EDBT 2026 Demo / reviewers in the wild / expert
Zhijun Wu 0001
dblp:21/3743-1
· DBLP profile ↗
44ranked-venue papers
21as first author
31since 2021 · last 2026
0000-0002-0691-1767ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 12 first-author · 15 since 2021Computer networks · 9 · 3 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OCREN: A countermeasure for ADS-B attacks in the context of air traffic controlabstractAutomatic dependent surveillance–broadcast (ADS-B) is a surveillance technology widely endorsed by the International Civil Aviation Organization (ICAO). It has seen extensive use in both commercial and general aviation, playing a vital role in supporting air traffic control (ATC) operations. However, the inherent openness of the ADS-B protocol leaves it vulnerable to malicious network attacks. Previous research has largely overlooked ATC application scenarios in commercial air transportation, and existing detection algorithms suffer from low attack detection rates. Furthermore, current research lacks effective and reliable methods for responding to identified attacks. This paper primarily investigates ADS-B attack detection and recovery within the context of ATC. We integrate flight plans with ADS-B data to create a flight data restriction domain and employ the online classification restriction-extreme learning machine (OCR-ELM) model to detect and flag abnormal data streams. Subsequently, the nonlinear autoregressive neural network (NARX) model, combined with a recovery strategy, is utilized to restore the flagged abnormal data. The proposed method enables precise and rapid identification of abnormal targets in ADS-B data and eases targeted recovery of the affected data points. We employed real flight data to simulate anomalous data caused by various malicious attacks, evaluating detection and recovery performance using several performance metrics. The results show that our method achieves an average detection accuracy of 98.6%, a false positive rate of 1.69%, a false negative rate of 0.93%, and an average structural similarity index of 0.9895 for the recovered data. This method ensures the security of information and continuous accessibility of ADS-B, thus enhancing the operational safety and robustness of air traffic control. Meng Yue 0002, Sunshuo Shi, Zhijun Wu 0001 |
Expert Syst. Appl. | 4 |
| 2026 | LMDA: Lightweight Multiauthority CP-ABE Scheme Based on Dynamic Attributes for System Wide Information ManagementabstractThe System Wide Information Management (SWIM) system serves as an advanced platform for managing and sharing diverse aviation data, such as aeronautical, flight, and meteorological information. With the exponential growth of aviation data, ensuring data security and privacy within SWIM has become increasingly important. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is widely regarded as an effective cryptographic technique for ensuring secure and private data access. However, traditional CP-ABE schemes rely on computationally expensive bilinear pairings, which are unsuitable for resource-constrained aviation Internet of Things application scenarios in SWIM, such as Aircraft Access to SWIM. To address this limitation, we propose a lightweight multi-authority CP-ABE scheme based on dynamic attributes. This scheme replaces bilinear pairing operations with efficient scalar multiplication on elliptic curve points and outsources most decryption operations to outsourcing decryption nodes, thereby significantly reducing computational overhead. In addition, this scheme introduces a dynamic attribute mechanism to support fine-grained access control, and outsources data verification and attribute revocation to the blockchain to ensure data integrity. Security analysis shows that our scheme achieves indistinguishability under adaptive chosen-ciphertext attacks and is resistant to collusion attacks. Experimental evaluations further demonstrate that our scheme significantly enhances computational and communication efficiency. Lizhe Zhang, Yiao Ma, Zhijun Wu 0001, Kenian Wang |
IEEE Internet Things J. | 3 |
| 2026 | Defending PoW Blockchains Against Game-Theoretic DoS Attacks: A Rational Strategy AnalysisabstractGame-theoretic denial-of-service (GDoS) attacks exploit rational miners' incentives to degrade the throughput and security of proof-of-work (PoW) blockchains, even when the attacker controls less than 20% of the total hash power. Existing defenses commonly rely on protocol modifications, which risk hard forks and destabilize the system. This paper presents the first rational, protocol-preserving defense against GDoS attacks. We formalize GDoS by unifying selfish-mining-based and blockchain-based denial-of-service variants under a common definition, and establish its theoretical foundation through a dynamic game model with a subgame perfect Nash equilibrium (SPNE). Unlike prior protocol-level defenses, our strategy maintains consensus integrity without introducing any changes to PoW. We propose a cooperative hash-power hopping mechanism in which miners temporarily reallocate hash power to larger pools when under attack to preserve expected payoffs and suppress attacker incentives. To quantify miner utilities under different strategies, we develop a combined game-theoretic and Markov-chain analytical framework and derive closed-form critical profitability thresholds. Simulations calibrated to real-world Bitcoin hash-power distributions show that the proposed strategy reduces attacker revenue gains by more than 20% and prevents throughput degradation across the entire attack range. These results demonstrate that rational, incentive-compatible cooperation can effectively strengthen PoW blockchains against emerging strategic threats. Zhijun Wu 0001, Zhiquan Liu 0001, Meng Yue 0002, Yanrong Lu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | SPRLP: Spatial-aware Pathfinding Routing for Aeronautical Ad-Hoc Networks based on Location PredictionabstractThe global aviation industry's swift expansion is nearing the capacity limits of civil aviation communications system, with transoceanic flights being particularly affected. To counter these challenges, we propose the Spatial-aware Pathfinding Routing based on Location Prediction (SPRLP) for aeronautical ad-hoc networks (AANET). SPRLP addresses the unique challenges of AANET, such as vast network space, low node density, node mobility, dynamic topology, and bandwidth constraints. It enhances communication efficiency and reliability by combining packet transmission time with predicted neighbor locations to mitigate transmission interruptions. The routing algorithm incorporates aircraft position predictions, flight paths, and node congestion to establish stable and efficient communication paths within the aviation network. Additionally, an adaptive beacon interval mechanism is introduced to minimize routing overhead. Simulations using OMNeT++ demonstrate that SPRLP significantly outperforms other Mobile Ad-Hoc Network routing protocols in terms of efficiency and reliability. Meng Yue 0002, Baoxu Chen, Zhijun Wu 0001 |
IWCMC | 4 |
| 2025 | Trustworthy Management of Network Resources Based on BlockchainabstractWith the increasing demand for network resource management, traditional centralized management approaches face challenges such as single point of failure, excessive permissions, and privacy breaches when sharing resources across multiple domains. To address these issues, this paper proposes a blockchain-based trustworthy management solution for network resources. The proposed solution ensures data privacy and security through a decentralized blockchain mechanism, while providing fair and transparent resource allocation. The system design encompasses privacy protection, data immutability, authorized access control, as well as fairness and incentive compatibility in resource distribution. Analysis indicates that this solution enables effective and equitable resource management in the face of DDoS attacks, thereby providing an innovative pathway for building a secure and scalable network management system. Meng Yue 0002, Zhijun Wu 0001, Yanrong Lu |
IWCMC | 3 |
| 2025 | EDVFL: An evaluable and decentralized privacy-preserving VFL for secure data sharing in ATM
Qing Wang 0065, Zhijun Wu 0001, Yanrong Lu |
Comput. Networks | 2 |
| 2025 | Blockchain security threats: A comprehensive classification and impact assessment
Zhijun Wu 0001, Meng Yue 0002, Yanrong Lu |
Comput. Networks | 1 |
| 2025 | Detection of CIFA using SMOTEBoost and LSTM in NDN
Liang Liu 0012, Silin Peng, Zhijun Wu 0001 |
Comput. Secur. | 3 |
| 2025 | TrustCNAV: Certificateless aggregate authentication of civil navigation messages in GNSSabstractThe Global Navigation Satellite System (GNSS) is capable of accurate positioning because it can provide high-precision data. These data are transmitted to the receiver in the form of navigation messages, called civil navigation messages (CNAV). As it is transmitted in an open, transparent environment without data integrity protection mechanisms and secure data transmission measures, the CNAV is suspected to spoofing attacks. In 2023, the OPSGROUP has received approximately 50 reports of GPS spoofing activity. A spoofed plane's navigation system will show it as being in a different place - a security risk if a jet is guided to fly into a hostile country's airspace. To prevent the forging of GNSS positioning data by spoofing attacks targeting CNAV, we propose a certificateless aggregation authentication for CNAV by using the elliptic curve discrete logarithm problem and the combination of the GNAV structural characteristics, called TrustCNAV. Security proof and performance analysis indicate that this authentication scheme can resist spoofing attacks and ensure data security of CNAV, also it avoids pairing operations with high computational complexity, thus meeting security requirements without causing too much time and communication consumption. Zhijun Wu 0001, Liang Liu 0012, Meng Yue 0002 |
Comput. Secur. | 1 |
| 2025 | LBCDA: lightweight blockchain-assisted cross-domain authentication scheme with privacy protection for SWIMabstractAs a global civil aviation information-sharing service platform, cross-domain authentication of system wide information management (SWIM) has attracted much attention.Due to the inability of existing authentication schemes to meet the needs of lightweight users such as aircraft for secure cross-domain access to SWIM in the aircraft access to SWIM application, we propose a lightweight blockchain-assisted cross-domain authentication scheme for SWIM.The scheme uses certificateless cryptography to generate user private keys and achieves mutual authentication and key agreement for cross-domain users based on the elliptic curve Diffie-Hellman.Additionally, cross-domain users share authentication public parameters and anonymous identity through a consortium blockchain, thereby protecting identity privacy and establishing trust among them.We use SVO logic to prove that the authentication protocol realises its design goals and utilise the formal verification tool Scyther to demonstrate the scheme's security.Compared to the four existing schemes, our scheme has lower computational and communication overhead. Lizhe Zhang, Yiao Ma, Zhijun Wu 0001 |
Int. J. Inf. Comput. Secur. | 4 |
| 2025 | A DDoS attack detection method based on IQR and DFFCNN in SDN
Meng Yue 0002, Huayang Yan, Rui-Ze Han, Zhijun Wu 0001 |
J. Netw. Comput. Appl. | 4 |
| 2024 | Data Source Authentication Protocol for Aviation Broadband Communication SystemabstractThe Aviation Broadband Communication System (ABCS) plays a crucial role in the modern civil aviation field. However, when controlling the broadcast information of Broadcast Control Channel (BC), the system faces network security issues such as man in the middle attacks and pseudo base station attacks, which have become increasingly serious. Therefore, when designing and developing aviation broadband communication systems, it is necessary to fully consider the guarantee mechanism for ensuring secure data transmission. This article focuses on the BC control channel and successfully implements source authentication for broadcast control data using the Timed Efficient Stream Loss Tolerant Algorithm Protocol (TESLA) combined with the SM3 algorithm. The proposed method effectively solves the security issues faced by broadcast data. By analyzing the security overhead brought by the added security mechanisms, we have proven that this method is superior to packet-by-packet signature authentication protection and hash chain authentication schemes, thus meeting the requirements of aviation digital communication application scenarios. Yongqiang Huang 0005, Zhijun Wu 0001, Meng Yue 0002 |
IWCMC | 3 |
| 2024 | Network Security Situation Assessment Method Based Eigenvector CentralityabstractTraditional network security situation assessment methods rely too much on expert systems, and with networks that gradually show dynamic and heterogeneous characteristics, such as vehicle networks and aviation networks, the general assessment methods can no longer be used well. To address these problems, this paper proposes a method that uses a neural network approach to identify threats and based on this, quantifies the importance of network devices using eigenvector centrality indicators, combining with the severity and impact of the attack to assess the network security situation. The method uses sparse encoder to extract network flow features for identification; uses a combination of BiLSTM with attention mechanism to identify the attacks present in the network; modeling the correlation relationship between hosts in the network by classifying different hosts and quantifying the impact of various attacks on the network space to obtain the situation value. The results from the experiment demonstrate that the model performs superiorly to the compared model, and the quantification technique is characterized by increased objectivity and precision. Zhijun Wu 0001, Haoyu Fan |
IWCMC | 1 |
| 2024 | VLDoS: Variable Low-Rate DoS Attack Model for BBR Algorithm in TCP
Meng Yue 0002, Zihan Lai, Zhijun Wu 0001 |
SecureComm (2) | 4 |
| 2024 | A Reliable Encrypted Traffic Classification Method Based on Attention MechanismsabstractIn online encrypted traffic classification, existing machine learning methods face the challenge of manually extracting flow-level statistical features. Deep learning methods encounter complex preprocessing issues, requiring models to balance complexity and accuracy. Therefore, this paper proposes a reliable method for encrypted traffic classification based on attention mechanism. The method designs a neural network model based on the Transformer architecture. The model employs embedding operations to extract byte features and utilizes position encoding to capture spatial features, which enables efficient packet-level classification of encrypted traffic. By using only the first 40 bytes of the packet header as input, the model avoids analyzing the payload, thereby reducing the risk of privacy breaches. Moreover, the simplified input features reduce the time overhead for feature extraction, enhancing training speed and making the model suitable for deployment in high real-time scenarios. This paper validates the proposed method experimentally using two public datasets: ISCX VPN-nonVPN and ISCX Tor-nonTor. The experimental results indicate that the proposed method outperforms existing approaches, achieving an improvement of at least 1.5% in classification accuracy and 1.6% in F1 score. Additionally, with a memory usage of 533 MB, it meets the performance requirements for low-resource scenarios. Zhijun Wu 0001, Shanhe Niu, Meng Yue 0002 |
TrustCom | 1 |
| 2024 | CCS: A Cross-Plane Collaboration Strategy to Defend Against LDoS Attacks in SDNabstractSoftware-Defined Networking (SDN) actualizes the separation of control and forwarding, innovates network functionality with a logically centralized controller, and facilitates network-wide collaboration. Contemporary SDN infrastructure exposes potential bottlenecks which are prone to engaging low-rate denial of service (LDoS) attacks. Currently, a great deal of detection methods are deployed in the controller, and the controller needs to poll the switch frequently, which brings heavy load to the controller and the southbound link. According to the analysis of existing researches, we focused on the how to decrease the frequent polling of the controller and improve the detection rate. In this paper, we adopted the idea of cross-plane collaboration and proposed a two-phase detection framework, which carried out the lightweight detection method in the data plane and the in-depth detection based on Bayesian voting mechanism in the control plane. Once LDoS attacks are detected, the controller recalculates routes for the bottleneck nodes using the optimized Dijkstra algorithm to complete mitigation. Theoretical analyses and extensive experiments are conducted to validate the performance of our proposed method. Test results show that our method outperforms other traditional methods in terms of the detection rate of 99.1%, the detection delay of 1.3s and the communication overhead of 1068 Byte/s, the average CPU utilization of controller remains at approximately 3.5%. The proposed method takes a step forward to enhance the security of SDN. Meng Yue 0002, Qingxin Yan, Zichao Lu, Zhijun Wu 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Research on SWIM Cooperative Emergency Response and Resilient Disaster Recovery Based on SurvivabilityabstractSystem Wide Information Management (SWIM), as a basic network facility for providing aviation flight data sharing services, is facing a large quantity of security threats. In order to actively respond to possible security incidents and disasters situations in the SWIM system, this paper studies the SWIM coordinated emergency response and resilient disaster recovery methods to ensure the rapid recovery and survivability of SWIM data services. Specifically, our research includes: (i) SWIM collaborative emergency response and resilient disaster backup architecture based on survivability; (ii) SWIM active drift and compensatory mutual assistance mechanism; (iii) SWIM adaptive random autonomous scheduling algorithm; (iv) Redundant SWIM data backup and resilient disaster recovery method. SWIM emergency response and disaster recovery is the lifeline to guarantee aviation shared data security, which has great significance for aviation transportation to operate safely and efficiently. Jin Lei, Zhijun Wu 0001 |
ISADS | 3 |
| 2023 | Search mechanism for data contents based on bloom filter and tree hybrid structure in system wide information managementabstractAbstract The system wide information management (SWIM) system infrastructure layer uses information‐centric networking (ICN) to implement the cache routing and sharing of air traffic information data. The SWIM network searches and forwards routes on the basis of content names. The variable length, hierarchical name structure, and routing updates caused by the frequent publication and deletion of content make the implementation of fast name routing lookup algorithms a significant but arduous task. To address this problem, this study designed a name matching mechanism on the basis of the hybrid structure of the Bloom filter and the Tree. Compared with the traditional Bloom filter search scheme, this search mechanism reduces the quantity of Bloom filter insertion entries and reduces the possibility of hash collisions. Compared with the traditional Tree search scheme, the proposed mechanism can effectively solve the problem of numerous memory accesses caused by extremely long name prefixes, improving the query efficiency. In addition, the proposed composite structure is compared with several methods, such as DIPIT and NPT, by analyzing the effects of layering, global delay and search speed. The experimental results show that the proposed structure has a favourable performance in terms of storage overhead and search speed. Lizhe Zhang, Zhuoning Bai, Bohua Cui, Zhijun Wu 0001 |
IET Commun. | 4 |
| 2023 | A method of speech information hiding in inactive frame based on pitch modulationabstractTo solve the problem that the speech information hiding algorithm based on random position selection and matrix coding has insufficient hiding capacity, the paper proposes a novel pitch modulation steganography method based on inactive frame. In this method, the least significant bit (LSB) replacement method is adopted for inactive frames, and the speech information hiding algorithm based on random position selection and matrix coding is adopted for active frames, which realises the pitch modulation information hiding method based on inactive frames. Finally, simulation experiments are carried out for the pitch modulation information hiding method based on inactive frames. The results indicate that the maximum hiding capacity of the algorithm in this paper can reach 241.67 bps, which significantly improves the hiding capacity, and at the same time the concealment has also been improved to a certain extent. Zhijun Wu 0001, Chenlei Zhang |
Int. J. Inf. Comput. Secur. | 1 |
| 2023 | Unified identity authentication scheme of system wide information management based on SAML-PKI-LDAPabstractSystem wide information management (SWIM) is a platform to share and exchange information on the new air traffic management (ATM) services between different departments and systems in the civil aviation field. Through the connection of SWIM and various application services, a virtual information pool is formed to solve the interconnection issues of different systems. To ensure data security in the system and quick authentication of legitimate users, we propose a unified identity authentication scheme for SWIM. This scheme improves the security assertion markup language (SAML) cross-domain authentication model and integrates it with the public key infrastructure (PKI) authentication system and lightweight directory access protocol (LDAP). Experimental results show that this scheme realises the functions of user management, identity authentication, and cross-domain access, which can meet requirements of the SWIM gateway. Lizhe Zhang, Zhuoning Bai, Zhijun Wu 0001, Kenian Wang |
Int. J. Inf. Comput. Secur. | 3 |
| 2023 | GAN-LSTM-Based ADS-B Attack Detection in the Context of Air Traffic ControlabstractAutomatic dependent surveillance–broadcasting (ADS-B) is a surveillance technology strongly promoted by the International Civil Aviation Organization. It has been widely used in commercial and general aviation, to provide support for the normal operation of air traffic control (ATC) in commercial aviation. However, the openness of the ADS-B protocol makes it extremely vulnerable to cyber attacks. Previous research did not specifically consider the application scenarios of ATC in commercial air transport, and there is a problem of low attack detection rates. This article focuses on ADS-B attack detection under the background of ATC. We combine the flight plan with ADS-B information to construct an airspace flight image stream and process the image stream using a generative adversarial network–long short-term memory (GAN-LSTM) model to predict future images. Then, we identify abnormal images based on the normalized cross-correlation and mark anomalous targets. Our method can quickly locate anomalous targets in the controlled airspace. Based on real flight data, abnormal data for various malicious attacks were forged. We evaluated the detection performance of the method through a confusion matrix and several performance indices. The final experimental results showed that our detection scheme exhibited good detection performances for various attacks, with an average detection accuracy of 92.3%, a false positive rate of 11.9%, and a false negative rate of 6.2%. This approach guarantees the information security of ADS-B, thereby improving the operational security of ATC. Meng Yue 0002, Han Zheng 0003, Zhijun Wu 0001 |
IEEE Internet Things J. | 4 |
| 2023 | Consumer-source authentication with conditional anonymity in information-centric networking
Yanrong Lu, Chenzhuo Wang, Meng Yue 0002, Zhijun Wu 0001 |
Inf. Sci. | 4 |
| 2023 | MFPD-LSTM: A steganalysis method based on multiple features of pitch delay using RNN-LSTM
Zhijun Wu 0001 |
J. Inf. Secur. Appl. | 1 |
| 2022 | AMR Steganalysis based on Adversarial Bi-GRU and Data DistillationabstractExisting AMR (Adaptive Multi-Rate) steganalysis algorithms based on pitch delay have low detection accuracy on samples with short time or low embedding rate, and the model shows fragility under the attack of adversarial samples. To solve this problem, we design an advanced AMR steganalysis method based on adversarial Bi-GRU (Bi-directional Gated Recurrent Unit) and data distillation. First, Gaussian white noise is randomly added to part of the original speech to form adversarial data set, then artificially annotate a small amount of voice to train the model. Second, perform three transformations of 1.5 times speed, 0.5 times speed, and mirror flip on the remaining original voice data, then put them into Bi-GRU for classification, and the final predicted label obtained by the decision fusion corresponds to the original data. All data with the label is put back into the Bi-GRU model for final training at last. What needs to be pointed out is that each batch of final training data includes normal and adversarial samples. This method adopts a semi-supervised learning method, which greatly saves the resources consumed by manual labeling, and introduces adversarial Bi-GRU, which can realize the two-direction analysis of samples for a long time. Based on improving the detection accuracy, the safety and robustness of the model are greatly improved. The experimental results show that for normal and adversarial samples, the algorithm can achieve accuracy of 96.73% and 95.6% respectively. Zhijun Wu 0001 |
IH&MMSec | 1 |
| 2022 | LDoS attack detection method based on traffic classification predictionabstractAbstract Aiming at the low rate and strong concealment of low‐rate Denial of Service (LDoS) attacks, the calculation of traffic Hurst index is combined with traffic classification, and a machine learning LDoS attack detection method based on search sorting is proposed. The method first calculates the segmentation Hurst exponent of each flow, and constructs a traffic similarity matrix as a statistical feature. Then, using the improved model XGBoost of the Gradient Boosting Decision Tree (GBDT), the traffic is classified and predicted. The network angle distinguishes between normal traffic and abnormal Origin‐Destination (OD) flows containing LDoS attacks, thereby achieving the purpose of detecting LDoS attacks. The method in this study was validated using the US public network dataset Abilene. The experimental results show that the global LDoS attack traffic detection method based on the Hurst index and GBDT algorithm achieves better detection results under different attack rates. Liang Liu 0012, Zhijun Wu 0001, Qingbo Pan, Meng Yue 0002 |
IET Inf. Secur. | 3 |
| 2022 | An Incremental Learning Method Based on Dynamic Ensemble RVM for Intrusion DetectionabstractDue to the dynamic changes of network data over time, static intrusion detection systems cannot adapt well to the behavioral characteristics of the input network data, resulting in reduced detection accuracy. In addition, continuous input data streams will bring huge challenges to resource storage and computing costs. Therefore, we propose an intrusion detection method of dynamic ensemble incremental learning (DEIL-RVM), and realize a dynamically adjusted ensemble intrusion detection model. In which a new overall misclassification probability weight value (OMPW) based on incremental set or data chunk is designed as the basis for updating the ensemble model, and it can be used to prune and replace the poor base component in the ensemble model. We presented a probabilistic decision function taking into account the posterior probability of each base RVM model dividing the sample into each category. The RVM with high sparsity is used as the base component to obtain the good balance between the accuracy, robustness and resource consumption, which can sacrifice less time and storage cost in ensemble incremental learning while achieving higher detection accuracy and stability in network data streams. Zhijun Wu 0001, Pan Gao 0009, Lei Cui 0006, Jiusheng Chen |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | Verified CSAC-Based CP-ABE Access Control of Cloud Storage in SWIMabstractAs a wide-ranging distributed system, System Wide Information Management (SWIM) aims to provide an aviation information sharing platform that carries various information systems in the aviation field, so that the business of each subsystem can safely interact. As the data center of SWIM, the cloud storage platform has many functions and services based on third-party platforms. At the same time, it also brings the problem of a third-party trust crisis. In order to effectively verify the trustworthiness of third parties, this paper designs a new verifiable CSAC attribute encryption access control scheme. It introduces the cloud storage administration center (CSAC), and decentralizes multiple sub-authorization centers based on a subset of user attributes. The client uses the verification information provided by multiple sub-authorization centers to combine with the verification algorithm, which is based on the ciphertext access policy attribute encryption algorithm (CP-ABE) and introduces a secret sharing scheme that can identify fraudsters, and client can use this to verify CSAC. The credibility of and the security of key distribution. Compared with the previous solutions, this solution not only effectively solves the problem of the incomplete credibility of third parties, but also improves the efficiency of encryption and decryption, and ensures the security of data interaction in SWIM. Zhijun Wu 0001, Jia Nie |
EUC | 1 |
| 2021 | I-CIFA: An improved collusive interest flooding attack in named data networkingabstractNamed Data Network (NDN) as a new network architecture, in recent years become a hot research, its security has been widespread concern. With the continuous updating of distributed denial of service (DDoS) attack methods in NDN networks, this article designs a new type of attack, called the Improved Collusive Flooding Attack (I-CIFA). I-CIFA attack combines the advantages of mainstream DDoS attack in NDN network, and is an attack method generated by low-rate DDoS attack and the cooperation of collusive producer. On the basis of the existing DDoS attack, the I-CIFA attack further improves the ability to destroy the network and the ability to resist the existing defense scheme. I-CIFA is designed on the basis of CIFA by improving the attack nodes and so on. In addition to redefining and configuring the attack parameters, improvements were also made in two aspects. First, the probing mode to probe the pending interest table (PIT) capacity of the routing nodes was added before attack started. Second, the way in which each attacker requests a packet from the collusive producer in each attack cycle has been further improved. Test results show that I-CIFA can cause 87.5% of the legitimate interest packets in the whole network to be discarded, and it is not only has a strong attack range on the network, but it is also difficult to be detected by existing CIFA-countermeasures. Zhijun Wu 0001, Wenzhi Feng, Jin Lei, Meng Yue 0002 |
J. Inf. Secur. Appl. | 1 |
| 2021 | Coherent Detection of Synchronous Low-Rate DoS AttacksabstractLow-rate denial-of-service (LDoS) attacks are characterized by low average rate and periodicity. Under certain conditions, the high concealment of LDoS attacks enables them to transfer the attack stream to the network without being detected at all before the end. In this article, plenty of LDoS attack traffic is spread to the victim end to detect LDoS attacks. Through experimental analysis, it is found that the attack pulses at the victim end have sequence correlation, so the coherence detection technology in spread spectrum communication is proposed to detect LDoS attacks. Therefore, this paper proposes an attack detection method based on coherent detection, which adopts bivariate cyclic convolution algorithm. Similar to the generation of receiving terminal phase dry detection code in spread spectrum communication, we construct a local detection sequence to complete the extraction of LDoS attack stream from the background traffic of the victim terminal, that is, the coherent detection of LDoS attacks. When predicting the features of an LDoS attack, how to construct the parameters of the detection sequence (such as period, pulse duration, amplitude, and so on) is very important. In this paper, we observe the correlation of LDoS attacks and use coherence detection to detect LDoS attacks. By comparing calculated cross-correlation values with designed double threshold rules, the existence of attacks can be determined. The simulation platform and experiments show that this method has high detection performance. Zhijun Wu 0001, Guang Li 0006, Meng Yue 0002 |
Secur. Commun. Networks | 1 |
| 2021 | Low-High Burst: A Double Potency Varying-RTT Based Full-Buffer Shrew Attack ModelabstractThe full-buffer Shrew (FB-Shrew) denial of service (DoS) attack is a variant of the classic Shrew attack that exploits the congestion control mechanism of transmission control protocol (TCP). Here, an attacker sends a high-rate burst of attack packets only after the router buffer is filled with TCP packets, causing the router to drop legitimate packets, and forcing the retransmission of TCP packets. As such, an FB-Shrew attack can cause maximum damage with minimum resources. In this paper, we challenge an assumption of constant round trip time adopted in the original FB-Shrew model. As a result, this model fails to achieve its expected attack effect. In response, we analyze the TCP congestion window and queue behaviors to develop two low-high burst models for maximizing the potency of the FB-Shrew attack. Model 1 is designed to achieve the attack effect expected of the original model. Then, the attack potency of Model 1 is enhanced by simply adjusting the starting time of the attack burst to form Model 2. Mode 1 only exploits the retransmission timeout (RTO) mechanism. Model 2 takes advantage of both the RTO mechanism and the fast retransmission mechanism. In this way, Model 2 further slows down the growth of the congestion window and extends the attack period. A combination of theoretical analyses and simulations are adopted to first validate the proper functioning and effectiveness of the two models for a standard network configuration, and then we assess their attack performances with variations in different network parameters. Our performance assessment demonstrates that one attack unit of Model 2 damages almost twice the number of TCP units as one attack unit of Model 1, which represents an increase in attack potency of nearly 200 percent. The present study provides an expanded basis to explore FB-Shrew attack patterns that may be utilized by attackers. Moreover, the damage that could be inflicted by such attack and the extent to which defense strategies are capable of mitigating the attack's impact could be assessed more precisely by defenders. Meng Yue 0002, Minxiao Wang, Zhijun Wu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | High-Potency Models of LDoS Attack Against CUBIC + REDabstractA TCP-targeted low-rate denial of service (LDoS) attack exploits the vulnerabilities of TCP congestion control mechanism. The most widely used TCP congestion control algorithm, CUBIC, increases the resilience to LDoS. This paper explores high-potency patterns of LDoS attacks against CUBIC TCP under the RED queue management scenario, and develops two attack models, the D- and S-models to maximize attack potency (i.e., the damage-to-cost ratio). Theoretical analyses and extensive experiments are conducted to validate the proper function of the models and evaluate their performance. Test results show that the models can effectively throttle CUBIC TCP throughput. Under standard-configured network parameters, one attack unit can damage up to about 21 and 26 TCP units for the D- and S-models, respectively, which represents an increase in attack potency about 20%. The attack potencies of our proposed models are at least 250% greater than that of the traditional attack model. In addition, with variations in different network parameters, these two models are still efficient and alternatively maximize the attack potency. Finally, attack countermeasures are outlined. The present study offers a basis to explore new attack manners which may be exploited by attackers and inspires researchers to develop new measurements against such attack. Meng Yue 0002, Jing Li 0103, Zhijun Wu 0001, Minxiao Wang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Mitigation measures of collusive interest flooding attacks in named data networking
Zhijun Wu 0001, Wenzhi Feng, Meng Yue 0002, Xinran Xu, Liang Liu 0012 |
Comput. Secur. | 1 |
| 2019 | A secret classified label control model based on the identity-based cryptographyabstractAiming at the defects of complex certificate management and high waste of resources in the traditional secure electronic file label management system, a secret classified label (SCL) control model was established based on the identity-based cryptography (IBC). In the secure controlling model of SCL, the digital signature method and the hierarchical access method of electronic documents based on the identity-based cryptography are used to digitally sign the confidential labels and encrypt the confidential documents respectively. Through the modeling of confidential clients, file servers, and key generation centers, the irreproachability of file-level identification and the hierarchical access to files are achieved. Finally, the feasibility, practicability and security of the model are verified by testing the system performance and analyzing the system security. Zhijun Wu 0001, Shan Tian, Meng Yue 0002 |
IWCMC | 1 |
| 2019 | Sequence alignment detection of TCP-targeted synchronous low-rate DoS attacks
Zhijun Wu 0001, Qingbo Pan, Meng Yue 0002, Liang Liu 0012 |
Comput. Networks | 1 |
| 2019 | Detecting LDoS attack bursts based on queue distributionabstractLow‐rate denial of service (LDoS) attacks exploit the congestion control mechanism to degrade the network quality of service. As a classic active queue management algorithm, random early detection (RED) algorithm is widely used to avoid network congestion. However, RED is vulnerable to LDoS attacks. LDoS attacks with well‐configured attack parameters force RED queue to fluctuate severely, thereby throttling transmission control protocol (TCP) senders’ sending rate. A feedback control model is proposed to describe the process of the congestion control, by which the congestion window and queue behaviours are analysed combined. After that, a two‐dimensional queue distribution model composed of the instantaneous queue and the average queue is designed to extract the attack feature. Moreover then, a combination of a simple distance‐based approach and an adaptive threshold algorithm is proposed to detect every LDoS attack burst. Test results of network simulator (NS)‐2 simulation and test‐bed experiments indicate that the proposed detection strategy can almost completely detect LDoS attack bursts and is especially robust to legitimate short bursts. Meng Yue 0002, Zhijun Wu 0001 |
IET Inf. Secur. | 2 |
| 2016 | Low-Rate DoS Attacks Detection Based on Network MultifractalabstractLow-rate denial of service (LDoS) attacks send periodic pulse sequences with relative low rate to form aggregation flows at the victim end. LDoS attack flows have the characteristics of low average rate and great concealment. It is hard to detect LDoS attack flows from normal traffic due to low rate property. Network traffic measurement shows that aggregate network traffic is multifractal. In order to characterize and analyze network traffic, researchers have developed concise mathematical models to explore complex multifractal structure. Although the LDoS attack flows are very small, it will inevitably lead to the change of multifractal characteristics of network traffic. This paper targets at exploiting and estimating the changes in multifractal characteristics of network traffic for detecting LDoS attack flows. The algorithm of multifractal detrended fluctuation analysis (MF-DFA) is used to explore the change in terms of multifractal characteristics over a small scale of network traffic due to LDoS attacks. Through wavelet analysis, the singularity and bursty of network traffic under LDoS attacks are estimated by using Hölder exponent. The difference values (D-value) of Hölder exponent of network traffic between normal and under LDoS attack situations are calculated. The D-value is used as the basis to determine LDoS attacks. A detection threshold is set based on the statistical results. The presence of LDoS attacks can be confirmed through comparing D-value with detection threshold. Experiments on detection performance have been performed in the test-bed network and simulation platform. The extensive experimental results are congruent with the theoretical analysis. Zhijun Wu 0001, Liyuan Zhang 0009, Meng Yue 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2015 | The Research on Optimizing Deployment Strategy for Aviation SWIM Application Servers
Zhijun Wu 0001 |
ICIC (3) | 2 |
| 2013 | Chaos-based detection of LDoS attacks
Zhijun Wu 0001, Jin Lei, Sarhan M. Musa |
J. Syst. Softw. | 1 |
| 2012 | Research on Time Synchronization and Flow Aggregation in LDDoS Attack Based on Cross-correlationabstractThis paper addresses time synchronization and flow aggregation in Low-rate Distributed Denial of Service (LDDoS) attack, which is formed by a number of well-organized LDoS attack. A cross-correlation algorithm is proposed to ensure that each distributed attack pulse is aggregated and synchronous accurately to form a powerful pulse at the victim end. Simulation results show that the LDDoS attack effects can be improved significantly by using cross-correlation algorithm to coordinate attack pulses. Zhijun Wu 0001, Meng Yue 0002 |
TrustCom | 1 |
| 2012 | MSABMS-based approach of detecting LDoS attack
Zhijun Wu 0001, Bao-song Pei |
Comput. Secur. | 1 |
| 2007 | An Information-Hiding Model for Secure Communication
Zhijun Wu 0001 |
ICIC (1) | 2 |
| 2007 | Approach to Hide Secret Speech Information in G.721 Scheme
Zhijun Wu 0001 |
ICIC (1) | 2 |
| 2007 | Scheme of Defending Against DDoS Attacks in Large-Scale ISP Networks
Zhijun Wu 0001 |
NPC | 1 |
| 2006 | G.711-Based Adaptive Speech Information Hiding Approach
Zhijun Wu 0001 |
ICIC (1) | 1 |