Feng Cheng 0002

dblp:24/1795 · DBLP profile ↗
← Back
59ranked-venue papers
9as first author
12since 2021 · last 2026
0000-0002-7420-3703ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 28 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 5 since 2021Computer networks · 6 · 1 first-author · 1 since 2021Systems, architecture and hardware · 5Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications
abstract
Natural language interfaces to structured databases are becoming increasingly common, largely due to advances in large language models (LLMs) that enable users to query data using conversational input rather than formal query languages such as SQL. While this paradigm significantly improves usability and accessibility, it introduces new security risks, particularly the amplification of SQL injection vulnerabilities through the prompt-to-SQL translation process. Malicious users can exploit these mechanisms by crafting adversarial prompts that manipulate model behavior and generate unsafe queries. In this work, we propose a multi-layered security framework designed to detect and mitigate LLM-mediated SQL injection attacks. The framework integrates a front-end security shield for prompt sanitization, an advanced threat detection model for behavioral and semantic anomaly identification, and a signature-based control layer for known attack patterns. We evaluate the proposed framework under diverse and realistic attack scenarios, including prompt injection, obfuscated SQL payloads, and context-manipulation attacks. To ensure robustness, we generate and curate a comprehensive benchmark dataset of adversarial prompts and assess performance across a fine-tuned LLM configuration. Experimental results demonstrate that the proposed approach achieves high detection accuracy while maintaining low false-positive rates, significantly improving the secure deployment of LLM-powered database applications.
Farzad Nourmohammadzadeh Motlagh, Mehrdad Hajizadeh, Mehryar Majd, Pejman Najafi, Feng Cheng 0002, Christoph Meinel
ICAART (2)5
2025 Large Language Models in Cybersecurity: State-of-the-Art
Farzad Nourmohammadzadeh Motlagh, Mehrdad Hajizadeh, Mehryar Majd, Pejman Najafi, Feng Cheng 0002, Christoph Meinel
ICISSP (2)5
2024 HEOD: Human-assisted Ensemble Outlier Detection for cybersecurity
Pejman Najafi, Feng Cheng 0002, Christoph Meinel
Comput. Secur.2
2024 You are your friends: Detecting malware via guilt-by-association and exempt-by-reputation
Pejman Najafi, Wenzel Pünter, Feng Cheng 0002, Christoph Meinel
Comput. Secur.3
2023 A fine-grained modal label-based multi-stage network for multimodal sentiment analysis
Ting Wu 0005, Feng Cheng 0002, Shuhua Tan, Fen Yi, Yansong Huang
Expert Syst. Appl.4
2023 A Region Group Adaptive Attention Model For Subtle Expression Recognition
abstract
Facial expression recognition has received extensive attention in recent years due to its important applications in many fields. Most expression samples used in research are relatively easy to analyze emotions because they have explicit expressions with strong intensities. However, in situations such as video question and answer, business negotiation, polygraph detection in the security field, autism treatment and medical escort, emotions are expressed in suppressed manners with low intensive expression or subtle expressions, making it difficult to estimate emotions accurately. In these situations, how to effectively extract expression features from facial expression images is a critical problem that affects the accuracy of subtle expression recognition. To address this problem, we propose an end-to-end group adaptive attention model for subtle expression recognition. Cropping an image into several regions of interest (ROI) according to the correlations between facial skeleton and emotions, the proposed model analyses the relationship among regions of interest, and mutual relations between local regions and the holistic region. Using the region group adaptive attention mechanism, the model effectively trains the convolutional neural network to efficiently extract facial expressions representing features and increases the accuracy and robustness of the recognition, particularly in some subtle facial expression circumstances. To improve the ability of different regional features to discriminate expressions, a group adaptive loss function is introduced to verify and improve estimation accuracy. Extensive experiments are conducted on the existing public face datasets CK+, JAFFE, KDEF and the self-collected subtle expression dataset SFER. Results show that the proposed model achieves accuracies of 99.59%, 95.20%, and 93.47% with datasets CK+, JAFFE, and KDEF, respectively. The proposed model thus generally achieves better performance in facial expression recognition than other methods.
Gan Chen, Kanrun Huang, Feng Cheng 0002, Yansong Huang
IEEE Trans. Affect. Comput.5
2023 Short Text Classification of Chinese with Label Information Assisting
abstract
As a common language form in oral communication, short text is hard to be used in the applications such as intent understanding, text classification and so on due to its limited content and information, as well as irregular expression and missing components. To increase the availability of short texts in real applications, we propose a Label Information Assisting-based Model (LIAM) for Chinese short text classification. In the model, we jointly use sentence-level features and word-level features to reduce text information loss. And the sentence-level features are fused with relevant label information by the Label Information Extending and Fusion (LIEF) module while the word-level features are also enhanced with assistance of relevant label information. By utilizing the text-related information from labels as extended information, the model enriches and enhances the features of short text, benefiting classification. To verify the correctness and effectiveness of the proposed method, we conduct extensive experiments on four Chinese datasets and six sub-datasets with different models. The experimental results show that LIAM presented can effectively enrich information for text and much improve the performance of short text classification. It performs much better than other methods do. What is more, the less the training set, the greater the advantages of the model.
Qianqian Xu 0003, Cangzhi Zheng, Shuhua Tan, Fen Yi, Feng Cheng 0002
ACM Trans. Asian Low Resour. Lang. Inf. Process.6
2022 A Comprehensive Review of Anomaly Detection in Web Logs
abstract
Anomaly detection is a significant problem that has been researched within diverse research areas and application domains, especially in the area of web-based internet services or cybersecurity. Many anomaly detection techniques have been developed for specific application domains, while others are more generic. The Log files of Web-server give insight into the state of web-server and applications running on it and enable the detection of abnormal incidents or behavior. This paper focuses on particularly web-server HTTP logs to the problems of Web-server Log Anomaly Detection (WLAD) due to their own nature and features and aims to provide a brief review of different Data-driven techniques to get to the bottom of recent studies and developments made in the context of WLAD. Moreover, in this paper, the literature related to webserver logs analysis, as well as other closely related to the WLAD topic, are taken into consideration for review. We have classified existing techniques into different categories based on the underlying approach adopted. When applying a particular technique, these assumptions can be used as guidelines to assess the method’s effectiveness in this area. We also provide a basic security anomaly detection approach for each category and compare the existing methods as variants of the basic technique. Further, we identify the cons and pros of the current practices for each category. We also discuss the computational complexity of the methods, which is an essential issue in the domain of Big Data.
Mehryar Majd, Pejman Najafi, Seyed Ali Alhosseini, Feng Cheng 0002, Christoph Meinel
BDCAT4
2021 A Feasibility Study of Log-Based Monitoring for Multi-cloud Storage Systems
Muhammad I. H. Sukmana, Justus Cöster, Wenzel Pünter, Kennedy Torkura, Feng Cheng 0002, Christoph Meinel
AINA (2)5
2021 NLP-based Entity Behavior Analytics for Malware Detection
abstract
In this research, we formulate malware detection as a large-scale data-mining problem within Security Information and Event Management (SIEM) systems. We hypothesize that behavioral analysis of executable/process activities, such as file reads/writes, process creations, network connections, or registry modifications, enables the detection of advanced stealthy malware. To achieve this detection, we model processes behaviors as a set of directed acyclic graph streams and identify outliers in the set of graph streams. We enable this detection by conversion of the behavioral graph streams into documents, embedding using state-of-the-art Natural Language Processing model, and eventually performing novel outlier detection on the high dimensional vector representation of the documents. We evaluate our approach in a real-world setting, next to the SIEM system of a large-scale international enterprise (over 3TB of EDR logs). The proposed method has shown the capability to detect previously unknown threats.
Pejman Najafi, Daniel Köhler, Feng Cheng 0002, Christoph Meinel
IPCCC3
2021 SIEMA: Bringing Advanced Analytics to Legacy Security Information and Event Management
Pejman Najafi, Feng Cheng 0002, Christoph Meinel
SecureComm (1)2
2021 Continuous auditing and threat detection in multi-cloud infrastructure
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
Comput. Secur.3
2020 A Brokerage Approach for Secure Multi-Cloud Storage Resource Management
Muhammad I. H. Sukmana, Kennedy Torkura, Sezi Dwi Sagarianti Prasetyo, Feng Cheng 0002, Christoph Meinel
SecureComm (2)4
2019 MalRank: a measure of maliciousness in SIEM-based knowledge graphs
abstract
In this paper, we formulate threat detection in SIEM environments as a large-scale graph inference problem. We introduce a SIEM-based knowledge graph which models global associations among entities observed in proxy and DNS logs, enriched with related open source intelligence (OSINT) and cyber threat intelligence (CTI). Next, we propose MalRank, a graph-based inference algorithm designed to infer a node maliciousness score based on its associations to other entities presented in the knowledge graph, e.g., shared IP ranges or name servers.
Pejman Najafi, Alexander Mühle, Wenzel Pünter, Feng Cheng 0002, Christoph Meinel
ACSAC4
2019 Supporting Internet-Based Location for Location-Based Access Control in Enterprise Cloud Storage Solution
Muhammad I. H. Sukmana, Kennedy Torkura, Hendrik Graupner, Ankit Chauhan, Feng Cheng 0002, Christoph Meinel
AINA5
2019 The (Persistent) Threat of Weak Passwords: Implementation of a Semi-automatic Password-Cracking Algorithm
Chris Pelchen, David Jaeger, Feng Cheng 0002, Christoph Meinel
ISPEC3
2019 SlingShot - Automated Threat Detection and Incident Response in Multi Cloud Storage Systems
abstract
Cyber-attacks against cloud storage infrastructure e.g. Amazon S3 and Google Cloud Storage, have increased in recent years. One reason for this development is the rising adoption of cloud storage for various purposes. Robust counter-measures are therefore required to tackle these attacks especially as traditional techniques are not appropriate for the evolving attacks. We propose a two-pronged approach to address these challenges in this paper. The first approach involves dynamic snapshotting and recovery strategies to detect and partially neutralize security events. The second approach builds on the initial step by automatically correlating the generated alerts with cloud event log, to extract actionable intelligence for incident response. Thus, malicious activities are investigated, identified and eliminated. This approach is implemented in SlingShot, a cloud threat detection and incident response system which extends our earlier work - CSBAuditor, which implements the first step. The proposed techniques work together in near real time to mitigate the aforementioned security issues on Amazon Web Services (AWS) and Google Cloud Platform (GCP). We evaluated our techniques using real cloud attacks implemented with static and dynamic methods. The average Mean Time to Detect is 30 seconds for both providers, while the Mean Time to Respond is 25 minutes and 90 minutes for AWS and GCP respectively. Thus, our proposal effectively tackles contemporary cloud attacks.
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
NCA3
2019 Security Chaos Engineering for Cloud Services: Work In Progress
abstract
The majority of security breaches in cloud infrastructure in recent years are caused by human errors and misconfigured resources. Novel security models are imperative to overcome these issues. Such models must be customer-centric, continuous, not focused on traditional security paradigms like intrusion detection and adopt proactive techniques. Thus, this paper proposes CloudStrike, a cloud security system that implements the principles of Chaos Engineering to enable the aforementioned properties. Chaos Engineering is an emerging discipline employed to prevent non-security failures in cloud infrastructure via Fault Injection Testing techniques. CloudStrike employs similar techniques with a focus on injecting failures that impact security i.e. integrity, confidentiality and availability. Essentially, CloudStrike leverages the relationship between dependability and security models. Preliminary experiments provide insightful and prospective results.
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
NCA3
2018 Securing Cloud Storage Brokerage Systems Through Threat Models
abstract
Cloud storage brokerage is an abstraction aimed at providing value-added services. However, Cloud Service Brokers are challenged by several security issues including enlarged attack surfaces due to integration of disparate components and API interoperability issues. Therefore, appropriate security risk assessment methods are required to identify and evaluate these security issues, and examine the efficiency of countermeasures. A possible approach for satisfying these requirements is employment of threat modeling concepts, which have been successfully applied in traditional paradigms. In this work, we employ threat models including attack trees, attack graphs and Data Flow Diagrams against a Cloud Service Broker (CloudRAID) and analyze these security threats and risks. Furthermore, we propose an innovative technique for combining Common Vulnerability Scoring System (CVSS) and Common Configuration Scoring System (CCSS) base scores in probabilistic attack graphs to cater for configuration-based vulnerabilities which are typically leveraged for attacking cloud storage systems. This approach is necessary since existing schemes do not provide sufficient security metrics, which are imperatives for comprehensive risk assessments. We demonstrate the efficiency of our proposal by devising CCSS base scores for two common attacks against cloud storage: Cloud Storage Enumeration Attack and Cloud Storage Exploitation Attack. These metrics are then used in Attack Graph Metric-based risk assessment. Our experimental evaluation shows that our approach caters for the aforementioned gaps and provides efficient security hardening options. Therefore, our proposals can be employed to improve cloud security.
Kennedy Torkura, Muhammad I. H. Sukmana, Michael Meinig, Anne V. D. M. Kayem, Feng Cheng 0002, Hendrik Graupner, Christoph Meinel
AINA5
2018 A Virtual Machine Dynamic Adjustment Strategy Based on Load Forecasting
Yingtao Wang, Gan Chen, Lujin You, Feng Cheng 0002, Weiqiang Lv
ICA3PP (2)5
2018 CSBAuditor: Proactive Security Risk Analysis for Cloud Storage Broker Systems
abstract
Cloud Storage Brokers (CSB) provide seamless and concurrent access to multiple Cloud Storage Services (CSS) while abstracting cloud complexities from end-users. However, this multi-cloud strategy faces several security challenges including enlarged attack surfaces, malicious insider threats, security complexities due to integration of disparate components and API interoperability issues. Novel security approaches are imperative to tackle these security issues. Therefore, this paper proposes CS-BAuditor, a novel cloud security system that continuously audits CSB resources, to detect malicious activities and unauthorized changes e.g. bucket policy misconfigurations, and remediates these anomalies. The cloud state is maintained via a continuous snapshotting mechanism thereby ensuring fault tolerance. We adopt the principles of chaos engineering by integrating BrokerMonkey, a component that continuously injects failure into our reference CSB system, CloudRAID. Hence, CSBAuditor is continuously tested for efficiency i.e. its ability to detect the changes injected by BrokerMonkey. CSBAuditor employs security metrics for risk analysis by computing severity scores for detected vulnerabilities using the Common Configuration Scoring System, thereby overcoming the limitation of insufficient security metrics in existing cloud auditing schemes. CSBAuditor has been tested using various strategies including chaos engineering failure injection strategies. Our experimental evaluation validates the efficiency of our approach against the aforementioned security issues with a detection and recovery rate of over 96 %.
Kennedy Torkura, Muhammad I. H. Sukmana, Tim Strauss, Hendrik Graupner, Feng Cheng 0002, Christoph Meinel
NCA5
2018 A threat modeling approach for cloud storage brokerage and file sharing systems
abstract
Cloud storage brokerage systems abstract cloud storage complexities by mediating technical and business relationships between cloud stakeholders, while providing value-added services. This however raises security challenges pertaining to the integration of disparate components with sometimes conflicting security policies and architectural complexities. Assessing the security risks of these challenges is therefore important for Cloud Storage Brokers (CSBs). In this paper, we present a threat modeling schema to analyze and identify threats and risks in cloud brokerage brokerage systems. Our threat modeling schema works by generating attack trees, attack graphs, and data flow diagrams that represent the interconnections between identified security risks. Our proof-of-concept implementation employs the Common Configuration Scoring System (CCSS) to support the threat modeling schema, since current schemes lack sufficient security metrics which are imperatives for comprehensive risk assessments. We demonstrate the efficiency of our proposal by devising CCSS base scores for two attacks commonly launched against cloud storage systems: Cloud sStorage Enumeration Attack and Cloud Storage Exploitation Attack. These metrics are then combined with CVSS based metrics to assign probabilities in an Attack Tree. Thus, we show the possibility combining CVSS and CCSS for comprehensive threat modeling, and also show that our schemas can be used to improve cloud security.
Kennedy Torkura, Muhammad I. H. Sukmana, Michael Meinig, Feng Cheng 0002, Christoph Meinel, Hendrik Graupner
NOMS4
2018 CAVAS: Neutralizing Application and Container Security Vulnerabilities in the Cloud Native Era
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
SecureComm (1)3
2018 Weight-based strategy for an I/O-intensive application at a cloud data center
abstract
Summary Applications with different characteristics in the cloud may have different resources preferences. However, traditional resource allocation and scheduling strategies rarely take into account the characteristics of applications. Considering that an I/O‐intensive application is a typical type of application and that frequent I/O accesses, especially small files randomly accessing the disk, may lead to an inefficient use of resources and reduce the quality of service (QoS) of applications, a weight allocation strategy is proposed based on the available resources that a physical server can provide as well as the characteristics of the applications. Using the weight obtained, a resource allocation and scheduling strategy is presented based on the specific application characteristics in the data center. Extensive experiments show that the strategy is correct and can guarantee a high concurrency of I/O per second (IOPS) in a cloud data center with high QoS. Additionally, the strategy can efficiently improve the utilization of the disk and resources of the data center without affecting the service quality of applications.
Danxu Liu, Yingtao Wang, Feng Cheng 0002
Concurr. Comput. Pract. Exp.5
2017 Automatic Vulnerability Classification Using Machine Learning
Marian Gawron, Feng Cheng 0002, Christoph Meinel
CRiSIS2
2017 Identifying Suspicious User Behavior with Neural Networks
abstract
The number of attacks that use sophisticated and complex methods increased lately. The main objective of these attacks is to largely infiltrate the target network and to stay undetected. Therefore, the attackers often use valid credentials and standard administrative tools to hide between legitimate user actions and to hinder detection. Most existing security systems, which use standard signature-based or anomaly-based approaches, are not able to identify this type of malicious activities. Furthermore, it is also most often not feasible to analyze user behavior manually, due to the complexity of this task and the high amount of different user actions. Thus, it is necessary to develop new automated approaches to identify suspicious user behavior. In this paper, we propose to use neural networks to analyze user behavior and to identify suspicious actions. Due to the fact that neural networks require suitable datasets to learn the difference between suspicious and benign actions, we describe a behavioral simulation system to generate reasonable datasets. These datasets use different behavioral features to describe log-on and log-off activities of users. To identify suitable neural network models for user behavior analysis, we evaluate and compare 16,275 different feed-forward neural networks with three different datasets and 75 recurrent neural networks with one dataset. The results show that the used dataset and the complexity of a model are crucial to achieve a high accuracy. Appropriate models, which also consider context behavior information, are able to automatically classify before unseen user actions with an accuracy of up to 98 %.
Martin Ussath, David Jaeger, Feng Cheng 0002, Christoph Meinel
CSCloud3
2017 Guilt-by-Association: Detecting Malicious Entities via Graph Mining
Pejman Najafi, Andrey Sapegin, Feng Cheng 0002, Christoph Meinel
SecureComm3
2017 Towards a system for complex analysis of security events in large-scale networks
Andrey Sapegin, David Jaeger, Feng Cheng 0002, Christoph Meinel
Comput. Secur.3
2017 Evaluation of in-memory storage engine for machine learning analysis of security events
abstract
Summary Modern security information and event management systems should be capable to store and process high amount of events or log messages in different formats and from different sources. This requirement often prevents such systems from usage of computational heavy algorithms for security analysis. To deal with this issue, we built our system based on an in‐memory database with an integrated machine learning library, namely, SAP HANA. Three approaches, that is, (1) deep normalisation of log messages, (2) storing data in the main memory and (3) running data analysis directly in the database, allow us to increase processing speed in such a way that machine learning analysis of security events becomes possible nearly in real time. Besides that, we developed a universal anomaly detection algorithm, which uses vector space model to represent and cluster textual log messages. Together with deep normalisation approach, this algorithm solves the problem of correlation for heterogenous security events containing many text fields. To prove our concepts, we measured the processing speed for the developed system on the data generated using Active Directory testbed, compared it with classical system architecture based on PostgreSQL database and showed the efficiency of our approach for high‐speed analysis of security events. Copyright © 2016 John Wiley & Sons, Ltd.
Andrey Sapegin, Marian Gawron, David Jaeger, Feng Cheng 0002, Christoph Meinel
Concurr. Comput. Pract. Exp.4
2016 Towards Better Attack Path Visualizations Based on Deep Normalization of Host/Network IDS Alerts
abstract
Mitigation techniques employed by attackers has meant that traditional Network Intrusion Detection Systems (NIDS) are no longer able to reliably protect a network in the face of ever more sophisticated attacks. Security Information and Event Management (SIEM) systems monitor network systems by analyzing the logs they produce. In this paper, we propose a method of visualizing attacks by aggregating, normalizing and analyzing alerts raised by SIEM-based IDS (SIDS) systems as well as NIDS systems in real-time. We present the results of our proposed visualization technique when applied to different attack scenarios. In many cases, our approach allows for the path an attacker takes during their attack to be visualized.
Amir Azodi, Feng Cheng 0002, Christoph Meinel
AINA2
2016 Event attribute tainting: A new approach for attack tracing and event correlation
abstract
The number of revealed and analyzed attacks that use sophisticated and complex methods increased lately. Through the usage of such methods the attackers are able to evade existing security systems and prevent a comprehensive detection of the malicious activities. Therefore, it is often necessary to perform a manual investigation of complex attacks, to identify all steps and malicious activities that belong to an attack. One main objective of an investigation is to correlate existing events and reveal relations between different activities, to get a comprehensive overview of the attack. Due to the fact that the correlation is often done manually, this process is complex and time consuming. In this paper, we propose a new automated correlation approach that uses the tainting concept to identify related log events. The approach uses meaningful attributes as taint sources and a taint policy to propagate the taint to related events. For the identification of the correlations, it is also possible to use meta-information sources to support the correlation process. Furthermore, the tainting based approach allows to visualize the correlation results in a taint graph, which simplifies the traceability. We successfully evaluated the proposed approach with log events from a simulated attack where real world attack methods and tools were used. With the new approach it was possible to identify all events that recorded the malicious activities of the attacker and the created taint graph allowed a comprehensive retracing of the attack. Thus, the correlation approach can support investigations in an effective way, because it reduces the complexity of event correlation and the needed time.
Martin Ussath, Feng Cheng 0002, Christoph Meinel
NOMS2
2016 Insights into Encrypted Network Connections: Analyzing Remote Desktop Protocol Traffic
abstract
An increasing number of network connections are encrypted to protect the confidentiality of the transferred data. Also attackers make greater use of encrypted protocols to hide from detection and to hinder investigations. Currently, most security systems (e.g., Intrusion Detection Systems (IDSs) and firewalls) cannot effectively analyze encrypted traffic. This results in "blind spots", which can put the security of a whole environment at risk. In this paper, we propose a system that is capable of investigating encrypted Remote Desktop Protocol (RDP) connections. In the first step the private RSA key of the RDP server is used to decrypt the TLS/SSL layer of the RDP stream. In the second step our system extracts all relevant information (e.g., keystrokes and transferred files) from the RDP connection. This information makes it possible to reconstruct the behavior and the activities of an attacker with a high accuracy. For the evaluation of our approach we performed a scan of 231,025 internet facing RDP systems and revealed that over 95 % of the RDP connections to these systems can be decrypted with our system.
Martin Ussath, Feng Cheng 0002, Christoph Meinel
PDP2
2015 Automatic detection of vulnerabilities for advanced security analytics
abstract
The detection of vulnerabilities in computer systems and computer networks as well as the weakness analysis are crucial problems. The presented method tackles the problem with an automated detection. For identifying vulnerabilities the approach uses a logical representation of preconditions and postconditions of vulnerabilities. The conditional structure simulates requirements and impacts of each vulnerability. Thus an automated analytical function could detect security leaks on a target system based on this logical format. With this method it is possible to scan a system without much expertise, since the automated or computer-aided vulnerability detection does not require special knowledge about the target system. The gathered information is used to provide security advisories and enhanced diagnostics which could also detect attacks that exploit multiple vulnerabilities of the system.
Marian Gawron, Feng Cheng 0002, Christoph Meinel
APNOMS2
2015 Multi-step Attack Pattern Detection on Normalized Event Logs
abstract
Looking at recent cyber-attacks in the news, a growing complexity and sophistication of attack techniques can be observed. Many of these attacks are performed in multiple steps to reach the core of the targeted network. Existing signature detection solutions are focused on the detection of a single step of an attack, but they do not see the big picture. Furthermore, current signature languages cannot integrate valuable external threat intelligence, which would simplify the creation of complex signatures and enables the detection of malicious activities seen by other targets. We extend an existing multi-step signature language to support attack detection on normalized log events, which were collected from various applications and devices. Additionally, the extended language supports the integration of external threat intelligence and allows us to reference current threat indicators. With this approach, we can create generic signatures that stay up-to-date. Using our language, we could detect various login brute-force attempts on multiple applications with only one generic signature.
David Jaeger, Martin Ussath, Feng Cheng 0002, Christoph Meinel
CSCloud3
2015 Parallel and distributed normalization of security events for instant attack analysis
abstract
When looking at media reports nowadays, major security breaches of big companies and governments seem to be a normal situation. An important step for the investigation or even prevention of these breaches is to normalize and analyze security-related log events from various systems in the target network. However, the number of log events produced in big IT landscapes can grow up to multiple billions per day. Current log management solutions, e.g., Security Information and Event Management (SIEM), cannot even closely normalize such huge amounts of data and therefore disable the tracking of attacks in real-time, which means that the log data remains unusable for attack analysis. In this paper, we present an approach to fully normalize event logs in high-speed by making use of established high-performance inter-thread messaging in conjunction with a hierarchical knowledge-base of log formats and parallel processing on multiple low-end systems. Using our approach, we are able to process more than 250,000 events/sec on relatively low-profile machines and can therefore easily handle more than 20 billion events/day, which is enough to handle average and peek loads of log events from big enterprise networks.
David Jaeger, Andrey Sapegin, Martin Ussath, Feng Cheng 0002, Christoph Meinel
IPCCC4
2015 High-Speed Security Analytics Powered by In-Memory Machine Learning Engine
abstract
Modern Security Information and Event Management systems should be capable to store and process high amount of events or log messages in different formats and from different sources. This requirement often prevents such systems from usage of computational-heavy algorithms for security analysis. To deal with this issue, we built our system based on an in-memory data base with an integrated machine learning library, namely SAP HANA. Three approaches, i.e. (1) deep normalisation of log messages (2) storing data in the main memory and (3) running data analysis directly in the database, allow us to increase processing speed in such a way, that machine learning analysis of security events becomes possible nearly in real-time. To prove our concepts, we measured the processing speed for the developed system on the data generated using Active Directory tested and showed the efficiency of our approach for high-speed analysis of security events.
Andrey Sapegin, Marian Gawron, David Jaeger, Feng Cheng 0002, Christoph Meinel
ISPDC4
2015 Simulation user behavior on a security testbed using user behavior states graph
abstract
For testing new methods of network security or new algorithms of security analytics, we need the experimental environments as well as the testing data which are much as possible similar to the real-world data. Therefore, the researchers are always trying to find the best approaches and recommendations of creating and simulating testbeds, because the issue of automation of the testbed creation is a crucial goal to accelerate research progress. One of the ways to generate data is simulate the user behavior on the virtual machines, but the challenge is how to describe what we want to simulate.
Aragats Amirkhanyan, Andrey Sapegin, Marian Gawron, Feng Cheng 0002, Christoph Meinel
SIN4
2015 Automatic vulnerability detection for weakness visualization and advisory creation
abstract
The detection of vulnerabilities in computer systems and computer networks as well as the representation of the results are crucial problems. The presented method tackles the problem with an automated detection and an intuitive representation. For detecting vulnerabilities the approach uses a logical representation of preconditions and postconditions of vulnerabilities. Thus an automated analytical function could detect security leaks on a target system. The gathered information is used to provide security advisories and enhanced diagnostics for the system. Additionally the conditional structure allows us to create attack graphs to visualize the network structure and the integrated vulnerability information. Finally we propose methods to resolve the identified weaknesses whether to remove or update vulnerable applications and secure the target system. This advisories are created automatically and provide possible solutions for the security risks.
Marian Gawron, Aragats Amirkhanyan, Feng Cheng 0002, Christoph Meinel
SIN3
2015 Normalizing Security Events with a Hierarchical Knowledge Base
David Jaeger, Amir Azodi, Feng Cheng 0002, Christoph Meinel
WISTP3
2013 Hierarchical object log format for normalisation of security events
abstract
The differences in log file formats employed in a variety of services and applications remain to be a problem for security analysts and developers of intrusion detection systems. The proposed solution, i.e. the usage of common log formats, has a limited utilization within existing solutions for security management. In our paper, we reveal the reasons for this limitation. We show disadvantages of existing common log formats for normalisation of security events. To deal with it we have created a new log format that fits for intrusion detection purposes and can be extended easily. Taking previous work into account, we would like to propose a new format as an extension to existing common log formats, rather than a standalone specification.
Andrey Sapegin, David Jaeger, Amir Azodi, Marian Gawron, Feng Cheng 0002, Christoph Meinel
IAS5
2013 Multi-core Supported High Performance Security Analytics
abstract
Such information as system and application logs as well as the output from the deployed security measures, e.g., IDS alerts, firewall logs, scanning reports, etc., is important for the administrators or security operators to be aware at first time of the running state of the system and take efforts if necessary. In this context, high performance security analytics is proposed to address the challenges to rapidly gather, manage, process, and analyze the large amount of real-time information generated from the large scale of enterprise IT-Infrastructure while it is being operated. As an example of next generation Security Information and Event Management (SIEM) platform, Security Analytics Lab (SAL) has been designed and implemented based on the newly emerged In-Memory data management technique, which makes it possible to efficiently organize and access different types of event information through a consistent central storage and interface. To correlate the information from different sources and identify the meaningful information is another challenging task, which makes great sense for quickly judging the current situation and making the decision. In this paper, the multi-core processing technique is introduced in the SAL platform. Various correlation algorithms, e.g., k-means based algorithms, ROCK and QROCK clustering algorithms, have been implemented and integrated in the multi-core supported SAL architecture. Practical experiments are conducted and analyzed to proof that the performance of analytics can be significantly improved by applying multi-core processing technique in SAL.
Feng Cheng 0002, Amir Azodi, David Jaeger, Christoph Meinel
DASC1
2013 A New Approach to Building a Multi-tier Direct Access Knowledgebase for IDS/SIEM Systems
abstract
Looking at current IDS and SIEM systems, we observe heavy processing power dedicated solely to answering a simple question, What is the format of the log line that the IDS (or SIEM) system should process next? Due to the apparent difficulties of uniquely identifying a log line at run-time, most systems today do little or no normalisation of the events they receive. Indeed these systems often rely on popular search engine applications for processing and analysing the event information they receive, which results in slower and far less accurate event correlations. In this process, a large list of tokenisers is usually created in order to find an answer to the above posted question. The tokenisers are run against the log lines, until a match is found. The appropriate log line can then be passed on to the correct extraction module for further processing. This process is currently the standard procedure of most IDS and SIEM systems. To address this problem and to optimise and improve the said process, this paper describes a method for detecting the exact type and format of a read log line in the first place. The method presented performs in an efficient manner, while it is less resource hungry. The proposed detection system is described and implemented, its pros and cons are analysed and weighed against methods currently implemented by popular IDS and SIEM systems for solving this task.
Amir Azodi, David Jaeger, Feng Cheng 0002, Christoph Meinel
DASC3
2013 Catch the Spike: On the Locality of Individual BGP Update Bursts
abstract
Internet scalability depends on scalability of its core routing protocol - Border Gateway Protocol (BGP). However, dynamics of BGP still conceal many unanswered questions. Most of these questions are related to BGP update messages: root cause of update spikes, correlation between update spikes in the different parts of the Internet and influence of individual spikes on global routing. This article presents a methodology to locate routing events behind specific BGP update spikes. The method explores correlated updates seen on different vantage points [1]. Although previous work [2] uses similar approach to identify origin of update bursts, we revise the question considering one-second update spikes as a point of view. This concept allows not only to identify an area where the routing event has happened, but also to find, how an individual BGP update spike was formed, i.e. find a propagation path for a set of routing events behind the spike. Revealed propagation paths - if analysed for a significant amount of update messages - could tell us new facts about specific types of routing events and improve our understanding of BGP scalability.
Andrey Sapegin, Feng Cheng 0002, Christoph Meinel
MSN2
2012 An alert correlation platform for memory-supported techniques
abstract
SUMMARY Intrusion Detection Systems (IDS) have been widely deployed in practice for detecting malicious behavior on network communication and hosts. False‐positive alerts are a popular problem for most IDS approaches. The solution to address this problem is to enhance the detection process by correlation and clustering of alerts. To meet the practical requirements, this process needs to be finished fast, which is a challenging task as the amount of alerts in large‐scale IDS deployments is significantly high. We identifytextitdata storage and processing algorithms to be the most important factors influencing the performance of clustering and correlation. We propose and implement a highly efficient alert correlation platform. For storage, a column‐based database, an In‐Memory alert storage, and memory‐based index tables lead to significant improvements of the performance. For processing, algorithms are designed and implemented which are optimized for In‐Memory databases, e.g. an attack graph‐based correlation algorithm. The platform can be distributed over multiple processing units to share memory and processing power. A standardized interface is designed to provide a unified view of result reports for end users. The efficiency of the platform is tested by practical experiments with several alert storage approaches, multiple algorithms, as well as a local and a distributed deployment. Copyright © 2011 John Wiley & Sons, Ltd.
Sebastian Roschke, Feng Cheng 0002, Christoph Meinel
Concurr. Comput. Pract. Exp.2
2011 An Integrated Network Scanning Tool for Attack Graph Construction
Feng Cheng 0002, Sebastian Roschke, Christoph Meinel
GPC1
2011 BALG: Bypassing Application Layer Gateways using multi-staged encrypted shellcodes
abstract
Modern attacks are using sophisticated and innovative techniques. The utilization of cryptography, self-modified code, and integrated attack frameworks provide more possibilities to circumvent most existing perimeter security approaches, such as firewalls and IDS. Even Application Layer Gateways (ALG) which enforce the most restrictive network access can be exploited by using advanced attack techniques. In this paper, we propose a new attack for circumventing ALGs. By using polymorphic and encrypted shellcode, multiple shellcode stages, protocol compliant and encrypted shell tunneling, and reverse channel discovery techniques, we are able to effectively bypass ALGs. The proposed attack consists of four phases with certain requirements and results. We implemented the initial shellcode as well as the different stages and conducted the practical attack using an existing ALG. The possibility to prevent this attack with existing approaches is discussed and further research in the area of perimeter security and log management is motivated.
Sebastian Roschke, Feng Cheng 0002, Christoph Meinel
Integrated Network Management2
2010 Using vulnerability information and attack graphs for intrusion detection
abstract
Intrusion Detection Systems (IDS) have been used widely to detect malicious behavior in network communication and hosts. IDS management is an important capability for distributed IDS solutions, which makes it possible to integrate and handle different types of sensors or collect and synthesize alerts generated from multiple hosts located in the distributed environment. Sophisticated attacks are difficult to detect and make it necessary to integrate multiple data sources for detection and correlation. Attack graph (AG) is used as an effective method to model, analyze, and evaluate the security of complicated computer systems or networks. The attack graph workflow consists of three parts: information gathering, attack graph construction, and visualization. This paper proposes the integration of the AG workflow with an IDS management system to improve alert and correlation quality. The vulnerability and system information is used to prioritize and tag the incoming IDS alerts. The AG is used during the correlation process to filter and optimize correlation results. A prototype is implemented using automatic vulnerability extraction and AG creation based on unified data models.
Sebastian Roschke, Feng Cheng 0002, Christoph Meinel
IAS2
2010 A Specialized Tool for Simulating Lock-Keeper Data Transfer
abstract
Simulation is an efficient way to model a real system by a computer program and is used to study and evaluate the characteristics or behaviors of the system. In this paper, we present an effective simulation tool that is designed for simulating the working procedure of the Lock-Keeper system, which is a high level security device for physically separating two networks. Due to the special mechanism of data exchange within the Lock-Keeper system, it is a challenging task to specify the Lock-Keeper's performance for a given application scenario. To get enough performance data, the intuitive way is to practically conduct numerous testing experiments and then analyze their results, which is extremely time consuming. Therefore, we are motivated to design and implement a simulator to predict the Lock-Keeper performance theoretically. Compare with most of available network simulation tools, the proposed simulator is capable of simulating the transfer of application layer data, i.e., file based data streams. The simulator is built based on a simple model of the Lock-Keeper data exchange procedure. Information on a target application scenario can be specified within an XML file, which is used as the input for the later calculation. Several kinds of reports are generated by this specialized simulator to indicate how the data is exchanged through Lock-Keeper. To verify the simulation results, we conduct several experiments, which practically test data transfer for the scenarios using the real Lock-Keeper system. The comparison between theoretical simulation and practical testing proves the effectiveness of our proposed simulation tool.
Feng Cheng 0002, Thanh-Dien Tran, Sebastian Roschke, Christoph Meinel
AINA1
2010 A Flexible and Efficient Alert Correlation Platform for Distributed IDS
abstract
Intrusion Detection Systems (IDS) have been widely deployed in practice for detecting malicious behavior on network communication and hosts. The problem of false-positive alerts is a popular existing problem for most of IDS approaches. The solution to address this problem is correlation and clustering of alerts. To meet the practical requirements, this process needs to be finished as soon as possible, which is a challenging task as the amount of alerts produced in large scale deployments of distributed IDS is significantly high. We identify the data storage and processing algorithms to be the most important factors influencing the performance of clustering and correlation. We propose and implement the utilization of memory-supported algorithms and a column-oriented database for correlation and clustering in an extensible IDS correlation platform. The utilization of the column-oriented database, an In-Memory Alert Storage, and memory-based index tables leads to significant improvements on the performance. Different types of correlation modules can be integrated and compared on this platform. A plugin concept for Receivers provides flexible integration of various sensors and additional IDS management systems. The platform can be distributed over multiple processing units to share memory and processing power. A standardized interface is designed to provide a unified view of result reports for end users. The efficiency of the proposed platform is tested by practical experiments with several alert storage approaches, different simple algorithms, as well as local and distributed deployment.
Sebastian Roschke, Feng Cheng 0002, Christoph Meinel
NSS2
2009 An Extensible and Virtualization-Compatible IDS Management Architecture
abstract
Efficient intrusion detection system (IDS) management is a prominent capability for distributed IDS solutions, which makes it possible to integrate and handle different types of sensors or collect and synthesize alerts generated from multiple hosts located in a loosely coupled environment. Extensibility is the main requirement for most of IDS management systems. The concept of virtualization has been introduced into many popular IDS implementations due to the advantage on isolation and fast recovery in case of being compromised. Advanced capability for combining these newly emerged virtual machine (VM) based IDS approaches is another requirement for IDS management. This paper proposes an extensible IDS management architecture based on a new design of event gatherer component. By using the known IDS standard IDMEF and a plug-in concept, the Event gatherer ensures flexibility and compatibility.Experiments are carried out to demonstrate the extensibility and virtualization-compatibility of the proposed IDS management architecture.
Sebastian Roschke, Feng Cheng 0002, Christoph Meinel
IAS2
2009 Remodeling Vulnerability Information
Feng Cheng 0002, Sebastian Roschke, Robert Schuppenies, Christoph Meinel
Inscrypt1
2009 Intrusion Detection in the Cloud
abstract
Intrusion detection systems (IDS) have been used widely to detect malicious behaviors in network communication and hosts. IDS management is an important capability for distributed IDS solutions, which makes it possible to integrate and handle different types of sensors or collect and synthesize alerts generated from multiple hosts located in the distributed environment. Facing new application scenarios in cloud computing, the IDS approaches yield several problems since the operator of the IDS should be the user, not the administrator of the cloud infrastructure. Extensibility, efficient management, and compatibility to virtualization-based context need to be introduced into many existing IDS implementations.Additionally, the cloud providers need to enable possibilities to deploy and configure IDS for the user. Within this paper, we summarize several requirements for deploying IDS in the cloud and propose an extensible IDS architecture for being easily used in a distributed cloud infrastructure.
Sebastian Roschke, Feng Cheng 0002, Christoph Meinel
DASC2
2009 Implementing IDS Management on Lock-Keeper
Feng Cheng 0002, Sebastian Roschke, Christoph Meinel
ISPEC1
2009 Towards Unifying Vulnerability Information for Attack Graph Construction
Sebastian Roschke, Feng Cheng 0002, Robert Schuppenies, Christoph Meinel
ISC2
2009 A Theoretical Model of Lock-Keeper Data Exchange and its Practical Verification
abstract
Performance is a critical aspect for all kinds of security solutions. The Lock-Keeper is a high-level security solution which implements the concept of physical separation. To evaluate and predict the performance of Lock-Keeper, the internal data transfer process has to be analyzed and simulated. As the Lock-Keeper consists of three independent systems, connected through a hardware-based switch, with file-based communication, the internal data transfer process is relatively complex. In this paper, we propose a mathematical model which can be used to formally represent most of the Lock-Keeper data transfer scenarios. The model is verified by practical experiments for three different application scenarios. We conclude that the performance of the Lock-Keeper system highly depends on the application scenarios.
Sebastian Roschke, Feng Cheng 0002, Thanh-Dien Tran, Christoph Meinel
NPC2
2008 Strong Authentication over Lock-Keeper
Feng Cheng 0002, Christoph Meinel
SOFSEM1
2007 A Secure Web Services Providing Framework Based on Lock-Keeper
Feng Cheng 0002, Michael Menzel 0001, Christoph Meinel
APNOMS1
2007 A Simple, Smart and Extensible Framework for Network Security Measurement
Feng Cheng 0002, Christian Wolter, Christoph Meinel
Inscrypt1
2003 The DualGate Lock-Keeper: A Highly Efficient, Flexible and Applicable Network Security Solution
Feng Cheng 0002, Paul Ferring, Christoph Meinel, Gerhard Müllenheim, Jochen Bern
SNPD1