Fu-Hau Hsu

dblp:38/3634 · DBLP profile ↗
← Back
25ranked-venue papers
19as first author
3since 2021 · last 2021
0000-0002-2586-5874ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 4 first-author · 1 since 2021Computer networks · 7 · 6 first-author · 1 since 2021Security and privacy · 6 · 6 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorArtificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Web and mobile security · 38% Authentication and access control · 19% Privacy and data protection · 19%
Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 100%

Topics — the 8 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
access control
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Web and mobile security › mobile security
android permission control
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Web and mobile security
mobile security
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Privacy and data protection › mobile privacy
runtime permission management
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Network security
traffic analysis
0.212014
Detect Fast-Flux Domains Through Response Time Differences · IEEE J. Sel. Areas Commun. 2014
Software maintenance and evolution › software ecosystems
third-party libraries
0.112021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Malware analysis
malware defense
0.112012
Antivirus Software Shield Against Antivirus Terminators · IEEE Trans. Inf. Forensics Secur. 2012
Network measurement and analytics › traffic analysis
DNS traffic analysis
0.112014
Detect Fast-Flux Domains Through Response Time Differences · IEEE J. Sel. Areas Commun. 2014

Methods — techniques the papers use, named apart from their topics

dynamic permission API · 1.0android framework modification · 1.0response time analysis · 0.4fast-flux score · 0.4system service descriptor table hooking · 0.1API call interception · 0.1browser helper object · 0.1behavior-based detection · 0.1
YearPublicationVenuePosition
2021 IoTD: An approach to identify E-mails sent by IoT devices
Fu-Hau Hsu, Jyun-Shao Wu, Chih-Wen Ou, Tzu-Chi Liu, YungYu Zhuang
Comput. Commun.1
2021 SMS Observer: A dynamic mechanism to analyze the behavior of SMS-based malware
Chun-Yi Wang, Chi-Yu You, Fu-Hau Hsu, Chia-Hao Lee 0001, Che-Hao Liu, YungYu Zhuang
J. Parallel Distributed Comput.3
2021 DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries
abstract
Today's smartphone app stores are full of apps with diverse features. Many developers use third-party libraries to reduce the development time and cost, but developers often ignore the security problems of third-party libraries. A major security problem introduced by third-party libraries is that a third-party library has the same permissions as the apps, calledhost-appshereafter, that use it. According to previous research, having the same permissions as its host apps, a third-party library could have unauthorized access to user data, which poses a serious threat to app users. Therefore, how to prevent third-party libraries from abusing permissions has become an important issue. To solve this problem, this paper proposes a Dynamic Permission Control mechanism, calledDynamic Permission ControllerorDPChereafter, for app developers to prohibit third-party libraries from abusing host apps’ dangerous permissions. DPC modifies the permission control mechanism of Android framework to make apps have a more flexible permission management mechanism when they are running. DPC provides new APIs which allows an app to dynamically disable a granted dangerous permission before invoking an API of a third-party library and restore the dangerous permission after completing the API. Hence, DPC protects user's privacy by blocking unauthorized access from third-party libraries. Meanwhile, without the requirement that an app developer needs to know the detail of third-party libraries, the app still can use APIs of third-party libraries safely. Experimental results show that DPC works with many popular apps downloaded from Google Play well and DPC prohibits a third-party library from having the same dangerous permissions that its host apps have. Hence, unlike previous solutions, DPC does not have compatibility problems. The overhead introduced by DPC on an emulator and Nexus 7 are 1.8 and 0.3 percent respectively.
Fu-Hau Hsu, Nien-Chi Liu, Yanling Hwang, Che-Hao Liu, Chuan-Sheng Wang, Chang-Yi Chen
IEEE Trans. Dependable Secur. Comput.1
2019 A solution to detect the existence of a malicious rogue AP
Fu-Hau Hsu, Yu-Liang Hsu, Chuan-Sheng Wang
Comput. Commun.1
2017 Detecting Web-Based Botnets Using Bot Communication Traffic Features
abstract
Web-based botnets are popular nowadays. A Web-based botnet is a botnet whose C&C server and bots use HTTP protocol, the most universal and supported network protocol, to communicate with each other. Because the botnet communication can be hidden easily by attackers behind the relatively massive HTTP traffic, administrators of network equipment, such as routers and switches, cannot block such suspicious traffic directly regardless of costs. Based on the clients constituent of a Web server and characteristics of HTTP responses sent to clients from the server, this paper proposes a traffic inspection solution, called Web-based Botnet Detector (WBD). WBD is able to detect suspicious C&C (Command-and-Control) servers of HTTP botnets regardless of whether the botnet commands are encrypted or hidden in normal Web pages. More than 500 GB real network traces collected from 11 backbone routers are used to evaluate our method. Experimental results show that the false positive rate of WBD is 0.42%.
Fu-Hau Hsu, Chih-Wen Ou, Yanling Hwang, Ya-Ching Chang, Po-Ching Lin
Secur. Commun. Networks1
2016 VRS: a values-based reputation system for web services
abstract
Abstract The reputation system is used to display the reputation of entities based on the ratings or appraisals given by users who have used or purchased those entities. Web service providers supply various reputation systems for their users. However, these promising reputation systems face some challenges. First, even though different persons have different preference andvalues(values are a person's beliefs about what things are good or bad), these systems still give the same rating to the same entity for all users. Second, they may be greatly influenced by Sybil attacks. In this paper, we propose a reputation system, called values‐based reputation system (VRS), to solve the aforementioned problems. VRS customizes the rating of an entity for each user based on the ratings of the entities provided by other users who have similarvaluesor preference to the user. Experimental results on 256 users show that compared with existing reputation systems VRS is more robust to Sybil attacks and provides a recommendation rating that is closer to the rating given by the user after it used the related entity. Copyright © 2016 John Wiley & Sons, Ltd.
Fu-Hau Hsu, Yu-Liang Hsu, Yanling Hwang, Li-Han Chen, Chuan-Sheng Wang, Chang-Kuo Tso, Szu-Chi Liu, Po-Ching Lin, Chi-Hsien Hsu
Secur. Commun. Networks1
2016 Data concealments with high privacy in new technology file system
Fu-Hau Hsu, Min-Hao Wu, Syun-Cheng Ou, Shiuh-Jeng Wang
J. Supercomput.1
2015 Web security in a windows system as PrivacyDefender in private browsing mode
Fu-Hau Hsu, Min-Hao Wu, Yi-Wen Chang, Shiuh-Jeng Wang
Multim. Tools Appl.1
2015 Defeat scanning worms in cyber warfare
abstract
Abstract In this paper, we propose an automatic defense system, called Serum System, against scanning worms. The homeland security department of a country can use Serum System to protect its Internet infrastructure. When an infecting host is infecting a Serum System host, called Serum System Server (SSS), the SSS automatically replaces the shellcode inside the infecting string with its code (called serum code) and then uses the modified string (called serum string) to counterattack the infecting host and takes control of it. The serum code transforms the infecting host into a Serum System Client (SSC) that has the same functions as the SSS and is immune to the same worm. Therefore, infecting hosts attacking SSSs or SSCs will transform themselves into SSCs. We implemented Serum System on Linux and also built a mathematical model for Serum System to analyze its effectiveness and bandwidth savings. Our analyses show that with only a small number of SSSs and through chain counterattacks, Serum System can automatically and rapidly defeat related infected hosts. Compared with white worms whose spread cannot be controlled, Serum System only spreads on infected hosts. The amount of accumulative traffic saved by Serum System at time tick 450 reached 90%. Copyright © 2014 John Wiley & Sons, Ltd.
Fu-Hau Hsu, Li-Han Chen, Chia-Jun Lin
Secur. Commun. Networks1
2014 Hawkeye: Finding spamming accounts
abstract
Email spam is a critical problem to the Internet for a long time. The average amount of spam mail reached 72.1% of all email traffic in the world in 2012. The greatest threat to the email service providers was the spam mail sent from botnet, because the spam mail sent from botnet was accounting for more than 78% in 2011; therefore appeared many anti-spam solutions and techniques that were focus on the botnet. Owing to these anti-spam techniques, botnet spam is not effective as before. Spammers are finding new way to send the spam mail. One of the effective methods is using compromised accounts (or bot accounts) to send the spam mail because compromised accounts have good reputation IP addresses and compromised accounts send the spam mail with complete SMTP implemented server, such as Gmail, Yahoo!Mail, and Microsoft Live Mail. The spam mail send form compromised accounts are very difficult to be detected by any anti-spam techniques. Hence, we focus on the features spammers cannot easily hide. According to our research we find that normal users usually do not reply to the spam mail. Moreover, our empirical analysis reveals that the compromised account actually have low reply rate. We develop a system called “Hawkeye” that can find the compromised accounts effectively by checking the account's reply rate.
Chia-Heng Li, Fu-Hau Hsu, Shih-Jen Chen, Chuan-Sheng Wang, Yao-Hsin Chen, Yanling Hwang
APNOMS2
2014 Detect Fast-Flux Domains Through Response Time Differences
abstract
A fast-flux service network (FFSN) uses dynamic DNS to map a dynamic domain, called fast-flux domain (FF domain), to various IP addresses and uses flux bots to redirect network traffic. Due to its powerful capability to conceal the hosts hidden behind the flux bots, FFSNs are widely adopted by attackers to cover various scams. Although diverse promising solutions have been proposed to detect FF domains, they face the same problem-different countermeasures could be used to bypass their detection. Hence, it becomes a critical issue to develop a new detection solution. According to our survey, unlike normal network services that use dynamic DNS to balance the workloads of their hosts, FFSNs utilize dynamic DNS to hide important bots. As a result, the response time of subsequent requests to an FF domain becomes more fluctuating. Based on the response time differences, this paper develops a new metric, Fast-Flux Score (FF-Score), to detect FF domains. Our system, called fast-flux domain detector (FFDD), is used on a computer that could be an end host or an IDS. A user with a set of unknown URLs, which may be obtained from spam or social networks, can simply determine whether they are benign domains or fast-flux ones using FFDD. Experimental results show that FFDD can accurately detect FF domains with only a 0.3% false positive rate and a 2% false negative rate. It takes less than 20 min for FFDD to determine whether a domain is an FF domain. In addition, FFDD is a lightweight stand-alone system; hence, it does not require special support from an ISP or any other network service.
Fu-Hau Hsu, Chuan-Sheng Wang, Chi-Hsien Hsu, Chang-Kuo Tso, Li-Han Chen, Song-Hui Lin
IEEE J. Sel. Areas Commun.1
2014 Image reversibility in data embedding on the basis of blocking-predictions
Fu-Hau Hsu, Min-Hao Wu, Cheng-Hsing Yang, Shiuh-Jeng Wang
Peer-to-Peer Netw. Appl.1
2014 Visible watermarking with reversibility of multimedia images for ownership declarations
Fu-Hau Hsu, Min-Hao Wu, Cheng-Hsing Yang, Shiuh-Jeng Wang
J. Supercomput.1
2013 Reversible data hiding using side-match predictions on steganographic images
Fu-Hau Hsu, Min-Hao Wu, Shiuh-Jeng Wang
Multim. Tools Appl.1
2013 Reversibility of image with balanced fidelity and capacity upon pixels differencing expansion
Fu-Hau Hsu, Min-Hao Wu, Shiuh-Jeng Wang, Chia-Ling Huang
J. Supercomput.1
2012 Antivirus Software Shield Against Antivirus Terminators
abstract
In the last several decades, the arms race between malware writers and antivirus programmers has become more and more severe. The simplest way for a computer user to secure his computer is to install antivirus software on his computer. As antivirus software becomes more sophisticated and powerful, evading the detection of antivirus software becomes an important part of malware. As a result, malware writers have developed various approaches to increase the survivability and concealment of their malware. One of these technologies is to terminate antivirus software right after the execution of the malware. In this paper, we propose a mechanism, called ANtivirus Software Shield (ANSS), to prevent antivirus software from being terminated without the consciousness of the antivirus software users. ANSS uses System Service Descriptor Table (SSDT) hooking to intercept specific Windows APIs and analyzes them to filter out hazardous API calls that will terminate antivirus software. When using several pieces of malware that can terminate various brands of antivirus applications to make our experiments, the results show that ANSS can protect antivirus software from being terminated by them with at most 0.42% CPU performance overhead and 1.77% memory write performance overhead.
Fu-Hau Hsu, Min-Hao Wu, Chang-Kuo Tso, Chi-Hsien Hsu, Chieh-Wen Chen
IEEE Trans. Inf. Forensics Secur.1
2011 BrowserGuard: A Behavior-Based Solution to Drive-by-Download Attacks
abstract
Along with an increasing user population of various web applications, browser-based drive-by-download attacks soon become one of the most common security threats to the cyber community. A user using a vulnerable browser or browser plug-ins may become a victim of a drive-by-download attack right after visiting a vicious web site. The end result of such attacks is that an attacker can download and execute any code on the victim's host. This paper proposes a runtime, behavior-based solution, BrowserGuard, to protect a browser against drive-by-download attacks. BrowserGuard records the download scenario of every file that is loaded into a host through a browser. Then based on the download scenario, BrowserGuard blocks the execution of any file that is loaded into a host without the consent of a browser user. Due to its behavior-based detection nature, BrowserGuard does not need to analyze the source file of any web page or the run-time states of any script code, such as Javascript. BrowserGuard also does not need to maintain any exploit code samples and does not need to query the reputation value of any web site. We utilize the standard BHO mechanism of Windows to implement BrowserGuard on IE 7.0. Experimental results show that BrowserGuard has low performance overhead (less than 2.5%) and no false positives and false negatives for the web pages used in our experiments.
Fu-Hau Hsu, Chang-Kuo Tso, Yi-Chun Yeh, Wei-Jen Wang, Li-Han Chen
IEEE J. Sel. Areas Commun.1
2010 Actor Garbage Collection Using Vertex-Preserving Actor-to-Object Graph Transformations
Wei-Jen Wang, Carlos A. Varela, Fu-Hau Hsu, Cheng-Hsien Tang
GPC3
2010 A neural tree and its application to spam e-mail detection
Mu-Chun Su, Hsu-Hsun Lo, Fu-Hau Hsu
Expert Syst. Appl.3
2010 HSP: A solution against heap sprays
Fu-Hau Hsu, Cheng-Hsien Huang, Chi-Hsien Hsu, Chih-Wen Ou, Li-Han Chen, Ping-Cheng Chiu
J. Syst. Softw.1
2006 Scalable network-based buffer overflow attack detection
abstract
Buffer overflow attack is the main attack method that most if not all existing malicious worms use to propagate themselves from machine to machine. Although a great deal of research has been invested in defense mechanisms against buffer overflow attack, most of them require modifications to the network applications and/or the platforms that host them. Being an extension work of CTCP, this paper presents a network-based low performance overhead buffer overflow attack detection system called Nebula 1 NEtwork-based BUffer overfLow Attack detection, which can detect both known and zero-day buffer overflow attacks based solely on the packets observed without requiring any modifications to the end hosts. Moreover, instead of deriving a specific signature for each individual buffer overflow attack instance, Nebula uses a generalized signature that can capture all known variants of buffer overflow attacks while reducing the number of false positives to a negligible level. In addition, Nebula is built on a centralized TCP/IP architecture that effectively defeats all existing NIDS evasion techniques. Finally, Nebula incorporates a payload type identification mechanism that reduces further the false positive rate and scales the proposed buffer overflow attack detection scheme to gigabit network links.
Fu-Hau Hsu, Fanglu Guo, Tzi-cker Chiueh
ANCS1
2004 CTCP: A Transparent Centralized TCP/IP Architecture for Network Security
abstract
Many nework security problems can be solved in a centralized TCP (CTCP) architecture, in which an organization's edge router transparently proxies every TCP connection between an internal host and an external host on the Internet. This paper describes the design, implementation, and evaluation of a CTCP router prototype that is built on the Linux kernel. By redirecting all packets targeting at nonexistent or nonopen-to-public ports to a CTCP socket which pretends to be the original receivers, CTCP could confirm the real identification of the packet sources, collect suspicious traffic from them, and make an illusion that the scanned target ports are all open, thus renders port scanning an useless effort. Under CTCP architecture, external hosts only interacts with a secure CTCP router; therefore, any OS fingerprinting attempt and DoS/DDoS attack targeting at TCP/IP implementation bugs could be thwarted. Moreover, By further checking traffic originating from confirmed scanners, the CTCP router can actually identify buffer overflow attack traffic. Finally, the CTCP router solves the TCP connection hijacking problem by introducing an additional check on the sequence number filed of incoming packets. Despite providing a rich variety of protection, the CTCP architecture does not incur much overhead. On a 1.1 GHz Pentium-3 machine with gigabit Ethernet interfaces, the throughput of the CTCP router is 420.3 Mbits/sec, whereas the throughput of a generic Linux router on the same hardware is only 409.1 Mbits/sec.
Fu-Hau Hsu, Tzi-cker Chiueh
ACSAC1
2003 A Path Information Caching and Aggregation Approach to Traffic Source Identification
abstract
Probabilistic packet marking (PPM) is a technique designed to identify packet traffic sources with low storage and processing overhead on network routers. In most previous PPM approaches, individual path messages carry only partial path information. These methods are susceptible to "path falsification" attacks, which greatly reduce their effectiveness. This work proposes a path-falsification-attack free PPM algorithm called Path Information Caching and Aggregation (PICA) that records paths of packet streams in fix-length path messages, thus eliminating the need of path reconstruction at the receiver end. Besides, by using a router's forwarding table to decompose packet volume, this semi-stateful method is more accurate in traffic volume report. It also supports both a packet rate-based path message generation algorithm and a redundant path message suppression mechanism to further eliminate path messages with the same destination. Finally, PICA protects PICA routers from being attacked by faked path messages. We have performed a trace-driven simulation study on the proposed PICA algorithm and compared its effectiveness with IETF's iTrace scheme by varying the sampling probability, the number of attack sources, and attack traffic rate. Compared to iTrace, the PICA algorithm reduces the total number of path messages required by a factor of more than 2, while reporting traffic volume more accurately.
Fu-Hau Hsu, Tzi-cker Chiueh
ICDCS1
2002 Sago: A Network Resource Management System for Real-Time Content Distribution
abstract
Content replication and distribution is an effective technology to reduce the response time for Web accesses and has been proven quite popular among large Internet content providers. However, existing content distribution systems assume a store-and-forward delivery model and is mostly based on static content. This paper describes the design, implementation, and initial evaluation of a network resource management system for real-time Internet content distribution called Sago, which provides facilities to provision and allocate network resources so that multiple bandwidth-guaranteed and fault-tolerant multicast connections can be multiplexed on a single physical network. Sago includes a novel network resource mapping algorithm that takes into account both physical network topology and dynamic traffic demands, a network-wide fault tolerance mechanism that supports both node-level and link-level fault tolerance, and a hierarchical network link scheduler that provides performance protection among multicast connections sharing the same physical network link. Moreover, Sago does not require any IP multicasting support from underlying network routers because it performs application-level multicasting. The technologies underlying Sago are important building blocks for real-time content distribution networks, end-to-end quality of service guarantee over global corporate intranets, and application-specific adaptation of wide-area network services.
Tzi-cker Chiueh, Kartik Gopalan, Anindya Neogi, Srikant Sharma, Sheng-Ming Shan, Jiawu Chen, Wei Li 0020, Nikolai Joukov, Fu-Hau Hsu, Fanglu Guo, Sheng-I Doong
ICPADS11
2001 RAD: A Compile-Time Solution to Buffer Overflow Attacks
abstract
Buffer overflow attack can inflict upon almost arbitrary programs and is one of the most common vulnerabilities that can seriously compromise the security of a network-attached computer system. This paper presents a compiler-based solution to the notorious buffer overflow attack problem. Using this solution, users can prevent attackers from compromising their systems by changing the return address to execute injected code, which is the most common method used in buffer overflow attacks. Return address defender (RAD) is a simple compiler patch that automatically creates a safe area to store a copy of return addresses and automatically adds protection code into applications that it compiles to defend programs against buffer overflow attacks. Using it to protect a program does not need to modify the source code of the protected programs. Moreover, RAD does not change the layout of stack frames, so binary code it generated is compatible with existing libraries and other object files. Empirical performance measurements on a fully operational RAD prototype show that programs protected by RAD only experience a factor of between 1.01 to 1.31 slow-down. In this paper we present the principle of buffer overflow attacks, a taxonomy of defense methods, the implementation details of RAD, and the performance analysis of the RAD prototype.
Tzi-cker Chiueh, Fu-Hau Hsu
ICDCS2