Peng Zhou 0002

dblp:23/5823-2 · DBLP profile ↗
← Back
19ranked-venue papers
13as first author
6since 2021 · last 2025
0000-0003-4371-6714ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 7 first-author · 4 since 2021Computer networks · 5 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Source identification for worm propagation: A graph neural network approach and evaluation on social network and internet datasets
Qitao Huo, Peng Zhou 0002
Comput. Networks2
2025 TrojanProbe: Fingerprinting Trojan tunnel implementations by actively probing crafted HTTP requests
Liuying Lv, Peng Zhou 0002
Comput. Secur.2
2024 Detecting prototype pollution for node.js: Vulnerability review and new fuzzing inputs
Peng Zhou 0002
Comput. Secur.1
2023 P3 AD: Privacy-Preserved Payload Anomaly Detection for Industrial Internet of Things
abstract
Payload-based anomaly detection (PAD) model is commonly built upon a big data of normal payload samples, and hence is able to discover zero-day attacks and unknown faults without the need of any negative samples in training phase. But such detection model encounters new challenges to adapt well to the emerging Industrial Internet of Things (IIoT). That is, the modern industrial processes are usually running in a very high complexity, resulting the payloads much more complex and diverse. Further, the industrial data is likely too sensitive to be shared in public, and thus induces a new privacy concern. To tackle these challenges, we propose${\mathrm{ P}}^{3}{\mathrm{ AD}}$, a novel privacy-preserved payload-based anomaly detection model for IIoT. The basic idea is to train a two-dimensional convolutional neural network (2D-CNN) based auto-encoder using normal payloads over a federated GAN (Generative Adversarial Network) architecture, and then to detect anomalies by an unexpected dissimilarity between the original payloads and the payloads reconstructed by the auto-encoder. By the 2D-CNN, we can model the normal payloads from both the request and response directions simultaneously, and thus have more opportunities to capture the complex and dynamic industrial behaviors that are possibly reflected in the bi-directional network communications. By the GAN, we can train a more generalized auto-encoder that is able to reconstruct more general payload samples without the need to have them in advance for model training. By the federated architecture, we can remove the need of direct sharing of normal payloads, and learn them indirectly by aggregating local models across different industrial data owners, hence ensuring the payload privacy. We have evaluated${\mathrm{ P}}^{3}{\mathrm{ AD}}$using four public industrial payload datasets as well as considering four typical IIoT PAD scenarios. The detection results achieve more than 0.966 in terms of F1 score for global condition and at least 0.753 for all kinds of federated settings, proving the effectiveness of our${\mathrm{ P}}^{3}{\mathrm{ AD}}$with privacy preserved.
Peng Zhou 0002, Dakui Wu, Minrui Fei
IEEE Trans. Netw. Serv. Manag.1
2021 Modeling social worm propagation for advanced persistent threats
Peng Zhou 0002, Xiaojing Gu, Surya Nepal, Jianying Zhou 0001
Comput. Secur.1
2021 Detecting multi-stage attacks using sequence-to-sequence model
Peng Zhou 0002, Gongyan Zhou, Dakui Wu, Minrui Fei
Comput. Secur.1
2020 Federated Deep Payload Classification for Industrial Internet with Cloud-Edge Architecture
abstract
Payload classification is a kind of powerful deep packet inspection model built on the raw payloads of network traffic, and hence can remove the need of any configuration assumptions for network management and intrusion detection. While in the emerging industrial Internet, a majority of local industry owners are not willing to share their private payloads that possibly contain sensitive information and thus cause the classification model not always well trained due to the lack of sufficient training samples. In this paper, we address this privacy concern and propose a federated learning model for industrial payload classification. In particular, we consider a cloud-edge architecture for the industrial Internet topology, and assemble federated learning process by cloud-edge collaboration: each data owner has his own edge server for learning a local classification model and the industrial cloud takes the responsibility for aggregating local models to a federated one. We adopt a gradient-based deep convolutional neural network model as our local classifier and use the method of weighted gradient averaging for model aggregation. By this way, the data owners can avoid to disclose their private payload for model training, but instead share their local model's gradients to keep the federated model able to learn local samples indirectly. At the end, we have conducted a large set of experiments with real-world industrial Internet traffic datasets, and have successfully confirmed the effectiveness of the proposed federated model for payload classification with privacy-preserved.
Peng Zhou 0002
MSN1
2018 Magic Train: Design of Measurement Methods against Bandwidth Inflation Attacks
abstract
Bandwidth measurement is important for many network applications and services, such as peer-to-peer networks, video caching and anonymity services. To win a bandwidth-based competition for some malicious purpose, adversarial Internet hosts may falsely announce a larger network bandwidth. Some preliminary solutions have been proposed to this problem. They can either evade the bandwidth inflation by a consensus view (i.e., opportunistic bandwidth measurements) or detect bandwidth frauds via forgeable tricks (i.e., detection through bandwidth's CDF symmetry). However, smart adversaries can easily remove the forgeable tricks and report an equally larger bandwidth to avoid the consensus analyses. To defend against the smart bandwidth inflation frauds, we design magic train, a new measurement method which combines an unpredictable packet train with estimated round-trip time (RTT) for detection. The inflation behaviors can be detected through highly contradictory bandwidth results calculated using different magic trains or a train's different segments, or large deviation between the estimated RTT and the RTT reported by the train's first packet. Being an uncooperative measurement method, magic train can be easily deployed on the Internet. We have implemented the magic train using RAW socket and LibPcap, and evaluated the implementation in a controlled testbed and the Internet. The results have successfully confirmed the effectiveness of magic train in detecting and preventing smart bandwidth inflation attacks.
Peng Zhou 0002, Rocky K. C. Chang, Xiaojing Gu, Minrui Fei, Jianying Zhou 0001
IEEE Trans. Dependable Secur. Comput.1
2016 Harvesting File Download Exploits in the Web: A Hacker's View
abstract
File download vulnerability, which exposes web servers' local filesystem to the public, is among the most serious security threats in the web. Exploiting this vulnerability will cause disastrous consequences such as, but not limited to, system intrusion, database intrusion and even the leakage of massive confidential documents. Although the file download vulnerability has been known in the literature for a long time, a comprehensive study of its exploitability in the wild is still lacked. In this paper, we survey the landscape of file download vulnerabilities across different countries and domains, and more importantly, examines their exploitability from a hacker's perspective. We have successfully revealed the weak protection of this vulnerability in today's web, as well as confirmed its wide exploitability. To demonstrate the serious consequences, we present two real-world intrusion case studies. One is a system intrusion against a Chinese government website, and the other is a database intrusion targeted to a Chinese industrial service. Our intrusion cases have been confirmed as severe security events by CNCERT (an official security agency in China). At the end, we explore the root cause of this weak protection by analyzing the perils and pitfalls of existing defending solutions, and thereby propose a new enhancement. The basic idea is to deploy a mandatory access control mechanism in the server-side script engine kernel, so as to isolate the files managed by the web server from the local filesystem. We have implemented security-enhanced PHP (i.e. SEPHP), a prototype of our new solution by modifying the source code of PHP5 script engine, and also evaluated the performance overhead induced by SEPHP in a real-world web setting.
Peng Zhou 0002, Xiaojing Gu, Rocky K. C. Chang
Comput. J.1
2016 HTTPAS: active authentication against HTTPS man-in-the-middle attacks
abstract
Hypertext transfer protocol secure (HTTPS) relies on a group of pre‐trusted certificate authorities (CAs) for authentication and hence can avoid man‐in‐the‐middle attacks. However unfortunately, this authentication architecture can be completely subverted in case any one (usually the weakest one) of CAs has been compromised. To tackle this critical flaw, pioneer works such as notary‐based systems and pre‐shared secrets have been proposed. These state‐of‐the‐art techniques can neither seek maximal protection from available CAs nor resist potential man‐in‐the‐middle variants. In this study, the authors propose HTTPAS, a new HTTP Active Secure framework that can enhance the HTTPS authentication against man‐in‐the‐middle attacks by actively utilising available CAs and exploiting Internet path diversity as much as possible. In particular, HTTPAS is designed with four practical solutions, each of which can make a unique trade‐off among authentication capability, deployment difficulty and efficiency. They have implemented HTTPAS using the open secure sockets layer (SSL) suite, and also evaluated the implementation through experiments on several public certificate data sets and the Internet. Their results have successfully confirmed the authentication effectiveness of HTTPAS with only a few performance overheads and moderate deployment effort.
Peng Zhou 0002, Xiaojing Gu
IET Commun.1
2015 A priori trust inference with context-aware stereotypical deep learning
Peng Zhou 0002, Xiaojing Gu, Jie Zhang 0002, Minrui Fei
Knowl. Based Syst.1
2015 Toward Energy-Efficient Trust System Through Watchdog Optimization for WSNs
abstract
Watchdog technique is a fundamental building block to many trust systems that are designed for securing wireless sensor networks (WSNs). Unfortunately, this kind of technique consumes much energy and hence largely limits the lifespan of WSN. Although the state-of-the-art studies have realized the importance of trust systems' efficiency in WSNs and proposed several preliminary solutions, they have overlooked to optimize the watchdog technique, which is perhaps among the top energy-consuming units. In this paper, we reveal the inefficient use of watchdog technique in existing trust systems, and thereby propose a suite of optimization methods to minimize the energy cost of watchdog usage, while keeping the system's security in a sufficient level. Our contributions consist of theoretical analyses and practical algorithms, which can efficiently and effectively schedule the watchdog tasks depending on the sensor nodes' locations and the target nodes' trustworthiness. We have evaluated our algorithms through experiments on top of a WSNET simulation platform and an in-door WSN testbed in our collaborative lab. The results have successfully confirmed that our watchdog optimization techniques can save at least 39.44% energy without sacrificing much security (<;0.06 in terms of trust accuracy and robustness), even in some cases enhance the protection against certain attacks.
Peng Zhou 0002, Siwei Jiang, Athirai Aravazhi Irissappane, Jie Zhang 0002, Jianying Zhou 0001, Joseph Chee Ming Teo
IEEE Trans. Inf. Forensics Secur.1
2013 SGor: Trust graph based onion routing
Peng Zhou 0002, Xiapu Luo, Ang Chen 0001, Rocky K. C. Chang
Comput. Networks1
2013 Inference attacks against trust-based onion routing: Trust degree to the rescue
Peng Zhou 0002, Xiapu Luo, Rocky K. C. Chang
Comput. Secur.1
2012 More Anonymity through Trust Degree in Trust-Based Onion Routing
Peng Zhou 0002, Xiapu Luo, Rocky K. C. Chang
SecureComm1
2012 Robust Network Covert Communications Based on TCP and Enumerative Combinatorics
abstract
The problem of communicating covertly over the Internet has recently received considerable attention from both industry and academic communities. However, the previously proposed network covert channels are plagued by their unreliability and very low data rate. In this paper, we show through a new class of timing channels coined as Cloak that it is possible to devise a 100 percent reliable covert channel and yet offer a much higher data rate (up to an order of magnitude) than the existing timing channels. Cloak is novel in several aspects. First, Cloak uses the different combinations of N packets sent over X flows in each round to represent a message. The combinatorial nature of the encoding methods increases the channel capacity largely with (N,X). Second, based on the well-known 12-fold Way, Cloak offers 10 different encoding and decoding methods, each of which has a unique tradeoff among several important considerations, such as channel capacity and camouflage capability. Third, the packet transmissions modulated by Cloak can be carefully crafted to mimic normal TCP flows for evading detection. We have implemented Cloak and evaluated it in the PlanetLab and a controlled testbed. The results show that it is not uncommon for Cloak to have an order of channel goodput improvement over the IP Timing channel and JitterBug. Moreover, Cloak does not suffer from any message loss under various loss and reordering scenarios.
Xiapu Luo, Edmond W. W. Chan, Peng Zhou 0002, Rocky K. C. Chang
IEEE Trans. Dependable Secur. Comput.3
2011 Exposing invisible timing-based traffic watermarks with BACKLIT
abstract
Traffic watermarking is an important element in many network security and privacy applications, such as tracing botnet C&C communications and deanonymizing peer-to-peer VoIP calls. The state-of-the-art traffic watermarking schemes are usually based on packet timing information and they are notoriously difficult to detect. In this paper, we show for the first time that even the most sophisticated timing-based watermarking schemes (e.g., RAINBOW and SWIRL) are not invisible by proposing a new detection system called BACKLIT. BACKLIT is designed according to the observation that any practical timing-based traffic watermark will cause noticeable alterations in the intrinsic timing features typical of TCP flows. We propose five metrics that are sufficient for detecting four state-of-the-art traffic watermarks for bulk transfer and interactive traffic. BACKLIT can be easily deployed in stepping stones and anonymity networks (e.g., Tor), because it does not rely on strong assumptions and can be realized in an active or passive mode. We have conducted extensive experiments to evaluate BACKLIT's detection performance using the PlanetLab platform. The results show that BACKLIT can detect watermarked network flows with high accuracy and few false positives.
Xiapu Luo, Peng Zhou 0002, Junjie Zhang 0004, Roberto Perdisci, Wenke Lee, Rocky K. C. Chang
ACSAC2
2011 A combinatorial approach to network covert communications with applications in Web Leaks
abstract
Various effective network covert channels have recently demonstrated the feasibility of encoding messages into the timing or content of individual network objects, such as data packets and request messages. However, we show in this paper that more robust and stealthy network covert channels can be devised by exploiting the relationship of the network objects. In particular, we propose a combinatorial approach for devising a wide spectrum of covert channels which can meet different objectives based on the channel capacity and channel undetectability. To illustrate the approach, we design WebLeaks and ACKLeaks, two novel covert channels which can leak information through the data and acknowledgment traffic in a web session. We implement both channels and deploy them on the PlanetLab nodes for evaluation. Besides the channel capacity, we apply the state-of-the-art detection schemes to evaluate their camouflage capability. The experiment results show that their capacity can be boosted up by our combinatorial approach, and at the same time they can effectively evade the detection.
Xiapu Luo, Peng Zhou 0002, Edmond W. W. Chan, Rocky K. C. Chang, Wenke Lee
DSN2
2011 HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows
Xiapu Luo, Peng Zhou 0002, Edmond W. W. Chan, Wenke Lee, Rocky K. C. Chang, Roberto Perdisci
NDSS2