EDBT 2026 Demo / reviewers in the wild / expert
Zhi Xue
dblp:44/3322
· DBLP profile ↗
49ranked-venue papers
0as first author
40since 2021 · last 2026
0000-0003-2875-304XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 15 since 2021Computer networks · 15 · 13 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Z-Solver: A Zero-Label Captcha Solver via Unsupervised Domain Adaptation from Synthetic Data
Weiqi Bai, Xianwen Deng, Zhi Xue |
ICC | 5 |
| 2026 | RateSniffer: A Lightweight and Robust Website Fingerprinting Defense via Rate-Aware Morphing
Xianwen Deng, Weiqi Bai, Zhi Xue |
ICC | 5 |
| 2026 | Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP EcosystemabstractLarge language models(LLMs) are increasingly integrated with external systems through the Model Context Protocol(MCP),which standardizes tool invocation and has rapidly become a backbone for LLM-powered applications. While this paradigm enhances functionality,it also introduces a fundamental security shift:LLMs transition from passive information processors to autonomous orchestrators of task-oriented toolchains,expanding the attack surface,elevating adversarial goals from manipulating single outputs to hijacking entire execution flows. In this paper,we identify and characterize a systematic privacy-leakage attack pattern,termed Parasitic Toolchain Attacks,instantiated as MCP Unintended Privacy Disclosure(MCP-UPD). These attacks require no direct victim interaction;instead,adversaries embed malicious instructions into external data sources that LLMs access during legitimate tasks. Unlike traditional prompt injection and tool poisoning attacks,our attack targets the interconnected toolchain itself,assembling multiple legitimate tools into a coordinated workflow whose combined behavior accomplishes malicious objectives. In MCP-UPD,the malicious logic infiltrates the toolchain and unfolds in three phases:Parasitic Ingestion,Privacy Collection,and Privacy Disclosure,culminating in stealthy exfiltration of private data. Our root cause analysis reveals that MCP lacks both context-tool isolation and least-privilege enforcement,enabling adversarial instructions to propagate unchecked into sensitive tool invocations. To assess the severity,we design MCP-SEC and conduct the first large-scale security census of the MCP ecosystem,analyzing 12230 tools across 1360 servers. Our findings show that the MCP ecosystem is rife with real-world exploitable gadgets and diverse attack methods,underscoring systemic risks in MCP platforms and the urgent need for defense mechanisms in LLM-integrated environments. Shuli Zhao, Qinsheng Hou, Zihan Zhan, Yuchong Xie, Libo Chen 0001, Shenghong Li 0001, Zhi Xue |
SP | 9 |
| 2026 | Learning Flow Semantics for Encrypted Traffic Analysis: A Contrastive Pre-Training ApproachabstractEncrypted traffic analysis is crucial for cyberspace security. Self-supervised learning shows great promise to enhance traffic analysis with the pre-trained traffic encoder, which is constructed using large-scale, readily available unlabeled traffic data. However, existing approaches struggle to handle the increasingly prevalent encrypted traffic, as their generative reconstruction tasks cannot process encrypted content. To this end, we propose TACO, a robust and flexible encrypted traffic analysis system based on flow semantics learning. Specifically, we first design several feasible traffic data augmentation strategies to prepare flow semantics knowledge from the unlabeled traffic. Then, our traffic encoder with a traffic partition module learns the semantics knowledge based on the contrastive pre-training paradigm. It serves as a traffic foundation encoder that can comprehend flow semantics and extract effective semantic representations. Finally, we fine-tune the traffic encoder to leverage flow semantics for various downstream encrypted traffic analysis tasks. The experimental results illustrate that TACO outperforms the optimal baseline by 7.5% in average F1 score on four traffic classification datasets and achieves an improvement of at least 11.62% in average F1 score on the three transfer tasks, while indicating superior efficiency. We will release the source code as well as the experiment data upon publication to foster future research. Ruijie Zhao 0001, Mingwei Zhan, Qi Li 0002, Zhuotao Liu, Xianwen Deng, Guang Cheng 0001, Zhi Xue, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2025 | Leveraging Frozen Batch Normalization for Co-Training in Source-Free Domain AdaptationabstractSource-free domain adaptation (SFDA) aims to adapt a source model, initially trained on a fully-labeled source domain, to an unlabeled target domain. Previous works assume that the statistics of Batch Normalization layers in the source model capture domain-specific knowledge and directly replace them with target domain-related statistics during training. However, our observations indicate that \emph{source-like} samples in target data exhibit less deviation in the feature space of the source model when preserving the source domain-relevant statistics. In this paper, we propose co-training the source model with frozen Batch Normalization layers as part of the domain adaptation process. Specifically, we combine the source model and the target model to produce more robust pseudo-labels for \emph{global} class clustering and to identify more precise neighbor samples for \emph{local} neighbor clustering. Extensive experiments validate the effectiveness of our approach, showcasing its superiority over current state-of-the-art methods on three standard benchmarks. Our codes are available on \url{https://github.com/SJTU-dxw/BN-SFDA.} Xianwen Deng, Zhi Xue |
AISTATS | 3 |
| 2025 | Robust Training of Efficient Traffic Classifier with Noisy Labels
Zuoyu Qiu, Mingwei Zhan, Xianwen Deng, Zhi Xue, Ruijie Zhao 0001 |
Inscrypt (2) | 4 |
| 2025 | Detecting Malicious Encrypted Traffic with Multimodal RepresentationsabstractThe rapid advancement of encryption technology enhances network security while enabling hidden attackers to avoid detection. Traditional methods for malicious encrypted traffic detection, which predominantly rely on a single modality such as statistical features or content representations, often fall short of adapting to dynamic network environments. Methods based on graph representations grapple with challenges such as insufficient modeling of the encryption properties and substantial computational resource requirements. Multimodal-based methods seldom consider the graph-based dynamic representation and often overlook the differences in feature spaces. Moreover, these methods are not evaluated for universality across platforms. To solve challenges above, we propose M2D, a multimodal-based framework for malicious encrypted traffic detection suitable for all versions of TLS protocols. M2D extracts (a) heterogeneous graph representation from spatial and temporal features to capture both dynamic patterns and complex interactions between different entities; (b) ciphertext visual representation to enhance content encapsulation; and (c) plaintext representation to explore semantics, then fuses them through the multi-head attention mechanism to emphasize more effective components. Furthermore, we set up an encrypted network traffic dataset generated by sandbox, with session keys embedded for decryption. Experimental results on both public and proposed datasets demonstrate the superior performance of M2D in binary and multi-class classification tasks. Additionally, ablation studies confirm the effectiveness of each component. Ruijie Zhao 0001, Libo Chen 0001, Lingyun Ying, Zhengguang Han, Zhi Xue |
ICC | 7 |
| 2025 | Multi-modal Datagram Representation with Spatial-Temporal State Space Models and Inter-flow Contrastive Learning for Encrypted Traffic Classification
Xianwen Deng, Ruijie Zhao 0001, Mingwei Zhan, Shaoqian Wu, Zhi Xue |
ICICS (3) | 6 |
| 2025 | FlowRefiner: A Robust Traffic Classification Framework against Label NoiseabstractNetwork traffic classification is essential for network management and security. In recent years, deep learning (DL) algorithms have emerged as essential tools for classifying complex traffic. However, they rely heavily on high-quality labeled training data. In practice, traffic data is often noisy due to human error or inaccurate automated labeling, which could render classification unreliable and lead to severe consequences. Although some studies have alleviated the label noise issue in specific scenarios, they are difficult to generalize to general traffic classification tasks due to the inherent semantic complexity of traffic data. In this paper, we propose FlowRefiner, a robust and general traffic classification framework against label noise. FlowRefiner consists of three core components: a traffic semantics-driven noise detector, a confidence-guided label correction mechanism, and a cross-granularity robust classifier. First, the noise detector utilizes traffic semantics extracted from a pre-trained encoder to identify mislabeled flows. Next, the confidence-guided label correction module fine-tunes a label predictor to correct noisy labels and construct refined flows. Finally, the cross-granularity robust classifier learns generalized patterns of both flow-level and packet-level, improving classification robustness against noisy labels. We evaluate our method on four traffic datasets with various classification scenarios across varying noise ratios. Experimental results demonstrate that FlowRefiner mitigates the impact of label noise and consistently outperforms state-of-the-art baselines by a large margin. The code is available at https://github.com/NSSL-SJTU/FlowRefiner. Mingwei Zhan, Ruijie Zhao 0001, Xianwen Deng, Zhi Xue, Qi Li 0002, Zhuotao Liu, Guang Cheng 0001, Ke Xu 0002 |
NeurIPS | 4 |
| 2025 | Countmamba: A Generalized Website Fingerprinting Attack via Coarse-Grained Representation and Fine-Grained PredictionabstractTor is the leading low-latency anonymous communication network, widely used to protect users' privacy through mechanisms such as random relay selection. However, despite these defenses, Tor traffic remains susceptible to website finger-printing (WF) attacks, where attackers analyze side-channel information (e.g., packet size, direction, inter-packet timing) to infer visited websites. Although WF attacks have shown high success rates in controlled settings, they rely on complete, unperturbed traffic, making them vulnerable to real-world de-fense mechanisms. Traditional WF approaches, which typically employ Machine Learning (ML) or Deep Learning (DL) to classify packet sequences as a single-label prediction, struggle to generalize in practical scenarios, especially under defenses that alter packet patterns or in environments requiring multi-label, early-stage analysis. In this work, we introduce Countmamba, a robust and adaptable WF attack framework designed to address the challenges posed by real-world defenses, early-stage traffic analysis, and multi-tab browsing. Countmamba employs a Windowed Traffic Counting Matrix (WTCM) to create re-silient, coarse-grained traffic representations by aggregating packet events within fixed time intervals, allowing it to with-stand moderate perturbations from defenses. Additionally, a state-space-oriented (SSO) classifier incrementally generates fine-grained predictions from partial traffic data, maintaining high attack accuracy while enabling early-stage and multi-tab attack capabilities. Unlike prior WF methods, Countmamba iteratively updates predictions as new data arrives, eliminating the need for complete traffic capture and enabling reliable inference even in complex, multi-tab environments. Extensive experiments demonstrate that Countmamba outperforms state-of-the-art WF attacks across robust, early-stage, and multi-tab scenarios, highlighting its applicability for realistic, adaptive WF analysis in Tor networks. The source code as well as the experiment data is available at https://github.com/SJTU-dxw/CountMamba-WF. Xianwen Deng, Ruijie Zhao 0001, Mingwei Zhan, Zhi Xue |
SP | 5 |
| 2025 | Dr. Docker: A Large-Scale Security Measurement of Docker Image EcosystemabstractDocker has transformed modern software development, enabling the widespread reuse of containerized applications. Currently, Docker images are primarily distributed through centralized registries, among which Docker Hub is the largest, allowing developers to share and reuse images easily. The threats within these images also spread through the supply chain via dependency relationships, posing risks to anyone using the image and all images built based on it. However, it is unclear to what extent the threats within Docker images are distributed and propagated. Hequan Shi, Lingyun Ying, Libo Chen 0001, Hai-Xin Duan, Zhi Xue |
WWW | 6 |
| 2025 | A combined feature selection approach for malicious email detection based on a comprehensive email datasetabstractAbstract In recent years, new malicious email attacks have emerged. We summarize two major challenges in the current field of malicious email detection using machine learning algorithms. (1) Current works on malicious email detection use different datasets and lack a unified and comprehensive open source dataset standard for evaluating detection performance. In addition, outdated data makes it difficult to detect new types of malicious email attacks. (2) There are limitations in feature selection and extraction. Relying only on static features or body textual features cannot satisfy the detection of both common phishing or spam email and new malicious emails that exploit protocol vulnerabilities. To address these problems, we propose the Exploiting Protocol Vulnerability Malicious Email (EPVME) dataset, which contains 49,136 malicious email samples. The EPVME dataset is constructed by summarizing and simulating the novel types of malicious email attacks that exploit email protocol vulnerabilities. In our dataset, the coverage of the types of malicious emails and the number of them are significantly increased. By collecting the currently available open source datasets, we build a large-scale dataset with 660,985 samples. Through two sets of comparative experiments on the dataset containing EPVME, we verify the necessity, reliability, and validity of the EPVME dataset. By using a large and comprehensive open source email dataset, we hope to help subsequent work on malicious email detection achieve comparative performance. Furthermore, we propose a new feature selection and construction method that combines both static features and textual features. We extract 79 static features from both the header and body parts of email samples, perform textual feature extraction on the pre-processed body parts, and combine various machine learning algorithms for detection model construction and experimental comparison. Our detection model can achieve an accuracy of 99.968% and a false positive rate of 0.099%. Libo Chen 0001, Zhi Xue |
Cybersecur. | 6 |
| 2025 | Enhancing Real-Time Operating System Security Analysis via Slice-Based Fuzzing
Yuchong Xie, Qinsheng Hou, Libo Chen 0001, Bo Zhang 0063, Shenghong Li 0001, Zhi Xue |
IEEE Trans. Software Eng. | 9 |
| 2024 | Vulnerability-oriented Testing for RESTful APIs
Wenlong Du, Libo Chen 0001, Ruijie Zhao 0001, Junmin Zhu, Zhengguang Han, Zhi Xue |
USENIX Security Symposium | 9 |
| 2024 | Code is not Natural Language: Unlock the Power of Semantics-Oriented Graph Representation for Binary Code Similarity Detection
Haojie He, Xingwei Lin, Ziang Weng, Ruijie Zhao 0001, Shuitao Gan, Libo Chen 0001, Yuede Ji, Jiashui Wang, Zhi Xue |
USENIX Security Symposium | 9 |
| 2024 | AN-Net: an Anti-Noise Network for Anonymous Traffic Classification
Xianwen Deng, Zhi Xue |
WWW | 3 |
| 2024 | SaTC: Shared-Keyword Aware Taint Checking for Detecting Bugs in Embedded SystemsabstractIoT devices have brought invaluable convenience to our daily life. However, their pervasiveness also amplifies the impact of security vulnerabilities. Many widespread vulnerabilities of embedded systems reside in their vulnerable border services. Unfortunately, existing vulnerability detection methods can neither effectively nor efficiently analyze such border services: they either introduce heavy execution overheads or have many false positives and negatives. In this paper, we propose a novel static taint checking solution, SaTC, to effectively detect security vulnerabilities in border services provided by embedded devices. Our key insight is that string literals on border interfaces are commonly shared between front-end files and back-end binaries to encode user input. Thus, we extract common keywords from the front-end and use them to locate reference points in the back-end, which indicate the input entry. Then, we apply targeted data-flow analysis to detect dangerous uses of the untrusted user input accurately. We implemented a prototype of SaTC and evaluated it on 39 firmware samples from six popular vendors. SaTC discovered 36 unknown bugs, of which CVE/CNVD/PSV confirms 33. Compared to the state-of-the-art tool KARONTE, SaTC found significantly more bugs in the test set. It shows that SaTC is effective in discovering bugs in embedded systems. Libo Chen 0001, Jiaqi Linghu, Qinsheng Hou, Quanpu Cai, Shanqing Guo, Zhi Xue |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | A Novel Self-Supervised Framework Based on Masked Autoencoder for Traffic ClassificationabstractTraffic classification is a critical task in network security and management. Recent research has demonstrated the effectiveness of the deep learning-based traffic classification method. However, the following limitations remain: (1) the traffic representation is simply generated from raw packet bytes, resulting in the absence of important information; (2) the model structure of directly applying deep learning algorithms does not take traffic characteristics into account; and (3) scenario-specific classifier training usually requires a labor-intensive and time-consuming process to label data. In this paper, we introduce a masked autoencoder (MAE) based traffic transformer with multi-level flow representation to tackle these problems. To model raw traffic data, we design a formatted traffic representation matrix with hierarchical flow information. After that, we develop an efficient Traffic Transformer, in which packet-level and flow-level attention mechanisms implement more efficient feature extraction with lower complexity. At last, we utilize MAE paradigm to pre-train our classifier with a large amount of unlabeled data, and perform fine-tuning with a few labeled data for a series of traffic classification tasks. Experiment findings reveal that our method outperforms state-of-the-art methods on five real-world traffic datasets by a large margin. The code is available at https://github.com/NSSL-SJTU/YaTC. Ruijie Zhao 0001, Mingwei Zhan, Xianwen Deng, Fangqi Li 0001, Guan Gui 0001, Zhi Xue |
IEEE/ACM Trans. Netw. | 8 |
| 2023 | Yet Another Traffic Classifier: A Masked Autoencoder Based Traffic Transformer with Multi-Level Flow RepresentationabstractTraffic classification is a critical task in network security and management. Recent research has demonstrated the effectiveness of the deep learning-based traffic classification method. However, the following limitations remain: (1) the traffic representation is simply generated from raw packet bytes, resulting in the absence of important information; (2) the model structure of directly applying deep learning algorithms does not take traffic characteristics into account; and (3) scenario-specific classifier training usually requires a labor-intensive and time-consuming process to label data. In this paper, we introduce a masked autoencoder (MAE) based traffic transformer with multi-level flow representation to tackle these problems. To model raw traffic data, we design a formatted traffic representation matrix with hierarchical flow information. After that, we develop an efficient Traffic Transformer, in which packet-level and flow-level attention mechanisms implement more efficient feature extraction with lower complexity. At last, we utilize the MAE paradigm to pre-train our classifier with a large amount of unlabeled data, and perform fine-tuning with a few labeled data for a series of traffic classification tasks. Experiment findings reveal that our method outperforms state-of-the-art methods on five real-world traffic datasets by a large margin. The code is available at https://github.com/NSSL-SJTU/YaTC. Ruijie Zhao 0001, Mingwei Zhan, Xianwen Deng, Guan Gui 0001, Zhi Xue |
AAAI | 7 |
| 2023 | VD-Guard: DMA Guided Fuzzing for Hypervisor Virtual DeviceabstractVirtualization has been widely used in various scenarios, such as cloud computing. As its core technology, virtualization hypervisor brings up the efficiency of sharing the physical machine's resources via virtual devices. However, virtualization hypervisor also introduces significant security risks due to defective design or implementation schemes on virtual devices. Although several methods have been proposed to detect vulnerabilities in virtual devices, they still cannot effectively discover them because of missing critical information related to the MMIO/PIO and DMA operations to guide their dynamic methods. In this paper, we propose a hybrid method, VD-GUARD, to detect vulnerabilities in virtual devices. Specifically, it first leverages static control flow analysis to track call traces from various data entry points of virtual devices (MMIO/PIO functions) to the critical dispatcher points (DMA functions), and generate seeds that can trigger this call trace via static analysis and limited fuzzing test. And then, it takes these seeds as input and leverages DMA guided fuzzing to discover bugs. To verify the effectiveness of Vd-guard, we build a dataset, including 10 bugs in QEMU, based on previous works, and Vd-guardoutperforms the state-of-the-art hypervisor fuzzer Morphuzz. Vd-guardalso has found 4 new vulnerabilities in QEMU and VirtualBox, all of which have been confirmed and fixed (have been assigned 3 CVE IDs). Yuwei Liu 0001, Yuchong Xie, Libo Chen 0001, Yingming Zeng, Zhi Xue, Purui Su |
ASE | 8 |
| 2023 | Both Sides Needed: A Two-Dimensional Measurement Study of Email Security Based on SPF and DMARCabstractAs important email authentication protocols, SPF and DMARC can effectively reduce the risk of spoofing and improve the security of email systems. In this paper, we perform, for the first time, a comprehensive and integrated measurement of the state of SPF and DMARC adoption on the Alexa Top Million Domains in 2023, both in two dimensions with email sending and receiving. We provide a detailed analysis and comparison of the results. Our measurement shows that the number of domains configured with SPF and DMARC records is increasing while the number of invalid records is also growing. Among domains with email sending/receiving capabilities, approximately 27% of domain mail servers cannot verify the SPF and DMARC of received emails. Email security must be achieved on both the sending and receiving sides. We recommend that all domain administrators pay more attention to the systemic issues of SPF and DMARC deployments. Libo Chen 0001, Zhi Xue |
MSN | 6 |
| 2023 | SAWD: Structural-Aware Webshell Detection System with Control Flow GraphabstractWith the increasing prevalence of web servers, protecting them from cyber attacks has become a crucial task for online service providers.Webshells, which are backdoors to websites, are commonly used by hackers to gain unauthorized access to web servers.However, traditional methods for detecting webshells often fail to produce satisfactory results due to the use of obfuscation or encryption to conceal their characteristics.In recent years, webshell detection methods based on deep learning (DL) have received significant attention, but they struggle to preserve the syntax and semantic information contained in the source code.In this paper, we propose a structuralaware webshell detection system to address these problems, denoted as SAWD.Specifically, we first generate the control flow graph (CFG) with syntax and semantic information from the PHP source code.Then, we leverage CFG to build our graph representation, which consists of the adjacency matrix and keywords-based basic block features.Finally, based on our graph representation, we adopt convolutional neural networks (GCN) combined with graph pooling to detect webshells more efficiently.Experimental results demonstrate that our method outperforms state-of-the-art webshell detection systems on the collected dataset. Junmin Zhu, Yizhao Yao, Xianwen Deng, Yaoguang Yong, Libo Chen 0001, Zhi Xue, Ruijie Zhao 0001 |
SEKE | 7 |
| 2023 | GeeSolver: A Generic, Efficient, and Effortless Solver with Self-Supervised Learning for Breaking Text CaptchasabstractAlthough text-based captcha, which is used to differentiate between human users and bots, has faced many attack methods, it remains a widely used security mechanism and is employed by some websites. Some deep learning-based text captcha solvers have shown excellent results, but the labor-intensive and time-consuming labeling process severely limits their viability. Previous works attempted to create easy-to-use solvers using a limited collection of labeled data. However, they are hampered by inefficient preprocessing procedures and inability to recognize the captchas with complicated security features.In this paper, we propose GeeSolver, a generic, efficient, and effortless solver for breaking text-based captchas based on self-supervised learning. Our insight is that numerous difficult-to-attack captcha schemes that "damage" the standard font of characters are similar to image masks. And we could leverage masked autoencoders (MAE) to improve the captcha solver to learn the latent representation from the "unmasked" part of the captcha images. Specifically, our model consists of a ViT encoder as latent representation extractor and a well-designed decoder for captcha recognition. We apply MAE paradigm to train our encoder, which enables the encoder to extract latent representation from local information (i.e., without masking part) that can infer the corresponding character. Further, we freeze the parameters of the encoder and leverage a few labeled captchas and many unlabeled captchas to train our captcha decoder with semi-supervised learning.Our experiments with real-world captcha schemes demonstrate that GeeSolver outperforms the state-of-the-art methods by a large margin using a few labeled captchas. We also show that GeeSolver is highly efficient as it can solve a captcha within 25 ms using a desktop CPU and 9 ms using a desktop GPU. Besides, thanks to latent representation extraction, we successfully break the hard-to-attack captcha schemes, proving the generality of our solver. We hope that our work will help security experts to revisit the design and availability of text-based captchas. The code is available at https://github.com/NSSL-SJTU/GeeSolver. Ruijie Zhao 0001, Xianwen Deng, Zhicong Yan, Zhengguang Han, Libo Chen 0001, Zhi Xue |
SP | 7 |
| 2023 | Subdomain Protection is Needed: An SPF and DMARC-Based Empirical Measurement Study and Proactive Solution of Email SecurityabstractSPF and DMARC are two important email authen-tication protocols that can effectively reduce the risk of spoofing attacks and improve email security. In this paper, we provide an empirical measurement study of how well SPF and DMARC are deployed and managed. We perform an active measurement on the Alexa Top Million Domains and their subdomains. For the first time, we present a measurement of subdomain configuration. SPF and DMARC adoption is growing, but still more than 70% of domains do not have proper configurations. More than 90% of all domains lack subdomain configurations. Through experiments, we show that in the absence of effective SPF and DMARC configurations, domains and subdomains can be used by attackers to send spoofed emails. To address this issue, we provide a complete set of proactive email security defense solutions. We summarize detailed mitigation measures and email security assessment methodologies. We also propose the SPF Macro-based Abnormal Email Detection System (SMAEDS), which enables proactive defense against spoofed email attacks. We recommend that the community pay more attention to the systemic issues of SPF and DMARC deployment. We hope that this work can help improve the security of the email ecosystem and reduce the risk of phishing attacks. Dengke Mi, Libo Chen 0001, Zhi Xue |
SRDS | 6 |
| 2023 | Semisupervised Federated-Learning-Based Intrusion Detection Method for Internet of ThingsabstractFederated learning (FL) has become an increasingly popular solution for intrusion detection to avoid data privacy leakage in Internet of Things (IoT) edge devices. Existing FL-based intrusion detection methods, however, suffer from three limitations: 1) model parameters transmitted in each round may be used to recover private data, which leads to security risks; 2) not independent and identically distributed (non-IID) private data seriously adversely affect the training of FL (especially distillation-based FL); and 3) high communication overhead caused by the large model size greatly hinders the actual deployment of the solution. To address these problems, this article develops an intrusion detection method based on a semisupervised FL scheme via knowledge distillation. First, our proposed method leverages unlabeled data via distillation method to enhance the classifier performance. Second, we build a model based on convolutional neural networks (CNNs) for extracting deep features of the traffic packets, and take this model as both the classifier network and discriminator network. Third, the discriminator is designed to improve the quality of each client’s predicted labels, and to avoid the failure of distillation training caused by a large number of incorrect predictions under private non-IID data. Moreover, the combination of the hard-label strategy and voting mechanism further reduces communication overhead. The experiments on the real-world traffic data set with three non-IID scenarios show that our proposed method can achieve better detection performance as well as lower communication overhead than state-of-the-art methods. Ruijie Zhao 0001, Zhi Xue, Tomoaki Ohtsuki, Bamidele Adebisi, Guan Gui 0001 |
IEEE Internet Things J. | 3 |
| 2023 | A Novel Traffic Classifier With Attention Mechanism for Industrial Internet of ThingsabstractWith the development of the Industrial Internet of Things (IIoT), the complex traffic generated by large-scale IIoT devices presents challenges for traffic analysis. Most of existing deep learning-based traffic analysis methods use a single flow for classification, resulting in being misled by the irrelevant flow. Thus, it is necessary to use flow sequences for traffic analysis. However, existing models fail to effectively distinguish unimportant flows in flow sequence, which affects the classification performance. To address the aforementioned challenges, we propose a novel traffic classifier called flow transformer to perform traffic analysis with flow sequences, which leverages multihead attention mechanism to strengthen the information interaction between related flows. Besides, the RF-based feature selection method is designed to select the optimal feature combination, avoiding insignificant features from reducing the performance of the classifier. Experimental results on three real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods with a large margin. Ruijie Zhao 0001, Yiteng Huang, Xianwen Deng, Yong Shi 0009, Jiabin Li, Zijing Huang, Zhi Xue |
IEEE Trans. Ind. Informatics | 8 |
| 2022 | SFuzz: Slice-based Fuzzing for Real-Time Operating SystemsabstractReal-Time Operating System (RTOS) has become the main category of embedded systems. It is widely used to support tasks requiring real-time response such as printers and switches. The security of RTOS has been long overlooked as it was running in special environments isolated from attackers. However, with the rapid development of IoT devices, tremendous RTOS devices are connected to the public network. Due to the lack of security mechanisms, these devices are extremely vulnerable to a wide spectrum of attacks. Even worse, the monolithic design of RTOS combines various tasks and services into a single binary, which hinders the current program testing and analysis techniques working on RTOS. In this paper, we propose SFuzz, a novel slice-based fuzzer, to detect security vulnerabilities in RTOS. Our insight is that RTOS usually divides a complicated binary into many separated but single-minded tasks. Each task accomplishes a particular event in a deterministic way and its control flow is usually straightforward and independent. Therefore, we identify such code from the monolithic RTOS binary and synthesize a slice for effective testing. Specifically, SFuzz first identifies functions that handle user input, constructs call graphs that start from callers of these functions, and leverages forward slicing to build the execution tree based on the call graphs and pruning the paths independent of external inputs. Then, it detects and handles roadblocks within the coarse-grain scope that hinder effective fuzzing, such as instructions unrelated to the user input. And then, it conducts coverage-guided fuzzing on these code snippets. Finally, SFuzz leverages forward and backward slicing to track and verify each path constraint and determine whether a bug discovered in the fuzzer is a real vulnerability. SFuzz successfully discovered 77 zero-day bugs on 35 RTOS samples, and 67 of them have been assigned CVE or CNVD IDs. Our empirical evaluation shows that SFuzz outperforms the state-of-the-art tools (e.g., UnicornAFL) on testing RTOS. Libo Chen 0001, Quanpu Cai, Zhenbang Ma, Hong Hu 0004, Minghang Shen, Shanqing Guo, Hai-Xin Duan, Kaida Jiang, Zhi Xue |
CCS | 11 |
| 2022 | A Lightweight Semi-Supervised Learning Method Based on Consistency Regularization for Intrusion DetectionabstractWith the development of the Industrial Internet of Things (IIoT), more frequent attacks occur to intrude IIoT devices. A reasonably designed intrusion detection method can effectively guarantee the security of IIoT. Over the past decade, different methods of intrusion detection based on deep learning (DL) have been proposed, which helps intrusion detection keep evolving and become more robust. However, these previous researches usually require the participation of a large number of experts, and gradually become invalid with the continuous development of intrusion methods. The limited compute capability of IIoT devices also greatly hinder the deployment of overly complex DL models. To address these challenges, this paper proposes a lightweight semi-supervised learning (LSSL) method based on consistency regularization for intrusion detection. Our proposed method enhances the detection performance by using unlabeled traffic data for consistency training. Besides, we adopt separable convolutions for efficient feature extraction. Experimental results on two widely-used benchmark datasets show that the detection performance of our model is significantly improved by the consistency training, and it can effectively detect various attacks in complex networks. Ruijie Zhao 0001, Tiantian Tang, Guan Gui 0001, Zhi Xue |
ICC | 4 |
| 2022 | A Semi-Supervised Federated Learning Scheme via Knowledge Distillation for Intrusion DetectionabstractFederated learning (FL) has become an increasingly popular solution for intrusion detection to avoid data privacy leakage in Internet of Things (IoT) edge devices. However, most of the current FL-based intrusion detection methods still suffer from three limitations: (1) model parameters transmitted in each round may be used to recover private data which leads to security risks, (2) not independent and identically distributed (non-IID) private data seriously adversely affects the training of FL (especially distillation-based FL), and (3) high communication overhead caused by the large model size greatly hinders the actual deployment of the solution. To address these problems, this paper develops an intrusion detection method based on semi-supervised FL scheme via knowledge distillation. First, our proposed method leverages unlabeled data via distillation method to enhance the classifier performance. Second, we build a CNN-based model for extracting deep features of the traffic packets, and take this model as both the classifier network and discriminator network. Third, discriminator is designed to improve the quality of each client’s predicted labels, to avoid the failure of distillation training caused by a large number of incorrect predictions under private non-IID data. Moreover, the combination of hard-label strategy and voting mechanism further reduces communication overhead. Experimental results on the real-world traffic dataset show that our proposed method can achieve better classification performance as well as lower communication overhead than state-of-the-art methods. Ruijie Zhao 0001, Linbo Yang, Zhi Xue, Guan Gui 0001, Tomoaki Ohtsuki |
ICC | 4 |
| 2022 | 3E-Solver: An Effortless, Easy-to-Update, and End-to-End Solver with Semi-Supervised Learning for Breaking Text-Based CaptchasabstractText-based captchas are the most widely used security mechanism currently. Due to the limitations and specificity of the segmentation algorithm, the early segmentation-based attack method has been unable to deal with the current captchas with newly introduced security features (e.g., occluding lines and overlapping). Recently, some works have designed captcha solvers based on deep learning methods with powerful feature extraction capabilities, which have greater generality and higher accuracy. However, these works still suffer from two main intrinsic limitations: (1) many labor costs are required to label the training data, and (2) the solver cannot be updated with unlabeled data to recognize captchas more accurately. In this paper, we present a novel solver using improved FixMatch for semi-supervised captcha recognition to tackle these problems. Specifically, we first build an end-to-end baseline model to effectively break text-based captchas by leveraging encoder-decoder architecture and attention mechanism. Then we construct our solver with a few labeled samples and many unlabeled samples by improved FixMatch, which introduces teacher forcing, adaptive batch normalization, and consistency loss to achieve more effective training. Experiment results show that our solver outperforms state-of-the-arts by a large margin on current captcha schemes. We hope that our work can help security experts to revisit the design and usability of text-based captchas. The source code of this work is available at https://github.com/SJTU-dxw/3E-Solver-CAPTCHA. Xianwen Deng, Ruijie Zhao 0001, Libo Chen 0001, Zhi Xue |
IJCAI | 6 |
| 2022 | Flow Sequence-Based Anonymity Network Traffic Identification with Residual Graph Convolutional NetworksabstractIdentifying anonymity services from network traffic is a crucial task for network management and security. Currently, some works based on deep learning have achieved excellent performance for traffic analysis, especially those based on flow sequence (FS), which utilizes information and features of the traffic flow. However, these models still face a serious challenge because of lacking a mechanism to take into account relationships between flows, resulting in mistakenly recognizing irrelevant flows in FS as clues for identifying traffic. In this paper, we propose a novel FS-based anonymity network traffic identification framework to tackle this problem, which leverages Residual Graph Convolutional Network (ResGCN) to exploit relationships between flows for FS feature extraction. Moreover, we design a practical scheme to preprocess the raw data of real-world traffic, which further improves identification performance and efficiency. Experimental results on two real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods by a large margin. Ruijie Zhao 0001, Xianwen Deng, Libo Chen 0001, Zhi Xue |
IWQoS | 6 |
| 2022 | MT-FlowFormer: A Semi-Supervised Flow Transformer for Encrypted Traffic ClassificationabstractWith the increasing demand for the protection of personal network meta-data, encrypted networks have grown in popularity, so do the challenge of monitoring and analyzing encrypted network traffic. Currently, some deep learning-based methods have been proposed to leverage statistical features for encrypted traffic classification, which are barely affected by encryption techniques. However, these works still suffer from two main intrinsic limitations: (1) the feature extraction process lacks a mechanism to take into account correlations between flows in the flow sequence; and (2) a large volume of manually-labeled data is required for training an effective deep classifier. In this paper, we propose a novel semi-supervised framework to address these problems. To be specific, an efficient classifier with attention mechanism is proposed to extract features from flow sequences with low computational cost. Then, a Mean Teacher-style semi-supervised framework is adopted to exploit the unlabeled traffic data, where a spatiotemporal data augmentation method is designed as the key component to explore the spatial and temporal relationship within the unlabeled traffic data. Experimental results on two real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods with a large margin. Ruijie Zhao 0001, Xianwen Deng, Zhicong Yan, Zhi Xue |
KDD | 5 |
| 2022 | IDSGAN: Generative Adversarial Networks for Attack Generation Against Intrusion Detection
Zilong Lin 0001, Yong Shi 0009, Zhi Xue |
PAKDD (3) | 3 |
| 2022 | A Novel Intrusion Detection Method Based on Lightweight Neural Network for Internet of ThingsabstractThe purpose of a network intrusion detection (NID) is to detect intrusions in the network, which plays a critical role in ensuring the security of the Internet of Things (IoT). Recently, deep learning (DL) has achieved a great success in the field of intrusion detection. However, the limited computing capabilities and storage of IoT devices hinder the actual deployment of DL-based high-complexity models. In this article, we propose a novel NID method for IoT based on the lightweight deep neural network (LNN). In the data preprocessing stage, to avoid high-dimensional raw traffic features leading to high model complexity, we use the principal component analysis (PCA) algorithm to achieve feature dimensionality reduction. Besides, our classifier uses the expansion and compression structure, the inverse residual structure, and the channel shuffle operation to achieve effective feature extraction with low computational cost. For the multiclassification task, we adopt the NID loss that acts as a better loss function to replace the standard cross-entropy loss for dealing with the problem of uneven distribution of samples. The results of experiments on two real-world NID data sets demonstrate that our method has excellent classification performance with low model complexity and small model size, and it is suitable for classifying the IoT traffic of normal and attack scenarios. Ruijie Zhao 0001, Guan Gui 0001, Zhi Xue, Tomoaki Ohtsuki, Bamidele Adebisi, Haris Gacanin |
IEEE Internet Things J. | 3 |
| 2022 | SEAF: A Scalable, Efficient, and Application-independent Framework for container security detectionabstractContainer technology has become a popular development that can conveniently accelerate building, running, and sharing applications. However, a container image packaging a collection of software usually lurks various defects threatening consumer safety, such as embedded malware, software vulnerability, privacy leakage, etc. Moreover, developers and users share container images through a centralized, public, and massive repository (e.g., Docker Hub), which can magnify the impact of these security defects in a fast-spreading way. Unfortunately, existing detection methods cannot effectively or efficiently discover such hidden flaws among the numerous images. This paper proposes a novel method to effectively detect and measure container security flaws embedded in images. Based on the crucial insight that container images are constructed hierarchically, each image depends on layers of forwarding image and adds updated content in layers of itself. Our work mines a Global Relationship Tree (GRT) based on dependency among the images that contain common layers. Meanwhile, by traversing the GRT and leveraging content differential analysis, we can locate the changing content in an image corresponding to defects. Therefore, when checking flaws among numerous images, we make a layer-sensitive detection by reusing common layers’ detection results in iterative processes to boost detection and accurately measure the influence scope of defects. Finally, we summarize and develop a set of detection primitives for scaling our approach to handle various flaws that may lead to multiple risks in potential. Depending upon this method, we implemented SEAF, a Scalable, Efficient, and Application-independent Framework, and evaluated it on popular images of diverse applications in Docker Hub. The experiment result shows that SEAF can discover different security flaws fast. Compared to the state-of-the-art tool, Clair, SEAF is more efficient and can find significantly more types of defects. Libo Chen 0001, Yihang Xia, Zhenbang Ma, Ruijie Zhao 0001, Wenqi Sun, Zhi Xue |
J. Inf. Secur. Appl. | 8 |
| 2021 | An Efficient and Lightweight Approach for Intrusion Detection based on Knowledge DistillationabstractNetwork intrusion detection (NID) is an important cyber security scheme to identify attacks in network traffic. Recent years, a large amount of studies try to improve the accuracy of the NID by kinds of deep learning approaches. However, these models always require a lot of calculation and space, which constitutes a major hurdle to practical implementation of DL-based models. Thus, lightweight model is imperative, but there are very few applications of DL-based lightweight algorithms in NID models. In this paper, we propose a lightweight knowledge distillation (LKD) model for NID using the idea of knowledge distillation and separable convolution. To the best of our knowledge, it is the first system to use the knowledge distillation approach for NID. The experiment results show that the accuracy of the proposed approach reaches 91.46% and 94.30% on the KDD-CUP99 and UNSW-NB15 datasets respectively. The performance of our model is superior to some approaches based on deep neural network or some machine learning methods. Moreover, both the computational cost and model size of our model are reduced by about 99% compared to the original model. Ruijie Zhao 0001, Yong Shi 0009, Zhi Xue |
ICC | 5 |
| 2021 | Flow Transformer: A Novel Anonymity Network Traffic Classifier with Attention MechanismabstractSupervising anonymity network is a critical issue in the field of network security, and traditional traffic analysis methods cannot cope with complex anonymity traffic. In recent years, the traffic analysis method based on deep learning has achieved good performance. However, most of the existing studies do not consider the temporal-spatial correlation of the traffic, and only use a single flow for classification. A few works take continuous flows as flow sequence for traffic classification, but they do not distinguish the different importance of each flow. To tackle this issue, we propose a novel flow-based traffic classifier called FLOW TRANSFORMER to classify anonymity network traffic. FLOW TRANSFORMER uses multi-head attention mechanism to set higher weights for important flows, and extracts flow sequence features according to the importance weights. Besides, the RF-based feature selection method is designed to select the optimal feature combination, which can effectively avoid the insignificant features from reducing the performance and efficiency of the classifier. Experimental results on two real-world traffic datasets demonstrate that the proposed method outperforms state-of-the-art methods with a large margin. Ruijie Zhao 0001, Yiteng Huang, Xianwen Deng, Zhi Xue, Jiabin Li, Zijing Huang |
MSN | 4 |
| 2021 | A Semi-supervised Deep Learning-Based Solver for Breaking Text-Based CAPTCHAsabstractText-based CAPTCHAs are still the most widely used CAPTCHA mode. Many researchers have proposed attack methods to break them. In previous attacks, segmentation-based methods require at least three steps: preprocessing, segmentation, and recognition, which means that different modes of CAPTCHA require various preprocessing and segmentation algorithms. In recent years, a series of deep learning (DL) models have been designed for cracking text-based CAPTCHAs. However, these methods require annotating numerous images, which are time-consuming and labor-intensive. In this paper, we propose a semi-supervised DL-based solver for breaking text-based CAPTCHAs, which can use a small number of labeled CAPTCHAs to achieve a high-performance attack model. The CNN module and the attention-based Seq2Seq module are two key components for effective feature extraction and character recognition. The experimental results show that our solver successfully attacked 9 types of most popular text-based CAPTCHAs, and the attack success rate is better than the four latest attack models. In addition, our model does not perform any data preprocessing and has a fast attack speed, making it more suitable for real-time attacks. The code and dataset are available on the github. Xianwen Deng, Ruijie Zhao 0001, Zhi Xue, Libo Chen 0001 |
TrustCom | 3 |
| 2021 | Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems
Libo Chen 0001, Quanpu Cai, Yunfan Zhan, Hong Hu 0004, Jiaqi Linghu, Qinsheng Hou, Chao Zhang 0008, Hai-Xin Duan, Zhi Xue |
USENIX Security Symposium | 10 |
| 2021 | A Novel Approach based on Lightweight Deep Neural Network for Network Intrusion DetectionabstractWith the ubiquitous network applications and the continuous development of network attack technology, all social circles have paid close attention to the cyberspace security. Intrusion detection systems (IDS) plays a very important role in ensuring computer and communication systems security. Recently, deep learning has achieved a great success in the field of intrusion detection. However, the high computational complexity poses a major hurdle for the practical deployment of DL-based models. In this paper, we propose a novel approach based on a lightweight deep neural network (LNN) for IDS. We design a lightweight unit that can fully extract data features while reducing the computational burden by expanding and compressing feature maps. In addition, we use inverse residual structure and channel shuffle operation to achieve more effective training. Experiment results show that our proposed model for intrusion detection not only reduces the computational cost by 61.99% and the model size by 58.84%, but also achieves satisfactory accuracy and detection rate. Ruijie Zhao 0001, Zhaojie Li, Zhi Xue, Tomoaki Ohtsuki, Guan Gui 0001 |
WCNC | 3 |
| 2020 | A Unified Host-based Intrusion Detection Framework using Spark in CloudabstractThe host-based intrusion detection system (HIDS) is an essential research domain of cybersecurity. HIDS examines log data of hosts to identify intrusive behaviors. The detection efficiency is a significant factor of HIDS. Traditionally, HIDS is often installed with a standalone mode. Training detection engines with a large amount of data on a single physical computer with limited computing resources may be time-consuming. Therefore, this paper offers a unified HIDS framework based on Spark and deployed in the Google cloud. The framework includes a unified machine learning pipeline to implement scalable and efficient HIDS. Ming Liu 0021, Zhi Xue, Xiangjian He |
TrustCom | 2 |
| 2020 | A PHP and JSP Web Shell Detection System With Text Processing Based On Machine LearningabstractWeb shell is one of the most common network attack methods, and traditional detection methods may not detect complex and flexible variants of web shell attacks. In this paper, we present a comprehensive detection system that can detect both PHP and JSP web shells. After file classification, we use different feature extraction methods, i.e. AST for PHP files and bytecode for JSP files. We present a detection model based on text processing methods including TF-IDF and Word2vec algorithms. We combine different kinds of machine learning algorithms and perform a comprehensively controlled experiment. After the experiment and evaluation, we choose the detection machine learning model of the best performance, which can achieve a high detection accuracy above 98%. Han Zhang 0027, Ming Liu 0021, Zihan Yue, Zhi Xue, Yong Shi 0009, Xiangjian He |
TrustCom | 4 |
| 2018 | Character-Level Intrusion Detection Based On Convolutional Neural NetworksabstractDeep learning models are increasingly applied in the intrusion detection system (IDS) and propel its development nowadays. In this paper, a new character-level IDS is proposed based on convolutional neural networks and obtains better performance. Different from other models which are in the feature level, this model is in the character level, which views network traffic records as sequences of characters. Each character of a record is encoded into a vector based on an alphabet. The vectors of the characters in the record are aggregated into a matrix as the input of the convolutional neural networks with an improved structure. This model simplifies the preprocessing without considering the priori knowledge about the data. Experiments on the dataset NSL-KDD show that the binary classification and the multi-classification of our model have good performance. Compared with other machine learning algorithms in term of accuracy, our model outperforms those algorithms. The comparison with the model using convolutional neural networks with the preprocessing in the feature level reveals that our model performs much better with high accuracy, high detection rate and low false alarm rate. Steven Z. Lin, Yong Shi 0009, Zhi Xue |
IJCNN | 3 |
| 2014 | Enhanced MIMOME wiretap channel via adopting full-duplex MIMO radiosabstractIn this paper, secure communication over a multi-input multi-output multi-eavesdropper (MIMÓME) wiretap channel is considered. We propose an enhanced MIMÓME artificial noise (AN) model in which the receiver (Bob) adopts the latest Full-Duplex MIMO Radio technique to emit AN jointly with the transmitter (Alice). An achievable secrecy rate is obtained for this model over an unfavorable noiseless eavesdropping channel. Optimization problem is formulated to solve the beamforming and power allocation for Alice and Bob's transmitting signals and to determine the dimension allocation between the information and AN signals. Simulations are carried out to illustrate the optimization process, and the results show that the enhanced MIMÓME model outperforms existing AN models for low self-interference regime. Yongkai Zhou, Zhi Xue |
GLOBECOM | 3 |
| 2014 | Application of Full-Duplex Wireless Technique into Secure MIMO Communication: Achievable Secrecy Rate based OptimizationabstractThis letter considers the secure MIMO transmission in a wireless environment, in which one transmitter (Alice), one receiver (Bob) and one eavesdropper (Eve) are involved. Apart from the artificial noise (AN) generated by Alice, Bob can also exploit his remaining antenna resources to emit AN to further impair Eve's channel. Such kind of AN can be cancelled by Bob himself by applying the Full-Duplex wireless communication technique. A computable secrecy rate is obtained for this model over a Rayleigh-fading eavesdropping channel. In order to maximize the secrecy rate, a joint optimization scheme is proposed to assign the TX/RX antennas for Bob and to design the beamforming and power allocation for Alice's information and AN signal. Simulation is carried out to illustrate the process of the proposed optimization scheme. Yongkai Zhou, Zheng Zheng Xiang, Zhi Xue |
IEEE Signal Process. Lett. | 4 |
| 2013 | Integrated Network Service to Enhance Multicast CommunicationabstractOne of the features of the Software Defined Network (SDN) is to integrate network service into the network layer to better support the application and alleviate the burden of client-server end. Multicast as an efficient communication method, it can be exploited to provide more meaningful network services to applications which involve one-to-many and many-to-many communication. Traditional multicast implementation mainly emphasizes on low network overhead and its function is kept as simple as possible. This makes multicast vulnerable to misuse. However, when network service is integrated into multicast based on the architecture of SDN, the robustness and security of multicast can be enhanced. This paper proposed a detailed implementation of secure network services to enhance the whole process of the multicast communication. Furthermore, the pricing policy is also discussed for different kinds of multicast application scenarios. Yongkai Zhou, Pengze Guo, Zhi Xue |
DASC | 4 |
| 2013 | Artificial Noise Generated in MIMO Scenario: Optimal Power DesignabstractIn wireless communication, the transmitter (Alice) can send artificial noise (AN) to interfere with the eavesdropper (Eve). This letter considers the AN MIMO scenario, i.e., both Alice and the legitimate receiver (Bob) are equipped with multiple antennas. A closed-form expression for the lower bound of secrecy capacity is obtained. It is proved that water-filling is the optimal power allocation scheme. An efficient iterative algorithm is proposed to find the optimal power distribution ratio between information and AN so that maximum secrecy capacity can be achieved. Simulation results show that the proposed algorithm converges fast, and multiple antennas can improve the secrecy capacity to some extent compared to the AN MISO case. Yongkai Zhou, Shivani Patel, Liang Pang 0003, Zhi Xue |
IEEE Signal Process. Lett. | 6 |
| 2010 | An Efficient Self-Healing Key Distribution with Resistance to the Collusion Attack for Wireless Sensor NetworksabstractThe main property of the self-healing key distribution scheme is that even if during a certain session some broadcast messages are lost due to network faults, the users are still capable of recovering lost session keys on their own, without requesting additional transmission from the group manager. In this paper, we propose and analyze an efficient self-healing key distribution scheme based on vector space secret sharing and one way hash function. We prove that our scheme achieves both forward and backward secrecy and resists to a collusion attack. Zhi Xue |
ICC | 2 |
| 2008 | Attack Grammar: A New Approach to Modeling and Analyzing Network Attack SequencesabstractAttack graphs have been used to show multiple attack paths in large scale networks. They have been proved to be useful utilities for network hardening and penetration testing. However, the basic concept of using graphs to represent attack paths has limitations. In this paper, we propose a new approach, the attack grammar, to model and analyze network attack sequences. Attack grammars are superior in the following areas: First, attack grammars express the interdependency of vulnerabilities better than attack graphs. They are especially suitable for the IDS alerts correlation. Second, the attack grammar can serve as a compact representation of attack graphs and can be converted to the latter easily. Third, the attack grammar is a context-free grammar. Its logical formality makes it better comprehended and more easily analyzed. Finally, the algorithmic complexity of our attack grammar approach is quartic with respect to the number of host clusters, and analyses based on the attack grammar have a run time linear to the length of the grammar, which is quadratic to the number of host clusters. Yinqian Zhang, Xun Fan, Zhi Xue |
ACSAC | 4 |