Kun Zhang 0016

dblp:96/3115-16 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
12since 2021 · last 2025
0000-0003-2278-0979ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 6 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Zero-trust based dynamic access control for cloud computing
abstract
Abstract Most corporations and organizations rely heavily on access control to protect data accessibility and enable resource sharing across networks and departments. However, with the development of cloud computing, traditional boundary protection struggles to mitigate the increasing attacks and threats. In addition, most existing dynamic access control methods match static rules with dynamic metrics, which cause system damage through their delayed responses to threats and attacks. The zero-trust architecture (ZTA) provides continuous authentication and dynamic authorization for all users to accommodate the security demands of cloud computing. Drawing inspiration from the ZTA, we first present a TBAC (Trust-based Access Control) model and design a trust assessment methodology to update user trustworthiness. Then, we introduce dynamic rules in the TBAC model to implement a dynamic access control system DR-TBAC (TBAC with Dynamic Rule). We apply the DQN (Deep Q-Network) algorithm to dynamically update the trust thresholds based on static rules comparing dynamic trust with predefined trust thresholds to achieve adaptive access control policies. In this paper, we rebuild the cloud security access environment from the perspective of dynamic trust and rule optimization and strengthen the constraints on user behaviors throughout the access control lifecycle of cloud computing. Finally, a thorough analysis and assessment regarding offline training models and the online deployment of the DR-TBAC system into the cloud platform highlight its security and accuracy relative to baseline models.
Ri Wang, Chen Li 0066, Kun Zhang 0016, Bibo Tu
Cybersecur.3
2025 Towards Unsupervised Time-Series Anomaly Detection for Virtual Cloud Networks
abstract
Virtual cloud network (VCN) is a fundamental cloud resource for endpoints (VMs or containers) to communicate with each other and with the outside. Anomaly detection, a key security approach for VCNs, faces serious challenges: 1) Current feature models are difficult to apply to VCNs with significant differences from traditional networks. 2) Current anomaly detection models lack the adaptability to learn multiple normal patterns simultaneously. The need to train a dedicated model for each endpoint causes serious scalability problems in VCNs. 3) Current anomaly detection models have difficulty addressing the complex temporal dependency and non-stationarity of VCNs. To address these challenges, we propose a new multilevel feature model MFM and a new unsupervised time-series anomaly detection model GTGmVAE. By combining the basic features with the topology features specifically designed for VCNs, MFM effectively characterizes the patterns of VCNs. GTGmVAE combines the new local-global feature extractor with the latent space following a Gaussian mixture distribution to achieve the strong adaptability to learn multiple normal patterns simultaneously, and achieves the strong temporal modeling capability to effectively address the complex temporal dependency and non-stationarity of VCNs by adequately modeling the global temporal dependencies of the input samples and latent variables. Extensive experiments on the VCN anomaly detection dataset CIC-IDS2018 and the time-series anomaly detection benchmark dataset SMD show that GTGmVAE with MFM achieves the desirable performance, and GTGmVAE outperforms all nine representative state-of-the-art detection models.
Zixuan Ma, Chen Li 0066, Kun Zhang 0016, Bibo Tu
IEEE Trans. Inf. Forensics Secur.3
2024 EI-XIDS: An explainable intrusion detection system based on integration framework
abstract
The application of Deep Learning (DL) in Intrusion Detection Systems (IDS) has become a focal point of research due to its outstanding performance. However, the black-box nature of these systems has raised concerns within the research community. Addressing this challenge, this paper draws upon the concept of ensemble learning and introduces an Explainable Intrusion Detection System (X-IDS), EI-XIDS. This system integrates a variety of advanced Explainable Artificial Intelligence (XAI) methods and adaptively selects them according to different scenarios through reinforcement learning. Comparative experiments demonstrate that EI-XIDS outperforms the current state-of-the-art explanation methods, achieving label flip rates of 97% and 96% on the NSL-KDD and UNSW-NB15 datasets, respectively. These results underscore EI-XIDS’s superior interpretability accuracy, robustness, and sparsity, showcasing its significant potential in the field of network security.
Chen Li 0066, Kun Zhang 0016, Haojun Xia, Bibo Tu
CSCWD3
2024 CloudFusion: Multi-Source Intrusion Detection in Cloud Environments
abstract
Addressing the multifaceted security challenges inherent in cloud environments, our study delineates a robust, real-time threat detection framework. This methodology integrates three cardinal technologies: a memory access mechanism rooted in Virtual Machine Monitor (VMM) analytics, offering profound insights into the operational dynamics of virtual machines; a semantic reconstruction method, informed by software architectural tenets, adept at discerning intricate adversarial activities; and a log-oriented decoding and rule alignment mechanism tailored for sophisticated handling of cloud-based log data. In unison, these technologies forge a proficient, instantaneous threat detection paradigm. Applied and authenticated on a cloud platform, the proposed framework buttressed by judiciously crafted security protocols enables the contemporaneous surveillance of malicious incursions affecting virtual machines, host systems, and network data streams. Both functionality and efficiency assessments attest to the system’s adeptness in precise threat identification while ensuring minimal performance disruption for host and client systems.
Kun Zhang 0016, Haojun Xia, Bibo Tu, Chen Li 0066
CSCWD2
2024 Using KVM Events to Detect VM Memory-Sharing Lateral Movement Attacks in a Virtualized Environment
abstract
Virtual machine (VM) memory-sharing lateral movement attacks are becoming more advanced, while detection methods against them are still perceived as non-practical. Especially the current detection methods can't detect the VM escape attack. In this paper, we introduce a novel monitoring approach to detect VM memory-sharing lateral movement attacks operations inside a virtualization environment. We utilize the Kernel Virtual Machine (KVM) event sequence data in the kernel and process this data using a machine learning technique to identify any VM memory-sharing lateral movement attacks operations in the guest VM. Experimental results demonstrate that our method successfully separates the VM memory-sharing lateral movement attacks datasets on VMs from the non attacks datasets on VMs, on both trained and nontrained data scenarios. Besides, we also explain the classification results by extracting the set of most important features that separate both classes using their Fisher scores and variance and show that our detecting approach can work to detect VM memory-sharing lateral movement attacks in general. Finally, we evaluate the overhead impact of our VM memory-sharing lateral movement attacks detecting method and show that it has a negligible computation overhead on the host and the guest VM.
Kun Zhang 0016, Chen Li 0066
ISPA1
2023 AuthConFormer: Sensor-based Continuous Authentication of Smartphone Users Using A Convolutional Transformer
Kun Zhang 0016, Ruibang You, Bibo Tu
Comput. Secur.2
2023 Multisensor-Based Continuous Authentication of Smartphone Users With Two-Stage Feature Extraction
abstract
The one-time authentication mechanism in traditional authentication methods cannot continuously authenticate smartphone users’ identities throughout the session. Continuous authentication based on the behavioral biometrics recorded by the built-in sensors can solve this issue. However, the existing methods based on multisensor have poor ability to extract valuable features that can represent smartphone users’ behavioral patterns. This article proposes a novel method combining the manual construction and the deep metric learning method to perform two-stage feature extraction, respectively. We transform the time-series raw data from three sensors (accelerometer, gyroscope, and magnetometer) into 69 statistical features in the first stage. Furthermore, unlike the existing serial feature fusion methods, we innovatively fuse the constructed statistical features from three sensors into a three-channel matrix. Then, the fused features matrix with a three-channel is fed to the deep metric learning model for the second stage of feature extraction. We use the elliptic envelope algorithm to classify the user as a legitimate user or an impostor. Finally, we evaluate the performance of the proposed method on two public data sets. Experimental results show that our method can achieve an average accuracy of 99.71% and an average equal error rate (EER) of 0.56% on the hand movement, movement, orientation, and grasp data set, and an average accuracy of 99.59% and an average EER of 0.61% on the BrainRun data set.
Kun Zhang 0016, Ruibang You, Bibo Tu
IEEE Internet Things J.2
2023 HyperPS: A Virtual-Machine Memory Protection Approach Through Hypervisor's Privilege Separation
abstract
The HostOS or Hypervisor constitutes the most important cornerstone of today's commercial cloud environment security. Unfortunately, the HostOS/Hypervisor, especially the QEMU-KVM architecture, is not immune to all vulnerabilities and exploitations. Recently, researchers have put forward lots of schemes to protect Virtual Machines under the compromised HostOS/Hypervisor. However, some of these schemes rely on special hardware facilities, while other (e.g., Nested Virtualization schemes) require large modification to current commercial cloud architecture. In this paper, we present a novel scheme, named HyperPS, to implement virtual machine protection under the compromised HostOS/Hypervisor. The key idea of HyperPS is to deprive the HostOS/Hypervisor of the privileges of managing the physical memory into an isolated and trusted execution environment. HyperPS does not rely customized hardware or extra processor privilege. HyperPS shares the same privilege with the HostOS. We have implemented a fully functional prototype based on the KVM in Intel x86_64 architecture. Experiment results show that HyperPS has achieved an acceptable trade-off between security and performance.
Kunli Lin, Wenqing Liu, Kun Zhang 0016, Bibo Tu
IEEE Trans. Dependable Secur. Comput.3
2022 Evaluation and Optimization on Virtualization Performance Cost under Semantic Gap
abstract
Virtualization is a key enabling technology in modern data centers. While it provides numerous benefits, it also creates new problems. Virtualization requires the hypervisor to treat the virtual machine as a black box, limiting the ability of information exchange between the hypervisor and the virtual machine, bringing a problem known as the semantic gap. Currently, much research on the semantic gap mainly focuses on bridging the semantic gap. The evaluation of the semantic gap, on the other hand, is a neglected but crucial problem, and relevant research is currently lacking. Therefore, this paper proposes a corresponding virtualization performance cost model to better evaluate the semantic gap. Based on this cost model, we summarize solutions that can be used to alleviate the semantic gap. Furthermore, we propose a novel evaluation method for the CPU double scheduling semantic gap. Finally, we propose an effective virtio-balloon based dynamic memory tuning strategy to alleviate the memory semantic gap. The experiments show that for 400.perlbench, our strategy saves 551MB of memory on average during running and reclaims 990MB of memory after running, with a performance cost of only 1.1%. For 429.mcf, our strategy saves 815MB of memory on average during running and reclaims 2130MB of memory after running, although with the performance cost of 27.6%, it prevents performance cliff-like drop caused by memory shortage.
Haojun Xia, Kun Zhang 0016, Bibo Tu
CSCWD3
2021 HyperKRP: A Kernel Runtime Security Architecture with A Tiny Hypervisor on Commodity Hardware
abstract
The large body of kernel code provides broad attack surfaces to exploitable bugs or misconfigurations. Current mitigations are difficult to be integrated together or have a non-trivial performance or code size impact. Thus, systematical protection for the kernel is of critical importance and is required. In this paper, we propose a kernel runtime security architecture, called HyperKRP, to provide systematical protection for kernel code, critical kernel data, and efficient kernel page tables. We have implemented a fully working prototype for a recent Linux kernel running on the Intel x86 processor. Our prototype is compromised of three protection engines based on a small size hypervisor. The evaluation shows that HyperKRP effectively ensures kernel runtime security with acceptable overhead.
Kunli Lin, Wenqing Liu, Kun Zhang 0016, Haojun Xia, Bibo Tu
GLOBECOM3
2021 Remote Attestation of Large-scale Virtual Machines in the Cloud Data Center
abstract
With the development of cloud computing, remote attestation of virtual machines has received extensive attention. However, the current schemes mainly concentrate on the single prover, and the attestation of a large-scale virtualization environment will cause TPM bottleneck and network congestion, resulting in low efficiency of attestation. This paper proposes CloudTA, an extensible remote attestation architecture. CloudTA groups all virtual machines on each cloud server and introduces an integrity measurement group (IMG) to measure virtual machines and generate trusted evidence by a group. Subsequently, the cloud server reports the physical platform and VM group's trusted evidence for group verification, reducing latency and improving efficiency. Besides, CloudTA designs a hybrid high concurrency communication framework for supporting remote attestation of large-scale virtual machines by combining active requests and periodic reports. The evaluation results suggest that CloudTA has good efficiency and scalability and can support remote attestation of ten thousand virtual machines.
Kun Zhang 0016, Bibo Tu
TrustCom2
2021 Log-based Anomaly Detection from Multi-view by Associating Anomaly Scores with User Trust
abstract
Logs, prevalent among nearly all computer systems, contain rich information that helps with troubleshooting or root cause analysis. Therefore, logs are excellent information sources for anomaly detection. Since logs are diverse and heterogeneous, to deal with all of them requires maintenance personnel to check detection results one by one, which is troublesome. This paper applies an ensemble method that combines the output of different results of log anomaly detection and generates a unified output to reduce the burden of maintenance personnel. Since logs are recorded according to user behavior, they often have non-fixed intervals. We apply a trust computational model to transform the unevenly distributed data into a regularly spaced time series. To our best knowledge, this is the first work to employ the trust in the data processing. Futhermore, there are some parameters introduced by the trust computational model. We take advantage of the parametric ensemble technique to address the issue of parameter choice and finally improve the accuracy of anomaly detection. In this way, our method allows one to track a user from multi-view by logs with ease. The experiment shows that our method could achieve a good performance in detecting anomalies of user behavior from multiple kinds of logs.
Lin Wang 0042, Kun Zhang 0016, Chen Li 0066, Bibo Tu
TrustCom2
2018 PCA: Page Correlation Aggregation for Memory Deduplication in Virtualized Environments
Kun Zhang 0016, Bibo Tu
ICICS2