Yanling Hwang

dblp:136/0661 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 since 2021Computer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Web and mobile security · 50% Authentication and access control · 25% Privacy and data protection · 25%
Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
access control
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Web and mobile security › mobile security
android permission control
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Web and mobile security
mobile security
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Privacy and data protection › mobile privacy
runtime permission management
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Software maintenance and evolution › software ecosystems
third-party libraries
0.112021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021

Methods — techniques the papers use, named apart from their topics

dynamic permission API · 1.0android framework modification · 1.0
YearPublicationVenuePosition
2021 DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries
abstract
Today's smartphone app stores are full of apps with diverse features. Many developers use third-party libraries to reduce the development time and cost, but developers often ignore the security problems of third-party libraries. A major security problem introduced by third-party libraries is that a third-party library has the same permissions as the apps, calledhost-appshereafter, that use it. According to previous research, having the same permissions as its host apps, a third-party library could have unauthorized access to user data, which poses a serious threat to app users. Therefore, how to prevent third-party libraries from abusing permissions has become an important issue. To solve this problem, this paper proposes a Dynamic Permission Control mechanism, calledDynamic Permission ControllerorDPChereafter, for app developers to prohibit third-party libraries from abusing host apps’ dangerous permissions. DPC modifies the permission control mechanism of Android framework to make apps have a more flexible permission management mechanism when they are running. DPC provides new APIs which allows an app to dynamically disable a granted dangerous permission before invoking an API of a third-party library and restore the dangerous permission after completing the API. Hence, DPC protects user's privacy by blocking unauthorized access from third-party libraries. Meanwhile, without the requirement that an app developer needs to know the detail of third-party libraries, the app still can use APIs of third-party libraries safely. Experimental results show that DPC works with many popular apps downloaded from Google Play well and DPC prohibits a third-party library from having the same dangerous permissions that its host apps have. Hence, unlike previous solutions, DPC does not have compatibility problems. The overhead introduced by DPC on an emulator and Nexus 7 are 1.8 and 0.3 percent respectively.
Fu-Hau Hsu, Nien-Chi Liu, Yanling Hwang, Che-Hao Liu, Chuan-Sheng Wang, Chang-Yi Chen
IEEE Trans. Dependable Secur. Comput.3
2017 Detecting Web-Based Botnets Using Bot Communication Traffic Features
abstract
Web-based botnets are popular nowadays. A Web-based botnet is a botnet whose C&C server and bots use HTTP protocol, the most universal and supported network protocol, to communicate with each other. Because the botnet communication can be hidden easily by attackers behind the relatively massive HTTP traffic, administrators of network equipment, such as routers and switches, cannot block such suspicious traffic directly regardless of costs. Based on the clients constituent of a Web server and characteristics of HTTP responses sent to clients from the server, this paper proposes a traffic inspection solution, called Web-based Botnet Detector (WBD). WBD is able to detect suspicious C&C (Command-and-Control) servers of HTTP botnets regardless of whether the botnet commands are encrypted or hidden in normal Web pages. More than 500 GB real network traces collected from 11 backbone routers are used to evaluate our method. Experimental results show that the false positive rate of WBD is 0.42%.
Fu-Hau Hsu, Chih-Wen Ou, Yanling Hwang, Ya-Ching Chang, Po-Ching Lin
Secur. Commun. Networks3
2016 VRS: a values-based reputation system for web services
abstract
Abstract The reputation system is used to display the reputation of entities based on the ratings or appraisals given by users who have used or purchased those entities. Web service providers supply various reputation systems for their users. However, these promising reputation systems face some challenges. First, even though different persons have different preference andvalues(values are a person's beliefs about what things are good or bad), these systems still give the same rating to the same entity for all users. Second, they may be greatly influenced by Sybil attacks. In this paper, we propose a reputation system, called values‐based reputation system (VRS), to solve the aforementioned problems. VRS customizes the rating of an entity for each user based on the ratings of the entities provided by other users who have similarvaluesor preference to the user. Experimental results on 256 users show that compared with existing reputation systems VRS is more robust to Sybil attacks and provides a recommendation rating that is closer to the rating given by the user after it used the related entity. Copyright © 2016 John Wiley & Sons, Ltd.
Fu-Hau Hsu, Yu-Liang Hsu, Yanling Hwang, Li-Han Chen, Chuan-Sheng Wang, Chang-Kuo Tso, Szu-Chi Liu, Po-Ching Lin, Chi-Hsien Hsu
Secur. Commun. Networks3
2014 Hawkeye: Finding spamming accounts
abstract
Email spam is a critical problem to the Internet for a long time. The average amount of spam mail reached 72.1% of all email traffic in the world in 2012. The greatest threat to the email service providers was the spam mail sent from botnet, because the spam mail sent from botnet was accounting for more than 78% in 2011; therefore appeared many anti-spam solutions and techniques that were focus on the botnet. Owing to these anti-spam techniques, botnet spam is not effective as before. Spammers are finding new way to send the spam mail. One of the effective methods is using compromised accounts (or bot accounts) to send the spam mail because compromised accounts have good reputation IP addresses and compromised accounts send the spam mail with complete SMTP implemented server, such as Gmail, Yahoo!Mail, and Microsoft Live Mail. The spam mail send form compromised accounts are very difficult to be detected by any anti-spam techniques. Hence, we focus on the features spammers cannot easily hide. According to our research we find that normal users usually do not reply to the spam mail. Moreover, our empirical analysis reveals that the compromised account actually have low reply rate. We develop a system called “Hawkeye” that can find the compromised accounts effectively by checking the account's reply rate.
Chia-Heng Li, Fu-Hau Hsu, Shih-Jen Chen, Chuan-Sheng Wang, Yao-Hsin Chen, Yanling Hwang
APNOMS6