Zhenxin Zhan

dblp:91/8279 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
0since 2021 · last 2015
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-authorSystems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Network security · 100%
Computer networks
3 papers
Network measurement and analytics · 100%

Topics — the 5 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › intrusion detection and prevention
intrusion detection
0.422015
Predicting Cyber Attack Rates With Extreme Values · IEEE Trans. Inf. Forensics Secur. 2015
Characterizing Honeypot-Captured Cyber Attacks: Statistical Framework and Case Study · IEEE Trans. Inf. Forensics Secur. 2013
Network security › attack modeling
attack prediction
0.212015
Predicting Cyber Attack Rates With Extreme Values · IEEE Trans. Inf. Forensics Secur. 2015
Network security › malware propagation
epidemic modeling
0.112012
A Stochastic Model of Multivirus Dynamics · IEEE Trans. Dependable Secur. Comput. 2012
Network security
malware propagation
0.112012
A Stochastic Model of Multivirus Dynamics · IEEE Trans. Dependable Secur. Comput. 2012
Network measurement and analytics › network diffusion
epidemic threshold
0.012012
A Stochastic Model of Multivirus Dynamics · IEEE Trans. Dependable Secur. Comput. 2012

Methods — techniques the papers use, named apart from their topics

gray-box prediction · 0.8time series theory · 0.4extreme value theory · 0.4statistical framework · 0.3long-range dependence analysis · 0.3stochastic epidemic model · 0.3statistical physics · 0.3
YearPublicationVenuePosition
2015 Predicting Cyber Attack Rates With Extreme Values
abstract
It is important to understand to what extent, and in what perspectives, cyber attacks can be predicted. Despite its evident importance, this problem was not investigated until very recently, when we proposed using the innovative methodology of gray-box prediction. This methodology advocates the use of gray-box models, which accommodate the statistical properties/phenomena exhibited by the data. Specifically, we showed that gray-box models that accommodate the long-range dependence phenomenon can predict the attack rate (i.e., the number of attacks per unit time) 1-h ahead-of-time with an accuracy of 70.2%-82.1%. To the best of our knowledge, this is the first result showing the feasibility of prediction in this domain. We observe that the prediction errors are partly caused by the models' incapability in predicting the large attack rates, which are called extreme values in statistics. This motivates us to analyze the extreme-value phenomenon, using two complementary approaches: 1) the extreme value theory (EVT) and 2) the time series theory (TST). In this paper, we show that EVT can offer long-term predictions (e.g., 24-h ahead-of-time), while gray-box TST models can predict attack rates 1-h ahead-of-time with an accuracy of 86%-87.9%. We explore connections between the two approaches, and point out future research directions. Although our prediction study is based on specific cyber attack data, our methodology can be equally applied to analyze any cyber attack data of its kind.
Zhenxin Zhan, Maochao Xu, Shouhuai Xu
IEEE Trans. Inf. Forensics Secur.1
2014 Adaptive Epidemic Dynamics in Networks: Thresholds and Control
abstract
Theoretical modeling of computer virus/worm epidemic dynamics is an important problem that has attracted many studies. However, most existing models are adapted from biological epidemic ones. Although biological epidemic models can certainly be adapted to capture some computer virus spreading scenarios (especially when the so-called homogeneity assumption holds), the problem of computer virus spreading is not well understood because it has many important perspectives that are not necessarily accommodated in the biological epidemic models. In this article, we initiate the study of such a perspective, namely that ofadaptivedefense against epidemic spreading in arbitrary networks. More specifically, we investigate a nonhomogeneous Susceptible-Infectious-Susceptible (SIS) model where the model parameters may vary with respect to time. In particular, we focus on two scenarios we callsemi-adaptivedefense andfully adaptivedefense, which accommodate implicit and explicit dependency relationships between the model parameters, respectively. In the semi-adaptive defense scenario, the model’s input parameters are given; the defense is semi-adaptive because the adjustment is implicitly dependent upon the outcome of virus spreading. For this scenario, we present a set of sufficient conditions (some are more general or succinct than others) under which the virus spreading will die out; such sufficient conditions are also known asepidemic thresholdsin the literature. In the fully adaptive defense scenario, some input parameters are not known (i.e., the aforementioned sufficient conditions are not applicable) but the defender can observe the outcome of virus spreading. For this scenario, we present adaptive control strategies under which the virus spreading will die out or will be contained to a desired level.
Shouhuai Xu, Wenlian Lu, Zhenxin Zhan
ACM Trans. Auton. Adapt. Syst.4
2013 Cross-layer detection of malicious websites
abstract
Web threats pose the most significant cyber threat. Websites have been developed or manipulated by attackers for use as attack tools. Existing malicious website detection techniques can be classified into the categories of static and dynamic detection approaches, which respectively aim to detect malicious websites by analyzing web contents, and analyzing run-time behaviors using honeypots. However, existing malicious website detection approaches have technical and computational limitations to detect sophisticated attacks and analyze massive collected data. The main objective of this research is to minimize the limitations of malicious website detection. This paper presents a novel cross-layer malicious website detection approach which analyzes network-layer traffic and application-layer website contents simultaneously. Detailed data collection and performance evaluation methods are also presented. Evaluation based on data collected during 37 days shows that the computing time of the cross-layer detection is 50 times faster than the dynamic approach while detection can be almost as effective as the dynamic approach. Experimental results indicate that the cross-layer detection outperforms existing malicious website detection techniques.
Zhenxin Zhan, Shouhuai Xu, Keying Ye
CODASPY2
2013 Characterizing Honeypot-Captured Cyber Attacks: Statistical Framework and Case Study
abstract
Rigorously characterizing the statistical properties of cyber attacks is an important problem. In this paper, we propose the first statistical framework for rigorously analyzing honeypot-captured cyber attack data. The framework is built on the novel concept of stochastic cyber attack process, a new kind of mathematical objects for describing cyber attacks. To demonstrate use of the framework, we apply it to analyze a low-interaction honeypot dataset, while noting that the framework can be equally applied to analyze high-interaction honeypot data that contains richer information about the attacks. The case study finds, for the first time, that long-range dependence (LRD) is exhibited by honeypot-captured cyber attacks. The case study confirms that by exploiting the statistical properties (LRD in this case), it is feasible to predict cyber attacks (at least in terms of attack rate) with good accuracy. This kind of prediction capability would provide sufficient early-warning time for defenders to adjust their defense configurations or resource allocations. The idea of “gray-box” (rather than “black-box”) prediction is central to the utility of the statistical framework, and represents a significant step towards ultimately understanding (the degree of) the predictability of cyber attacks.
Zhenxin Zhan, Maochao Xu, Shouhuai Xu
IEEE Trans. Inf. Forensics Secur.1
2012 A Stochastic Model of Multivirus Dynamics
abstract
Understanding the spreading dynamics of computer viruses (worms, attacks) is an important research problem, and has received much attention from the communities of both computer security and statistical physics. However, previous studies have mainly focused on single-virus spreading dynamics. In this paper, we study multivirus spreading dynamics, where multiple viruses attempt to infect computers while possibly combating against each other because, for example, they are controlled by multiple botmasters. Specifically, we propose and analyze a general model (and its two special cases) of multivirus spreading dynamics in arbitrary networks (i.e., we do not make any restriction on network topologies), where the viruses may or may not coreside on computers. Our model offers analytical results for addressing questions such as: What are the sufficient conditions (also known as epidemic thresholds) under which the multiple viruses will die out? What if some viruses can "rob” others? What characteristics does the multivirus epidemic dynamics exhibit when the viruses are (approximately) equally powerful? The analytical results make a fundamental connection between two types of factors: defense capability and network connectivity. This allows us to draw various insights that can be used to guide security defense.
Shouhuai Xu, Wenlian Lu, Zhenxin Zhan
IEEE Trans. Dependable Secur. Comput.3
2010 Trustworthy Information: Concepts and Mechanisms
Shouhuai Xu, Haifeng Qian, Fengying Wang, Zhenxin Zhan, Elisa Bertino, Ravi S. Sandhu
WAIM4