EDBT 2026 Demo / reviewers in the wild / expert
Fu-Hau Hsu
dblp:38/3634
· DBLP profile ↗
25ranked-venue papers
19as first author
3since 2021 · last 2021
0000-0002-2586-5874ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 4 first-author · 1 since 2021Computer networks · 7 · 6 first-author · 1 since 2021Security and privacy · 6 · 6 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorArtificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Web and mobile security · 38% Authentication and access control · 19% Privacy and data protection · 19% | |
| Software engineering, system software, and programming languages
1 paper |
Software maintenance and evolution · 100% |
Topics — the 8 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Authentication and access control
access control |
0.5 | 1 | 2021 | DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021 |
Web and mobile security › mobile security
android permission control |
0.5 | 1 | 2021 | DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021 |
Web and mobile security
mobile security |
0.5 | 1 | 2021 | DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021 |
Privacy and data protection › mobile privacy
runtime permission management |
0.5 | 1 | 2021 | DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021 |
Network security
traffic analysis |
0.2 | 1 | 2014 | Detect Fast-Flux Domains Through Response Time Differences · IEEE J. Sel. Areas Commun. 2014 |
Software maintenance and evolution › software ecosystems
third-party libraries |
0.1 | 1 | 2021 | DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021 |
Malware analysis
malware defense |
0.1 | 1 | 2012 | Antivirus Software Shield Against Antivirus Terminators · IEEE Trans. Inf. Forensics Secur. 2012 |
Network measurement and analytics › traffic analysis
DNS traffic analysis |
0.1 | 1 | 2014 | Detect Fast-Flux Domains Through Response Time Differences · IEEE J. Sel. Areas Commun. 2014 |
Methods — techniques the papers use, named apart from their topics
dynamic permission API · 1.0android framework modification · 1.0response time analysis · 0.4fast-flux score · 0.4system service descriptor table hooking · 0.1API call interception · 0.1browser helper object · 0.1behavior-based detection · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | IoTD: An approach to identify E-mails sent by IoT devices
Fu-Hau Hsu, Jyun-Shao Wu, Chih-Wen Ou, Tzu-Chi Liu, YungYu Zhuang |
Comput. Commun. | 1 |
| 2021 | SMS Observer: A dynamic mechanism to analyze the behavior of SMS-based malware
Chun-Yi Wang, Chi-Yu You, Fu-Hau Hsu, Chia-Hao Lee 0001, Che-Hao Liu, YungYu Zhuang |
J. Parallel Distributed Comput. | 3 |
| 2021 | DPC: A Dynamic Permission Control Mechanism for Android Third-Party LibrariesabstractToday's smartphone app stores are full of apps with diverse features. Many developers use third-party libraries to reduce the development time and cost, but developers often ignore the security problems of third-party libraries. A major security problem introduced by third-party libraries is that a third-party library has the same permissions as the apps, calledhost-appshereafter, that use it. According to previous research, having the same permissions as its host apps, a third-party library could have unauthorized access to user data, which poses a serious threat to app users. Therefore, how to prevent third-party libraries from abusing permissions has become an important issue. To solve this problem, this paper proposes a Dynamic Permission Control mechanism, calledDynamic Permission ControllerorDPChereafter, for app developers to prohibit third-party libraries from abusing host apps’ dangerous permissions. DPC modifies the permission control mechanism of Android framework to make apps have a more flexible permission management mechanism when they are running. DPC provides new APIs which allows an app to dynamically disable a granted dangerous permission before invoking an API of a third-party library and restore the dangerous permission after completing the API. Hence, DPC protects user's privacy by blocking unauthorized access from third-party libraries. Meanwhile, without the requirement that an app developer needs to know the detail of third-party libraries, the app still can use APIs of third-party libraries safely. Experimental results show that DPC works with many popular apps downloaded from Google Play well and DPC prohibits a third-party library from having the same dangerous permissions that its host apps have. Hence, unlike previous solutions, DPC does not have compatibility problems. The overhead introduced by DPC on an emulator and Nexus 7 are 1.8 and 0.3 percent respectively. Fu-Hau Hsu, Nien-Chi Liu, Yanling Hwang, Che-Hao Liu, Chuan-Sheng Wang, Chang-Yi Chen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | A solution to detect the existence of a malicious rogue AP
Fu-Hau Hsu, Yu-Liang Hsu, Chuan-Sheng Wang |
Comput. Commun. | 1 |
| 2017 | Detecting Web-Based Botnets Using Bot Communication Traffic FeaturesabstractWeb-based botnets are popular nowadays. A Web-based botnet is a botnet whose C&C server and bots use HTTP protocol, the most universal and supported network protocol, to communicate with each other. Because the botnet communication can be hidden easily by attackers behind the relatively massive HTTP traffic, administrators of network equipment, such as routers and switches, cannot block such suspicious traffic directly regardless of costs. Based on the clients constituent of a Web server and characteristics of HTTP responses sent to clients from the server, this paper proposes a traffic inspection solution, called Web-based Botnet Detector (WBD). WBD is able to detect suspicious C&C (Command-and-Control) servers of HTTP botnets regardless of whether the botnet commands are encrypted or hidden in normal Web pages. More than 500 GB real network traces collected from 11 backbone routers are used to evaluate our method. Experimental results show that the false positive rate of WBD is 0.42%. Fu-Hau Hsu, Chih-Wen Ou, Yanling Hwang, Ya-Ching Chang, Po-Ching Lin |
Secur. Commun. Networks | 1 |
| 2016 | VRS: a values-based reputation system for web servicesabstractAbstract The reputation system is used to display the reputation of entities based on the ratings or appraisals given by users who have used or purchased those entities. Web service providers supply various reputation systems for their users. However, these promising reputation systems face some challenges. First, even though different persons have different preference andvalues(values are a person's beliefs about what things are good or bad), these systems still give the same rating to the same entity for all users. Second, they may be greatly influenced by Sybil attacks. In this paper, we propose a reputation system, called values‐based reputation system (VRS), to solve the aforementioned problems. VRS customizes the rating of an entity for each user based on the ratings of the entities provided by other users who have similarvaluesor preference to the user. Experimental results on 256 users show that compared with existing reputation systems VRS is more robust to Sybil attacks and provides a recommendation rating that is closer to the rating given by the user after it used the related entity. Copyright © 2016 John Wiley & Sons, Ltd. Fu-Hau Hsu, Yu-Liang Hsu, Yanling Hwang, Li-Han Chen, Chuan-Sheng Wang, Chang-Kuo Tso, Szu-Chi Liu, Po-Ching Lin, Chi-Hsien Hsu |
Secur. Commun. Networks | 1 |
| 2016 | Data concealments with high privacy in new technology file system
Fu-Hau Hsu, Min-Hao Wu, Syun-Cheng Ou, Shiuh-Jeng Wang |
J. Supercomput. | 1 |
| 2015 | Web security in a windows system as PrivacyDefender in private browsing mode
Fu-Hau Hsu, Min-Hao Wu, Yi-Wen Chang, Shiuh-Jeng Wang |
Multim. Tools Appl. | 1 |
| 2015 | Defeat scanning worms in cyber warfareabstractAbstract In this paper, we propose an automatic defense system, called Serum System, against scanning worms. The homeland security department of a country can use Serum System to protect its Internet infrastructure. When an infecting host is infecting a Serum System host, called Serum System Server (SSS), the SSS automatically replaces the shellcode inside the infecting string with its code (called serum code) and then uses the modified string (called serum string) to counterattack the infecting host and takes control of it. The serum code transforms the infecting host into a Serum System Client (SSC) that has the same functions as the SSS and is immune to the same worm. Therefore, infecting hosts attacking SSSs or SSCs will transform themselves into SSCs. We implemented Serum System on Linux and also built a mathematical model for Serum System to analyze its effectiveness and bandwidth savings. Our analyses show that with only a small number of SSSs and through chain counterattacks, Serum System can automatically and rapidly defeat related infected hosts. Compared with white worms whose spread cannot be controlled, Serum System only spreads on infected hosts. The amount of accumulative traffic saved by Serum System at time tick 450 reached 90%. Copyright © 2014 John Wiley & Sons, Ltd. Fu-Hau Hsu, Li-Han Chen, Chia-Jun Lin |
Secur. Commun. Networks | 1 |
| 2014 | Hawkeye: Finding spamming accountsabstractEmail spam is a critical problem to the Internet for a long time. The average amount of spam mail reached 72.1% of all email traffic in the world in 2012. The greatest threat to the email service providers was the spam mail sent from botnet, because the spam mail sent from botnet was accounting for more than 78% in 2011; therefore appeared many anti-spam solutions and techniques that were focus on the botnet. Owing to these anti-spam techniques, botnet spam is not effective as before. Spammers are finding new way to send the spam mail. One of the effective methods is using compromised accounts (or bot accounts) to send the spam mail because compromised accounts have good reputation IP addresses and compromised accounts send the spam mail with complete SMTP implemented server, such as Gmail, Yahoo!Mail, and Microsoft Live Mail. The spam mail send form compromised accounts are very difficult to be detected by any anti-spam techniques. Hence, we focus on the features spammers cannot easily hide. According to our research we find that normal users usually do not reply to the spam mail. Moreover, our empirical analysis reveals that the compromised account actually have low reply rate. We develop a system called “Hawkeye” that can find the compromised accounts effectively by checking the account's reply rate. Chia-Heng Li, Fu-Hau Hsu, Shih-Jen Chen, Chuan-Sheng Wang, Yao-Hsin Chen, Yanling Hwang |
APNOMS | 2 |
| 2014 | Detect Fast-Flux Domains Through Response Time DifferencesabstractA fast-flux service network (FFSN) uses dynamic DNS to map a dynamic domain, called fast-flux domain (FF domain), to various IP addresses and uses flux bots to redirect network traffic. Due to its powerful capability to conceal the hosts hidden behind the flux bots, FFSNs are widely adopted by attackers to cover various scams. Although diverse promising solutions have been proposed to detect FF domains, they face the same problem-different countermeasures could be used to bypass their detection. Hence, it becomes a critical issue to develop a new detection solution. According to our survey, unlike normal network services that use dynamic DNS to balance the workloads of their hosts, FFSNs utilize dynamic DNS to hide important bots. As a result, the response time of subsequent requests to an FF domain becomes more fluctuating. Based on the response time differences, this paper develops a new metric, Fast-Flux Score (FF-Score), to detect FF domains. Our system, called fast-flux domain detector (FFDD), is used on a computer that could be an end host or an IDS. A user with a set of unknown URLs, which may be obtained from spam or social networks, can simply determine whether they are benign domains or fast-flux ones using FFDD. Experimental results show that FFDD can accurately detect FF domains with only a 0.3% false positive rate and a 2% false negative rate. It takes less than 20 min for FFDD to determine whether a domain is an FF domain. In addition, FFDD is a lightweight stand-alone system; hence, it does not require special support from an ISP or any other network service. Fu-Hau Hsu, Chuan-Sheng Wang, Chi-Hsien Hsu, Chang-Kuo Tso, Li-Han Chen, Song-Hui Lin |
IEEE J. Sel. Areas Commun. | 1 |
| 2014 | Image reversibility in data embedding on the basis of blocking-predictions
Fu-Hau Hsu, Min-Hao Wu, Cheng-Hsing Yang, Shiuh-Jeng Wang |
Peer-to-Peer Netw. Appl. | 1 |
| 2014 | Visible watermarking with reversibility of multimedia images for ownership declarations
Fu-Hau Hsu, Min-Hao Wu, Cheng-Hsing Yang, Shiuh-Jeng Wang |
J. Supercomput. | 1 |
| 2013 | Reversible data hiding using side-match predictions on steganographic images
Fu-Hau Hsu, Min-Hao Wu, Shiuh-Jeng Wang |
Multim. Tools Appl. | 1 |
| 2013 | Reversibility of image with balanced fidelity and capacity upon pixels differencing expansion
Fu-Hau Hsu, Min-Hao Wu, Shiuh-Jeng Wang, Chia-Ling Huang |
J. Supercomput. | 1 |
| 2012 | Antivirus Software Shield Against Antivirus TerminatorsabstractIn the last several decades, the arms race between malware writers and antivirus programmers has become more and more severe. The simplest way for a computer user to secure his computer is to install antivirus software on his computer. As antivirus software becomes more sophisticated and powerful, evading the detection of antivirus software becomes an important part of malware. As a result, malware writers have developed various approaches to increase the survivability and concealment of their malware. One of these technologies is to terminate antivirus software right after the execution of the malware. In this paper, we propose a mechanism, called ANtivirus Software Shield (ANSS), to prevent antivirus software from being terminated without the consciousness of the antivirus software users. ANSS uses System Service Descriptor Table (SSDT) hooking to intercept specific Windows APIs and analyzes them to filter out hazardous API calls that will terminate antivirus software. When using several pieces of malware that can terminate various brands of antivirus applications to make our experiments, the results show that ANSS can protect antivirus software from being terminated by them with at most 0.42% CPU performance overhead and 1.77% memory write performance overhead. Fu-Hau Hsu, Min-Hao Wu, Chang-Kuo Tso, Chi-Hsien Hsu, Chieh-Wen Chen |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2011 | BrowserGuard: A Behavior-Based Solution to Drive-by-Download AttacksabstractAlong with an increasing user population of various web applications, browser-based drive-by-download attacks soon become one of the most common security threats to the cyber community. A user using a vulnerable browser or browser plug-ins may become a victim of a drive-by-download attack right after visiting a vicious web site. The end result of such attacks is that an attacker can download and execute any code on the victim's host. This paper proposes a runtime, behavior-based solution, BrowserGuard, to protect a browser against drive-by-download attacks. BrowserGuard records the download scenario of every file that is loaded into a host through a browser. Then based on the download scenario, BrowserGuard blocks the execution of any file that is loaded into a host without the consent of a browser user. Due to its behavior-based detection nature, BrowserGuard does not need to analyze the source file of any web page or the run-time states of any script code, such as Javascript. BrowserGuard also does not need to maintain any exploit code samples and does not need to query the reputation value of any web site. We utilize the standard BHO mechanism of Windows to implement BrowserGuard on IE 7.0. Experimental results show that BrowserGuard has low performance overhead (less than 2.5%) and no false positives and false negatives for the web pages used in our experiments. Fu-Hau Hsu, Chang-Kuo Tso, Yi-Chun Yeh, Wei-Jen Wang, Li-Han Chen |
IEEE J. Sel. Areas Commun. | 1 |
| 2010 | Actor Garbage Collection Using Vertex-Preserving Actor-to-Object Graph Transformations
Wei-Jen Wang, Carlos A. Varela, Fu-Hau Hsu, Cheng-Hsien Tang |
GPC | 3 |
| 2010 | A neural tree and its application to spam e-mail detection
Mu-Chun Su, Hsu-Hsun Lo, Fu-Hau Hsu |
Expert Syst. Appl. | 3 |
| 2010 | HSP: A solution against heap sprays
Fu-Hau Hsu, Cheng-Hsien Huang, Chi-Hsien Hsu, Chih-Wen Ou, Li-Han Chen, Ping-Cheng Chiu |
J. Syst. Softw. | 1 |
| 2006 | Scalable network-based buffer overflow attack detectionabstractBuffer overflow attack is the main attack method that most if not all existing malicious worms use to propagate themselves from machine to machine. Although a great deal of research has been invested in defense mechanisms against buffer overflow attack, most of them require modifications to the network applications and/or the platforms that host them. Being an extension work of CTCP, this paper presents a network-based low performance overhead buffer overflow attack detection system called Nebula 1 NEtwork-based BUffer overfLow Attack detection, which can detect both known and zero-day buffer overflow attacks based solely on the packets observed without requiring any modifications to the end hosts. Moreover, instead of deriving a specific signature for each individual buffer overflow attack instance, Nebula uses a generalized signature that can capture all known variants of buffer overflow attacks while reducing the number of false positives to a negligible level. In addition, Nebula is built on a centralized TCP/IP architecture that effectively defeats all existing NIDS evasion techniques. Finally, Nebula incorporates a payload type identification mechanism that reduces further the false positive rate and scales the proposed buffer overflow attack detection scheme to gigabit network links. Fu-Hau Hsu, Fanglu Guo, Tzi-cker Chiueh |
ANCS | 1 |
| 2004 | CTCP: A Transparent Centralized TCP/IP Architecture for Network SecurityabstractMany nework security problems can be solved in a centralized TCP (CTCP) architecture, in which an organization's edge router transparently proxies every TCP connection between an internal host and an external host on the Internet. This paper describes the design, implementation, and evaluation of a CTCP router prototype that is built on the Linux kernel. By redirecting all packets targeting at nonexistent or nonopen-to-public ports to a CTCP socket which pretends to be the original receivers, CTCP could confirm the real identification of the packet sources, collect suspicious traffic from them, and make an illusion that the scanned target ports are all open, thus renders port scanning an useless effort. Under CTCP architecture, external hosts only interacts with a secure CTCP router; therefore, any OS fingerprinting attempt and DoS/DDoS attack targeting at TCP/IP implementation bugs could be thwarted. Moreover, By further checking traffic originating from confirmed scanners, the CTCP router can actually identify buffer overflow attack traffic. Finally, the CTCP router solves the TCP connection hijacking problem by introducing an additional check on the sequence number filed of incoming packets. Despite providing a rich variety of protection, the CTCP architecture does not incur much overhead. On a 1.1 GHz Pentium-3 machine with gigabit Ethernet interfaces, the throughput of the CTCP router is 420.3 Mbits/sec, whereas the throughput of a generic Linux router on the same hardware is only 409.1 Mbits/sec. Fu-Hau Hsu, Tzi-cker Chiueh |
ACSAC | 1 |
| 2003 | A Path Information Caching and Aggregation Approach to Traffic Source IdentificationabstractProbabilistic packet marking (PPM) is a technique designed to identify packet traffic sources with low storage and processing overhead on network routers. In most previous PPM approaches, individual path messages carry only partial path information. These methods are susceptible to "path falsification" attacks, which greatly reduce their effectiveness. This work proposes a path-falsification-attack free PPM algorithm called Path Information Caching and Aggregation (PICA) that records paths of packet streams in fix-length path messages, thus eliminating the need of path reconstruction at the receiver end. Besides, by using a router's forwarding table to decompose packet volume, this semi-stateful method is more accurate in traffic volume report. It also supports both a packet rate-based path message generation algorithm and a redundant path message suppression mechanism to further eliminate path messages with the same destination. Finally, PICA protects PICA routers from being attacked by faked path messages. We have performed a trace-driven simulation study on the proposed PICA algorithm and compared its effectiveness with IETF's iTrace scheme by varying the sampling probability, the number of attack sources, and attack traffic rate. Compared to iTrace, the PICA algorithm reduces the total number of path messages required by a factor of more than 2, while reporting traffic volume more accurately. Fu-Hau Hsu, Tzi-cker Chiueh |
ICDCS | 1 |
| 2002 | Sago: A Network Resource Management System for Real-Time Content DistributionabstractContent replication and distribution is an effective technology to reduce the response time for Web accesses and has been proven quite popular among large Internet content providers. However, existing content distribution systems assume a store-and-forward delivery model and is mostly based on static content. This paper describes the design, implementation, and initial evaluation of a network resource management system for real-time Internet content distribution called Sago, which provides facilities to provision and allocate network resources so that multiple bandwidth-guaranteed and fault-tolerant multicast connections can be multiplexed on a single physical network. Sago includes a novel network resource mapping algorithm that takes into account both physical network topology and dynamic traffic demands, a network-wide fault tolerance mechanism that supports both node-level and link-level fault tolerance, and a hierarchical network link scheduler that provides performance protection among multicast connections sharing the same physical network link. Moreover, Sago does not require any IP multicasting support from underlying network routers because it performs application-level multicasting. The technologies underlying Sago are important building blocks for real-time content distribution networks, end-to-end quality of service guarantee over global corporate intranets, and application-specific adaptation of wide-area network services. Tzi-cker Chiueh, Kartik Gopalan, Anindya Neogi, Srikant Sharma, Sheng-Ming Shan, Jiawu Chen, Wei Li 0020, Nikolai Joukov, Fu-Hau Hsu, Fanglu Guo, Sheng-I Doong |
ICPADS | 11 |
| 2001 | RAD: A Compile-Time Solution to Buffer Overflow AttacksabstractBuffer overflow attack can inflict upon almost arbitrary programs and is one of the most common vulnerabilities that can seriously compromise the security of a network-attached computer system. This paper presents a compiler-based solution to the notorious buffer overflow attack problem. Using this solution, users can prevent attackers from compromising their systems by changing the return address to execute injected code, which is the most common method used in buffer overflow attacks. Return address defender (RAD) is a simple compiler patch that automatically creates a safe area to store a copy of return addresses and automatically adds protection code into applications that it compiles to defend programs against buffer overflow attacks. Using it to protect a program does not need to modify the source code of the protected programs. Moreover, RAD does not change the layout of stack frames, so binary code it generated is compatible with existing libraries and other object files. Empirical performance measurements on a fully operational RAD prototype show that programs protected by RAD only experience a factor of between 1.01 to 1.31 slow-down. In this paper we present the principle of buffer overflow attacks, a taxonomy of defense methods, the implementation details of RAD, and the performance analysis of the RAD prototype. Tzi-cker Chiueh, Fu-Hau Hsu |
ICDCS | 2 |