EDBT 2026 Demo / reviewers in the wild / expert
Xuren Wang
dblp:74/4411
· DBLP profile ↗
29ranked-venue papers
9as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 10 · 3 first-author · 10 since 2021Security and privacy · 7 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 6 · 4 first-author · 2 since 2021Computer networks · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HiLo-MAE: Efficient Pre-trained Traffic Representation for Encrypted Network Sensing
Xubo Jiang, Xuren Wang |
SECON | 5 |
| 2025 | A Variant and Flow-Level AutoML Method for IoT Malicious Traffic DetectionabstractThe Internet of Things (IoT) involves communication and data exchange between a wide range of devices, often with security implications. Compared to Internet, IoT is costly to detect malicious traffic due to its complex protocols, resource limitations and variety of new attacks and attack variants. Automatic machine learning (AutoML) eliminates model selection and hyperparameter optimisation, which can reduce human dependency and address these issues. However, AutoML still cannot extract and represent features from raw data based on a specific problem. Manual feature extraction and representation will greatly affect the accuracy of the model and still rely on professional domain knowledge. Automated feature engineering in AutoML requires universal and efficient feature extraction and representation. This paper proposes a variant and flow-level AutoML (VFA) for IoT malicious traffic detection. VFA has added a binary representation of comprehensive content features based on the packet. The packet representation allows AutoML to automatically learn important features from a normalised aligned structure without guidance. Variant of exclusive OR (vXOR) enables data aggregation, allowing VFA to focus on the content features in the flow and the inherent connections between packets. VFA can strategically adjust monitoring priorities by adjusting parameters, allowing it to respond flexibly to different resource constraints or specific attack. We have evaluated VFA on a real-world dataset, IoT-23. We believe that the complete data-to-label VFA can be extended to other areas in the future. Xinqiang Zhao, Xuren Wang, Zijing Fan, Yepeng Yao, Zhengwei Jiang |
CSCWD | 3 |
| 2025 | Exploring the Effectiveness of Traditional Machine Learning Models in IoT Malicious Traffic DetectionabstractAs the Internet of Things (IoT) rapidly evolves, security concerns have become increasingly prominent. Machine learning-based network intrusion detection systems can identify and respond to malicious traffic with minimal latency. However, building an effective IoT malicious traffic detection system requires specialized knowledge, and the limited computational resources of IoT devices pose a trade-off between utility and security. Addressing these challenges, this study presents research on an IoT malicious traffic detection model based on traditional machine learning techniques. Compared to other methods, traditional machine learning models have fewer parameters and lower storage requirements. This study optimized the construction process of traditional machine learning models, using feature reduction and recursive feature elimination to minimize the number of features, thereby further reducing model parameters. Bayesian optimization was employed to mitigate performance errors from manual tuning, leading to the selection of the most optimal model. This research focuses on flow-level data classification, specifically selecting flow-level statistical features as model inputs. These features enable the model to conduct detailed analysis of data flows, accurately classifying them into different categories, such as benign traffic, DDoS attacks, and botnets. In experimental evaluations, the model demonstrated high accuracy, with an F1 score exceeding 0.75, validating its effectiveness and reliability in real-world applications. Famei He, Songheng He, Runshi Liu, Qianli Li, Xuren Wang |
CSCWD | 8 |
| 2025 | ET-FS: Functional Specialization Method for Multi-Task Learning in Encrypted Traffic ClassificationabstractPre-trained Transformer models have demonstrated remarkable ability in learning generalizable feature representations for encrypted traffic analysis, driving the development of effective methods in this field. Their separate hidden and output layer architecture supports efficient multi-task joint classification. However, in real-world multi-task scenarios, these models face challenges due to high computational overhead and performance degradation on individual tasks during joint training. To address these, we introduce ET-FS (Encrypted Traffic Classification via Functional Specialization), a novel three-stage framework for efficient multi-task training in encrypted traffic classification. In the first stage, ET-FS constructs a multi-task joint model based on pre-trained encrypted traffic models and task groups, followed by joint fine-tuning using single-task labeled datasets. In the second stage, we propose an innovative method to assess the nature of tasks within the model and groups, allowing identification of optimal parameters. In the third stage, we leverage the functional specialization of multi-head attention in Transformer architectures, introducing a partially frozen multi-task fine-tuning strategy. Specifically, during the final phase of training, only a selected proportion of task-related attention heads are updated, while irrelevant heads are frozen, mitigating gradient interference between tasks. Experimental results show that the ET-FS Final Model, trained with the proposed framework, is applicable across diverse scenarios. With sufficient resources, it surpasses baselines on all tasks and metrics, achieving 93% accuracy for app classification, 98% for service classification, and over 99% for other tasks. Even with limited resources and imbalanced datasets, it maintains robust performance and good generalization, highlighting its practical potential for encrypted traffic classification. Xinzhu Feng, Gaopeng Gou, Chang Liu 0049, Wenqi Dong, Famei He, Xuren Wang |
TrustCom | 7 |
| 2024 | HRTC: A Triplet Joint Extraction Model Based on Cyber Threat Intelligence
HuanZhou Yue, Xuren Wang, Zhengwei Jiang, Yuxia Fu |
KSEM (5) | 2 |
| 2024 | P-TIMA: a framework of T witter threat intelligence mining and analysis based on a prompt-learning NER modelabstractAbstract Open-source information platforms such as Twitter continuously provide the latest threat intelligence, including new vulnerabilities and in-the-wild exploitations of advanced persistent threat (APT) groups. Automated extraction of threat intelligence from Twitter has become crucial for defenders to access up-to-date threat knowledge. However, existing studies mainly rely on supervised learning methods to extract threat intelligence knowledge, such as entities, which require a large amount of annotated data. This paper presents Threat Intelligence Mining and Analysis based on Prompt Learning (P-TIMA), a framework specifically crafted for extracting and analyzing threat intelligence from Twitter. P-TIMA employs our innovative few-shot entity recognition method, SecEntPrompt (SEP), built on prompt learning, to extract vulnerability intelligence from Twitter. Additionally, P-TIMA analyzes and profiles the overarching vulnerability intelligence obtained from Twitter, along with in-the-wild exploitation intelligence of APT groups. The SEP improves the average entity recognition F1 score by 3.62-4.40 compared with the best-performing comparison model and outperforms the method based on the large language model on recognition performance and inference time. To validate our framework, we apply P-TIMA to extract vulnerability-related threat intelligence from real Twitter data. Through case studies, we then analyze trends in vulnerability threats and the exploitation capabilities of APT groups. In conclusion, our framework provides a more efficient and accurate method for extracting threat intelligence from Twitter, enabling defenders to stay up-to-date with the latest threat trends and helping them improve their defense strategies against cyber attacks. Yizhe You, Zhengwei Jiang, Peian Yang, Kai Zhang 0035, Xuren Wang, Chenpeng Tu, Huamin Feng |
Comput. J. | 6 |
| 2023 | Simplified-Xception: A New Way to Speed Up Malicious Code ClassificationabstractTraditional malicious code detection methods require a lot of manpower and resources, which makes the research of malicious code very difficult. The selection of malicious code features mainly relies on the subjective analysis and selection of experts, which has a large impact on the detection effect of the model. In this paper, malicious codes are converted into greyscale images as model inputs, and features are automatically extracted using a deep-learning model. An improved convolutional neural network model based on Xception (Simplified Xception) is proposed for malicious code family classification. The model reduces the number of modules in the original model and adds a depth-separable convolutional layer with a step size of 2 to enhance the generated grey-scale images. The model is compared with CNN models, ResNet50, and improved models related to Inception. The experimental results show that the accuracy of SimplifiedXception is 98%, which is better than other related models. Compared to the Xception model, the accuracy of the Simplified-Xception model was improved by 1.3% and the number of parameters was reduced by half. Xinshuai Zhu, Songheng He, Xuren Wang, Peian Yang, Yuxia Fu |
CSCWD | 3 |
| 2023 | FineCTI: A Framework for Mining Fine-grained Cyber Threat Information from Twitter Using NER ModelabstractTo timely respond to cyber threats related to a specific IT infrastructure called fine-grained (e.g., Windows or Linux), security analysts need to require timely and comprehensive threat information. Twitter, as a vital source of real-time threat information, provides abundant but overwhelming information due to the increased data sources. Automatically mining and summarizing fine-grained threat information from Twitter can help security analysts maintain the infrastructure’s security. Most existing studies focus on classification, which carries less threat information. Some works use clustering based on text similarity relying on the embedding of text obtained from pre-trained models, which cannot be applied to short text, resulting in noisy clusters. Several works build topic models. However, the incoherent topic keywords are difficult to understand and analyze. To overcome these challenges, we design a FineCTI framework to mine the threat information related to the specific infrastructure on Twitter and generate a detailed threat information summary that is machine-readable and human-readable, efficiently reducing information overload. FineCTI optimizes the feature extraction part based on the named entity recognition model and performs clustering based on features extracted, thus effectively reducing the influence of sparsity of tweets on the clustering result and with the V-measure score improved by 7%. The cluster analysis results show that we can mine the fine-grained threats up to 15 days before the official disclosure date. Kai Zhang 0035, Zhengwei Jiang, Peian Yang, Xuren Wang, Huamin Feng |
TrustCom | 6 |
| 2022 | TI-Prompt: Towards a Prompt Tuning Method for Few-shot Threat Intelligence Twitter Classification*abstractObtaining the latest Threat Intelligence (TI) via Twitter has become one of the most important methods for defenders to catch up with emerging cyber threats. Existing TI Twitter classification works mainly based on supervised learning methods. Such approaches require large amounts of annotated data and are difficult to be transferred to other TI Twitter classification tasks. This paper proposes a prompt-based method for classifying TI on Twitter, named TI-Prompt. TI-Prompt lever-ages the prompt-tuning method with two templates in different TI Twitter classification tasks. TI-Prompt also uses a semantic similarity-based approach to automatically enrich the prompt verbalizer without expert knowledge and a verbalizer refinement method to calibrate the verbalizer based on the training data. We evaluate TI-Prompt with binary and multi-classification tasks on two Twitter Threat Intelligence datasets. Evaluation results show that the proposed TI-Prompt improves 5-10% over the best performance of previous supervised learning methods under the few-shot settings. Compared to the general prompt-tuning methods, the proposed prompt-tuning templates can also improve the classification performance by 2–5%. Meanwhile, the proposed verbalizer enrichment method and refinement method improve classification accuracy by 1–4% compared with the general single-word verbalizer prompt method. Therefore, TI-Prompt can be extended to other Threat Intelligence classification tasks without requiring large amounts of training data, significantly reducing the annotation cost. Yizhe You, Zhengwei Jiang, Kai Zhang 0035, Xuren Wang, Shirui Wang, Huamin Feng |
COMPSAC | 5 |
| 2022 | The Hyperbolic Temporal Attention Based Differentiable Neural Turing Machines for Diachronic Graph Embedding in Cyber Threat IntelligenceabstractCyber Threat Intelligence (CTI) is an effective approach to solve cyber security problems, finding unknown threats is becoming a problem to be solved. Research based on threat intelligence knowledge graphs has gradually increased for its capability to capture entity characteristics and better predict unknown threats. Most of the current research focuses on Euclidean space, however, the Euclidean space is insufficient to capture the hierarchical information of the knowledge graph. In this paper, we propose a novel Hyperbolic Temporal Attention based Differential Neural Turing Machines for diachronic graph embedding framework (HTA-DNTM), which adopts a graph attention network model based on hyperbolic space, simultaneously uses multi-head self-attention to map the temporal graph into hyperbolic space and incorporates hyperbolic graph neural network and hyperbolic gated recurrent neural network, capturing the evolving behaviors and implicitly preserve hierarchical information simultaneously. Moreover, we demonstrate significantly improved performance over various approaches on CTI. A series of benchmark experiments illustrate HTA-DNTM has ability to generate higher quality than state-of-the-art word embedding models in CTI fields. Binghua Song, Baoxu Liu, Zhengwei Jiang, Xuren Wang |
CSCWD | 5 |
| 2022 | APTNER: A Specific Dataset for NER Missions in Cyber Threat Intelligence FieldabstractThis paper provides a new dataset for Named Entity Recognition (NER) missions in cyber threat intelligence (CTI) studying. To the best of our knowledge, the proposed dataset is the biggest and challenging one in the field to comply with the STIX 2.1 specification. We collected the APT (Advanced Persistent Threats) reports from different network security companies and manually annotated them. Then we constructed a dataset named APTNER, which can be used for NER joint and multi-task learning tasks in CTI. Apart from common labels like IP, URL, mal-ware, location and so on, APTNER contains 21 categories, which make APTNER more challenging than other NER datasets in CTI field and we have proved the rationality of the dataset. For ease of comparison studies, we realize several state-of-the-art baselines and report their analysis. To facilitate future work on fine-grained NER for CTI, we make APTNER public at https://github.com/wangxuren/APTNER. Xuren Wang, Songheng He, Zihan Xiong, Xinxin Wei, Zhengwei Jiang |
CSCWD | 1 |
| 2022 | Cyber Threat Intelligence Entity Extraction Based on Deep Learning and Field Knowledge EngineeringabstractThe typical domain characteristics of Cyber Threat Intelligence (CTI), such as fuzzy entity boundary, polysemy or a single word corresponding to multiple word expressions and so on, makes the entity recognition result be worse than we expected. In addition, there are many challenges in directly migrating entity recognition models from the general field to CTI field. Therefore, we propose a deep learning entity recognition model with supplementing the domain knowledge engineering, which takes the open-source Cyber Threat Intelligence entity recognition as the research object, covering natural language processing, deep learning and cyber threat intelligence fields. Firstly, we use BERT model to obtain the dynamic word vector, then encode the word sequence by using BiLSTM-CRF, and finally improve the recognition result by using knowledge engineering of the Cyber Threat Intelligence to help increase the accuracy of entity recognition. Besides, we verify the effectiveness of the proposed model by experiments. Xuren Wang, Runshi Liu, Zhiting Ling, Peian Yang |
CSCWD | 1 |
| 2022 | A Graph Learning Approach with Audit Records for Advanced Attack InvestigationabstractSystem audit logs are widely adopted in enterprise security by their support for causality analysis that generates provenance graphs to investigate advanced attacks. However, detecting attack activity in the overwhelming amount of logs is like looking for a needle in a haystack, which slows down the speed of attack investigation. In this paper, we propose an automated approach for attack detection and investigation by learning the contextual semantics of the provenance graph. Our framework uncovers the semantics of the attack events through the structural context of audit logs. Further, an attention-based graph convolutional neural network is utilized to capture the structural identity associated with the attack path. It is important to note that when inferring whether a specific system node is malicious or not, our approach optimizes the provenance subgraph generated for that node without destroying its contextual semantics. The discovered attack nodes are correlated chronologically for attack investigation and scenario reconstruction. Our approach is evaluated on a real-world Advanced Persistent Threats (APT) dataset. The results show that our approach has a high F1 score (95.97%) for identifying attack nodes in audit logs and speeds up the process of attack investigation (reducing the analysis workload by 91.24%). Jian Liu 0008, Zhengwei Jiang, Xuren Wang |
GLOBECOM | 4 |
| 2022 | TriCTI: an actionable cyber threat intelligence discovery system via trigger-enhanced neural networkabstractAbstract The cybersecurity report provides unstructured actionable cyber threat intelligence (CTI) with detailed threat attack procedures and indicators of compromise (IOCs), e.g., malware hash or URL (uniform resource locator) of command and control server. The actionable CTI, integrated into intrusion detection systems, can not only prioritize the most urgent threats based on the campaign stages of attack vectors (i.e., IOCs) but also take appropriate mitigation measures based on contextual information of the alerts. However, the dramatic growth in the number of cybersecurity reports makes it nearly impossible for security professionals to find an efficient way to use these massive amounts of threat intelligence. In this paper, we propose a trigger-enhanced actionable CTI discovery system (TriCTI) to portray a relationship between IOCs and campaign stages and generate actionable CTI from cybersecurity reports through natural language processing (NLP) technology. Specifically, we introduce the “campaign trigger” for an effective explanation of the campaign stages to improve the performance of the classification model. The campaign trigger phrases are the keywords in the sentence that imply the campaign stage. The trained final trigger vectors have similar space representations with the keywords in the unseen sentence and will help correct classification by increasing the weight of the keywords. We also meticulously devise a data augmentation specifically for cybersecurity training sets to cope with the challenge of the scarcity of annotation data sets. Compared with state-of-the-art text classification models, such as BERT, the trigger-enhanced classification model has better performance with accuracy (86.99%) and F1 score (87.02%). We run TriCTI on more than 29k cybersecurity reports, from which we automatically and efficiently collect 113,543 actionable CTI. In particular, we verify the actionability of discovered CTI by using large-scale field data from VirusTotal (VT). The results demonstrate that the threat intelligence provided by VT lacks a part of the threat context for IOCs, such as the Actions on Objectives campaign stage. As a comparison, our proposed method can completely identify the actionable CTI in all campaign stages. Accordingly, cyber threats can be identified and resisted at any campaign stage with the discovered actionable CTI. Jian Liu 0008, Yitong He, Xuren Wang, Zhengwei Jiang, Peian Yang |
Cybersecur. | 5 |
| 2022 | TIM: threat context-enhanced TTP intelligence mining on unstructured threat dataabstractAbstract TTPs (Tactics, Techniques, and Procedures), which represent an attacker’s goals and methods, are the long period and essential feature of the attacker. Defenders can use TTP intelligence to perform the penetration test and compensate for defense deficiency. However, most TTP intelligence is described in unstructured threat data, such as APT analysis reports. Manually converting natural language TTPs descriptions to standard TTP names, such as ATT&CK TTP names and IDs, is time-consuming and requires deep expertise. In this paper, we define the TTP classification task as a sentence classification task. We annotate a new sentence-level TTP dataset with 6 categories and 6061 TTP descriptions from 10761 security analysis reports. We construct a threat context-enhanced TTP intelligence mining (TIM) framework to mine TTP intelligence from unstructured threat data. The TIM framework uses TCENet (Threat Context Enhanced Network) to find and classify TTP descriptions, which we define as three continuous sentences, from textual data. Meanwhile, we use the element features of TTP in the descriptions to enhance the TTPs classification accuracy of TCENet. The evaluation result shows that the average classification accuracy of our proposed method on the 6 TTP categories reaches 0.941. The evaluation results also show that adding TTP element features can improve our classification accuracy compared to using only text features. TCENet also achieved the best results compared to the previous document-level TTP classification works and other popular text classification methods, even in the case of few-shot training samples. Finally, the TIM framework organizes TTP descriptions and TTP elements into STIX 2.1 format as final TTP intelligence for sharing the long-period and essential attack behavior characteristics of attackers. In addition, we transform TTP intelligence into sigma detection rules for attack behavior detection. Such TTP intelligence and rules can help defenders deploy long-term effective threat detection and perform more realistic attack simulations to strengthen defense. Yizhe You, Zhengwei Jiang, Peian Yang, Baoxu Liu, Huamin Feng, Xuren Wang |
Cybersecur. | 7 |
| 2021 | Modeling Attackers Based on Heterogenous Graph through Malicious HTTP RequestsabstractAs modern computer attacks are growing more and more complicated, there is a need for defenders to detect malicious activities and analyze which attacker or organization these attacks came from. It is a challenge to model an attacker from malicious web logs. In this paper, we modeled attacker activities based on malicious HTTP requests collected from kinds of websites, which recorded the behavior of IP addresses and provided the possibility to describe the attacker based on HTTP requests. First, we propose a novel method to get the IP address embedding through two aspects: we designed a heterogeneous graph, named IP-Domain-Graph, to capture the relation between the IP address and the domain it has sent malicious requests, and we designed an embedding method of requests content to capture the behavioral characteristics of the IP address. Then we use a similarity calculation method to cluster IP addresses to describe an attacker. The experimental results demonstrate the effectiveness of the proposed method. Shengqin Ao, Yitong He, Xuren Wang, Zhengwei Jiang |
CSCWD | 4 |
| 2021 | HSRF: Community Detection Based on Heterogeneous Attributes and Semi-Supervised Random ForestabstractPotential connections between complex networks need to be discovered by the network community detection. Current detection methods are commonly based on homogeneous information networks, which usually extract single information among the nodes of the complex network and will lead to incomplete information or information loss. To address these problems existing on community detection, we propose a novel method based on heterogeneous attributes and semi-supervised Random Forest (HSRF) inspired by heterogeneous information networks. We define heterogeneous attribute arrays of nodes, which reflect the structural relationships between nodes in complex networks. Semi-supervised learning based on Jaccard similarity coefficients is introduced to predict the noise points and solve the problem of anti-noise interference. Our experiments on real networks and synthetic standard networks show that HSRF improves the generalization of the undirected and directed network community detection. Moreover, our HSRF performs better in terms of robustness when the community boundary structure becomes more ambiguous and convenient for parallel processing. Zijing Fan, Liling Xin, Xuren Wang, Zhengwei Jiang, Qiuyun Wang |
CSCWD | 4 |
| 2021 | A Framework for Document-level Cybersecurity Event Extraction from Open Source DataabstractWith the rapid development of the Internet, the number of cyber threats increases exponentially. More and more cyber threats come from new and unexpected sources, leading organizations and individuals to facing more security risks and vulnerabilities. Automatically obtaining and structuring security information from cybersecurity news can help security analysts to identify useful information more quickly. Most existing studies on extracting security events merely focused on the event detection task, aiming to discover and categorize cybersecurity events from the plain text. However, such event detection methods cannot capture useful information such as who performed the cyberattack, when the data breach event happened, who was the victim, etc. These arguments of a cybersecurity event are needed for analysts to get cybersecurity event details directly. Several studies have tried to extract rich semantic information of cybersecurity events, but they merely focused on extracting event arguments within the sentence scope. These studies still have limitations when the event arguments needed to recognize spread across multiple sentences. In this paper, we proposed a framework that effectively extracts cybersecurity events at the document-level from cybersecurity news, blogs and announcements. We model the document level event extraction task as a sequence tagging problem. The goal is to identify the related arguments of cybersecurity events from documents. Firstly, we get the characters embedding and incorporate the word information into the character representations. Then we design a sliding window mechanism to get the cross-sentence context information. Finally, we predict the label of each character. We build a Chinese cybersecurity dataset and use three methods to evaluate our method, and the experimental results demonstrate the effectiveness of the proposed model. Xiangyu Du, Yitong He, Xuren Wang, Zhengwei Jiang |
CSCWD | 5 |
| 2021 | A Method for Extracting Unstructured Threat Intelligence Based on Dictionary Template and Reinforcement LearningabstractIn recent years, individuals, organizations and countries are all threatened by cyber threats to some degree. The proposal of threat intelligence sharing scheme has greatly helped the protection of cyber security. Traditional threat intelligence sharing scheme mainly collects and analyzes information manually, which include but not limited to Indicators of Compromise (IOC) and forms a machine readable report for Security Operations Center (SOC) to take corresponding action. Therefore, it is challenging and significant to easily and automatically share and exchange cyber threat intelligence (CTI). Aiming at extracting the information of CTI efficiently, we construct a model of automatic information extraction process of the entity recognition and relationship extraction, which are used to extract effective entities and relationships in threat intelligence reports and improve the efficiency of threat intelligence sharing. The specific content and research results include two aspects: (1) Research on threat intelligence entity recognition model. We use the BERT model as a corpus pre-training model based on the classic neural network BiLSTM-CRF, and proposes a model DT-BERT-BiLSTM-CRF based on the dictionary template. The BERT pre-training model makes full use of the contextual semantic information of the corpus and alleviates the problem of ambiguity in the process of threat intelligence entity recognition. By constructing a dictionary template of threat intelligence entities, the accuracy of entity recognition in the threat intelligence field is further improved. (2) Research on the extraction of ITC relations. We constructed the relation extraction data set with distant supervision methods. For alleviating the noise annotation data, we introduce the attention mechanism and reinforcement learning into traditional neural networks, proposing a model NR-RL-PCNN-ATT. Through a new reward mechanism, our model improves the sentence selection quality and the efficiency of relationship extraction. Xuren Wang, Binghua Song, Zhengwei Jiang, Shengqin Ao |
CSCWD | 1 |
| 2021 | FSSRE: Fusing Semantic Feature and Syntactic Dependencies Feature for threat intelligence Relation ExtractionabstractThreat intelligence relation extraction plays an important role in threat intelligence text analysis and processing.To extract the relation between two threat entities in a sentence, we develop a novel framework called FSSRE which fuses sematic feature and syntactic dependencies feature for threat intelligence relation extraction.We utilize graph convolutional networks (GCN) to extract syntactic dependencies features, and utilize Sentence-BERT to extract contextual semantic features.To keep vital information with irrelevant content removed to the most extent, we further apply a novel pruning strategy, SDP-VP, to the input trees.With retaining the shortest path and nodes that are 𝑲 hops away from nodes on the shortest path, we give the edge connected to the verb nodes a weight of 𝒘 times.We create an advanced persistent threat (APT) intelligence entities and intra-sentence relations dataset, APTER-SENT, for that there is no public dataset can be used for relation extraction research in the threat intelligence field.Experimental results on APTER-SENT demonstrate improved performance over competitive baselines.At the same time, we also conducted experiments on the SemEval-2010 dataset.The results of the experiment indicate that our method is still effective on this dataset. Xuren Wang, Mengbo Xiong, Famei He, Peian Yang, Binghua Song, Zhengwei Jiang, Zihan Xiong |
SEKE | 1 |
| 2021 | CAN: Complementary Attention Network for Aspect Level Sentiment Classification in Social E-Commerce
Yali Luo, Zhengwei Jiang, Peian Yang, Xuren Wang |
WCNC | 5 |
| 2020 | A Weak Coupling of Semi-Supervised Learning with Generative Adversarial Networks for Malware ClassificationabstractMalware classification helps to understand its purpose and is also an important part of attack detection. And it is also an important part of discovering attacks. Due to continuous innovation and development of artificial intelligence, it is a trend to combine deep learning with malware classification. In this paper, we propose an improved malware image rescaling algorithm (IMIR) based on local mean algorithm. Its main goal of IMIR is to reduce the loss of information from samples during the process of converting binary files to image files. Therefore, we construct a neural network structure based on VGG model, which is suitable for image classification. In the real world, a mass of malware family labels are inaccurate or lacking. To deal with this situation, we propose a novel method to train the deep neural network by Semi-supervised Generative Adversarial Network (SGAN), which only needs a small amount of malware that have accurate labels about families. By integrating SGAN with weak coupling, we can retain the weak links of supervised part and unsupervised part of SGAN. It improves the accuracy of malware classification by making classifiers more independent of discriminators. The results of experimental demonstrate that our model achieves exhibiting favorable performance. The recalls of each family in our data set are all higher than 93.75%. Shuwei Wang, Qiuyun Wang, Zhengwei Jiang, Xuren Wang, Rongqi Jing |
ICPR | 4 |
| 2020 | Towards Comprehensive Detection of DNS TunnelsabstractThe Domain Name System (DNS) is a fundamental service of the Internet, and the DNS tunnel is one of the most threatening abuses of DNS, posing a huge threat to user privacy and Internet security. Attackers conceal the information into DNS packets to evade firewalls and intrusion detection systems. Recently, newly developed DNS tunnels used by Advanced Persist Threat groups tend to use A and AAAA resource records (RRs) for transmission, making them more invisible and more threatening. Previous DNS tunnel detection approaches mainly focus on subdomains and TXT RRs, but less attention has been paid to newly developed DNS tunnels based on A and AAAA RRs. In this paper, we present a novel DNS tunnel detection method that can detect newly developed A and AAAA RR based DNS tunnels. Since DNS tunnels will transmit a large amount of encrypted or encoded data in the DNS queries and responses, we extracted novel features from domains and 4 types of RRs (A, AAAA, TXT and CNAME RRs) that are most commonly used for tunneling to measure the amount and content of information exchanged between the authoritative nameservers and the clients. We also analyze the detection capabilities when different features were used. The anomaly detection algorithm is employed on domains related features and 4 types of RRs related features, respectively. The overlaps of outliers will be marked as DNS tunnels. Our approach has been evaluated on real-world network traffic. The experimental results show that our approach can detect all DNS tunnels in the dataset with a extremely low false positive rate. Meng Luo 0006, Qiuyun Wang, Yepeng Yao, Xuren Wang, Peian Yang, Zhengwei Jiang |
ISCC | 4 |
| 2020 | NER in Threat Intelligence Domain with TSFL
Xuren Wang, Zihan Xiong, Xiangyu Du, Zhengwei Jiang, Mengbo Xiong |
NLPCC (1) | 1 |
| 2020 | Threat Intelligence Relationship Extraction Based on Distant Supervision and Reinforcement Learning
Xuren Wang, Qiuyun Wang, Changxin Su |
SEKE | 1 |
| 2020 | DNRTI: A Large-scale Dataset for Named Entity Recognition in Threat IntelligenceabstractNamed entity recognition is an important and challenging problem in Natural language processing. Although the past decade has witnessed major advances in entity recognition in many fields, such successes have been slow to network security field, not only because of the data in the network security field is very professional, but also due to the sensitive information in the data. To advance named entity recognition research in network security field, we introduce a large-scale Dataset for Named Entity Recognition in Threat Intelligence (DNRTI). To this end, we collect more than 300 pieces of threat intelligence. The data in DNRTI is all annotated by experts in threat intelligence interpretation using 13 object categories. The fully annotated DNRTI contains 175220 words. To build a baseline for named entity recognition in the threat intelligence field, we evaluate some deep learning model on DNRTI. Experiments demonstrate that DNRTI well represents the key information in threat intelligence and are quite challenging. Xuren Wang, Xinpei Liu, Shengqin Ao, Zhengwei Jiang, Zongyi Xu, Zihan Xiong, Mengbo Xiong |
TrustCom | 1 |
| 2020 | Joint Learning for Document-Level Threat Intelligence Relation Extraction and Coreference Resolution Based on GCNabstractIn order to help researchers quickly understand the connection between new threat events and previous threat events, threat intelligence document-level relation extraction plays a very important role in threat intelligence text analysis and processing. Because there is no public document-level threat intelligence dataset, we create APTERC-DOC, an APT intelligence entities, relations and coreference dataset. We treat the relation extraction as a multi-classification task. Treating the coreference relation as a kind of predefined relations, we develop a joint learning framework called TIRECO, a model which can simultaneously complete threat intelligence relation extraction and coreference resolution. In order to solve the problem of document-level text being too long to extract feature, we propose the concept of sentence set, which transforms document-level relation extraction into inter-sentence relation extraction. To incorporate relevant information with maximally removing irrelevant content in sentence set, we further apply a novel pruning strategy (SDP-VP-SET) to the input trees considering that verbs are crucial in determining the relation between entities in sentence set. With retaining the shortest path and nodes that are K hops away from the shortest path, we give the edge connected to the verb nodes a weight of w times. Experimental results show that our model not only performs well in the extraction of inter-sentence relations, it is also effective in intra-sentence relations, and the F1 value has increased by 15.694%. Xuren Wang, Mengbo Xiong, Yali Luo, Zhengwei Jiang, Zihan Xiong |
TrustCom | 1 |
| 2020 | A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural networkabstractAbstract Command and control (C2) servers are used by attackers to operate communications. To perform attacks, attackers usually employee the Domain Generation Algorithm (DGA), with which to confirm rendezvous points to their C2 servers by generating various network locations. The detection of DGA domain names is one of the important technologies for command and control communication detection. Considering the randomness of the DGA domain names, recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names. However, these methods are insufficient to handle wordlist-based DGA threats, which generate domain names by randomly concatenating dictionary words according to a special set of rules. In this paper, we proposed a a deep learning framework ATT-CNN-BiLSTM for identifying and detecting DGA domains to alleviate the threat. Firstly, the Convolutional Neural Network (CNN) and bidirectional Long Short-Term Memory (BiLSTM) neural network layer was used to extract the features of the domain sequences information; secondly, the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names. Finally, the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification. Our extensive experimental results demonstrate the effectiveness of the proposed model, both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones. To be precise,we got a F1 score of 98.79% for the detection and macro average precision and recall of 83% for the classification task of DGA domain names. Fangli Ren, Zhengwei Jiang, Xuren Wang |
Cybersecur. | 3 |
| 2004 | Rough Set Theory: Application in Electronic Commerce Data MiningabstractAs Electronic Commerce become more and more prevalent to people, this paper discusses application of rough set theory in Electronic Commerce (EC) data mining. The EC sites collect large data every day. The data includes valuable information about customers, products and so on. The large amount of data can be mined to find the unknown knowledge or trends hiding in the data, which can be used by the sites to arrange their products according to the buyers' preference and take appropriate selling policies. This paper employs rough set theory that can perform feature selection to obtain patterns of customers and products. Xuren Wang, Rongsheng Xu |
Web Intelligence | 1 |