EDBT 2026 Demo / reviewers in the wild / expert
Huaqun Guo
dblp:57/34
· DBLP profile ↗
27ranked-venue papers
12as first author
6since 2021 · last 2024
0000-0001-6753-6537ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 since 2021Computer networks · 6 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Ransomware Insight AnalyzerabstractThis paper aims to analyze and provide insights on vulnerabilities being exploited by ransomware attacks. This paper offers users a comprehensive overview of exploited Common Vulnerabilities and Exposures (CVE). Our analysis includes displaying charts on various aspects such as the top ransomware gangs, the most frequently abused CVE IDs, comparative information before and after the year 2021, common attack vectors, and more. Key findings from our research show that the top ransomware gangs include Conti and Cerber. The most exploited CVE IDs are CVE-2021-34473 and CVE-2021-34523, which correspond to the Microsoft Exchange Server Remote Code Execution Vulnerability and the Microsoft Exchange Server Elevation of Privilege Vulnerability, respectively. Additionally, we identified common attack vectors such as network attacks, application attacks, and data breaches, with instance counts of 10,091, 7,087, and 1,115, respectively. These insights provide valuable information for understanding and mitigating ransomware threats. Xin Lin Gan, Zhi Ren James Tan, Yu En Bernice Goo, Xin Ling Jocelyn Yeo, Vi Shean Lim, Yan Cong Boo, Huaqun Guo |
SIN | 7 |
| 2024 | Simulation of Pre-Ransomware Attacks on Active DirectoryabstractActive Directory is adopted by many organizations today. However, not many know how to securely implement it. This is concerning, particularly with the increasing prevalence of ransomware attacks. A ransomware attack inevitably affects organizations' business operations, data loss, and causes financial loss. Our approach aims to enable analysis of technical routes and behavioral aspects of attackers' “pre-ransomware” actions in an AD network while taking their capabilities and attack surfaces into account for realistic scenarios. By integrating simulations of vulnerable AD networks with an SIEM server, we demonstrate how AD attacks are carried out, to collect raw data on such attacks for future study for improvement of organizational detection capabilities. En Jie Tan, Kowit Tan, Royce Yu Feng Chong, Yi Ching Tan, Huaqun Guo |
SIN | 7 |
| 2024 | Security Situation Awareness PlatformabstractIn the current digital era, organizations are increasingly vulnerable to sophisticated ransomware attacks, demanding robust and dynamic security measures. This paper introduces a security scoring platform designed to enhance organizational defenses against such threats. Unlike existing solutions that rely on static data and lack customization, the platform integrates real-time dynamic data with a customizable security scoring system tailored to the specific needs of the organization. The platform employs a sophisticated algorithm that not only evaluates the organization's security posture but also provides actionable remediation measures, enabling a proactive response to vulnerabilities. It supports comprehensive asset management, historical data analysis, and multilingual capabilities, ensuring a versatile and user-friendly interface for global applications. By merging real-time data analysis, custom security scoring, and a holistic view of an organization's security landscape, the platform addresses the limitations of conventional security information and event management systems (SIEMs) and security operation centers (SOCs), offering a more accurate, responsive, and cost-effective solution. This paper details the development, architecture, and functionality of the platform, illustrating its effectiveness in fortifying organizational defenses in a rapidly evolving cyber threat landscape. Charisee Zhi Ling Yip, Tee Kiat Chua, Clarabel Jinghui Teo, Jing Rui Goh, Brandon Jia Le Loo, Huaqun Guo |
SIN | 6 |
| 2024 | Ransopedia: Your Trusty Guide to Ransomware TrendsabstractRansomware is a form of malware which attackers use to encrypt corporate and individual victims' data to blackmail them for financial gain. While ransomware-related cyberattacks occur frequently, information regarding historical ransomware attacks and their exploited vulnerabilities is sparse and unorganized. We present Ransopedia, a tool that achieves two goals. Firstly, it is a curated encyclopedia that is intended to provide the public with insights on ransomware attacks and associated vulnerabilities. Secondly, it forecasts potential future vulnerabilities through predictive analytics. Thura Zaw Aung, Nathan Chen Tao Leow, Damian Jun Jie Ng, Jia Jin Sim, Seth Matthias Wen Xiong Teas, Nicholas Heng-Loong Wong, Chee Kwang Quah, Huaqun Guo |
TENCON | 8 |
| 2023 | The Impact of the COVID-19 Pandemic on Retrenchment, Vaccinations, and Global HappinessabstractCOVID-19's impacts have spread widely in all directions such as economy, people's lifestyles and well-being. Though existing studies have highlighted such an impact, it remains unclear how the current COVID-19 situation has affected the retrenchment, vaccination and global happiness. In this paper, we present an automated tool enables the public to view various insight. In particular, we integrate and analyze the data from various data sources and show how the COVID19 has impacted Singapore and globally. We employ the regression models to identify the correlation between Human Development Index, Stringency Index, Gross Domestic Product per Capita, Total Deaths from COVID-19, and Total Cases of COVID-19; the rate of vaccination and vaccine hesitancy; and the factors to positively correlate to the global happiness. The insight provided adds values to better fight against the COVID-19 pandemic and future global crisis. Ng Wei Shen Jackson, Jullisha Sasikumar, Wong Yok Hung, Osama Rasheed Khan, Vivian Ng Zhi Hui, Sahar Al-Sudani, Huaqun Guo, Zhengkui Wang |
DeSE | 7 |
| 2022 | A survey on blockchain technology and its securityabstractBlockchain is a technology that has desirable features of decentralization, autonomy, integrity, immutability, verification, fault-tolerance, anonymity, auditability, and transparency. In this paper, we first carry out a deeper survey about blockchain technology, especially its history, consensus algorithms' quantitative comparisons, details of cryptography in terms of public key cryptography, Zero-Knowledge Proofs, and hash functions used in the blockchain, and the comprehensive list of blockchain applications. Further, the security of blockchain itself is a focus in this paper. In particular, we assess the blockchain security from risk analysis to derive comprehensive blockchain security risk categories, analyze the real attacks and bugs against blockchain, and summarize the recently developed security measures on blockchain. Finally, the challenges and research trends are presented to achieve more scalable and securer blockchain systems for the massive deployments. Huaqun Guo, Xingjie Yu |
Blockchain Res. Appl. | 1 |
| 2020 | Rail System Anomaly Detection via Machine Learning ApproachesabstractSupervisory Control and Data Acquisition (SCADA) system which monitors and controls physical processes/operations within a rail infrastructure is critical. SCADA system's accessing to key components and infrastructure information make it a promising attack target. This paper explores building machine learning models to detect anomalies in a rail SCADA system through the usage of network traffic data. The attack scenarios designed based on domain expertise are epoch time attack and TCP payload length attack in this paper. Data pre-processing is done before passing into machine learning approaches for training. The anomaly detection machine learning models are evaluated using several metrics such as true positive rate and precision. Results show that supervised learning approaches (K-Nearest Neighbours (KNN), Linear Support Vector Classification (LinearSVC), Random Forest, Gaussian Bayes) outperform unsupervised learning approach (K-Means). Exploration into the use of the full original network traffic versus a subset of network traffic for model training has shown that the latter performed better in precision due to the presence of overfitting to specific alarm network traffic. Finally, our experiment results show that supervised learning approach KNN is effective to detect the attacks with high precision. Zi Shan Lee, Huaqun Guo, Luying Zhou |
TENCON | 2 |
| 2020 | CIMA: Compiler-Enforced Resilience Against Memory Safety Attacks in Cyber-Physical Systems
Eyasu Getahun Chekole, Sudipta Chattopadhyay 0001, Martín Ochoa, Huaqun Guo, Unnikrishnan C. |
Comput. Secur. | 4 |
| 2019 | Efficient Password Guessing Based on a Password Segmentation ApproachabstractMost cracking tools against alphanumeric passwords conduct password guessing based on sophisticatedly constructed password dictionaries. The rule-based methods which continuously expand the size of dictionaries based on simple permutation and concatenation is the traditional way to construct password dictionaries. To increase the intelligence in dictionary generation, some password cracking tools extract password patterns from the training passwords based on machine learning, and thus construct dictionaries using the extracted patterns. However, these tools either have low guessing efficiency, or produce password generation models with low interpretability. Usually, a password could be split into several meaningful segments each of which represents particular personal information or a grammatically correct word, and the password patterns could be extracted from these segments. In this paper, we propose a novel password cracking tool, which breaks each training password to meaningful segments, learns the patterns from the password segments, and generates personalized high-efficiency password dictionaries based on the learned patterns. The experimental results show that the proposed tool is more efficient than the traditional rule-based tools as well as alphanumeric patterns-based tools. Furthermore, to evaluate the impact of personal information leakage on password security, we use personal information of the target users as the inputs for the proposed tool and analyze the password guessing efficiency. Gelei Deng, Xingjie Yu, Huaqun Guo |
GLOBECOM | 3 |
| 2019 | White-Box Implementation of the KMAC Message Authentication Code
Jiqiang Lu, Huaqun Guo |
ISPEC | 3 |
| 2019 | SCADAWall: A CPI-enabled firewall model for SCADA security
Huaqun Guo, Jianying Zhou 0001, Luying Zhou, Jun Wen Wong |
Comput. Secur. | 2 |
| 2019 | A fog computing based approach to DDoS mitigation in IIoT systems
Luying Zhou, Huaqun Guo, Gelei Deng |
Comput. Secur. | 2 |
| 2017 | Cyber-physical authentication for metro systemsabstractThis paper aims to address control device security issue with Metro systems. It would be devastating in the event that control devices are suffering from cyber attacks or physical attacks. Thus, in this paper, we present a cyber-physical authentication approach which combine an add-on security module (AOSM) and a cyber security protocol for cyber-physical device authentication and data transmission. Tests and performance evaluation have then been done to show the feasibility of the proposed protocol as the time efficiency of the protocol is critical to the functionality of the control system. Huaqun Guo, Jun Wen Wong |
APCC | 1 |
| 2017 | A scheme for lightweight SCADA packet authenticationabstractDevelopment and deployment of cyber security measures for legacy SCADA systems usually encounter challenges of limited computation resources in the field devices for supporting the designed cryptography processing. This paper presents a scheme with which the field device performs message authentication and integrity check only on selected critical packets such that it protects the system operation while avoiding high computation workload, and applies the scheme to a transportation SCADA system. The proposed scheme takes into account of the SCADA computation power limitation and real time requirements, and the extreme difficulty of making any changes to hardware or software in the legacy system. AES-CCM and symmetric key methods are applied for providing message authentication and integrity, and a bump-in-the-wire (BITW) implementation approach is adopted to avoid the changes to the legacy system. This lightweight packet authentication scheme is implemented and demonstrated over a testbed of a metro transportation SCADA system. Experiments show the effects of the scheme in blocking malicious packet attack and the comparison with a firewall approach. Luying Zhou, Huaqun Guo, Jianying Zhou 0001, Jun Wen Wong |
APCC | 2 |
| 2012 | Hybrid multimedia broadcast encryption schemesabstractBroadcast encryption in a pay television system is actually a key management issue, where smaller key storage and shorter header length are required to assure the quality of service. The existing solutions come up with two typical structures. One is the matrix-based structure without revocation capability and the other is the tree-based structure in Advanced Access Content System. In this paper, we propose two promising schemes that exploit the combination of the two structures to solve the revocation problem in the matrix-based structure to meet the requirements of the small key storage and short header. Mathematical derivations and calculations are performed to prove the feasibility of the proposed schemes. Huaqun Guo, Maode Ma |
WCNC | 2 |
| 2011 | HASVC: An Efficient Hybrid Authentication Scheme for Vehicular CommunicationabstractThe emerging vehicular communications will enable a variety of applications for safety, traffic efficiency, driver assistance and infotainment. Due to high vehicular speed, sporadic connection, limited communication range, and large volume of data that need to be transmitted, vehicular communications have the crucial requirements of fast authentication and encryption/decryption. This paper addresses the new and special challenges related to vehicular communications, such as large overhead and latency, presents our Hybrid scheme HASVC to address the authentication issue, and evaluates its performance so as to meet the stringent requirement of real time vehicular communications. The experimental results show that our authentication protocol can securely protect the exchanged information with less overhead and less authentication latency. Huaqun Guo, Zonghua Zhang, Lawrence Wai-Choong Wong, Maode Ma, Yongdong Wu |
ICC | 1 |
| 2011 | Performance evaluation of 802.11p device for secure vehicular communicationabstractThe emerging vehicular communications will enable a variety of applications for safety, traffic efficiency, driver assistance and infotainment. Due to high vehicular speed, sporadic connection, limited communication range, and large volume of data that need to be transmitted, vehicular communications have the stringent requirement of real-time vehicular communications. This paper presents our tests with 802.11p device and presents its performance evaluation in terms of throughput, loss rate, communication range and resending rate. The experimental results show that the 802.11p device can achieve real-time vehicular communications and is suitable for the applications with medium throughput, and a few hundred meters of communication range. Huaqun Guo, Shen-Tat Goh, Nicholas C. S. Foo, Lawrence Wai-Choong Wong |
IWCMC | 1 |
| 2011 | A reliable routing protocol for VANET communicationsabstractVehicular Ad-hoc Network (VANET) is an emerging new technology to enable communications among vehicles and nearby roadside infrastructures to provide intelligent transportation applications. In order to provide stable connections between vehicles, a reliable routing protocol is needed. Currently, there are several routing protocols designed for MANETs could be applied to VANETs. However, due to the unique characteristics of VANETs, the results are not encouraging. In this paper, we propose a new routing protocol named AODV-VANET, which incorporates the vehicles' movement information into the route discovery process based on Ad hoc On-Demand Distance Vector (AODV). A Total Weight of the Route is introduced to choose the best route together with an expiration time estimation to minimize the link breakages. With these modifications, the proposed protocol is able to achieve better routing performances. Huaqun Guo, Lawrence Wai-Choong Wong |
IWCMC | 2 |
| 2010 | Secure wireless communication platform for EV-to-Grid researchabstract"Vehicle to Grid" power or V2G will be a new green energy scheme that allows electricity to flow from Electric Vehicles (EVs) to power lines. The objective of this paper is to design and develop a secure wireless communication platform for V2G research, with the aim to develop a suitable wireless test bed for the V2G in Singapore. First, this paper presents our system block diagram and required methods design which include V2G architecture design, integrated OBU (on-board unit) design, base station (Aggregator), Telematics, V2G authentication protocol, and schedule optimization of EVs against Grid conditions. It then focuses on the authentication protocol for secure wireless communications between the Aggregators and EVs. It addresses the new and special challenges related to EVs, such as large overhead and latency, which are crucial for secure wireless communications with dynamic and fast moving EVs. Finally, the paper presents the initial test results and shows that our authentication protocol can securely protect the exchanged information with less overhead and less authentication latency. Huaqun Guo, Lawrence Wai-Choong Wong, Vivy Suhendra, Yongdong Wu |
IWCMC | 1 |
| 2009 | DINCast: Optimizing Application-Level Shared-Tree MulticastabstractApplication-level multicast suffers some disadvantages in terms of high multicast delay, overloading at rendezvous point (RP) and single-point of failure. In this paper, we propose DINCast to optimize application-level shared-tree multicast. The general idea of DINCast is to form a special logical data loop and use this loop instead of the RP as multicast sources. To demonstrate its effectiveness, we first analyze multicast delay with the inclusion of transmission delay, queuing delay and propagation delay of a typical symmetrical shared-tree multicast. We evaluate three placement schemes of DINCast. Our simulation results show that DINCast is effective in optimizing the multicast delay over the shared-tree multicast and the reduced rate of multicast delay may be up to 50%. Next, for any multicast tree, we carry out further simulations to optimize multicast delay. The experimental results show that DINCast can achieve better performance than original shared-tree multicast. Huaqun Guo, Lek Heng Ngoh, Lawrence Wai-Choong Wong, Nazreen Beevi |
AINA | 1 |
| 2009 | An Anonymous DoS-Resistant Password-Based Authentication, Key Exchange and Pseudonym Delivery Protocol for Vehicular NetworksabstractVehicular networks are gaining popularity because vehicular communications are able to help minimize accidents, improve traffic conditions and provide infotainment services. Security and privacy are important challenges in the deployment of vehicular networks. Authentication, key exchange and pseudonym delivery protocols can be used to provide security and privacy in vehicular networks. However, two important aspects of security and privacy, namely protection against DoS attacks and vehicle node anonymity, are currently not being addressed in existing authentication, key exchange and pseudonym delivery protocols for vehicular networks. In this paper, we propose an anonymous DoS-resistant password-based AUthentiCation, Key Exchange and Pseudonym delivERy(AUCKEPER) Protocol for vehicular networks that provides both protection against DoS attacks and vehicle node anonymity. A security and complexity analysis shows that the proposed AUCKEPER protocol is secure, more efficient and has advantages over a recently proposed state-of-the-art authentication, key exchange and pseudonym delivery protocol. Joseph Chee Ming Teo, Lek Heng Ngoh, Huaqun Guo |
AINA | 3 |
| 2009 | Secure wireless vehicle monitoring and controlabstractThe availability of real-time CAN-ECU data and the emerging vehicular networks are critical for advanced vehicle monitoring and control. This paper presents our integrated info-security scheme, real-time hardware/software solutions and their application scenarios. The core is the Integrated Info-Security Circuit Board to communicate with ECUs and sensors inside a vehicle through CAN Bus, LIN Bus, FlexRay and MOST Bus with wire interfaces, and to communicate with other vehicles, road-side infrastructure and mobile phones with wireless interfaces. We have built the first prototype with two circuit boards which communicate directly with CAN network and process CAN messages. One circuit board is used for monitoring and control Vehicle Functions via real-time CAN messages, while another circuit board is used to monitoring and control vehicle itself to against the theft. The demonstrations in the first prototype show that our solutions work very well. Huaqun Guo, Lek Heng Ngoh, Yongdong Wu, Joseph Chee Ming Teo |
APSCC | 1 |
| 2006 | An Optimized Peer-to-Peer Overlay Network for Service DiscoveryabstractIn this paper, we propose DINPeer, an optimized peer-to-peer (P2P) overlay network for service discovery by overcoming limitations in current multicast discovery approaches and P2P overlay systems. DINPeer exploits a spiral-ring method to discover an inner ring with most powerful nodes (DIN Nodes) to form a logical DINloop. With the facilitation of the DINloop, multiple DIN Nodes easily form Steiner trees using Steiner tree-based heuristic routing algorithm. DINPeer further integrates the DINloop and Steiner trees with the P2P overlay network. The key features of DINPeer include that multiple DIN Nodes function as the Rendezvous Points (RPs) for theirs associated logical spaces respectively, and Steiner trees facilitate the communication among multiple DIN Nodes. Multiple powerful DIN Nodes release the burden on the centralized server and the self-recovered DINloop avoids the single point of failure. Simulations show that DINPeer is able to reduce multicast delay for the fast service discovery. Huaqun Guo, D. Q. Zhang, Lek Heng Ngoh, Lawrence Wai-Choong Wong, Y. K. Koh |
ISCC | 1 |
| 2006 | Comparison of in-network versus Staggered Multicast video distribution models
Huaqun Guo, Lek Heng Ngoh, Lawrence Wai-Choong Wong, Joo Geok Tan |
Multim. Tools Appl. | 1 |
| 2005 | DINloop based inter-domain multicast with MPLSabstractTo overcome the existing scalability problems, DINloop (Data-in-Network loop) based multicast with MPLS (multiprotocol label switching) is proposed to optimize inter-domain multicast. In our approach, multiple DIN Nodes in the core network form the DINloop using MPLS so that multiple multicast sessions share a single DINloop. We adopts a label stack method to use fewer labels and label switch paths (LSPs) are established between DIN Nodes to create the DINloop. Packet processing module analyzes the coming multicast packet and MPLS Manager assigns a label stack to it. Simulations show that DINloop based multicast uses the least message load needed to form the multicast architecture. In addition, the routing table size in the core router does not increase as the number of multicast group increases, and therefore DINloop based multicast increases the routing scalability for inter-domain multicast. Finally, the multicast delay in DINloop based multicast is moderate lager than other protocols. Huaqun Guo, Lek Heng Ngoh, Lawrence Wai-Choong Wong |
IPCCC | 1 |
| 2005 | A DINloop-Based Inter-domain Multicast Using MPLSabstractTo overcome scalability and control overhead problems existing in inter-domain multicast, DINloop (data-in-network loop) based multicast with MPLS is proposed. DINloop is a special logical path formed using MPLS label switched paths and it consists of multiple DIN nodes which are core routers that connect to each intra-domain. We use DINloop to manage inter-domain multicast group membership. Facilitated by the DINloop, multiple DIN nodes in the core network easily form a Steiner tree for multicast traffic. Furthermore, traffic for different multicast groups sharing the same path are aggregated through a label stack. Simulations demonstrate that DINloop-based multicast results in less message load needed to form the multicast structure. In addition, the routing table size in other core routers does not increase as the number of multicast group increases, and therefore routing scalability is improved. Finally, the inter-domain multicast delay in DINloop-based multicast is lower than that of a unidirectional tree. Huaqun Guo, Lek Heng Ngoh, Lawrence Wai-Choong Wong |
ISCC | 1 |
| 2005 | DINCast: a hop efficient dynamic multicast infrastructure for P2P computing
Huaqun Guo, Lek Heng Ngoh, Lawrence Wai-Choong Wong, Joo Geok Tan |
Future Gener. Comput. Syst. | 1 |