EDBT 2026 Demo / reviewers in the wild / expert
Lingyu Wang 0001
dblp:w/LingyuWang
· DBLP profile ↗
115ranked-venue papers
16as first author
28since 2021 · last 2025
0000-0002-7441-7541ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 86 · 14 first-author · 23 since 2021Computer networks · 10 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 5 · 2 since 2021Software engineering, systems software and programming languages · 4Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Artificial intelligence and machine learning · 2Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CapMan: Detecting and Mitigating Linux Capability Abuses at Runtime to Secure Privileged Containers
Alireza Moghaddas Borhan, Hugo Kermabon-Bobinnec, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar |
ESORICS (3) | 3 |
| 2025 | Connecting the Extra Dots (Contexts): Correlating External Information about Point of Interest for Attack InvestigationabstractProvenance analysis is one of the go-to solutions today for human analysts to investigate security incidents. To assist analysts in managing the sheer size of provenance graphs, many pruning solutions have been proposed. Such solutions rely on graph-theory features, anomaly detection, and other techniques to identify nodes and edges that are irrelevant to the detected incident. Despite differences in their methodologies, those solutions typically share a common approach when it comes to the detected incident, i.e., they merely regard the incident as an abstract starting point, without tapping into it further. However, we observe that this may lead to missed opportunities for pruning, since the incident is typically associated with external information, e.g., knowledge about the exploit or the vulnerability, which may provide extra contextual insights for effective pruning. Based on such an observation, we propose Contexts, a solution that complements existing pruning approaches by leveraging external information about the incident. Specifically, the solution extracts contextual information from external sources, maps such information to provenance graph nodes, and then correlates those nodes to form a subgraph relevant to the incident. Our implementation and experiments based on real-world attacks demonstrate its effectiveness, e.g., working as the pre-processor of an existing pruning approach, it helps to reduce the false positives from more than 150k to less than ten, and as a standalone pruning solution, Contextsachieves 100% TPR for 19 out of 20 attacks, with an FPR below 0.6% for 16 out of 20 attacks. Finally, its real-world practicality is illustrated through a user study where 94.4% of participants agreed with its usefulness in attack investigation. Sareh Mohammadi, Hugo Kermabon-Bobinnec, Azadeh Tabiban, Lingyu Wang 0001, Tomás Navarro Múnera, Yosr Jarraya |
SP | 4 |
| 2025 | PerfSPEC: Performance Profiling-Based Proactive Security Policy Enforcement for ContainersabstractContainer environments provide cloud native applications with scalability, flexibility, and portable support. As a popular container orchestrator, Kubernetes facilitates automatic deployment and maintenance of a large number of containerized applications. However, potential misconfigurations, vulnerabilities, or implementation flaws may empower attackers to exploit the Kubernetes cluster. Although existing solutions such as runtime security policy enforcement may prevent an attack, they can be inefficient in large scale container environments. In this paper, we propose a performance profiling-based proactive security policy enforcement solution, namely, PerfSPEC. First, we accelerate the proactivization of policies (which typically requires significant manual effort) by proposing to profile and rank existing policies according to their induced overhead. This allows us to better focus our efforts and greatly improve the overall response time (e.g., by 98% in contrast to less than 49%). Then, we address the performance limitations of existing solutions by leveraging learning-based approaches to predict future events and compute their verification results in advance. As a result, PerfSPEC achieves a viable response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) even for large container environments (up to 800 Pods). Hugo Kermabon-Bobinnec, Sima Bagheri, Mahmood Gholipourchoubeh, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Cross-Level Security Verification for Network Functions Virtualization (NFV)abstractNetwork Functions Virtualization (NFV) is a popular solution for providing multi-tenant network services on top of existing cloud infrastructures in an agile and cost-effective manner. However, as NFV employs multiple levels of virtualization, it also introduces novel security challenges, such as cloud-level security breaches that are invisible to NFV-level tenants. Towards verifying the security of NFV across all the levels (a.k.a. cross-level security verification), existing solutions are mostly insufficient, as each such solution typically only focuses on one specific level (e.g., cloud, SDN, or SFC), and verifying every level separately would be expensive or even infeasible. In this paper, we propose an efficient and practical system,NFVGuard+, for cross-level security verification for NFV. Particularly, the efficiency ofNFVGuard+is achieved by first performing the costly security verification at one level, and then extrapolating the verification result to other levels through conducting relatively lightweight consistency checks. Additionally, the practicality ofNFVGuard+is ensured by automating the essential steps (e.g., identifying security properties, collecting verification data, and conducting verification) based on a novel Entity-Relationship (ER) model of NFV stack, integrating the approach with OpenStack/Tacker (a popular choice for an NFV deployment), and finally evaluating its effectiveness using both synthetic and real data. Alaa Oqaily, Mohammad Ekramul Kabir, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar, Makan Pourzandi, Mourad Debbabi, Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Measuring the Security Posture of IEC 61850 Smart Grid Substations Against Supply Chain AttacksabstractRecently, there has been a surge of interest in analyzing and modeling emerging cyberattacks resulting from supply chain vulnerabilities in smart grids. These vulnerabilities are deliberately injected into devices before shipment by a malicious or trustworthy but compromised vendor during supply chain attacks. As a result, those vulnerabilities possess unique characteristics, such as stealthiness. Such characteristics, together with the limited number of vendors, demand new techniques for measuring the security posture of smart grids in the presence of those vulnerabilities. On this basis, this article first defines a supply chain risk metric to measure the risks of different devices containing those vulnerabilities based on several risk factors. Afterward, we enhance the previously defined$kSupply$metric and propose a new metric, namely$kSupplier$to include vendors in the risk assessment. Finally, we evaluate the proposed metrics and models through simulations conducted on IEEE 14 and 39-bus systems. Onur Duman, Mohsen Ghafouri, Lingyu Wang 0001, Marthe Kassouf, Ribal Atallah, Mourad Debbabi |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | CCSM: Building Cross-Cluster Security Models for Edge-Core Environments Involving Multiple Kubernetes ClustersabstractWith the emergence of 5G networks and their large scale applications such as IoT and autonomous vehicles, telecom operators are increasingly offloading the computation closer to customers (i.e., on the edge). Such edge-core environments usually involve multiple Kubernetes clusters potentially owned by different providers. Confidentiality concerns could prevent those providers from sharing data freely with each other, which makes it challenging to perform common security tasks such as security verification across different clusters. In this work, we propose a solution for building cross-cluster security models to enable various security analyses, while preserving confidentiality for each cluster. We design a six-step methodology to model both the cross-cluster communication and cross-cluster event dependency, and we apply those models to different security use cases. We implement our solution based on a 5G edge-core environment that involves multiple Kubernetes clusters, and our experimental results demonstrate its efficiency (e.g., less than 8 seconds of processing time for a model with 3,600 edges and nodes) and accuracy (e.g., more than 96% for cross-cluster event prediction). Mahmood Gholipourchoubeh, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi |
CODASPY | 5 |
| 2024 | SecMonS: A Security Monitoring Framework for IEC 61850 Substations Based on Configuration Files and Logs
Onur Duman, Mengyuan Zhang 0001, Lingyu Wang 0001, Mourad Debbabi |
DIMVA | 3 |
| 2024 | Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall Sequences
Hugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang 0001, Suryadipta Majumdar, Makan Pourzandi |
NDSS | 3 |
| 2024 | ChainPatrol: Balancing Attack Detection and Classification with Performance Overhead for Service Function Chains Using Virtual Trailers
Momen Oqaily, Hinddeep Purohit, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi, Mourad Debbabi |
USENIX Security Symposium | 4 |
| 2024 | iCAT+: An Interactive Customizable Anonymization Tool Using Automated Translation Through Deep LearningabstractData anonymization is a viable solution for data owners to mitigate their privacy concerns. However, existing data anonymization tools are inflexible to support various privacy and utility requirements of both data owners and data users. In most cases, this limitation is due to a lack of understanding of those requirements as well as the non-customizability of the existing tools. To address this limitation, we proposeiCAT+, which is an interactive and customizable anonymization approach. More specifically, we first automate the interpretation of data owners’ and data users’ textual requirements by deploying a Convolutional Neural Network (CNN) model for Natural Language Processing (NLP). Second, we introduce the concept of theanonymization spaceto model possible combinations of per-attribute anonymization primitives based on the level of privacy and utility that each primitive provides. Third, we design an ontology model that maps the translated requirements into their appropriate anonymization primitives in the defined anonymization space corresponding to the plain data. Fourth, we evaluate the efficiency and effectiveness ofiCAT+based on both real and synthetic network data. Finally, we assess its usability through a real user study involving participants from industry and research laboratories. Our experiments show the effectiveness and efficiency of our solution (e.g., requirement translation accuracy of 99% at the data owner side and 98% at the data user side, with a computational time of around one minute for the Google cluster dataset). Momen Oqaily, Mohammad Ekramul Kabir, Suryadipta Majumdar, Yosr Jarraya, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Caught-in-Translation (CiT): Detecting Cross-Level Inconsistency Attacks in Network Functions Virtualization (NFV)abstractAs one of the main technology pillars of 5G networks, Network Functions Virtualization (NFV) enables agile and cost-effective deployment of network services. However, the multi-level, multi-actor design of NFV may also allow for inconsistency between the different abstraction levels to be mistakenly or intentionally introduced, as shown in recent studies. Serious security issues, such as man-in-the-middle, network sniffing, and DoS, may arise at one abstraction level without being noticed by the victims at another level. Most existing solutions are either limited to one abstraction level of NFV or reliant on direct access to lower-level data which could become inaccessible when managed by different providers. In this paper, by drawing an analogy between cross-level NFV event sequences and natural languages, we propose a Neural Machine Translation-based approach, namely,Caught-in-Translation (CiT), to detect cross-level inconsistency attacks in NFV at runtime. Specifically, we first extract event sequences from different abstraction levels of an NFV stack. We then leverage Long Short-Term Memory (LSTM) to translate the event sequences from one level to another. Finally, we apply both a similarity metric and a Siamese neural network to compare thetranslatedevent sequences with theoriginalones to detect attacks. We integrateCiTinto OpenStack/Tacker, a popular open-source NFV implementation, and evaluate its performance using both real and synthetic data. Experimental results show the benefit of leveraging NMT asCiTachieves AUC≥96.03%, which significantly outperforms traditional SVM-based anomaly detection. We also evaluateCiTin terms of its efficiency, scalability, and robustness for detecting inconsistency attacks in NFV platforms. Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes ClustersabstractA large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution. Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | A Tenant-based Two-stage Approach to Auditing the Integrity of Virtual Network Function Chains Hosted on Third-Party CloudsabstractThere is a growing trend of hosting chains of Virtual Network Functions (VNFs) on third-party clouds for more cost-effective deployment. However, the multi-actor nature of such a deployment may allow a mismatch to silently arise between tenant-level specifications of VNF chains and their cloud provider-level deployment. Most existing auditing approaches would face difficulties in identifying such an integrity breach. First, relying on the cloud provider may not be sufficient, since modifications made by a stealthy attacker may seem legitimate to the provider. Second, the tenant cannot directly perform the auditing due to limited access to the provider-level data. In addition, shipping such data to the tenant would incur prohibitive overhead and confidentiality concerns. In this paper, we design a tenant-based, two-stage solution where the first stage leverages tenant-level side-channel information to identify suspected integrity breaches, and then the second stage automatically identifies and anonymizes selected provider-level data for the tenant to verify the suspected breaches from the first stage. The key advantages of our solution are: (i) the first stage gives tenants more control and transparency (with the capability of identifying integrity breaches without the provider's assistance), and (ii) the second stage provides tenants higher accuracy (with the capability of rigorous verification based on provider-level data). Our solution is integrated into OpenStack/Tacker (a popular choice for NFV deployment), and its effectiveness is demonstrated via experiments (e.g., up to 90% accuracy with the first stage alone). Momen Oqaily, Suryadipta Majumdar, Lingyu Wang 0001, Mohammad Ekramul Kabir, Yosr Jarraya, A. S. M. Asadujjaman, Makan Pourzandi, Mourad Debbabi |
CODASPY | 3 |
| 2023 | Evaluating the Security Posture of 5G Networks by Combining State Auditing and Event Monitoring
Md. Nazmul Hoq, Jia Wei Yao, Suryadipta Majumdar, Lingyu Wang 0001, Amine Boukhtouta, Makan Pourzandi, Mourad Debbabi |
ESORICS (2) | 5 |
| 2023 | Warping the Defence Timeline: Non-Disruptive Proactive Attack Mitigation for Kubernetes ClustersabstractIn spite of being the de-facto standard of container orchestrators, Kubernetes reportedly suffers from security vulnerabilities and misconfigurations which may lead to severe security threats to the containerized environments it manages. Mitigating such threats based on alerts raised by existing security monitoring solutions (e.g., Falco) can be challenging. First, taking actions upon every alert can cause unacceptable service disruption, as many such alerts may turn out to be false positives. Second, validating each alert by administrators before taking actions may render the mitigation too late to prevent irreversible damages, e.g., denial of service. In this paper, we propose a non-disruptive proactive mitigation approach to address those limitations. Our main idea is to proactively trigger mitigation ahead of an attack to prevent irreversible damages, while designing the mitigation actions to be non-disruptive to avoid any service disruption caused by false alerts. We implement and integrate our approach with Kubernetes, and show its effectiveness and efficiency. Sima Bagheri, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi |
ICC | 5 |
| 2023 | A Generalized Framework for Preserving Both Privacy and Utility in Data OutsourcingabstractProperty preserving encryption techniques have significantly advanced the utility of encrypted data in data outsourcing. However, while preserving certain properties (e.g., the prefixes or order of the data) in the encrypted data, such encryption schemes are typically limited to specific data types (e.g., IP addresses) or applications (e.g., range queries over order-preserved data), and highly vulnerable to the emerging inference attacks which may greatly limit their applications in practice. In this paper, to the best of our knowledge, we make the first attempt to generalize the prefix-preserving encryption to make it applicable to more general data types (e.g., geo-locations, market basket data, DNA sequences, numerical data and timestamps) and secure against the inference attacks. Furthermore, we present a generalized multi-view outsourcing framework that generates multiple indistinguishable data views in which one view fully preserves the utility for data analysis, and its accurate analysis result can be obliviously retrieved. We empirically evaluate the performance of our outsourcing framework against two common inference attacks on two different real datasets: the check-in location dataset and network traffic dataset. The experimental results demonstrate that our proposed framework preserves both privacy (with bounded leakage and indistinguishable data views) and utility (with 100% analysis accuracy). Shangyu Xie, Meisam Mohammady, Han Wang 0021, Lingyu Wang 0001, Jaideep Vaidya, Yuan Hong 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2022 | WPES '22: 21st Workshop on Privacy in the Electronic SocietyabstractThese proceedings contain the papers selected for inclusion in the technical program for the 21st ACM Workshop on Privacy in the Electronic Society (WPES 2022), held in conjunction with the 29th ACM Conference on Computer and Communication Security (CCS 2022). This year, WPES is held as a hybrid event (including both in-person and online presentations) on November 7, 2022. Yuan Hong 0001, Lingyu Wang 0001 |
CCS | 2 |
| 2022 | 5GFIVer: Functional Integrity Verification for 5G Cloud-Native Network Functionsabstract5G networks attain a better performance along with a reduction in cost by cloudifying its network functions as Cloud+native Network Functions (CNFs). However, CNF may introduce new security concerns (e.g., data exfiltration and ransomware) due to potential code injection attacks against network functions at runtime. This will potentially result in a breach of functional integrity of these network functions. Towards verifying such functional integrity breaches of CNFs at the 5G-operator-level, existing approaches fell short, as most of them either (i) perform pre-deployment verification (i.e., verifying the CNF image before the deployment) and hence fail to verify integrity breaches occurring after the deployment, or (ii) perform post-deployment verification (i.e., verifying against attack signatures or normal behavior patterns) approaches that require provider-level data (e.g., system calls) which is usually inaccessible to 5G operators. In this paper, we propose 5GFIVer, a new operator-oriented approach for functional integrity verification of CNFs that overcomes the above-mentioned limitations. First, our approach utilizes the side-channel information such as performance metrics (which are already available at the operator level) so that no provider-level data is needed. Second, our approach implements unsupervised machine learning algorithms to detect outliers through time-series analysis of those available performance metrics, and hence no instrumentation for the data collection as well as no training data is required. Third, we leverage the correlation between multiple CNFs to improve the accuracy and minimize false positives (e.g., caused by cloud dynamics). Our experimental results under an open source 5G testbed demonstrate the effectiveness and negligible overhead of our solution. A. S. M. Asadujjaman, Mohammad Ekramul Kabir, Hinddeep Purohit, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Makan Pourzandi |
CloudCom | 5 |
| 2022 | ProSPEC: Proactive Security Policy Enforcement for ContainersabstractBy providing lightweight and portable support for cloud native applications, container environments have gained significant momentum lately. A container orchestrator such as Kubernetes can enable the automatic deployment and maintenance of a large number of containerized applications. However, due to its critical role, a container orchestrator also attracts a wide range of security threats exploiting misconfigurations or implementation flaws. Moreover, enforcing security policies at runtime against such security threats becomes far more challenging, as the large scale of container environments implies high complexity, while the high dynamicity demands a short response time. In this paper, we tackle this key security challenge to container environments through a proactive approach, namely, ProSPEC. Our approach leverages learning-based prediction to conduct the computationally intensive steps (e.g., security verification) in advance, while keeping the runtime steps (e.g., policy enforcement) lightweight. Consequently, ProSPEC can ensure a practical response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) for large container environments (up to 800 Pods). Hugo Kermabon-Bobinnec, Mahmood Gholipourchoubeh, Sima Bagheri, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
CODASPY | 7 |
| 2022 | MLFM: Machine Learning Meets Formal Method for Faster Identification of Security Breaches in Network Functions Virtualization (NFV)
Alaa Oqaily, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi, Suryadipta Majumdar |
ESORICS (3) | 3 |
| 2022 | A Generalized Framework for Preserving Both Privacy and Utility in Data Outsourcing (Extended Abstract)abstractIn this paper, we propose a prefix-preserving encryption based data outsourcing framework which is applicable to multiple different types of data, such as geo-locations, market basket data, DNA sequences, numerical data and timestamps. It enables accurate data analyses on the encrypted data while ensuring strong privacy against inference attacks. The basic idea is to generates multiple indistinguishable data views in which one view fully preserves the utility for data analysis, and its accurate analysis result can be obliviously retrieved. We empirically evaluate the performance of our outsourcing framework against two common inference attacks on two different real datasets: the check-in location dataset and network traffic dataset, respectively. The experimental results demonstrate that our proposed framework preserves both privacy (with bounded leakage and indistinguishability of data views) and utility. Shangyu Xie, Meisam Mohammady, Han Wang 0021, Lingyu Wang 0001, Jaideep Vaidya, Yuan Hong 0001 |
ICDE | 4 |
| 2022 | ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)
Azadeh Tabiban, Heyang Zhao, Yosr Jarraya, Makan Pourzandi, Mengyuan Zhang 0001, Lingyu Wang 0001 |
NDSS | 6 |
| 2022 | Factor of Security (FoS): Quantifying the Security Effectiveness of Redundant Smart Grid SubsystemsabstractAccording to International Electrotechnical Commission (IEC) 61850-90-4, most smart grid substations are designed with redundancy in order to improve their availability in case of failures. Redundancy usually takes the form of having multiple subsystems with identical functionality based on the assumption that failures in one subsystem are isolated from other subsystems. However, this is not necessarily true in the case of failures caused by malicious attacks, because attackers can easily reuse their skills and tools across different subsystems under similar configurations. Taking this into consideration, this article introduces the factor of security (FoS) metrics to quantify the security effectiveness of redundant subsystems in smart grids. Specifically, we first apply the attack graph model to capture various threats in smart grids and substations; we then formally define the FoS metric and the probabilistic FoS metric, and finally we evaluate those metrics through simulations. Onur Duman, Mengyuan Zhang 0001, Lingyu Wang 0001, Mourad Debbabi, Ribal Atallah, Bernard Lebel |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | ProSAS: Proactive Security Auditing System for CloudsabstractThe multi-tenancy in a cloud along with its dynamic and self-service nature could cause severe security concerns, such as isolation breaches among cloud tenants. To mitigate such concerns and ensure the accountability and transparency of the cloud providers towards their tenants, verifying cloud states against a list of security policies, a.k.a.security auditing, is a promising solution. However, the existing security auditing solutions for clouds suffer from several limitations. First, the traditional auditing approach, which is retroactive in nature, can only detect violations after the fact and hence, often becomes ineffective while dealing with the dynamic nature of a cloud. Second, the existing runtime approaches can cause significant delay in the response time while dealing with the sheer size of a cloud. Finally, the current proactive approaches typically rely on prior knowledge about future changes in a cloud and also require significant manual efforts, and thus become less practical for a dynamic environment like cloud. To address those limitations, we present a novel proactive security auditing system, namely,ProSAS, which can prevent violations to security policies at runtime with a practical response time, and yet does not require prior knowledge about future changes. More specifically,ProSASfirst establishes its models (e.g., dependency relationships between cloud events, and critical events) through learning from historical data (e.g., logs); it then predicts future critical events which would likely follow a received event by leveraging the dependency relationships; afterwards, it proactively verifies the impacts of those future events, and prevents those events which can cause violations of security policies. ProSAS is integrated into OpenStack, a popular cloud management platform, and we provide a concrete guideline to port ProSAS to other popular cloud platforms, such as Google Cloud Platform, and Amazon EC2. Our experiment results using both real and synthetic data demonstrate the improvement of efficiency (i.e., reducing response time to 1,450 nanoseconds at best and 8.5 milliseconds on average for a large-scale cloud with 10,000 tenants) and level of automation (i.e., learning more than 20 new critical events spanning 100 days) in proactive security auditing by ProSAS. Suryadipta Majumdar, Gagandeep Singh Chawla, Amir Alimohammadifar, Taous Madi, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2021 | VMGuard: State-Based Proactive Verification of Virtual Network Isolation With Application to NFVabstractNetwork Functions Virtualization (NFV) leverages from clouds to simplify and automate the creation and deployment of network services on the fly in a multi-tenant environment. However, clouds may also bring issues leading to tenants' concerns over possible breaches violating the isolation of their deployments. Verifying such network isolation breaches in cloud-enabled NFV environments faces unique challenges. The fine-grained and distributed network access control (e.g., per-function security group rules), which is typical to virtual cloud infrastructures, requires examining not only the events but also the states of all virtual resources using a state-based verification approach. However, verifying the state of a virtual infrastructure may become highly complex and non-scalable due to its sheer size paired with the self-serviced dynamic nature of clouds. In this article, we propose VMGuard, a state-based proactive approach for efficiently verifying large-scale virtual infrastructures in cloud and NFV against network isolation policies. Informally, our key idea is to proactively trigger the verification based on predicted events and their simulated impact upon the current state, such that we can have the best of both worlds, i.e., the efficiency of a proactive approach and the effectiveness of state-based verification. We implement and evaluate VMGuard based on OpenStack, and our experiments with both real and synthetic data demonstrate the performance and efficiency, e.g., less than five milliseconds to perform incremental verification on a dataset with more than 25, 000 VMs and less than two milliseconds with the proactive module enabled. Gagandeep Singh Chawla, Mengyuan Zhang 0001, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | SegGuard: Segmentation-Based Anonymization of Network Data in Clouds for Privacy-Preserving Security AuditingabstractSecurity auditing allows cloud tenants to verify the compliance of cloud infrastructure with respect to desirable security properties, e.g., whether a tenant’s virtual network is properly isolated from other tenants’ networks. However, the input to the auditing task, such as the detailed topology of the underlying cloud infrastructure, typically contains sensitive information which a cloud provider may be reluctant to hand over to a third party auditor. Additionally, auditing results intended for one tenant may inadvertently reveal private information about other tenants, e.g., another tenant’s VM is reachable due to a misconfiguration. How to anonymize both the input data and the auditing results in order to prevent such information leakage is a novel challenge that has received little attention. Directly applying most of the existing anonymization techniques to such a context would either lead to insufficient protection or render the data unsuitable for auditing. In this article, we proposeSegGuard, a novel anonymization approach that prevents cross-tenant information leakage through per-tenant encryption, and prevents information leakage to auditors through hiding real input segments among fake ones; in addition, applying property-preserving encryption in an innovative way enablesSegGuardto preserve the data utility for auditing while mitigating semantic attacks. We implementSegGuardbased on OpenStack, and evaluate its effectiveness and overhead using both synthetic and real data. Our experimental results demonstrate thatSegGuardcan reduce the information leakage to a negligible level (e.g., less than 1 percent for an adversary with 50 percent pre-knowledge) with a practical response time (e.g., 62 seconds to anonymize a cloud infrastructure with 25,000 virtual machines). Momen Oqaily, Yosr Jarraya, Meisam Mohammady, Suryadipta Majumdar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | Network Attack Surface: Lifting the Concept of Attack Surface to the Network Level for Evaluating Networks' Resilience Against Zero-Day AttacksabstractThe concept of attack surface has seen many applications in various domains, e.g., software security, cloud security, mobile device security, Moving Target Defense (MTD), etc. However, in contrast to the original attack surface metric, which is formally and quantitatively defined for a software, most of the applications at higher abstraction levels, such as the network level, are limited to an intuitive and qualitative notion, losing the modeling power of the original concept. In this paper, we lift the attack surface concept to the network level as a formal security metric for evaluating the resilience of networks against zero day attacks. Specifically, we first develop novel models for aggregating the attack surface of different network resources. We then design heuristic algorithms to estimate the network attack surface while reducing the effort spent on calculating attack surface for individual resources. Finally, the proposed methods are evaluated through experiments. Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | A Multi-view Approach to Preserve Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces or require heavy data sanitization or perturbation, which may result in a significant loss of data utility. In this article, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces: Those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The experimental results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Momen Oqaily, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
ACM Trans. Priv. Secur. | 3 |
| 2020 | R2DP: A Universal and Automated Approach to Optimizing the Randomization Mechanisms of Differential Privacy for Utility Metrics with No Known Optimal DistributionsabstractDifferential privacy (DP) has emerged as a de facto standard privacy notion for a wide range of applications. Since the meaning of data utility in different applications may vastly differ, a key challenge is to find the optimal randomization mechanism, i.e., the distribution and its parameters, for a given utility metric. Existing works have identified the optimal distributions in some special cases, while leaving all other utility metrics (e.g., usefulness and graph distance) as open problems. Since existing works mostly rely on manual analysis to examine the search space of all distributions, it would be an expensive process to repeat such efforts for each utility metric. To address such deficiency, we propose a novel approach that can automatically optimize different utility metrics found in diverse applications under a common framework. Our key idea that, by regarding the variance of the injected noise itself as a random variable, a two-fold distribution may approximately cover the search space of all distributions. Therefore, we can automatically find distributions in this search space to optimize different utility metrics in a similar manner, simply by optimizing the parameters of the two-fold distribution. Specifically, we define a universal framework, namely, randomizing the randomization mechanism of differential privacy (R2DP), and we formally analyze its privacy and utility. Our experiments show that R2DP can provide better results than the baseline distribution (Laplace) for several utility metrics with no known optimal distributions, whereas our results asymptotically approach to the optimality for utility metrics having known optimal distributions. As a side benefit, the added degree of freedom introduced by the two-fold distribution allows R2DP to accommodate the preferences of both data owners and recipients. Meisam Mohammady, Shangyu Xie, Yuan Hong 0001, Mengyuan Zhang 0001, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
CCS | 5 |
| 2020 | NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) StackabstractNetwork Functions Virtualization (NFV) enables agile and cost-effective deployment of multi-tenant network services on top of a cloud infrastructure. However, the multi-tenant and multilevel nature of NFV may lead to novel security challenges, such as stealthy attacks exploiting potential inconsistencies between different levels of the NFV stacks. Consequently, the security compliance of a multilevel NFV stack cannot be sufficiently established using existing solutions, which typically focus on one level. Moreover, the naive approach of separately verifying every level could be expensive or even infeasible. In this paper, we propose, NFVGuard, the first multilevel approach to the formal security verification of NFV stacks. Our key idea is to conduct the security verification at only one level, and then assure that verification result for other levels by verifying the consistency between adjacent levels. We integrate NFVGuard with OpenStack/Tacker, a popular platform for the NFV deployment, and experimentally evaluate its effectiveness. Alaa Oqaily, Sudershan Lakshmanan Thirunavukkarasu, Yosr Jarraya, Suryadipta Majumdar, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
CloudCom | 7 |
| 2020 | Modeling and Mitigating Security Threats in Network Functions Virtualization (NFV)
Nawaf Alhebaishi, Lingyu Wang 0001, Sushil Jajodia |
DBSec | 2 |
| 2020 | CPA: Accurate Cross-Platform Binary Authorship Characterization Using LDAabstractBinary authorship characterization refers to the process of identifying stylistic characteristics that are related to the author of an anonymous binary code. The aim is to automate the laborious and error-prone reverse engineering task of discovering information related to the author(s) of binary code. This paper presents CPA, a novel approach for characterizing the authors of program binaries. Instead of using generic features such as n-grams, CPA proposes a set of new features based on collections of various aspects of author style, including author code traits, code structure characteristics, and author expertise in solving coding tasks. It employs the Latent Dirichlet Allocation (LDA) algorithm to generate author style signatures to help identify similar author style characteristics in other binaries. We evaluated CPA on large datasets extracted from selected opensource C/C++ projects in GitHub and Google Code Jam events, and it successfully attributed a large number of authors with a significantly higher F1score: around 91% when the number of authors was 1,500. In addition, the false positive rate was low, around 1.5%. When the code was subjected to refactoring techniques or code transformation or was processed using different compilers/compilation settings, there was no significant drop in accuracy, demonstrating the robustness of our tool. Finally, in the case of code written by multiple authors, CPA was able to identify the authors with a high F1score, around 89%. Saed Alrabaee, Mourad Debbabi, Lingyu Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Modeling NFV Deployment to Identify the Cross-Level Inconsistency VulnerabilitiesabstractBy providing network functions through software running on standard hardware, Network Functions Virtualization (NFV) brings many benefits, such as increased agility and flexibility with reduced costs, as well as additional security concerns. Although existing works have examined various security issues of NFV, such as vulnerabilities in VNF software and DoS, there has been little effort on a security issue that is intrinsic to NFV, i.e., as an NFV environment typically involves multiple abstraction levels, the inconsistency that may arise between different levels can potentially be exploited for security attacks. In this paper, we propose the first NFV deployment model to capture the deployment aspects of NFV at different abstraction levels, which is essential for an in-depth study of the inconsistencies between such levels. Based on the model and an implemented NFV testbed, we present concrete attack scenarios in which the inconsistencies are exploited to attack the network functions in a stealthy manner. Finally, we study the feasibility of detecting the inconsistencies through verification. Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001, Alaa Oqaily, Gagandeep Singh Chawla, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
CloudCom | 5 |
| 2019 | CASFinder: Detecting Common Attack Surface
Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 3 |
| 2019 | BinEye: Towards Efficient Binary Authorship Characterization Using Deep Learning
Saed Alrabaee, ElMouatez Billah Karbab, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 3 |
| 2019 | Proactivizer: Transforming Existing Verification Tools into Efficient Solutions for Runtime Security Enforcement
Suryadipta Majumdar, Azadeh Tabiban, Meisam Mohammady, Alaa Oqaily, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 7 |
| 2019 | iCAT: An Interactive Customizable Anonymization Tool
Momen Oqaily, Yosr Jarraya, Mengyuan Zhang 0001, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
ESORICS (1) | 4 |
| 2019 | Optimizing the network diversity to improve the resilience of networks against unknown attacks
Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
Comput. Commun. | 2 |
| 2019 | Mitigating the insider threat of remote administrators in clouds through maintenance task assignmentsabstractToday’s cloud providers strive to attract customers with better services and less downtime in a highly competitive market. The need for minimizing the operational cost unavoidably leads cloud providers to rely on third party remote administrators for fulfilling regular maintenance tasks. In such a scenario, the lack of trust in those third party remote administrators paired with the extra privileges granted to them to complete the maintenance tasks usually implies undesirable security threats. A dishonest remote administrator, or an attacker armed with the stolen credential of a remote administrator, can pose severe insider threats to both the cloud provider and its tenants. In this paper, we take the first step towards understanding and mitigating such insider threats of remote administrators in clouds. Specifically, we first model the maintenance task assignments and their corresponding security impact due to privilege escalation. We then mitigate such impact through optimizing the task assignments with respect to given constraints. Finally, the simulation results demonstrate the effectiveness of our solution in various scenarios. Nawaf Alhebaishi, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
J. Comput. Secur. | 2 |
| 2019 | Decoupling coding habits from functionality for effective binary authorship attributionabstractBinary authorship attribution refers to the process of identifying the author of a given anonymous binary file based on stylistic characteristics. It aims to automate the laborious and error-prone reverse engineering task of discovering information related to the author(s) of a binary code. Existing works typically employ machine learning methods to extract features that are unique for each author and subsequently match them against a given binary to identify the author. However, most existing works share a common critical limitation, i.e., they cannot distinguish between features representing program functionality and those representing authorship (e.g., authors’ coding habits). Such distinction is crucial for effective authorship attribution because what is unique in a particular binary may be attributed to either author, compiler, or function. In this study, we present BinAuthor a system capable of decoupling program functionality from authors’ coding habits in binary code. To capture coding habits, BinAuthor leverages a set of features that are based on collections of functionality-independent choices made by authors during coding. Our evaluation demonstrates that BinAuthor outperforms existing methods in several aspects. First, it successfully attributes a larger number of authors with a significantly higher accuracy (around [Formula: see text]) based on the large datasets extracted from selected open-source C[Formula: see text] projects in GitHub, Google Code Jam events, Planet Source Code contests, and several programming projects. Second, BinAuthor is more robust than previous methods; there is no significant drop in accuracy when the code is subjected to refactoring techniques, simple obfuscation, and processed with different compilers. Finally, decoupling authorship from functionality allows us to apply BinAuthor to real malware binaries (Citadel, Zeus, Stuxnet, Flame, Bunny, and Babar) to automatically generate evidence on similar coding habits. Saed Alrabaee, Paria Shirani, Lingyu Wang 0001, Mourad Debbabi, Aiman Hanna |
J. Comput. Secur. | 3 |
| 2019 | Learning probabilistic dependencies among events for proactive security auditing in cloudsabstractSecurity compliance auditing is a viable solution to ensure the accountability and transparency of a cloud provider to its tenants. However, the sheer size of a cloud, coupled with the high operational complexity implied by the multi-tenancy and self-service nature, can easily render existing runtime auditing techniques too expensive and non-scalable. To this end, a proactive approach, which prepares for the auditing ahead of critical events, is a promising solution to reduce the response time to a practical level. However, a key limitation of such approaches is their reliance on manual efforts to extract the dependency relationships among events, which greatly restricts their practicality. What makes things worse is the fact that, as the most important input to security auditing, the logs and configuration databases of a real world cloud platform can be unstructured and not ready to be used for efficient security auditing. In this paper, we first propose a log processing technique, which prepares raw cloud logs for different analysis purposes, and then design a learning-based proactive security auditing system, namely, [Formula: see text]. To this end, we conduct case studies on current log formats in different real-world OpenStack (a popular cloud platform) deployments, and identify major challenges in log processing. Later, we design a stand-alone log processor for clouds, which may potentially be used for various log analyses. Consequently, we leverage the log processor outputs to extract probabilistic dependencies from runtime events for the dependency models. Finally, through these dependency models, we proactively prepare for security critical events and prevent security violations resulting from those critical events. Furthermore, we integrate [Formula: see text] to OpenStack and perform extensive experiments in both simulated and real cloud environments that show a practical response time (e.g., 6 ms to audit a cloud of 100,000 VMs) and a significant improvement (e.g., about 50% faster) over existing proactive approaches. In addition, we successfully and efficiently apply our log processor outputs to other learning techniques (e.g., executing sequence pattern mining algorithms within 18 ms for 50,000 events). Suryadipta Majumdar, Azadeh Tabiban, Yosr Jarraya, Momen Oqaily, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
J. Comput. Secur. | 7 |
| 2019 | Large-Scale Empirical Study of Important Features Indicative of Discovered Vulnerabilities to Assess Application SecurityabstractExisting research on vulnerability discovery models shows that the existence of vulnerabilities inside an application may be linked to certain features, e.g., size or complexity, of that application. However, the applicability of such features to demonstrate the relative security between two applications is not well studied, which may depend on multiple factors in a complex way. In this paper, we perform the first large-scale empirical study of the correlation between various features of applications and the abundance of vulnerabilities. Unlike existing work, which typically focuses on one particular application, resulting in limited successes, we focus on the more realistic issue of assessing the relative security level among different applications. To the best of our knowledge, this is the most comprehensive study of 780 real-world applications involving 6498 vulnerabilities. We apply seven feature selection methods to nine feature subsets selected among 34 collected features, which are then fed into six types of machine learning models, producing 523 estimations. The predictive power of important features is evaluated using four different performance measures. This paper reflects that the complexity of applications is not the only factor in vulnerability discovery and the human-related factors contribute to explaining the number of discovered vulnerabilities in an application. Mengyuan Zhang 0001, Xavier de Carné de Carnavalet, Lingyu Wang 0001, Ahmed Ragab |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | ISOTOP: Auditing Virtual Networks Isolation Across Cloud Layers in OpenStackabstractMulti-tenancy in the cloud is a double-edged sword. While it enables cost-effective resource sharing, it increases security risks for the hosted applications. Indeed, multiplexing virtual resources belonging to different tenants on the same physical substrate may lead to critical security concerns such as cross-tenants data leakage and denial of service. Particularly, virtual networks isolation failures are among the foremost security concerns in the cloud. To remedy these, automated tools are needed to verify security mechanisms compliance with relevant security policies and standards. However, auditing virtual networks isolation is challenging due to the dynamic and layered nature of the cloud. Particularly, inconsistencies in network isolation mechanisms across cloud-stack layers, namely, the infrastructure management and the implementation layers, may lead to virtual networks isolation breaches that are undetectable at a single layer. In this article, we propose an offline automated framework for auditing consistent isolation between virtual networks in OpenStack-managed cloud spanning over overlay and layer 2 by considering both cloud layers’ views. To capture the semantics of the audited data and its relation to consistent isolation requirement, we devise a multi-layered model for data related to each cloud-stack layer’s view. Furthermore, we integrate our auditing system into OpenStack, and present our experimental results on assessing several properties related to virtual network isolation and consistency. Our results show that our approach can be successfully used to detect virtual network isolation breaches for large OpenStack-based data centers in reasonable time. Taous Madi, Yosr Jarraya, Amir Alimohammadifar, Suryadipta Majumdar, Yushun Wang, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ACM Trans. Priv. Secur. | 7 |
| 2018 | Preserving Both Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces, or require heavy data sanitization or perturbation, both of which may result in a significant loss of data utility. In this paper, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces; those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
CCS | 2 |
| 2018 | QuantiC: Distance Metrics for Evaluating Multi-Tenancy Threats in Public CloudabstractAs a cornerstone of cloud computing, multi-tenancy brings not only the benefit of resource sharing but also additional security implications. To achieve an optimal trade-off between security and resource sharing, cloud providers are obliged to evaluate the potential threats related to multi-tenancy. However, quantitative approaches for evaluating those threats are largely missing in existing works. In this paper, we propose a set of multi-level distance metrics that quantify the proximity of tenants' virtual resources inside a cloud. Those metrics are defined based on the configuration and deployment in a cloud, such that a cloud provider may apply them to evaluate the risk related to potential multi-tenancy attacks. We conduct case studies and experiments on both real and fictitious clouds. The obtained results show the effectiveness and applicability of our metrics. We further implement our metrics in OpenStack and show how they can be applied for distance auditing. Taous Madi, Mengyuan Zhang 0001, Yosr Jarraya, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
CloudCom | 6 |
| 2018 | Modeling and Mitigating the Insider Threat of Remote Administrators in Clouds
Nawaf Alhebaishi, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 2 |
| 2018 | BINARM: Scalable and Efficient Detection of Vulnerabilities in Firmware Images of Intelligent Electronic Devices
Paria Shirani, Leo Collard, Basile L. Agba, Bernard Lebel, Mourad Debbabi, Lingyu Wang 0001, Aiman Hanna |
DIMVA | 6 |
| 2018 | Stealthy Probing-Based Verification (SPV): An Active Approach to Defending Software Defined Networks Against Topology Poisoning Attacks
Amir Alimohammadifar, Suryadipta Majumdar, Taous Madi, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 6 |
| 2018 | On Leveraging Coding Habits for Effective Binary Authorship Attribution
Saed Alrabaee, Paria Shirani, Lingyu Wang 0001, Mourad Debbabi, Aiman Hanna |
ESORICS (1) | 3 |
| 2018 | Realtime intrusion risk assessment model based on attack and service dependency graphs
Alireza Shameli-Sendi, Michel R. Dagenais, Lingyu Wang 0001 |
Comput. Commun. | 3 |
| 2018 | Surviving unpatchable vulnerabilities through heterogeneous network hardening optionsabstractThe administrators of a mission critical network usually have to worry about non-traditional threats, e.g., how to live with known, but unpatchable vulnerabilities, and how to improve the network’s resilience against potentially unknown vulnerabilities. To this end, network hardening is a well-known preventive security solution that aims to improve network security by taking proactive actions, namely, hardening options. However, most existing network hardening approaches rely on a single hardening option, such as disabling unnecessary services, which becomes less effective when it comes to dealing with unknown and unpatchable vulnerabilities. There lacks a heterogeneous approach that can combine different hardening options in an optimal way to deal with both unknown and unpatchable vulnerabilities. In this paper, we propose such an approach by unifying multiple hardening options, such as service diversification, firewall rule modification, adding, removing, and relocating network resources, and access control, all under the same model. We then apply security metrics designed for evaluating network resilience against unknown and unpatchable vulnerabilities, and consequently derive optimal solutions to maximize security under given cost constraints. Finally, we study the effectiveness of our solution against unpatchable vulnerabilities through simulations. Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
J. Comput. Secur. | 2 |
| 2018 | User-Level Runtime Security Auditing for the CloudabstractCloud computing is emerging as a promising IT solution for enabling ubiquitous, convenient, and on-demand accesses to a shared pool of configurable computing resources. However, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security auditing techniques. Auditing in cloud poses many unique challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures), and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and need of runtime verification for the dynamic nature of cloud). To this end, existing runtime auditing techniques do not offer a practical response time to verify a wide-range of user-level security properties for a large cloud. In this paper, we propose a runtime security auditing framework for the cloud with special focus on the user-level including common access control and authentication mechanisms e.g., RBAC, ABAC, SSO, and we implement and evaluate the framework based on OpenStack, a widely deployed cloud management system. The main idea towards reducing the response time to a practical level is to perform the costly operations only once, which is followed by significantly more efficient incremental runtime verification. Our experimental results show that runtime security auditing in a large cloud environment is realistic under our approach (e.g., our solution performs runtime auditing of 100,000 users within 500 milliseconds). Suryadipta Majumdar, Taous Madi, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2018 | FOSSIL: A Resilient and Efficient System for Identifying FOSS Functions in Malware BinariesabstractIdentifying free open-source software (FOSS) packages on binaries when the source code is unavailable is important for many security applications, such as malware detection, software infringement, and digital forensics. This capability enhances both the accuracy and the efficiency of reverse engineering tasks by avoiding false correlations between irrelevant code bases. Although the FOSS package identification problem belongs to the field of software engineering, conventional approaches rely strongly on practical methods in data mining and database searching. However, various challenges in the use of these methods prevent existing function identification approaches from being effective in the absence of source code. To make matters worse, the introduction of obfuscation techniques, the use of different compilers and compilation settings, and software refactoring techniques has made the automated detection of FOSS packages increasingly difficult. With very few exceptions, the existing systems are not resilient to such techniques, and the exceptions are not sufficiently efficient. To address this issue, we propose FOSSIL , a novel resilient and efficient system that incorporates three components. The first component extracts the syntactical features of functions by considering opcode frequencies and applying a hidden Markov model statistical test. The second component applies a neighborhood hash graph kernel to random walks derived from control-flow graphs, with the goal of extracting the semantics of the functions. The third component applies z-score to the normalized instructions to extract the behavior of instructions in a function. The components are integrated using a Bayesian network model, which synthesizes the results to determine the FOSS function. The novel approach of combining these components using the Bayesian network has produced stronger resilience to code obfuscation. We evaluate our system on three datasets, including real-world projects whose use of FOSS packages is known, malware binaries for which there are security and reverse engineering reports purporting to describe their use of FOSS, and a large repository of malware binaries. We demonstrate that our system is able to identify FOSS packages in real-world projects with a mean precision of 0.95 and with a mean recall of 0.85. Furthermore, FOSSIL is able to discover FOSS packages in malware binaries that match those listed in security and reverse engineering reports. Our results show that modern malware binaries contain 0.10--0.45 of FOSS packages. Saed Alrabaee, Paria Shirani, Lingyu Wang 0001, Mourad Debbabi |
ACM Trans. Priv. Secur. | 3 |
| 2017 | Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options
Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 2 |
| 2017 | BinShape: Scalable and Robust Binary Library Function Identification Using Function Shape
Paria Shirani, Lingyu Wang 0001, Mourad Debbabi |
DIMVA | 2 |
| 2017 | LeaPS: Learning-Based Proactive Security Auditing for Clouds
Suryadipta Majumdar, Yosr Jarraya, Momen Oqaily, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 6 |
| 2017 | TenantGuard: Scalable Runtime Verification of Cloud-Wide VM-Level Network Isolation
Yushun Wang, Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
NDSS | 7 |
| 2017 | Privacy Preserving Smart Meter Streaming Against Information Leakage of Appliance StatusabstractThe smart grid frequently collects consumers' fine-grained power usage data through smart meters to facilitate various applications, such as billing, load monitoring, regional statistics, and demand response. However, the smart meter reading streams may also pose severe privacy threats to the consumers by leaking their appliances' ON/OFF status. In this paper, we first quantitatively measure the information leakage with respect to specific appliances' status from any reading stream, and define a novel privacy notion to bound such information leakage. In addition, we propose a privacy preserving streaming algorithm with different options to effectively convert readings and promptly stream safe readings in different fashions. The output time series readings satisfy our privacy notion while guaranteeing excellent utility, such as extremely low aggregation errors and billing errors. Finally, we experimentally validate the effectiveness and efficiency of our approach using real data sets. Yuan Hong 0001, Wen Ming Liu, Lingyu Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
Taous Madi, Suryadipta Majumdar, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
CODASPY | 6 |
| 2016 | Diversifying Network Services Under Cost Constraints for Better Resilience Against Unknown Attacks
Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 2 |
| 2016 | Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (1) | 6 |
| 2016 | A taint based approach for automatic reverse engineering of gray-box file formats
Baojiang Cui, Yongle Hao, Lingyu Wang 0001 |
Soft Comput. | 4 |
| 2016 | Key-Aggregate Searchable Encryption (KASE) for Group Data Sharing via Cloud StorageabstractThe capability of selectively sharing encrypted data with different users via public cloud storage may greatly ease security concerns over inadvertent data leaks in the cloud. A key challenge to designing such encryption schemes lies in the efficient management of encryption keys. The desired flexibility of sharing any group of selected documents with any group of users demands different encryption keys to be used for different documents. However, this also implies the necessity of securely distributing to users a large number of keys for both encryption and search, and those users will have to securely store the received keys, and submit an equally large number of keyword trapdoors to the cloud in order to perform search over the shared data. The implied need for secure communication, storage, and complexity clearly renders the approach impractical. In this paper, we address this practical problem, which is largely neglected in the literature, by proposing the novel concept of key-aggregate searchable encryption and instantiating the concept through a concrete KASE scheme, in which a data owner only needs to distribute a single key to a user for sharing a large number of documents, and the user only needs to submit a single trapdoor to the cloud for querying the shared documents. The security analysis and performance evaluation both confirm that our proposed schemes are provably secure and practically efficient. Baojiang Cui, Zheli Liu, Lingyu Wang 0001 |
IEEE Trans. Computers | 3 |
| 2016 | Network Diversity: A Security Metric for Evaluating the Resilience of Networks Against Zero-Day AttacksabstractDiversity has long been regarded as a security mechanism for improving the resilience of software and networks against various attacks. More recently, diversity has found new applications in cloud computing security, moving target defense, and improving the robustness of network routing. However, most existing efforts rely on intuitive and imprecise notions of diversity, and the few existing models of diversity are mostly designed for a single system running diverse software replicas or variants. At a higher abstraction level, as a global property of the entire network, diversity and its effect on security have received limited attention. In this paper, we take the first step toward formally modeling network diversity as a security metric by designing and evaluating a series of diversity metrics. In particular, we first devise a biodiversity-inspired metric based on the effective number of distinct resources. We then propose two complementary diversity metrics, based on the least and the average attacking efforts, respectively. We provide guidelines for instantiating the proposed metrics and present a case study on estimating software diversity. Finally, we evaluate the proposed metrics through simulation. Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Massimiliano Albanese |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStackabstractCloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a security compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute). Suryadipta Majumdar, Taous Madi, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
CloudCom | 6 |
| 2015 | k-jump: A strategy to design publicly-known algorithms for privacy preserving micro-data disclosureabstractAbstract Data owners are expected to disclose micro-data for research, analysis, and various other purposes. In disclosing micro-data with sensitive attributes, the goal is usually two fold. First, the data utility of disclosed data should be maximized for analysis purposes. Second, the private information contained in such data must be to an acceptable level. Typically, a disclosure algorithm evaluates potential generalization functions in a predetermined order, and then discloses the first generalization that satisfies the desired privacy property. Recent studies show that adversarial inferences using knowledge about such disclosure algorithms can usually render the algorithm unsafe. In this paper, we show that an existing unsafe algorithm can be transformed into a large family of safe algorithms, namely, k-jump algorithms. We then prove that the data utility of different k-jump algorithms is generally incomparable. The comparison of data utility is independent of utility measures and syntactic privacy models. Finally, we analyze the computational complexity of k-jump algorithms, and confirm the necessity of safe algorithms even when a secret choice is made among algorithms. Wen Ming Liu, Lingyu Wang 0001, Lei Zhang 0004, Shunzhi Zhu |
J. Comput. Secur. | 2 |
| 2014 | Collaboratively Solving the Traveling Salesman Problem with Limited Disclosure
Yuan Hong 0001, Jaideep Vaidya, Haibing Lu, Lingyu Wang 0001 |
DBSec | 4 |
| 2014 | Modeling Network Diversity for Evaluating the Robustness of Networks against Zero-Day Attacks
Lingyu Wang 0001, Mengyuan Zhang 0001, Sushil Jajodia, Anoop Singhal, Massimiliano Albanese |
ESORICS (2) | 1 |
| 2014 | PPTP: Privacy-Preserving Traffic Padding in Web-Based ApplicationsabstractWeb-based applications are gaining popularity as they require less client-side resources, and are easier to deliver and maintain. On the other hand, web applications also pose new security and privacy challenges. In particular, recent research revealed that many high profile web applications might cause sensitive user inputs to be leaked from encrypted traffic due to side-channel attacks exploiting unique patterns in packet sizes and timing. Moreover, existing solutions, such as random padding and packet-size rounding, were shown to incur prohibitive overhead while still failing to guarantee sufficient privacy protection. In this paper, we first observe an interesting similarity between this privacy-preserving traffic padding (PPTP) issue and another well studied problem, privacy-preserving data publishing (PPDP). Based on such a similarity, we present a formal PPTP model encompassing the privacy requirements, padding costs, and padding methods. We then formulate PPTP problems under different application scenarios, analyze their complexity, and design efficient heuristic algorithms. Finally, we confirm the effectiveness and efficiency of our algorithms by comparing them to existing solutions through experiments using real-world web applications. Wen Ming Liu, Lingyu Wang 0001, Pengsu Cheng, Kui Ren 0001, Shunzhi Zhu, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | k-Zero Day Safety: A Network Security Metric for Measuring the Risk of Unknown VulnerabilitiesabstractBy enabling a direct comparison of different security solutions with respect to their relative effectiveness, a network security metric may provide quantifiable evidences to assist security practitioners in securing computer networks. However, research on security metrics has been hindered by difficulties in handling zero-day attacks exploiting unknown vulnerabilities. In fact, the security risk of unknown vulnerabilities has been considered as something unmeasurable due to the less predictable nature of software flaws. This causes a major difficulty to security metrics, because a more secure configuration would be of little value if it were equally susceptible to zero-day attacks. In this paper, we propose a novel security metric, k-zero day safety, to address this issue. Instead of attempting to rank unknown vulnerabilities, our metric counts how many such vulnerabilities would be required for compromising network assets; a larger count implies more security because the likelihood of having more unknown vulnerabilities available, applicable, and exploitable all at the same time will be significantly lower. We formally define the metric, analyze the complexity of computing the metric, devise heuristic algorithms for intractable cases, and finally demonstrate through case studies that applying the metric to existing network security practices may generate actionable knowledge. Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Pengsu Cheng, Steven Noel |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2014 | Proof-Carrying Cloud Computation: The Case of Convex OptimizationabstractCloud computing offers a great opportunity to bridge the gap between the fast growing computation needs and limited local resources. However, without the adequate trust and strong integrity assurance, it would be difficult to expect clients to completely turn over control of their computation to the cloud. Hence, securing cloud computation becomes an imperative and challenging task, especially in the aspect of integrity verification. To address the challenge, we propose a hassle-free, fixed-rate, and job-based software as a service cloud model along with the integrity verification mechanisms, with particular focus on outsourcing the widely applicable engineering optimization problem, i.e., convex optimization. We aim to construct efficient integrity verification mechanisms using application-specific techniques. Our security design does not require the use of heavy cryptographic tools. Instead, we leverage the inherent structure of the optimization problems and make the computation outsourcing proof-carrying to achieve efficient integrity verification. The proposed design provides substantial computational savings on the client side and introduces marginal overhead on the cloud side. We further prove its correctness and soundness. The extensive experiments under the real cloud environment show our mechanisms ensure strong integrity assurance with high efficiency on both the client and the cloud sides and are readily applicable in current practice. Cong Wang 0001, Kui Ren 0001, Lingyu Wang 0001, Bingsheng Zhang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2013 | Background Knowledge-Resistant Traffic Padding for Preserving User Privacy in Web-Based ApplicationsabstractWhile enjoying the convenience of Software as a Service (SaaS), users are also at an increased risk of privacy breaches. Recent studies show that a Web-based application may be inherently vulnerable to side-channel attacks which exploit unique packet sizes to identify sensitive user inputs from encrypted traffic. Existing solutions based on packet padding or packet-size rounding generally rely on the assumption that adversaries do not possess prior background knowledge about possible user inputs. In this paper, we propose a novel random ceiling padding approach whose results are resistant to such adversarial knowledge. Specifically, the approach injects randomness into the process of forming padding groups, such that an adversary armed with background knowledge would still face sufficient uncertainty in estimating user inputs. We formally present a generic scheme and discuss two concrete instantiations. We then confirm the correctness and performance of our approach through both theoretic analysis and experiments with two real world applications. Wen Ming Liu, Lingyu Wang 0001, Kui Ren 0001, Mourad Debbabi |
CloudCom (1) | 2 |
| 2013 | Proof-carrying cloud computation: The case of convex optimizationabstractCloud computing provides a “pay-per-use” utility service which offers the customer the economical access to large amount of computing resources with minimal management overhead. Despite the tremendous benefits, computation outsourcing also eliminates the customer's ultimate control over the data computation process, which makes securing cloud computation an imperative and challenging task, especially in the aspect of integrity verification. To address these challenges, in this paper we propose to research on integrity verification mechanisms for secure outsourced computations in cloud computing. In particular, we focus on outsourcing the widely applicable engineering optimization problem, i.e., convex optimization, and aim to investigate efficient integrity verification mechanisms using application-specific techniques. Our security design does not require the use of heavy cryptographic tools. Instead, we leverage the inherent structure of the optimization problems and the proof-carrying characteristics of the solving algorithms to achieve efficient integrity verification. The proposed design provides substantial computational savings on the customer side and introduce marginal overhead on the cloud side. We further prove its correctness and soundness. The extensive experiments under real cloud environment show our mechanisms ensure strong integrity assurance with high efficiency on both the customer and cloud sides and are readily applicable in practice. Cong Wang 0001, Qian Wang 0002, Kui Ren 0001, Lingyu Wang 0001 |
INFOCOM | 5 |
| 2013 | An Efficient Approach to Assessing the Risk of Zero-Day Vulnerabilities
Massimiliano Albanese, Sushil Jajodia, Anoop Singhal, Lingyu Wang 0001 |
SECRYPT | 4 |
| 2013 | A Unified Framework for Measuring a Network's Mean Time-to-CompromiseabstractMeasuring the mean time-to-compromise provides important insights for understanding a network's weaknesses and for guiding corresponding defense approaches. Most existing network security metrics only deal with the threats of known vulnerabilities and cannot handle zero day attacks with consistent semantics. In this paper, we propose a unified framework for measuring a network's mean time-to-compromise by considering both known, and zero day attacks. Specifically, we first devise models of the mean time for discovering and exploiting individual vulnerabilities. Unlike existing approaches, we replace the generic state transition model with a more vulnerability-specific graphical model. We then employ Bayesian networks to derive the overall mean time-to-compromise by aggregating the results of individual vulnerabilities. Finally, we demonstrate the framework's practical application to network hardening through case studies. William Nzoukou, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
SRDS | 2 |
| 2012 | Privacy streamliner: a two-stage approach to improving algorithm efficiencyabstractIn releasing data with sensitive information, a data owner usually has seemingly conflicting goals, including privacy preservation, utility optimization, and algorithm efficiency. In this paper, we observe that a high computational complexity is usually incurred when an algorithm conflates the processes of privacy preservation and utility optimization. We then propose a novel privacy streamliner approach to decouple those two processes for improving algorithm efficiency. More specifically, we first identify a set of potential privacy-preserving solutions satisfying that an adversary's knowledge about this set itself will not help him/her to violate the privacy property; we can then optimize utility within this set without worrying about privacy breaches since such an optimization is now simulatable by adversaries. To make our approach more concrete, we study it in the context of micro-data release with publicly known generalization algorithms. The analysis and experiments both confirm our algorithms to be more efficient than existing solutions. Wen Ming Liu, Lingyu Wang 0001 |
CODASPY | 2 |
| 2012 | k-Indistinguishable Traffic Padding in Web Applications
Wen Ming Liu, Lingyu Wang 0001, Kui Ren 0001, Pengsu Cheng, Mourad Debbabi |
Privacy Enhancing Technologies | 2 |
| 2012 | Aggregating CVSS Base Scores for Semantics-Rich Network Security MetricsabstractA network security metric is desirable in evaluating the effectiveness of security solutions in distributed systems. Aggregating CVSS scores of individual vulnerabilities provides a practical approach to network security metric. However, existing approaches to aggregating CVSS scores usually cause useful semantics of individual scores to be lost in the aggregated result. In this paper, we address this issue through two novel approaches. First, instead of taking each base score as an input, our approach drills down to the underlying base metric level where dependency relationships have well-defined semantics. Second, our approach interprets and aggregates the base metrics from three different aspects in order to preserve corresponding semantics of the individual scores. Finally, we confirm the advantages of our approaches through simulation. Pengsu Cheng, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
SRDS | 2 |
| 2011 | Mechanism Design-Based Secure Leader Election Model for Intrusion Detection in MANETabstractIn this paper, we study leader election in the presence of selfish nodes for intrusion detection in mobile ad hoc networks (MANETs). To balance the resource consumption among all nodes and prolong the lifetime of an MANET, nodes with the most remaining resources should be elected as the leaders. However, there are two main obstacles in achieving this goal. First, without incentives for serving others, a node might behave selfishly by lying about its remaining resources and avoiding being elected. Second, electing an optimal collection of leaders to minimize the overall resource consumption may incur a prohibitive performance overhead, if such an election requires flooding the network. To address the issue of selfish nodes, we present a solution based on mechanism design theory. More specifically, the solution provides nodes with incentives in the form of reputations to encourage nodes in honestly participating in the election process. The amount of incentives is based on the Vickrey, Clarke, and Groves (VCG) model to ensure truth-telling to be the dominant strategy for any node. To address the optimal election issue, we propose a series of local election algorithms that can lead to globally optimal election results with a low cost. We address these issues in two possible application settings, namely, Cluster-Dependent Leader Election (CDLE) and Cluster-Independent Leader Election (CILE). The former assumes given clusters of nodes, whereas the latter does not require any preclustering. Finally, we justify the effectiveness of the proposed schemes through extensive experiments. Noman Mohammed, Hadi Otrok, Lingyu Wang 0001, Mourad Debbabi, Prabir Bhattacharya |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2010 | k-Zero Day Safety: Measuring the Security Risk of Networks against Unknown Attacks
Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Steven Noel |
ESORICS | 1 |
| 2010 | k-jump strategy for preserving privacy in micro-data disclosureabstractIn disclosing micro-data with sensitive attributes, the goal is usually two fold. First, the data utility of disclosed data should be maximized for analysis purposes. Second, the private information contained in such data must be limited to an acceptable level. Recent studies show that adversarial inferences using knowledge about a disclosure algorithm can usually render the algorithm unsafe. In this paper, we show that an existing unsafe algorithm can be transformed into a large family of distinct safe algorithms, namely, k-jump algorithms. We prove that the data utility of different k-jump algorithms is generally incomparable. Therefore, a secret choice can be made among all k-jump algorithms to eliminate adversarial inferences while improving the data utility of disclosed micro-data. Wen Ming Liu, Lingyu Wang 0001, Lei Zhang 0004 |
ICDT | 2 |
| 2010 | On the analysis of the Zeus botnet crimeware toolkitabstractIn this paper, we present our reverse engineering results for the Zeus crimeware toolkit which is one of the recent and powerful crimeware tools that emerged in the Internet underground community to control botnets. Zeus has reportedly infected over 3.6 million computers in the United States. Our analysis aims at uncovering the various obfuscation levels and shedding the light on the resulting code. Accordingly, we explain the bot building and installation/infection processes. In addition, we detail a method to extract the encryption key from the malware binary and use that to decrypt the network communications and the botnet configuration information. The reverse engineering insights, together with network traffic analysis, allow for a better understanding of the technologies and behaviors of such modern HTTP botnet crimeware toolkits and opens an opportunity to inject falsified information into the botnet communications which can be used to defame this crimeware toolkit. Hamad Binsalleeh, Thomas C. Ormerod, Amine Boukhtouta, Prosenjit Sinha, Amr M. Youssef, Mourad Debbabi, Lingyu Wang 0001 |
PST | 7 |
| 2010 | PCM: a privacy-preserving detection mechanism in mobile ad hoc networksabstractAbstract Although extensive research work has been undertaken to secure mobilead hocnetworks, till recently, researchers began to pay attention to the anonymity issue, and this issue was investigated mainly in terms of secure routing and data forwarding. We indicate that, in mobilead hocnetworks, there is an increasing interest in providing anonymity for the witnesses, i.e., those users who share their knowledge in detecting either malicious or selfish users. On the other hand, it is also a challenging problem to prevent the misuse of anonymous sources. In this paper, we propose thePlainClothesMan(PCM) protocol to provide anonymity for the witness who helps identify malicious or selfish users. Once there are more than a certain number of claims from distinct users against the same user, she is identified as a malicious or selfish user. Moreover, in PCM, the misuse of the witness anonymity is prevented in such a way that any malicious user who broadcasts multiple invalid claims against the same user for the same reason can be identified. Two exemplary scenarios are designed and simulated to model the necessities of witness anonymity in mobilead hocnetworks. Simulation results show that witness anonymity is very important for ensuring proper and efficient executions of fundamental functionalities of mobilead hocnetworks, e.g., certificate revocation and fairness, and PCM is both effective and efficient in providing such a type of anonymity. Copyright © 2009 John Wiley & Sons, Ltd. Bo Zhu 0001, Kui Ren 0001, Lingyu Wang 0001, Mourad Debbabi |
Secur. Commun. Networks | 3 |
| 2010 | Providing witness anonymity under peer-to-peer settingsabstractIn this paper, we introduce the concept ofwitness anonymityfor peer-to-peer systems, as well as other systems with the peer-to-peer nature. Witness anonymity combines the seemingly conflicting requirements of anonymity (for honest peers who report on the misbehavior of other peers) and accountability (for malicious peers that attempt to misuse the anonymity feature to slander honest peers). We propose theSecure Deep Throat(SDT) protocol to provide anonymity for the witnesses of malicious or selfish behavior to enable such peers to report on this behavior without fear of retaliation. On the other hand, in SDT, the misuse of anonymity is restrained in such a way that any malicious peer attempting to send multiple claims against the same innocent peer for the same reason (i.e., the same misbehavior type) can be identified. We also describe how SDT can be used in two modes. The active mode can be used in scenarios with real-time requirements, e.g., detecting and preventing the propagation of peer-to-peer worms, whereas the passive mode is suitable for scenarios without strict real-time requirements, e.g., query-based reputation systems. We analyze the security and overhead of SDT, and present countermeasures that can be used to mitigate various attacks on the protocol. Moreover, we show how SDT can be easily integrated with existing protocols/mechanisms with a few examples. Our analysis shows that the communication, storage, and computation overheads of SDT are acceptable in peer-to-peer systems. Bo Zhu 0001, Sanjeev Setia, Sushil Jajodia, Lingyu Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2010 | Localized Multicast: Efficient and Distributed Replica Detection in Large-Scale Sensor NetworksabstractDue to the poor physical protection of sensor nodes, it is generally assumed that an adversary can capture and compromise a small number of sensors in the network. In a node replication attack, an adversary can take advantage of the credentials of a compromised node to surreptitiously introduce replicas of that node into the network. Without an effective and efficient detection mechanism, these replicas can be used to launch a variety of attacks that undermine many sensor applications and protocols. In this paper, we present a novel distributed approach called Localized Multicast for detecting node replication attacks. The efficiency and security of our approach are evaluated both theoretically and via simulation. Our results show that, compared to previous distributed approaches proposed by Parno et al., Localized Multicast is more efficient in terms of communication and memory costs in large-scale sensor networks, and at the same time achieves a higher probability of detecting node replicas. Bo Zhu 0001, Sanjeev Setia, Sushil Jajodia, Sankardas Roy, Lingyu Wang 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2009 | Preserving Privacy for Location-Based Services with Continuous QueriesabstractLocation-based service (LBS) is gaining momentum as GPS-equipped mobile devices become increasingly affordable and popular. One of the potential obstacles faced by LBS is that users may raise concerns about their personal privacy when location data are sent to a distrusted LBS provider. A well-known solution is to render the location data less accurate through spatial or temporal cloaking. In this paper, we show that by combining consecutive location data including speed, heading direction, and cloaked locations, an adversary can obtain more accurate estimation of the actual location. We propose a solution to prevent such inferences by cloaking speed and direction. Since the cloaking is based on estimated future locations, we devise methods for tolerating errors caused by the estimation process. We report simulation results on the tradeoff between the capability of tolerating errors and the degree of cloaking. Lingyu Wang 0001, Benjamin C. M. Fung |
ICC | 2 |
| 2009 | An Aspect-Oriented Approach for Software Security Hardening: from Design to ImplementationabstractSecurity is a very challenging task in software engineering. Enforcing security policies should be taken care of during the early phases of the software development life cycle to prevent security breaches in the final product. Since security is a crosscutting concern that pervades the entire software, integrating security solutions at the software design level may result in scattering and tangling security features throughout the entire design. To address this issue, we propose in this paper an aspect-oriented approach for specifying and enforcing security hardening solutions. This approach provides software designers with UML-based capabilities to perform security hardening in a clear and organized way, at the UML design level, without the need to be security experts. We also present the SHP profile, a UML-based security hardening language to describe and specify security hardening solutions at the UML design level. Finally, we explore the efficiency and the relevance of our approach by applying it to a real world case study and present the experimental results. Djedjiga Mouheb, Chamseddine Talhi, Azzam Mourad, Vitor Lima, Mourad Debbabi, Lingyu Wang 0001, Makan Pourzandi |
SoMeT | 6 |
| 2009 | Privacy-preserving data publishing for cluster analysis
Benjamin C. M. Fung, Ke Wang 0001, Lingyu Wang 0001, Patrick C. K. Hung |
Data Knowl. Eng. | 3 |
| 2009 | Evaluating privacy threats in released database views by symmetric indistinguishabilityabstractA privacy violation occurs when the association between an individual identity and data considered private by that individual is obtained by an unauthorized party. Uncertainty and indistinguishability are two independent aspects that characterize the Lingyu Wang 0001, Xiaoyang Sean Wang, Claudio Bettini, Sushil Jajodia |
J. Comput. Secur. | 2 |
| 2008 | Securing Telehealth Applications in a Web-Based e-Health PortalabstractTelehealth applications can deliver medical services to patients at remote locations using telecommunications technologies, such as the Internet. At the same time, such applications also pose unique security challenges. First, the trust issue becomes more severe due to the lack of visual proofs in telehealth applications. The public key infrastructure (PKI) is insufficient for providing the same kind of trust a patient may attain during a face-to-face service. Second, telehealth services, such as tele-monitoring or tele-consultant, naturally demand a systematic organization of users, roles, resources, and flows of information. Existing access control mechanisms in an e-health system are usually incapable of dealing with such workflow-based services. This paper provides cost-efficient solutions to those issues in the context of a Web-based e-health portal system. First, we propose a PKI-like infrastructure for establishing trust between users using biometrics-based authentication and hierarchies of trust. Second, we develop an access control method for workflow-based telehealth services using a rule-based module already available in the portal system. Shuo Lu, Yuan Hong 0001, Lingyu Wang 0001, Rachida Dssouli |
ARES | 4 |
| 2008 | An Efficient Approach to Minimum-Cost Network Hardening Using Attack GraphsabstractAttack graphs can reveal the threat of sophisticated multi-step attacks by enumerating possible sequences of exploits leading to the compromise of given critical resources. Finding a solution to remove such threats by hands is tedious and error prone, particularly for larger and poorly secured networks. Existing automated approaches for hardening a network has an exponential complexity and is not scalable to large networks. This paper proposes a novel approach of applying the Reduced Ordered Binary Decision Diagram (ROBDD) method to network hardening. Existing mature optimization techniques in ROBDD makes the proposed approach an efficient solution that can potentially be applied to large networks. Feng Chen 0015, Lingyu Wang 0001, Jinshu Su |
IAS | 2 |
| 2008 | Measuring Network Security Using Bayesian Network-Based Attack GraphsabstractGiven the increasing dependence of our societies on information systems, the overall security of these systems should be measured and improved. Existing work generally focuses on measuring individual vulnerabilities instead of measuring their combined effects. Recent research has explored the application of attack graphs and probabilistic security metrics to address this challenge. However, such work usually assumes metrics of individual vulnerabilities to be independently distributed and combines them in an arbitrary manner. They cannot address more realistic cases, such as exploiting one vulnerability makes another vulnerability easier to exploit. In this paper, we propose to model probability metrics based on attack graphs as a special Bayesian Network. This approach provides a sound theoretical foundation to such metrics. It can also provide the capabilities of using conditional probabilities to address the general cases of interdependency between vulnerabilities. Marcel Frigault, Lingyu Wang 0001 |
COMPSAC | 2 |
| 2008 | Preserving Privacy in E-health Systems Using Hippocratic DatabasesabstractSafeguarding patientspsila private information is one of the most challenging issues in the design and implementation of modern e-Health systems. Recent advances in Hippocratic Databases (HDB) show a promising direction towards the enforcement of privacy policies in e-Health systems. This paper tackles issues in applying the HDB design to e-Health systems. More specifically, we design an architecture for integrating APPEL preferences with HDB; we extend the original HDB design to support fine-grained privacy authorizations demanded by patients; we adapt the design to a multi-dimensional model; we also propose a design for hierarchical authorizations. Finally, we discuss implementation issues and justify our designs with experimental results. Yuan Hong 0001, Shuo Lu, Lingyu Wang 0001, Rachida Dssouli |
COMPSAC | 4 |
| 2008 | An Attack Graph-Based Probabilistic Security Metric
Lingyu Wang 0001, Tania Islam, Anoop Singhal, Sushil Jajodia |
DBSec | 1 |
| 2008 | Exclusive Strategy for Generalization Algorithms in Micro-data Disclosure
Lei Zhang 0004, Lingyu Wang 0001, Sushil Jajodia, Alexander Brodsky 0001 |
DBSec | 2 |
| 2008 | A framework for privacy-preserving cluster analysisabstractReleasing person-specific data could potentially reveal sensitive information of individuals. k-anonymization is a promising privacy protection mechanism in data publishing. Though substantial research has been conducted on k-anonymization and its extensions in recent years, few of them consider releasing data for a specific purpose of data analysis. This paper presents a practical data publishing framework for determining a generalized version of data that preserves both individual privacy and information usefulness for cluster analysis. Experiments on real-life data suggest that, by focusing on preserving cluster structure in the generalization process, the cluster quality is significantly better than the cluster quality on the generalized data without such focus. The major challenge of generalizing data for cluster analysis is the lack of class labels that could be used to guide the generalization process. Our approach converts the problem into the counterpart problem for classification analysis where class labels encode the cluster structure in the data, and presents a framework to evaluate the cluster quality on the generalized data. Benjamin C. M. Fung, Ke Wang 0001, Lingyu Wang 0001, Mourad Debbabi |
ISI | 3 |
| 2008 | An Integrity Lock Architecture for Supporting Distributed Authorizations in Database Federations
Wei Li 0021, Lingyu Wang 0001, Bo Zhu 0001, Lei Zhang 0004 |
SEC | 2 |
| 2008 | A Mechanism Design-Based Multi-Leader Election Scheme for Intrusion Detection in MANETabstractIn this paper, we study the election of multiple leaders for intrusion detection in the presence of selfish nodes in mobile ad hoc networks (MANETs). To balance the resource consumption and prolong the lifetime of all nodes, each cluster should elect a node with the most remaining resources as its leader. However, without incentives for serving others, a node may behave selfishly by lying about its remaining resource and avoiding being elected. We present a solution based on mechanism design theory. More specifically, we design a scheme for electing cluster leaders that have the following two advantages: First, the collection of elected leaders is the optimal in the sense that the overall resource consumption will be balanced among all nodes in the network overtime. Second, the scheme provides the leaders with incentives in the form of reputation so that nodes are encouraged to honestly participate in the election process. The design of such incentives is based on the Vickrey, Clarke, and Groves (VCG) model by which truth-telling is the dominant strategy for each node. Simulation results show that our scheme can effectively prolong the overall lifetime of IDS in MANET and balance the resource consumptions among all the nodes. Noman Mohammed, Hadi Otrok, Lingyu Wang 0001, Mourad Debbabi, Prabir Bhattacharya |
WCNC | 3 |
| 2008 | A Moderate to Robust Game Theoretical Model for Intrusion Detection in MANETsabstractOne popular solution for reducing the resource consumption of intrusion detection system (IDS) in MANET is to elect a head-cluster (leader) to provide intrusion detection service to other nodes in the same cluster. However, such a moderate mode is only suitable when the probability of attack is low. Once the probability of attack is high, victim nodes should launch their own IDSs to detect and thwart intrusions. Such a robust mode is, however, costly with respect to energy and leads nodes to die faster. Clearly, to reduce the resource consumption of IDSs and yet keep its effectiveness, a critical issue is: when should we shift from moderate to robust mode? In this paper, we formalize this issue as a nonzero-sum noncooperative game theoretical model that takes into consideration the tradeoff between security and IDS resource consumption. The game solution will guide the leader-IDS to find the right moment for notifying the victim node to launch its IDS once the security risk is high enough. To achieve this goal, the Bayesian game theory is used to analyze the interaction between the leader-IDS and intruder with incomplete information about the intruder. By solving such a game, we are able to find the threshold value for notifying the victim node to launch its IDS once the probability of attack exceeds that value. Simulation results show that our scheme can effectively reduce the IDS resource consumption without sacrificing security. Hadi Otrok, Noman Mohammed, Lingyu Wang 0001, Mourad Debbabi, Prabir Bhattacharya |
WiMob | 3 |
| 2008 | A game-theoretic intrusion detection model for mobile ad hoc networks
Hadi Otrok, Noman Mohammed, Lingyu Wang 0001, Mourad Debbabi, Prabir Bhattacharya |
Comput. Commun. | 3 |
| 2008 | Implementing interactive analysis of attack graphs using relational databasesabstractAn attack graph models the causal relationships between vulnerabilities. Attack graphs have important applications in protecting critical resources in networks against sophisticated multi-step intrusions. Currently, analyses of attack graphs largely depend on proprietary implementations of speciali zed algorithms. However, developing and implementing algorithms causes a delay to the availability of new analyses. The delay is usually unacceptable due to rapidly-changing needs in defending against network intrusions. An administrator may want to revise an analysis as soon as its outcome is observed. Such an interactive analysis, similar to that in decision support systems, is desirable but difficult with current approaches based on proprietary implementations of algorithms. This paper addresses the above issue through a relational approach. Specifically, we devise a relational model for representing necessary inputs, such as network configurations and domain knowledge, and we generate attack graphs from these inputs as relational views. We show that typical analyses can be supported through different type of searches in an attack graph, and these searches can be realized as relational queries. Our approach eliminates the needs for implementing algorithms, because an analysis is now simply a relational query. The interactive analysis of attack graphs becomes possible, since relational queries can be dynamically constructed and revised at run time. As a side effect, experimental results show that the mature optimization techniques in relational databases can transparently improve the performance of the analysis. Lingyu Wang 0001, Anoop Singhal, Sushil Jajodia |
J. Comput. Secur. | 1 |
| 2007 | Preventing Collusion Attacks on the One-Way Function Tree (OFT) Scheme
Xuxin Xu, Lingyu Wang 0001, Amr M. Youssef, Bo Zhu 0001 |
ACNS | 2 |
| 2007 | Measuring the Overall Security of Network Configurations Using Attack Graphs
Lingyu Wang 0001, Anoop Singhal, Sushil Jajodia |
DBSec | 1 |
| 2007 | An Efficient and Truthful Leader IDS Election Mechanism for MANET
Hadi Otrok, Noman Mohammed, Lingyu Wang 0001, Mourad Debbabi, Prabir Bhattacharya |
WiMob | 3 |
| 2007 | Parity-based inference control for multi-dimensional range sum queriesabstractThis paper studies the inference control of multi-dimensional range (MDR) sum queries. We show that existing inference control methods are usually inefficient for MDR queries. We then consider parity-based inference control that restricts users to queries involving an even number of sensitive values. Such a restriction renders inferences significantly more difficult, because an even number is closed under addition and subtraction, whereas inferences target at one value. However, more sophisticated inferences are still possible with only even MDR queries. We show that the collection of all even MDR queries causes inferences if and only if a special collection of sum-two queries (that is, the summation of exactly two values) does so. The result leads to an inference control method with an improved computational complexity [Formula: see text] (over the previous result of [Formula: see text]) for m MDR queries over n values. We show that no odd MDR queries can be answered without causing inferences. We show how to check non-MDR queries for inferences in linear time. We also show how to find large inference-free subsets of even MDR queries when they do cause inferences. Lingyu Wang 0001, Yingjiu Li, Sushil Jajodia, Duminda Wijesekera |
J. Comput. Secur. | 1 |
| 2006 | Interactive Analysis of Attack Graphs Using Relational Queries
Lingyu Wang 0001, Anoop Singhal, Sushil Jajodia |
DBSec | 1 |
| 2006 | Using attack graphs for correlating, hypothesizing, and predicting intrusion alerts
Lingyu Wang 0001, Anyi Liu, Sushil Jajodia |
Comput. Commun. | 1 |
| 2006 | Minimum-cost network hardening using attack graphs
Lingyu Wang 0001, Steven Noel, Sushil Jajodia |
Comput. Commun. | 1 |
| 2005 | An Efficient and Unified Approach to Correlating, Hypothesizing, and Predicting Intrusion Alerts
Lingyu Wang 0001, Anyi Liu, Sushil Jajodia |
ESORICS | 1 |
| 2004 | Securing OLAP Data Cubes Against Privacy BreachesabstractAn OLAP (On-line Analytic Processing) system with insufficient security countermeasures may disclose sensitive information and breach an individual's privacy. Both unauthorized accesses and malicious inferences may lead to such inappropriate disclosures. Existing access control models in relational databases are unsuitable for the multi-dimensional data cubes used by OLAP. Inference control methods in statistical databases are expensive and apply to limited situations only. We first devise a flexible framework for specifying authorization objects in data cubes. The framework can partition a data cube both vertically based on dimension hierarchies and horizontally based on slices of data. We then study how to control inferences in data cubes. The proposed method eliminates both unauthorized accesses and malicious inferences. Its effectiveness does not depend on specific types of aggregation functions, external knowledge, or sensitivity criteria. The technique is efficient and readily implementable. Its on-line performance overhead is comparable to that of the minimal security requirement. Its enforcement requires little modification to existing OLAP systems. Lingyu Wang 0001, Sushil Jajodia, Duminda Wijesekera |
S&P | 1 |
| 2004 | Cardinality-based inference control in data cubesabstractThis paper addresses the inference problem in on-line analytical processing (OLAP) systems. The inference problem occurs when the exact values of sensitive attributes can be determined through answers to OLAP queries. Most existing inference control methods are computationally expensive for OLAP systems, because they ignore the special structures of OLAP queries. By exploiting such structures, we derive cardinality-based sufficient conditions for safe OLAP data cubes. Specifically, data cubes are safe from inferences if their core cuboids are dense enough, in the sense that the number of known values is under a tight bound. We then apply the sufficient conditions on the basis of a three-tier inference control model. The model introduces an aggregation tier between data and queries. The aggregation tier represents a collection of safe data cubes that are pre-computed over a partition of the data using the proposed sufficient conditions. The aggregation tier is then used to provide users with inference-free queries. Our approach mitigates the performance penalty of inference control, because partitioning the data yields smaller input to inference control algorithms, pre-computing the aggregation tier reduces on-line delay, and using cardinality-based conditions guarantees linear-time complexity. Lingyu Wang 0001, Duminda Wijesekera, Sushil Jajodia |
J. Comput. Secur. | 1 |
| 2003 | Precisely Answering Multi-dimensional Range Queries without Privacy Breaches
Lingyu Wang 0001, Yingjiu Li, Duminda Wijesekera, Sushil Jajodia |
ESORICS | 1 |
| 2002 | Auditing Interval-Based Inference
Yingjiu Li, Lingyu Wang 0001, Xiaoyang Sean Wang, Sushil Jajodia |
CAiSE | 2 |
| 2002 | Towards Secure XML Federations
Lingyu Wang 0001, Duminda Wijesekera, Sushil Jajodia |
DBSec | 1 |
| 2002 | Cardinality-Based Inference Control in Sum-Only Data Cubes
Lingyu Wang 0001, Duminda Wijesekera, Sushil Jajodia |
ESORICS | 1 |