VLDB 2026 Research / reviewers in the wild / expert
Weizhong Qiang
dblp:q/WeizhongQiang
· DBLP profile ↗
50ranked-venue papers
22as first author
14since 2021 · last 2026
0000-0003-4390-3819ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 21 · 9 first-author · 7 since 2021Security and privacy · 18 · 9 first-author · 7 since 2021Computer networks · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VulJSFormer: Learning to Detect JavaScript Vulnerabilities with Vulnerability-Relevant Graphs
Kunlun Ren, Haochen He, Weizhong Qiang, Yueming Wu 0001, Deqing Zou |
DSN | 4 |
| 2026 | Forseti: A Decentralized Permission Transfer Framework for IoT LeasingabstractThe widespread use of IoT devices in the accommodation and hospitality sectors has created demand for temporary device-permission sharing and transfer. Prior work has largely focused on security issues in device permission sharing, with far less attention devoted to device permission transfer. However, inappropriate access control management during device permission transfer can also lead to violations of the users' expectations of control over their devices. For example, a malicious host retaining or regaining access to a camera after its permission has been transferred to a tenant. In this paper, we present the first systematic study on understanding and enhancing the security of device permission transfer in IoT leasing. To this end, we propose Forseti, a new authorization framework that leverages zero-knowledge proof and a decentralized ledger to ensure that the rights of both hosts and tenants are not violated. Our evaluation demonstrates that Forseti is effective, efficient, scalable, and compatible with existing IoT platforms. Bin Yuan 0002, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | ρHammer: Reviving RowHammer Attacks on New Architectures via PrefetchingabstractRowhammer is a critical vulnerability in dynamic random access memory (DRAM) that continues to pose a significant threat to various systems. However, we find that conventional load-based attacks are becoming highly ineffective on the most recent architectures such as Intel Alder and Raptor Lake. In this paper, we present $ρ$Hammer, a new Rowhammer framework that systematically overcomes three core challenges impeding attacks on these new architectures. First, we design an efficient and generic DRAM address mapping reverse-engineering method that uses selective pairwise measurements and structured deduction, enabling recovery of complex mappings within seconds on the latest memory controllers. Second, to break through the activation rate bottleneck of load-based hammering, we introduce a novel prefetch-based hammering paradigm that leverages the asynchronous nature of x86 prefetch instructions and is further enhanced by multi-bank parallelism to maximize throughput. Third, recognizing that speculative execution causes more severe disorder issues for prefetching, which cannot be simply mitigated by memory barriers, we develop a counter-speculation hammering technique using control-flow obfuscation and optimized NOP-based pseudo-barriers to maintain prefetch order with minimal overhead. Evaluations across four latest Intel architectures demonstrate $ρ$Hammer's breakthrough effectiveness: it induces up to 200K+ additional bit flips within 2-hour attack pattern fuzzing processes and has a 112x higher flip rate than the load-based hammering baselines on Comet and Rocket Lake. Also, we are the first to revive Rowhammer attacks on the latest Raptor Lake architecture, where baselines completely fail, achieving stable flip rates of 2,291/min and fast end-to-end exploitation. Shan Tang, Yulin Tang, Xiapu Luo, Yinqian Zhang, Weizhong Qiang |
MICRO | 6 |
| 2024 | Owl: Differential-Based Side-Channel Leakage Detection for CUDA ApplicationsabstractOver the past decade, various methods for detecting side-channel leakage have been proposed and proven to be effective against CPU side-channel attacks. These methods are valuable in assisting developers to identify and patch side-channel vulnerabilities. Nevertheless, recent research has revealed the feasibility of exploiting side-channel vulnerabilities to steal sensitive information from GPU applications, which are beyond the reach of previous side-channel detection methods. Therefore, in this paper, we conduct an in-depth examination of various GPU features and present Owl, a novel side-channel detection tool targeting CUDA applications on NVIDIA GPUs. Owl is designed to detect and locate side-channel leakage in various types of CUDA applications. When tracking the execution of CUDA applications, we design a hierarchical tracing scheme and extend the A-DCFG (Attributed Dynamic Control Flow Graph) to address the massively parallel execution in CUDA, ensuring Owl's detection scalability. After completing the initial assessment and filtering, we conduct statistical tests on the differences in program traces to determine whether they are indeed caused by input variations, subsequently facilitating the positioning of side-channel leaks. We evaluate Owl's capability to detect side-channel leaks by testing it on Libgpucrypto, PyTorch, and nvJPEG. Meanwhile, we verify that our solution effectively handles a large number of threads. Owl has successfully identified hundreds of leaks within these applications. To the best of our knowledge, we are the first to implement side-channel leakage detection for general CUDA applications. Wenjie Xue, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
DSN | 4 |
| 2024 | ReminISCence: Trusted Monitoring Against Privileged Preemption Side-Channel Attacks
Yinqian Zhang, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
ESORICS (4) | 4 |
| 2024 | DeepFPD: Browser Fingerprinting Detection via Deep Learning With Multimodal Learning and AttentionabstractBrowser fingerprinting is a stateless tracking technique that poses a significant security threat to users' privacy. However, the distinction between fingerprinting and nonfingerprinting scripts is far from well-defined, making the detection of fingerprinting scripts very challenging. Existing methods for detecting browser fingerprinting are based on heuristics or machine learning, and thus either require strictly defined rules or are not able to learn the features of fingerprinting scripts comprehensively, failing to detect a significant fraction of fingerprinting scripts. To detect browser fingerprinting more effectively, we propose a deep learning-based detection method,DeepFPD, in which multiple script modalities including tokens, abstract syntax trees, and control flow graphs are learned by using different specific neural networks to obtain lexical, syntax, and control flow information of the script code. Moreover, the attention mechanism is introduced to enhance the effectiveness ofDeepFPD. The experimental results on the training dataset and test dataset constructed based on real-world scripts show thatDeepFPDoutperforms the state-of-the-art work with an F1-measure improvement of 8.3% and 18.7%, respectively. Weizhong Qiang, Kunlun Ren, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Reliab. | 1 |
| 2023 | JSRevealer: A Robust Malicious JavaScript Detector against ObfuscationabstractDue to the convenience and popularity of Web applications, they have become a prime target for attackers. As the main programming language for Web applications, many methods have been proposed for detecting malicious JavaScript, among which static analysis-based methods play an important role because of their high effectiveness and efficiency. However, obfuscation techniques are commonly used in JavaScript, which makes the features extracted by static analysis contain many useless and disguised features, leading to many false positives and false negatives in detection results. In this paper, we propose a novel method to find out the essential features related to the semantics of JavaScript code. Specifically, we develop JS-Revealer, a robust, effective, scalable, and interpretable detector for malicious JavaScript. To test the capabilities of JSRevealer, we conduct comparative experiments with four other state-of-the-art malicious JavaScript detection tools. The experimental results show that JSRevealer has an average F1 of 84.8% on the data obfuscated by different obfuscators, which is 21.6%, 22.3%, 18.7%, and 22.9% higher than the tools CUJO, ZOZZLE, JAST, and JSTAP, respectively. Moreover, the detection results of JSRevealer can be interpreted, which can provide meaningful insights for further security research. Kunlun Ren, Weizhong Qiang, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
DSN | 2 |
| 2023 | An Empirical Study on the Effects of Obfuscation on Static Machine Learning-Based Malicious JavaScript DetectorsabstractMachine learning is increasingly being applied to malicious JavaScript detection in response to the growing number of Web attacks and the attendant costly manual identification. In practice, to hide their malicious behaviors or protect intellectual copyrights, both malicious and benign scripts tend to obfuscate their own code before uploading. While obfuscation is beneficial, it also introduces some additional code features (e.g., dead code) into the code. When machine learning is employed to learn a malicious JavaScript detector, these additional features can affect the model to make it less effective. However, there is still a lack of clear understanding of how robust existing machine learning-based detectors are on different obfuscators. In this paper, we conduct the first empirical study to figure out how obfuscation affects machine learning detectors based on static features. Through the results, we observe several findings: 1) Obfuscation has a significant impact on the effectiveness of detectors, causing an increase both in false negative rate (FNR) and false positive rate (FPR), and the bias of obfuscation in the training set induces detectors to detect obfuscation rather than malicious behaviors. 2) The common measures such as improving the quality of the training set by adding relevant obfuscated samples and leveraging state-of-the-art deep learning models can not work well.3) The root cause of obfuscation effects on these detectors is that feature spaces they use can only reflect shallow differences in code, not about the nature of benign and malicious, which can be easily affected by the differences brought by obfuscation. 4) Obfuscation has a similar effect on realistic detectors in VirusTotal, indicating that this is a common real-world problem. Kunlun Ren, Weizhong Qiang, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
ISSTA | 2 |
| 2023 | SpecTerminator: Blocking Speculative Side Channels Based on Instruction Classes on RISC-VabstractIn modern processors, speculative execution has significantly improved the performance of processors, but it has also introduced speculative execution vulnerabilities. Recent defenses are based on the delayed execution to block various speculative side channels, but we show that several of the current state-of-the-art defenses fail to block some of the available speculative side channels, and the current most secure defense introduces a performance overhead of up to 24.5%. We propose SpecTerminator, the first defense framework based on instruction classes that can comprehensively and precisely block all existing speculative side channels. In SpecTerminator, a novel speculative side channel classification scheme based on the features of secret transmission is proposed, and the sensitive instructions in the speculative window are classified and identified using optimized hardware taint tracking and instruction masking techniques to accurately determine the scope of leakage. Then, according to the execution characteristics of these instructions, dedicated delayed execution strategies, such as TLB request ignoring, selective issue, and extended delay-on-miss, are designed for each type of sensitive instruction to precisely control that these instructions are delayed only in pipeline stages that are at risk of leakage. In contrast to previous defenses based on the Gem5 simulator, we have innovatively implemented defenses against Spectre attacks based on the open-source instruction set RISC-V on an FPGA-accelerated simulation platform that is more similar to real hardware. To evaluate the security of SpecTerminator, we have replicated various existing x86-based Spectre variants on RISC-V. On SPEC 2006, SpecTerminator defends against Spectre attacks based on memory hierarchy side channels with a performance overhead of 2.6% and against all existing Spectre attacks with a performance overhead of 6.0%. Hai Jin 0001, Zhuo He, Weizhong Qiang |
ACM Trans. Archit. Code Optim. | 3 |
| 2022 | AutoSlicer: Automatic Program Partitioning for Securing Sensitive Data Based-on Data Dependency Analysis and Code RefactoringabstractLegacy programs are normally monolithic (that is, all code runs in a single process and is not partitioned), and a bug in a program may result in the entire program being vulnerable and therefore untrusted. Program partitioning can be used to separate a program into multiple partitions, so as to isolate sensitive data or privileged operations. Manual program partitioning requires programmers to rewrite the entire source code, which is cumbersome, error-prone, and not generic. Automatic program partitioning tools can separate programs according to the dependency graph constructed based on data or programs. However, programmers still need to manually implement remote service interfaces for inter-partition communication. Therefore, in this paper, we propose AutoSlicer, whose purpose is to partition a program more automatically, so that the programmer is only required to annotate sensitive data. AutoSlicer constructs accurate data dependency graphs (DDGs) by enabling execution flow graphs, and the DDG-based partitioning algorithm can compute partition information based on sensitive annotations. In addition, the code refactoring toolchain can automatically transform the source code into sensitive and insensitive partitions that can be deployed on the remote procedure call framework. The experimental evaluation shows that AutoSlicer can effectively improve the accuracy (13%-27%) of program partitioning by enabling EFG, and separate real-world programs with a relatively smaller performance overhead (0.26%-9.42%). Weizhong Qiang |
TrustCom | 1 |
| 2022 | Efficient and Robust Malware Detection Based on Control Flow Traces Using Deep Neural Networks
Weizhong Qiang, Hai Jin 0001 |
Comput. Secur. | 1 |
| 2022 | Privacy Preserving High-Order Bi-Lanczos in Cloud-Fog Computing for Industrial ApplicationsabstractIndustrial cyber–physical–social systems (CPSSs), a prominent data-driven paradigm, tightly couple and coordinate social space into cyber–physical systems (CPSs) within industrial environments. With the proliferation of cloud–fog computing, cloud–fog computing becomes the most prominent computing paradigm used to implement industrial data analysis. However, the open environment of cloud–fog computing and the limited control of industrial CPSSs users make industrial data analysis without compromising users’ privacy one great research challenge in practical cloud–fog-based industrial applications. High-order Bi-Lanczos (HOBI-Lanczos) approach has shown remarkable success in heterogeneous data analysis in industrial applications. In this article, a novel privacy preserving HOBI-Lanczos approach using tensor train in cloud–fog computing is proposed for industrial data applications. Specifically, a privacy preserving industrial data analysis model using cloud–fog computing and tensor train is firstly proposed. The proposed model enables fogs and clouds to securely carry out industrial data analysis for large-scale tensors given in a tensor train format. In addition, by using this model, a privacy preserving HOBI-Lanczos approach is provided. Last but not least, by using a brain-controlled robot system case study, the proposed approach is theoretically and empirically analyzed. Our proposed approach is proven to be secure. A series of experiments corroborate the superiority of the proposed approach in cloud–fog computing for industrial applications. Jun Feng 0007, Laurence T. Yang, Ronghao Zhang, Weizhong Qiang, Jinjun Chen |
IEEE Trans. Ind. Informatics | 4 |
| 2021 | Defending CNN against privacy leakage in edge computing via binary neural networks
Weizhong Qiang, Renwan Liu, Hai Jin 0001 |
Future Gener. Comput. Syst. | 1 |
| 2021 | CloudCFI: Context-Sensitive and Incremental CFI in the Cloud EnvironmentabstractControl-Flow Integrity(CFI) is one of the most promising techniques against control-flow hijacking attacks. ForCommercial Off-the-Shelf(COTS) binaries, a number of solutions provide coarse-grained CFI and thus are context-insensitive, while having the benefit of introducing a low runtime overhead. However, they can hardly defend against elaborately designed attacks due to the inaccuracy of theControl-Flow Graphs(CFGs). This paper presentsCloudCFI, a context-sensitive and incremental CFI, which specifically makes full use of the characteristic of the cloud environment, where multiple instances of a software run on multiple virtual machines, and the control flow checking result from one software instance could be utilized to handle the control-hijacking occurred on other sibling instances. InCloudCFI, the accuracy of the control flow checking can be continuously increased to offer the incremental CFI, and a context-sensitive CFI policy is enforced to determine the validity of the control flow of the execution path through checking the entire execution path instead of the single edge or partial edges in the execution path.CloudCFIincludes the static phase and the runtime phase respectively. Control-flow information and basic-block information is collected through emulation execution in the static phase, and the execution paths are tracked in runtime phase to collect process-tracking information. Next, it recovers the execution path by using basic-block information and process-tracking information, and checks the validity of the control flow by using the control-flow information. A prototype system is implemented and evaluated from several aspects using RIPE and SPEC benchmarks, as well as real-world cloud applications, Memcached and Redis. The evaluation results show thatCloudCFIcan defend against most common control-flow hijacking attacks. Meanwhile, it only introduces a low runtime performance overhead. Weizhong Qiang, Yingda Huang, Hai Jin 0001, Laurence T. Yang, Deqing Zou |
IEEE Trans. Cloud Comput. | 1 |
| 2020 | A Tensor-Based Optimization Model for Secure Sustainable Cyber-Physical-Social Big Data ComputationsabstractSecure cyber-physical-social big data computations are being increasingly used to protect the users' data security in cyber-physical-social systems (CPSS). Despite the increasing popularity, how to process the tasks of the secure cyber-physical-social big data computations, while taking care of the energy consumption and meeting the users' requirements, remains challenging. To address the problem, in this work, we propose a novel tensor-based optimization model for the secure sustainable cyber-physical-social big data computations. The proposed model is a general and fine-grained model, which can jointly optimize the execution time, energy consumption, reliability, and quality of experience, and can comprehensively take into account step, task, time slot, type, node, core, cryptosystem, and security level. To our knowledge, this is the first study to holistically optimize the tasks in the secure cyber-physical-social big data computations. To illustrate the proposed model, the case study of the secure high-order Lanczos in cloud-assisted CPSS is presented. Finally, the proposed model is empirically evaluated by using multi-objective optimization, and the extensive results demonstrate that from the users' perspective our proposed tensor-based optimization model is preferable for the secure sustainable cyber-physical-social big data computations. Jun Feng 0007, Laurence T. Yang, Ronghao Zhang, Shunli Zhang 0003, Guohui Dai, Weizhong Qiang |
IEEE Trans. Sustain. Comput. | 6 |
| 2019 | Differential Privacy Preservation for Smart Meter Systems
Junfang Wu, Weizhong Qiang, Tianqing Zhu, Hai Jin 0001, Peng Xu 0003, Sheng Shen 0005 |
ICA3PP (1) | 2 |
| 2019 | A Multigranularity Forensics and Analysis Method on Privacy Leakage in Cloud EnvironmentabstractThe problem of cloud forensics aims at processing multidimensional, massive, and heterogeneous data to collect and recover evidence in cloud environment. Existing approaches focus on excavating all suspicious behaviors from data and ignore privacy leakage details and behavioral characteristics. In order to conduct privacy leakage analysis in cloud specifically, we propose a multigranularity privacy leakage forensics method to analyze privacy violations caused by malware in cloud environment. By simulating the target virtual machine environment, our method can detect privacy leakage behaviors of malware without touching user's privacy data. We combine continuous RAM mirroring technology and dynamic taint analysis to assist the forensics investigation. To demonstrate the efficacy and utility of our method, we evaluate its performance with some real-world malware samples by comparing with some state-of-the-art malware analysis systems. Experimental results indicate that our method can identify more privacy leakage paths and behaviors. Deqing Zou, Jian Zhao 0012, Yueming Wu 0001, Weizhong Qiang, Hai Jin 0001 |
IEEE Internet Things J. | 5 |
| 2019 | LSTM and Edge Computing for Big Data Feature Recognition of Industrial Electrical EquipmentabstractWith the rapid development of Industrial Internet of Things, the category and quantity of industrial equipment will increase gradually. For centralized monitoring and management of numerous and multivariate equipment in the intelligent manufacturing process, the equipment categories shall be identified first. However, manual labeling of electrical equipment needs high costs. For the purpose of recognizing industrial equipment accurately in manufacturing systems, this study adopts the long short-term memory to analyze big data features and build a nonintrusive load monitoring system. Edge computing is used to implement parallel computing to improve the efficiency of equipment identification. Considering the practical popularity, the fairly priced low-frequency Smart Meter is used to collect the appliance data. According to the proposed optimal adjustment strategy of parameter model, the average random recognition rate can achieve 88% and the average recognition rate of the continuous data of a single electrical equipment can achieve 83.6%. Chin-Feng Lai, Wei-Che Chien, Laurence T. Yang, Weizhong Qiang |
IEEE Trans. Ind. Informatics | 4 |
| 2019 | Performance and security in cloud computing
Weizhong Qiang |
J. Supercomput. | 1 |
| 2019 | Defending Against Flow Table Overloading Attack in Software-Defined NetworksabstractThe Software-Defined Network (SDN) is a new and promising network architecture. At the same time, SDN will surely become a new target of cyber attackers. In this paper, we point out one critical vulnerability in SDNs, the size of flow table, which is most likely to be attacked. Due to the expensive and power-hungry features of Ternary Content Addressable Memory (TCAM), a flow table usually has a limited size, which can be easily disabled by a flow table overloading attack (a transformed DDoS attack). To provide a security service in SDN, we proposed a QoS-aware mitigation strategy, namely, peer support strategy, which integrates the available idle flow table resource of the whole SDN system to mitigate such an attack on a single switch of the system. We established a practical mathematical model to represent the studied system, and conducted a thorough analysis for the system in various circumstances. Based on our analysis, we found that the proposed strategy can effectively defeat the flow table overloading attacks. Extensive simulations and testbed-based experiments solidly support our claims. Moreover, our work also shed light on the implementation of SDN networks against possible brute-force attacks. Bin Yuan 0002, Deqing Zou, Shui Yu 0001, Hai Jin 0001, Weizhong Qiang, Jinan Shen |
IEEE Trans. Serv. Comput. | 5 |
| 2018 | Se-Lambda: Securing Privacy-Sensitive Serverless Applications Using SGX Enclave
Weizhong Qiang, Zezhao Dong, Hai Jin 0001 |
SecureComm (1) | 1 |
| 2018 | TNGuard: Securing IoT Oriented Tenant Networks Based on SDNabstractIn the paradigm of infrastructure-as-a-service cloud computing involving an Internet of Things network, customers outsource their infrastructure to the cloud. An outsourced infrastructure is a virtual infrastructure that mimics the physical infrastructure of the precloud era; it is therefore referred to as a tenant network (TN) in this paper. This practice draws upon the notion of TN abstraction, which specifies how TNs should be managed. However, current virtual software-defined network (SDN) technology uses an SDN hypervisor to attain TNs, where the cloud administrator is given much-more-than-necessary privileges; thus, not only could violation of the security principle of least privilege occur, but the threat of a malicious or innocent-but-compromised administrator may be present. Motivated by this need, we propose the specification of TN abstraction, including its functions and security requirements. Then, we present a platform-independent concretization of this abstraction called TNGuard, which is an SDN-based architecture that protects the TNs while removing unnecessary privileges from the cloud administrator. In order to show that TNGuard concretizes the TN abstraction, we present an instantiation of TNGuard on the Xen virtualization platform with the Ryu controller. Experimental results show that the resulting system is practical, incurring a small performance overhead. Weiqi Dai, Weizhong Qiang, Laurence T. Yang, Deqing Zou, Hai Jin 0001, Shouhuai Xu, Zirong Huang |
IEEE Internet Things J. | 3 |
| 2018 | Fine-Grained Control-Flow Integrity Based on Points-to Analysis for CPSabstractA cyber-physical system (CPS) is known as a mix system composed of computational and physical capabilities. The fast development of CPS brings new security and privacy requirements. Code reuse attacks that affect the correct behavior of software by exploiting memory corruption vulnerabilities and reusing existing code may also be threats to CPS. Various defense techniques are proposed in recent years as countermeasures to emerging code reuse attacks. However, they may fail to fulfill the security requirement well because they cannot protect the indirect function calls properly when it comes to dynamic code reuse attacks aiming at forward edges of control-flow graph (CFG). In this paper, we propose P-CFI, a fine-grained control-flow integrity (CFI) method, to protect CPS against memory-related attacks. We use points-to analysis to construct the legitimate target set for every indirect call cite and check whether the target of the indirect call cite is in the legitimate target set at runtime. We implement a prototype of P-CFI on LLVM and evaluate both its functionality and performance. Security analysis proves that P-CFI can mitigate the dynamic code reuse attack based on forward edges of CFG. Performance evaluation shows that P-CFI can protect CPS from dynamic code reuse attacks with trivial time overhead between 0.1% and 3.5% (Copyright © 2018 John Wiley & Sons, Ltd.). Weizhong Qiang, Shizhen Wang, Hai Jin 0001 |
Secur. Commun. Networks | 1 |
| 2018 | Corrigendum to "Fine-Grained Control-Flow Integrity Based on Points-to Analysis for CPS"
Weizhong Qiang, Shizhen Wang, Hai Jin 0001, Jiangying Zhong |
Secur. Commun. Networks | 1 |
| 2017 | JSFfox: Run-Timely Confining JavaScript for Firefox
Weizhong Qiang, JiaZhen Guo, Hai Jin 0001 |
ACISP (2) | 1 |
| 2017 | Fully Context-Sensitive CFI for COTS Binaries
Weizhong Qiang, Yingda Huang, Deqing Zou, Hai Jin 0001, Shizhen Wang, Guozhong Sun |
ACISP (2) | 1 |
| 2017 | DroidAuditor: A framework for auditing covert communication on AndroidabstractSummary Exploitation of covert channels in smartphone operating systems may lead to furtive data transmission between applications with different permissions, which might threaten users' privacy. Restricting the access to shared system resources can effectively prevent the exploitation of known covert channels. However, it inevitably limits the normal usage of those resources. In this paper, we propose a general method that detects covert channel attack at runtime without impacting the accessibility of shared resources in the system. The main idea of the method is to track and audit the use of system resources known as potential covert channel variables and impose interferences on those channels to reduce their capacity once violations are detected. We implement a prototype framework, which is able to audit and interfere covert communication both in the application layer and in the native layer of Android. The experimental results demonstrate that our method can effectively reduce the data rate of user‐defined covert channels while the overhead is negligible. Weizhong Qiang, Shifan Xin, Hai Jin 0001, Guozhong Sun |
Concurr. Comput. Pract. Exp. | 1 |
| 2017 | MUC: Updating cloud applications dynamically via multi-version execution
Weizhong Qiang, Laurence T. Yang, Hai Jin 0001 |
Future Gener. Comput. Syst. | 1 |
| 2016 | Reducing TCB of Linux Kernel Using User-Space Device Driver
Weizhong Qiang, Hai Jin 0001 |
ICA3PP | 1 |
| 2016 | Auditing Covert Communication between Applications on AndroidabstractExploitation of covert channels in smartphone operating systems may lead to furtive data transmission between applications with different permissions, which might threaten users' privacy. Restricting the access to shared system resources can effectively prevent the exploitation of known covert channels. However, it inevitably limits the normal usage of those resources. In this paper, we propose a general method that detects covert channel attack at runtime without impacting the accessibility of shared resources in the system. The main idea of the method is to track and audit the use of system resources known as potential covert channel variables, and impose interferences on those channels to reduce their capacity once violations are detected. We implement a prototype framework, which is able to audit and interfere covert communication both in the application layer and the native layer of Android. The experimental results demonstrate that our method can effectively reduce the data rate of user-defined covert channels while the overhead is negligible. Weizhong Qiang, Shifan Xin, Hai Jin 0001, Xinqiao Lv, Qin Zhang 0004 |
ISPDC | 1 |
| 2016 | Secure cryptographic functions via virtualization-based outsourced computingabstractSummary Cryptographic functions, such as encryption/decryption libraries, are common and important tools for applications to enhance confidentiality of the data. However, these functions could be compromised by subtle attacks launched by untrusted operating system or other applications, and sensitive keys or cryptographic procedures could then be compromised. In this paper, based on virtualization technology, we propose a novel approach that outsources the cryptographic functions in one virtual machine (VM) into another dedicated VM, so that sensitive keys and the cryptographic procedures are only contained by this VM with specific purpose. We also propose a prototype, called cryptographic function assurance (CFA), to enhance the security of cryptographic functions. Taking OpenSSL as an example, CFA allows those applications that use OpenSSL library to transparently utilize CFA to protect the cryptographic functions. We present the detailed implementation, as well as the security analysis of CFA. We also give the performance evaluation for OpenSSL's interfaces and Apache httpd, to show the overhead caused by the integration of CFA. Copyright © 2015 John Wiley & Sons, Ltd. Weizhong Qiang, Weiqi Dai, Hai Jin 0001 |
Concurr. Comput. Pract. Exp. | 1 |
| 2016 | Social network analysis and its applicationabstractThe purpose of this special issue is to collate a selection of representative research articles that were primarily presented at the 2015 International Conference on Cloud Computing and Big Data 1. This conference brings together researchers and industry practitioners in order to exchange information regarding advancements in the state-of-the-art and practice of cloud computing, big data, and social network, as well as to identify emerging research topics and define the future directions of cloud computing, big data, and social network. Nowadays, various social applications such as blogs, e-mail, instant messaging, social networking (Facebook, Twitter, LinkedIn, etc.), wikis, and social bookmarking have been widely popularized by providing digital platforms for social interaction. Today's online social network or mobile social network pervades all aspects of our daily lives and contains vast amount of data. From this vast amount of data, ability is needed to extract and analyze the social networks of a new era that can be consisted of millions of nodes and connections. Meanwhile, various critical issues such as clustering and evolution mining of social networks, modeling and understanding of social behaviors via computational means, information spread and modeling, social influence analysis, social recommendations, etc., provide significant challenges. This special issue is devoted to analysis of these large-scale social structures and what is more important to identify the areas where social network analysis can be applied and provide the knowledge that is not accessible for other types of analysis. This special issue contains research papers addressing the state-of-the-art in social network analysis and its application. A set of carefully selected works was invited based on the original presentations at the 2015 International Conference on Cloud Computing and Big Data 1, which was held in Huangshan, China, 17–19 June 2015. The extended works have been thoroughly reviewed by an international technical reviewing committee, and only nine papers covering a wide range of relevant challenges in social network were selected for this special issue. The manuscripts tackle research on different topics, including networking, infrastructures, algorithms, applications, and miscellaneous. The set of accepted papers can be organized under the following key subjects and subsections and are briefly described in the remaining parts of this section. Data center is the most important infrastructure for many key applications, such as social network analysis, web service, etc. Data center networks usually mix with a large amount of latency-agnostic background flows and a large number of latency-sensitive application flows. Directly using the traditional TCP in data center networks, which is deadline agnostic, may suffer from performance and efficiency problem. The recent works that improve TCP focus on the latency-sensitive flows themselves but cannot effectively ensure deadline for the latency-sensitive flows. In the first paper, ‘Make-way: transporting latency-sensitive flows nonblockingly in oversubscription data center networks’ 2, by Deng Gang, Gong Zhenghu, and Wang Hong, a new data center network transport protocol, called Make-way, is proposed for satisfying the deadlines of latency-sensitive flows. In Make-way, once a latency-sensitive flow encounters congestion, the latency-agnostic background flows will make way for it. Especially, Make-way does not need any special support of hardware modification. Because the latency-agnostic flows in data center networks usually contribute the majority of traffic, by doing so, the latency-sensitive flows may be transported nonblockingly in data center networks and thus can meet their deadlines. Extensive simulation results show that Make-way can meet the deadlines of latency-sensitive flows with a probability of more than 97%. MapReduce has been widely regarded as a flexible, scalable, and easy-to-use distributed programming paradigm for big data processing such as social network data analysis. The second paper, ‘MEMoMR: accelerate MapReduce via reuse of intermediate results’ 3, by Hong Yao, Jinlai Xu, Zhongwen Luo, and Deze Zeng, tries to accelerate the MapReduce performance from the intermediate result-reusing aspect. The authors observe that existing intermediate result-reusing mechanism is not efficient enough, as many input/output operations are wasted. Efficient reusing of the intermediate results could potentially improve the MapReduce performance. Inspired by such fact, they propose a framework, named more efficient intermediate result reusing for MapReduce (MEMoMR), by introducing a novel reusing mechanism that can substantially reduce the input/output overhead. To this end, they invent a new metadata description method and apply it in the reusing phase. They practically realize MEMoMR and evaluate its performance by implementing it in a real cluster. The experiment results show that MEMoMR can improve the system performance as high as 23.4%, comparing against Dache. Stream processing is one of the key technologies for data processing in social networks. In order to speed up processing in stream processing systems, a data analysis operator could be partitioned into n parallel tasks, which are usually deployed on m nodes coexisting with other application operators. Because the node performance can vary in unpredictable ways, the tasks should be redistributed at runtime for stream applications to meet their strict latency requirements. In order to redistribute the tasks to the best node and dynamically adapt to resource or load fluctuations, the third paper, ‘Runtime-aware adaptive scheduling in stream processing’ 4, by Yuan Liu, Xuanhua Shi, and Hai Jin, presents a runtime-aware adaptive schedule mechanism that aims at minimizing the operator processing latency and minimizing the latency difference between different nodes' tasks. A new abstraction called performance cost ratio (PCR) is proposed, which evaluates the node performance. The higher the node's PCR is, the less cost the node will pay for processing one tuple and the more tasks should be deployed on it. The PCR-based quantitative algorithm applies itself to make task loads quantized to the processing capacity of nodes, move the minimum amount of operator's tasks, and keep the tasks locally at the same time. A runtime-aware adaptive scheduler is implemented as an extension to stream processing system, Storm. Matrix factorization is one of leading techniques for many applications, including social network-based recommendation systems. Many parallel stochastic gradient descent (SGD) methods have been proposed to address the matrix factorization issue on shared-memory (multi-core) systems and distributed systems. However, these methods cannot be accelerated significantly on graphics processing unit (GPU) systems because the serious over-writing problem and thread divergence may occur. The fourth paper, ‘GPUSGD: a GPU-accelerated stochastic gradient descent algorithm for matrix factorization’ 5, by Jing Jin, Siyan Lai, Su Hu, Jing Lin, and Xiaola Lin, proposes an efficient GPU algorithm, named GPUSGD, to solve the matrix factorization problem based on SGD method. The proposed GPUSGD not only can handle the over-writing problem but also can avoid the performance loss caused by the thread divergence. The experimental results show that, compared with the existing state-of-the-art parallel methods, GPUSGD performs much better in accelerating the matrix factorization. The authors also claim that the proposed algorithm is the first work of developing a parallel SGD method to improve the matrix factorization on the GPU. Correlation analysis is both popular and useful in a number of social networking research, particularly in the exploratory data analysis. In the fifth paper, ‘Using Spearman's correlation coefficients for exploratory data analysis on big dataset’ 6, by Chengwei Xiao, Jiaqi Ye, Rui Máximo Esteves, and Chunming Rong, three well-known and often-used correlation coefficients – Pearson product-moment correlation coefficient and Spearman and Kendall rank correlation coefficients – are compared from definition to application domain. Based on the characteristics of the pump's vibration dataset, the nonparametric and distribution-free Spearman rank correlation coefficient is introduced to analyze the relationship between the pump's state and each of the 207 880 variables. The percentage of variables and exact variables' tables with high Spearman's correlation coefficients for state 1 and state 2, state 1 and state 3, state 2 and state 3, and 3 states in different files are obtained respectively, which has important valuation for the future research of the unsupervised machine learning system. Alongside the rapid development of e-commerce, purchase prediction has become an increasingly important consideration for a wide variety of retail platforms. Along with the development of social networks, much attention has been given to the influence of the social networks on users' purchase. The sixth paper, ‘Purchase prediction using tmall-specific features’ 7, by Yang Zhao, Liang Yao, and Yin Zhang, proposes a framework which combines machine learning methods with a threshold-moving approach to predict sets of pairs (user ID and brand ID) in terms of whether a certain brand is purchased by a specified user according to his or her historical activity records. Three specific feature groups are extracted: click features, purchase features, and collect-and-cart features using a dataset from Tmall, a Chinese business-to-consumer online retail platform. Next, seven user purchase prediction experiments with different combinations of the three feature groups are conducted, and the purchase prediction performance is observed. The results show that a combination of all three feature groups, with 27 features in total, provides valuable purchase prediction contributions. It is identified that the last-day shopping cart count, from the collect-and-cart feature group, is a valuable feature capable of markedly affecting prediction performance. In addition, the purchase feature group is also shown to have a greater impact on purchase prediction. Social network has become a very popular way by which Internet users communicate and interact online. Effective user interest prediction is significant for service providers in a set of application scenarios such as user behavior analysis, resource recommendation, etc. In the seventh paper, ‘Interest prediction in social networks based on Markov chain modeling on clustered users’ 8, submitted by Xianghan Zheng, Dongyun An, and Wenzhong Guo, user interest prediction method based on the Markov chain modeling on clustered users is proposed with the following procedure: collecting dataset from 4613 users and more than 16 million messages from Sina Weibo, obtaining each user's interest eigenvalue sequence and establishing single-Markov chain model, and implementing user clustering algorithm for the multi-Markov chain construction in order to divide users into a set of predefined interest categories. The proposed solution is capable of predicting both long-term and short-term user interests based on a suitable selection of the initial state distribution, λ. The proposed solution also proves that short-term interests are consistent with long-term interests if the influences of social or user-related events that cause interruptions (e.g., earthquake, birthday, etc.) are not considered. Furthermore, the experiments show that the proposed solution is feasible and efficient and can achieve a higher accuracy of prediction than that of the other approaches such as support vector machine and K-means. The flourishing social networks have greatly enriched the ways of communications and thus brought people in the world much closer than ever. However, critical contexts of the traditional face-to-face communications, for example, body gestures, could be missing during the online communication, hampering the user experiences. The eighth paper, ‘AAH: accurate activity recognition of human beings using WiFi signals’ 9, by Yu Gu, Lianghu Quan, and Fuji Ren, tries to fill in the blank by presenting a passive and device-free activity recognition system through harvesting fingerprints of different activities from ubiquitous WiFi signals. The proposed system can be integrated into any existing wireless local area networks without additional hardware supports. Also, it does not need the subjects to be cooperative during the recognition process. A prototype system is built and evaluated via extensive real-world experiments. By comparing with three state-of-the art solutions, that is, K-nearest neighbor, naive Bayes, and bagging, the superiority of the proposed method is shown in terms of accuracy and complexity. For analyzing the social network, it is important to classify the network traffic and identify the applications running in the network. With the rapid development of smart phones, recent years have witnessed an exponential growth of the number of mobile apps. Considering the security and management issues, network operators need to have a clear visibility into the apps running in the network. The ninth paper, ‘Automatically identifying apps in mobile traffic’ 10, by Lingjun She, Jianhua Sun, Hao Chen, Wenyong Zhong, Cheng Chang, Zhiwen Chen, Wentao Li, and Shuna Yao, presents a novel approach to generating the fingerprints for mobile apps from network traffic. The fingerprints that characterize the unique behaviors of specific mobile apps can be used to identify mobile apps from the real network traffic. In order to handle the large volume of traffic efficiently, the authors use non-negative matrix factorization to perform traffic analysis to cluster similar network traffic into groups. Then, access patterns of individual apps that are extracted from each group can be used as fingerprints, distinguishing apps from others uniquely. The experimental evaluations show that the proposed approach can identify the mobile apps from random and mixed network traffic with high precision. The articles presented in this special issue provide recent advances in some fields related to social network analysis and applications. In particular, the manuscripts undertake research on different topics, including networking, infrastructures, algorithms, applications, and miscellaneous. We hope that the readers can benefit from the perspectives presented in this special issue and will contribute to these strategically important, exciting, and fast-growing research areas. In closing, we would like to thank all the authors who have submitted their research work to this special issue. We would also like to acknowledge the contribution of many experts in the field who have participated in the review process and provided helpful suggestions to the authors on improving the content and presentation of the papers. We would also like to express our gratitude to the editor-in-chief, Prof. Geoffrey C. Fox, for his support and help in bringing forward this special issue. We hope you will enjoy the papers in this collection. Weizhong Qiang, Xianghan Zheng, Ching-Hsien Hsu |
Concurr. Comput. Pract. Exp. | 1 |
| 2016 | CDMCR: multi-level fault-tolerant system for distributed applications in cloudabstractAbstract Cloud provides users with a new model of utilizing the computing infrastructure with the ability to perform parallel and distributed computations using elastic virtual cluster. However, the multi‐level and complex features make cloud computing system more prone to failure. In this paper, we present a multi‐level fault‐tolerant system for distributed applications in cloud named Distributed‐application oriented Multi‐level Checkpoint/Restart for Cloud (CDMCR). The CDMCR system backups the complete state of applications periodically with a snapshot‐based distributed checkpointing protocol, including file system state. Thus, we cannot only recover processes but also rollback data. A multi‐level recovery strategy is proposed, which includes process‐level recovery, virtual machine recreation, and host rescheduling, enabling comprehensive and efficient fault tolerance for different components in cloud. We deploy CDMCR as PaaS, so that users can be liberated from node management and system configuration and get access to fault‐tolerant service conveniently. We have implemented this system based on the Xen virtualization platform and the OpenNebula cloud platform. Experiments on the prototype demonstrate the correctness of the system. Analysis shows that CDMCR does not cause message loss or data loss, and the backup time remains nearly constant as the number of nodes increases on virtual cluster. Copyright © 2015 John Wiley & Sons, Ltd. Weizhong Qiang, Changqing Jiang, Longbo Ran, Deqing Zou, Hai Jin 0001 |
Secur. Commun. Networks | 1 |
| 2015 | Multi-version Execution for the Dynamic Updating of Cloud ApplicationsabstractSoftwares usually need to be updated to fix bugs or add new features. On the other hand, some critical softwares, such as cloud applications, need to provide service continuously, thus should be updated without downtime. Conventional Dynamic Software Updating (DSU) systems try to update programs while running, but they hardly consider the communication of the program to be updated with other programs, which may lead to some inconsistency problems. We handle the problem with an improved DSU system by using multi-version execution. When a new update arrives, instead of updating the application to the new version, we fork a new process of the old version and dynamically update it to the new version, then make these two versions run concurrently until the update finishes. We implement a prototype system called MUC (Multi-vesion for Updating of Cloud) on Linux. To verify our prototype, we apply MUC to cloud applications Redis and Ice cast, and evaluate the overhead of MUC at runtime. Weizhong Qiang, Hai Jin 0001, Deqing Zou, Duoqiang Wang |
COMPSAC | 2 |
| 2015 | A lightweight software fault-tolerance system in the cloud environmentabstractSummary With the development of cloud computing, the demand of high availability for services is growing. Unfortunately, software failures greatly reduce system availability. This paper presents a lightweight software fault‐tolerance system, called SHelp, which can effectively recover programs from many types of software bugs in the cloud environment. With error virtualization techniques, it proposes ‘weighted’ rescue points techniques to effectively survive software failures through bypassing the faulty path. For multiple application instances running on different virtual machine, a three‐level storage hierarchy with several comprehensive cache updating algorithms for rescue points management is adopted to share error handling information. On the one hand, SHelp can reduce the redundancy for multiple application instances; on the other hand, it can more effectively and quickly recover from faults caused by the same bugs. A Linux prototype is implemented on an open‐source virtual machine monitor platform, Xen, and evaluated using four Web server applications that contain various types of bugs. The experimental results show that SHelp can recover server applications from these bugs in just a few seconds with modest performance overhead. Copyright © 2013 John Wiley & Sons, Ltd. Hai Jin 0001, Deqing Zou, Bing Bing Zhou, Weizhong Qiang |
Concurr. Comput. Pract. Exp. | 5 |
| 2015 | A Skip-gram-based Framework to Extract Knowledge from Chinese Reviews in Cloud Environment
Feng Zhao 0003, Hai Jin 0001, Weizhong Qiang |
Mob. Networks Appl. | 4 |
| 2014 | Improving Log-Based Fault Diagnosis by Log Classification
Deqing Zou, Hai Jin 0001, Weizhong Qiang, Zongfen Han, Xueguang Chen |
NPC | 4 |
| 2014 | CloudTaint: an elastic taint tracking framework for malware detection in the cloud
Jinfeng Yuan, Weizhong Qiang, Hai Jin 0001, Deqing Zou |
J. Supercomput. | 2 |
| 2013 | Design and implementation of a trusted monitoring framework for cloud platforms
Deqing Zou, Wenrong Zhang, Weizhong Qiang, Guofu Xiang, Laurence T. Yang, Hai Jin 0001, Kan Hu |
Future Gener. Comput. Syst. | 3 |
| 2013 | CloudAC: a cloud-oriented multilayer access control system for logic virtual domainabstractThe security issue has been a challenging concern for cloud computing because of the multitenant usage model. In cloud, each application normally runs on a dynamic coalition that is composed by multiple virtual machines (VMs) running on different virtualised service nodes, which the authors called logic virtual domain (LVD). Moreover, the owners of cloud applications, who are also the tenants of cloud, would specify some security policies to control the access to those resources that they have paid for. Therefore the owners of cloud infrastructures have to provide the tenants with the mechanism to correctly configure and enforce the access control policies on resources that are from multiple service nodes, to meet the security requirements from cloud applications. To address the above challenge, this study presents the design and implementation about a multilayer access control architecture for LVD, named CloudAC, aiming to provide isolation control, information flow control and resource‐sharing control among multiple VMs on Xen virtualisation platforms in cloud computing environment. The theory and technology this research formed will provide reliable security guarantee for resource configuration and application deployment on LVDs. Weizhong Qiang, Deqing Zou, Shenglan Wang, Laurence T. Yang, Hai Jin 0001, Lei Shi 0001 |
IET Inf. Secur. | 1 |
| 2012 | A standards-based interoperable single sign-on framework in ARC Grid middleware
Weizhong Qiang, Aleksandr Konstantinov, Deqing Zou, Laurence T. Yang |
J. Netw. Comput. Appl. | 1 |
| 2012 | Proactive recovery approach for intrusion tolerance with dynamic configuration of physical and virtual replicasabstractABSTRACT Proactive recovery mechanism has been widely used in building intrusion‐tolerant systems that are able to tolerate an arbitrary number of faults. However, previous proactive recovery methods seldom consider the dynamic in attacking power that may cause the increase in fault rate, resulting unguaranteed service availability. This paper describes an approach for tolerating intrusions, or more precisely, damages to replicated data, through dynamic configuration of physical and virtual replicas, which follows a general approach called proactive recovery, and proposes to dynamically adjust recovery frequency to handle potentially changing fault rate. This dynamic proactive recovery method takes the dynamic changes of attaching power into consideration to avoid/minimize the effect of intrusions. Our method is especially effective and useful in intrusion tolerance with physical replicas: it dynamically provides virtual replicas during rejuvenation phase. Copyright © 2012 John Wiley & Sons, Ltd. Feng Zhao 0003, Weizhong Qiang, Hai Jin 0001, Deqing Zou, Qin Zhang 0004 |
Secur. Commun. Networks | 3 |
| 2010 | SHelp: Automatic Self-Healing for Multiple Application Instances in a Virtual Machine EnvironmentabstractWhen multiple instances of an application running on multiple virtual machines, an interesting problem is how to utilize the fault handling result from one application instance to heal the same fault occurred on other sibling instances, and hence to ensure high service availability in a cloud computing environment. This paper presents SHelp, a lightweight runtime system that can survive software failures in the framework of virtual machines. It applies weighted rescue points and error virtualization techniques to effectively make applications by-pass the faulty path. A two-level storage hierarchy is adopted in the rescue point database for applications running on different virtual machines to share error handling information to reduce the redundancy and to more effectively and quickly recover from future faults caused by the same bugs. A Linux prototype is implemented and evaluated using four web server applications that contain various types of bugs. Our experimental results show that SHelp can make server applications to recover from these bugs in just a few seconds with modest performance overhead. Hai Jin 0001, Deqing Zou, Bing Bing Zhou, Weizhong Qiang |
CLUSTER | 5 |
| 2010 | Securing Interoperable Grid Services in ARC Grid Middleware
Weizhong Qiang, Aleksandr Konstantinov, Mattias Ellert, Hai Jin 0001 |
GPC | 1 |
| 2010 | The Design and Implementation of Standards-Based Grid Single Sign-On Using Federated IdentityabstractSecurity infrastructure is one of the most challenging tasks in the development, integration and deployment of Grid middle wares. Even though the Grid community addresses the security issue through public key infrastructures (PKI) to support mutual authentication using X.509 certificates, maintaining X.509 credentials is not that easy for non-IT-experts, and has proved to be an obstacle for a more wide deployment of Grid technologies. The identity federation is an increasingly popular technology that can facilitate cross-domain single sign-on without requiring the users to maintain any credentials additional to their own institutional accounts. We believe that utilizing identity federation for Grid middle wares is a promising path for the Grid technology to get more widely used. This paper describes a single sign-on infrastructure developed as a part of the Nordu Grid ARC (Advanced Resource Connector) Grid middleware. It adopts the identity federation standard (SAML), as well as Web Service approach. It focuses on a single sign-on solution at the middleware level for users to access Grids by only using their frequently used accounts, without being bothered to maintain X.509 credentials. Users can use their username/password only to access Grids developed in ARC middleware, as well as access Grids developed in other middle wares that requires users to provide X.509 certificates. Moreover, the single sign-on for workflow-like Grid applications (in which intermediate entities act on behalf of users) is also supported. In addition, the performance of single sign-on solution is measured. We identify performance limitations of security-related services inside this solution, and analyse the ways to avoid the limitations. To our knowledge, the work presented in this paper is the first evaluated implementation that utilizes identity federation for Grid usage on the middleware level. Weizhong Qiang, Aleksandr Konstantinov |
HPCC | 1 |
| 2008 | A Trusted Group Signature Architecture in Virtual Computing Environment
Deqing Zou, Yunfa Li 0001, Song Wu 0001, Weizhong Qiang |
ATC | 4 |
| 2007 | An Authentication and Access Control Framework for Group Communication Systems in Grid EnvironmentabstractCollaboration is used for information sharing and activity coordinating, and it exists broadly in many fields. Group communication enables efficient communication between a set of processes logically organized into groups and communicating via multicast in an asynchronous environment. One of the key technologies for collaborative applications is secure group communication. Current research on secure group communication scarcely considers the existing security mechanism in local systems. As a result, group communication systems couldn 't provide general support for collaborative applications running on a specific system. Based on the existing grid security technologies, we propose an authentication and access control framework at virtual organization (VO) level for group communication in grid environment. By introducing role-based access control (RBAC) and attribute-based approach, we define group management policies and design group control protocols. The protocols are analyzed from three aspects: compatibility, performance, and security. Finally, we implement a prototype based on GridShib. Deqing Zou, Laurence T. Yang, Weizhong Qiang, Xueguang Chen, Zongfen Han |
AINA | 3 |
| 2006 | Daonity: An Experience on Enhancing Grid Security by Trusted Computing Technology
Weizhong Qiang, Zhi-Dong Shen, Chunrun Chen, Huanguo Zhang, Deqing Zou |
ATC | 2 |
| 2005 | VO-Sec: An Access Control Framework for Dynamic Virtual Organization
Hai Jin 0001, Weizhong Qiang, Xuanhua Shi, Deqing Zou |
ACISP | 2 |
| 2005 | A Formal General Framework and Service Access Model for Service GridabstractConstituent resources in a grid system need to be used in a coordinated fashion to deliver non trivial qualities of service. Various e-science and e-business use cases are investigated to guide how to create grid systems, and determine which functions grid systems should have. Web services emerge as a standard interoperable technology for grid systems. Although the motivations and goals for service grids are obvious, there is no clear definition for service grids to define and describe the general framework and service access model. In this paper, the general framework for service grids is defined in a formal approach, and the virtual organization based service access mechanism is modeled based on abstract state machines (ASM). In the service access model we proposed, the quality of service (QoS) issue is considered for the user request. This resulting serves as a theoretical base for our service grid system, HowU. Deqing Zou, Weizhong Qiang, Xuanhua Shi |
ICECCS | 2 |