Yizhen Sun

dblp:24/8595 · DBLP profile ↗
← Back
10ranked-venue papers
9as first author
4since 2021 · last 2025
0000-0002-2794-7195ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 6 first-author · 1 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Security and privacy · 1 · 1 first-author
YearPublicationVenuePosition
2025 An Innovative Model for Solving the Identical Shortcut Problem in Anomaly Detection of AIOps
Haokai Luo, Yizhen Sun, Hanyu Deng
ICA3PP (8)2
2025 An Attribute-Sensitive Data Protection Method for UAV Based on FPE
Yizhen Sun, Yating Chen, Shigeng Zhang
ICA3PP (8)1
2025 An Adaptive Watermark Embedding Method for Multi-modal Data in Power Systems
Yizhen Sun, Yizhou Jiang, Wen-Xiao Zhao, Jingyuan Xue, Shigeng Zhang
ICA3PP (8)1
2023 Timbre-Based Portable Musical Instrument Recognition Using LVQ Learning Algorithm
Yizhen Sun
Mob. Networks Appl.1
2020 Accurate IoT Device Identification from Merely Packet Length
abstract
With the massive deployment of IoT devices, the management of IoT devices becomes more and more important. In this paper, We only need the packet length the device sent to serves in 180s to identify the device. We evaluated the algorithms K-Nearest Neighbor, Random Forest, Suport Vector Machine and Multilayer Perceptron for classification. The results show that the Random Forest is the best and can achieve 99.6% if accuracy in the identification of devices. We also ranked the importance of 10 features related to packet length. Using the five most important features (media, mean, skewness, absolute energy, standard deviation and of packet length), we can achieve 99.5% accuracy on the public dataset and 99.29% accuracy on our dataset.
Yizhen Sun, Shupo Fu, Shigeng Zhang, Yongfa Li
MSN1
2020 A Method to Construct Vulnerability Knowledge Graph based on Heterogeneous Data
abstract
In recent years, there are more and more attacks and exploitation aiming at network security vulnerabilities. It is effective for us to prevent criminals from exploiting vulnerabilities for attacks and help security analysts maintain equipment security that knows vulnerabilities and threats on time. With the knowledge graph, we can organize, manage, and utilize the massive information effectively in cyberspace. In this paper we construct the vulnerability ontology after analyzing multi-source heterogeneous databases. And the vulnerability knowledge graph is established. Experimental results show that the accuracy of entity recognition for extracting vendor names reaches 89.76%. The more rules used in entity recognition, the higher the accuracy and the lower the error rate.
Yizhen Sun, Dandan Lin, Hong Song 0004, Minjia Yan, Linjing Cao
MSN1
2020 WSAD: An Unsupervised Web Session Anomaly Detection Method
abstract
servers in the Internet are vulnerable to Web attacks, to detect Web attacks, a commonly used method is to detect anomalies in the request parameters by making regular-expression-based matching rules for the parameters based on known security threats. However, such methods cannot detect unknown anomalies well and they can also be easily bypassed by using techniques like transcoding. Moreover, existing anomaly detection methods are usually based on a single HTTP request, which is easy to ignore the attack behavior within a period of time, such as brute-force password cracking attack. In this paper, we propose an unsupervised W eb S ession A nomaly D etection method called WSAD. WSAD uses ten features of web session to perform anomaly detection. After extracting the ten features, WSAD uses the DBSCAN algorithm to cluster the features of each session and outputs the outliers found in the clustering process as anomalies. We evaluate the performance of WSAD on several datasets from multiple real websites of a company. The results indicate that WSAD could detect malicious behaviors that could not be detected by Web Application Firewall, and it almost has no false positives.
Yizhen Sun, Yiman Xie, Weiping Wang 0003, Shigeng Zhang, Yating Chen
MSN1
2020 RPAD: An Unsupervised HTTP Request Parameter Anomaly Detection Method
abstract
Web servers in the Internet are vulnerable to Web attacks. A general way to launch Web attacks is to carry attack payloads in HTTP request parameters, e.g. SQL Injection and XSS attacks. To detect Web attacks, a commonly used method is to detect anomalies in the request parameters by making regular-expression-based matching rules for the parameters based on known security threats. However, such methods cannot detect unknown anomalies well and they can also be easily bypassed by using techniques like transcoding. Moreover, existing anomaly detection methods are usually based on supervised learning methods that require a large number of high-quality labelled samples as training sets, which are difficult to obtain in real situations. In this paper, we propose an unsupervised HTTP Request Parameter Anomaly Detection method called RPAD. RPAD uses five features of HTTP request parameters to perform anomaly detection including type, length, number of tokens, encoding type and character feature. After extracting the five features, RPAD uses the DBSCAN algorithm to cluster the parameters of each target access request and outputs the outliers found in the clustering process as anomalies. We evaluate the performance of RPAD on several datasets from multiple real websites of a Cyber Security Company. The results indicate that RPAD is highly efficient in detecting deviating abnormal parameter values with an accuracy of 99%.
Yizhen Sun, Yiman Xie, Weiping Wang 0003, Shigeng Zhang, Jingchuan Feng
TrustCom1
2019 Intelligent Log Analysis System for Massive and Multi-Source Security Logs: MMSLAS Design and Implementation Plan
abstract
In the Internet of Things and industrial controlnetwork servers, a large number of logs will be formed everymoment. This log information, as an important basis for eventrecording and security auditing, provides important informa-tion for identifying threat sources, identifying threat degreeand judging threat impact. However, the current security loganalysis system usually only standardizes the logs separately, and lacks the correlation analysis of the information fromvarious sources. Thus, this paper presents an intelligent loganalysis system for massive and multi-source security logs-MMSLAS(Massive and Multi-Source Security Log AnalysisSystem). In the log analysis module, the system integratesbusiness rule analysis and behavior analysis and additionallyadopts a machine learning-based analysis method, which fullyexploits the correlation between security logs and realizes thecomprehensive analysis of multi-source security logs. At thesame time, the distributed architecture scheme is also sufficientto cope with the system load caused by a large amount ofdata. The final implementation results show that MMSLAScan quickly locate the improper behavior in the log, and detectthe abnormal requests in advance according to the analysis ofthe behavior trajectory.
Yizhen Sun, Shaoming Guo, Zhongwei Chen
MSN1
2019 A Deception Defense and Active Defense Based Three-Dimensional Defense Architecture: DA-3DD Design and Implementation Plan
abstract
With the development of network technology, security attacks against IoT and the industrial Internet havebecome more covert and diversified. However, the traditional network security defense means can only aim at a single attack, and can only intercept or defend passively, which can't deal with the complex security protection forms of IoT and industrial Internet. Therefore, this paper proposes a three-dimensional defense architecture-DA-3DD based on deception defense and active defense and provides an implementation scheme. The structure of DA-3DD is simple and easy to realize. While integrating traditional network security protection means, two honeypot systems, Information Collection Honeypot and Reverse Honeypot, are designed additionally, which overcomes the disadvantages of passive and low coverage of traditional honeypot protection system. Finally, the whole architecture realizes active, all-round and three-dimensional network security protection, which provides a new idea for the design of similar security protection system.
Yizhen Sun, Xiaotao Peng, Shaoming Guo
MSN1