EDBT 2026 Demo / reviewers in the wild / expert
Meng Yu 0001
dblp:13/2440-1
· DBLP profile ↗
34ranked-venue papers
9as first author
2since 2021 · last 2023
0000-0003-2630-5956ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 7 first-author · 2 since 2021Computer networks · 6 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Machine Learning Based Resilience Testing of an Address Randomization Cyber DefenseabstractMoving target defenses (MTDs) are widely used as an active defense strategy for thwarting cyberattacks on cyber-physical systems by increasing diversity of software and network paths. Recently, machine Learning (ML) and deep Learning (DL) models have been demonstrated to defeat some of the cyber defenses by learning attack detection patterns and defense strategies. It raises concerns about the susceptibility of MTD to ML and DL methods. In this article, we analyze the effectiveness of ML and DL models when it comes to deciphering MTD methods and ultimately evade MTD-based protections in real-time systems. Specifically, we consider a MTD algorithm that periodically randomizes address assignments within the MIL-STD-1553 protocol—a military standard serial data bus. Two ML and DL-based tasks are performed on MIL-STD-1553 protocol to measure the effectiveness of the learning models in deciphering the MTD algorithm: 1) determining whether there is an address assignments change i.e., whether the given system employs a MTD protocol and if it does 2) predicting the future address assignments. The supervised learning models (random forest and k-nearest neighbors) effectively detected the address assignment changes and classified whether the given system is equipped with a specified MTD protocol. On the other hand, the unsupervised learning model (K-means) was significantly less effective. The DL model (long short-term memory) was able to predict the future addresses with varied effectiveness based on MTD algorithm's settings. Ganapathy Mani, Marina Haliem, Bharat K. Bhargava, Indu Manickam, Kevin Kochpatcharin, Myeongsu Kim, Eric D. Vugrin, Weichao Wang, Pelin Angin, Meng Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 11 |
| 2021 | Quantify Co-Residency Risks in the Cloud Through Deep LearningabstractCloud computing, while becoming more and more popular as a dominant computing platform, introduces new security challenges. When virtual machines are deployed in a cloud environment, virtual machine placement strategies can significantly affect the overall security risks of the entire cloud. In recent years, the attacks are specifically designed to co-locate with target virtual machines in the cloud. The virtual machine placement without considering the security risks may put the users, or even the entire cloud, in danger. In this article, we present a fine-grained model to quantify the risk level caused by co-residency. Using a large scale dataset collected from Microsoft Azure Platform, we profile the behavior patterns of normal service subscribers (tenants) using our proposed feature metrics. Tenants are clustered into multiple categories. After the baseline is established based on the normal behavior pattern, the derivation can be evaluated for each category and the high-risk group can be labeled accordingly. With the labeled datasets, a classification component and a quantification component are constructed to dynamically quantify the co-residency risks for a specific virtual machine. Our experimental results demonstrate the robustness of our model to the new data and the accuracy is verified by examination of F-score Matrix. Wanyu Zang, Meng Yu 0001, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | Building a Trustworthy Execution Environment to Defeat Exploits from both Cyber Space and Physical Space for ARMabstractThe rapid evolution of Internet-of-Things (IoT) technologies has led to an emerging need to make them smarter. However, the smartness comes at the cost of multi-vector security exploits. From cyber space, a compromised operating system could access all the data in a cloud-aware IoT device. From physical space, cold-boot attacks and DMA attacks impose a great threat to the unattended devices. In this paper, we propose TrustShadow that provides a comprehensively protected execution environment for unmodified application running on ARM-based IoT devices. To defeat cyber attacks, TrustShadow takes advantage of ARM TrustZone technology and partitions resources into the secure and normal worlds. In the secure world, TrustShadow constructs a trusted execution environment for security-critical applications. This trusted environment is maintained by a lightweight runtime system. The runtime system does not provide system services itself. Rather, it forwards them to the untrusted normal-world OS, and verifies the returns. The runtime system further employs a page based encryption mechanism to ensure that all the data segments of a security-critical application appear in ciphertext in DRAM chip. When an encrypted data page is accessed, it is transparently decrypted to a page in the internal RAM, which is immune to physical exploits. Le Guan, Chen Cao 0004, Peng Liu 0005, Xinyu Xing 0001, Xinyang Ge, Shengzhi Zhang, Meng Yu 0001, Trent Jaeger |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2018 | Empirical Evaluation of the Hypervisor Scheduling on Side Channel AttacksabstractAlong with the wide adoption of the cloud platform, various attacks also target clouds. Due to the sharing of the underlying physical resources among different virtual machines (VMs), various side-channel attacks have been demonstrated to be capable of stealing victim's secret information, such as encryption key, by monitoring the victim's access pattern to a shared hardware, such as CPU cache. Among various defense mechanisms proposed, the hypervisor scheduling based schemes shed some light on lightweight solutions that are more likely to be adopted in practice. However, scheduling is affected by several factors that have not been thoroughly investigated so far. In this study, we aim to study in-depth the impact of various factors affecting the hypervisor scheduling, with the objective to understand their impact on mitigating these side-channel attacks. Our results can not only deepen our understanding, but also provide some guidelines to design effective scheduling based defenses in the future. Li Liu 0045, An Wang 0002, Wanyu Zang, Meng Yu 0001, Songqing Chen |
ICC | 4 |
| 2018 | Shuffler: Mitigate Cross-VM Side-Channel Attacks via Hypervisor Scheduling
Li Liu 0045, An Wang 0002, Wanyu Zang, Meng Yu 0001, Menbai Xiao, Songqing Chen |
SecureComm (1) | 4 |
| 2018 | Risk-aware multi-objective optimized virtual machine placement in the cloudabstractCloud computing, while becoming more and more popular as a dominant computing platform, introduces new security challenges. When virtual machines are deployed in a cloud environment, virtual machine placement strategies can significantly affect the overall security risks of the entire cloud. In recent years, the attacks are specifically designed to co-locate with target virtual machines in the cloud. The virtual machine placement without considering the security risks may put the users, or even the entire cloud, in danger. In this paper, we present a comprehensive approach to quantify the security risk of cloud environments from network, host and VM. Accordingly, we propose a Security-aware Multi-Objective Optimization based virtual machine Placement scheme (SMOOP) to seek a Pareto-optimal solution that reduces the overall security risks of a cloud, while considering workload balance, resource utilization on CPU, memory, disk, and network traffic. New placement strategies are designed and our evaluation results demonstrate their effectiveness. The security of clouds could be improved with affordable overheads. The latest VM allocation policies are further studied and integrated into our designs to defeat the co-residence attacks. Wangyu Zang, Li Liu 0045, Songqing Chen, Meng Yu 0001 |
J. Comput. Secur. | 5 |
| 2017 | Reducing Security Risks of Clouds Through Virtual Machine Placement
Wanyu Zang, Songqing Chen, Meng Yu 0001 |
DBSec | 4 |
| 2017 | TrustShadow: Secure Execution of Unmodified Applications with ARM TrustZoneabstractThe rapid evolution of Internet-of-Things (IoT) technologies has led to an emerging need to make them smarter. A variety of applications now run simultaneously on an ARM-based processor. For example, devices on the edge of the Internet are provided with higher horsepower to be entrusted with storing, processing and analyzing data collected from IoT devices. This significantly improves efficiency and reduces the amount of data that needs to be transported to the cloud for data processing, analysis and storage. However, commodity OSes are prone to compromise. Once they are exploited, attackers can access the data on these devices. Since the data stored and processed on the devices can be sensitive, left untackled, this is particularly disconcerting. In this paper, we propose a new system, TrustShadow that shields legacy applications from untrusted OSes. TrustShadow takes advantage of ARM TrustZone technology and partitions resources into the secure and normal worlds. In the secure world, TrustShadow constructs a trusted execution environment for security-critical applications. This trusted environment is maintained by a lightweight runtime system that coordinates the communication between applications and the ordinary OS running in the normal world. The runtime system does not provide system services itself. Rather, it forwards requests for system services to the ordinary OS, and verifies the correctness of the responses. To demonstrate the efficiency of this design, we prototyped TrustShadow on a real chip board with ARM TrustZone support, and evaluated its performance using both microbenchmarks and real-world applications. We showed TrustShadow introduces only negligible overhead to real-world applications. Le Guan, Peng Liu 0005, Xinyu Xing 0001, Xinyang Ge, Shengzhi Zhang, Meng Yu 0001, Trent Jaeger |
MobiSys | 6 |
| 2016 | Energy efficient approximate self-adaptive data collection in wireless sensor networks
Bin Wang 0015, Xiaochun Yang 0001, Guoren Wang, Ge Yu 0001, Wanyu Zang, Meng Yu 0001 |
Frontiers Comput. Sci. | 6 |
| 2014 | Detangling Resource Management Functions from the TCB in Privacy-Preserving Virtualization
Zili Zha, Wanyu Zang, Meng Yu 0001, Peng Liu 0005 |
ESORICS (1) | 4 |
| 2014 | Approximate Self-Adaptive Data Collection in Wireless Sensor Networks
Bin Wang 0015, Xiaochun Yang 0001, Wanyu Zang, Meng Yu 0001 |
WASA | 4 |
| 2014 | Cloud computing for detecting high-order genome-wide epistatic interaction via dynamic clusteringabstractBACKGROUND: Taking the advantage of high-throughput single nucleotide polymorphism (SNP) genotyping technology, large genome-wide association studies (GWASs) have been considered to hold promise for unravelling complex relationships between genotype and phenotype. At present, traditional single-locus-based methods are insufficient to detect interactions consisting of multiple-locus, which are broadly existing in complex traits. In addition, statistic tests for high order epistatic interactions with more than 2 SNPs propose computational and analytical challenges because the computation increases exponentially as the cardinality of SNPs combinations gets larger. RESULTS: In this paper, we provide a simple, fast and powerful method using dynamic clustering and cloud computing to detect genome-wide multi-locus epistatic interactions. We have constructed systematic experiments to compare powers performance against some recently proposed algorithms, including TEAM, SNPRuler, EDCF and BOOST. Furthermore, we have applied our method on two real GWAS datasets, Age-related macular degeneration (AMD) and Rheumatoid arthritis (RA) datasets, where we find some novel potential disease-related genetic factors which are not shown up in detections of 2-loci epistatic interactions. CONCLUSIONS: Experimental results on simulated data demonstrate that our method is more powerful than some recently proposed methods on both two- and three-locus disease models. Our method has discovered many novel high-order associations that are significantly enriched in cases from two real GWAS datasets. Moreover, the running time of the cloud implementation for our method on AMD dataset and RA dataset are roughly 2 hours and 50 hours on a cluster with forty small virtual machines for detecting two-locus interactions, respectively. Therefore, we believe that our method is suitable and effective for the full-scale analysis of multiple-locus epistatic interactions in GWAS. Xuan Guo 0004, Meng Yu 0001, Ning Yu 0004, Yi Pan 0001 |
BMC Bioinform. | 2 |
| 2014 | Obtaining K-obfuscation for profile privacy in social networksabstractABSTRACT The increasing popularity of social networks in various application domains has raised privacy concerns for the individuals involved. In this work, we formally present the definition of profile privacy leakage, which is a newly identified privacy leakage in social networks. However, applying existing methods straightforwardly cannot provide efficient privacy protection for the profiles meanwhile incurring a large amount of information loss. We propose k‐obfuscation to protect profiles against graph property based attacks. We develop a general framework for obtaining k‐obfuscation. In this framework, we propose a novel safe vertex‐profile mapping mechanism, named as k‐mapping. We also design a number of techniques to make the k‐mapping method efficient meanwhile maintaining the data utilities. Extensive experiments on real datasets show the satisfactory performance of our methods in terms of privacy protection, efficiency, and practical utilities. Copyright © 2014 John Wiley & Sons, Ltd. Bin Wang 0015, Xiaochun Yang 0001, Meng Yu 0001, Wanyu Zang |
Secur. Commun. Networks | 4 |
| 2013 | MyCloud: supporting user-configured privacy protection in cloud computingabstractPrivacy concern is still one of the major issues that prevent users from moving to public clouds. The root cause of the privacy problem is that the cloud provider has more privileges than it is necessary, which leaves no options for the cloud users to protect their privacy. Due to the same problem, once the control virtual machine or the cloud platform is compromised, all user's privacy will be breached. Many cryptographic solutions have been developed to protect sensitive data in the cloud. However, arbitrary processing is usually prohibited once cryptography is used. Homomorphic cryptography is considered promising but it does not offer practical performance at the current stage. Wanyu Zang, Meng Yu 0001, Peng Liu 0005 |
ACSAC | 4 |
| 2013 | Cloud Computing for De Novo Metagenomic Sequence Assembly
Xuan Guo 0004, Meng Yu 0001, Yi Pan 0001 |
ISBRA | 3 |
| 2013 | Quantitative survivability evaluation of three virtual machine-based server architectures
Alex Hai Wang, Meng Yu 0001, Wanyu Zang, Peng Liu 0005, Sushil Jajodia |
J. Netw. Comput. Appl. | 4 |
| 2012 | Improving Virtualization Security by Splitting Hypervisor into Smaller Components
Wuqiong Pan, Meng Yu 0001, Jiwu Jing |
DBSec | 3 |
| 2012 | Revealing Abuses of Channel Assignment Protocols in Multi-channel Wireless Networks: An Investigation Logic Approach
Qijun Gu, Kyle Jones, Wanyu Zang, Meng Yu 0001, Peng Liu 0005 |
ESORICS | 4 |
| 2012 | Incentive Compatible Moving Target Defense against VM-Colocation Attacks in Clouds
Meng Yu 0001, Wanyu Zang |
SEC | 4 |
| 2012 | Improving Cloud Survivability through Dependency based Virtual Machine Placement
Wanyu Zang, Meng Yu 0001, Xubin He |
SECRYPT | 5 |
| 2012 | Collaborative Traffic-Aware Intrusion Monitoring in Multi-channel Mesh NetworksabstractIntrusion monitoring is an indispensable security measure for multi-channel wireless mesh networks. This paper studies how to use mesh routers to monitor a network while supporting regular traffic. This paper shows that the traffic aware monitoring (TRAM) problem is an NP-hard problem, which is challenging in coordinating monitoring and traffic forwarding to provide maximal monitoring coverage. This paper proposes three heuristic strategies for seeking optimal monitoring channels and develops a TRAM protocol for accommodating monitoring and transmission simultaneously in mesh networks. The evaluation shows that the proposed TRAM scheme can effectively utilize mesh routers' idle time for monitoring with only minor impact to regular traffic. Qijun Gu, Wanyu Zang, Meng Yu 0001, Peng Liu 0005 |
TrustCom | 3 |
| 2011 | An Efficient RSA Implementation without Precomputation
Wuqiong Pan, Jiwu Jing, Luning Xia, Zongbin Liu, Meng Yu 0001 |
Inscrypt | 5 |
| 2011 | Lightweight Attacks against Channel Assignment Protocols in MIMC Wireless NetworksabstractAlthough multi-interface multi-channel (MIMC) wireless networks have drawn much attention, they are susceptible to various attacks. This paper describes three new types of attacks against a variety of channel assignment protocols: utilization-based conflict attack, link break attack, and denial-of-data attack. These attacks exploit the vulnerabilities arising from the inherent properties of channel assignment protocols in MIMC wireless networks. Analysis and simulation show that the identified attacks are not only very lightweight in attacking but also devastating to the connectivity, throughput, and availability of the MIMC wireless networks. Qijun Gu, Meng Yu 0001, Wanyu Zang, Peng Liu 0005 |
ICC | 2 |
| 2010 | Evaluating Survivability and Costs of Three Virtual Machine based Server Architectures
Meng Yu 0001, Alex Hai Wang, Wanyu Zang, Peng Liu 0005 |
SECRYPT | 1 |
| 2010 | Recovery of data integrity under multi-tier architecturesabstractRecovery from attacks has been extensively studied at the database transaction level and the application level in recent years. To recover compromised database transactions, compensating and redoing the compromised database transactions need to be conducted under the concurrency control restrictions. Under a multi-tier service architecture, at the application level, attack recovery has more restrictions introduced by either control dependencies among application activities or application specifications. Thus, the multi-tier service architecture introduces more challenges to the attack recovery problem. In this study, the authors describe the recovery problems with a multi-layer dependency graph (MLDG). They also describe the techniques of damage assessment and recovery based on an MLDG. Meng Yu 0001, Wanyu Zang, Peng Liu 0005 |
IET Inf. Secur. | 1 |
| 2009 | The implementation and evaluation of a recovery system for workflows
Meng Yu 0001, Peng Liu 0005, Wanyu Zang |
J. Netw. Comput. Appl. | 1 |
| 2008 | TRACE: Zero-Down-Time Database Damage Tracking, Quarantine, and Cleansing with Negligible Run-Time Overhead
Meng Yu 0001, Peng Liu 0005 |
ESORICS | 2 |
| 2007 | Database Isolation and Filtering against Data Corruption AttacksabstractVarious attacks (e.g., SQL injections) may corrupt data items in the database systems, which decreases the integrity level of the database. Intrusion detections systems are becoming more and more sophisticated to detect such attacks. However, more advanced detection techniques require more complicated analyses, e.g, sequential analysis, which incurs detection latency. If we have an intrusion detection system as a filter for all system inputs, we introduce a uniform processing latency to all transactions of the database system. In this paper, we propose to use a "unsafe zone" to isolate user's SQL queries from a "safe zone" of the database. In the unsafe zone, we use polyinstantiations and flags for the records to provide an immediate but different view from that of the safe zone to the user. Such isolation has negligible processing latency from the user's view, while it can significantly improve the integrity level of the whole database system and reduce the recovery costs. Our techniques provide different integrity levels within different zones. Both our analytical and experimental results confirm the effectiveness of our isolation techniques against data corruption attacks to the databases. Our techniques can be applied to database systems to provide multizone isolations with different levels of QoS. Meng Yu 0001, Wanyu Zang, Peng Liu 0005 |
ACSAC | 1 |
| 2005 | Defensive Execution of Transactional Processes against AttacksabstractIt is a well known problem that the attack recovery of a self-healing system rolls back not only malicious transactions, but also legitimate transactions that are dependent on the malicious transactions. Rolling back and re-executing damaged transactions increase the response time of the system and may cause a significant processing delay. In such situations, the availability of the system is compromised and the system suffers the vulnerability of denial of service (DoS). In this paper, we propose a defensive executing technique and analyze its effectiveness. Our technique concurrently executes multiple paths of a transactional processes based on the prediction generated by a discrete time Markov chain. The defensive execution can reduce the delay caused by recovery. We also propose a branch cutting technique to reduce the extra cost introduced by defensive execution. Our analytical results show that our technique is practical against transactional level attacks Meng Yu 0001, Wanyu Zang, Peng Liu 0005 |
ACSAC | 1 |
| 2005 | Specifying and using intrusion masking models to process distributed operationsabstractIt is important for critical applications to provide critical services without any integrity or availability degradation in the presence of intrusions. This requirement can be satisfied by intrusion masking techniques under some situations. Compared with intrusion tolerance techniques, where some i ntegrity or availability degradations are usually caused, intrusion masking techniques use substantial replications to avoid such degradations. Existing intrusion masking techniques, such as the state machine approach, can effectively mask intrusions when processing requests from a client using a server replica group, but they are fairly limited in processing a (multi-stage) distributed operation across multiple server replica groups. As more and more applications (e.g., supply chain management, distributed banking) need to process distributed operations in an intrusion-masking fashion, it is in urgent need to overcome the limitations of existing intrusion masking techniques. In this paper, we specify and compose two intrusion-masking models for inter-replica-group distributed computing. Using these two models, a variety of applications can mask (numerous kinds of) intrusions. Our intrusion masking models overcome the limitations of existing intrusion masking techniques. The survivability of our intrusion-masking models is quantitatively analyzed. A simple yet practical implementation method of our intrusion-masking models is proposed and applied to build two intrusion-masking two-phase-commit (2PC) protocols, and the corresponding efficiency is analyzed. The two intrusion-masking 2PC protocols and the analysis results show that the proposed intrusion-masking models have good utility, practicality, and survivability. Finally, the composition methodology developed in this paper can also be used to develop other intrusion-masking distributed computing models. Meng Yu 0001, Peng Liu 0005, Wanyu Zang |
J. Comput. Secur. | 1 |
| 2005 | Incentive-based modeling and inference of attacker intent, objectives, and strategiesabstractAlthough the ability to model and infer attacker intent, objectives, and strategies (AIOS) may dramatically advance the literature of risk assessment, harm prediction, and predictive or proactive cyber defense, existing AIOS inference techniques are ad hoc and system or application specific. In this paper, we present a general incentive-based method to model AIOS and a game-theoretic approach to inferring AIOS. On one hand, we found that the concept of incentives can unify a large variety of attacker intents; the concept of utilities can integrate incentives and costs in such a way that attacker objectives can be practically modeled. On the other hand, we developed a game-theoretic AIOS formalization which can capture the inherent interdependency between AIOS and defender objectives and strategies in such a way that AIOS can be automatically inferred. Finally, we use a specific case study to show how attack strategies can be inferred in real-world attack--defense scenarios. Peng Liu 0005, Wanyu Zang, Meng Yu 0001 |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2004 | Self-Healing Workflow Systems under AttacksabstractWorkflow systems are popular in daily business processing. Since vulnerability cannot be totally removed from a workflow management system, successful attacks always happen and may inject malicious tasks or incorrect data into the workflow system. Referring to the incorrect data further corrupt more data objects in the system, which comprises the integrity level of the system. This problem cannot be efficiently solved by existing defense mechanisms, such as access control, intrusion detection, and checkpoints. In this paper, we propose a practical solution for online attack recovery of workflows. The recovery system discovers all damages caused by the malicious tasks that the intrusion detection system reports and automatically repairs the damages based on data and control dependencies among workflow tasks. We analyze the behaviors of our attack recovery system based on the continuous time Markov chain model. The analytical results demonstrate that our system is practical when the parameters of the system are reasonably designed. Meng Yu 0001, Peng Liu 0005, Wanyu Zang |
ICDCS | 1 |
| 2003 | Multi-Version Attack Recovery for Workflow SystemabstractWorkflow systems are popular in daily business processing. Since vulnerabilities cannot be totally removed from a system, recovery from successful attacks is unavoidable. We focus on attacks that inject malicious tasks into workflow management systems. We introduce practical techniques for on-line attack recovery, which include rules for locating damage and rules for execution order. In our system, an independent intrusion detection system reports identified malicious tasks periodically. The recovery system detects all damage caused by the malicious tasks and automatically repairs the damage according to dependency relations. Without multiple versions of data objects, recovery tasks may be corrupted by executing normal tasks when we try to run damage analysis and normal tasks concurrently. We address the problem by introducing multiversion data objects to reduce unnecessary blocking of normal task execution and improve the performance of the whole system. We analyze the integrity level and performance of our system. The analytic results demonstrate guidelines for designing such kinds of systems. Meng Yu 0001, Peng Liu 0005, Wanyu Zang |
ACSAC | 1 |
| 2003 | Intrusion Masking for Distributed Atomic Operations
Meng Yu 0001, Peng Liu 0005, Wanyu Zang |
SEC | 1 |