Zhenquan Ding

dblp:151/4858 · DBLP profile ↗
← Back
18ranked-venue papers
4as first author
13since 2021 · last 2024
0000-0002-8449-6140ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 8 since 2021Systems, architecture and hardware · 5 · 1 first-author · 1 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
YearPublicationVenuePosition
2024 VDTriplet: Vulnerability detection with graph semantics using triplet model
Hao Sun 0028, Lei Cui 0003, Zhenquan Ding, Siyuan Li 0014, Zhiyu Hao, Hongsong Zhu
Comput. Secur.4
2023 An Enhanced Vulnerability Detection in Software Using a Heterogeneous Encoding Ensemble
abstract
Detecting vulnerabilities in source code is essential to prevent cybersecurity attacks. Deep learning-based vulnerability detection is an active research topic in software security. However, existing deep learning-based vulnerability detectors (VD) are limited to using either serialization-based or graph-based methods, which do not combine serialized global and structured local information at the same time. As a result, a single method cannot perform well for semantic information that exists in complex source code, leading to low detection accuracy. In this paper, we present EL-VDetect, a stacked ensemble learning approach for vulnerability detection that eliminates these issues. EL-VDetect enhances feature selection techniques to represent the best relevant vulnerability features with the slice code and subgraphs, reducing redundant information of vulnerabilities. Our model combines serialization-based and graph-based neural networks to successfully capture the global and local context information of source code, effectively understands code semantics, and focuses on vulnerable nodes based on the attention mechanism to accurately detect vulnerabilities. To evaluate EL-VDetect's effectiveness, we crawl a real-world dataset from CVEDetails, consisting of functions for eight applications. A comprehensive performance analysis of the real-world dataset shows that EL-VDetect achieves 90.72% accuracy, outperforming baseline deep learning models by 1.75-26.21 %. Our proposed model can better identify vulnerabilities in software than other existing vulnerability detection models.
Hao Sun 0028, Yongji Liu, Zhenquan Ding, Yang Xiao 0011, Zhiyu Hao, Hongsong Zhu
ISCC3
2023 API2Vec: Learning Representations of API Sequences for Malware Detection
abstract
Analyzing malware based on API call sequence is an effective approach as the sequence reflects the dynamic execution behavior of malware.Recent advancements in deep learning have led to the application of these techniques for mining useful information from API call sequences. However, these methods mainly operate on raw sequences and may not effectively capture important information especially for multi-process malware, mainly due to the API call interleaving problem.
Lei Cui 0003, Jiancong Cui, Yuede Ji, Zhiyu Hao, Zhenquan Ding
ISSTA6
2023 HEMC: a dynamic behaviour analysis system for malware based on hardware virtualisation
abstract
Since many malwares disguise themselves by encrypting, obfuscating and recompiling, it is not easy for static analysis methods to recognise new or unknown malwares. This paper proposes a novel dynamic analysis technology based on hardware virtualisation to analyse more malwares with lower computational resources. Firstly, it intercepts the system-call functions to achieve on-demand behaviour analysis by setting special permissions in their physical addresses, which can be dynamically acquired when system-call functions are loaded into memory, as well as only monitoring high-risk functions, which take a small part of the whole functions. Then, this paper utilises copy-on-write technique and incremental image capability to reduce hard drive consumption and hard disk replication time. Finally, this paper proposes a novel approach to capture the return value of system-call functions to deeply analyse the poisoned results of malware samples. Meanwhile, a prototype system, called HEMC, is implemented based on QEMU/KVM . The experiments demonstrate that proposed methods outperform existing methods in efficiency and performance on malware dynamic analysis.
Zhenquan Ding, Lei Cui 0003, Haiqiang Fei, Yongji Liu, Zhiyu Hao
Int. J. Inf. Comput. Secur.1
2022 SeqTrace: API Call Tracing Based on Intel PT and VMI for Malware Detection
Zhenquan Ding, Yonghe Guo, Lei Cui 0003, Yuanlong Peng, Zhiyu Hao
ICA3PP1
2022 MalPro: Learning on Process-Aware Behaviors for Malware Detection
abstract
Malware continuously evolve and become more and more sophisticated. Learning on execution behavior is proven to be effective for malware detection. In this paper, we present MalPro, a DNN based malware detection approach that performs learning on process-aware behaviors for Windows programs. It first employs logistic regression-based weighting method to assess the sensitivity of an API to malicious behavior, and weights the API following run-time arguments with varying degrees of sensitivities. Then, it constructs the process graph of inter-process interactions from which a set of attributes are extracted, for characterizing the relationship of various processes in term of invoke actions. Finally, it feeds the weighted API sequences and the process graph attributes into the DNN for training a binary classifier to detect malware. Moreover, we have implemented and evaluated MalPro on two datasets. The results demonstrate that our method outperforms naive models, verifying the effectiveness of MalPro.
Ying Tong, Chunlai Du, Yongji Liu, Zhenquan Ding, Qingyun Ran, Lei Cui 0003, Zhiyu Hao
ISCC5
2022 Mal-Bert-GCN: Malware Detection by Combining Bert and GCN
abstract
With the dramatic increase in malicious software, the sophistication and innovation of malware have increased over the years. In particular, the dynamic analysis based on the deep neural network has shown high accuracy in malware detection. However, most of the existing methods only employ the raw API sequence feature, which cannot accurately reflect the actual behavior of malicious programs in detail. The relationship between API calls is critical for detecting suspicious behavior. Therefore, this paper proposes a malware detection method based on the graph neural network. We first connect the API sequences executed by different processes to build a directed process graph. Then, we apply Bert to encode the API sequences of each process into node embedding, which facilitates the semantic execution information inside the processes. Finally, we employ GCN to mine the deep semantic information based on the directed process graph and node embedding. In addition to presenting the design, we have implemented and evaluated our method on 10,000 malware and 10,000 benign software datasets. The results show that the precision and recall of our detection model reach 97.84% and 97.83%, verifying the effectiveness of our proposed method.
Zhenquan Ding, Yonghe Guo, Lei Cui 0003, Zhiyu Hao
TrustCom1
2022 An empirical study of vulnerability discovery methods over the past ten years
Lei Cui 0003, Jiancong Cui, Zhiyu Hao, Zhenquan Ding, Yongji Liu
Comput. Secur.5
2022 Black box attack and network intrusion detection using machine learning for malicious traffic
Yiran Zhu, Lei Cui 0003, Zhenquan Ding, Yongji Liu, Zhiyu Hao
Comput. Secur.3
2022 CruParamer: Learning on Parameter-Augmented API Sequences for Malware Detection
abstract
Learning on execution behaviour, i.e., sequences of API calls, is proven to be effective in malware detection. In this paper, we present CruParamer, a deep neural network based malware detection approach for Windows platform that performs learning on sequences of parameter-augmented APIs. It first employs rule-based and clustering-based classification to assess the sensitivity of a parameter to malicious behaviour, and further labels the API following the run-time parameters with varying degrees of sensitivities. Then, it encodes the APIs by concatenating the native embedding and the sensitive embedding of labelled APIs, for characterizing the relationship between successive labelled APIs and their correspondence in terms of security semantics. Finally, it feeds the sequences of API embedding into the deep neural network for training a binary classifier to detect malware. In addition to presenting the design, we have implemented CruParamer and evaluated it on two datasets. The results demonstrate that CruParamer outperforms naïve models when taking raw APIs as input, proving the effectiveness of CruParamer. Moreover, we have evaluated the impact ofmimicryand adversarial attacks on our model, and the results verify the robustness of CruParamer.
Zhiyu Hao, Lei Cui 0003, Yiran Zhu, Zhenquan Ding, Yongji Liu
IEEE Trans. Inf. Forensics Secur.6
2022 iConSnap: An Incremental Continuous Snapshots System for Virtual Machines
abstract
The reliability of data and services hosted on a virtual machine (VM) is a top concern in cloud environments. The Continuous Snapshots can reduce the data loss in case of failures and thus is prevailing for protecting long-running systems. However, existing methods suffer from long VM downtime, long snapshot interval and significant performance loss. In this article, we present iConSnap, a system designed to take fine-grained continuous snapshots of virtual machines without compromising VM performance. First, iConSnap adopts the copy-on-write (COW) mechanism to save the memory pages on-demand, and thus decreases the VM downtime to about 200 milliseconds. Second, we extend the idea of COW and propose a lazily incremental approach to save the delta data between two successive snapshots only once, thereby reducing the snapshot duration and snapshot data a lot. Third, we propose a scheduling mechanism to mitigate the VM performance penalty issue. Last, we introduce a method combined of compression and time-aware multi-granularity reclamation strategy to reduce the storage costs without losing performance and availability. We implement iConSnap on QEMU/KVM and evaluate it through a set of experiments. The experimental results show that iConSnap outperforms existing approaches in terms of VM downtime, snapshot duration, storage costs and VM performance.
Zhiyu Hao, Wei Wang 0428, Lei Cui 0003, Xiao-chun Yun, Zhenquan Ding
IEEE Trans. Serv. Comput.5
2021 EmuIoTNet: An Emulated IoT Network for Dynamic Analysis
Qin Si, Lei Cui 0003, Zhenquan Ding, Yongji Liu, Zhiyu Hao
ICICS (1)4
2021 VDSimilar: Vulnerability detection based on code similarity of vulnerabilities and patches
Hao Sun 0028, Lei Cui 0003, Zhenquan Ding, Zhiyu Hao, Jiancong Cui, Peng Liu 0044
Comput. Secur.4
2020 CHEAPS2AGA: Bounding Space Usage in Variance-Reduced Stochastic Gradient Descent over Streaming Data and Its Asynchronous Parallel Variants
Yaqiong Peng, Haiqiang Fei, Zhenquan Ding, Zhiyu Hao
ICA3PP (2)4
2016 Piccolo: A Fast and Efficient Rollback System for Virtual Machine Clusters
abstract
Rollback is an effective technique to resume the system execution from a recorded intermediate state upon failures. However, in virtualized environments, rollback of a virtual machine cluster (VMC) produces high network traffic and long service disruption, consequentially imposing significant overhead both on network and applications. In this paper, we propose Piccolo, a fast and efficient rollback system, to restore a VMC from snapshot files over datacenter network. We exploit the similarity among VMC snapshots and leverage multicast to deliver the identical pages across VMs placed on disperse hosts, thereby bypassing transmission of a large number of unnecessary pages. In addition to presenting Piccolo, we detail its implementation, and evaluate it by a set of experiments. The results show that Piccolo could achieve a significant reduction in terms of total sent data, network traffic and rollback latency compared to the existing generic rollback techniques.
Lei Cui 0003, Zhiyu Hao, Chonghua Wang, Haiqiang Fei, Zhenquan Ding
ICPP5
2015 Lightweight Virtual Machine Checkpoint and Rollback for Long-running Applications
Lei Cui 0003, Zhiyu Hao, Haiqiang Fei, Zhenquan Ding, Bo Li 0005, Peng Liu 0044
ICA3PP (3)5
2015 Traffic Replay in Virtual Network Based on IP-Mapping
Zhiyu Hao, Yongzheng Zhang 0002, Zhenquan Ding, Haiqiang Fei
ICA3PP (4)4
2013 CADM: A Centralized Administration and Dynamic Monitoring Framework for Network Intrusion Detection Based on Virtualization
abstract
Virtualization technology, which has the characteristic of producing dynamic change, enables the virtual network structure to no longer depend strictly on the underlying hardware environment. With virtualization platform administrators tasked with preventing attacks in order to provide uninterrupted service, existing intrusion detection technologies are continuously challenged. Consequently, this paper proposes a Centralized Administration and Dynamic Monitoring framework (CADM) based on virtualization for network intrusion detection. CADM is able to centrally administrate, and monitor network behavior in the virtual computing environment by automatically deploying and updating intrusion detection processes and rules. In the aspect of monitoring capability, CADM allows the monitoring locations in intrusion detection to be automatically adjusted in real time, thus adapting to the dynamic changes (such as migration) of virtual machines (VMs). Moreover, the monitoring processes involved in intrusion detection could also be automatically updated by dynamically updating security strategies. In the aspect of monitoring granularity, CADM is able to monitor network interfaces of each virtual machine (VM) for fine-grained network intrusion detection and network traffic acquisition. Our experimental results demonstrate that more convenient and efficient monitoring and administrating capabilities are available with CADM for virtualization platform administrators.
Zhenquan Ding, Zhiyu Hao, Yongzheng Zhang 0002
PDCAT1