Jing Wang 0150

dblp:02/736-150 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2026
0009-0000-3624-7759ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Adaptive detection of encrypted malware traffic via fully convolutional masked autoencoders
Jizhe Jia, Meng Shen 0001, Qingjun Yuan, Jing Wang 0150, Haotian He, Liehuang Zhu
Frontiers Comput. Sci.5
2026 Early-Stage Detection of Encrypted Malware Traffic via Multi-Flow Temporal Graph Learning
abstract
Malware widely adopts network traffic encryption techniques to conceal malicious activities. Recent research has demonstrated the effectiveness of machine learning (ML)-, deep learning (DL)-, and pre-training-based malware traffic detection methods. However, a vast majority of these methods rely on the collected complete traffic during the malware attack. While certain methods can operate on partial traffic, their detection accuracy often significantly decreases when the available data is restricted to the extreme early stage, where information is most sparse. In this paper, we proposeDawnGuard, an effective early-stage encrypted malware traffic detection framework through multi-flow temporal graph learning. Specifically, based on the temporal packet density distribution analysis,DawnGuardinnovatively proposes a self-adjusting data augmentation strategy for early-stage malware traffic, which can force the model to focus on the early-stage interaction phase with more distinguishable properties. Meanwhile, considering that temporal-topological correlations among multiple flows can provide more distinguishable properties in a malware attack, we further develop a temporal graph learning framework to extract features, which can formMulti-Flow Graph Features (MGF). By utilizingMGF,Dawn-Guardimplements a Vision Transformer-based detection mechanism, enabling accurate and precise encrypted malware traffic detection with early-stage traffic by capturing both local and global contextual relationships. Extensive experiments with two real-world datasets demonstrate thatDawnGuardoutperforms the state-of-the-art (SOTA) methods in three typical scenarios: varying early-stage time windows, imbalanced data, and unseen malware detection. Particularly,DawnGuardachieves an average F1 of 95.11%, 8.7% higher than the SOTA method, by only utilizing the first 20% loading ratio of complete traffic.
Jizhe Jia, Yi Zhao 0011, Meng Shen 0001, Susu Cui, Jing Wang 0150, Bufan Zhao 0001, Wei Wang 0012, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.5
2024 Behavior-Driven Encrypted Malware Detection with Robust Traffic Representation
Jizhe Jia, Jing Wang 0150, Meng Shen 0001, Liehuang Zhu
ICA3PP (5)3
2024 Time Is Not Enough: Timing Leakage Analysis on Cryptographic Chips via Plaintext-Ciphertext Correlation in Non-Timing Channel
abstract
In side-channel testing, the standard timing analysis works when the vendor can provide a measurement to indicate the execution time of cryptographic algorithms. In this paper, we find that there exists timing leakage in power/electromagnetic channels, which is often ignored in traditional timing analysis. Hence a new method of timing analysis is proposed to deal with the case where execution time is not available. Different execution time leads to different execution intervals, affecting the locations of plaintext and ciphertext transmission. Our method detects timing leakage by studying changes in plaintext-ciphertext correlation when traces are aligned forward and backward. Experiments are then carried out on different cryptographic devices. Furthermore, we propose an improved timing analysis framework which gives appropriate methods for different scenarios.
Congming Wei, Guangze Hong, An Wang 0001, Jing Wang 0150, Shaofei Sun, Yaoling Ding, Liehuang Zhu, Wenrui Ma
IEEE Trans. Inf. Forensics Secur.4