Zhiyu Hao

dblp:53/5889 · DBLP profile ↗
← Back
52ranked-venue papers
3as first author
28since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 13 since 2021Systems, architecture and hardware · 18 · 4 since 2021Computer networks · 4 · 4 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Offline Policy Enhancement and Transfer by Combining Experimental and External One-Sided Treatment Data
abstract
In this article, we investigate a novel setting for offline policy enhancement and transfer that involves two distinct datasets: an experimental dataset and an external one-sided treatment dataset. The experimental dataset, though unconfounded, is constrained by its small sample. Consequently, methods based solely on the experimental dataset may suffer from low accuracy and limited generalizability. In contrast, the external one-sided treatment dataset typically has a larger sample size but includes observations from only one treatment arm (e.g., all units belong to the control group, with no units receiving the treatment). Based only on the external one-sided treatment dataset, it cannot identify the policy reward. By combining the two datasets, we propose a principled framework to accomplish two key tasks: (1) policy enhancement: improving the accuracy of offline policy evaluation and learning in the experimental dataset by leveraging the external one-sided treatment dataset; (2) policy transfer : enabling offline policy evaluation and learning in the external one-sided treatment dataset by utilizing information from the experimental dataset, and thus making the learned policies applicable to a broader range of data distributions. Extensive experiments demonstrate that our proposed methods not only estimate rewards more accurately but also learn policies that closely approximate the theoretically optimal policy. The code is available at https://anonymous.4open.science/r/Offline-Policy-Enhancement-and-Transfer-E0D1 for double-blind review.
Qinwei Yang, Zhiyu Hao, Peng Wu 0012
KDD (1)3
2026 CTISum: A new benchmark dataset for Cyber Threat Intelligence summarization
Wei Peng 0008, Junmei Ding, Wei Wang 0428, Lei Cui 0003, Zhiyu Hao, Xiao-chun Yun
Comput. Secur.6
2025 BTRFormer: Hierarchical Learning of Encrypted Traffic Using a Masked Autoencoder with Block-Based Traffic Representation
abstract
Encrypted traffic classification (ETC) is essential for ensuring network security and efficient management. Despite advances in deep learning, ETC remains challenging as existing models struggle to learn robust, discriminative representations from content-encrypted, highly imbalanced traffic.To address these challenges, we propose BTRFormer, a novel ETC approach that capitalizes on the inherent properties of encryption algorithms to enhance classification accuracy. At the core of BTRFormer lies a block-based, multi-layer traffic representation that adopts a 4×4 block as the fundamental unit, inspired by the encryption algorithm’s use of 16-byte blocks for encryption operations. This representation preserves the intrinsic structure of encrypted payloads, facilitating the model’s ability to learn deep semantic features. Subsequently, a transformer-based model is employed to learn from the multi-layer representation, capturing intra-block, inter-block, and inter-packet dependencies through block-wise attention mechanisms. Finally, BTRFormer leverages a pre-training phase on large-scale unlabeled data, followed by fine-tuning with a minimal amount of labeled samples to improve generalization and adaptability. Experimental results show that BTRFormer significantly outperforms SOTA methods on six real-world datasets, highlighting its effectiveness in encrypted traffic classification and secure network management.
Junnan Yin, Lei Cui 0003, Zhiyu Hao, Peng Liu 0044, Xiao-chun Yun
ICNP3
2025 Bottom Aggregating, Top Separating: An Aggregator and Separator Network for Encrypted Traffic Understanding
abstract
Encrypted traffic classification refers to the task of identifying the application, service or malware associated with network traffic that is encrypted. Previous methods mainly have two weaknesses. Firstly, from the perspective of word-level (namely, byte-level) semantics, current methods use pre-training language models like BERT, learned general natural language knowledge, to directly process byte-based traffic data. However, understanding traffic data is different from understanding words in natural language, using BERT directly on traffic data could disrupt internal word sense information so as to affect the performance of classification. Secondly, from the perspective of packet-level semantics, current methods mostly implicitly classify traffic using abstractive semantic features learned at the top layer, without further explicitly separating the features into different space of categories, leading to poor feature discriminability. In this paper, we propose a simple but effective Aggregator and Separator Network (ASNet) for encrypted traffic understanding, which consists of two core modules. Specifically, a parameter-free word sense aggregator enables BERT to rapidly adapt to understanding traffic data and keeping the complete word sense without introducing additional model parameters. And a category-constrained semantics separator with task-aware prompts (as the stimulus) is introduced to explicitly conduct feature learning independently in semantic spaces of different categories. Experiments on five datasets across seven tasks demonstrate that our proposed model achieves the current state-of-the-art results without pre-training in both the public benchmark and real-world collected traffic dataset. Statistical analyses and visualization experiments also validate the interpretability of the core modules. Furthermore, what is important is that ASNet does not need pre-training, which dramatically reduces the cost of computing power and time. The model code and dataset will be released inhttps://github.com/pengwei-iie/ASNET.
Wei Peng 0008, Lei Cui 0003, Wei Wang 0428, Xiaoyu Cui, Zhiyu Hao, Xiao-chun Yun
IEEE Trans. Inf. Forensics Secur.6
2025 Reliable Open-Set Network Traffic Classification
abstract
The widespread use of modern network communications necessitates effective resource control and management in TCP/IP networks. However, most existing network traffic classification methods are limited to labeled known classes and struggle to handle open-set scenarios, where known classes coexist with significant volumes of unknown classes of traffic. To solve this problem more accurately and reliably, we propose RoNeTC. This method achieves high-precision classification by enhancing feature extraction and quantifying the reliability of classification decisions through uncertainty estimation. For feature extraction, we divide each packet of a flow into three views for parallel training, integrating both local and global feature representations across multiple packets to enhance accuracy. We devise a second-order classification probability to quantify the reliability of the classifier’s results and to visualize the reliability of open-set flow classification in terms of uncertainty. Additionally, we dynamically fuse classification decisions from multiple views, evaluating decision uncertainty to classify known and unknown flows and ensure robust, reliable results. We compare RoNeTC with four state-of-the-art (SOTA) methods in six open-set scenarios. RoNeTC outperforms the other methods by an average of 25.94% in F1 across all open-set scenarios, indicating its superior performance in open-set network traffic classification.
Xueman Wang, Yipeng Wang 0001, Yingxu Lai, Zhiyu Hao, Alex X. Liu
IEEE Trans. Inf. Forensics Secur.4
2024 APIBeh: Learning Behavior Inclination of APIs for Malware Classification
abstract
Malware classification involves categorizing mal-ware samples based on their characteristics. While deep learning techniques applied to malware execution traces, mainly API calls, have shown potential in this field, they still perform poorly. This is primarily because they treat all APIs equally and train classifiers directly on native APIs, which inadequately capture the under-lying family-related semantics. In this paper, we first investigate the behaviors of multiple malware families and observe that different families exhibit divergent behaviors, with each family consistently favoring certain behaviors over time. Motivated by this, we propose APIBeh, a new embedding method designed to enhance malware classification. APIBeh first utilizes Benignity Degree Algorithm to identify and exclude insignificant, likely benign APIs from sequences. Then, it introduces the concept of Behavior Inclination, which quantifies the association between an API and malicious behaviors, facilitating high-level behavior encoding for each API. This Behavior Inclination embedding is then concatenated with raw embedding to represent an API, and fed into a DL model for classifier training. Experimental results show that APIBeh outperforms existing embedding methods in classification performance, e.g., 3.18% boost in weighted f1-score over a recent study using word2vec. In addition, it offers robustness to concept drift and adversarial attacks.
Lei Cui 0003, Yiran Zhu, Junnan Yin, Zhiyu Hao, Wei Wang 0428, Peng Liu 0044, Xiao-chun Yun
ISSRE4
2024 VDTriplet: Vulnerability detection with graph semantics using triplet model
Hao Sun 0028, Lei Cui 0003, Zhenquan Ding, Siyuan Li 0014, Zhiyu Hao, Hongsong Zhu
Comput. Secur.6
2024 API2Vec++: Boosting API Sequence Representation for Malware Detection and Classification
abstract
Analyzing malware based on API call sequences is an effective approach, as these sequences reflect the dynamic execution behavior of malware. Recent advancements in deep learning have facilitated the application of these techniques to mine valuable information from API call sequences. However, these methods typically operate on raw sequences and may not effectively capture crucial information, especially in the case of multi-process malware, due to theAPI call interleaving problem. Furthermore, they often fail to capture contextual behaviors within or across processes, which is particularly important for identifying and classifying malicious activities. Motivated by this, we present API2Vec++, a graph-based API embedding method for malware detection and classification. First, we construct a graph model to represent the raw sequence. Specifically, we design the Temporal Process Graph (TPG) to model inter-process behaviors and the Temporal API Property Graph (TAPG) to model intra-process behaviors. Compared to our previous graph model, the TAPG model exposes operations with associated behaviors within the process through node properties and thus enhances detection and classification abilities. Using these graphs, we develop a heuristic random walk algorithm to generate numerous paths that can capture fine-grained malicious familial behavior. By pre-training these paths using the BERT model, we generate embeddings of paths and APIs, which can then be used for malware detection and classification. Experiments on a real-world malware dataset demonstrate that API2Vec++ outperforms state-of-the-art embedding methods and detection/classification methods in both accuracy and robustness, particularly for multi-process malware.
Lei Cui 0003, Junnan Yin, Jiancong Cui, Yuede Ji, Peng Liu 0044, Zhiyu Hao, Xiao-chun Yun
IEEE Trans. Software Eng.6
2023 MalAder: Decision-Based Black-Box Attack Against API Sequence Based Malware Detectors
abstract
The API call sequence based malware detectors have proven to be promising, especially when incorporated with deep neural networks (DNNs). Several adversarial attack methods are proposed to fool these detectors by introducing undetectable perturbations into normal samples. However, in real-world scenarios, the malware detector provides only the predicted label for a given sample, without exposing its network architecture or output probability, making it challenging for adversarial attacks under the decision-based black-box. Existing work in this area typically relies on random-based methods that suffer high costs and low attack success rates. To address these limitations, we propose a novel decision-based black-box attack against API sequence based malware detectors, called MalAder. Our approach aims to improve the attack success rate as well as query efficiency through a directional perturbation algorithm. First, it utilizes attention-based API ranking to assess the importance of API calls in the context of different API sequences. This assessment guides the insertion position for perturbation. Then, the perturbation is carried out using benign distance perturbing, which gradually shortens the semantic distance from adversarial API sequences to a set of benign samples. Finally, our algorithm iteratively generates adversarial malware samples by performing perturbations. In addition, we have implemented MalAder and evaluated its performance against two classic malware detectors. The results show that MalAder outperforms state-of-the-art decision-based black-box adversarial attacks, proving its effectiveness.
Lei Cui 0003, Hui Wen 0001, Zhi Li 0018, Hongsong Zhu, Zhiyu Hao, Limin Sun 0001
DSN6
2023 An Enhanced Vulnerability Detection in Software Using a Heterogeneous Encoding Ensemble
abstract
Detecting vulnerabilities in source code is essential to prevent cybersecurity attacks. Deep learning-based vulnerability detection is an active research topic in software security. However, existing deep learning-based vulnerability detectors (VD) are limited to using either serialization-based or graph-based methods, which do not combine serialized global and structured local information at the same time. As a result, a single method cannot perform well for semantic information that exists in complex source code, leading to low detection accuracy. In this paper, we present EL-VDetect, a stacked ensemble learning approach for vulnerability detection that eliminates these issues. EL-VDetect enhances feature selection techniques to represent the best relevant vulnerability features with the slice code and subgraphs, reducing redundant information of vulnerabilities. Our model combines serialization-based and graph-based neural networks to successfully capture the global and local context information of source code, effectively understands code semantics, and focuses on vulnerable nodes based on the attention mechanism to accurately detect vulnerabilities. To evaluate EL-VDetect's effectiveness, we crawl a real-world dataset from CVEDetails, consisting of functions for eight applications. A comprehensive performance analysis of the real-world dataset shows that EL-VDetect achieves 90.72% accuracy, outperforming baseline deep learning models by 1.75-26.21 %. Our proposed model can better identify vulnerabilities in software than other existing vulnerability detection models.
Hao Sun 0028, Yongji Liu, Zhenquan Ding, Yang Xiao 0011, Zhiyu Hao, Hongsong Zhu
ISCC5
2023 API2Vec: Learning Representations of API Sequences for Malware Detection
abstract
Analyzing malware based on API call sequence is an effective approach as the sequence reflects the dynamic execution behavior of malware.Recent advancements in deep learning have led to the application of these techniques for mining useful information from API call sequences. However, these methods mainly operate on raw sequences and may not effectively capture important information especially for multi-process malware, mainly due to the API call interleaving problem.
Lei Cui 0003, Jiancong Cui, Yuede Ji, Zhiyu Hao, Zhenquan Ding
ISSTA4
2023 Software Vulnerability Detection Using an Enhanced Generalization Strategy
Hao Sun 0028, Zhe Bu, Yang Xiao 0011, Chengsheng Zhou, Zhiyu Hao, Hongsong Zhu
SETTA5
2023 HEMC: a dynamic behaviour analysis system for malware based on hardware virtualisation
abstract
Since many malwares disguise themselves by encrypting, obfuscating and recompiling, it is not easy for static analysis methods to recognise new or unknown malwares. This paper proposes a novel dynamic analysis technology based on hardware virtualisation to analyse more malwares with lower computational resources. Firstly, it intercepts the system-call functions to achieve on-demand behaviour analysis by setting special permissions in their physical addresses, which can be dynamically acquired when system-call functions are loaded into memory, as well as only monitoring high-risk functions, which take a small part of the whole functions. Then, this paper utilises copy-on-write technique and incremental image capability to reduce hard drive consumption and hard disk replication time. Finally, this paper proposes a novel approach to capture the return value of system-call functions to deeply analyse the poisoned results of malware samples. Meanwhile, a prototype system, called HEMC, is implemented based on QEMU/KVM . The experiments demonstrate that proposed methods outperform existing methods in efficiency and performance on malware dynamic analysis.
Zhenquan Ding, Lei Cui 0003, Haiqiang Fei, Yongji Liu, Zhiyu Hao
Int. J. Inf. Comput. Secur.6
2023 eHotSnap: An Efficient and Hot Distributed Snapshots System for Virtual Machine Cluster
abstract
With the popularity of IaaS clouds, many distributed and networked applications are running in virtual machine cluster (VMC). The distributed snapshots of VMC are a practical approach to guarantee system reliability. It rewinds the system to an intermediate state from failures so that the applications can continue execution from a point near the failure. However, the applications running in the VMC suffer from long disruption and significant performance degradation due to the heavy cost distributed snapshots, especially when designed to guarantee global consistency of VMC snapshots. This article presents eHotSnap, which takes distributed snapshots of a VMC efficiently. eHotSnap divides the native snapshot into light cost transient snapshot and heavy cost memory snapshot and then coordinates the VM snapshots immediately after transient snapshots. In this way, it decouples coordination from heavy cost snapshots so that the distributed snapshots are taken (completed in logic) within a second. Then, it performs memory snapshot and optimizes it with a two-layer optimization, which first employs de-duplication to reduce the amount of snapshot data and then leverages priority queue to serve guest write operations preferentially. In addition to presenting eHotSnap, we have implemented a prototype on QEMU/KVM. The experimental results demonstrate the effectiveness and efficiency of the proposed approach.
Bo Li 0005, Lei Cui 0003, Zhiyu Hao, Yongji Liu, Yongnan Li
IEEE Trans. Parallel Distributed Syst.3
2022 SeqTrace: API Call Tracing Based on Intel PT and VMI for Malware Detection
Zhenquan Ding, Yonghe Guo, Lei Cui 0003, Yuanlong Peng, Zhiyu Hao
ICA3PP8
2022 MalPro: Learning on Process-Aware Behaviors for Malware Detection
abstract
Malware continuously evolve and become more and more sophisticated. Learning on execution behavior is proven to be effective for malware detection. In this paper, we present MalPro, a DNN based malware detection approach that performs learning on process-aware behaviors for Windows programs. It first employs logistic regression-based weighting method to assess the sensitivity of an API to malicious behavior, and weights the API following run-time arguments with varying degrees of sensitivities. Then, it constructs the process graph of inter-process interactions from which a set of attributes are extracted, for characterizing the relationship of various processes in term of invoke actions. Finally, it feeds the weighted API sequences and the process graph attributes into the DNN for training a binary classifier to detect malware. Moreover, we have implemented and evaluated MalPro on two datasets. The results demonstrate that our method outperforms naive models, verifying the effectiveness of MalPro.
Ying Tong, Chunlai Du, Yongji Liu, Zhenquan Ding, Qingyun Ran, Lei Cui 0003, Zhiyu Hao
ISCC9
2022 Mal-Bert-GCN: Malware Detection by Combining Bert and GCN
abstract
With the dramatic increase in malicious software, the sophistication and innovation of malware have increased over the years. In particular, the dynamic analysis based on the deep neural network has shown high accuracy in malware detection. However, most of the existing methods only employ the raw API sequence feature, which cannot accurately reflect the actual behavior of malicious programs in detail. The relationship between API calls is critical for detecting suspicious behavior. Therefore, this paper proposes a malware detection method based on the graph neural network. We first connect the API sequences executed by different processes to build a directed process graph. Then, we apply Bert to encode the API sequences of each process into node embedding, which facilitates the semantic execution information inside the processes. Finally, we employ GCN to mine the deep semantic information based on the directed process graph and node embedding. In addition to presenting the design, we have implemented and evaluated our method on 10,000 malware and 10,000 benign software datasets. The results show that the precision and recall of our detection model reach 97.84% and 97.83%, verifying the effectiveness of our proposed method.
Zhenquan Ding, Yonghe Guo, Lei Cui 0003, Zhiyu Hao
TrustCom6
2022 ClusterRR: a record and replay framework for virtual machine cluster
abstract
The Record and Replay (RnR) technology provides the ability to reproduce past execution of systems deterministically. It has many prominent applications, including fault tolerance, security analysis, and failure diagnosis. In system virtualization, previous RnR researches mainly focus on individual VM, including coherent replaying of multi-core systems, reducing performance penalty and storage overhead. However, with the emerging of distributed systems deployed in virtual machine clusters (VMC), the existing RnR technology of individual VM can not meet the requirements of analyzers and developers. The critical challenge for VMC RnR is to maintain the consistency of global state. In this paper, we propose ClusterRR, a RnR framework for VMC. To solve the inconsistency problem, we propose coordination protocols to schedule the record and replay process of VMs. Meanwhile, we employ a Hybrid RnR approach to reduce the performance penalty and storage costs caused by recording network events. Moreover, we implement ClusterRR on QEMU/KVM platform and utilize a network packets retransmission framework to guarantee the reproducibility of VMC replay. Last, we conduct a series of experiments to measure its efficiency and overhead. The results show that ClusterRR would efficiently replay the execution of the whole VMC at instruction-level granularity.
Wei Wang 0428, Zhiyu Hao, Lei Cui 0003
VEE2
2022 CodeDiff: A Malware Vulnerability Detection Tool Based on Binary File Similarity for Edge Computing Platform
Zihao Chu, Yonghe Guo, Yongji Liu, Lei Cui 0003, Zhiyu Hao
WASA (3)7
2022 Optimizing genomic control in mixed model associations with binary diseases
abstract
Complex computation and approximate solution hinder the application of generalized linear mixed models (GLMM) into genome-wide association studies. We extended GRAMMAR to handle binary diseases by considering genomic breeding values (GBVs) estimated in advance as a known predictor in genomic logit regression, and then reduced polygenic effects by regulating downward genomic heritability to control false negative errors produced in the association tests. Using simulations and case analyses, we showed in optimizing GRAMMAR, polygenic effects and genomic controls could be evaluated using the fewer sampling markers, which extremely simplified GLMM-based association analysis in large-scale data. Further, joint association analysis for quantitative trait nucleotide (QTN) candidates chosen by multiple testing offered significant improved statistical power to detect QTNs over existing methods.
Zhiyu Hao, Runqing Yang, Pao Xu
Briefings Bioinform.4
2022 An empirical study of vulnerability discovery methods over the past ten years
Lei Cui 0003, Jiancong Cui, Zhiyu Hao, Zhenquan Ding, Yongji Liu
Comput. Secur.3
2022 Black box attack and network intrusion detection using machine learning for malicious traffic
Yiran Zhu, Lei Cui 0003, Zhenquan Ding, Yongji Liu, Zhiyu Hao
Comput. Secur.6
2022 CruParamer: Learning on Parameter-Augmented API Sequences for Malware Detection
abstract
Learning on execution behaviour, i.e., sequences of API calls, is proven to be effective in malware detection. In this paper, we present CruParamer, a deep neural network based malware detection approach for Windows platform that performs learning on sequences of parameter-augmented APIs. It first employs rule-based and clustering-based classification to assess the sensitivity of a parameter to malicious behaviour, and further labels the API following the run-time parameters with varying degrees of sensitivities. Then, it encodes the APIs by concatenating the native embedding and the sensitive embedding of labelled APIs, for characterizing the relationship between successive labelled APIs and their correspondence in terms of security semantics. Finally, it feeds the sequences of API embedding into the deep neural network for training a binary classifier to detect malware. In addition to presenting the design, we have implemented CruParamer and evaluated it on two datasets. The results demonstrate that CruParamer outperforms naïve models when taking raw APIs as input, proving the effectiveness of CruParamer. Moreover, we have evaluated the impact ofmimicryand adversarial attacks on our model, and the results verify the robustness of CruParamer.
Zhiyu Hao, Lei Cui 0003, Yiran Zhu, Zhenquan Ding, Yongji Liu
IEEE Trans. Inf. Forensics Secur.2
2022 iConSnap: An Incremental Continuous Snapshots System for Virtual Machines
abstract
The reliability of data and services hosted on a virtual machine (VM) is a top concern in cloud environments. The Continuous Snapshots can reduce the data loss in case of failures and thus is prevailing for protecting long-running systems. However, existing methods suffer from long VM downtime, long snapshot interval and significant performance loss. In this article, we present iConSnap, a system designed to take fine-grained continuous snapshots of virtual machines without compromising VM performance. First, iConSnap adopts the copy-on-write (COW) mechanism to save the memory pages on-demand, and thus decreases the VM downtime to about 200 milliseconds. Second, we extend the idea of COW and propose a lazily incremental approach to save the delta data between two successive snapshots only once, thereby reducing the snapshot duration and snapshot data a lot. Third, we propose a scheduling mechanism to mitigate the VM performance penalty issue. Last, we introduce a method combined of compression and time-aware multi-granularity reclamation strategy to reduce the storage costs without losing performance and availability. We implement iConSnap on QEMU/KVM and evaluate it through a set of experiments. The experimental results show that iConSnap outperforms existing approaches in terms of VM downtime, snapshot duration, storage costs and VM performance.
Zhiyu Hao, Wei Wang 0428, Lei Cui 0003, Xiao-chun Yun, Zhenquan Ding
IEEE Trans. Serv. Comput.1
2021 EmuIoTNet: An Emulated IoT Network for Dynamic Analysis
Qin Si, Lei Cui 0003, Zhenquan Ding, Yongji Liu, Zhiyu Hao
ICICS (1)6
2021 Genome-wide hierarchical mixed model association analysis
abstract
In genome-wide mixed model association analysis, we stratified the genomic mixed model into two hierarchies to estimate genomic breeding values (GBVs) using the genomic best linear unbiased prediction and statistically infer the association of GBVs with each SNP using the generalized least square. The hierarchical mixed model (Hi-LMM) can correct confounders effectively with polygenic effects as residuals for association tests, preventing potential false-negative errors produced with genome-wide rapid association using mixed model and regression or an efficient mixed-model association expedited (EMMAX). Meanwhile, the Hi-LMM performs the same statistical power as the exact mixed model association and the same computing efficiency as EMMAX. When the GBVs have been estimated precisely, the Hi-LMM can detect more quantitative trait nucleotides (QTNs) than existing methods. Especially under the Hi-LMM framework, joint association analysis can be made straightforward to improve the statistical power of detecting QTNs.
Zhiyu Hao, Runqing Yang
Briefings Bioinform.1
2021 VDSimilar: Vulnerability detection based on code similarity of vulnerabilities and patches
Hao Sun 0028, Lei Cui 0003, Zhenquan Ding, Zhiyu Hao, Jiancong Cui, Peng Liu 0044
Comput. Secur.5
2021 VulDetector: Detecting Vulnerabilities Using Weighted Feature Graph Comparison
abstract
Code similarity is one promising approach to detect vulnerabilities hidden in software programs. However, due to the complexity and diversity of source code, current methods suffer low accuracy, high false negative and poor performance, especially in analyzing a large program. In this paper, we propose to tackle these problems by presenting VulDetector, a static-analysis tool to detect C/C++ vulnerabilities based on graph comparison at the granularity of function. At the key of VulDetector is a weighted feature graph (WFG) model which characterizes function with a small yet semantically rich graph. It first pinpoints vulnerability-sensitive keywords to slice the control flow graph of a function, thereby reducing the graph size without compromising security-related semantics. Then, each sliced subgraph is characterized using WFG, which provides both syntactic and semantic features in varying degrees of security. As for graph comparison, we take full usage of vulnerability graph and patch graph to improve accuracy. In addition, we propose two optimization methods based on analysis of vulnerabilities. We have implemented VulDetector to automatically detect vulnerabilities in software programs with known vulnerabilities. The experimental results prove the effectiveness and efficiency of VulDetector.
Lei Cui 0003, Zhiyu Hao, Haiqiang Fei, Xiao-chun Yun
IEEE Trans. Inf. Forensics Secur.2
2020 CHEAPS2AGA: Bounding Space Usage in Variance-Reduced Stochastic Gradient Descent over Streaming Data and Its Asynchronous Parallel Variants
Yaqiong Peng, Haiqiang Fei, Zhenquan Ding, Zhiyu Hao
ICA3PP (2)5
2020 pRnR: A Parallel Record-Replay Framework for Virtual Machines
abstract
The record and replay(RnR) technology of virtual machine(VM) provides the ability to reproduce the past execution of a VM deterministically. It has many promising applications in the cloud environment, including fault tolerance, security analysis, and failure diagnosis. Existing studies in this area pay more effort in optimizing the record method, such as reducing performance penalty and storage costs. However, considering that many practical applications follow the record once, replay many mode, the optimization for the replay is more critical, especially for efficiency. In this paper, we propose pRnR, a novel parallel RnR framework, to support efficient replay. By combining the native RnR framework with an improved continuous snapshots mechanism, pRnR divides the full execution into many independent and complete slices, each of which supports arbitrary replay. In addition, it supports two replay modes to improve replay efficiency, i.e., multi-slice parallel replay and multi-dimension parallel replay. Moreover, we apply our pRnR framework to syscall-based diagnosis to demonstrate its usability. The experimental results show that pRnR is more efficient than existing RnR frameworks.
Wei Wang 0428, Lei Cui 0003, Zhiyu Hao, Haiqiang Fei, Chonghua Wang, Yaqiong Peng
ICCD3
2020 Lock-Free Parallelization for Variance-Reduced Stochastic Gradient Descent on Streaming Data
abstract
Stochastic Gradient Descent (SGD) is an iterative algorithm for fitting a model to the training dataset in machine learning problems. With low computation cost, SGD is especially suited for learning from large datasets. However, the variance of SGD tends to be high because it uses only a single data point to determine the update direction at each iteration of gradient descent, rather than all available training data points. Recent research has proposed variance-reduced variants of SGD by incorporating a correction term to approximate full-data gradients. However, it is difficult to parallelize such variants with high performance and accuracy, especially on streaming data. As parallelization is a crucial requirement for large-scale applications, this article focuses on the parallel setting in a multicore machine and presents LFS-STRSAGA, a lock-free approach to parallelizing variance-reduced SGD on streaming data. LFS-STRSAGA embraces a lock-free data structure to process the arrival of streaming data in parallel, and asynchronously maintains the essential information to approximate full-data gradients with low cost. Both our theoretical and empirical results show that LFS-STRSAGA matches the accuracy of the state-of-the-art variance-reduced SGD on streaming data under sparsity assumption (common in machine learning problems), and that LFS-STRSAGA reduces the model update time by over 98 percent.
Yaqiong Peng, Zhiyu Hao, Xiao-chun Yun
IEEE Trans. Parallel Distributed Syst.2
2019 Quick approximation of threshold values for genome-wide association studies
abstract
Standard normal statistics, chi-squared statistics, Student's t statistics and F statistics are used to map quantitative trait nucleotides for both small and large sample sizes. In genome-wide association studies (GWASs) of single-nucleotide polymorphisms (SNPs), the statistical distributions depend on both genetic effects and SNPs but are independent of SNPs under the null hypothesis of no genetic effects. Therefore, hypothesis testing when a nuisance parameter is present only under the alternative was introduced to quickly approximate the critical thresholds of these test statistics for GWASs. When only the statistical probabilities are available for high-throughput SNPs, the approximate critical thresholds can be estimated with chi-squared statistics, formulated by statistical probabilities with a degree of freedom of two. High similarities in the critical thresholds between the accurate and approximate estimations were demonstrated by extensive simulations and real data analysis.
Zhiyu Hao, Jinhua Ye, Jingli Zhao, Shuling Li, Runqing Yang
Briefings Bioinform.1
2019 Framework for risk assessment in cyber situational awareness
abstract
A large number of data is generated to help network analysts to evaluate the network security situation in traditional detection and prevention measures, but it is not used fully and effectively, there is not a holistic view of the network situation on it for now. To address this issue, a framework is proposed to evaluate the security situation of the network from three dimensions: threat, vulnerability and stability, and merge the results at decision level to measure the security situation of the overall network. In the case studies, the authors demonstrate how the framework is deployed in the network and how to use it to reflect the security situation of the network in real time. Results of the case study show that the framework can evaluate the security situation of the network accurately and reasonably.
Rongrong Xi, Xiao-chun Yun, Zhiyu Hao
IET Inf. Secur.3
2019 Fast Wait-Free Construction for Pool-Like Objects with Weakened Internal Order: Stacks as an Example
abstract
This paper focuses on a large class of concurrent data structures that we call pool-like objects (e.g., stack, double-ended queue, and queue). Performance and progress guarantee are two important characteristics for concurrent data structures. In the aspect of performance, weakening the internal order in a pool-like object is an effective technique to reduce the synchronization cost among threads accessing the object, but no objects with weakened internal order provide a progress guarantee as strong as wait-freedom. Meanwhile, wait-free algorithms tend to be inefficient, which is mainly attributed to the helping mechanisms. Based on the philosophy of existing helping mechanisms, a wait-free pool-like object with weakened internal order would suffer from unnecessary process of getting the latest object state and synchronization. This paper takes a state-of-the-art implementation of stacks with weakened internal order as an example, and transforms it into a highly-efficient wait-free stack named WF-TS-Stack. The transformation method includes a helping mechanism with state reuse and a relaxed removal scheme. In addition, we use a simple and effective scheme to further improve the performance of WF-TS-Stack in Non-Uniform Memory Access (NUMA) architectures. Our evaluation with representative benchmarks shows that WF-TS-Stack outperforms its original building blocks by up to 1.45× at maximum concurrency. We also discuss how to yield an efficient double-ended queue (deque) variant of WF-TS-Stack, because deque is a more generalized pool-like object.
Yaqiong Peng, Xiao-chun Yun, Zhiyu Hao
IEEE Trans. Parallel Distributed Syst.3
2018 ShadowMonitor: An Effective In-VM Monitoring Framework with Hardware-Enforced Isolation
Bin Shi 0003, Lei Cui 0003, Bo Li 0005, Xudong Liu 0001, Zhiyu Hao, Haiying Shen
RAID5
2018 SnapFiner: A Page-Aware Snapshot System for Virtual Machines
abstract
Virtual machine (VM) snapshot, enabling a VM to be resumed from a previously recorded state, is an essential part of cloud infrastructures. Unfortunately, the snapshot data are likely to be lost due to the high rate of disk failures, so that the associated VM fails to recover properly. To enhance data availability without compromising application performance upon rollback recovery, it is desired to place multiple replicas of snapshot across disperse disks. However, due to the large size of replica, it induces non-trivial storage cost when managing massive snapshots in clouds. In this paper, we investigate this problem and find out that the semantic gap existed between snapshot creation and snapshot storing is one key factor inducing high storage cost. To this end, we propose SnapFiner, a page-aware snapshot system for creating and storing massive snapshot files efficiently. First, SnapFiner acquires a fine-grained page categorization with an in-depth page exploration from three orthogonal views, thereby discovering more pages that can be excluded from the snapshot. Second, SnapFiner varies the number of replicas for different page categories based on a page-aware replication policy, achieving low storage cost without compromising availability and performance. Third, SnapFiner handles the loss of pages either intentionally dropped upon snapshot creation or unexpectedly damaged due to disk failures, enabling proper system execution after rollback recovery. We have implemented SnapFiner on QEMU/KVM to justify its practicality for Linux guests. The experimental results demonstrate that SnapFiner reduces the storage cost by 33 and 69.5 percent respectively compared to our previous work PARS and the naive approach on QEMU/KVM and HDFS.
Lei Cui 0003, Zhiyu Hao, Xiao-chun Yun
IEEE Trans. Parallel Distributed Syst.2
2018 FA-Stack: A Fast Array-Based Stack with Wait-Free Progress Guarantee
abstract
The prevalence of multicore processors necessitates the design of efficient concurrent data structures. Shared concurrent stacks are widely used as inter-thread communication structures in parallel applications. Wait-free stacks can ensure that each thread completes operations on them in a finite number of steps. This characteristic is valuable for parallel applications and operating systems, especially in real-time environments. Unfortunately, because wait-free algorithms are typically hard to design and considered inefficient, practical wait-free stacks are rare. In this paper, we present a practical, fast array-based concurrent stack with wait-free progress guarantee, named FA-Stack. A series of optimizations are proposed to bound the number of steps required to complete every push and pop operation. In addition, FA-Stack adopts a time-stamped scheme to reclaim memory. We use linearizability, a correctness condition for concurrent data structures, to prove that FA-Stack is a wait-free linearizable stack with respect to the Last in First Out (LIFO) semantics. Our evaluation with representative benchmarks shows that FA-Stack is an efficient wait-free stack. For example, compared to Sim-Stack (a state-of-the-art wait-free stack), FA-Stack improves the throughput of halfhalf benchmark by upto 2.4×.
Yaqiong Peng, Zhiyu Hao
IEEE Trans. Parallel Distributed Syst.2
2017 NOR: Towards Non-intrusive, Real-Time and OS-agnostic Introspection for Virtual Machines in Cloud Environment
Chonghua Wang, Zhiyu Hao, Xiao-chun Yun
Inscrypt2
2017 SA-PFRS: Semantics-Aware Page Frame Reclamation System in Virtualized Environments
abstract
Page reclamation is one compelling way to overcommit memory in modern operating systems. To achieve wise reclamation, the Linux kernels employ page frame reclamation algorithm (PFRA) to reclaim pages based on the page usage view. However, due to the semantic gap problem in virtualized environments, the native PFRA suffers three types of unwise evictions including false eviction, superficial eviction and omitted eviction. This will lead to high swapping I/O activity and consequently limits the ability to overcommit memory. We present SA-PFRS, a Semantics-Aware Page Frame Reclamation System, to address this problem. SA-PFRS separates the memory pages allocated for guests from reclaimable candidates in host, explores how the pages are being used by guest OS, and adjusts the reclamation order in the view of guest. Then, SA-PFRS re-arranges the reclamation sequence of guest pages and host pages, so as to reclaim the memory pages in a global semantics-aware manner. This enables SA-PFRS to eliminate a large number of swapping I/O operations when memory is overcommitted. We implement a prototype of SA-PFRS in Linux kernel, and show its effectiveness through a set of experiments.
Lei Cui 0003, Zhiyu Hao, Chonghua Wang
ICPADS3
2017 A Hypervisor Level Provenance System to Reconstruct Attack Story Caused by Kernel Malware
Chonghua Wang, Shiqing Ma, Xiangyu Zhang 0001, Junghwan Rhee, Xiao-chun Yun, Zhiyu Hao
SecureComm6
2017 Piccolo: A Fast and Efficient Rollback System for Virtual Machine Clusters
abstract
Rollback is an effective technique to resume the system execution from a recorded intermediate state upon failures, without having to restart the entire system. However, in virtualized environments, rollback of a virtual machine cluster (VMC) produces high network traffic and long service disruption, particularly for a large cluster used for scientific computing, thereby imposing significant overhead both on network and applications. This paper proposes Piccolo, a fast and efficient rollback system, to restore a VMC from snapshot files over data center network. First, we exploit the similarity among VMC snapshots and leverage multicast to deliver the identical pages across VMs placed on disperse hosts, thereby bypassing unnecessary transmission of a large number of pages. Second, we analyze the impact on network traffic of varying VM placements in data center network, formulate the traffic aware placement as an optimization problem, and design a two-tier approximation algorithm that efficiently solves the problem. In addition to presenting Piccolo, we detail its implementation, and evaluate it by a set of experiments. The results show that Piccolo could achieve a significant reduction in terms of total sent data, network traffic and rollback latency compared to the existing generic techniques.
Lei Cui 0003, Zhiyu Hao, Yaqiong Peng, Xiao-chun Yun
IEEE Trans. Parallel Distributed Syst.2
2016 DMNS: A Framework to Dynamically Monitor Simulated Network
abstract
With rapid development of network simulation technology, monitoring system has become an essential tool for the researching and testing of network space activities. However, the current monitoring technologies of simulated networks cannot satisfy the requirements in terms of flexibility and efficiency. This paper proposes a framework called DMNS to dynamically monitor simulated network. With DMNS, users are able to customize the monitored objects and monitoring actions to meet the requirements of flexibility. In addition, the administrators could dynamically change the monitoring rules for saving resources based on callback mechanism. DMNS also considers the requirements of large-scale distributed simulation. Specifically, it leverages message oriented middleware to achieve efficient monitoring message information transmission to guarantee the robustness of the monitoring system. We implement a prototype of DMNS in a network range system and demonstrate the effectiveness by a case study.
Zhiyu Hao, Yongzheng Zhang 0002, Yaqiong Peng, Zhenxi Sun
ICPADS2
2016 Piccolo: A Fast and Efficient Rollback System for Virtual Machine Clusters
abstract
Rollback is an effective technique to resume the system execution from a recorded intermediate state upon failures. However, in virtualized environments, rollback of a virtual machine cluster (VMC) produces high network traffic and long service disruption, consequentially imposing significant overhead both on network and applications. In this paper, we propose Piccolo, a fast and efficient rollback system, to restore a VMC from snapshot files over datacenter network. We exploit the similarity among VMC snapshots and leverage multicast to deliver the identical pages across VMs placed on disperse hosts, thereby bypassing transmission of a large number of unnecessary pages. In addition to presenting Piccolo, we detail its implementation, and evaluate it by a set of experiments. The results show that Piccolo could achieve a significant reduction in terms of total sent data, network traffic and rollback latency compared to the existing generic rollback techniques.
Lei Cui 0003, Zhiyu Hao, Chonghua Wang, Haiqiang Fei, Zhenquan Ding
ICPP2
2016 Quantitative threat situation assessment based on alert verification
abstract
Abstract Traditional network threat situational assessment is based on raw alerts, not combined with contextual information, which influences the accuracy of assessment. In this paper, we propose a method to quantitatively assess network threat situation based on not only alerts but also contextual information. It firstly verifies alerts by matching alerts with contextual information to determine the successful probability of attacks, then analyzes the impact caused by attacks according to the severity and the corresponding asset value of them, and finally quantitatively assesses network threat situation based on the successful probability and the impact of attacks. Case studies show that the method can assess network threat situations more reasonably. Copyright © 2016 John Wiley & Sons, Ltd.
Rongrong Xi, Xiao-chun Yun, Zhiyu Hao, Yongzheng Zhang 0002
Secur. Commun. Networks3
2015 Lightweight Virtual Machine Checkpoint and Rollback for Long-running Applications
Lei Cui 0003, Zhiyu Hao, Haiqiang Fei, Zhenquan Ding, Bo Li 0005, Peng Liu 0044
ICA3PP (3)2
2015 Traffic Replay in Virtual Network Based on IP-Mapping
Zhiyu Hao, Yongzheng Zhang 0002, Zhenquan Ding, Haiqiang Fei
ICA3PP (4)2
2015 Exploring Efficient and Robust Virtual Machine Introspection Techniques
Chonghua Wang, Xiao-chun Yun, Zhiyu Hao, Lei Cui 0003, Yandong Han, Qingxin Zou
ICA3PP (3)3
2015 Botnet spoofing: fighting botnet with itself
abstract
As the arms race between botmasters and defenders becomes increasingly common, the emerging advanced botnets have evolved to be more resilient to traditional mitigation strategies. For security-conscious Internet users, the host-based security software i.e., antivirus and firewall could provide effective protection against the botnet attacks; however, the remaining security-unconscious users will suffer from the botnet attacks and will be compromised easily. Consequently, how to protect both security-conscious and security-unconscious users against advanced botnets without any command and control vulnerability has posed a great challenge to this day. In this paper, we propose the idea of botnet spoofing that aims at addressing the aforementioned challenge to some degree. Botnet spoofing exploits the essential property of a persistent bot that it MUST obtain its file path before subsequent autostart registration or self-propagation to spoof a specific bot and trick the specific bot to propagate BotSpoofer instead of propagating itself, consequently making the victim not only avoid an originally successful attack but also achieve extra protection provided by BotSpoofer. Thus, botnet spoofing is independent of the vulnerability, protocol, and structure of botnet command and control. To prove the feasibility of botnet spoofing, we create a prototype named ConSpoofer-targeting Conficker. The results show that ConSpoofer could be passively delivered to other victims, which are located by Conficker, through Conficker's three propagation methods in an automatic, simple, accurate, and scalable manner. The goal of our work is to provide a new mitigation strategy that will promote the development of more efficient countermeasures against advanced botnets. Copyright © 2013 John Wiley & Sons, Ltd.
Xiang Cui, Lihua Yin, Shuyuan Jin, Zhiyu Hao
Secur. Commun. Networks4
2013 Counting sort for the live migration of virtual machines
abstract
The live migration of virtual machines is an important technique in the area of virtualization, and it has been used for load balancing, fault tolerance, and system maintenance in modern data centers, clusters, and cloud computing. The pre-copy algorithm is the most used method for the live migration of virtual machines. However, the existing problem of repeatedly transferring dirty memory pages leads the increase of the transferring data amount, delays of the total migration time as well as the downtime. By analyzing the iteration process of the pre-copy algorithm, we find that the transferring order of memory pages during every middle round has a huge impact on the generation and transferring of dirty memory pages. Further we put forward the concept of the live migration of virtual machines based on the counting sort. During every middle round of the iteration process, we do not transfer the memory pages according to their original order, instead we transfer the memory pages according to their times of being dirty. Experiment results show that with different workloads the counting sort method could simultaneously decrease the transferring data amount, the total migration time, and the downtime to improve the performance of the live migration.
Qingxin Zou, Zhiyu Hao, Xiao-chun Yun, Yongzheng Zhang 0002
CLUSTER2
2013 CADM: A Centralized Administration and Dynamic Monitoring Framework for Network Intrusion Detection Based on Virtualization
abstract
Virtualization technology, which has the characteristic of producing dynamic change, enables the virtual network structure to no longer depend strictly on the underlying hardware environment. With virtualization platform administrators tasked with preventing attacks in order to provide uninterrupted service, existing intrusion detection technologies are continuously challenged. Consequently, this paper proposes a Centralized Administration and Dynamic Monitoring framework (CADM) based on virtualization for network intrusion detection. CADM is able to centrally administrate, and monitor network behavior in the virtual computing environment by automatically deploying and updating intrusion detection processes and rules. In the aspect of monitoring capability, CADM allows the monitoring locations in intrusion detection to be automatically adjusted in real time, thus adapting to the dynamic changes (such as migration) of virtual machines (VMs). Moreover, the monitoring processes involved in intrusion detection could also be automatically updated by dynamically updating security strategies. In the aspect of monitoring granularity, CADM is able to monitor network interfaces of each virtual machine (VM) for fine-grained network intrusion detection and network traffic acquisition. Our experimental results demonstrate that more convenient and efficient monitoring and administrating capabilities are available with CADM for virtualization platform administrators.
Zhenquan Ding, Zhiyu Hao, Yongzheng Zhang 0002
PDCAT2
2012 Modeling Social Engineering Botnet Dynamics across Multiple Social Networks
Xiao-chun Yun, Zhiyu Hao, Yongzheng Zhang 0002, Xiang Cui, Yipeng Wang 0001
SEC3
2011 A Propagation Model for Social Engineering Botnets in Social Networks
abstract
With the rapid development of social networking services and the diversification of social engineering attacks, new high-infection botnet (called SE-botnet by us), which exploits social engineering attacks to spread bots in social networks, has become an underlying threat. Predicting the threat of SE-botnet can help defenders mitigate it effectively. In this paper, we focus on SE-botnet's infection and defense, presenting a propagation model for it. We take full account of social networks' characteristics and human dynamics, and abstract the general process of social engineering attacks used by SE-botnet. Our preliminary simulation results demonstrate that the SE-botnet can capture tens of thousands of bots in one day with a great infection capacity. our propagation model can accurately predict this process with less than 5% deviation.
Xiao-chun Yun, Zhiyu Hao, Xiang Cui, Yipeng Wang 0001
PDCAT3