atyabi, Shouhuai Xu |
Proc. IEEE | 5 |
| 2024 | PAD: Towards Principled Adversarial Malware Detection Against Evasion AttacksabstractMachine Learning (ML) techniques can facilitate the automation ofmalicious software(malware for short) detection, but suffer from evasion attacks. Many studies counter such attacks in heuristic manners, lacking theoretical guarantees and defense effectiveness. In this article, we propose a new adversarial training framework, termedPrincipledAdversarial MalwareDetection (PAD), which offers convergence guarantees for robust optimization methods. PAD lays on a learnable convex measurement that quantifies distribution-wise discrete perturbations to protect malware detectors from adversaries, whereby for smooth detectors, adversarial training can be performed with theoretical treatments. To promote defense effectiveness, we propose a new mixture of attacks to instantiate PAD to enhance deep neural network-based measurements and malware detectors. Experimental results on two Android malware datasets demonstrate: (i) the proposed method significantly outperforms the state-of-the-art defenses; (ii) it can harden ML-based malware detection against 27 evasion attacks with detection accuracies greater than 83.45%, at the price of suffering an accuracy decrease smaller than 2.16% in the absence of attacks; (iii) it matches or outperforms many anti-malware scanners in VirusTotal against realistic adversarial malware. Deqiang Li, Shicheng Cui, Yun Li 0009, Jia Xu 0003, Fu Xiao 0001, Shouhuai Xu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Robin: A Novel Method to Produce Robust Interpreters for Deep Learning-Based Code ClassifiersabstractDeep learning has been widely used in source code classification tasks, such as code classification according to their functionalities, code authorship attribution, and vulnerability detection. Unfortunately, the black-box nature of deep learning makes it hard to interpret and understand why a classifier (i.e., classification model) makes a particular prediction on a given example. This lack of interpretability (or explainability) might have hindered their adoption by practitioners because it is not clear when they should or should not trust a classifier's prediction. The lack of interpretability has motivated a number of studies in recent years. However, existing methods are neither robust nor able to cope with out-of-distribution examples. In this paper, we propose a novel method to produce Robust interpreters for a given deep learning-based code classifier; the method is dubbed Robin. The key idea behind Robin is a novel hybrid structure combining an interpreter and two approximators, while leveraging the ideas of adversarial training and data augmentation. Experimental results show that on average the interpreter produced by Robin achieves a 6.11% higher fidelity (evaluated on the classifier), 67.22% higher fidelity (evaluated on the approximator), and 15.87x higher robustness than that of the three existing interpreters we evaluated. Moreover, the interpreter is 47.31% less affected by out-of-distribution examples than that of LEMNA. Zhen Li 0027, Ruqian Zhang, Deqing Zou, Ning Wang 0098, Shouhuai Xu, Chen Chen 0001, Hai Jin 0001 |
ASE | 6 |
| 2023 | Near-Ultrasound Inaudible Trojan (Nuit): Exploiting Your Speaker to Attack Your Microphone
Shouhuai Xu |
USENIX Security Symposium | 3 |
| 2023 | Electoral manipulation via influence: probabilistic model
Liangde Tao, Lin Chen 0009, Lei Xu 0012, Shouhuai Xu, Zhimin Gao, Larry Shi |
Auton. Agents Multi Agent Syst. | 4 |
| 2023 | Does OpenBSD and Firefox's Security Improve With Time?abstractOzment and Schechter (USENIX Security’2006) analyzed the evolution of OpenBSD vulnerabilities over the span of 7 years (1998-2005) and concluded that its security increases with age. In this paper, we extend their study by analyzing the evolution of OpenBSD vulnerabilities over the span of 22 years (1998-2020) and Firefox vulnerabilities over the span of 9 years (2011-2020). Our empirical study leads to a number of insights, including the following: both OpenBSD and Firefox get more secure (i.e., less vulnerable) with time, but today’s developers do not necessarily produce more secure code; OpenBSD and Firefox developers tend to make similar security mistakes, but Firefox vulnerabilities are easier to exploit; finally, Firefox’s vulnerability density is almost one order of magnitude higher than OpenBSD’s, meaning Firefox is more vulnerable. Deqing Zou, Shouhuai Xu, Xianjun Deng, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | RoPGen: Towards Robust Code Authorship Attribution via Automatic Coding Style TransformationabstractSource code authorship attribution is an important problem often encountered in applications such as software forensics, bug fixing, and software quality analysis. Recent studies show that current source code authorship attribution methods can be compromised by attackers exploiting adversarial examples and coding style manipulation. This calls for robust solutions to the problem of code authorship attribution. In this paper, we initiate the study on making Deep Learning (DL)-based code authorship attribution robust. We propose an innovative framework called Robust coding style Patterns Generation (RoPGen), which essentially learns authors' unique coding style patterns that are hard for attackers to manipulate or imitate. The key idea is to combine data augmentation and gradient augmentation at the adversarial training phase. This effectively increases the diversity of training examples, generates meaningful perturbations to gradients of deep neural networks, and learns diversified representations of coding styles. We evaluate the effectiveness of RoPGen using four datasets of programs written in C, C++, and Java. Experimental results show that RoPGen can significantly improve the robustness of DL-based code authorship attribution, by respectively reducing 22.8% and 41.0% of the success rate of targeted and untargeted attacks on average. Zhen Li 0027, Qian Chen 0019, Chen Chen 0001, Yayi Zou, Shouhuai Xu |
ICSE | 5 |
| 2022 | Reducing Intrusion Alert Trees to Aid Visualization
Eric Ficke, Raymond M. Bateman, Shouhuai Xu |
NSS | 3 |
| 2022 | Poster: Toward Zero-Trust Path-Aware Access ControlabstractIn this poster, we introduce path-aware risk scores for access control (PARSAC), a novel context-sensitive technique to enrich access requests with risk scoring of the path taken by those requests between the authenticated user and the resources they access. These path-aware risk scores enable another layer of security for traditional access control systems that addresses the need for fine-grained monitoring and enforcement within a zero-trust architecture. We define rules for general functions that can be used to determine risk and instantiate a specific approach to calculate path risk scores. We evaluate our approach with realistic network graphs; PARSAC finds more paths with lower risk when compared with traditional routing algorithms that select the shortest path. Joshua H. Seaton, Sena Hounsinou, Timothy Wood 0001, Shouhuai Xu, Philip N. Brown, Gedare Bloom |
SACMAT | 4 |
| 2022 | SAND: semi-automated adaptive network defense via programmable rule generation and deployment
Haoyu Chen 0004, Deqing Zou, Hai Jin 0001, Shouhuai Xu, Bin Yuan 0002 |
Sci. China Inf. Sci. | 4 |
| 2022 | Blockchain-based automated and robust cyber security management
Songlin He, Eric Ficke, Mir Mehedi Ahsan Pritom, Huashan Chen, Qiang Tang 0005, Qian Chen 0019, Marcus Pendleton, Laurent Njilla, Shouhuai Xu |
J. Parallel Distributed Comput. | 9 |
| 2022 | SySeVR: A Framework for Using Deep Learning to Detect Software VulnerabilitiesabstractThe detection of software vulnerabilities (or vulnerabilities for short) is an important problem that has yet to be tackled, as manifested by the many vulnerabilities reported on a daily basis. This calls for machine learning methods for vulnerability detection. Deep learning is attractive for this purpose because it alleviates the requirement to manually define features. Despite the tremendous success of deep learning in other application domains, its applicability to vulnerability detection is not systematically understood. In order to fill this void, we propose thefirstsystematic framework for using deep learning to detect vulnerabilities in C/C++ programs with source code. The framework, dubbedSyntax-based,Semantics-based, andVectorRepresentations(SySeVR), focuses on obtaining program representations that can accommodate syntax and semantic information pertinent to vulnerabilities. Our experiments with four software products demonstrate the usefulness of the framework: we detect 15 vulnerabilities that are not reported in the National Vulnerability Database. Among these 15 vulnerabilities, seven are unknown and have been reported to the vendors, and the other eight have been “silently” patched by the vendors when releasing newer versions of the pertinent software products. Zhen Li 0027, Deqing Zou, Shouhuai Xu, Hai Jin 0001, Yawei Zhu, Zhaoxuan Chen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Quantifying Cybersecurity Effectiveness of Dynamic Network DiversityabstractThe deployment of monoculture software stacks can have devastating consequences because a single attack can compromise all of the vulnerable computers in cyberspace. This one-vulnerability-affects-all phenomenon will continue until after software stacks are diversified, which is well recognized by the research community. However, existing studies mainly focused on investigating the effectiveness of software diversity at the building-block level (e.g., whether two independent implementations indeed exhibit independent vulnerabilities); the effectiveness of enforcing network-wide software diversity is little understood, despite its importance in possibly helping justify investment in software diversification. As a first step towards ultimately tackling this problem, we propose a systematic framework for modeling and quantifying the cybersecurity effectiveness of network diversity, including a suite of cybersecurity metrics. We also present an agent-based simulation to empirically demonstrate the usefulness of the framework. We draw a number of insights, including the surprising result that proactive diversity is effective under very special circumstances, but reactive-adaptive diversity is much more effective in most cases. Huashan Chen, Hasan Çam, Shouhuai Xu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | VulDeeLocator: A Deep Learning-Based Fine-Grained Vulnerability DetectorabstractAutomatically detecting software vulnerabilities is an important problem that has attracted much attention from the academic research community. However, existing vulnerability detectors still cannot achieve the vulnerability detection capability and the locating precision that would warrant their adoption for real-world use. In this article, we present a vulnerability detector that can simultaneously achieve a high detection capability and a high locating precision, dubbedVulnerabilityDeep learning-basedLocator(VulDeeLocator). In the course of designing VulDeeLocator, we encounter difficulties including how to accommodate semantic relations between the definitions of types as well as macros and their uses across files, how to accommodate accurate control flows and variable define-use relations, and how to achieve high locating precision. We solve these difficulties by using two innovative ideas: (i) leveraging intermediate code to accommodate extra semantic information, and (ii) using the notion ofgranularity refinementto pin down locations of vulnerabilities. When applied to 200 files randomly selected from three real-world software products, VulDeeLocator detects 18 confirmed vulnerabilities (i.e., true-positives). Among them, 16 vulnerabilities correspond to known vulnerabilities; the other two are not reported in the National Vulnerability Database (NVD) but have been “silently” patched by the vendor of Libav when releasing newer versions. Zhen Li 0027, Deqing Zou, Shouhuai Xu, Zhaoxuan Chen, Yawei Zhu, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Can We Leverage Predictive Uncertainty to Detect Dataset Shift and Adversarial Examples in Android Malware Detection?abstractThe deep learning approach to detecting malicious software (malware) is promising but has yet to tackle the problem of dataset shift, namely that the joint distribution of examples and their labels associated with the test set is different from that of the training set. This problem causes the degradation of deep learning models without users’ notice. In order to alleviate the problem, one approach is to let a classifier not only predict the label on a given example but also present its uncertainty (or confidence) on the predicted label, whereby a defender can decide whether to use the predicted label or not. While intuitive and clearly important, the capabilities and limitations of this approach have not been well understood. In this paper, we conduct an empirical study to evaluate the quality of predictive uncertainties of malware detectors. Specifically, we re-design and build 24 Android malware detectors (by transforming four off-the-shelf detectors with six calibration methods) and quantify their uncertainties with nine metrics, including three metrics dealing with data imbalance. Our main findings are: (i) predictive uncertainty indeed helps achieve reliable malware detection in the presence of dataset shift, but cannot cope with adversarial evasion attacks; (ii) approximate Bayesian methods are promising to calibrate and generalize malware detectors to deal with dataset shift, but cannot cope with adversarial evasion attacks; (iii) adversarial evasion attacks can render calibration methods useless, and it is an open problem to quantify the uncertainty associated with the predicted labels of adversarial examples (i.e., it is not effective to use predictive uncertainty to detect adversarial examples). Deqiang Li, Shuo Chen 0003, Qianmu Li, Shouhuai Xu |
ACSAC | 5 |
| 2021 | Hardness and Algorithms for Electoral Manipulation Under Media Influence
Liangde Tao, Lin Chen 0009, Lei Xu 0012, Shouhuai Xu, Zhimin Gao, Larry Shi, Dian Huang |
IJTCS-FAW | 4 |
| 2021 | ExHPD: Exploiting Human, Physical, and Driving Behaviors to Detect Vehicle Cyber AttacksabstractAs increasingly more vehicles are connected to the Internet, cyber attacks against vehicles are becoming a real threat with devastating consequences. This highlights the importance of detecting vehicle cyber attacks before fatal accidents occur. One natural method for tackling this problem is to adapt existing approaches for detecting attacks in enterprize networks, but which has achieved limited success. In this article, we propose a new approach to treat vehicles as cyber-physical-human systems, leading to a novel framework called exploiting human, physical and driving behaviors to detect vehicle cyber attacks (ExHPD). The framework has four detectors: 1) a human detector; 2) a physical behavior-based detector; 3) a driving behavior-based detector (DBD); and 4) an integrated physical and DBD. As the proof of concept, we recruited 50 drivers to conduct institutional review board-approved simulation-based driving tests. The experimental results show that ExHPD is effective to detect vehicle cyber attacks and avoid deadly crashes by offering drivers adequate time to safely pull over their compromised vehicle. The impact of driver's impulsiveness (one aspect of human factors) on the detectors' effectiveness and limitations of the present study are discussed. Future research directions toward an ultimately usable solution are outlined. Qian Chen 0019, Paul Romanowich, Jorge Castillo, Krishna Chandra Roy, Gustavo Chavez, Shouhuai Xu |
IEEE Internet Things J. | 6 |
| 2021 | Computational complexity characterization of protecting elections from bribery
Lin Chen 0009, Ahmed Sunny, Lei Xu 0012, Shouhuai Xu, Zhimin Gao, Yang Lu 0010, Larry Shi, Nolan Shah |
Theor. Comput. Sci. | 4 |
| 2021 | $\mu$μVulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability DetectionabstractFine-grained software vulnerability detection is an important and challenging problem. Ideally, a detection system (or detector) not only should be able to detect whether or not a program contains vulnerabilities, but also should be able to pinpoint the type of a vulnerability in question. Existing vulnerability detection methods based on deep learning can detect the presence of vulnerabilities (i.e., addressing the binary classification or detection problem), but cannot pinpoint types of vulnerabilities (i.e., incapable of addressing multiclass classification). In this paper, we propose the first deep learning-based system for multiclass vulnerability detection, dubbed μ VulDeePecker. The key insight underlying μ VulDeePecker is the concept of code attention, which can capture information that can help pinpoint types of vulnerabilities, even when the samples are small. For this purpose, we create a dataset from scratch and use it to evaluate the effectiveness of μ VulDeePecker. Experimental results show that μ VulDeePecker is effective for multiclass vulnerability detection and that accommodating control-dependence (other than data-dependence) can lead to higher detection capabilities. Deqing Zou, Sujuan Wang, Shouhuai Xu, Zhen Li 0027, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | A Framework for Predicting Data Breach Risk: Leveraging Dependence to Cope With SparsityabstractData breach is a major cybersecurity problem that has caused huge financial losses and compromised many individuals' privacy (e.g., social security numbers). This calls for deeper understanding about the data breach risk. Despite the substantial amount of attention that has been directed toward the issue, many fundamental problems are yet to be investigated. In this article, we initiate the study of modeling and predicting risk in enterprise-level data breaches. This problem is challenging because of the sparsity of breaches experienced by individual enterprises over time, which immediately disqualifies standard statistical models because there are not enough data to train such models. As a first step towards tackling the problem, we propose an innovative statistical framework to leverage the dependence between multiple time series. In order to validate the framework, we apply it to a dataset of enterprise-level breach incidents. Experimental results show its effectiveness in modeling and predicting enterprise-level breach incidents. Zijian Fang, Maochao Xu, Shouhuai Xu, Taizhong Hu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Interpreting Deep Learning-based Vulnerability Detector Predictions Based on Heuristic SearchingabstractDetecting software vulnerabilities is an important problem and a recent development in tackling the problem is the use of deep learning models to detect software vulnerabilities. While effective, it is hard to explain why a deep learning model predicts a piece of code as vulnerable or not because of the black-box nature of deep learning models. Indeed, the interpretability of deep learning models is a daunting open problem. In this article, we make a significant step toward tackling the interpretability of deep learning model in vulnerability detection. Specifically, we introduce a high-fidelity explanation framework, which aims to identify a small number of tokens that make significant contributions to a detector’s prediction with respect to an example. Systematic experiments show that the framework indeed has a higher fidelity than existing methods, especially when features are not independent of each other (which often occurs in the real world). In particular, the framework can produce some vulnerability rules that can be understood by domain experts for accepting a detector’s outputs (i.e., true positives) or rejecting a detector’s outputs (i.e., false-positives and false-negatives). We also discuss limitations of the present study, which indicate interesting open problems for future research. Deqing Zou, Yawei Zhu, Shouhuai Xu, Zhen Li 0027, Hai Jin 0001, Hengkai Ye |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2020 | Computational Complexity Characterization of Protecting Elections from Bribery
Lin Chen 0009, Ahmed Sunny, Lei Xu 0012, Shouhuai Xu, Zhimin Gao, Yang Lu 0010, Larry Shi, Nolan Shah |
COCOON | 4 |
| 2020 | APIN: Automatic Attack Path Identification in Computer NetworksabstractIdentifying the scope of a network attack can be difficult with limited information about the nature of the attack. Even more difficult is the automation of this process. Because of this, it is important to investigate new methods for mapping and quantifying the threat posed by an attack, in order to prioritize actions during incident response. To this end we propose a framework for automatic attack path identification in computer networks (APIN) by leveraging observable malicious behaviors to quantify the threat score of a set of attacks. Using two academic datasets, experimental results show that APIN is able to quickly reconstruct paths that offer meaningful insight into the nature of multi-step threats on the network, given only reasonable restrictions on network size and structure. These insights would not be possible with only existing tools, such as IDSs, and human analysts would require significant time and expertise to obtain the same findings without APIN's guidance. Eric Ficke, Shouhuai Xu |
ISI | 2 |
| 2020 | Data-Driven Characterization and Detection of COVID-19 Themed Malicious WebsitesabstractCOVID-19 has hit hard on the global community, and organizations are working diligently to cope with the new norm of "work from home". However, the volume of remote work is unprecedented and creates opportunities for cyber attackers to penetrate home computers. Attackers have been leveraging websites with COVID-19 related names, dubbed COVID-19 themed malicious websites. These websites mostly contain false information, fake forms, fraudulent payments, scams, or malicious payloads to steal sensitive information or infect victims' computers. In this paper, we present a data-driven study on characterizing and detecting COVID-19 themed malicious websites. Our characterization study shows that attackers are agile and are deceptively crafty in designing geolocation targeted websites, often leveraging popular domain registrars and top-level domains. Our detection study shows that the Random Forest classifier can detect COVID-19 themed malicious websites based on the lexical and WHOIS features defined in this paper, achieving a 98% accuracy and 2.7% false-positive rate. Mir Mehedi Ahsan Pritom, Kristin M. Schweitzer, Raymond M. Bateman, Min Xu 0001, Shouhuai Xu |
ISI | 5 |
| 2020 | Characterizing the Landscape of COVID-19 Themed Cyberattacks and DefensesabstractCOVID-19 (Coronavirus) hit the global society and economy with a big surprise. In particular, work-from-home has become a new norm for employees. Despite the fact that COVID-19 can equally attack innocent people and cyber criminals, it is ironic to see surges in cyberattacks leveraging COVID-19 as a theme, dubbed COVID-19 themed cyberattacks or COVID-19 attacks for short, which represent a new phenomenon that has yet to be systematically understood. In this paper, we make a first step towards fully characterizing the landscape of these attacks, including their sophistication via the Cyber Kill Chain model. We also explore the solution space of defenses against these attacks. Mir Mehedi Ahsan Pritom, Kristin M. Schweitzer, Raymond M. Bateman, Min Xu 0001, Shouhuai Xu |
ISI | 5 |
| 2019 | Election with Bribed Voter Uncertainty: Hardness and Approximation AlgorithmabstractBribery in election (or computational social choice in general) is an important problem that has received a considerable amount of attention. In the classic bribery problem, the briber (or attacker) bribes some voters in attempting to make the briber’s designated candidate win an election. In this paper, we introduce a novel variant of the bribery problem, “Election with Bribed Voter Uncertainty” or BVU for short, accommodating the uncertainty that the vote of a bribed voter may or may not be counted. This uncertainty occurs either because a bribed voter may not cast its vote in fear of being caught, or because a bribed voter is indeed caught and therefore its vote is discarded. As a first step towards ultimately understanding and addressing this important problem, we show that it does not admit any multiplicative O(1)-approximation algorithm modulo standard complexity assumptions. We further show that there is an approximation algorithm that returns a solution with an additive-ε error in FPT time for any fixed ε. Lin Chen 0009, Lei Xu 0012, Shouhuai Xu, Zhimin Gao, Larry Shi |
AAAI | 3 |
| 2019 | iTrustSO: an intelligent system for automatic detection of insecure code snippets in stack overflowabstractDespite the apparent benefits of modern social coding paradigm such as Stack Overflow, its potential security risks have been largely overlooked (e.g., insecure codes could be easily embedded and distributed). To address this imminent issue, in this paper, we bring a significant insight to leverage both social coding properties and code content for automatic detection of insecure code snippets in Stack Overflow. To determine if the given code snippets are insecure, we not only analyze the code content, but also utilize various kinds of relations among users, badges, questions, answers and code snippets in Stack Overflow. To model the rich semantic relationships, we first introduce a structured heterogeneous information network (HIN) for representation and then use meta-path based approach to incorporate higher-level semantics to build up relatedness over code snippets. Later, we propose a novel hierarchical attention-based sequence learning model named CodeHin2Vec to seamlessly integrate node (i.e., code snippet) content with HIN-based relations for representation learning. After that, a classifier is built for insecure code snippet detection. Integrating our proposed method, an intelligent system named iTrustSO is accordingly developed to address the code security issues in modern software coding platforms. Comprehensive experiments on the data collections from Stack Overflow are conducted to validate the effectiveness of our developed system iTrustSO by comparisons with alternative methods. Lingwei Chen, Shifu Hou, Yanfang Ye 0001, Thirimachos Bourlai, Shouhuai Xu, Liang Zhao 0002 |
ASONAM | 5 |
| 2019 | KCRS: A Blockchain-Based Key Compromise Resilient Signature System
Lei Xu 0012, Lin Chen 0009, Zhimin Gao, Xinxin Fan, Kimberly Doan, Shouhuai Xu, Larry Shi |
BlockSys | 6 |
| 2019 | Election with Bribe-Effect Uncertainty: A Dichotomy ResultabstractWe consider the electoral bribery problem in computational social choice. In this context, extensive studies have been carried out to analyze the computational vulnerability of various voting (or election) rules. However, essentially all prior studies assume a deterministic model where each voter has an associated threshold value, which is used as follows. A voter will take a bribe and vote according to the attacker's (i.e., briber's) preference when the amount of the bribe is above the threshold, and a voter will not take a bribe when the amount of the bribe is not above the threshold (in this case, the voter will vote according to its own preference, rather than the attacker's). In this paper, we initiate the study of a more realistic model where each voter is associated with a willingness function, rather than a fixed threshold value. The willingness function characterizes the likelihood a bribed voter would vote according to the attacker's preference; we call this bribe-effect uncertainty. We characterize the computational complexity of the electoral bribery problem in this new model. In particular, we discover a dichotomy result: a certain mathematical property of the willingness function dictates whether or not the computational hardness can serve as a deterrence to bribery attackers. Lin Chen 0009, Lei Xu 0012, Shouhuai Xu, Zhimin Gao, Larry Shi |
IJCAI | 3 |
| 2019 | iDev: Enhancing Social Coding Security by Cross-platform User Identification Between GitHub and Stack OverflowabstractAs modern social coding platforms such as GitHub and Stack Overflow become increasingly popular, their potential security risks increase as well (e.g., risky or malicious codes could be easily embedded and distributed). To enhance the social coding security, in this paper, we propose to automate cross-platform user identification between GitHub and Stack Overflow to combat the attackers who attempt to poison the modern software programming ecosystem. To solve this problem, an important insight brought by this work is to leverage social coding properties in addition to user attributes for cross-platform user identification. To depict users in GitHub and Stack Overflow (attached with attributed information), projects, questions and answers as well as the rich semantic relations among them, we first introduce an attributed heterogeneous information network (AHIN) for modeling. Then, we propose a novel AHIN representation learning model AHIN2Vec to efficiently learn node (i.e., user) representations in AHIN for cross-platform user identification. Comprehensive experiments on the data collections from GitHub and Stack Overflow are conducted to validate the effectiveness of our developed system iDev integrating our proposed method in cross-platform user identification by comparisons with other baselines. Yujie Fan, Yiming Zhang 0002, Shifu Hou, Lingwei Chen, Yanfang Ye 0001, Chuan Shi 0001, Liang Zhao 0002, Shouhuai Xu |
IJCAI | 8 |
| 2019 | A deep learning framework for predicting cyber attacks ratesabstractLike how useful weather forecasting is, the capability of forecasting or predicting cyber threats can never be overestimated. Previous investigations show that cyber attack data exhibits interesting phenomena, such as long-range dependence and high nonlinearity, which impose a particular challenge on modeling and predicting cyber attack rates. Deviating from the statistical approach that is utilized in the literature, in this paper we develop a deep learning framework by utilizing the bi-directional recurrent neural networks with long short-term memory, dubbed BRNN-LSTM. Empirical study shows that BRNN-LSTM achieves a significantly higher prediction accuracy when compared with the statistical approach. Maochao Xu, Shouhuai Xu, Peng Zhao 0012 |
EURASIP J. Inf. Secur. | 3 |
| 2019 | Metrics Towards Measuring Cyber AgilityabstractIn cyberspace, evolutionary strategies are commonly used by both attackers and defenders. For example, an attacker's strategy often changes over the course of time, as new vulnerabilities are discovered and/or mitigated. Similarly, a defender's strategy changes over time. These changes may or may not be in direct response to a change in the opponent's strategy. In any case, it is important to have a set of quantitative metrics to characterize and understand the effectiveness of attackers' and defenders' evolutionary strategies, which reflect their cyber agility. Despite its clear importance, few systematic metrics have been developed to quantify the cyber agility of attackers and defenders. In this paper, we propose the first metric framework for measuring cyber agility in terms of the effectiveness of the dynamic evolution of cyber attacks and defenses. The proposed framework is generic and applicable to transform any relevant, quantitative, and/or conventional static security metrics (e.g., false positives and false negatives) into dynamic metrics to capture dynamics of system behaviors. In order to validate the usefulness of the proposed framework, we conduct case studies on measuring the evolution of cyber attacks and defenses using two real-world datasets. We discuss the limitations of the current work and identify future research directions. Jose David Mireles, Eric Ficke, Jin-Hee Cho, Patrick M. Hurley, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | Unified Preventive and Reactive Cyber Defense Dynamics Is Still Globally ConvergentabstractA class of the preventive and reactive cyber defense dynamics has recently been proven to be globally convergent, meaning that the dynamics always converges to a unique equilibrium whose location only depends on the values of the model parameters (but not the initial state of the dynamics). In this paper, we unify the aforementioned class of preventive and reactive cyber defense dynamics models and the closely related class of N-intertwined epidemic models into a single framework. We prove that the unified dynamics is still globally convergent under some mild conditions, which are naturally satisfied by the two specific classes of dynamics models mentioned above and are inevitable when analyzing a more general framework. We also characterize the convergence speed of the unified dynamics. As a corollary, we obtain that the N-intertwined epidemic model and its extension are globally convergent, together with a full characterization on their convergence speed, which is only partially addressed in the literature. Zongzong Lin, Wenlian Lu, Shouhuai Xu |
IEEE/ACM Trans. Netw. | 3 |
| 2018 | ICSD: An Automatic System for Insecure Code Snippet Detection in Stack Overflow over Heterogeneous Information NetworkabstractAs the popularity of modern social coding paradigm such as Stack Overflow grows, its potential security risks increase as well (e.g., insecure codes could be easily embedded and distributed). To address this largely overlooked issue, in this paper, we bring an important new insight to exploit social coding properties in addition to code content for automatic detection of insecure code snippets in Stack Overflow. To determine if the given code snippets are insecure, we not only analyze the code content, but also utilize various kinds of relations among users, badges, questions, answers, code snippets and keywords in Stack Overflow. To model the rich semantic relationships, we first introduce a structured heterogeneous information network (HIN) for representation and then use meta-path based approach to incorporate higher-level semantics to build up relatedness over code snippets. Later, we propose a novel network embedding model named snippet2vec for representation learning in HIN where both the HIN structures and semantics are maximally preserved. After that, a multi-view fusion classifier is constructed for insecure code snippet detection. To the best of our knowledge, this is the first work utilizing both code content and social coding properties to address the code security issues in modern software coding platforms. Comprehensive experiments on the data collections from Stack Overflow are conducted to validate the effectiveness of the developed system ICSD which integrates our proposed method in insecure code snippet detection by comparisons with alternative approaches. Yanfang Ye 0001, Shifu Hou, Lingwei Chen, Xin Li 0005, Liang Zhao 0002, Shouhuai Xu |
ACSAC | 6 |
| 2018 | DroidEye: Fortifying Security of Learning-Based Classifier Against Adversarial Android Malware AttacksabstractTo combat the evolving Android malware attacks, systems using machine learning techniques have been successfully deployed for Android malware detection. In these systems, based on different feature representations, various kinds of classifiers are constructed to detect Android malware. Unfortunately, as classifiers become more widely deployed, the incentive for defeating them increases. In this paper, we first extract a set of features from the Android applications (apps) and represent them as binary feature vectors; with these inputs, we then explore the security of a generic learning-based classifier for Android malware detection in the presence of adversaries. To harden the evasion, we first present count featurization to transform the binary feature space into continuous probabilities encoding the distribution in each class (either benign or malicious). To improve the system security while not compromising the detection accuracy, we further introduce softmax function with adversarial parameter to find the best trade-off between security and accuracy for the classifier. Accordingly, we develop a system named DroidEye which integrates our proposed method for Android malware detection. Comprehensive experiments on the real sample collection from Comodo Cloud Security Center are conducted to validate the effectiveness of DroidEye against adversarial Android malware attacks. Our proposed secure-learning paradigm is also applicable for other detection tasks, such as spammer detection in social media. Lingwei Chen, Shifu Hou, Yanfang Ye 0001, Shouhuai Xu |
ASONAM | 4 |
| 2018 | A safety and security architecture for reducing accidents in intelligent transportation systemsabstractThe Internet of Things (IoT) technology is transforming the world into Smart Cities, which have a huge impact on future societal lifestyle, economy and business. Intelligent Transportation Systems (ITS), especially IoT-enabled Electric Vehicles (EVs), are anticipated to be an integral part of future Smart Cities. Assuring ITS safety and security is critical to the success of Smart Cities because human lives are at stake. The state-of-the-art understanding of this matter is very superficial because there are many new problems that have yet to be investigated. For example, the cyber-physical nature of ITS requires considering human-in-the-loop (i.e., drivers and pedestrians) and imposes many new challenges. In this paper, we systematically explore the threat model against ITS safety and security (e.g., malfunctions of connected EVs/transportation infrastructures, driver misbehavior and unexpected medical conditions, and cyber attacks). Then, we present a novel and systematic ITS safety and security architecture, which aims to reduce accidents caused or amplified by a range of threats. The architecture has appealing features: (i) it is centered at proactive cyber-physical-human defense; (ii) it facilitates the detection of early-warning signals of accidents; (iii) it automates effective defense against a range of threats. Qian Chen 0019, Azizeh K. Sowan, Shouhuai Xu |
ICCAD | 3 |
| 2018 | VulDeePecker: A Deep Learning-Based System for Vulnerability Detection
Zhen Li 0027, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin 0001, Sujuan Wang, Zhijun Deng, Yuyi Zhong |
NDSS | 3 |
| 2018 | Special issue on social network security and privacyabstractAbstract This special issue contains 28 full papers selected from the Computer Animation Miroslaw Kutylowski, Yu Wang 0017, Shouhuai Xu, Laurence T. Yang |
Concurr. Comput. Pract. Exp. | 3 |
| 2018 | TNGuard: Securing IoT Oriented Tenant Networks Based on SDNabstractIn the paradigm of infrastructure-as-a-service cloud computing involving an Internet of Things network, customers outsource their infrastructure to the cloud. An outsourced infrastructure is a virtual infrastructure that mimics the physical infrastructure of the precloud era; it is therefore referred to as a tenant network (TN) in this paper. This practice draws upon the notion of TN abstraction, which specifies how TNs should be managed. However, current virtual software-defined network (SDN) technology uses an SDN hypervisor to attain TNs, where the cloud administrator is given much-more-than-necessary privileges; thus, not only could violation of the security principle of least privilege occur, but the threat of a malicious or innocent-but-compromised administrator may be present. Motivated by this need, we propose the specification of TN abstraction, including its functions and security requirements. Then, we present a platform-independent concretization of this abstraction called TNGuard, which is an SDN-based architecture that protects the TNs while removing unnecessary privileges from the cloud administrator. In order to show that TNGuard concretizes the TN abstraction, we present an instantiation of TNGuard on the Xen virtualization platform with the Ryu controller. Experimental results show that the resulting system is practical, incurring a small performance overhead. Weiqi Dai, Weizhong Qiang, Laurence T. Yang, Deqing Zou, Hai Jin 0001, Shouhuai Xu, Zirong Huang |
IEEE Internet Things J. | 7 |
| 2018 | Architectural Protection of Application Privacy against Software and Physical Attacks in Untrusted Cloud EnvironmentabstractIn cloud computing, it is often assumed that cloud vendors are trusted; the guest Operating System (OS) and the Virtual Machine Monitor (VMM, also called Hypervisor) are secure. However, these assumptions are not always true in practice and existing approaches cannot protect the data privacy of applications when none of these parties are trusted. We investigate how to cope with a strong threat model which is that the cloud vendors, the guest OS, or the VMM, or both of them are malicious or untrusted, and can launch attacks against privacy of trusted user applications. This model is relevant because applications may be small enough to be formally verified, while the guest OS and VMM are too complex to be formally verified. Specifically, we present the design and analysis of an architectural solution which integrates a set of components on-chip to protect the memory of trusted applications from potential software and hardware based attacks from untrusted cloud providers, compromised guest OS, or malicious VMM. Full-system performance evaluation results show that the design only incurs 9 percent overhead on average, which is a small performance price that is paid for the substantial security gain. Lei Xu 0012, Jong-Hyuk Lee, Qingji Zheng, Shouhuai Xu, Taeweon Suh, Won Woo Ro, Larry Shi |
IEEE Trans. Cloud Comput. | 5 |
| 2018 | Statistical Estimation of Malware Detection Metrics in the Absence of Ground TruthabstractThe accurate measurement of security metrics is a critical research problem, because an improper or inaccurate measurement process can ruin the usefulness of the metrics. This is a highly challenging problem, particularly when the ground truth is unknown or noisy. In this paper, we measure five malware detection metrics in the absence of ground truth, which is a realistic setting that imposes many technical challenges. The ultimate goal is to develop principled, automated methods for measuring these metrics at the maximum accuracy possible. The problem naturally calls for investigations into statistical estimators by casting the measurement problem as a statistical estimation problem. We propose statistical estimators for these five malware detection metrics. By investigating the statistical properties of these estimators, we characterize when the estimators are accurate, and what adjustments can be made to improve them under what circumstances. We use synthetic data with known ground truth to validate these statistical estimators. Then, we employ these estimators to measure five metrics with respect to a large data set collected from VirusTotal. Pang Du, Zheyuan Sun, Huashan Chen, Jin-Hee Cho, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | Modeling and Predicting Cyber Hacking BreachesabstractAnalyzing cyber incident data sets is an important method for deepening our understanding of the evolution of the threat situation. This is a relatively new research topic, and many studies remain to be done. In this paper, we report a statistical analysis of a breach incident data set corresponding to 12 years (2005-2017) of cyber hacking activities that include malware attacks. We show that, in contrast to the findings reported in the literature, both hacking breach incident inter-arrival times and breach sizes should be modeled by stochastic processes, rather than by distributions because they exhibit autocorrelations. Then, we propose particular stochastic process models to, respectively, fit the inter-arrival times and the breach sizes. We also show that these models can predict the inter-arrival times and the breach sizes. In order to get deeper insights into the evolution of hacking breach incidents, we conduct both qualitative and quantitative trend analyses on the data set. We draw a set of cybersecurity insights, including that the threat of cyber hacks is indeed getting worse in terms of their frequency, but not in terms of the magnitude of their damage. Maochao Xu, Kristin M. Schweitzer, Raymond M. Bateman, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | VulPecker: an automated vulnerability detection system based on code similarity analysis
Zhen Li 0027, Deqing Zou, Shouhuai Xu, Hai Jin 0001, Hanchao Qi |
ACSAC | 3 |
| 2015 | Verifiable Delegated Set Intersection Operations on Outsourced Encrypted DataabstractWe initiate the study of the following problem: Suppose Alice and Bob would like to outsource their encrypted private data sets to the cloud, and they also want to conduct the set intersection operation on their plaintext data sets. The straightforward solution for them is to download their outsourced cipher texts, decrypt the cipher texts locally, and then execute a commodity two-party set intersection protocol. Unfortunately, this solution is not practical. We therefore motivate and introduce the novel notion of Verifiable Delegated Set Intersection on outsourced encrypted data (VDSI). The basic idea is to delegate the set intersection operation to the cloud, while (i) not giving the decryption capability to the cloud, and (ii) being able to hold the misbehaving cloud accountable. We formalize security properties of VDSI and present a construction. In our solution, the computational and communication costs on the users are linear to the size of the intersection set, meaning that the efficiency is optimal up to a constant factor. Qingji Zheng, Shouhuai Xu |
IC2E | 2 |
| 2015 | TEE: A virtual DRTM based execution environment for secure cloud-end computing
Weiqi Dai, Hai Jin 0001, Deqing Zou, Shouhuai Xu, Weide Zheng, Lei Shi 0001, Laurence T. Yang |
Future Gener. Comput. Syst. | 4 |
| 2015 | Predicting Cyber Attack Rates With Extreme ValuesabstractIt is important to understand to what extent, and in what perspectives, cyber attacks can be predicted. Despite its evident importance, this problem was not investigated until very recently, when we proposed using the innovative methodology of gray-box prediction. This methodology advocates the use of gray-box models, which accommodate the statistical properties/phenomena exhibited by the data. Specifically, we showed that gray-box models that accommodate the long-range dependence phenomenon can predict the attack rate (i.e., the number of attacks per unit time) 1-h ahead-of-time with an accuracy of 70.2%-82.1%. To the best of our knowledge, this is the first result showing the feasibility of prediction in this domain. We observe that the prediction errors are partly caused by the models' incapability in predicting the large attack rates, which are called extreme values in statistics. This motivates us to analyze the extreme-value phenomenon, using two complementary approaches: 1) the extreme value theory (EVT) and 2) the time series theory (TST). In this paper, we show that EVT can offer long-term predictions (e.g., 24-h ahead-of-time), while gray-box TST models can predict attack rates 1-h ahead-of-time with an accuracy of 86%-87.9%. We explore connections between the two approaches, and point out future research directions. Although our prediction study is based on specific cyber attack data, our methodology can be equally applied to analyze any cyber attack data of its kind. Zhenxin Zhan, Maochao Xu, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Programmable decoder and shadow threads: Tolerate remote code injection exploits with diversified redundancyabstractWe present a lightweight hardware framework for providing high assurance detection and prevention of code injection attacks using a lockstep diversified shadow execution. Recent studies show that hardware diversification can detect software attacks by checking the consistency of their behavior simultaneously. Unfortunately, the severe performance degradation and extra system costs caused by these methods are unacceptable in many applications. This paper presents a hardware-level, lockstep shadow thread framework to enrich the diversity of the software execution, with the facilitation from programmable hardware decoder and novel CPU support of tightly coupled shadow thread technique. Specifically, given a piece of (legacy) binary code, we first generate diversified binary versions using an offline binary rewriter and programmable hardware binary translator at runtime. Two diversified binary code images are launched as dual simultaneous threads in the hardware layer with one as the primary thread and the other one as shadow thread. Instructions from the shadow thread are not executed but just compared, and thus incur no OS side-effects. The extended CPU is able to decode instructions from both threads, and dispatch them to the next stage pipeline for a lockstep comparison. Any mismatch of the decoded instructions from the two threads caused by remotely injected binary code will be detected. Our design provides instruction set randomization (ISR) with minimal cost in performance, when compared with straightforward ISR implementation. The simulation results indicate that our framework incurs very small overheads and provides a protection against code injection attacks. Ziyi Liu 0002, Larry Shi, Shouhuai Xu, Zhiqiang Lin 0001 |
DATE | 3 |
| 2014 | VABKS: Verifiable attribute-based keyword search over outsourced encrypted dataabstractIt is common nowadays for data owners to outsource their data to the cloud. Since the cloud cannot be fully trusted, the outsourced data should be encrypted. This however brings a range of problems, such as: How should a data owner grant search capabilities to the data users? How can the authorized data users search over a data owner's outsourced encrypted data? How can the data users be assured that the cloud faithfully executed the search operations on their behalf? Motivated by these questions, we propose a novel cryptographic solution, called verifiable attribute-based keyword search (VABKS). The solution allows a data user, whose credentials satisfy a data owner's access control policy, to (i) search over the data owner's outsourced encrypted data, (ii) outsource the tedious search operations to the cloud, and (iii) verify whether the cloud has faithfully executed the search operations. We formally define the security requirements of VA B K S and describe a construction that satisfies them. Performance evaluation shows that the proposed schemes are practical and deployable. Qingji Zheng, Shouhuai Xu, Giuseppe Ateniese |
INFOCOM | 2 |
| 2014 | A roadmap for privacy-enhanced secure data provenance
Elisa Bertino, Gabriel Ghinita, Murat Kantarcioglu, Dang Nguyen 0001, Jae Park, Ravi S. Sandhu, Salmin Sultana, Bhavani Thuraisingham, Shouhuai Xu |
J. Intell. Inf. Syst. | 9 |
| 2014 | Adaptive Epidemic Dynamics in Networks: Thresholds and ControlabstractTheoretical modeling of computer virus/worm epidemic dynamics is an important problem that has attracted many studies. However, most existing models are adapted from biological epidemic ones. Although biological epidemic models can certainly be adapted to capture some computer virus spreading scenarios (especially when the so-called homogeneity assumption holds), the problem of computer virus spreading is not well understood because it has many important perspectives that are not necessarily accommodated in the biological epidemic models. In this article, we initiate the study of such a perspective, namely that ofadaptivedefense against epidemic spreading in arbitrary networks. More specifically, we investigate a nonhomogeneous Susceptible-Infectious-Susceptible (SIS) model where the model parameters may vary with respect to time. In particular, we focus on two scenarios we callsemi-adaptivedefense andfully adaptivedefense, which accommodate implicit and explicit dependency relationships between the model parameters, respectively. In the semi-adaptive defense scenario, the model’s input parameters are given; the defense is semi-adaptive because the adjustment is implicitly dependent upon the outcome of virus spreading. For this scenario, we present a set of sufficient conditions (some are more general or succinct than others) under which the virus spreading will die out; such sufficient conditions are also known asepidemic thresholdsin the literature. In the fully adaptive defense scenario, some input parameters are not known (i.e., the aforementioned sufficient conditions are not applicable) but the defender can observe the outcome of virus spreading. For this scenario, we present adaptive control strategies under which the virus spreading will die out or will be contained to a desired level. Shouhuai Xu, Wenlian Lu, Zhenxin Zhan |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2013 | Cross-layer detection of malicious websitesabstractWeb threats pose the most significant cyber threat. Websites have been developed or manipulated by attackers for use as attack tools. Existing malicious website detection techniques can be classified into the categories of static and dynamic detection approaches, which respectively aim to detect malicious websites by analyzing web contents, and analyzing run-time behaviors using honeypots. However, existing malicious website detection approaches have technical and computational limitations to detect sophisticated attacks and analyze massive collected data. The main objective of this research is to minimize the limitations of malicious website detection. This paper presents a novel cross-layer malicious website detection approach which analyzes network-layer traffic and application-layer website contents simultaneously. Detailed data collection and performance evaluation methods are also presented. Evaluation based on data collected during 37 days shows that the computing time of the cross-layer detection is 50 times faster than the dynamic approach while detection can be almost as effective as the dynamic approach. Experimental results indicate that the cross-layer detection outperforms existing malicious website detection techniques. Zhenxin Zhan, Shouhuai Xu, Keying Ye |
CODASPY | 3 |
| 2013 | Characterizing Honeypot-Captured Cyber Attacks: Statistical Framework and Case StudyabstractRigorously characterizing the statistical properties of cyber attacks is an important problem. In this paper, we propose the first statistical framework for rigorously analyzing honeypot-captured cyber attack data. The framework is built on the novel concept of stochastic cyber attack process, a new kind of mathematical objects for describing cyber attacks. To demonstrate use of the framework, we apply it to analyze a low-interaction honeypot dataset, while noting that the framework can be equally applied to analyze high-interaction honeypot data that contains richer information about the attacks. The case study finds, for the first time, that long-range dependence (LRD) is exhibited by honeypot-captured cyber attacks. The case study confirms that by exploiting the statistical properties (LRD in this case), it is feasible to predict cyber attacks (at least in terms of attack rate) with good accuracy. This kind of prediction capability would provide sufficient early-warning time for defenders to adjust their defense configurations or resource allocations. The idea of “gray-box” (rather than “black-box”) prediction is central to the utility of the statistical framework, and represents a significant step towards ultimately understanding (the degree of) the predictability of cyber attacks. Zhenxin Zhan, Maochao Xu, Shouhuai Xu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2012 | Key-insulated symmetric key cryptography and mitigating attacks against cryptographic cloud softwareabstractSoftware-based attacks (e.g., malware) pose a big threat to cryptographic software because they can compromise the associated cryptographic keys in their entirety. In this paper, we investigate key-insulated symmetric key cryptography, which can mitigate the damage caused by repeated attacks against cryptographic software. To illustrate the feasibility of key-insulated symmetric key cryptography, we also report a proof-of-concept implementation in the Kernel-based Virtual Machine (KVM) environment. Yevgeniy Dodis, Weiliang Luo, Shouhuai Xu, Moti Yung |
AsiaCCS | 3 |
| 2012 | Secure and efficient proof of storage with deduplicationabstractBoth security and efficiency are crucial to the success of cloud storage. So far, security and efficiency of cloud storage have been separately investigated as follows: On one hand, security notions such as Proof of Data Possession (PDP) and Proof of Retrievability (POR) have been introduced for detecting that the data stored in the cloud has been tampered with. On the other hand, the notion of Proof of Ownership (POW) has also been proposed to alleviate the cloud server from storing multiple copies of the same data, which could substantially reduce the consumption of both network bandwidth and server storage space. These two aspects are seemingly quite to the opposite of each other. In this paper, we show, somewhat surprisingly, that the two aspects can actually co-exist within the same framework. This is possible fundamentally because of the following insight: The public verifiability offered by PDP/POR schemes can be naturally exploited to achieve POW. This "one stone, two birds" phenomenon not only inspired us to propose the novel notion of Proof of Storage with Deduplication (POSD), but also guided us to design a concrete scheme that is provably secure in the Random Oracle model based on the Computational Diffie-Hellman (CDH) assumption. Qingji Zheng, Shouhuai Xu |
CODASPY | 2 |
| 2012 | Push- and pull-based epidemic spreading in networks: Thresholds and deeper insightsabstractUnderstanding the dynamics of computer virus (malware, worm) in cyberspace is an important problem that has attracted a fair amount of attention. Early investigations for this purpose adapted biological epidemic models, and thus inherited the so-called homogeneity assumption that each node is equally connected to others. Later studies relaxed this often unrealistic homogeneity assumption, but still focused on certain power-law networks. Recently, researchers investigated epidemic models inarbitrarynetworks (i.e., no restrictions on network topology). However, all these models only capturepush-basedinfection, namely that an infectious node always actively attempts to infect its neighboring nodes. Very recently, the concept ofpull-basedinfection was introduced but was not treated rigorously. Along this line of research, the present article investigates push- and pull-based epidemic spreading dynamics in arbitrary networks, using a nonlinear dynamical systems approach. The article advances the state-of-the-art as follows: (1) It presents a more general and powerful sufficient condition (also known as epidemic threshold in the literature) under which the spreading will become stable. (2) It gives both upper and lower bounds on the global mean infection rate, regardless of the stability of the spreading. (3) It offers insights into, among other things, the estimation of the global mean infection rate through localized monitoring of a smallconstantnumber of nodes,withoutknowing the values of the parameters. Shouhuai Xu, Wenlian Lu |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2012 | Enhancing Data Trustworthiness via Assured Digital SigningabstractDigital signatures are an important mechanism for ensuring data trustworthiness via source authenticity, integrity, and source nonrepudiation. However, their trustworthiness guarantee can be subverted in the real world by sophisticated attacks, which can obtain cryptographically legitimate digital signatures without actually compromising the private signing key. This problem cannot be adequately addressed by a purely cryptographic approach, by the revocation mechanism of Public Key Infrastructure (PKI) because it may take a long time to detect the compromise, or by using tamper-resistant hardware because the attacker does not need to compromise the hardware. This problem will become increasingly more important and evident because of stealthy malware (or Advanced Persistent Threats). In this paper, we propose a novel solution, dubbed Assured Digital Signing (ADS), to enhancing the data trustworthiness vouched by digital signatures. In order to minimize the modifications to the Trusted Computing Base (TCB), ADS simultaneously takes advantage of trusted computing and virtualization technologies. Specifically, ADS allows a signature verifier to examine not only a signature's cryptographic validity but also its system security validity that the private signing key and the signing function are secure, despite the powerful attack that the signing application program and the general-purpose Operating System (OS) kernel are malicious. The modular design of ADS makes it application-transparent (i.e., no need to modify the application source code in order to deploy it) and almost hypervisor-independent (i.e., it can be implemented with any Type I hypervisor). To demonstrate the feasibility of ADS, we report the implementation and analysis of an Xen-based ADS system. Weiqi Dai, T. Paul Parker, Hai Jin 0001, Shouhuai Xu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2012 | A Stochastic Model of Multivirus DynamicsabstractUnderstanding the spreading dynamics of computer viruses (worms, attacks) is an important research problem, and has received much attention from the communities of both computer security and statistical physics. However, previous studies have mainly focused on single-virus spreading dynamics. In this paper, we study multivirus spreading dynamics, where multiple viruses attempt to infect computers while possibly combating against each other because, for example, they are controlled by multiple botmasters. Specifically, we propose and analyze a general model (and its two special cases) of multivirus spreading dynamics in arbitrary networks (i.e., we do not make any restriction on network topologies), where the viruses may or may not coreside on computers. Our model offers analytical results for addressing questions such as: What are the sufficient conditions (also known as epidemic thresholds) under which the multiple viruses will die out? What if some viruses can "rob” others? What characteristics does the multivirus epidemic dynamics exhibit when the viruses are (approximately) equally powerful? The analytical results make a fundamental connection between two types of factors: defense capability and network connectivity. This allows us to draw various insights that can be used to guide security defense. Shouhuai Xu, Wenlian Lu, Zhenxin Zhan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | Non-interactive editable signatures for assured data provenanceabstractIn order to make people truly benefit from data sharing, we need technical solutions to assuring the trustworthiness of data received from parties one may not have encountered in the past. Assured data provenance is an important means for this purpose because it (i) allows data providers to get credited for their contribution or sharing of data, (ii) is able to hold the data providers accountable for the data they contributed, and (iii) enables the data providers to supply high-quality data in a self-healing fashion. While the above (i) and (ii) have been investigated to some extent, the above (iii) is a new perspective that, to our knowledge, has not been investigated in the literature. In this paper, we introduce a novel cryptographic technique that can simultaneously offer these properties. Our technique is called editable signatures, which allow a user, Bob, to edit (e.g., replace, modify, and insert) some portions of the message that is contributed and signed by Alice such that the resulting edited message is jointly signed by Alice and Bob in some fashion. While it is easy to see that the above (i) and (ii) are achieved, the above (iii) is also achieved because Bob may have a better knowledge of the situation that allows him to provide more accurate/trustworthy information than Alice, who may intentionally or unintentionally enter inaccurate or even misleading data into an information network. This is useful because Alice's inaccurate or even misleading information will never be released into an information network if it can be ``cleaned" or "healed" by Bob. Specifically, we propose two novel cryptographic constructions that can be used to realize the above functions in some practical settings. Haifeng Qian, Shouhuai Xu |
CODASPY | 2 |
| 2011 | Fair and dynamic proofs of retrievabilityabstractCloud computing is getting increasingly popular, but has yet to be widely adopted arguably because there are many security and privacy problems that have not been adequately addressed. A specific problem encountered in the context of cloud storage, where clients outsource their data (files) to untrusted cloud storage servers, is to convince the clients that their data are kept intact at the storage servers. An important approach to achieve this goal is called Proof of Retrievability (POR), by which a storage server can convince a client --- via a concise proof --- that its data can be recovered. However, existing POR solutions can only deal with static data (i.e., data items must be fixed), and actually are not secure when used to deal with dynamic data (i.e., data items need be inserted, deleted, and modified). Motivated by the need to securely deal with dynamic data, we propose the first dynamic POR scheme for this purpose. Moreover, we introduce a new property, called fairness, which is necessary and also inherent to the setting of dynamic data because, without ensuring it, a dishonest client could legitimately accuse an honest cloud storage server of manipulating its data. Our solution is based on two new tools, one is an authenticated data structure we call range-based 2-3 trees (rb23Tree for short), and the other is an incremental signature scheme we call hash-compress-and-sign (HCS for short). These tools might be of independent value as well. Qingji Zheng, Shouhuai Xu |
CODASPY | 2 |
| 2011 | A Stochastic Model for Quantitative Security Analyses of Networked SystemsabstractTraditional security analyses are often geared toward cryptographic primitives or protocols. Although such analyses are necessary, they cannot address a defender's need for insight into which aspects of a networked system having a significant impact on its security, and how to tune its configurations or parameters so as to improve security. This question is known to be notoriously difficult to answer, and the state of the art is that we know little about it. Toward ultimately addressing this question, this paper presents a stochastic model for quantifying security of networked systems. The resulting model captures two aspects of a networked system: 1) the strength of deployed security mechanisms such as intrusion detection systems and 2) the underlying vulnerability graph, which reflects how attacks may proceed. The resulting model brings the following insights: 1) How should a defender “tune” system configurations (e.g., network topology) so as to improve security? 2) How should a defender “tune” system parameters (e.g., by upgrading which security mechanisms) so as to improve security? 3) Under what conditions is the steady-state number of compromised entities of interest below a given threshold with a high probability? Simulation studies are conducted to confirm the analytic results, and to show the tightness of the bounds of certain important metric that cannot be resolved analytically. Xiaohu Li, T. Paul Parker, Shouhuai Xu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2011 | Exploiting Trust-Based Social Networks for Distributed Protection of Sensitive DataabstractHow can we protect sensitive data of average users? In this paper, we propose taking advantage of real-life social trust between average users (called “trust-based social networks”) as well as threshold cryptography. This leads to a new type of complex systems, for which we define and characterize the following novel properties: 1) attack-resilience, which captures the consequences of computers getting compromised; 2) security utility of anonymous social networks, which captures the security gained when the underlying social network links are not known to the attacker; 3) security utility of psychological soundness, which captures the security gained when a user keeps a decisive share of its sensitive data; 4) availability, which captures the effect when computers are not always responsive; 5) the trade-off between attack-resilience and availability. Shouhuai Xu, Xiaohu Li, T. Paul Parker |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | Social Network-Based Botnet Command-and-Control: Emerging Threats and Countermeasures
Erhan J. Kartaltepe, Jose Andre Morales, Shouhuai Xu, Ravi S. Sandhu |
ACNS | 3 |
| 2010 | TEE: a virtual DRTM based execution environment for secure cloud-end computingabstractCloud computing is believed to be the next major paradigm of computing because it will substantially reduce the cost of IT systems. Ensuring security in the cloud-end is necessary because customers' data are stored and processed there. Previous studies have mainly focused on secure cloud-end storage, whereas secure cloud-end computing is much less investigated. The current practice is solely based on Virtual Machines (VM), and cannot offer adequate security because the guest Operating Systems (OS) often can be easily breached (e.g., by exploiting their vulnerabilities). This motivates the need of solutions for more secure cloud-end computing. This poster presents the design, implementation and analysis of a candidate solution, called Trusted Execution Environment (TEE), which takes advantage of both virtualization and trusted computing technologies simultaneously. The novelty behind TEE is the virtualization of the Dynamic Root of Trust for Measurement (DRTM). Weiqi Dai, Hai Jin 0001, Deqing Zou, Shouhuai Xu, Weide Zheng, Lei Shi 0001 |
CCS | 4 |
| 2010 | Analyzing and Exploiting Network Behaviors of Malware
Jose Andre Morales, Areej Al-Bataineh, Shouhuai Xu, Ravi S. Sandhu |
SecureComm | 3 |
| 2010 | Trustworthy Information: Concepts and Mechanisms
Shouhuai Xu, Haifeng Qian, Fengying Wang, Zhenxin Zhan, Elisa Bertino, Ravi S. Sandhu |
WAIM | 1 |
| 2010 | Non-interactive multisignatures in the plain public-key model with efficient verification
Haifeng Qian, Shouhuai Xu |
Inf. Process. Lett. | 2 |
| 2009 | A First Step towards Characterizing Stealthy BotnetsabstractBotnets have become a top cyber threat. Existing studies on botnets have mainly focused on showing how to exploit certain characteristics of existing botnets to detect them. However, such detection mechanisms could be defeated by stealthy botnets that are designed to evade them. Therefore, it is important to understand the power of stealthy botnets so as to answer questions such as: What kinds of stealth techniques can survive what kinds of detection mechanisms? Towards the ultimate goal, this paper makes a first step with the aim to build fundamental understandings of stealthy botnet command and control (C&C). Justin Leonard, Shouhuai Xu, Ravi S. Sandhu |
ARES | 2 |
| 2009 | A Framework for Understanding BotnetsabstractBotnets have become a severe threat to the cyberspace. However, existing studies are typically conducted in an ad hoc fashion, by demonstrating specific analysis on captured bot programs or bot communication mechanisms so as to suggest means to counter them. Although such studies are important, another perhaps even more important problem that is largely left unaddressed is: how should we build a unified framework that can help us understand botnets in a systematic fashion? In this paper we make a first step towards the goal by presenting a framework, which especially suggests a general architecture that could be coupled with certain advanced techniques that have not been exploited in existing botnets. The framework also suggests a set of attributes that can be used to measure and compare botnets. Moreover, the dynamic nature of botnets (e.g., a victim machine may be powered-off during some time intervals) implies that a botnet, and thus its attributes, are stochastic in nature. This means that a meaningful comparison between botnet attributes should be based on the concept of stochastic order. Justin Leonard, Shouhuai Xu, Ravi S. Sandhu |
ARES | 2 |
| 2009 | Assured Information Sharing Life CycleabstractThis paper describes our approach to assured information sharing. The research is being carried out under a MURI 9Multiuniversiyt Research Initiative) project funded by the Air Force Office of Scientific Research (AFOSR). The main objective of our project is: define, design and develop an Assured Information Sharing Lifecycle (AISL) that realizes the DoD's information sharing value chain. In this paper we describe the problem faced by the Department of Defense and our solution to developing an AISL System. Tim Finin, Anupam Joshi, Hillol Kargupta, Yelena Yesha, Joel Sachs, Elisa Bertino, Ninghui Li 0001, Chris Clifton, Eugene H. Spafford, Bhavani Thuraisingham, Murat Kantarcioglu, Alain Bensoussan 0001, Nathan Berg, Latifur Khan, Jiawei Han 0001, ChengXiang Zhai, Ravi S. Sandhu, Shouhuai Xu, Jim Massaro, Lada A. Adamic |
ISI | 18 |
| 2009 | A Characterization of the problem of secure provenance managementabstractData (or information) provenance has many important applications. However, prior work on data provenance management almost exclusively focused on the collection, representation, query, and storage of provenance data. In contrast, the security aspect of provenance management has not been understood nor adequately addressed. A natural question then is: What would a secure provenance management system - perhaps as an analogy to secure database management systems - look like? In this paper, we explore the problem space of secure provenance management systems with an emphasis on the security requirements for such systems, and characterize desired solutions for tackling the problem. We believe that this paper makes a significant step towards a comprehensive solution to the problem of secure provenance management. Shouhuai Xu, Qun Ni, Elisa Bertino, Ravi S. Sandhu |
ISI | 1 |
| 2009 | Leak-free mediated group signaturesabstractGroup signatures are a useful cryptographic construct for privacy-preserving non-repudiable authentication, and there have been many group signature schemes. In this paper, we introduce a variant of group signatures that offers two new security properties called leak-freedom and immediate-revocation. Intuitively, the former ensures that an insider (i.e., an authorized but malicious signer) be unable to convince an outsider (e.g., a signature receiver) that she indeed signed a certain message; whereas the latter ensures that the authorization for a user to issue group signatures can be immediately revoked whenever the need arises (temporarily or permanently). These properties are not offered in existing group signature schemes, nor captured by their security definitions. However, these properties might be crucial to a large class of enterprise-centric applications because they are desirable from the perspective of the enterprises who adopt group signatures or are the group signatures liability-holders (i.e., will be held accountable for the consequences of group signatures). In addition to introducing these new security properties, we present a scheme that possesses both traditional and these newly introduced properties. Our scheme is constructed using an architectural approach where a mediation server is exploited to trade on-line communications for the extra security properties, which explains why the resulting scheme is called “leak-free mediated group signatures”. Xuhua Ding, Gene Tsudik, Shouhuai Xu |
J. Comput. Secur. | 3 |
| 2008 | Exploiting social networks for threshold signing: attack-resilience vs. availabilityabstractDigital signatures are an important security mechanism, especially when non-repudiation is desired. However, non-repudiation is meaningful only when the private signing keys and functions are adequately protected --- an assumption that is very difficult to accommodate in the real world because computers (and thus cryptographic keys and functions) could be relatively easily compromised. One approach to resolving, or at least alleviating, this problem is to use threshold cryptography. But how should such techniques be employed in the real world? In this paper we propose exploiting social networks whereby average users take advantage of their trusted ones to help secure their cryptographic keys. While the idea is simple from an individual user's perspective, we aim to understand the resulting systems from a whole-system perspective. Specifically, we propose and investigate two measures of the resulting systems: attack-resilience, which captures the security consequences due to the compromise of some computers and thus the compromise of the cryptographic key shares stored on them; availability, which captures the effect when computers are not always responsive (due to the peer-to-peer nature of social networks). Shouhuai Xu, Xiaohu Li, T. Paul Parker |
AsiaCCS | 1 |
| 2008 | Collaborative Attack vs. Collaborative Defense
Shouhuai Xu |
CollaborateCom | 1 |
| 2008 | Empirical Analysis of Certificate Revocation Lists
Daryl Walleck, Yingjiu Li, Shouhuai Xu |
DBSec | 3 |
| 2008 | Distributed and Secure Bootstrapping of Mobile Ad Hoc Networks: Framework and ConstructionsabstractSecure bootstrapping of mobile ad hoc networks (MANETs) is a challenging problem in scenarios in which network users (or nodes) do not share trust relationships prior to the network deployment. In recent years, a number of schemes have been proposed to solve this problem, assuming either no or limited trust between the nodes prior to their deployment. Despite numerous proposals, there is no common understanding of the proposed schemes and of the trade-offs that they provide. This has consequences for both researchers and practitioners, who do not have a clear idea how to compare the schemes and how to select a scheme for a given application. In this article, we present a framework that helps in understanding and comparing schemes for secure bootstrapping of MANETs. The framework is general because it is policy-neutral and can accommodate many existing bootstrapping schemes. The proposed framework can equally serve as a good basis for the development of new MANET bootstrapping schemes; we show how the development of the framework leads to two new (classes of) distributed bootstrapping schemes. Within the framework, we not only investigate and characterize the properties of the relevant bootstrapping schemes, but also give methods for practitioners to select the relevant system parameters in the Random Walk and the (Restricted) Random Waypoint mobility models. Shouhuai Xu, Srdjan Capkun |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2007 | Towards Quantifying the (In)Security of Networked SystemsabstractTraditional security analyses are often geared towards cryptographic primitives or protocols. Although such analyses are absolutely necessary, they do not provide much insight for answering an equally important question: what is the security assurance of a physically or logically networked system when we consider it as a whole? This question is known to be notoriously difficult, and the state-of-the-art is that we know very little about it. In this paper, we make a step towards resolving it with a new modeling approach. Xiaohu Li, T. Paul Parker, Shouhuai Xu |
AINA | 3 |
| 2007 | How to Secure Your Email Address Book and Beyond
Erhan J. Kartaltepe, T. Paul Parker, Shouhuai Xu |
CANS | 3 |
| 2007 | A Scalable and Secure Cryptographic Service
Shouhuai Xu, Ravi S. Sandhu |
DBSec | 1 |
| 2007 | Protecting Cryptographic Keys from Memory Disclosure AttacksabstractCryptography has become an indispensable mechanism for securing systems, communications and applications. While offering strong protection, cryptography makes the assumption that cryptographic keys are kept absolutely secret. In general this assumption is very difficult to guarantee in real life because computers may be compromised relatively easily. In this paper we investigate a class of attacks, which exploit memory disclosure vulnerabilities to expose cryptographic keys. We demonstrate that the threat is real by formulating an attack that exposed the private key of an OpenSSH server within1minute, and exposed the private key of an Apache HTTP server within5minutes. We propose a set of techniques to address such attacks. Experimental results show that our techniques are efficient (i.e., imposing no performance penalty) and effective - unless a large portion of allocated memory is disclosed. Keith Harrison, Shouhuai Xu |
DSN | 2 |
| 2007 | Towards an analytic model of epidemic spreading in heterogeneous systemsabstractMathematical models have been utilized to help understand the epidemic spreading of malicious codes (e.g., computer virus and worms). However, existing such models are either adapted from the ones developed to capture the epidemic spreading of biologically infectious diseases in homogeneous systems, or suitable only for a very specific class of heterogeneous systems. In this paper we present an attempt at building an analytic model of epidemic spreading of malicious codes in arbitrary heterogeneous systems. Xiaohu Li, T. Paul Parker, Shouhuai Xu |
QSHINE | 3 |
| 2007 | On the security of group communication schemesabstractMany emerging applications in both wired and wireless networks need support of secure group commu-nications. There have been many secure group communication schemes in the setting of wired networks. These schemes can be directly adopted in, or appropriately adapted to, the setting of wireless networks such as mobile ad hoc networks (MANETs) and sensor networks. In this paper we show that the popular group communication schemes that we have examined are vulnerable to the following attack: An out-sider adversary who compromises a certain legitimate group member could obtain all past and present group keys; this is in sharp contrast to the widely-accepted belief that a such adversary can only obtain the present group key. This attack is very powerful also because it provides the adversary the following flexibility: There are possibly many legitimate group members such that compromising any of them leads to the exposure of those past and present group keys. In order to understand and deal with the attack, we formalize two security models for stateful and stateless group communication schemes, respectively. We show that some practical methods can make a subclass of the group communication schemes immune to the attack. Shouhuai Xu |
J. Comput. Secur. | 1 |
| 2006 | Towards Understanding the (In)security of Networked Systems under Towards Understanding the (In)security of Networked Systems under Topology-Directed Stealthy AttacksabstractConsider a networked system of interest, where "networked" may be in a physical sense, meaning that the nodes are physically connected by point-to-point communication channels, or in a logical sense, meaning that the nodes are connected via edges that reflect certain relationships between the nodes (e.g., trust relationships). In such a system, once some nodes have been compromised, the attack would be directed by the network topology because compromise of a node may cause the compromise of its neighbors. Furthermore, the attack could be crafty or stealthy, meaning that it would always try not to trigger the intrusion detection alarm of the networked system. In such a setting, a question of particular interest to the system administrator is: What is the quantitative security assurance of the networked system? This problem is notoriously known to be difficult, and the state-of-the-art is that we know very little about it. This paper aims to move a step towards resolving this problem T. Paul Parker, Shouhuai Xu |
DASC | 2 |
| 2006 | Towards Blocking Outgoing Malicious Impostor EmailsabstractElectronic mails (emails) have become an indispensable part of most people daily routines. However, they were not designed for deployment in an adversarial environment, which explains why there have been so many incidents such as spamming and phishing. Malicious impostor emails sent by sophisticated attackers are perhaps even more damaging, because their contents, except the attachments, may look perfectly legitimate while silently targeting certain critical information such as cryptographic keys and passwords. In this paper, we explore a mechanism for blocking malicious impostor emails called ContAining Malicious Emails Locally (CAMEL), which aims at blocking compromised victim user machines from further infecting others. Erhan J. Kartaltepe, Shouhuai Xu |
WOWMOM | 2 |
| 2006 | LHAP: A lightweight network access control protocol for ad hoc networks
Sencun Zhu, Shouhuai Xu, Sanjeev Setia, Sushil Jajodia |
Ad Hoc Networks | 2 |
| 2006 | GKMPAN: An Efficient Group Rekeying Scheme for Secure Multicast in Ad-Hoc NetworksabstractWe present GKMPAN, an efficient and scalable group rekeying protocol for secure multicast in ad hoc networks. Our protocol exploits the property of ad hoc networks that each member of a group is both a host and a router, and distributes the group key to member nodes via a secure hop-by-hop propagation scheme. A probabilistic scheme based on pre-deployed symmetric keys is used for implementing secure channels between members for group key distribution. GKMPAN also includes a novel distributed scheme for efficiently updating the pre-deployed keys. GKMPAN has three attractive properties. First, it is significantly more efficient than group rekeying schemes that were adapted from those proposed for wired networks. Second, GKMPAN has the property of partial statelessness; that is, a node can decode the current group key even if it has missed a certain number of previous group rekeying operations. This makes it very attractive for ad hoc networks where nodes may lose packets due to transmission link errors or temporary network partitions. Third, in GKMPAN the key server does not need any information about the topology of the ad hoc network or the geographic location of the members of the group. We study the security and performance of GKMPAN through detailed analysis and simulation; we have also implemented GKMPAN in a sensor network testbed. Sencun Zhu, Sanjeev Setia, Shouhuai Xu, Sushil Jajodia |
J. Comput. Secur. | 3 |
| 2005 | Brief announcement: a flexible framework for secret handshakesabstractSecret handshakes offer anonymous and unobservable authentication and serve as an important tool in the arsenal of privacy-preserving techniques. Prior research focused on 2-party secret handshakes with one-time credentials. This paper breaks new ground on two accounts: (1) we obtain secure and efficient secret handshakes with reusable credentials, and (2) we provide the first treatment of multi-party secret handshakes. Gene Tsudik, Shouhuai Xu |
PODC | 2 |
| 2004 | Accountable Ring Signatures: A Smart Card Approach
Shouhuai Xu, Moti Yung |
CARDIS | 1 |
| 2004 | k-anonymous secret handshakes with reusable credentialsabstractThe problem of privacy-preserving authentication has been extensively investigated in a set of diverse system settings. However, a full-fledged such mechanism called secret handshake, whereby two users (e.g., CIA agents) authenticate each other in a way that no one reveals its own membership (or credential) unless the peer's legitimacy was already ensured of, remains to be elusive because simultaneity of authentication must be guaranteed even in the presence of an active adversary that may act as a handshake initiator or responder. The state-of-the-art secret handshake scheme is very efficient, but imposes on the users the following restriction: either they have to use one-time credentials, or they have to suffer from the privacy degradation that all the sessions involving a same user (or credential are trivially linkable. In this paper, we present the first secret handshake schemes that achieve unlinkability while allowing the users to reuse their credentials (i.e., unlinkability is not achieved by means of one-time credentials). Specifically, we introduce the concept of $k$-anonymous secret handshakes where $k$ is an adjustable parameter indicating the desired anonymity assurance. We present a detailed construction based on public key cryptosystems, and sketch another based on symmetric key cryptosystems. Both schemes are efficient, and can even be seamlessly integrated into a standard public key infrastructure (PKI). Moreover, and their security analysis does not resort to any random oracle. Shouhuai Xu, Moti Yung |
CCS | 1 |
| 2004 | Leak-Free Group Signatures with Immediate RevocationabstractGroup signatures are an interesting and appealing cryptographic construct with many promising potential applications. This work is motivated by attractive features of group signatures, particularly, their potential to serve as foundation for anonymous credential systems. We reexamine the entire notion of group signatures from a systems perspective and identify two new security requirements: leak-freedom and immediate-revocation, which are crucial for a large class of applications. We then present a new group signature scheme that achieves all identified properties. Our scheme is based on the so-called systems architecture approach. It is more efficient than the state-of-the-art and facilitates easy implementation. Moreover, it reflects the well-known separation-of-duty principle. Another benefit of our scheme is the obviated reliance on underlying anonymous communication channels, which are necessary in previous schemes. Xuhua Ding, Gene Tsudik, Shouhuai Xu |
ICDCS | 3 |
| 2004 | GKMPAN: An Efficient Group Rekeying Scheme for Secure Multicast in Ad-Hoc NetworksabstractWe present GKMPAN, an efficient and scalable group rekeying protocol for secure multicast in ad hoc networks. Our protocol exploits the property of ad hoc networks that each member of a group is both a host and a router, and distributes the group key to member nodes via a secure hop-by-hop propagation scheme. A probabilistic scheme based on predeployed symmetric keys is used for implementing secure channels between members for group key distribution. GKMPAN also includes a novel distributed scheme for efficiently updating the predeployed keys. GKMPAN has three attractive properties. First, it is significantly more efficient than group rekeying schemes that were adapted from those proposed for wired networks. Second, GKMPAN has the property of partial statelessness; that is, a node can decode the current group key even if it has missed a certain number of previous group rekeying operations. This makes it very attractive for ad hoc networks where nodes may lose packets due to transmission link errors or temporary network partitions. Third, in GKMPAN the key server does not need any information about the topology of the ad hoc network or the geographic location of the members of the group. We study the security and performance of GKMPAN through detailed analysis and simulation. Sencun Zhu, Sanjeev Setia, Shouhuai Xu, Sushil Jajodia |
MobiQuitous | 3 |
| 2003 | Accumulating Composites and Improved Group Signing
Gene Tsudik, Shouhuai Xu |
ASIACRYPT | 2 |
| 2003 | Two Efficient and Provably Secure Schemes for Server-Assisted Threshold Signatures
Shouhuai Xu, Ravi S. Sandhu |
CT-RSA | 1 |
| 2003 | Establishing Pairwise Keys for Secure Communication in Ad Hoc Networks: A Probabilistic ApproachabstractA prerequisite for a secure communication between two nodes in an ad hoc network is that the nodes share a key to bootstrap their trust relationship. In this paper, we present a scalable and distributed protocol that enables two nodes to establish a pairwise shared key on the fly, without requiring the use of any on-line key distribution center. The design of our protocol is based on a novel combination of two techniques - probabilistic key sharing and threshold secret sharing. Our protocol is scalable since every node only needs to possess a small number of keys, independent of the network size, and it is computationally efficient because it only relies on symmetric key cryptography based operations. We show that a pairwise key established between two nodes using our protocol is secure against a collusion attack by up to a certain number of compromised nodes. We also show through a set of simulations that our protocol can be parameterized to meet the desired levels of performance, security and storage for the application under consideration. Sencun Zhu, Shouhuai Xu, Sanjeev Setia, Sushil Jajodia |
ICNP | 2 |
| 2003 | Constructing Disjoint Paths for Secure Communication
Amitabha Bagchi, Amitabh Chaudhary, Michael T. Goodrich, Shouhuai Xu |
DISC | 4 |
| 2002 | Key-Insulated Public Key Cryptosystems
Yevgeniy Dodis, Jonathan Katz, Shouhuai Xu, Moti Yung |
EUROCRYPT | 3 |
| 2000 | Friendly Observers Ease Off-Line E-Cash
Shouhuai Xu, Moti Yung, Gendu Zhang |
CARDIS | 1 |