Changzhen Hu

dblp:57/7454 · DBLP profile ↗
← Back
58ranked-venue papers
2as first author
28since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 4 since 2021Computer networks · 15 · 11 since 2021Systems, architecture and hardware · 7 · 5 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021
YearPublicationVenuePosition
2026 PQ-FRL: A Privacy-Preserving and Quality-Aware Federated Reinforcement Learning for UAV-Assisted Edge Computing
abstract
Optimizing service performance in UAV-assisted Mobile Edge Computing (MEC) systems often relies on effective cooperative trajectory and resource allocation. Federated Reinforcement Learning (FRL) provides a distributed paradigm to collaboratively learn these policies without sharing raw observations. However, practical deployments face severe coupled challenges: the model quality degradation caused by Differential Privacy (DP) noise injection, heterogeneous environments (Non-IID data), and complex physical constraints. To mitigate these issues, we propose PQ-FRL, a Privacy-Preserving and Quality-Aware FRL framework. Our approach utilizes an Output Perturbation DP mechanism to provide strict per-round protection for uploaded policy updates, representing a pragmatic engineering trade-off between securing immediate operational privacy and maintaining continuous-control DRL convergence. To address the mixed-action space, we incorporate a Straight-Through Estimator (STE) for differentiable offloading decisions, guided by a conditionally shaped reward to prevent suboptimal local equilibria. Furthermore, a novel Quality-Aware (QA) aggregation mechanism dynamically assigns weights based on explicitly DP-protected local reward signals, helping to disentangle noise from inherently poor performance. Simulation results indicate that PQ-FRL can effectively balance realistic non-linear energy and latency constraints. Under the evaluated heterogeneous scenarios and strict privacy budgets, our method demonstrates robust utility preservation and exhibits graceful degradation as physical airspace congestion increases with larger swarm sizes, offering a stable and practical solution for privacy-sensitive UAV edge computing.
Zifeng Dai, Shengjun Wei, Changzhen Hu
IEEE Internet Things J.4
2026 TARG-YOLO: an efficient small target detection framework for UAV
Zifeng Dai, Changzhen Hu, Shengjun Wei
Mach. Vis. Appl.4
2025 Defining and measuring the resilience of network services
Kewei Wang 0005, Changzhen Hu, Chun Shan
Comput. Networks2
2025 Process-oriented security assessment of network services
Kewei Wang 0005, Changzhen Hu, Chun Shan
Comput. Networks2
2025 A novel malware detection method based on audit logs and graph neural network
Yewei Zhen, Donghai Tian, Xiaohu Fu, Changzhen Hu
Eng. Appl. Artif. Intell.4
2025 IMUNE: A novel evolutionary algorithm for influence maximization in UAV networks
Shuhang Han, Donghai Tian, Changzhen Hu
J. Netw. Comput. Appl.4
2025 Distributed Set-Membership Fusion Estimation for Complex Networks With Communication Constraints
abstract
This paper concerns the distributed set-membership fusion estimation (SMFE) problem of complex networks subject to communication constraints and unknown-but-bounded (UBB) noises, where nodes communicate with their neighbours based on a given topology. There are three main contributions: 1) an event-based coding-decoding mechanism (CDM) is designed in each communication channel to code the transmitted data with a finite bit rate, where the purpose is to save communication resources and enhance transmission security; 2) a fusion estimation method, which can fusion a group of local estimation sets, is introduced to estimate the system state with a trace-maximal ellipsoid, where the local estimators make full use of the information from itself as well as its neighbours. It helps to improve the accuracy and precision of the estimation effectively; 3) a genetic algorithm (GA) is firstly adopted to tackle the co-design issue of bit rate allocation protocol and estimator gain. It aims to reduce decoding errors while ensuring good estimation performance. To demonstrate the superiority of the above contributions, a numerical simulation is provided to validate the proposed SMFE method.Note to Practitioners—Complex networks can be applied to various practical problems, such as biological networks, neural networks, and social networks. The set-membership estimation (SME) method limits the state of the system to an ellipsoidal region. This paper studies the SMFE method, which fuses an ellipsoidal set containing the intersection of all local ellipsoidal sets to form a relatively small region containing the system state, thereby improving the estimation performance. Each communication channel equals with event-based CDM, which improves the robustness and security of data transmission. The bit rate allocation mechanism optimized by GA breaks the traditional uniform allocation scheme, which can reduce decoding error and improve estimation accuracy. Therefore, the method proposed in this paper can be used for navigation and positioning devices.
Changzhen Hu, Xiangpeng Xie 0001, Sanbo Ding, Yan-Hui Jing 0001
IEEE Trans Autom. Sci. Eng.1
2024 SMP-NoC: A Flexible and Efficient Shared Memory Protection Unit on Network-on-Chip
Shengjun Wei, Changzhen Hu
ICA3PP (4)4
2024 BedIDS: An Effective Network Anomaly Detection Method by Fusing Behavior Evolution characteristics
abstract
Leveraging artificial intelligence models to enhance the performance of intrusion detection systems has become an important component in the field. However, as the scale of networks continues to expand, the structure of networks becomes more complex, and the amount of data in the networks grows larger. Existing methods are facing numerous challenges, including difficulties in constructing training datasets for models, challenges in transferring and reusing models, and high costs associated with model training. This paper introduces a novel approach named BedIDS. This method involves constructing the evolutionary process of network behavior and calculating the evolutionary characteristics of network behavior. Using only the most fundamental five network traffic features, including IP addresses, BedIDS achieves rapid and accurate detection performance on a device equipped with a 3060ti graphics card. We conducted tests using the CICIDS2017 and UNSW-NB15 datasets to evaluate its performance. Experimental results demonstrate that BedIDS maintains high detection accuracy and improves detection speed while requiring a relatively low AI computing force.
Changzhen Hu, Chun Shan, Junkai Yi
TrustCom2
2024 Component-based modeling of cascading failure propagation in directed dual-weight software networks
Donghai Tian, Chong Yuan, Changzhen Hu
Comput. Networks5
2024 Blockchain-and-6G-based Ubiquitous UAV Task Security Management Architecture
Jun Zheng 0007, Shengjun Wei, Changzhen Hu
Comput. Commun.4
2024 MDGraph: A novel malware detection method based on memory dump and graph neural network
Donghai Tian, Xiaoqi Jia, Changzhen Hu
Expert Syst. Appl.5
2024 A blockchain-based ubiquitous entity authentication and management scheme with homomorphic encryption for FANET
Jun Zheng 0007, Teng He, Shengjun Wei, Changzhen Hu
Peer Peer Netw. Appl.5
2024 Event-Based Distributed Set-Membership Estimation for Complex Networks Under Deception Attacks
abstract
This paper addresses the problem of event-based distributed set-membership estimation for complex networks with unknown but bounded (UBB) disturbances. To reflect the compromised data transmissions in cyber security, deception attacks are taken into consideration. Meanwhile, a novel estimation model is proposed against UBB disturbances. In order to schedule the signal transmissions between nodes and remote estimators, a novel decentralized dynamic periodic event-triggered mechanism (DPETM) with a time-varying threshold is developed for each node of the complex networks, which reduces the waste of communication resources and the complexity of computation. Thereafter, a series of distributed set-membership estimators are designed, whose parameters are explicitly determined in terms of the resolution of a particular linear matrix inequality (LMI) related to the information of the communication topology. An optimized ellipsoid estimation set is obtained by applying a recursive optimization algorithm. Finally, the simulation results are shown to demonstrate the viability of the proposed method.Note to Practitioners—This paper is motivated by set-membership state estimation problem of complex networks in practical missions, such as military, environment, industry, etc. The set-membership estimation of complex networks provides a reliable confidence region for each system node. Event-triggered control is an effective method for the design of set-membership estimator. But the common results require the systems to monitor the measurements point-to-point, which leads to the huge consumption of calculation and communication resources. For this reason, this paper originally extends the DPETM to the discrete-time version from the field of continuous-time systems. Meanwhile, this paper considers the deception attacks in communication channels, and the generic framework established earlier can tackle simultaneously sector-bounded nonlinearity, UBB disturbances, and deception attacks. The main difficulty of this paper lies in the analysis for the sawtooth constraint of periodic samplings. For this difficulty, we introduce a piecewise auxiliary function, which is similar with the loop-function in the field of continuous-time systems. Together with recursive optimization algorithm, the detailed analysis method is proposed for the reliable confidence regions of each set-membership estimator.
Changzhen Hu, Sanbo Ding, Xiangpeng Xie 0001
IEEE Trans Autom. Sci. Eng.1
2024 Evaluation of Application Layer DDoS Attack Effect in Cloud Native Applications
abstract
Cloud native application is especially susceptible to application layer DDoS attack. This attributes to the internal service calls, by which microservices cooperate and communicate with each other, amplifying the effect of application layer DDoS attack. Since different services have varying degrees of sensitivity to an attack, a sophisticated attacker can take advantage of those especially expensive API calls to produce serious damage to the availability of services and applications with ease. To better analyze the severity of and mitigate application layer DDoS attacks in cloud native applications, we propose a novel method to evaluate the effect of application layer DDoS attack, that is able to quantitatively characterize the amplifying effect introduced by the complex structure of application system. We first present the descriptive model of the scenario. Then, Riemannian manifolds are constructed as the state spaces of the attack scenarios, in which attacks are described as homeomorphisms. Finally, we apply differential geometry principles to quantitatively calculate the attack effect, which is derived from the action of an attack and the movement it produces in the state spaces. The proposed method is validated in various application scenarios. We show that our approach provides accurate evaluation results, and outperforms existing solutions.
Kewei Wang 0005, Changzhen Hu, Chun Shan
IEEE Trans. Cloud Comput.2
2023 TEBDS: A Trusted Execution Environment-and-Blockchain-supported IoT data sharing system
Jun Zheng 0007, Teng He, Shengjun Wei, Changzhen Hu
Future Gener. Comput. Syst.5
2023 B-UAVM: A Blockchain-Supported Secure Multi-UAV Task Management Scheme
abstract
The advent of unmanned aerial vehicle (UAV) swarm technology brings possibilities to help humans complete tasks in no man’s land, such as deserts and rainforests. However, UAV network faces many cyber threats, where attackers can impersonate legitimate entities or tamper with UAV task data. For identity security, most of the existing methods use centralized authentication schemes, which have a single point of failure problem. For data security, the existing methods only secure the task data in the ground system, ignoring the data security in the air network. Therefore, the existing methods are not suitable for ubiquitous UAV scenarios. Blockchain secures data security while eliminating the single point of failure problem, and has been widely used in distributed scenarios. In this article, to secure entity identity and task data, we propose a blockchain-supported secure multi-UAV task management scheme (B-UAVM). Specifically, a three-layer blockchain structure is constructed to secure multitasks, and achieve ubiquitous control of UAV formations. Besides, six types of blocks and three types of transactions are designed to achieve safe processing and storage of task data and entity information. Furthermore, an improved practical byzantine fault tolerance (IPBFT) consensus mechanism and a UAV-formation-action-considered ground station consensus mechanism (UFAGS) are introduced in the Server Network and Ground Control Network, respectively, to accelerate the consensus. The experimental results show that the number of transactions generated per second (TPS) of B-UAVM is about$0.5\times $and$3.7\times $of the existing method when the block size or the number of blockchain nodes increases, respectively.
Jun Zheng 0007, Teng He, Shengjun Wei, Chun Shan, Changzhen Hu
IEEE Internet Things J.6
2023 DEFIA: Evaluate defense effectiveness by fusing behavior information of cyberattacks
Zhen Liu 0034, Changzhen Hu, Chun Shan, Zheheng Peng
Inf. Sci.2
2023 ADCaDeM: A Novel Method of Calculating Attack Damage Based on Differential Manifolds
abstract
Calculating system damage caused by a cyberattack can help in understanding the impact and destructiveness of the attack to discover system security weaknesses. Thus, system damage calculations is important in the process of network offense–defense confrontation. However, there is little research on attack damage calculation. Current methods are unable to quantitatively evaluate the impact of an attack in a rational and accurate way. The lack of theoretical support and the complexity of both cyber systems and attacks bring tremendous challenges to attack damage calculations. In this paper, we propose a novel method called ADCaDeM to enable quantitative attack damage calculation based on a differential manifold. The damage is a negative utility produced by attack behaviors on an attacked object, which can be characterized and expressed by its attributes. We formally map the attack behaviors into a space constructed by the attributes of the attacked object in a mathematical way. Then, we propose an algorithm to construct these attributes as a differential manifold to represent their algebraic topological structure. According to the theory of tangent vectors and geodesics on the differential manifold, we can calculate attack behavioral utility in a physical way, such as computing the work done in physics. Regardless of the complexity of the dimensional structure of the attributes, the differential manifold structure can reasonably represent and calculate the damage caused by an attack. We simulate a data theft attack and a web penetration attack to test the performance of ADCaDeM and compare it with existing methods. Our experimental results illustrate ADCaDeM's advance in terms of rationality for calculating the damage caused by some typical cyberattacks.
Zhen Liu 0034, Changzhen Hu, Chun Shan, Zheng Yan 0002
IEEE Trans. Dependable Secur. Comput.2
2022 Calculation of utility of network services based on state manifolds
Kewei Wang 0005, Changzhen Hu, Chun Shan
Comput. Networks2
2022 CJSpector: A Novel Cryptojacking Detection Method Using Hardware Trace and Deep Learning
Qianjin Ying, Yulei Yu, Donghai Tian, Xiaoqi Jia, Rui Ma 0004, Changzhen Hu
J. Grid Comput.6
2022 MaliCage: A packed malware family classification framework based on DNN and GAN
Xianwei Gao, Changzhen Hu, Chun Shan, Weijie Han
J. Inf. Secur. Appl.2
2022 Semi-Synchronized Non-Blocking Concurrent Kernel Cruising
abstract
Kernel heap buffer overflow vulnerabilities have been exposed for decades, but there are few practical countermeasures that can be applied to OS kernels. Previous solutions either suffer from high performance overhead or compatibility problems with mainstream kernels and hardware. In this article, we presentKruiser, a concurrent kernel heap buffer overflow monitor. Unlike conventional methods, the security enforcement of which is usually inlined into the kernel execution, Kruiser migrates security enforcement from the kernel’s normal execution to a concurrent monitor process, leveraging the increasingly popular multi-core architectures. To reduce the synchronization overhead between the monitor process and the running kernel, we design a novel semi-synchronized non-blocking monitoring algorithm, which enables efficient runtime detection on live memory without incurring false positives. To prevent the monitor process from being tampered and provide guaranteed performance isolation, we utilize the virtualization technology to run the monitor process out of the monitored VM, while heap memory allocation information is collected inside the monitored VM in a secure and efficient way. The hybrid VM monitoring technique combined with the secure canary that cannot be counterfeited by attackers provides guaranteed overflow detection with high efficiency. We have implemented a prototype ofKruiserbased on Linux and the Xen/KVM hypervisor. The evaluation shows that Kruiser can detect realistic kernel heap buffer overflow attacks in cloud environment effectively with minimal cost.
Donghai Tian, Qiang Zeng 0001, Dinghao Wu, Peng Liu 0005, Changzhen Hu
IEEE Trans. Cloud Comput.5
2021 MDCHD: A novel malware detection method in cloud using hardware trace and deep learning
Donghai Tian, Qianjin Ying, Xiaoqi Jia, Rui Ma 0004, Changzhen Hu, Wenmao Liu
Comput. Networks5
2021 HBRSS: Providing high-secure data communication and manipulation in insecure cloud environments
Shengjun Wei, Changzhen Hu
Comput. Commun.5
2021 Riemannian manifold on stream data: Fourier transform and entropy-based DDoS attacks detection method
Zhen Liu 0034, Changzhen Hu, Chun Shan
Comput. Secur.2
2021 CMFuzz: context-aware adaptive mutation for fuzzers
Xiajing Wang, Changzhen Hu, Rui Ma 0004, Donghai Tian, Jinyuan He
Empir. Softw. Eng.2
2021 BinDeep: A deep learning approach to binary code similarity detection
Donghai Tian, Xiaoqi Jia, Rui Ma 0004, Shuke Liu, Changzhen Hu
Expert Syst. Appl.6
2020 LAFuzz: Neural Network for Efficient Fuzzing
abstract
Fuzzing is a well-known technique for efficiently finding software vulnerabilities. Unfortunately, due to syntax check, even the state-of-the-art fuzzers are not very efficient at discovering hard-to-trigger bugs in applications that expect highly structured inputs. Grammar-based fuzzers, while effective, often require expert knowledge and incur significant computational overhead. In this paper, we present LAFuzz, an automated fuzzer that generates high-quality seed inputs, which utilizes a variety of deep neural network model with different setup to efficiently fuzz programs that expect structured or unstructured inputs. We achieve this by combining mutation-based fuzzing and generation-based fuzzing offline. Our evaluation on 8 popular real-world applications demonstrated that LAFuzz-LSTM and LAFuzz-Attention significantly outperform AFL, a state-of-the-art fuzzer, on most cases both at discovering more crashes and achieving higher code coverage. In total, LAFuzz-LSTM and LAFuzz-Attention can effectively improve the code coverage over AFL by 7.55% and 7.67%; and both fuzzers can consistently discover 30.19% as well as 82.39% more unique crashes. Furthermore, extensive evaluation also showed that LAFuzz provides a great compatibility and expansibility.
Xiajing Wang, Changzhen Hu, Rui Ma 0004, Binbin Li 0001
ICTAI2
2020 Malware classification for the cloud via semi-supervised transfer learning
abstract
Malware threats and privacy protection are two of the biggest challenges in the cloud computing environment. Many studies have focused on the accuracy of malware detection, but they did not sufficiently take into account the privacy protection of cloud tenants. This paper proposes a novel malware detection model, based on semi-supervised transfer learning (SSTL) for the cloud, that consists of detection, prediction, and transfer components. To protect the privacy of tenants in the public cloud, a byte classifier based on a recurrent neural network (RNN) for its detection component is designed to detect malware. However, because it is limited by the scarcity of training samples, the accuracy of the byte classifier is only 94.72% after supervised learning. An asm classifier is proposed for the prediction component, and it achieves 99.69% accuracy. The transfer component invokes the prediction component to classify an unlabeled dataset, and it combines the predicted labels and byte features of the unlabeled dataset into a new training dataset. Through the advantages of semi-supervised learning, the new dataset is transferred to the byte classifier for training again. The test results on the Kaggle malware datasets show that semi-supervised transfer learning improved the accuracy of the detection component from 94.72% to 96.9%. The improved malware detection method can not only do a better job of resolving the privacy concerns of tenants in the public cloud than other similar methods, but it can also detect malware more accurately.
Xianwei Gao, Changzhen Hu, Chun Shan, Baoxu Liu, Zequn Niu
J. Inf. Secur. Appl.2
2019 Predicting blood pressure from physiological index data using the SVR algorithm
abstract
Blood pressure diseases have increasingly been identified as among the main factors threatening human health. How to accurately and conveniently measure blood pressure is the key to the implementation of effective prevention and control measures for blood pressure diseases. Traditional blood pressure measurement methods exhibit many inherent disadvantages, for example, the time needed for each measurement is difficult to determine, continuous measurement causes discomfort, and the measurement process is relatively cumbersome. Wearable devices that enable continuous measurement of blood pressure provide new opportunities and hopes. Although machine learning methods for blood pressure prediction have been studied, the accuracy of the results does not satisfy the needs of practical applications. This paper proposes an efficient blood pressure prediction method based on the support vector machine regression (SVR) algorithm to solve the key gap between the need for continuous measurement for prophylaxis and the lack of an effective method for continuous measurement. The results of the algorithm were compared with those obtained from two classical machine learning algorithms, i.e., linear regression (LinearR), back propagation neural network (BP), with respect to six evaluation indexes (accuracy, pass rate, mean absolute percentage error (MAPE), mean absolute error (MAE), R-squared coefficient of determination ( R 2 ) and Spearman’s rank correlation coefficient). The experimental results showed that the SVR model can accurately and effectively predict blood pressure. The multi-feature joint training and predicting techniques in machine learning can potentially complement and greatly improve the accuracy of traditional blood pressure measurement, resulting in better disease classification and more accurate clinical judgements.
Bing Zhang 0011, Huihui Ren, Guoyan Huang, Yongqiang Cheng 0001, Changzhen Hu
BMC Bioinform.5
2019 Software structure characteristic measurement method based on weighted network
Chun Shan, Shanshan Mei, Changzhen Hu, Limin Mao
Comput. Networks3
2019 An online approach to defeating ROP attacks∗
abstract
Summary Return‐Oriented Programming (ROP) attacks become very popular in recent years as these attacks can bypass traditional defense mechanisms such as data execution prevention (DEP) effectively. Previous solutions suffer from limitations in that: 1) some methods need to modify the target programs; 2) some methods introduce considerable performance cost; 3) some methods rely on the special hardware; and 4) ,most of existing methods could not provide an online protection for the target processes. In this paper, we present OnRop, an on‐the‐fly ROP attack protection system by using the commodity hardware features and OS internal facilities. Our system is compatible with the existing programs, and its protection layer can be added on demand. The experiments show that OnRop can detect ROP attacks effectively with moderate performance cost.
Donghai Tian, Xiaoqi Jia, Zhaolong Zhang, Li Zhan, Changzhen Hu, Jingfeng Xue
Concurr. Comput. Pract. Exp.5
2019 KEcruiser: A novel control flow protection for kernel extensions
Donghai Tian, Rui Ma 0004, Xiaoqi Jia, Changzhen Hu
Future Gener. Comput. Syst.4
2019 DEPLEST: A blockchain-based privacy-preserving distributed database toward user behaviors in social networks
Yun Chen 0004, Shengjun Wei, Changzhen Hu
Inf. Sci.5
2019 Establishing a software defect prediction model via effective dimension reduction
Changzhen Hu, Quanxin Zhang 0001
Inf. Sci.2
2018 A Double-Layer Detection and Classification Approach for Network Attacks
abstract
Network intrusion detection system (NIDS) plays a crucial role in maintaining network security. In this paper, we propose a novel double-layer detection and classification technique for network attacks. The advantage of our proposed method is that our two-layer hybird detection combines the advantage of multiple techniques, especially stacking ensemble method, and has better generalization performance. The first layer contains a GBDT classifier which is responsible for identifying DoS (Denial of Service) attacks. The second layer consists of KNN classifier and stacking ensemble classifier. KNN classifier is used to classify the DoS data from the first layer as more subtypes, such as, smurf, pod, neptune, teardrop, back and other DoS attack subtypes. Stacking ensemble classifier optimized by FOA (Fly Optimization Algorithm) is applied to divide the nonDoS data from the first layer to Normal, Probe, R2L (Remote to Local) and U2L (User to Root). The simulation and analysis are done based on KDD99 dataset and we use accuracy, precision rate and recall rate to evaluate our method. The experimental results suggest that our proposed method is a more robust and reliable model and can achieve higher accuracy than other previous methods.
Changzhen Hu
ICCCN3
2018 A Monte Carlo Graph Search Algorithm with Ant Colony Optimization for Optimal Attack Path Analysis
abstract
An optimal attack path is essential for an attacker. With an optimal attack path, the attacker can not only successfully carry out attacks, but also save time, energy and money. This article proposes a Monte Carlo Graph Search algorithm with Ant Colony Optimization(ACO-MCGS) to calculate optimal attack paths in target network. ACO-MCGS can get comprehensive results quickly and avoid the problem of path loss. ACO-MCGS has two steps to calculate optimal attack paths: selection and backpropagation. A weight vector containing host priority, CVSS risk value , host link number is proposed for every host in the target network. The weight vector is applied to improved Ant Colony Optimization algorithm to calculate the evaluation value of every attack path, which is used to screen the optimal attack paths for the first round. The weight vector is also used to calculate the total CVSS value and the average CVSS value of every attack path. Results of our experiment demonstrate the capabilities of the proposed algorithm to generate optimal attack paths in one single run. The results obtained by ACO-MCGS show good performance and are compared with Ant Colony Optimization Algorithm (ACO).
Changzhen Hu
ICCCN3
2018 A Dynamic Hidden Forwarding Path Planning Method Based on Improved Q-Learning in SDN Environments
abstract
Currently, many methods are available to improve the target network’s security. The vast majority of them cannot obtain an optimal attack path and interdict it dynamically and conveniently. Almost all defense strategies aim to repair known vulnerabilities or limit services in target network to improve security of network. These methods cannot response to the attacks in real-time because sometimes they need to wait for manufacturers releasing corresponding countermeasures to repair vulnerabilities. In this paper, we propose an improved Q-learning algorithm to plan an optimal attack path directly and automatically. Based on this path, we use software-defined network (SDN) to adjust routing paths and create hidden forwarding paths dynamically to filter vicious attack requests. Compared to other machine learning algorithms, Q-learning only needs to input the target state to its agents, which can avoid early complex training process. We improve Q-learning algorithm in two aspects. First, a reward function based on the weights of hosts and attack success rates of vulnerabilities is proposed, which can adapt to different network topologies precisely. Second, we remove the actions and merge them into every state that reduces complexity from O(N3) to O(N2) . In experiments, after deploying hidden forwarding paths, the security of target network is boosted significantly without having to repair network vulnerabilities immediately.
Yun Chen 0004, Changzhen Hu
Secur. Commun. Networks3
2018 Security Feature Measurement for Frequent Dynamic Execution Paths in Software System
abstract
The scale and complexity of software systems are constantly increasing, imposing new challenges for software fault location and daily maintenance. In this paper, the Security Feature measurement algorithm of Frequent dynamic execution Paths in Software, SFFPS, is proposed to provide a basis for improving the security and reliability of software. First, the dynamic execution of a complex software system is mapped onto a complex network model and sequence model. This, combined with the invocation and dependency relationships between function nodes, fault cumulative effect, and spread effect, can be analyzed. The function node security features of the software complex network are defined and measured according to the degree distribution and global step attenuation factor. Finally, frequent software execution paths are mined and weighted, and security metrics of the frequent paths are obtained and sorted. The experimental results show that SFFPS has good time performance and scalability, and the security features of the important paths in the software can be effectively measured. This study provides a guide for the research of defect propagation, software reliability, and software integration testing.
Qian Wang 0009, Jiadong Ren, Yongqiang Cheng 0001, Darryl N. Davis, Changzhen Hu
Secur. Commun. Networks6
2018 A policy-centric approach to protecting OS kernel from vulnerable LKMs
abstract
Summary Loadable kernel modules (LKMs) that contain vulnerabilities are a big threat to modern operating systems (OSs). The primary reason is that there is no protection mechanism inside the kernel space when the LKM is executed. As a result, kernel module exploitation can seriously affect the OS kernel security. Although many protection systems have been developed to address this problem in the past few years, there still remain some challenges: (1) How to automatically generate a security policy before the kernel module is enforced? (2) How to properly mediate the interactions between the kernel module and the OS kernel without modifications on the existing OS, hardware, and kernel module structure? To address these challenges, we present LKM guard (LKMG), a policy‐centric system that can protect commodity OS kernel from vulnerable LKMs. Compared with previous systems, LKMG is able to generate a security policy from a kernel module and then enforce the policy during the run time. Generally, the working process of LKMG can be divided into 2 stages. First, we utilize static analysis to extract the kernel code and data access patterns from a kernel module's source code and then combine these patterns with the related memory address information to generate a security policy. Second, by leveraging the hardware‐assisted virtualization technology, LKMG isolates the kernel module from the rest of the kernel and then enforces the kernel module's execution to obey the derived policy. The experiments show that our system can defend against various attacks launched by the compromised kernel module effectively with moderate performance cost.
Donghai Tian, Changzhen Hu, Peng Liu 0005
Softw. Pract. Exp.3
2017 Mining Frequent Patterns for Item-Oriented and Customer-Oriented Analysis
abstract
Frequent pattern mining can well extract insight from transaction patterns, and it is a desired capability for fully understanding the customer's purchase behavior. However, most of the algorithms are focus on the transverse relationship and the longitudinal analysis is missed. To address this defect, FP-ICA, a Frequent Pattern mining algorithm for Item-oriented and Customer-oriented Analysis is proposed. A pattern with its items occur in the same transaction is item-oriented, and a pattern with its items occur cross several transactions of a customer is customer-oriented. FP-ICA transforms the transactions to a bitmap which contains a header for recording customer information, and the frequent patterns are obtained by logic And-operation. Different mining rules are used for item-oriented and customer-oriented discovery. Experiments are conducted to demonstrate the fast speed achievement and good scalability of FP-ICA.
Wenzhe Liao, Qian Wang 0009, Jiadong Ren, Yongqiang Cheng 0001, Changzhen Hu
WISA6
2017 Mining Frequent Intra-Sequence and Inter-Sequence Patterns Using Bitmap with a Maximal Span
abstract
Frequent intra-sequence pattern mining and inter-sequence pattern mining are both important ways of association rule mining for different applications. However, most algorithms focus on just one of them, as attempting both is usually inefficient. To address this deficiency, FIIP-BM, a Frequent Intra-sequence and Inter-sequence Pattern mining algorithm using Bitmap with a maxSpan is proposed. FIIP-BM transforms each transaction to a bit vector, adjusts the maximal span according to user's demand and obtains the frequent sequences by logic And-operation. For candidate 2-pattern generation, the subscripts of the joining items should be checked first; the bit vector of the joining item will be left-shifted before calculation if the subscript is not 0. Left alignment rule is used for different bit vector length problems. FIIP-BM can mine both intra-sequence and inter-sequence patterns. Experiments are conducted to demonstrate the computational speed and memory efficiency of the FIIP-BM algorithm.
Wenzhe Liao, Qian Wang 0009, Luqun Yang, Jiadong Ren, Darryl N. Davis, Changzhen Hu
WISA6
2017 Anti-Jamming Power Control Game in Unmanned Aerial Vehicle Networks
abstract
In this paper, the anti-jamming issue in unmanned aerial vehicle (UAV) networks is analyzed in a static game and a dynamic game. We investigate the effect of wireless channel fading characteristics from a UAV to a ground station and flying cost on the performance of a closed-form Nash equilibrium (NE) in the static game. Besides, in a Stackelberg dynamic game, wherein the system model is hard to determine, we propose a Q- learning based anti-jamming scheme and evaluate its performance via exhaustive simulations, which can achieve relatively higher average utility and Signal to Interference plus Noise Ratio (SINR) than a benchmark method.
Shichao Lv, Liang Xiao 0003, Xiaoshan Wang, Changzhen Hu, Limin Sun 0001
GLOBECOM5
2017 Optimal Attack Path Generation Based on Supervised Kohonen Neural Network
Yun Chen 0004, Changzhen Hu
NSS3
2017 Defenses Against Wormhole Attacks in Wireless Sensor Networks
Rui Ma 0004, Changzhen Hu, Xiajing Wang
NSS4
2017 SulleyEX: A Fuzzer for Stateful Network Protocol
Rui Ma 0004, Tianbao Zhu, Changzhen Hu, Chun Shan
NSS3
2017 A Detecting Method of Array Bounds Defects Based on Symbolic Execution
Chun Shan, Shiyou Sun, Jingfeng Xue, Changzhen Hu
NSS4
2017 A Practical Method to Confine Sensitive API Invocations on Commodity Hardware
Donghai Tian, Dingjun Qi, Li Zhan, Yuhang Yin, Changzhen Hu, Jingfeng Xue
NSS5
2017 An Automatic Vulnerabilities Classification Method Based on Their Relevance
Changzhen Hu
NSS3
2017 A Quantitative Method for Evaluating Network Security Based on Attack Graph
Yukun Zheng, Changzhen Hu
NSS3
2014 Approach for malware identification using dynamic behaviour and outcome triggering
abstract
Malware identification is the process of determining the maliciousness of a program, which is necessary for detecting malware variants. Although some techniques have been developed to confront the rapid expansion of malware, they are not efficient to recognise booming malware instances, and can be evaded by using obfuscation techniques. In this study, a novel dynamic malware identification approach is proposed. Concretely, this approach employs techniques that explore multiple execution paths and trigger malicious behaviours with resulting outcomes. To this end, a group of featured malicious behaviours and outcomes (MBOs) are primarily constructed, from which weights for malware family classification are derived. A virtual monitor is then developed to dynamically trigger MBOs by exploring multipath with suitable probing depths. Finally, triggered malicious behaviours are modelled with features recorded in MBOs to train a malware classifier which can identify unknown malware variants. The experimental results on test cases demonstrate the proposed approach is effective in identifying new variants of popular malware families. The comparison with latest malware identifiers shows that our approach achieves lower false positive rate and can recognise malware equipped with obfuscation techniques.
Changzhen Hu, Xiao-chuan Jing, Xiaoyin Wang
IET Inf. Secur.2
2013 A Dynamic Detection Method to C/C++ Programs Memory Vulnerabilities Based on Pointer Analysis
abstract
Aiming at the problem of higher memory consumption and lower execution efficiency during the dynamic detecting to C/C++ programs memory vulnerabilities, this paper presents a dynamic detection method called ISC. The ISC improves the Safe-C using pointer analysis technology. Firstly, the ISC defines a simple and efficient fat pointer representation instead of the safe pointer in the Safe-C. Furthermore, the ISC uses the unification-based analysis algorithm with one level flow static pointer. This identification reduces the number of pointers that need to be converted to fat pointers. Then in the process of program running, the ISC detects memory vulnerabilities through constantly inspecting the attributes of fat pointers. Experimental results indicate that the ISC could detect memory vulnerabilities such as buffer overflows and dangling pointers. Comparing with the Safe-C, the ISC dramatically reduces the memory consumption and lightly improves the execution efficiency.
Rui Ma 0004, Lingkui Chen, Changzhen Hu, Jingfeng Xue
DASC3
2012 Kruiser: Semi-synchronized Non-blocking Concurrent Kernel Heap Buffer Overflow Monitoring
Donghai Tian, Qiang Zeng 0001, Dinghao Wu, Peng Liu 0005, Changzhen Hu
NDSS5
2011 Policy-Centric Protection of OS Kernel from Vulnerable Loadable Kernel Modules
Donghai Tian, Changzhen Hu, Peng Liu 0005
ISPEC3
2011 Boosting performance in attack intention recognition by integrating multiple techniques
Kunsheng Wang, Changzhen Hu, Xiao-chuan Jing
Frontiers Comput. Sci. China3
2010 Integrating Offline Analysis and Online Protection to Defeat Buffer Overflow Attacks
Donghai Tian, Changzhen Hu, Peng Liu 0005
ISC3
2009 Hierarchical Distributed Alert Correlation Model
abstract
Alert correlation is a promising technique in intrusion detection. It takes the alerts produced by intrusion detection systems and produces compact reports which provide a more succinct and high-level view of occurring or attempted intrusions and highly improve security expert's work efficiency. Traditional alert correlation system adopts a centralized architecture which can be easily over flooded by the raw alarms. To address this issue, a distributed alert correlation model based on hierarchical architecture is proposed. This model greatly improves the performance of alert correlation through integrating three novel methods. The experiments show effectiveness of this alert correlation model on 2000 DARPA intrusion detection scenario specific datasets.
Donghai Tian, Changzhen Hu
IAS2