Zhihui Han

dblp:143/6512 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
4since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021
YearPublicationVenuePosition
2022 APT Attribution for Malware Based on Time Series Shapelets
abstract
To discover and defend against APT attacks more efficiently, we need to conduct binary analysis and source tracing research on APT malicious codes. This paper attributes APT groups for malicious codes from the perspective of binary similarity. First, we innovatively select the local features of the binary functions for classification and apply time series mining techniques to the mining of sequences of basic blocks (called paths). The Shapelet model selects path shapelets, which are path fragments that can best represent paths and are used to distinguish paths. Path shapelets can provide path-level interpretability for classification. Second, we use API calls to filter functions and generate paths of interest to reduce resource consumption. To evaluate the proposed method, we collect APT malicious codes based on publicly available threat intelligence reports. Our method filters 92.82% of functions and generates an average of 1.37 paths per function. The classification effect has obvious advantages over other methods.
Qinqin Wang, Rui Mei, Zhihui Han
TrustCom5
2022 Measurement of Malware Family Classification on a Large-Scale Real-World Dataset
abstract
There are many review articles on malware analysis, which provide a comprehensive summary of the features, methods, and challenges of malware analysis. But these are limited to a theoretical overview. The purpose of this paper is to take malware family classification as an example, to restore and display the malware analysis in real scenarios.In this paper, the measurement of malware family classification is carried out on a large-scale dataset in the real world. We use the BODMAS dataset, which contains a total of 57,293 malware samples, with carefully curated family information (581 families). Referring to the common features (including static features and dynamic features) and machine learning methods mentioned in the review articles, we conduct feature extraction and classification experiments. Then, we summarize the classification results. Static features can efficiently classify a large number of samples, even with 10% packed samples. In real scenarios, the family distribution is extremely unbalanced, and the family classification results with a large number of samples are better. Different evaluation methods have different interpretations of the classification results. These measurement results provide a basis for further malware analysis in real applications.
Qinqin Wang, Rui Mei, Zhihui Han
TrustCom5
2021 CTSCOPY: Hunting Cyber Threats within Enterprise via Provenance Graph-based Analysis
abstract
In recent years, the security community has been working on detecting increasingly sophisticated cyber threats effectively and responding efficiently. A large body of approaches has been proposed and deployed for discovering malicious behaviors within enterprise IT environments. However, combating two main types of attacks, namely outsider Advanced Persistent Threats (APTs) and insider employee's malicious activities, is still a long-lasting confrontation. We propose a novel provenance graph-based approach for detecting these two major threats. First, we collect system event logs of endpoints in the enterprise IT environment and generate whole-system provenance graph and corresponding correlation graph. Then, we extract most uncommon or abnormal causality subgraphs for further graph embedding. Finally, we adopt an anomaly detection model to separate malicious parts from a mass of benign parts in the correlation graph for analysts' decision. We implement a prototype of CTSCOPY. Our evaluation demonstrates that it outperforms state-of-the-art approaches in various attack scenarios.
Rui Mei, Zhihui Han, Jian-Chun Jiang
QRS3
2021 Explainable APT Attribution for Malware Using NLP Techniques
abstract
APT attribution for malware refers to the process of identifying characteristics that are related to the APT group of an anonymous malware. This paper presents a novel approach for APT attribution. Our approach innovatively combines code features and string features for APT attribution, using paragraph vectors and bag-of-words vectors to represent function semantics and behavior reports, respectively. We apply the model interpretation to APT attribution for the first time, using Random Forest Classifier (RFC) and Local Interpretable Model-agnostic Explanations (LIME) to interpret the model results. We evaluate the method on a data set collected from threat intelligence reports. The results show that our method has advantages in feature selection, method application, and accuracy. Importantly, this article provides a detailed description and examples about the process of model interpretation. Model interpretation improves the trust of cyber security personnel in the model, and facilitates the analysis of network attacks and threat intelligence.
Qinqin Wang, Zhihui Han
QRS3
2020 Dissecting Mobile Offerwall Advertisements: An Explorative Study
abstract
Mobile advertising has become the most popular monetizing way in the Android app ecosystem. Offerwall, as a new form of mobile ads, has been widely adopted by apps, and a number of ad networks have provided such services. Although new to the ecosystem, offerwall ads have been criticized for being aggressive, and the contents disseminated are prone to security issues. However, to date, our community has not proposed any studies to dissect such issues related to offerwall ads. To this end, we present the first work to fill this gap. Specifically, we first develop a robust approach to identify apps that have embedded with offerwall ads. Then, we apply the tool to 10K apps and experimentally discover 312 offerwall apps. We go one step further to characterize them from several aspects, including security issues. Our observation reveals that offerwall ads could indeed be manipulated by hackers to fulfill malicious purposes.
Yangyu Hu, Li Li 0029, Guoai Xu, Zhihui Han, Haoyu Wang 0001
QRS7
2015 Operating System Security Policy Hardening via Capability Dependency Graphs
Zhihui Han, Liang Cheng 0004, Yang Zhang 0021, Dengguo Feng
ISPEC1
2014 Systematic Analysis and Detection of Misconfiguration Vulnerabilities in Android Smartphones
abstract
Android is a modern and popular software platform for smart phones. To manage information and features on smart phones, Android employs intent-based mechanism for inter-application or intra-application communication and provides a permission-based security model that requires each application to explicitly request permissions in its manifest file. However, misconfiguration defined in manifest files and that embedded in application code may result in vulnerabilities due to developer confusion and general misuse of the features provided by Android. In this paper, we propose a logic-programming-based approach to analyze smart phones and discover misconfiguration vulnerabilities in Android manifest file and application code. To enable misconfiguration vulnerability analysis and detection, we develop a static technique to extract security related information from application code, and employ logic predicates to describe various vulnerabilities. Based on this approach, we developed a tool called SADroid to systematically analyze and detect misconfiguration vulnerabilities in Android smart phones. Our results with two representative phones show that the inherent weakness of Android permission model and developers' programming errors make Android vulnerable to some attacks.
Zhihui Han, Liang Cheng 0004, Yang Zhang 0021, Shuke Zeng, Yi Deng 0002, Xiaoshan Sun
TrustCom1
2014 Evaluating and comparing the quality of access control in different operating systems
Liang Cheng 0004, Yang Zhang 0021, Zhihui Han, Yi Deng 0002, Xiaoshan Sun, Dengguo Feng
Comput. Secur.3
2013 Measuring and Comparing the Protection Quality in Different Operating Systems
Zhihui Han, Liang Cheng 0004, Yang Zhang 0021, Dengguo Feng
NSS1