EDBT 2026 Demo / reviewers in the wild / expert
Bibo Tu
dblp:12/4852
· DBLP profile ↗
49ranked-venue papers
5as first author
31since 2021 · last 2026
0000-0002-0278-7420ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 15 since 2021Systems, architecture and hardware · 13 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 10 · 10 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient packet classification with updatable learned index for online network defenseabstractAbstract Packet classification is a cornerstone of network security functions, such as firewalls, access control, and network metering. It involves taking different actions on packets based on security rules to implement these network security functions. As networks continue to evolve and the number of network instances rapidly increases, the complexity and size of network security rule sets are also expanding. Additionally, autonomous defense systems with artificial intelligence that can detect and block online attacks have become a new trend in network security. Packet classifiers need to not only achieve fast rule matching under large rule sets but also support rapid rule updates in order to deploy security rules issued by online defense systems in a timely manner. However, existing packet classification methods struggle to balance lookup speed with update performance. To achieve rapid rule matching and support fast rule updates in networks, we propose a novel approach called the Learned Index Updatable Tree (LIPT) to address this challenge. LIPT partitions the rule set into single-field non-overlapping subsets and constructs dynamic learned index trees for each subset using keys obtained by sampling. To implement rule updates directly within the learned index tree without reconstruction, LIPT employs a gap array layout in the data nodes, which reserves space for rule insertion. To enhance lookup and update performance, LIPT addresses the challenge of direct range validation in the data node through payload-assisted validation, which helps quickly identify lookup and insertion locations. Furthermore, LIPT employs a simple linear regression model to construct the learned index tree, enabling swift lookup based on the predictive results of the linear regression model; it also utilizes a cost model to simplify the construction process. We conduct a comprehensive evaluation of LIPT’s performance, showing that both lookup and update speeds are significantly improved compared to existing algorithms that support rule updating. Compared to the benchmark algorithm PSTSS, LIPT’s update speed increases by 25%, and its classification speed increases by 242%. Chen Li 0066, Zixuan Ma, Xuefei Chen, Bibo Tu |
Cybersecur. | 5 |
| 2026 | Software-Defined platform management for data center: security, low entropy, and efficiencyabstractAbstract The trend of heterogeneous servers and the rise of Software-Defined Data Center (SDDC) have transformed data center management. Collaborative management of hardware and software is crucial for rapid deployment and migration. As the boundary between physical infrastructure and virtual infrastructure blurs, data center management faces challenges in fine-grained resource provisioning, energy efficiency optimization, and security assurance. To address these challenges, this paper proposes a novel Software-Defined Platform Management (SDPM) architecture based on out-of-band management. This architecture extends server platform management capabilities from physical infrastructure to virtual machines. By abstracting heterogeneous resources into execution points managed by a centralized control plane and consolidating standard industry interfaces, the architecture introduces capabilities for resource provisioning, energy consumption regulation, as well as access control and trusted computing support. A prototype implementation on a real server and experimental results demonstrate that the architecture can dynamically allocate resources based on predictions of virtual machine workloads, optimize energy consumption through workload-aware and temperature-driven fan control, and support secure communication channels to implement advanced access control policies. These results highlight SDPM’s potential in advancing resource provisioning, energy efficiency, and security in modern data centers. Haojun Xia, Bibo Tu |
Cybersecur. | 4 |
| 2026 | Privacy-Preserving Continuous Authentication of Smartphone Users via Secret SharingabstractBehavioral biometrics based continuous authentication has been proven to be an effective supplement to traditional one-time authentication schemes ( like passwords), and it can continuously authenticate users throughout the session. Currently, most continuous authentication models leverage deep learning techniques to learn smartphone users' behavioral patterns from behavioral biometric data, and have made remarkable progress. However, training deep learning based continuous authentication models requires enormous computing power, which leads to resource-constrained mobile platforms relying on powerful cloud servers. Cloud servers need access to behavioral biometric data for training and inference, as this mayraise privacy concerns. Existing deep learning based continuous authentication schemes pay more attention to authenticationperformance, but ignore theprotectionof behavioral biometric data. To solve this issue, we present a privacy-preserving continuous authentication scheme based on secret sharing secure multi-party computation (MPC). More specifically, we secretly share behavioral biometric data among two cloud servers that train continuous authentication systems on joint data using two-party computation (2 PC) without compromising data privacy. Further, we evaluate the practical feasibility of our proposed privacy-preserving scheme on two realistic privacy-preserving continuous authentication models, which are constructed with deep learning and traditional machine learning techniques, respectively. Extensive experiments demonstrate the effectiveness of our two privacy-preserving continuous authentication models. Ding Wang 0002, Daojun Han, Jingtao Guo, Bibo Tu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Lightweight Distributed Cloud-Native Service Function Chain Anomaly Detection for Edge-Cloud NetworksabstractAnomaly detection in Service Function Chains (SFCs) is essential for ensuring the security of edge-cloud networks. However, edge servers in Industrial Internet of Things (IIoT) face challenges in meeting the real-time processing requirements for high-precision anomaly detection due to limited computational resources. In order to address this issue, we initially propose an architectural framework for in-band measurement of cloud-native SFC, which can efficiently detect the state information of virtual network functions (VNFs). Secondly, we propose LightSFC, a lightweight distributed edge-cloud network service function chain anomaly detection model. LightSFC achieves comprehensive awareness of the SFC state by collecting multi-source information from both the data plane and the control plane, and utilizes a lightweight deep Autoencoder model for proactive anomaly detection. Our experimental results show that LightSFC is capable of rapidly detecting anomalies with lower resource overhead. Compared to other methods, LightSFC exhibits superior performance in terms of accuracy, precision, recall, and F1-score, thereby substantiating its efficacy in SFC anomaly detection for edge-cloud networks. Xuefei Chen, Chen Li 0066, Bibo Tu |
CSCWD | 5 |
| 2025 | CPRAM: Cryptographic Performance-Aware Resource Affinity Management in Para-virtualized EnvironmentabstractThe rapid growth of cloud computing has made security a key challenge, with cryptographic technology playing a central role in ensuring the integrity and confidentiality of cloud services. Cryptographic services in the cloud are typically implemented using virtualized cryptographic resources, such as Virtual Cryptographic Machines (VCMs), which allow multiple tenants to share hardware cryptographic cards. The DPDK-based para-virtualized cryptographic card solution experiences performance degradation in NUMA-based multi-core systems due to cross-node memory access and resource affinity. This paper addresses these challenges by proposing Cryptographic Performance-Aware Resource Affinity Management (CPRAM), a method that optimizes cryptographic resource allocation while maintaining load balancing across shared system resources. CPRAM enhances VCM performance by considering both global hardware resource affinity and the impact of Intel DDIO on cryptographic card throughput. We establish priori models for affinity optimization. Our approach also mitigates the overhead of memory page migration through a multi-threaded migration strategy. We implement the prototype system and demonstrate the effectiveness of CPRAM on an Intel platform. The results show significant improvements in cryptographic performance, making CPRAM an efficient and scalable solution for cloud cryptographic services. Yanchang Feng, Chen Li 0066, Bibo Tu |
CSCWD | 4 |
| 2025 | ZTKA: A Zero-Trust Based Kernel Encryption Architecture for Transparent Data ProtectionabstractThe risk of data leakage has become a major challenge for various organizations. However, recent research has highlighted certain deficiencies in traditional data encryption schemes, significantly compromising the overall usability and security of systems especially for data in use. To address these challenges, this paper proposes a novel Linux kernellevel architecture based on zero-trust principles, named ZTKA. This architecture systematically integrates Zero Trust concepts, strictly adhering to the principle of least privilege access, and does not trust any other users or applications running on the same system. It achieves secure data isolation and protection of data in use. Our architecture ensures data security even in the event of partial system compromise by implementing secure key management, real-time data encryption, strict file isolation, and a series of performance optimization measures at the kernel level. The paper reviews the relevant theoretical background and provides empirical results from runtime measurements to compare performance and security with and without the kernel module. Observations indicate that the kernel-level architecture based on Zero Trust principles operates effectively across its modules, significantly enhancing the security of data usage in Linux while maintaining superior performance. Yanchang Feng, Xuefei Chen, Chen Li 0066, Bibo Tu |
CSCWD | 7 |
| 2025 | Interference Monitoring for Colocated Workloads in Low-Entropy Computing SystemsabstractUsers' expectations of internet applications have extended beyond basic functionality to prioritize tail latency and minimal jitter, factors often impacted by competitive interference among colocated workloads in operating systems. In the context of low-entropy computing, it is essential to monitor thread-level interference among colocated processes in a real-time and software-defined manner. This paper introduces NoiseCatcher, an interference monitoring solution that provides nanosecond-level reporting with minimal overhead on mission-critical threads. By leveraging eBPF (Extended Berkeley Packet Filter) and in-kernel shared data structures, our approach efficiently captures essential system events without requiring costly context switches. Aggregated data is then transmitted to the Baseboard Management Controller (BMC) via the system bus for persistent storage, with access provided through open RESTful APIs for flexible querying. The solution is evaluated on a production server, with comparative analysis against the Linux kernel's OSNOISE tracer. Results indicate that our solution not only matches OSNOISE in functionality but also achieves nanosecond-level precision, minimized performance degradation. Haojun Xia, Yanchang Feng, Bibo Tu |
CSCWD | 5 |
| 2025 | End-to-End Security Policy Automation with Multi-LLM Agents in Cloud-Native SystemsabstractMicroservice architectures have gained widespread adoption in cloud-native environments due to their flexibility and scalability. However, these architectures pose significant challenges in the automated generation and dynamic updating of fine-grained security policies. This paper presents LLM2policy, a novel framework that utilizes large language models (LLMs) for end-to-end automated security policy generation. LLM2policy extracts microservice entity information from deployment YAML files and identifies RPC call relationships from distributed tracing data, consolidating this information into a structured knowledge base. This knowledge base is then used to automatically generate Istio-compatible access control policies in YAML format, enabling dynamic policy updates. Evaluation results from five benchmark microservice systems demonstrate that LLM2policy achieves 100% accuracy in entity recognition and dependency extraction, over 98.81% accuracy in semantic extraction by the LLM, and unit test pass rates ranging from 93.75% to 100% for the generated policies. Furthermore, attack simulations confirm that the generated policies effectively mitigate unauthorized access, highlighting the practical applicability and robustness of LLM2policy in automated cloud-native security policy management. Xuefei Chen, Haohao Liu, Chen Li 0066, Bibo Tu |
TrustCom | 6 |
| 2025 | BLFair: enabling proportional I/O sharing for NVMe SSD in SPDK para-virtualization architectureabstractAbstract In data centers, the Storage Performance Development Kit (SPDK) para-virtualization architecture is an efficient solution for non-volatile memory express (NVMe) solid-state drive (SSD) virtualization but faces challenges in maintaining performance fairness and isolation due to storage resource competition among multi-tenants. However, the existing Quality of Service method in SPDK fails to ensure proportional I/O sharing among multi-tenants. Providing fairness and isolation while maintaining high storage utilization in SPDK remains a challenge. In this paper, we propose BLFair to address this problem. Specifically, BLFair implements proportional I/O sharing for multi-tenants in the SPDK. The design of BLFair can effectively reduce the high time complexity caused by the ordering and the overhead of maintaining the virtual clock. Moreover, BLFair allows for achieving a trade-off between proportional I/O sharing and maximizing storage utilization. BLFair also uses the lockless ring mechanism to achieve scalability for cross-core operation. We have implemented a prototype system of BLFair in SPDK. Finally, we conduct evaluations with different workloads in both local storage and NVMe over RDMA fabric environments. The results show that our method can achieve fairness and scalability. BLFair can achieve up to 7.09x 99.99th latency reduction compared to the system with no fairness. Evaluation results in realistic workloads also show that BLFair outperforms other methods. Yanchang Feng, Haojun Xia, Bibo Tu |
Comput. J. | 5 |
| 2025 | End-to-end anomaly detection of service function chain through multi-source data in cloud-native systems
Xuefei Chen, Jinfeng Kou, Haiqiang Li, Chen Li 0066, Bibo Tu |
Comput. Secur. | 7 |
| 2025 | Zero-trust based dynamic access control for cloud computingabstractAbstract Most corporations and organizations rely heavily on access control to protect data accessibility and enable resource sharing across networks and departments. However, with the development of cloud computing, traditional boundary protection struggles to mitigate the increasing attacks and threats. In addition, most existing dynamic access control methods match static rules with dynamic metrics, which cause system damage through their delayed responses to threats and attacks. The zero-trust architecture (ZTA) provides continuous authentication and dynamic authorization for all users to accommodate the security demands of cloud computing. Drawing inspiration from the ZTA, we first present a TBAC (Trust-based Access Control) model and design a trust assessment methodology to update user trustworthiness. Then, we introduce dynamic rules in the TBAC model to implement a dynamic access control system DR-TBAC (TBAC with Dynamic Rule). We apply the DQN (Deep Q-Network) algorithm to dynamically update the trust thresholds based on static rules comparing dynamic trust with predefined trust thresholds to achieve adaptive access control policies. In this paper, we rebuild the cloud security access environment from the perspective of dynamic trust and rule optimization and strengthen the constraints on user behaviors throughout the access control lifecycle of cloud computing. Finally, a thorough analysis and assessment regarding offline training models and the online deployment of the DR-TBAC system into the cloud platform highlight its security and accuracy relative to baseline models. Ri Wang, Chen Li 0066, Kun Zhang 0016, Bibo Tu |
Cybersecur. | 4 |
| 2025 | Thermal Elasticity-Aware Host Resource Provision for Carbon Efficiency on Virtualized Servers
Haojun Xia, Yanchang Feng, Haohao Liu, Bibo Tu |
IEEE Trans. Computers | 6 |
| 2025 | Behavioral Biometrics-Based Continuous Authentication Using a Lightweight Latent Representation Masked One-Class AutoencoderabstractBehavioral biometrics-based continuous authentication has proven to be an excellent supplement to one-time authentication schemes that applies behavioral biometrics to authenticate smartphone users’ identities throughout the session. However, it still has two key issues that need to be addressed: 1) Due to behavioral biometrics from attackers are not available a priori, continuous authentication models should be trained only with normal samples in an unsupervised manner rather than treated as binary or multi-class classification tasks; 2) Differences in behavioral biometrics between attackers and legitimate users are fine-grained, it is challenging to extract rich semantic information to model users’ behavioral patterns. To fill this gap, we propose a lightweight latent representation masked one-class autoencoder, which is trained only with legitimate users’ behavioral biometrics. It consists of two parts: masked latent representation generator (MLRG) and Reconstructor. First, we apply the MLRG to generate discriminative latent representation with low dimension and then as a mask to cover important parts of the latent representation generated from the Reconstructor. Second, we apply the Reconstructor to reconstruct input based on masked latent representation. Experimental results demonstrate that our approach achieves superior authentication performance of 0.68% EER, 0.94% EER, 2.14% EER, and 1.87% EER on four datasets, respectively. Ding Wang 0002, Chen Li 0066, Bibo Tu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | IMS: Towards Computability and Dynamicity for Intent-Driven Micro-SegmentationabstractMicro-segmentation (MSG), a pillar of Zero-Trust, provides fine-grained access control for east-west traffic between cloud endpoints (VMs/containers). Admins formulate strict whitelisting MSG policies that allow necessary traffic. However, current MSG systems lack the computability foundation to resolve policy inconsistencies, where policy overlap can cause conflicts that violate the security requirements, and to verify policy reachability to avoid erroneously blocking necessary traffic. Meanwhile, current MSG systems lack comprehensive dynamicity processing, including maintaining invariants when updating MSG policies and promptly adjusting policy enforcement for endpoint status changes. We propose IMS, the first intent-driven MSG system towards computability and dynamicity. IMS innovatively defines the endpoint group space and algebra, providing the computability foundation for formally and automatically verifying and processing MSG policies. Based on this, IMS implements functionalities to resolve policy inconsistencies and to verify policy reachability. Meanwhile, IMS achieves comprehensive and prompt dynamicity processing. IMS fulfils the verification and dynamicity processing requirements of intent-driven systems. We implement a prototype and evaluations show that the processing time of IMS functionalities scales linearly with the number of policies, and the average endpoint dynamicity processing time is 5.05 ms in the setup of 1,000 endpoints, illustrating that IMS is scalable and can process dynamicity promptly. Zixuan Ma, Chen Li 0066, Ruibang You, Bibo Tu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Towards Unsupervised Time-Series Anomaly Detection for Virtual Cloud NetworksabstractVirtual cloud network (VCN) is a fundamental cloud resource for endpoints (VMs or containers) to communicate with each other and with the outside. Anomaly detection, a key security approach for VCNs, faces serious challenges: 1) Current feature models are difficult to apply to VCNs with significant differences from traditional networks. 2) Current anomaly detection models lack the adaptability to learn multiple normal patterns simultaneously. The need to train a dedicated model for each endpoint causes serious scalability problems in VCNs. 3) Current anomaly detection models have difficulty addressing the complex temporal dependency and non-stationarity of VCNs. To address these challenges, we propose a new multilevel feature model MFM and a new unsupervised time-series anomaly detection model GTGmVAE. By combining the basic features with the topology features specifically designed for VCNs, MFM effectively characterizes the patterns of VCNs. GTGmVAE combines the new local-global feature extractor with the latent space following a Gaussian mixture distribution to achieve the strong adaptability to learn multiple normal patterns simultaneously, and achieves the strong temporal modeling capability to effectively address the complex temporal dependency and non-stationarity of VCNs by adequately modeling the global temporal dependencies of the input samples and latent variables. Extensive experiments on the VCN anomaly detection dataset CIC-IDS2018 and the time-series anomaly detection benchmark dataset SMD show that GTGmVAE with MFM achieves the desirable performance, and GTGmVAE outperforms all nine representative state-of-the-art detection models. Zixuan Ma, Chen Li 0066, Kun Zhang 0016, Bibo Tu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | An Efficient Authentication Scheme With Key Leakage-ResistanceabstractHarnessingthe data processing and communication capabilities of the Internet of Things (IoT), smart grids can seamlessly share power information across wired and wireless networks, enhancing the grid's reliability, stability, sustainability, and energy efficiency. Since smart meters' communication in the IoT network is carried out on the public channel, there is significant uncertainty about the authenticity of the transmitted electricity data and the security of the smart meter keys. Existing solutions cannot well-handle the above security issues. Therefore, in this article, an efficient authentication scheme with key leakage-resistance, signing key leakage-resistant authentication (SKLRA), for the IoT-enabled smart grid is proposed for IoT-integrated smart grids. The SKLRA scheme is designed to overcome the performance shortcomings and security limitations found in traditional certificateless key-insulated signature mechanisms and certificateless signature approaches that do not utilize random oracles, particularly for smart grid applications. We also provide a rigorous security analysis alongside experimental evaluations to demonstrate the robustness and practical viability of the SKLRA scheme in real-world applications. Jinglong Chen, Bibo Tu |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | Desktop Virtualization Optimization Methods Based on IDV ArchitectureabstractWith the growing demand for users’ flexible use of office desktops and enterprises’ centralized management of information resources, desktop virtualization technologies, represented by remote desktops, have become a prominent approach in current desktop management. Among the mainstream desktop virtualization technologies, Intelligent Desktop Virtualization (IDV) architecture offers significant advantages regarding network dependency and resource utilization. However, the IDV scenario presents challenges on the server, such as the increasing number of centrally managed images, resource consumption due to frequent image pulling, and low efficiency in image synchronization. Moreover, the terminal faces an issue of not fully leveraging hardware resources. Considering the IDV-specific characteristics, we design and implement a set of optimization methods for desktop virtualization, which outperform traditional IDV solutions. Haojun Xia, Chen Li 0066, Bibo Tu |
CSCWD | 4 |
| 2024 | An Efficient Caching Mechanism for End-host Network FunctionsabstractThe end host serves as a natural enforcement point for various network functions (NFs), such as network address translators (NATs), firewalls, and load balancers. However, due to the limitations of the Linux networking stack, NFs struggle to achieve high performance when utilizing high-speed network interfaces. The eXpress Data Path (XDP) is a high-performance framework for packet processing within the Linux kernel. It operates as an optimized execution point before the networking stack. In contrast to kernel-bypass solutions like DPDK, XDP offers an appealing alternative by providing comparable performance with lower CPU usage.In this paper, we propose PFC, a novel approach that leverages XDP for Pre-Function table Caching. PFC acts as a packet header processor for incoming packets, it consists of two distinct facets: one involves traffic management within the end host, and the other focuses on processing requests from distributed applications. Experimental results show that PFC can significantly increase throughput and achieve the equivalent performance compared to DPDK. Furthermore, PFC can integrate seamlessly with existing systems without requiring any modifications to the applications. Haojun Xia, Chen Li 0066, Bibo Tu |
CSCWD | 4 |
| 2024 | Continuous Authentication Technology Based on Device Driver BehaviorabstractAt present, the existing peripheral interface authentication is mostly based on static features, which cannot effectively resist the security threats in the new form. This paper proposes a continuous authentication technology of device driver behavior from a dynamic perspective, aiming to achieve continuous authentication of user identity through real-time monitoring and analysis of long-time interaction behavior between the device and the system. According to the process of peripheral access to the system, the device driver behavior is divided into the device driver behavior in the enumeration phase and the device driver behavior in the user usage phase. In the enumeration phase, this paper proposes an authentication technique based on device enumeration fingerprints; while in the user usage phase, continuous authentication of user identity is realized by continuous authentication technique in peripheral communication mode. We use three supervised learning algorithms for experiments, and their accuracy rate reaches more than 97.25%. Compared with the traditional identity authentication with static features, the dynamic continuous authentication through these two phases significantly enhances the security of identity authentication in the whole process of the peripheral. Haojun Xia, Haohao Liu, Bibo Tu |
CSCWD | 6 |
| 2024 | EI-XIDS: An explainable intrusion detection system based on integration frameworkabstractThe application of Deep Learning (DL) in Intrusion Detection Systems (IDS) has become a focal point of research due to its outstanding performance. However, the black-box nature of these systems has raised concerns within the research community. Addressing this challenge, this paper draws upon the concept of ensemble learning and introduces an Explainable Intrusion Detection System (X-IDS), EI-XIDS. This system integrates a variety of advanced Explainable Artificial Intelligence (XAI) methods and adaptively selects them according to different scenarios through reinforcement learning. Comparative experiments demonstrate that EI-XIDS outperforms the current state-of-the-art explanation methods, achieving label flip rates of 97% and 96% on the NSL-KDD and UNSW-NB15 datasets, respectively. These results underscore EI-XIDS’s superior interpretability accuracy, robustness, and sparsity, showcasing its significant potential in the field of network security. Chen Li 0066, Kun Zhang 0016, Haojun Xia, Bibo Tu |
CSCWD | 5 |
| 2024 | CloudFusion: Multi-Source Intrusion Detection in Cloud EnvironmentsabstractAddressing the multifaceted security challenges inherent in cloud environments, our study delineates a robust, real-time threat detection framework. This methodology integrates three cardinal technologies: a memory access mechanism rooted in Virtual Machine Monitor (VMM) analytics, offering profound insights into the operational dynamics of virtual machines; a semantic reconstruction method, informed by software architectural tenets, adept at discerning intricate adversarial activities; and a log-oriented decoding and rule alignment mechanism tailored for sophisticated handling of cloud-based log data. In unison, these technologies forge a proficient, instantaneous threat detection paradigm. Applied and authenticated on a cloud platform, the proposed framework buttressed by judiciously crafted security protocols enables the contemporaneous surveillance of malicious incursions affecting virtual machines, host systems, and network data streams. Both functionality and efficiency assessments attest to the system’s adeptness in precise threat identification while ensuring minimal performance disruption for host and client systems. Kun Zhang 0016, Haojun Xia, Bibo Tu, Chen Li 0066 |
CSCWD | 4 |
| 2024 | A Self-Supervised Targeted Process Anomaly Detection Method Based on the Minimum Set of Observed EventsabstractIn scenarios involving a single targeted application service, it is essential to monitor the security of business-oriented processes. However, there is currently a lack of lightweight, real-time online anomaly detection methods for targeted processes that do not require labeled data. This paper presents a self-supervised anomaly detection model for targeted processes, based on a minimal observation event set and utilizing eBPF and deep learning techniques. The model first selects a minimal set of observed events for the targeted process, which includes critical system calls, process scheduling, resource usage, and I/O operations. Unlike traditional system call sequence features, this model focuses on the rate of change in the frequency of feature selection calls. The detection model employs the VAE-LSTM algorithm, where the VAE module constructs robust short windows and the LSTM module estimates long-term correlations within the sequence. Through self-supervised learning, the model learns the normal behavior of targeted processes, extracts robust behavioral features, and reduces feature dimensions. By performing online detection of these learned features against runtime processes, the model achieves second-level anomaly detection for targeted processes. Finally, by simulating and constructing eight different types of process attack scenarios, the experimental results demonstrate a detection accuracy exceeding 92%, with a performance overhead of less than 10%. Haojun Xia, Limin Sun 0001, Zhanwei Song, Bibo Tu |
TrustCom | 6 |
| 2023 | AuthConFormer: Sensor-based Continuous Authentication of Smartphone Users Using A Convolutional Transformer
Kun Zhang 0016, Ruibang You, Bibo Tu |
Comput. Secur. | 4 |
| 2023 | Multisensor-Based Continuous Authentication of Smartphone Users With Two-Stage Feature ExtractionabstractThe one-time authentication mechanism in traditional authentication methods cannot continuously authenticate smartphone users’ identities throughout the session. Continuous authentication based on the behavioral biometrics recorded by the built-in sensors can solve this issue. However, the existing methods based on multisensor have poor ability to extract valuable features that can represent smartphone users’ behavioral patterns. This article proposes a novel method combining the manual construction and the deep metric learning method to perform two-stage feature extraction, respectively. We transform the time-series raw data from three sensors (accelerometer, gyroscope, and magnetometer) into 69 statistical features in the first stage. Furthermore, unlike the existing serial feature fusion methods, we innovatively fuse the constructed statistical features from three sensors into a three-channel matrix. Then, the fused features matrix with a three-channel is fed to the deep metric learning model for the second stage of feature extraction. We use the elliptic envelope algorithm to classify the user as a legitimate user or an impostor. Finally, we evaluate the performance of the proposed method on two public data sets. Experimental results show that our method can achieve an average accuracy of 99.71% and an average equal error rate (EER) of 0.56% on the hand movement, movement, orientation, and grasp data set, and an average accuracy of 99.59% and an average EER of 0.61% on the BrainRun data set. Kun Zhang 0016, Ruibang You, Bibo Tu |
IEEE Internet Things J. | 4 |
| 2023 | HyperPS: A Virtual-Machine Memory Protection Approach Through Hypervisor's Privilege SeparationabstractThe HostOS or Hypervisor constitutes the most important cornerstone of today's commercial cloud environment security. Unfortunately, the HostOS/Hypervisor, especially the QEMU-KVM architecture, is not immune to all vulnerabilities and exploitations. Recently, researchers have put forward lots of schemes to protect Virtual Machines under the compromised HostOS/Hypervisor. However, some of these schemes rely on special hardware facilities, while other (e.g., Nested Virtualization schemes) require large modification to current commercial cloud architecture. In this paper, we present a novel scheme, named HyperPS, to implement virtual machine protection under the compromised HostOS/Hypervisor. The key idea of HyperPS is to deprive the HostOS/Hypervisor of the privileges of managing the physical memory into an isolated and trusted execution environment. HyperPS does not rely customized hardware or extra processor privilege. HyperPS shares the same privilege with the HostOS. We have implemented a fully functional prototype based on the KVM in Intel x86_64 architecture. Experiment results show that HyperPS has achieved an acceptable trade-off between security and performance. Kunli Lin, Wenqing Liu, Kun Zhang 0016, Bibo Tu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Evaluation and Optimization on Virtualization Performance Cost under Semantic GapabstractVirtualization is a key enabling technology in modern data centers. While it provides numerous benefits, it also creates new problems. Virtualization requires the hypervisor to treat the virtual machine as a black box, limiting the ability of information exchange between the hypervisor and the virtual machine, bringing a problem known as the semantic gap. Currently, much research on the semantic gap mainly focuses on bridging the semantic gap. The evaluation of the semantic gap, on the other hand, is a neglected but crucial problem, and relevant research is currently lacking. Therefore, this paper proposes a corresponding virtualization performance cost model to better evaluate the semantic gap. Based on this cost model, we summarize solutions that can be used to alleviate the semantic gap. Furthermore, we propose a novel evaluation method for the CPU double scheduling semantic gap. Finally, we propose an effective virtio-balloon based dynamic memory tuning strategy to alleviate the memory semantic gap. The experiments show that for 400.perlbench, our strategy saves 551MB of memory on average during running and reclaims 990MB of memory after running, with a performance cost of only 1.1%. For 429.mcf, our strategy saves 815MB of memory on average during running and reclaims 2130MB of memory after running, although with the performance cost of 27.6%, it prevents performance cliff-like drop caused by memory shortage. Haojun Xia, Kun Zhang 0016, Bibo Tu |
CSCWD | 4 |
| 2022 | A Novel Discrete Bi-objective Optimization Method for Virtual Machine PlacementabstractAccording to the cloud computing paradigm, cloud providers can offer computing infrastructure as a service in virtual machines (VMs) running on physical machines (PMs). A data center relies on a VM placement (VMP) algorithm to allocate VMs to the appropriate PMs. As VMs are running on PMs, cloud services providers need to consider operating costs and minimize energy consumption to reduce costs. Meanwhile, multiple VMs running on fewer PMs will result in excellent resource contention, affecting the user experience. How to reduce energy consumption while maintaining VM performance remains a challenge. Although some existing VMPs study VM performance degradation, they do not consider the PM’s state, which will result in errors occurring when predicting VM performance. Moreover, many current VMP algorithms converge too slowly and easily fall into the local optimum solutions. So in this paper, first, we build the energy consumption model based on real data sets to obtain more accurate energy consumption values. Second, we investigate and model VM performance in CPU and memory. Third, we formulate the VMP as a discrete optimization problem based on the energy consumption model and VM performance model. We then propose a novel bi-objective discrete VMP (BDVMP) algorithm to solve it. Finally, we evaluate the BDVMP algorithm on both the CloudSim platform and the real Openstack platform. The results show the efficiency of our BDVMP algorithm. Yanchang Feng, Chen Li 0066, Bibo Tu |
ICPADS | 3 |
| 2021 | HyperKRP: A Kernel Runtime Security Architecture with A Tiny Hypervisor on Commodity HardwareabstractThe large body of kernel code provides broad attack surfaces to exploitable bugs or misconfigurations. Current mitigations are difficult to be integrated together or have a non-trivial performance or code size impact. Thus, systematical protection for the kernel is of critical importance and is required. In this paper, we propose a kernel runtime security architecture, called HyperKRP, to provide systematical protection for kernel code, critical kernel data, and efficient kernel page tables. We have implemented a fully working prototype for a recent Linux kernel running on the Intel x86 processor. Our prototype is compromised of three protection engines based on a small size hypervisor. The evaluation shows that HyperKRP effectively ensures kernel runtime security with acceptable overhead. Kunli Lin, Wenqing Liu, Kun Zhang 0016, Haojun Xia, Bibo Tu |
GLOBECOM | 5 |
| 2021 | Remote Attestation of Large-scale Virtual Machines in the Cloud Data CenterabstractWith the development of cloud computing, remote attestation of virtual machines has received extensive attention. However, the current schemes mainly concentrate on the single prover, and the attestation of a large-scale virtualization environment will cause TPM bottleneck and network congestion, resulting in low efficiency of attestation. This paper proposes CloudTA, an extensible remote attestation architecture. CloudTA groups all virtual machines on each cloud server and introduces an integrity measurement group (IMG) to measure virtual machines and generate trusted evidence by a group. Subsequently, the cloud server reports the physical platform and VM group's trusted evidence for group verification, reducing latency and improving efficiency. Besides, CloudTA designs a hybrid high concurrency communication framework for supporting remote attestation of large-scale virtual machines by combining active requests and periodic reports. The evaluation results suggest that CloudTA has good efficiency and scalability and can support remote attestation of ten thousand virtual machines. Kun Zhang 0016, Bibo Tu |
TrustCom | 3 |
| 2021 | Log-based Anomaly Detection from Multi-view by Associating Anomaly Scores with User TrustabstractLogs, prevalent among nearly all computer systems, contain rich information that helps with troubleshooting or root cause analysis. Therefore, logs are excellent information sources for anomaly detection. Since logs are diverse and heterogeneous, to deal with all of them requires maintenance personnel to check detection results one by one, which is troublesome. This paper applies an ensemble method that combines the output of different results of log anomaly detection and generates a unified output to reduce the burden of maintenance personnel. Since logs are recorded according to user behavior, they often have non-fixed intervals. We apply a trust computational model to transform the unevenly distributed data into a regularly spaced time series. To our best knowledge, this is the first work to employ the trust in the data processing. Futhermore, there are some parameters introduced by the trust computational model. We take advantage of the parametric ensemble technique to address the issue of parameter choice and finally improve the accuracy of anomaly detection. In this way, our method allows one to track a user from multi-view by logs with ease. The experiment shows that our method could achieve a good performance in detecting anomalies of user behavior from multiple kinds of logs. Lin Wang 0042, Kun Zhang 0016, Chen Li 0066, Bibo Tu |
TrustCom | 4 |
| 2021 | TKCA: a timely keystroke-based continuous user authentication with short keystroke sequence in uncontrolled settingsabstractAbstract Keystroke-based behavioral biometrics have been proven effective for continuous user authentication. Current state-of-the-art algorithms have achieved outstanding results in long text or short text collected by doing some tasks. It remains a considerable challenge to authenticate users continuously and accurately with short keystroke inputs collected in uncontrolled settings. In this work, we propose a Timely Keystroke-based method for Continuous user Authentication, named TKCA. It integrates the key name and two kinds of timing features through an embedding mechanism. And it captures the relationship between context keystrokes by the Bidirectional Long Short-Term Memory (Bi-LSTM) network. We conduct a series of experiments to validate it on a public dataset - the Clarkson II dataset collected in a completely uncontrolled and natural setting. Experiment results show that the proposed TKCA achieves state-of-the-art performance with 8.28% of EER when using only 30 keystrokes and 2.78% of EER when using 190 keystrokes. Chen Li 0066, Ruibang You, Bibo Tu, Linghui Li 0001 |
Cybersecur. | 4 |
| 2020 | Built-in Security Computer: Deploying Security-First Architecture Using Active Security ProcessorabstractContinually disclosed vulnerabilities reveal that traditional computer architecture lacks the consideration of security. This article proposes a security-first architecture, with an Active Security Processor (ASP) integrated to conventional computer architectures. To reduce the attack surface of ASP and improve the security of the whole system, the ASP is physically isolated from Computation Processor Units (CPU) with an asymmetric address space, which enables both ASP and CPU to run their operating system and applications independently in their own memory space. Furthermore, the ASP, which has the highest privilege (Super Root) of the whole system, possesses two advantageous features. First, the ASP can efficiently access all CPU resources and collect multi-dimensional information to monitor malicious behaviors, meanwhile, the CPU cannot access the ASP's private resources in any way. Second, instead of being scheduled by CPUs, the ASP can actively manage the security mechanisms employed in either CPUs or the ASP. Based on the security-first architecture, we introduce several typical security tasks running on ASP. With different considerations in terms of system overhead, complexity and performance, we also explore four typical system-level implementations for integrating the ASP to the security-first architecture. The first-generation ASP was designed and implemented based on the 40nm technology, and a security computer system was implemented based on it. Evaluations on this real hardware platform demonstrate that the security-first architecture can protect the system effectively with minor performance impacts on computing workloads. Dan Meng 0002, Rui Hou 0001, Bibo Tu, Xiaoqi Jia, Yu Wen 0001 |
IEEE Trans. Computers | 4 |
| 2018 | Simau: A Dynamic Privilege Management Mechanism for Host in Cloud Datacenters
Lin Wang 0042, Bibo Tu |
ICICS | 4 |
| 2018 | PCA: Page Correlation Aggregation for Memory Deduplication in Virtualized Environments
Kun Zhang 0016, Bibo Tu |
ICICS | 3 |
| 2018 | Security-first architecture: deploying physically isolated active security processors for safeguarding the future of computingabstractIt is fundamentally challenging to build a secure system atop the current computer architecture. The complexity in software, hardware and ASIC manufacture has reached beyond the capability of existing verification methodologies. Without whole-system verification, current systems have no proven security. It is observed that current systems are exposed to a variety of attacks due to the existence of a large number of exploitable security vulnerabilities. Some vulnerabilities are difficult to remove without significant performance impact because performance and security can be conflicting with each other. Even worse, attacks are constantly evolving, and sophisticated attacks are now capable of systematically exploiting multiple vulnerabilities while remain hidden from detection. Eagering to achieve security hardening of current computer architecture, existing defenses are mostly ad hoc and passive in nature. They are normally developed in responding to specific attacks spontaneously after specific vulnerabilities were discovered. As a result, they are not yet systematic in protecting systems from existing attacks and likely defenseless in front of zero-day attacks. To confront the aforementioned challenges, this paper proposes Security-first Architecture , a concept which enforces systematic and active defenses using Active Security Processors . In systems built based on this concept, traditional processors (i.e., Computation Processors ) are monitored and protected by Active Security Processors. The two types of processors execute on their own physically-isolated resources, including memory, disks, network and I/O devices. The Active Security Processors are provided with dedicated channels to access all the resources of the Computation Processors but not vice versa. This allows the Active Security Processors to actively detect and tackle malicious activities in the Computation Processors with minimum performance degradation while protecting themselves from the attacks launched from the Computation Processors thanks to the resource isolation. Dan Meng 0002, Rui Hou 0001, Bibo Tu, Xiaoqi Jia, Peng Liu 0005 |
Cybersecur. | 4 |
| 2017 | T-VMI: Trusted Virtual Machine Introspection in Cloud EnvironmentsabstractNowadays, the vulnerability of cloud environment exposed in security places Virtual Machine Introspection(VMI) at risk: once attackers subvert any layers of cloud environment, such as host, virtual machine manager(VMM) or qemu, VMI will be exposed undoubtedly to those attackers too. Nearly all existing VMI techniques implicitly assume that both VMM by which VMI accesses specific VM data and host which VMI is running on, are nonmalicious and immutable. Unfortunately, this assumption can be potentially violated with the growing shortage of security in cloud environment. Once VMM or host is exploited, attackers can tamper the code or hijack the data of VMI, then, falsify VM information and certifications to Cloud system's administrators who try to make sure the security of specific VM in certain compute node. This paper proposes a new trusted VMI monitor frame: T-VMI, which can avoid the malicious subversion of the routine of VMI. T-VMIguarantees the integrity of VMI code using isolation and the correctness of VMI data using high privilege level instruction and appropriate trap mechanism. This model is evaluated on a simulation environment by using ARM Foundation Model 8.0 and has been presented on a real development ARMv8 JUNO-r0 board. We finished the comprehensive experiments including effectiveness and performance, and the result and analysis show T-VMI has achieved the aim of expected effectiveness with acceptable performance cost. Lina Jia, Bibo Tu |
CCGrid | 3 |
| 2017 | HA-VMSI: A Lightweight Virtual Machine Isolation Approach with Commodity Hardware for ARMabstractOnce compromising the hypervisor, remote or local adversaries can easily access other customers' sensitive data in the memory and context of guest virtual machines (VMs). VM isolation is an efficient mechanism for protecting the memory of guest VMs from unauthorized access. However, previous VM isolation systems either modify hardware architecture or introduce a software module without being protected, and most of them focus on the x86 architecture. Bibo Tu, Dan Meng 0002 |
VEE | 2 |
| 2012 | Performance analysis and optimization of MPI collective operations on multi-core clusters
Bibo Tu, Jianping Fan 0002, Jianfeng Zhan |
J. Supercomput. | 1 |
| 2011 | Improving Data Locality of MapReduce by Scheduling in Homogeneous Computing EnvironmentsabstractData Locality is one of the critical factors to affect performance. This paper proposes a next-k-node scheduling (NKS) method to improve the data locality of map tasks. The method first calculates the probabilities of each map task, and then preferentially schedules the one with the highest probability. It generates low probabilities for the tasks which satisfy node locality with the nodes to issue requests, so it can reserve these tasks to these nodes. We have implemented the NKS method in hadoop-0.20.2. The experiment results have shown that the NKS method reduced 78% of the map tasks processed without node locality, reduced 77%of the network load caused by the tasks, and improved the performance of Hadoop MapReduce when comparing with the default task scheduling method in Hadoop. Obviously, the NKS method is very suitable for the homogeneous environment with network overload. Zhiyong Zhong, Shengzhong Feng, Bibo Tu, Jianping Fan 0002 |
ISPA | 4 |
| 2010 | Accelerating Spatial Data Processing with MapReduceabstractMap Reduce is a key-value based programming model and an associated implementation for processing large data sets. It has been adopted in various scenarios and seems promising. However, when spatial computation is expressed straightforward by this key-value based model, difficulties arise due to unfit features and performance degradation. In this paper, we present methods as follows: 1) a splitting method for balancing workload, 2) pending file structure and redundant data partition dealing with relation between spatial objects, 3) a strip-based two-direction plane sweeping algorithm for computation accelerating. Based on these methods, ANN(All nearest neighbors) query and astronomical cross-certification are developed. Performance evaluation shows that the Map Reduce-based spatial applications outperform the traditional one on DBMS. Jizhong Han, Bibo Tu, Jiao Dai, Wei Zhou 0019 |
ICPADS | 3 |
| 2009 | Accurate Analytical Models for Message Passing on Multi-core ClustersabstractMemory hierarchy on multi-core clusters has two-fold characteristics: vertical memory hierarchy and horizontal memory hierarchy. Vertical memory hierarchy has been modeled by previous work (e.g. memory logP, lognP, log3P etc.) to analyze middlewarepsilas effects on point-to-point communication with different message sizes and message strides; Horizontal memory hierarchy has become more prominent due to distinct performance among three levels of communication in a multi-core cluster: intra-CMP, inter-CMP and inter-node, which should adequately be considered. Derived from lognP and log3P models, new analytical models mlognP and its reduction 2log{2,3}P are proposed to unitedly abstract memory hierarchy on multi-core clusters in vertical and horizontal levels. The results of performance evaluation show that it is indispensable to incorporate horizontal memory hierarchy into new models suitable for multi-core clusters, and 2log{2,3}P model can predict communication costs for message passing on multi-core clusters more accurately than log3P model. Bibo Tu, Jianping Fan 0002, Jianfeng Zhan |
PDP | 1 |
| 2008 | Multi-core aware optimization for MPI collectivesabstractMPI collective operations on multi-core clusters should be multi-core aware. In this paper, collective algorithms with hierarchical virtual topology focus on the performance difference among different communication levels on multi-core clusters, simply for intra-node and inter-node communication; Furthermore, to select befitting segment sizes for intra-node collective communication can cater to cache hierarchy in multi-core processors. Based on existing collective algorithms in MPICH2, above two techniques construct portable optimization methodology over MPICH2 for collective operations on multi-core clusters. Conforming to above optimization methodology, multi-core aware broadcast algorithm has been implemented and evaluated as a case study. The results of performance evaluation show that the multi-core aware optimization methodology over MPICH2 is efficient. Bibo Tu, Ming Zou, Jianfeng Zhan, Jianping Fan 0002 |
CLUSTER | 1 |
| 2008 | Design Techniques for the Scalability of Cluster Management Software on Dawning SupercomputersabstractCluster management software has faced more increased scalability challenge with ever enlarged cluster scale. Its good scalability rests with feasible design techniques focusing on hybrid software topologies with partitioning policy, non-blocking I/O multiplexing and message on demand. Design patterns are generic solutions to recurring software design problems, and above three important techniques are abstracted the design pattern of scalable cluster management software in this paper. According to this design pattern, some cluster management tools, such as job scheduling, MPI job launcher and so on, have been designed and applied on Dawning supercomputers. Some results of performance evaluation have shown that good scalability of cluster management software on Dawning supercomputers has benefited from this design pattern. Bibo Tu, Ming Zou, Jianfeng Zhan, Jianping Fan 0002 |
ISPA | 1 |
| 2008 | A Fast-Start, Fault-Tolerant MPI Launcher on Dawning SupercomputersabstractDaemon-based MPI launchers are the mainstream in nowadays, because they can startup processes rapidly. However, effective task management and fault tolerance become more important as the scale of supercomputers enlarges. A new fast-start and fault tolerant launcher, called SFLauncher, has been used to startup MPICH task on Dawning supercomputers. This paper details its features and implementation, with emphasis on scalability, self-organization algorithm and garbage reclamation. The results of performance evaluation on SFLauncher are also given. Xu Liu 0001, Bibo Tu, Jianfeng Zhan, Dan Meng 0002 |
PDCAT | 2 |
| 2007 | A layered design methodology of cluster system stackabstractThe application range of cluster has expanded beyond scientific computing, but the present cluster system software fails to provide a flexible architecture to promote code reuse and facilitate building cluster system software for different computing contexts, most of which are developed from scratch case by case, or integrated or packaged with “the best practice”. In this paper, we have proposed a layered design methodology to build cluster system stack with different layers concentrating on different functions, and developed common sets of core service as reusing framework for different computing context. Following this methodology, we have built Phoenix-a complete cluster system stack for both scientific and business computing, which is verified and deployed on Dawning 4000A super computer for scientific computing and other cluster systems for business computing. The qualitative evaluation and our practices show the design methodology of Phoenix has advantages over other methodologies. Jianfeng Zhan, Lei Wang 0004, Bibo Tu, Yu Wen 0001, Yuansheng Chen, Wei Zhou 0019, Dan Meng 0002, Ninghui Sun |
CLUSTER | 3 |
| 2006 | A Failure-Aware Scheduling Strategy in Large-Scale Cluster SystemabstractAs the scale is expanding, node failure becomes a commonplace feature of large-scale cluster systems. As an important part of cluster operating system software, job scheduling takes charge with high efficient resource management and reasonable job scheduling. The function of job scheduling in cluster is divided into two sub-parts: job selection and node allocation. In this paper, we introduce a failure-aware scheduling strategy named LUNF (Longest Uptime Node First) node allocation policy using characterization of nodes' failure. Simulation results show that LUNF policy do better than random node allocation policy for the system performance. Linping Wu, Dan Meng 0002, Jianfeng Zhan, Lei Wang 0004, Bibo Tu |
CCGRID | 5 |
| 2006 | PhoenixG: A Unified Management Framework for Industrial Information GridabstractThe industrial information grid is a special kind of system, the users of which exclusively own geographically distributed computing resources for business service, and try to maintain the lowest total cost of ownership while guaranteeing quality of service. In this paper, we classify the industrial information grid as an extension to grid problem; develop a unified management framework for new management paradigm, which supports the distribution of administration labor and collaboration of system administrator at different locations; propose a self-organizing algorithm, which supports the initial establishment, daily management and exception processing of industrial information grid. Finally, we evaluate the performance of system management, and analyze the management overhead with this new management paradigm. Jianfeng Zhan, Gengpu Liu, Lei Wang 0004, Bibo Tu, Yang Li 0002, Yan Hao, Xuehai Hong, Dan Meng 0002, Ninghui Sun |
CCGRID | 4 |
| 2006 | Design Patterns of Scalable Cluster System SoftwareabstractThe design pattern of cluster system software has an important influence on scalability of massive cluster system. The paper presents design patterns of scalable cluster system software, including scalable software topologies and optimized communication modes. These design patterns have been widely applied in Dawning series of supercomputers and some results of performance evaluation show their good scalability Bibo Tu, Ming Zou, Jianfeng Zhan, Lei Wang 0004, Jianping Fan 0002 |
PDCAT | 1 |
| 2006 | The Failure-rate Aware Scheduling Policies for Large-scale Cluster SystemsabstractWith the scale expanding, node failures become one of the important obstacles when using large-scale cluster systems. The traditional scheduling policies of cluster only took into account the factors such as jobs priority and node load with the node failure rate omitted. The function of job scheduling in cluster system can be divided into two sub-processes: job selection process and node allocation process. In this paper, we introduce several scheduling policies considering the node failure rate with which the more dependable nodes are selected during the node allocation process. In the end, we use the discrete event-driven simulation method to evaluate the policies and the simulation results show that the failure-rate aware scheduling policies do better than random node allocation policy for the system performance Linping Wu, Dan Meng 0002, Jianfeng Zhan, Bibo Tu |
PDCAT | 5 |