EDBT 2026 Demo / reviewers in the wild / expert
Deqing Zou
dblp:z/DeqingZou
· DBLP profile ↗
163ranked-venue papers
23as first author
74since 2021 · last 2026
0000-0001-8534-5048ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 56 · 6 first-author · 26 since 2021Systems, architecture and hardware · 32 · 5 first-author · 9 since 2021Software engineering, systems software and programming languages · 30 · 4 first-author · 21 since 2021Applied, interdisciplinary, general and emerging computing · 20 · 2 first-author · 9 since 2021Computer networks · 19 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-authorArtificial intelligence and machine learning · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VulJSFormer: Learning to Detect JavaScript Vulnerabilities with Vulnerability-Relevant Graphs
Kunlun Ren, Haochen He, Weizhong Qiang, Yueming Wu 0001, Deqing Zou |
DSN | 6 |
| 2026 | VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability Analysis
Yueming Wu 0001, Yifeng Cai, Deqing Zou |
NDSS | 5 |
| 2026 | From Intention to Practice: Towards Systematic Validation of NIDS Rule Enforcement
Haoyu Chen 0004, Biang Xu, Jingyao Zhou, Bin Yuan 0002, Qiankun Zhang 0001, Deqing Zou, Hai Jin 0001 |
NSDI | 7 |
| 2026 | DMCGuard: risky perils and fine-grained control on IoT multiple device management channels
Bin Yuan 0002, Kaimin Zheng, Yan Jia 0009, Jiajun Ren, Kunming Wang 0003, Shengjiu Shi, Deqing Zou, Hai Jin 0001 |
Frontiers Comput. Sci. | 7 |
| 2026 | Forseti: A Decentralized Permission Transfer Framework for IoT LeasingabstractThe widespread use of IoT devices in the accommodation and hospitality sectors has created demand for temporary device-permission sharing and transfer. Prior work has largely focused on security issues in device permission sharing, with far less attention devoted to device permission transfer. However, inappropriate access control management during device permission transfer can also lead to violations of the users' expectations of control over their devices. For example, a malicious host retaining or regaining access to a camera after its permission has been transferred to a tenant. In this paper, we present the first systematic study on understanding and enhancing the security of device permission transfer in IoT leasing. To this end, we propose Forseti, a new authorization framework that leverages zero-knowledge proof and a decentralized ledger to ensure that the rights of both hosts and tenants are not violated. Our evaluation demonstrates that Forseti is effective, efficient, scalable, and compatible with existing IoT platforms. Bin Yuan 0002, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Eler: Ensemble Learning-Based Automated Verification of Code Clones
Shihan Dou, Siyue Feng, Yueming Wu 0001, Deqing Zou |
IEEE Trans. Software Eng. | 5 |
| 2025 | Position: LLMs Can be Good Tutors in English EducationabstractJingheng Ye, Shen Wang, Deqing Zou, Yibo Yan, Kun Wang, Hai-Tao Zheng, Ruitong Liu, Zenglin Xu, Irwin King, Philip S. Yu, Qingsong Wen. Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing. 2025. Jingheng Ye, Shen Wang 0005, Deqing Zou, Kun Wang 0042, Hai-Tao Zheng 0002, Zenglin Xu, Irwin King, Philip S. Yu, Qingsong Wen |
EMNLP | 3 |
| 2025 | ROMA: Recommendation-Oriented Language Model Adaptation Using Multi-Modal Multi-Domain Item SequencesabstractSequential recommendation (SR) aims to capture dynamic user preferences from users' historical behaviors. Recently, benefiting from astonishing understanding ability of pre-trained language models (PLMs), text-enhanced sequential recommender becomes a promising direction, which employs PLMs to extract semantic information for user/item representation. Although promising in improving performance and transferability, few existing text-enhanced SR studies have analyzed the differences between PLMs and recommenders, restricting the ability of PLMs for recommendation. In this paper, we make an in-depth comparison and conclude their discrepancies in representation and knowledge level, respectively, caused by different multi-modal content and task-oriented capabilities. Based on this, we propose a Recommendation-Oriented Language Model Adaptation framework (named ROMA) using multi-modal multi-domain item sequences. To empower PLMs with a rational understanding of user/item modeling and the recommendation task, ROMA partitions a PLM into bottom and top layers, respectively, allowing representation-level and task-level adaptation with elaborately designed architectures, transferring strategy and learning framework. Our experimental results on public benchmarks demonstrate the effectiveness and transferability of our framework. Additionally, we showcase the application value of ROMA on the recommender system of Huawei's AppGallery through online A/B testing, which shows significant improvements in online metrics. Jinpeng Wang 0002, Jieming Zhu, Zhicheng Zhang 0008, Deqing Zou, Hai-Tao Zheng 0002, Shutao Xia, Rui Zhang 0003 |
KDD (2) | 5 |
| 2025 | SoK: Automated Vulnerability Repair: Methods, Tools, and Assessments
Zhen Li 0027, Kedie Shu, Shenghua Guan, Deqing Zou, Shouhuai Xu, Bin Yuan 0002, Hai Jin 0001 |
USENIX Security Symposium | 5 |
| 2025 | Efficient and Privacy-Preserving Artificial Neural Network Model Training With Separated Data in IoTabstractMachine learning models based on artificial neural networks have been widely adopted to support diverse complex applications. However, the training of such models heavily relies on large-scale datasets, which may raise privacy concerns. Taking the Internet of Things (IoT) as an example, distributed edge devices collect data, while central servers aggregate this data for model training and in-depth analysis. Unlike frameworks like federated learning, local model training becomes infeasible due to constrained edge device capabilities, model confidentiality requirements, or the separation of complete data features across multiple devices. This scenario may render traditional federated learning-based privacy-preserving frameworks ineffective. To address these limitations, we propose an efficient privacy-preserving model training protocol that demonstrates practical advantages over fully homomorphic encryption and functional encryption methods. Our protocol leverages additively homomorphic encryption combined with the Chinese Remainder Theorem to design secure matrix-vector computations, minimizing encryption/decryption operations and reducing computational overhead on edge devices while preserving training efficiency and model accuracy. To further optimize performance, we further propose a secondary protocol that introduces optimization strategies to enhance efficiency and lighten edge nodes’ computational burdens. Security analysis and rigorous correctness proofs are provided, and performance evaluations and experimental validation confirm both protocols’ practical feasibility and effectiveness. Weiqi Dai, Yanke Zhang, Kim-Kwang Raymond Choo, Xia Xie 0001, Deqing Zou |
IEEE Internet Things J. | 6 |
| 2025 | MalScan: Android Malware Detection Based on Social-Network Centrality AnalysisabstractMalware scanning of an app market is expected to be scalable and effective. However, existing approaches use syntax-based features that can be evaded by transformation attacks or semantic-based features which are usually extracted by expensive program analysis. Therefore, to address the scalability challenges of traditional heavyweight static analysis, we propose a graph-based lightweight approachMalScanfor Android malware detection.MalScanconsiders the function call graph as a complex social network and employs centrality analysis on sensitiveapplication program interfaces(APIs) to express the semantic characteristics of the graph. On this basis, machine learning algorithms and ensemble learning algorithms are applied to classify the extracted features. We evaluateMalScanon datasets of 104,892 benign apps and 108,640 malwares, and the results of experiments indicate thatMalScanoutperforms six state-of-the-art detectors and can quickly detect Android malware with an f-value as high as 99%. In addition, there are also significant improvements in the robustness of Android app evolution and robustness to obfuscation. Finally, we conduct an exhaustive statistical study of over one million applications in the Google-Play app market and successfully identify 498 zero-day malware, which further validates the feasibility ofMalScanon market-wide malware scanning. Yueming Wu 0001, Wenqi Suo, Siyue Feng, Deqing Zou, Wei Yang 0013, Yang Liu 0003, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | CR-DAP: A Comprehensive and Regulatory Decentralized Anonymous Payment SystemabstractAmong various blockchain applications, decentralized anonymous payment (DAP) systems stand out for their enhanced privacy protection compared to traditional payment methods. However, DAPs face challenges such as the lack of asset recovery and identity verification features. To ensure the long-term healthy development of DAP systems, adherence to legal regulations and privacy protection is equally critical. In response to these requirements, we propose a$\textsf {CR}$-$\textsf {DAP}$system that offers a secure and efficient solution without compromising on practicality. Our innovation lies in introducing an identity-based traceable anonymous signature scheme, which skillfully balances anonymity with traceability. This scheme supports private key retrieval and allows for identity tracking when necessary, addressing key pain points in existing anonymous payment systems and enhancing user trust. We have implemented the prototype of this signature scheme and the$\textsf {CR}$-$\textsf {DAP}$system, evaluating its performance to demonstrate its practicality. Weiqi Dai, Xiaohai Dai, Kim-Kwang Raymond Choo, Xia Xie 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | MalPacDetector: An LLM-Based Malicious NPM Package DetectorabstractThe Node Package Manager (NPM) registry contains millions of JavaScript packages widely shared between worldwide developers. However, NPM has also been abused by attackers to spread malicious packages, highlighting the importance of detecting malicious NPM packages. Existing malicious NPM package detectors suffer from, among other things, high false positives and/or high false negatives. In this paper, we propose a novel Malicious NPM Package Detector (MalPacDetector), which leverages Large Language Model (LLM) to automatically and dynamically generate features (rather than asking experts to manually define them). To evaluate the effectiveness of Mal-PacDetector and existing detectors, we construct a new NPM package dataset, which overcomes the weaknesses of existing datasets (e.g., a small number of examples and a high repetition rate of malicious fragments). The experimental results show that MalPacDetector outperforms existing detectors by achieving a false positive rate of 1. 3% and a false negative rate of 7. 5%. In particular, MalPacDetector detects 39 previously unknown malicious packages, which are confirmed by the NPM security team. Zhen Li 0027, Jixiang Qu, Deqing Zou, Shouhuai Xu, Ziteng Xu, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | MalSensor: Fast and Robust Windows Malware ClassificationabstractDriven by the substantial profits, the evolution of Portable Executable (PE) malware has posed persistent threats. PE malware classification has been an important research field, and numerous classification methods have been proposed. With the development of machine learning, learning-based static classification methods achieve excellent performance. However, most existing methods cannot meet the requirements of industrial applications due to the limited resource consumption and concept drift. In this article, we propose a fast, high-accuracy, and robust FCG-based PE malware classification method. We first extract precise function call relationships through code and data cross-referencing analysis. Then we normalize function names to construct a concise and accurate function call graph. Furthermore, we perform topological analysis of the function call graph using social network analysis techniques, thereby enhancing the program function call features. Finally, we use a series of machine learning algorithms for classification. We implement a prototype system named MalSensor and compare it with nine state-of-the-art static PE malware classification methods. The experimental results show that MalSensor is capable of classifying a malicious file in 0.7 seconds on average with up to 98.35% accuracy, which represents a significant advantage over existing methods. Haojun Zhao, Yueming Wu 0001, Deqing Zou, Yang Liu 0003, Hai Jin 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | Fine-Grained Code Clone Detection by Keywords-Based Connection of Program Dependency GraphabstractCode clone detection is intended to identify functionally similar code fragments, a matter of escalating significance in contemporary software engineering. Numerous methodologies have been proffered for the detection of code clones, among which graph-based approaches exhibit efficacy in addressing semantic code clones. However, they all only consider the feature extraction of a single sample and ignore the semantic connection between different samples, resulting in the detection effect being unsatisfactory. Simultaneously, the majority of existing methods can only ascertain the presence of clones, lacking the capability to provide nuanced insights into which lines of code exhibit greater similarity. In this article, we advocate a novel PDG-based semantic clone detection method, namely,Keyborwhich can locate specific cloned lines of code by providing a fine-grained analysis of clone pairs. The highlight of the approach is to consider keywords as a bridge to connect PDG nodes of the target program to retain more semantic information about the functional code. To examine the effectiveness ofKeybor, we assess it on a widely usedBigCloneBenchdataset. Experimental results indicate thatKeyboris superior to 14 advanced code clone detection tools (i.e.,CCAligner,SourcererCC,Siamese,NIL,NiCad,LVMapper,CCFinder,CloneWorks,Oreo,Deckard,CCGraph,Code2Img,GPT-3.5-turbo, andGPT-4). Yueming Wu 0001, Wenqi Suo, Siyue Feng, Cong Wu 0003, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Reliab. | 5 |
| 2024 | UniEmbedding: Learning Universal Multi-Modal Multi-Domain Item Embeddings via User-View Contrastive LearningabstractLearning high-quality item embeddings is crucial for recommendation tasks such as matching and ranking. However, existing methods often rely on ID-based item embeddings learned end-to-end with downstream recommendation models, which may suffer from overfitting and limited generalizability. In this paper, we aim to learn universal item embeddings (dubbed UniEmbedding) that capture multi-modal semantics, generalize across multiple domains, and serve different downstream tasks. To achieve this goal, we introduce the UniEmbedding pretraining framework, which includes three modules: a domain-aware multi-modal adapter, a user-view projection module, and contrastive learning objectives across domains. Compared to naive ID embeddings, UniEmbedding provides rich semantic information that generalizes more effectively across domains. Unlike multi-modal embeddings directly extracted from off-the-shelf pretrained models, UniEmbedding achieves better alignment between content semantics and behaviors. We evaluated UniEmbedding on both public and industrial datasets, demonstrating its effectiveness in matching and ranking tasks. Furthermore, UniEmbedding has been deployed in multiple recommendation applications at Huawei, resulting in significant gains in user engagement metrics. Boqi Dai, Zhaocheng Du, Jieming Zhu, Deqing Zou, Quanyu Dai, Zhenhua Dong, Rui Zhang 0003, Hai-Tao Zheng 0002 |
CIKM | 5 |
| 2024 | Gradient Boosting-Accelerated Evolution for Multiple-Fault DiagnosisabstractLogic diagnosis is a key step in yield learning. Multiple faults diagnosis is challenging because of several reasons, including error masking, fault reinforcement, and huge search space for possible fault combinations. This work proposes a two-phase method for multiple-fault diagnosis. The first phase efficiently reduces the potential number of fault candidates through machine learning. The second phase obtains the final diagnosis results, by formulating the task as an combinational optimization problem that is later iteratively solved using binary evolution computation. Experiments shows that our method outperforms two existing methods for multiple-fault diagnosis, and achieves better diagnosability (improved by$1.87\times$) and resolution (improved by$1.42\times$) compared with a state-of-the-art commercial diagnosis tool. Chenliang Luo, Deqing Zou, Hai Jin 0001 |
DATE | 3 |
| 2024 | Owl: Differential-Based Side-Channel Leakage Detection for CUDA ApplicationsabstractOver the past decade, various methods for detecting side-channel leakage have been proposed and proven to be effective against CPU side-channel attacks. These methods are valuable in assisting developers to identify and patch side-channel vulnerabilities. Nevertheless, recent research has revealed the feasibility of exploiting side-channel vulnerabilities to steal sensitive information from GPU applications, which are beyond the reach of previous side-channel detection methods. Therefore, in this paper, we conduct an in-depth examination of various GPU features and present Owl, a novel side-channel detection tool targeting CUDA applications on NVIDIA GPUs. Owl is designed to detect and locate side-channel leakage in various types of CUDA applications. When tracking the execution of CUDA applications, we design a hierarchical tracing scheme and extend the A-DCFG (Attributed Dynamic Control Flow Graph) to address the massively parallel execution in CUDA, ensuring Owl's detection scalability. After completing the initial assessment and filtering, we conduct statistical tests on the differences in program traces to determine whether they are indeed caused by input variations, subsequently facilitating the positioning of side-channel leaks. We evaluate Owl's capability to detect side-channel leaks by testing it on Libgpucrypto, PyTorch, and nvJPEG. Meanwhile, we verify that our solution effectively handles a large number of threads. Owl has successfully identified hundreds of leaks within these applications. To the best of our knowledge, we are the first to implement side-channel leakage detection for general CUDA applications. Wenjie Xue, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
DSN | 5 |
| 2024 | ReminISCence: Trusted Monitoring Against Privileged Preemption Side-Channel Attacks
Yinqian Zhang, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
ESORICS (4) | 5 |
| 2024 | On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural VulnerabilitiesabstractSoftware vulnerabilities are a major cyber threat and it is important to detect them. One important approach to detecting vulnerabilities is to use deep learning while treating a program function as a whole, known as function-level vulnerability detectors. However, the limitation of this approach is not understood. In this paper, we investigate its limitation in detecting one class of vulnerabilities known as inter-procedural vulnerabilities, where the to-be-patched statements and the vulnerability-triggering statements belong to different functions. For this purpose, we create the first Inter-Procedural Vulnerability Dataset (InterPVD) based on C/C++ open-source software, and we propose a tool dubbed VulTrigger for identifying vulnerability-triggering statements across functions. Experimental results show that VulTrigger can effectively identify vulnerability-triggering statements and inter-procedural vulnerabilities. Our findings include: (i) inter-procedural vulnerabilities are prevalent with an average of 2.8 inter-procedural layers; and (ii) function-level vulnerability detectors are much less effective in detecting to-be-patched functions of inter-procedural vulnerabilities than detecting their counterparts of intra-procedural vulnerabilities. Zhen Li 0027, Ning Wang 0098, Deqing Zou, Ruqian Zhang, Shouhuai Xu, Chao Zhang 0008, Hai Jin 0001 |
ICSE | 3 |
| 2024 | Machine Learning is All You Need: A Simple Token-based Approach for Effective Code Clone DetectionabstractAs software engineering advances and the code demand rises, the prevalence of code clones has increased. This phenomenon poses risks like vulnerability propagation, underscoring the growing importance of code clone detection techniques. While numerous code clone detection methods have been proposed, they often fall short in real-world code environments. They either struggle to identify code clones effectively or demand substantial time and computational resources to handle complex clones. This paper introduces a code clone detection method namely Toma using tokens and machine learning. Specifically, we extract token type sequences and employ six similarity calculation methods to generate feature vectors. These vectors are then input into a trained machine learning model for classification. To evaluate the effectiveness and scalability of Toma, we conduct experiments on the widely used BigCloneBench dataset. Results show that our tool outperforms token-based code clone detectors and most tree-based clone detectors, demonstrating high effectiveness and significant time savings. Siyue Feng, Wenqi Suo, Yueming Wu 0001, Deqing Zou, Yang Liu 0003, Hai Jin 0001 |
ICSE | 4 |
| 2024 | MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT ImplementationsabstractIoT messaging protocols are critical to connecting users and IoT devices. Among all the protocols, the Message Queuing and Telemetry Transport (MQTT) is arguably the most widely used. Mainstream IoT platforms leverage MQTT brokers, server side implementation of MQTT, to enable and mediate user-device communication (e.g., the transmission of control commands). There are over 70 open-source MQTT brokers, which have been widely adopted in production. Any security defects in those open-source MQTT brokers easily get into many vendors’ IoT deployments with amplified impacts, inevitably endangering the security of IoT applications and millions of users. We report the first systematic security analysis of open-source MQTT brokers in the wild. To enable the analysis, we designed and developed MQTTactic, a semi-automatic tool that can formally verify MQTT broker implementations based on generated security properties. MQTTactic is based on static code analysis, formal modeling, and automated model checking (with off-the-shelf model checker Spin). In designing MQTTactic, we characterize and address key technical challenges. MQTTactic currently focuses on authorization-related properties, and discovered 7 novel, zero-day flaws practically enabling serious, unauthorized access. We reported all flaws to related parties, who acknowledged the issues and have been taking actions to fix them. Our thorough evaluation shows that MQTTactic is effective and practical. Bin Yuan 0002, Zhanxiang Song, Yan Jia 0009, Deqing Zou, Hai Jin 0001, Luyi Xing |
SP | 5 |
| 2024 | FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability Detection
Siyue Feng, Yueming Wu 0001, Wenjie Xue, Sikui Pan, Deqing Zou, Yang Liu 0003, Hai Jin 0001 |
USENIX Security Symposium | 5 |
| 2024 | DT-Block: Adaptive vertical federated reinforcement learning scheme for secure and efficient communication in 6G
Ihsan H. Abdulqadder, Israa T. Aziz, Deqing Zou |
Comput. Networks | 3 |
| 2024 | DFier: A directed vulnerability verifier for Ethereum smart contracts
Zeli Wang, Weiqi Dai, Kim-Kwang Raymond Choo, Deqing Zou |
J. Netw. Comput. Appl. | 5 |
| 2024 | Tensor Recurrent Neural Network With Differential PrivacyabstractRecurrent neural network (RNN), a branch of deep learning, is a powerful model for sequential data that has outstanding performance on a wide range of important Internet of Things (IoT) tasks. This unprecedented growth of RNN model has however encountered both heterogeneous IoT data and privacy issues. Existing RNN model can not deal with heterogeneous sequential data; often the larger datasets used in training of RNN model contain sensitive information. To tackle these challenges and for the first time, this research proposes a novel differentially private tensor-based RNN (DPTRNN) that can be applied in many challenging deep learning sequence tasks for IoT systems. Specifically, to process heterogeneous sequential data, we propose a tensor-based RNN model. To guarantee privacy, we develop a tensor-based back-propagation through time algorithm with perturbation to avoid exposing the sensitive information for training the tensor-based RNN model within the framework of differential privacy. Thorough security analysis shows that the differential private tensor-based RNN efficiently protects the confidentiality of sensitive user information for IoT. Our results from extensive experiments on two challenging large video datasets suggest that our proposed scheme is practical with guarantee of data privacy preservation and acceptable accuracy loss. Jun Feng 0007, Laurence T. Yang, Bocheng Ren, Deqing Zou, Mianxiong Dong, Shunli Zhang 0003 |
IEEE Trans. Computers | 4 |
| 2024 | Leakage of Authorization-Data in IoT Device Sharing: New Attacks and CountermeasureabstractDevice sharing among users is a common functionality in today's IoT clouds. Supporting device sharing are the delegation methods proposed by different IoT clouds, which we find are heterogeneous and ad-hoc IoT clouds use various data (e.g., device ID, product ID, and access token) as authorization certificates. In this paper, we report the first systematic study on how the authorization-data are managed in IoT device sharing. Our study brought to light the security risks in today's IoT authorization-data management, identifying 6 authorization-data leakage flaws. To mitigate such flaws, we propose an approach to hide the authorization-data from the delegatee (a.k.a., the user authorized to access the devices) without disrupting the device sharing services. We propose SecHARE, an automated tool to patch the vulnerable IoT clouds. We applied SecHARE to 3 popular open-source IoT clouds. Results have shown the compatibility, effectiveness, and efficiency of SecHARE. We have made SecHARE publicly available Bin Yuan 0002, Maogen Yang, Qunjinming Chen, Zhanxiang Song, Zhen Li 0027, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | PRBFPT: A Practical Redactable Blockchain Framework With a Public TrapdoorabstractWhile blockchain is known to support open and transparent data exchange, partly due to its nontamperability property, it can also be (ab)used to facilitate the spreading of fake and misleading information or information that was subsequently discredited. Hence, this paper proposes a practical, redactable blockchain framework with a public trapdoor (hereafter referred to as PRBFPT). PRBFPT comprises an editing scheme for adding blocks using a new type of blockchain with a chameleon hash. Specifically, PRBFPT is able to involve all nodes in the blockchain in the editing operations by means of a public trapdoor, without requiring additional trapdoor management by predefined nodes or organizations. PRBFPT is also designed to audit and record the content of each editing operation. In other words, after editing and deleting the original data, PRBFPT can still verify its legitimacy. We also propose a contract-based locked voting scheme to better support voting. We then evaluate the prototype implementation of PRBFPT, whose findings show that the total time consumption of adding modules is at the millisecond level, with a negligible impact on the performance of the original system. In addition, the evaluation findings show that the cost of initiating the special transactions is comparable to the consumption of normal Ethereum transactions and is within a manageable range. Weiqi Dai, Jinkai Liu, Kim-Kwang Raymond Choo, Xia Xie 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | PASSP: A Private Authorization Scheme Oriented Service ProvidersabstractIn our data-centric society, major service providers have access to vast amounts of user information (e.g., user-generated content such as social media posts, and device-generated content such as geolocation data) for convenient and efficient services. There are privacy implications when users authorize share personal data managed by service providers. To make authorization private and controllable, in this paper, we propose a private authorization scheme oriented service providers. A decentralized publicly-verifiable re-encryption method based on IPFS is proposed to minimize the reliance on service providers, by shifting to a distributed storage and computation model. Besides, we propose a trustless authorization authentication method that hides the authorization relationship to protect user privacy. We also evaluate the security of our scheme, as well as its performance to demonstrate utility. Weiqi Dai, Liangliang Yu, Kim-Kwang Raymond Choo, Deqing Zou, Xia Xie 0001, Hai Jin 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | Toward Automated Attack Discovery in SDN Controllers Through Formal VerificationabstractSoftware-defined Network (SDN), presented to be a novel architecture of network because of its separation of data plane and control plane, brings centralization and extensibility to network management as well as new attacks that exploit the flexibility of SDN. OpenFlow, which is the protocol that is applied by the majority of SDN, leads to the widely used definition of the communication between the controller and the switch resulting in similar implementations regardless of different vendors. In this paper, we focus on the mechanisms of packet processing and topology discovery and their fundamental weaknesses caused by general implementations or device limitations. Despite the common vulnerabilities, the universal standard mechanisms of basic function in SDN also enlighten us to present an automated attack discovery method based on the formal verification with a generic model of SDN system. We describe the abstraction of the SDN components, their key functions, and communications along with the malicious operations that could be executed by malicious hosts and malicious switches and translate them into a formal model of the SDN system. The formal verification carried on with the assertion representing the security properties derived from the common vulnerabilities of the SDN system reports the potential attack paths each of which shows an attack process. Our evaluation shows that our method can discover feasible attack paths efficiently and effectively, with 23 attacks being identified, among which 2 are new. We further demonstrate the practicality of the 2 new attacks. Bin Yuan 0002, Chi Zhang 0117, Jiajun Ren, Qunjinming Chen, Biang Xu, Qiankun Zhang 0001, Zhen Li 0027, Deqing Zou, Fan Zhang 0024, Hai Jin 0001 |
IEEE Trans. Netw. Serv. Manag. | 8 |
| 2024 | DeepFPD: Browser Fingerprinting Detection via Deep Learning With Multimodal Learning and AttentionabstractBrowser fingerprinting is a stateless tracking technique that poses a significant security threat to users' privacy. However, the distinction between fingerprinting and nonfingerprinting scripts is far from well-defined, making the detection of fingerprinting scripts very challenging. Existing methods for detecting browser fingerprinting are based on heuristics or machine learning, and thus either require strictly defined rules or are not able to learn the features of fingerprinting scripts comprehensively, failing to detect a significant fraction of fingerprinting scripts. To detect browser fingerprinting more effectively, we propose a deep learning-based detection method,DeepFPD, in which multiple script modalities including tokens, abstract syntax trees, and control flow graphs are learned by using different specific neural networks to obtain lexical, syntax, and control flow information of the script code. Moreover, the attention mechanism is introduced to enhance the effectiveness ofDeepFPD. The experimental results on the training dataset and test dataset constructed based on real-world scripts show thatDeepFPDoutperforms the state-of-the-art work with an F1-measure improvement of 8.3% and 18.7%, respectively. Weizhong Qiang, Kunlun Ren, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Reliab. | 4 |
| 2024 | Goner: Building Tree-Based N-Gram-Like Model for Semantic Code Clone DetectionabstractCode clone detection refers to the detection of code fragments that are functionally similar. As software engineering progresses, the significance of code clone detection continues to grow. A number of code clone detection techniques have been designed. Among these methods, tree-based code clone detection approaches can discover semantic code clones. However, given the intricate nature of tree structures, they consume plenty of time to complete the tree analysis, thus cannot scale to large-scale code scanning. In this paper, we propose a novel tree-based scalable semantic code clone detection method by transforming the heavy-weight tree processing into efficient N-gram-like subtrees analysis. Specifically, we build a variant of N-gram model to partition the original complex tree into small subtrees. After collecting all subtrees, we divide them into different groups according to the positions of the subtree nodes, and then calculate the similarity of the same group between two functions one by one. Similarity scores of all groups are made up of a feature vector. Given feature vectors, we train a machine learning model for semantic code clone detection. We implementGonerand conduct evaluations on two extensively utilized datasets, namely BigCloneBench and Google Code Jam. The experimental results indicate thatGoneroutperforms our comparative systems (i.e.SourcererCC,RtvNN,Deckard,ASTNN,TBCNN,CDLH,Amain,FCCA,DeepSim, andSCDetector). Additionally, in the context of scalability,Gonerdemonstrates remarkable speed, being approximately 56 times faster than another advanced tree-based tool, namelyASTNN, when it comes to identifying semantic code clones. Yueming Wu 0001, Siyue Feng, Wenqi Suo, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Reliab. | 4 |
| 2024 | An Empirical Study on Android Malware Characterization by Social Network AnalysisabstractAndroid malware detection has always been a hot research field. Prior work has validated that graph-based Android malware detection methods are effective, and several works have been proposed to regard the call graph of an app as a social network for more efficient classification. However, a social network contains many properties and there is a lack of perception as to which social network properties are more useful in differentiating malware from benign apps. Therefore, in this article, we present the first empirical study to analyze Android malware by different social network properties. We conduct extensive statistical analysis on 100 000 Android apps and apply three feature ranking methods to research the ability of 57 social network properties on malware detection. Moreover, in an effort to validate the effectiveness of these social network properties on malware detection, we implement a tool calledSNADroidby using these properties as features for models training and use it to complete classification. Our study reveals that theaverage triangles numberis the most impactful social network property in distinguishing malware from benign apps. Combined with the experimental results and in-depth analysis, we present the 15 most effective features for graph-based malware detection using social properties as a guideline. Haojun Zhao, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Reliab. | 3 |
| 2023 | JSRevealer: A Robust Malicious JavaScript Detector against ObfuscationabstractDue to the convenience and popularity of Web applications, they have become a prime target for attackers. As the main programming language for Web applications, many methods have been proposed for detecting malicious JavaScript, among which static analysis-based methods play an important role because of their high effectiveness and efficiency. However, obfuscation techniques are commonly used in JavaScript, which makes the features extracted by static analysis contain many useless and disguised features, leading to many false positives and false negatives in detection results. In this paper, we propose a novel method to find out the essential features related to the semantics of JavaScript code. Specifically, we develop JS-Revealer, a robust, effective, scalable, and interpretable detector for malicious JavaScript. To test the capabilities of JSRevealer, we conduct comparative experiments with four other state-of-the-art malicious JavaScript detection tools. The experimental results show that JSRevealer has an average F1 of 84.8% on the data obfuscated by different obfuscators, which is 21.6%, 22.3%, 18.7%, and 22.9% higher than the tools CUJO, ZOZZLE, JAST, and JSTAP, respectively. Moreover, the detection results of JSRevealer can be interpreted, which can provide meaningful insights for further security research. Kunlun Ren, Weizhong Qiang, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
DSN | 5 |
| 2023 | Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemabstractModern software systems are increasingly relying on dependencies from the ecosystem. A recent estimation shows that around 35% of an open-source project's code come from its depended libraries. Unfortunately, open-source libraries are often threatened by various vulnerability issues, and the number of disclosed vulnerabilities is increasing steadily over the years. Such vulnerabilities can pose significant security threats to the whole ecosystem, not only to the vulnerable libraries themselves, but also to the corresponding downstream projects. Many Software Composition Analysis (SCA) tools have been proposed, aiming to detect vulnerable libraries or components referring to existing vulnerability databases. However, recent studies report that such tools often generate a large number of false alerts. Particularly, up to 73.3% of the projects depending on vulnerable libraries are actually safe. Aiming to devise more precise tools, understanding the threats of vulnerabilities holistically in the ecosystem is significant, as already performed by a number of existing studies. However, previous researches either analyze at a very coarse granularity (e.g., without analyzing the source code) or are limited by the study scales. This study aims to bridge such gaps. In particular, we collect 44,450 instances of (CVE, upstream, downstream) relations and analyze around 50 million invocations made from downstream to upstream projects to understand the potential threats of upstream vulnerabilities to downstream projects in the Maven ecosystem. Our investigation makes interesting yet significant findings with respect to multiple aspects, including the reach-ability of vulnerabilities, the complexities of the reachable paths as well as how downstream projects and developers perceive upstream vulnerabilities. We believe such findings can not only provide a holistic understanding towards the threats of upstream vulnerabilities in the Maven ecosystem, but also can guide future researches in this field. Zeliang Yu, Ming Wen 0001, Deqing Zou, Hai Jin 0001 |
ICSE | 5 |
| 2023 | Enhancing Deep Learning-based Vulnerability Detection by Building Behavior Graph ModelabstractSoftware vulnerabilities have posed huge threats to the cyberspace security, and there is an increasing demand for automated vulnerability detection (VD). In recent years, deep learning-based (DL-based) vulnerability detection systems have been proposed for the purpose of automatic feature extraction from source code. Although these methods can achieve ideal performance on synthetic datasets, the accuracy drops a lot when detecting real-world vulnerability datasets. Moreover, these approaches limit their scopes within a single function, being not able to leverage the information between functions. In this paper, we attempt to extract the function's abstract behaviors, figure out the relationships between functions, and use this global information to assist DL-based VD to achieve higher performance. To this end, we build a Behavior Graph Model and use it to design a novel framework, namely VulBG. To examine the ability of our constructed Behavior Graph Model, we choose several existing DL-based VD models (e.g., TextCNN, ASTGRU, CodeBERT, Devign, and VulCNN) as our baseline models and conduct evaluations on two real-world datasets: the balanced$\text{FFMpeg}+\text{Qemu}$dataset and the unbalanced$\text{Chrome} +\text{Debian}$dataset. Experimental results indicate that VulBG enables all baseline models to detect more real vulnerabilities, thus improving the overall detection performance. Bin Yuan 0002, Yilin Fang, Yueming Wu 0001, Deqing Zou, Zhen Li 0027, Zhi Li 0048, Hai Jin 0001 |
ICSE | 5 |
| 2023 | Interpreters for GNN-Based Vulnerability Detection: Are We There Yet?abstractTraditional vulnerability detection methods have limitations due to their need for extensive manual labor. Using automated means for vulnerability detection has attracted research interest, especially deep learning, which has achieved remarkable results. Since graphs can better convey the structural feature of code than text, graph neural network (GNN) based vulnerability detection is significantly better than text-based approaches. Therefore, GNN-based vulnerability detection approaches are becoming popular. However, GNN models are close to black boxes for security analysts, so the models cannot provide clear evidence to explain why a code sample is detected as vulnerable or secure. At this stage, many GNN interpreters have been proposed. However, the explanations provided by these interpretations for vulnerability detection models are highly inconsistent and unconvincing to security experts. To address the above issues, we propose principled guidelines to assess the quality of the interpretation approaches for GNN-based vulnerability detectors based on concerns in vulnerability detection, namely, stability, robustness, and effectiveness. We conduct extensive experiments to evaluate the interpretation performance of six famous interpreters (GNN-LRP, DeepLIFT, GradCAM, GNNExplainer, PGExplainer, and SubGraphX) on four vulnerability detectors (DeepWukong, Devign, IVDetect, and Reveal). The experimental results show that the target interpreters achieve poor performance in terms of effectiveness, stability, and robustness. For effectiveness, we find that the instance-independent methods outperform others due to their deep insight into the detection model. In terms of stability, the perturbation-based interpretation methods are more resilient to slight changes in model parameters as they are model-agnostic. For robustness, the instance-independent approaches provide more consistent interpretation results for similar vulnerabilities. Suyuan Wang, Wenke Li, Junru Peng, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
ISSTA | 6 |
| 2023 | Fine-Grained Code Clone Detection with Block-Based Splitting of Abstract Syntax TreeabstractCode clone detection aims to find similar code fragments and gains increasing importance in the field of software engineering. There are several types of techniques for detecting code clones. Text-based or token-based code clone detectors are scalable and efficient but lack consideration of syntax, thus resulting in poor performance in detecting syntactic code clones. Although some tree-based methods have been proposed to detect syntactic or semantic code clones with decent performance, they are mostly time-consuming and lack scalability. In addition, these detection methods can not realize fine-grained code clone detection. They are unable to distinguish the concrete code blocks that are cloned. In this paper, we design Tamer, a scalable and fine-grained tree-based syntactic code clone detector. Specifically, we propose a novel method to transform the complex abstract syntax tree into simple subtrees. It can accelerate the process of detection and implement the fine-grained analysis of clone pairs to locate the concrete clone parts of the code. To examine the detection performance and scalability of Tamer, we evaluate it on a widely used dataset BigCloneBench. Experimental results show that Tamer outperforms ten state-of-the-art code clone detection tools (i.e., CCAligner, SourcererCC, Siamese, NIL, NiCad, LVMapper, Deckard, Yang2018, CCFinder, and CloneWorks). Tiancheng Hu, Zijing Xu, Yilin Fang, Yueming Wu 0001, Bin Yuan 0002, Deqing Zou, Hai Jin 0001 |
ISSTA | 6 |
| 2023 | An Empirical Study on the Effects of Obfuscation on Static Machine Learning-Based Malicious JavaScript DetectorsabstractMachine learning is increasingly being applied to malicious JavaScript detection in response to the growing number of Web attacks and the attendant costly manual identification. In practice, to hide their malicious behaviors or protect intellectual copyrights, both malicious and benign scripts tend to obfuscate their own code before uploading. While obfuscation is beneficial, it also introduces some additional code features (e.g., dead code) into the code. When machine learning is employed to learn a malicious JavaScript detector, these additional features can affect the model to make it less effective. However, there is still a lack of clear understanding of how robust existing machine learning-based detectors are on different obfuscators. In this paper, we conduct the first empirical study to figure out how obfuscation affects machine learning detectors based on static features. Through the results, we observe several findings: 1) Obfuscation has a significant impact on the effectiveness of detectors, causing an increase both in false negative rate (FNR) and false positive rate (FPR), and the bias of obfuscation in the training set induces detectors to detect obfuscation rather than malicious behaviors. 2) The common measures such as improving the quality of the training set by adding relevant obfuscated samples and leveraging state-of-the-art deep learning models can not work well.3) The root cause of obfuscation effects on these detectors is that feature spaces they use can only reflect shallow differences in code, not about the nature of benign and malicious, which can be easily affected by the differences brought by obfuscation. 4) Obfuscation has a similar effect on realistic detectors in VirusTotal, indicating that this is a common real-world problem. Kunlun Ren, Weizhong Qiang, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
ISSTA | 5 |
| 2023 | Precise and Efficient Patch Presence Test for Android Applications against Code ObfuscationabstractThird-party libraries (TPLs) are widely utilized by Android developers to implement new apps. Unfortunately, TPLs are often suffering from various vulnerabilities, which could be exploited by attackers to cause catastrophic consequences for app users. Therefore, testing whether a vulnerability has been patched in target apps is crucial. However, existing techniques are unable to effectively test patch presence for obfuscated apps while obfuscation is pervasive in practice. To address the new challenges introduced by code obfuscation, this study presents PHunter, which is a system that captures obfuscation-resilient semantic features of patch-related methods to identify the presence of the patch in target apps. Specifically, PHunter utilizes coarse-grained features to locate patch-related methods, and compares the fine-grained semantic similarity to determine whether the code has been patched. Extensive evaluations on 94 CVEs and 200 apps show that PHunter can outperform state-of-the-art tools, achieving an average accuracy of 97.1% with high efficiency and low false positive rates. Besides, PHunter is able to be resilient to different obfuscation strategies. More importantly, PHunter is useful in eliminating the false alarms generated by existing TPL detection tools. In particular, it can help reduce up to 25.2% of the false alarms with an accuracy of 95.3%. Zifan Xie, Ming Wen 0001, Haoxiang Jia, Xiaotong Huang, Deqing Zou, Hai Jin 0001 |
ISSTA | 6 |
| 2023 | Robin: A Novel Method to Produce Robust Interpreters for Deep Learning-Based Code ClassifiersabstractDeep learning has been widely used in source code classification tasks, such as code classification according to their functionalities, code authorship attribution, and vulnerability detection. Unfortunately, the black-box nature of deep learning makes it hard to interpret and understand why a classifier (i.e., classification model) makes a particular prediction on a given example. This lack of interpretability (or explainability) might have hindered their adoption by practitioners because it is not clear when they should or should not trust a classifier's prediction. The lack of interpretability has motivated a number of studies in recent years. However, existing methods are neither robust nor able to cope with out-of-distribution examples. In this paper, we propose a novel method to produce Robust interpreters for a given deep learning-based code classifier; the method is dubbed Robin. The key idea behind Robin is a novel hybrid structure combining an interpreter and two approximators, while leveraging the ideas of adversarial training and data augmentation. Experimental results show that on average the interpreter produced by Robin achieves a 6.11% higher fidelity (evaluated on the classifier), 67.22% higher fidelity (evaluated on the approximator), and 15.87x higher robustness than that of the three existing interpreters we evaluated. Moreover, the interpreter is 47.31% less affected by out-of-distribution examples than that of LEMNA. Zhen Li 0027, Ruqian Zhang, Deqing Zou, Ning Wang 0098, Shouhuai Xu, Chen Chen 0001, Hai Jin 0001 |
ASE | 3 |
| 2023 | Tritor: Detecting Semantic Code Clones by Building Social Network-Based Triads ModelabstractCode clone detection refers to finding the functional similarities between two code fragments, which is becoming increasingly important with the evolution of software engineering. It is reasonable because code cloning can increase maintenance costs and even cause the propagation of vulnerabilities, which can have a negative impact on software security. Numbers of code clone detection methods have been proposed, including tree-based methods that are capable of detecting semantic code clones. However, since tree structure is complex, these methods are difficult to apply to large-scale clone detection. In this paper, we propose a scalable semantic code clone detector based on semantically enhanced abstract syntax tree. Specifically, we add the control flow and data flow details into the original tree and regard the enhanced tree as a social network. Then we build a social network-based triads model to collect the similarity features between the two methods by analyzing different types of triads within the network. After obtaining all features, we use them to train a machine learning-based code clone detector (i.e., Tritor). Our comparative experimental results show that Tritor is superior to SourcererCC, RtvNN, Deckard, ASTNN, TBCNN, CDLH, and SCDetector, are equally good with DeepSim and FCCA. As for scalability, Tritor is about 39 times faster than another current state-of-the-art tree-based code clone detector ASTNN. Deqing Zou, Siyue Feng, Yueming Wu 0001, Wenqi Suo, Hai Jin 0001 |
ESEC/SIGSOFT FSE | 1 |
| 2023 | Network intrusion detection based on the temporal convolutional model
Ivandro Ortet Lopes, Deqing Zou, Ihsan H. Abdulqadder, Saeed Akbar, Zhen Li 0027, Francis A. Ruambo, Wagner Pereira |
Comput. Secur. | 2 |
| 2023 | The DAG blockchain: A secure edge assisted honeypot for attack detection and multi-controller based load balancing in SDN 5G
Ihsan H. Abdulqadder, Deqing Zou, Israa T. Aziz |
Future Gener. Comput. Syst. | 2 |
| 2023 | On the Security of Smart Home Systems: A Survey
Bin Yuan 0002, Jun Wan 0006, Deqing Zou, Hai Jin 0001 |
J. Comput. Sci. Technol. | 4 |
| 2023 | Does OpenBSD and Firefox's Security Improve With Time?abstractOzment and Schechter (USENIX Security’2006) analyzed the evolution of OpenBSD vulnerabilities over the span of 7 years (1998-2005) and concluded that its security increases with age. In this paper, we extend their study by analyzing the evolution of OpenBSD vulnerabilities over the span of 22 years (1998-2020) and Firefox vulnerabilities over the span of 9 years (2011-2020). Our empirical study leads to a number of insights, including the following: both OpenBSD and Firefox get more secure (i.e., less vulnerable) with time, but today’s developers do not necessarily produce more secure code; OpenBSD and Firefox developers tend to make similar security mistakes, but Firefox vulnerabilities are easier to exploit; finally, Firefox’s vulnerability density is almost one order of magnitude higher than OpenBSD’s, meaning Firefox is more vulnerable. Deqing Zou, Shouhuai Xu, Xianjun Deng, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | SmartPatch: Verifying the Authenticity of the Trigger-Event in the IoT PlatformabstractEmerging IoT clouds are playing a more important role in modern lives, enabling users/developers to program applications to make better use of smart devices. However, preliminary research has shown IoT cloud vulnerabilities could expose IoT users to security risks. To better understand the problem, we studied the SmartThings cloud, one of the most popular IoT cloud platforms that support user-defined device automation (SmartApps). Specifically, we found new vulnerabilities in SmartThings that allow attackers to fake events to trigger the SmartApps to operate devices (e.g., open a lock). Exploiting such vulnerabilities, we successfully faked 7 different types of events, which impact 138 (out of 187) SmartThings’ official open-sourced SmartApps. To defeat such attacks, we propose an authenticity-verification-based scheme to deny fake events. Moreover, we designed a tool,SmartPatch, to help users secure their SmartThings systems. In specific,SmartPatchautomatically patches the vulnerable SmartApps and Device Handlers (input) and outputs the flawless programs, which are ready for users to deploy in their SmartThings systems. We have madeSmartPatchpublicly available. With the help ofSmartPatch, we patched all the vulnerable SmartThings’ official open-sourced programs (146 SmartApps and 321 Device Handlers). Experiments have shown the compatibility, effectiveness, and efficiency of our proposed approach. Bin Yuan 0002, Maogen Yang, Luyi Xing, Xuchang Wang, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Code2Img: Tree-Based Image Transformation for Scalable Code Clone DetectionabstractCode clone detection is an active research domain of software engineering. There are two core demands for clone detection: scalable detection and complicated clone detection. For scalable detection, existing approaches treat the source code as a text or token sequence and then calculate their similarity. However, the text-based and token-based approaches are difficult to detect complicated clone types due to the lack of consideration of code structure. The methods based on intermediate representations of code can effectively achieve complex clone types detection but are limited by the complexity of representations to be scalable. In this paper, we proposeCode2Img, a tree-based code clone detector, which satisfies scalability while detecting complicated clones effectively. Given the source code, we first perform clone filtering by the inverted index to locate the suspected clones. For each suspected clone, we create the adjacency image based on the adjacency matrix of the normalized abstract syntax tree (AST). Then we design an image encoder to highlight the structural details further and refine pixels of the image. Specifically, we employ the Markov model to encode the adjacency image into a state probability image and remove its useless pixels. By this, the original complex tree can be transformed into a one-dimensional vector while preserving the structural feature of the AST. Finally, we detect clones by calculating the Jaccard Similarity of these vectors. We conduct comparative evaluations on effectiveness and scalability with eight other state-of-the-art clone detectors (SourcererCC,NIL,LVMapper,Nicad,Siamese,CCAligner,Deckard, andYang2018). The experimental results show thatCode2Imgachieves the best performance among all the comparative tools in terms of both detection effectiveness and scalability. It indicates thatCode2Imgcan be applicable to scalable complicated clone detection. Yilin Fang, Yaru Jia, Yueming Wu 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Software Eng. | 6 |
| 2022 | StateDiver: Testing Deep Packet Inspection Systems with State-Discrepancy GuidanceabstractDeep Packet Inspection (DPI) systems are essential for securing modern networks (e.g., blocking or logging abnormal network connections). However, DPI systems are known to be vulnerable in their implementations, which could be exploited for evasion attacks. Due to the critical role DPI systems play, many efforts have been made to detect vulnerabilities in the DPI systems through manual inspection, symbolic execution, and fuzzing, which suffer from either poor scalability, path explosion, or inappropriate feedback. In this paper, based on our observation that a DPI system usually reaches an abnormal internal state before a forbidden packet passes through it, we propose a fuzzing framework that prioritizes inputs/mutations which could trigger the DPI system’s abnormal internal states. Further, to avoid deep understanding of the DPI systems under inspection (e.g., to identify the abnormal states), we feed one pair of inputs to multiple DPI systems and check whether the state changes of these DPI systems are consistent — an inconsistent internal state change/transference in one of the DPI systems indicates a new abnormal state is reached in the corresponding DPI system. Naturally, inputs that trigger new abnormal states are preferentially selected for mutations to generate new inputs. Following this idea, we develop StateDiver, the first fuzzing framework that uses the state discrepancy between different DPI systems as feedback to find more bypassing strategies. We make StateDiver publicly available online. With the help of StateDiver, we tested 3 famous open-source DPI systems (Snort, Snort++, and Suricata) and discovered 16 bypass strategies (8 new and 8 previously known). We have reported all the vulnerabilities to the vendors and received one CVE by the time of paper writing. We also compared StateDiver with Geneva, the state-of-the-art fuzzing tool for detecting DPI bugs. Results showed that StateDiver outperformed Geneva at the number and speed of finding vulnerabilities, indicating the ability of StateDiver to detect strategies bypassing DPI systems effectively. Zhechang Zhang, Bin Yuan 0002, Kehan Yang, Deqing Zou, Hai Jin 0001 |
ACSAC | 4 |
| 2022 | VulCNN: An Image-inspired Scalable Vulnerability Detection SystemabstractSince deep learning (DL) can automatically learn features from source code, it has been widely used to detect source code vulnerability. To achieve scalable vulnerability scanning, some prior studies intend to process the source code directly by treating them as text. To achieve accurate vulnerability detection, other approaches consider distilling the program semantics into graph representations and using them to detect vulnerability. In practice, text-based techniques are scalable but not accurate due to the lack of program semantics. Graph-based methods are accurate but not scalable since graph analysis is typically time-consuming. Yueming Wu 0001, Deqing Zou, Shihan Dou, Wei Yang 0013, Hai Jin 0001 |
ICSE | 2 |
| 2022 | TreeCen: Building Tree Graph for Scalable Semantic Code Clone DetectionabstractCode clone detection is an important research problem that has attracted wide attention in software engineering. Many methods have been proposed for detecting code clone, among which text-based and token-based approaches are scalable but lack consideration of code semantics, thus resulting in the inability to detect semantic code clones. Methods based on intermediate representations of codes can solve the problem of semantic code clone detection. However, graph-based methods are not practicable due to code compilation, and existing tree-based approaches are limited by the scale of trees for scalable code clone detection. Deqing Zou, Junru Peng, Yueming Wu 0001, Junjie Shan, Hai Jin 0001 |
ASE | 2 |
| 2022 | Detecting Semantic Code Clones by Building AST-based Markov Chains ModelabstractCode clone detection aims to find functionally similar code fragments, which is becoming more and more important in the field of software engineering. Many code clone detection methods have been proposed, among which tree-based methods are able to handle semantic code clones. However, these methods are difficult to scale to big code due to the complexity of tree structures. In this paper, we design Amain, a scalable tree-based semantic code clone detector by building Markov chains models. Specifically, we propose a novel method to transform the original complex tree into simple Markov chains and measure the distance of all states in these chains. After obtaining all distance values, we feed them into a machine learning classifier to train a code clone detector. To examine the effectiveness of Amain, we evaluate it on two widely used datasets namely Google Code Jam and BigCloneBench. Experimental results show that Amain is superior to nine state-of-the-art code clone detection tools (i.e., SourcererCC, RtvNN, Deckard, ASTNN, TBCNN, CDLH, FCCA, DeepSim, and SCDetector). Yueming Wu 0001, Siyue Feng, Deqing Zou, Hai Jin 0001 |
ASE | 3 |
| 2022 | Robbery on DevOps: Understanding and Mitigating Illicit Cryptomining on Continuous Integration Service PlatformsabstractThe recent wave of in-browser cryptojacking has ebbed away, due to the new updates of mainstream cryptocurrrencies, which demand the level of mining resources browsers cannot afford. As replacements, resource-rich, loosely protected free Internet services, such as Continuous Integration (CI) platforms, have become attractive targets. In this paper, we report a systematic study on real-world illicit cryptomining on public CI platforms (called Cijacking). Unlike in-browser cryptojacking, Cijacks masquerade as CI jobs and are therefore more difficult to detect, since legitimate CI workflows such as container image building and testing also entail intensive computing. In our research, we leveraged the critical mining information the adversary has to specify, such as wallet addresses and mining pool domains, to recover the attack traces from GitHub repositories and the log files on CI platforms, leading to the discovery of 1,974 Cijacking instances, 30 campaigns across 12 different cryptocurrencies on 11 mainstream CI platforms. Further, our study unveils the evolution of attack strategies, in response to the protection put in place by the platforms, the duration of the mining jobs (as long as 33 months), and their lifecycle. Further discovered is the revenue of the attack, over ${\$}$20,000 per month. Since robust detection of cryptojacking is known to be hard, we developed a novel technique, called Cijitter, to strategically inject delays to the execution of a CI workflow to disproportionally penalize the mining jobs that need to work on a series of tasks under time constraints. Our analysis and evaluation, as conducted on both benchmarks and common CI jobs, show that our approach substantially suppresses the miner’s revenues, rendering them unprofitable, but only has small impacts on the performance of CI jobs and developer productivity (94.3% of CI jobs see a less than 10% delay). Zhi Li 0048, Weijie Liu 0004, XiaoFeng Wang 0001, Xiaojing Liao, Luyi Xing, Mingming Zha 0001, Hai Jin 0001, Deqing Zou |
SP | 9 |
| 2022 | SAND: semi-automated adaptive network defense via programmable rule generation and deployment
Haoyu Chen 0004, Deqing Zou, Hai Jin 0001, Shouhuai Xu, Bin Yuan 0002 |
Sci. China Inf. Sci. | 2 |
| 2022 | Effective network intrusion detection via representation learning: A Denoising AutoEncoder approach
Ivandro Ortet Lopes, Deqing Zou, Ihsan H. Abdulqadder, Francis A. Ruambo, Bin Yuan 0002, Hai Jin 0001 |
Comput. Commun. | 2 |
| 2022 | HAPPS: A Hidden Attribute and Privilege-Protection Data-Sharing Scheme With VerifiabilityabstractData is a key asset in our interconnected and smart city. Especially, in the context of healthcare, healthcare data can facilitate remote diagnosis and medical research. Because of the potentially sensitive nature of healthcare data, privacy is a key consideration for both individuals and organizations. We can broadly categorize privacy considerations into data privacy, attribute privacy, and privilege policy privacy. To support one or more notions of privacy, the potential of solutions, such as fine-grained access control [e.g., those based on attribute-based encryption (ABE)] and blockchain in realizing data sharing has been explored. However, these approaches generally only facilitate access control of data and the traceability of the sharing process, and do not protect the attribute and privilege policy privacy of users. Therefore, in this article, we implement HAPPS, a hidden attribute and privilege-protection data-sharing scheme with verifiability. The three key building blocks of HAPPS are zero-knowledge proof, blockchain, and distributed ABE (DABE). Specifically, in our approach, we propose a new data access control strategy (i.e., attribute-hidden zero-knowledge proof—at-ZKP) to hide user identity and attributes during the authorization process. Our scheme is embedded in the blockchain and built into the decentralized sharing platform to prevent central verifier counterfeiting and support auditing. To demonstrate utility, we prove that HAPPS ensures data, attribute, and privilege policy privacy. Findings of our evaluations implemented on Ethereum and using the data set from the healthcare cost and utilization project (HCUP), we demonstrate that our scheme can share sensitive healthcare records belonging to minors (e.g., children) without the at-ZKP incurring unrealistic cost. Weiqi Dai, Shuyue Tuo, Liangliang Yu, Kim-Kwang Raymond Choo, Deqing Zou, Hai Jin 0001 |
IEEE Internet Things J. | 5 |
| 2022 | SySeVR: A Framework for Using Deep Learning to Detect Software VulnerabilitiesabstractThe detection of software vulnerabilities (or vulnerabilities for short) is an important problem that has yet to be tackled, as manifested by the many vulnerabilities reported on a daily basis. This calls for machine learning methods for vulnerability detection. Deep learning is attractive for this purpose because it alleviates the requirement to manually define features. Despite the tremendous success of deep learning in other application domains, its applicability to vulnerability detection is not systematically understood. In order to fill this void, we propose thefirstsystematic framework for using deep learning to detect vulnerabilities in C/C++ programs with source code. The framework, dubbedSyntax-based,Semantics-based, andVectorRepresentations(SySeVR), focuses on obtaining program representations that can accommodate syntax and semantic information pertinent to vulnerabilities. Our experiments with four software products demonstrate the usefulness of the framework: we detect 15 vulnerabilities that are not reported in the National Vulnerability Database. Among these 15 vulnerabilities, seven are unknown and have been reported to the vendors, and the other eight have been “silently” patched by the vendors when releasing newer versions of the pertinent software products. Zhen Li 0027, Deqing Zou, Shouhuai Xu, Hai Jin 0001, Yawei Zhu, Zhaoxuan Chen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | VulDeeLocator: A Deep Learning-Based Fine-Grained Vulnerability DetectorabstractAutomatically detecting software vulnerabilities is an important problem that has attracted much attention from the academic research community. However, existing vulnerability detectors still cannot achieve the vulnerability detection capability and the locating precision that would warrant their adoption for real-world use. In this article, we present a vulnerability detector that can simultaneously achieve a high detection capability and a high locating precision, dubbedVulnerabilityDeep learning-basedLocator(VulDeeLocator). In the course of designing VulDeeLocator, we encounter difficulties including how to accommodate semantic relations between the definitions of types as well as macros and their uses across files, how to accommodate accurate control flows and variable define-use relations, and how to achieve high locating precision. We solve these difficulties by using two innovative ideas: (i) leveraging intermediate code to accommodate extra semantic information, and (ii) using the notion ofgranularity refinementto pin down locations of vulnerabilities. When applied to 200 files randomly selected from three real-world software products, VulDeeLocator detects 18 confirmed vulnerabilities (i.e., true-positives). Among them, 16 vulnerabilities correspond to known vulnerabilities; the other two are not reported in the National Vulnerability Database (NVD) but have been “silently” patched by the vendor of Libav when releasing newer versions. Zhen Li 0027, Deqing Zou, Shouhuai Xu, Zhaoxuan Chen, Yawei Zhu, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Differentially Private Tripartite Intelligent Matching Against Inference Attacks in Ride-Sharing ServicesabstractIn intelligent transportation systems, the key issue of the Ride-Sharing Service (RSS) is to find proper drivers for the passengers by Intelligent Matching (IM) of two or three objects, including the positions of drivers, the travel information of passengers, and the spots where passengers and drivers meet and separate. Unfortunately, the exposure of travel plans of passengers in the IM process due to inference attacks has raised concerns about the privacy violation. To resist the inference attacks, we propose a Differentially Private Tripartite IM (DPTIM) protocol for RSS. DPTIM is based on the tripartite IM process, which intelligently finds the suitable threshold to filter out the matched objects with satisfaction scores below the threshold, so as to provide the high average satisfaction score of matched passengers. Compared to existing relevant mechanisms, DPTIM is distinguished by the feature that it leverages the inference error and differential privacy techniques to prevent the prior-information-based inference attacks and constrain the posterior information leakage, while providing satisfactory matching results. Furthermore, DPTIM meets the personalized demand of location privacy by using the passenger-specific tolerance estimation on inference errors and the personalized privacy budget. Finally, we implement DPTIM on real-world datasets, and demonstrate the satisfactory performance of DPTIM in terms of the average satisfaction score of passengers, the anti-inference-attack capability, and the passenger-specific privacy requirement. Yuanyuan He 0002, Jianbing Ni, Laurence T. Yang, Wei Wei 0006, Xianjun Deng, Deqing Zou, Syed Hassan Ahmed |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2022 | Aroc: An Automatic Repair Framework for On-Chain Smart ContractsabstractOngoing smart contract attack events have seriously impeded the practical application of blockchain. Although lots of researches have been conducted, they mostly focus on off-chain vulnerability detection. However, smart contracts cannot be modified once they have been deployed on-chain, thus existing techniques cannot protect those deployed contracts from being attacked. To mitigate this problem, we propose a general smart contract repairer named Aroc, which can automatically patch vulnerable deployed contracts without changing the contract codes. The core insight of Aroc is to generate patch contracts to abort malicious transactions in advance. Taking the three most serious bug types (i.e., reentrancy, arithmetic bugs, and unchecked low-level checks) as examples, we present how Aroc automatically repairs them on-chain. We conduct abundant evaluations on four kinds of datasets to evaluate the effectiveness and efficiency of Aroc. In particular, Aroc can repair 95.95% of the vulnerable contracts with an average correctness ratio of 93.32%. Meanwhile, Aroc introduces acceptable additional overheads to smart contract users and blockchain miners. When compared with the state-of-the-art techniques, Aroc introduces either fewer execution overheads or contract codes. Hai Jin 0001, Zeli Wang, Ming Wen 0001, Weiqi Dai, Deqing Zou |
IEEE Trans. Software Eng. | 6 |
| 2022 | Double Attention Convolutional Neural Network for Sequential RecommendationabstractThe explosive growth of e-commerce and online service has led to the development of recommender system. Aiming to provide a list of items to meet a user’s personalized need by analyzing his/her interaction 1 history, recommender system has been widely studied in academic and industrial communities. Different from conventional recommender systems, sequential recommender systems attempt to capture the pattern of users’ sequential behaviors and the evolution of users’ preferences. Most of the existing sequential recommendation models only focus on user interaction sequence, but neglect item interaction sequence. An item interaction sequence also contains rich contextual information for capturing the item’s dynamic characteristic, since an item’s dynamic characteristic can be reflected by the users who interact with it in a period. Furthermore, existing dual sequential models use the same method to handle the user interaction sequence and item interaction sequence, and do not consider their different characteristics. Hence, we propose a novel D ouble A ttention C onvolution N eural N etwork (DACNN) , which incorporates user interaction sequence and item interaction sequence into an integrated neural network framework. DACNN leverages the strength of attention mechanism to capture the temporary suitability and adopts CNN to extract local sequential features. Experimental evaluations on the real datasets show that DACNN outperforms the baseline approaches. Qi Chen 0017, Guohui Li 0001, Quan Zhou 0003, Deqing Zou |
ACM Trans. Web | 5 |
| 2021 | Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsabstractAn IoT device today can be managed through different channels, e.g., by its device manufacturer's app, or third-party channels such as Apple's Home app, or a smart speaker. Supporting each channel is a management framework integrated in the device and provided by different parties. For example, a device that integrates Apple HomeKit framework can be managed by Apple Home app. We call the management framework of this kind, including all its device- and cloud-side components, a device management channel (DMC). 4 third-party DMCs are widely integrated in today's IoT devices along with the device manufacturer's own DMC: HomeKit, Zigbee/Z-Wave compatible DMC, and smart-speaker Seamless DMC. Each of these DMCs is a standalone system that has full mandate on the device; however, if their security policies and control are not aligned, consequences can be serious, allowing a malicious user to utilize one DMC to bypass the security control imposed by the device owner on another DMC. We call such a problem Chaotic Device Management (Codema). Yan Jia 0009, Bin Yuan 0002, Luyi Xing, Dongfang Zhao 0010, Yifan Zhang 0010, XiaoFeng Wang 0001, Yijing Liu 0007, Kaimin Zheng, Peyton Crnjak, Yuqing Zhang 0001, Deqing Zou, Hai Jin 0001 |
CCS | 11 |
| 2021 | HomDroid: detecting Android covert malware by social-network homophily analysisabstractAndroid has become the most popular mobile operating system. Correspondingly, an increasing number of Android malware has been developed and spread to steal users’ private information. There exists one type of malware whose benign behaviors are developed to camouflage malicious behaviors. The malicious component occupies a small part of the entire code of the application (app for short), and the malicious part is strongly coupled with the benign part. In this case, the malware may cause false negatives when malware detectors extract features from the entire apps to conduct classification because the malicious features of these apps may be hidden among benign features. Moreover, some previous work aims to divide the entire app into several parts to discover the malicious part. However, the premise of these methods to commence app partition is that the connections between the normal part and the malicious part are weak (repackaged malware). Yueming Wu 0001, Deqing Zou, Wei Yang 0013, Hai Jin 0001 |
ISSTA | 2 |
| 2021 | Automatically derived stateful network functions including non-field attributesabstractThe modern network consists of thousands of network devices from different suppliers that perform distinct code-pendent functions, such as routing, switching, modifying header fields, and access control across physical and virtual networks. Because of the network complexity, the network is prone to a wide range of errors, such as false-positive configuration, software errors, or unexpected interactions across protocols. These errors can lead to loops, sub-optimal routing, path leaks, black holes, and access control violations that make services unavailable, vulnerable to exploitation, or prone to attacks (e.g., DDoS attacks). To mitigate these problems, network operators deploy many different stateful network functions, like firewalls, NATs, load balancers, and intrusion-prevention boxes. They have become an important part of networks today, so it is critical to verify that these network functions are the same as expected deployments. All static network verification tools are meant to rigorously check network software or configuration for bugs before deployment. They usually use handwritten models or limited derivation models that are error-prone and ignore the fact that even the same type of network functions (from different vendors) still have different implementation details. In this paper, we propose a tool that can automatically synthesize more realistic and high-fidelity models that include stateful network functions with non-field attributes. We design an inferring algorithm, implement the transformation between data packages and symbolic packages, and obtain a finite state machine that can accurately express the actions of black-box network functions for a given configuration. Bin Yuan 0002, Shengyao Sun, Xianjun Deng, Deqing Zou, Haoyu Chen 0004, Shenghui Li, Hai Jin 0001 |
TrustCom | 4 |
| 2021 | Heterogeneous differential privacy for vertically partitioned databasesabstractSummary Existing privacy‐preserving approaches are generally designed to provide privacy guarantee for individual data in a database, which reduces the utility of the database for data analysis. In this paper, we propose a novel differential privacy mechanism to preserve the heterogeneous privacy of a vertically partitioned database based on attributes. We first present the concept of privacy label, which characterizes the privacy information of the database and is instantiated by the classification. Then, we use an information‐based method to systematically explore the dependencies between all attributes and the privacy label. We finally assign privacy weights to every attribute and design a heterogeneous mechanism according to the basic Laplace mechanism. Evaluations using real datasets demonstrate that the proposed mechanism achieves a balanced privacy and utility. Tianqing Zhu, Xiaofeng Ding 0001, Hai Jin 0001, Deqing Zou |
Concurr. Comput. Pract. Exp. | 5 |
| 2021 | Ethereum smart contract security research: survey and future research opportunities
Zeli Wang, Hai Jin 0001, Weiqi Dai, Kim-Kwang Raymond Choo, Deqing Zou |
Frontiers Comput. Sci. | 5 |
| 2021 | Trustzone-based secure lightweight wallet for hyperledger fabric
Weiqi Dai, Qinyuan Wang, Zeli Wang, Xiaobin Lin, Deqing Zou, Hai Jin 0001 |
J. Parallel Distributed Comput. | 5 |
| 2021 | CloudCFI: Context-Sensitive and Incremental CFI in the Cloud EnvironmentabstractControl-Flow Integrity(CFI) is one of the most promising techniques against control-flow hijacking attacks. ForCommercial Off-the-Shelf(COTS) binaries, a number of solutions provide coarse-grained CFI and thus are context-insensitive, while having the benefit of introducing a low runtime overhead. However, they can hardly defend against elaborately designed attacks due to the inaccuracy of theControl-Flow Graphs(CFGs). This paper presentsCloudCFI, a context-sensitive and incremental CFI, which specifically makes full use of the characteristic of the cloud environment, where multiple instances of a software run on multiple virtual machines, and the control flow checking result from one software instance could be utilized to handle the control-hijacking occurred on other sibling instances. InCloudCFI, the accuracy of the control flow checking can be continuously increased to offer the incremental CFI, and a context-sensitive CFI policy is enforced to determine the validity of the control flow of the execution path through checking the entire execution path instead of the single edge or partial edges in the execution path.CloudCFIincludes the static phase and the runtime phase respectively. Control-flow information and basic-block information is collected through emulation execution in the static phase, and the execution paths are tracked in runtime phase to collect process-tracking information. Next, it recovers the execution path by using basic-block information and process-tracking information, and checks the validity of the control flow by using the control-flow information. A prototype system is implemented and evaluated from several aspects using RIPE and SPEC benchmarks, as well as real-world cloud applications, Memcached and Redis. The evaluation results show thatCloudCFIcan defend against most common control-flow hijacking attacks. Meanwhile, it only introduces a low runtime performance overhead. Weizhong Qiang, Yingda Huang, Hai Jin 0001, Laurence T. Yang, Deqing Zou |
IEEE Trans. Cloud Comput. | 5 |
| 2021 | DSEOM: A Framework for Dynamic Security Evaluation and Optimization of MTD in Container-Based CloudabstractDue to the lightweight features, the combination of container technology and microservice architecture makes container-based cloud environment more efficient and agile than VM-based cloud environment. However, it also greatly amplifies the dynamism and complexity of the cloud environment and increases the uncertainty of security issues in the system concurrently. In this case, the effectiveness of defense mechanisms with fixed strategies would fluctuate as the updates occur in cloud environment. We refer this problem as effectiveness drift problem of defense mechanisms, which is particularly acute in the proactive defense mechanisms, such as moving target defense (MTD). To tackle this problem, we present DSEOM, a framework that can automatically perceive updates of container-based cloud environment, rapidly evaluate the effectiveness change of MTD and dynamically optimize MTD strategies. Specifically, we establish a multi-dimensional attack graphs model to formalize various complex attack scenarios. Combining with this model, we introduce the concept of betweenness centrality to effectively evaluate and optimize the implementation strategies of MTD. In addition, we present a series of security and performance metrics to quantify the effectiveness of MTD strategies in DSEOM. And we conduct extensive experiments to illustrate the existence of the effectiveness drift problem and demonstrate the usability and scalability of DSEOM. Hai Jin 0001, Zhi Li 0048, Deqing Zou, Bin Yuan 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | $\mu$μVulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability DetectionabstractFine-grained software vulnerability detection is an important and challenging problem. Ideally, a detection system (or detector) not only should be able to detect whether or not a program contains vulnerabilities, but also should be able to pinpoint the type of a vulnerability in question. Existing vulnerability detection methods based on deep learning can detect the presence of vulnerabilities (i.e., addressing the binary classification or detection problem), but cannot pinpoint types of vulnerabilities (i.e., incapable of addressing multiclass classification). In this paper, we propose the first deep learning-based system for multiclass vulnerability detection, dubbed μ VulDeePecker. The key insight underlying μ VulDeePecker is the concept of code attention, which can capture information that can help pinpoint types of vulnerabilities, even when the samples are small. For this purpose, we create a dataset from scratch and use it to evaluate the effectiveness of μ VulDeePecker. Experimental results show that μ VulDeePecker is effective for multiclass vulnerability detection and that accommodating control-dependence (other than data-dependence) can lead to higher detection capabilities. Deqing Zou, Sujuan Wang, Shouhuai Xu, Zhen Li 0027, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | CRSA: A Cryptocurrency Recovery Scheme Based on Hidden Assistance RelationshipsabstractAs cryptocurrency and blockchain-related assets become more common in our digital society, there is a corresponding need to secure our digital assets, including the private keys used to secure access to such assets (e.g., due to loss or corruption of the data storage medium). However, there are limitations in existing blockchain-related asset management and recovery methods. Therefore, we use zero-knowledge proof to design a cryptocurrency recovery scheme based on hidden assisting relationships (hereafter referred to as the CRSA scheme) to facilitate the recovery of blockchain assets. Specifically, when the user's private key is lost, and access to the assets cannot be obtained, the user leverages information such as the pre-defined list of assistants to authenticate himself/herself on the blockchain. Once the assistants have confirmed the legitimacy of the user's authentication request, the asset will be transferred from the old address to the new address. During the (identity) proof process, the zero-knowledge proof is used to ensure that the identification of assistants is not leaked to other nodes, assistants, and the adversary. We provide the formal definition of the above scheme and the security proof of the construction. We also implement a prototype of the system and evaluate its performance. Evaluations indicate that the time required for the zero-knowledge proof is less than 10s, and the block verification time is less than 100ms. Weiqi Dai, Kim-Kwang Raymond Choo, Zhongze Liu, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Detecting Malicious Switches for a Secure Software-defined Tactile InternetabstractThe rapid development of the Internet of Things has led to demand for high-speed data transformation. Serving this purpose is the Tactile Internet, which facilitates data transfer in extra-low latency. In particular, a Tactile Internet based on software-defined networking (SDN) has been broadly deployed because of the proven benefits of SDN in flexible and programmable network management. However, the vulnerabilities of SDN also threaten the security of the Tactile Internet. Specifically, an SDN controller relies on the network status (provided by the underlying switches) to make network decisions, e.g., calculating a routing path to deliver data in the Tactile Internet. Hence, the attackers can compromise the switches to jeopardize the SDN and further attack Tactile Internet systems. For example, an attacker can compromise switches to launch distributed denial-of-service attacks to overwhelm the SDN controller, which will disrupt all the applications in the Tactile Internet. In pursuit of a more secure Tactile Internet, the problem of abnormal SDN switches in the Tactile Internet is analyzed in this article, including the cause of abnormal switches and their influences on different network layers. Then we propose an approach that leverages the messages sent by all switches to identify abnormal switches, which adopts a linear structure to store historical messages at a relatively low cost. By mapping each flow message to the flow establishment model, our method can effectively identify malicious SDN switches in the Tactile Internet and thus enhance its security. Bin Yuan 0002, Chen Lin 0006, Deqing Zou, Laurence T. Yang, Hai Jin 0001 |
ACM Trans. Internet Techn. | 3 |
| 2021 | IntDroid: Android Malware Detection Based on API Intimacy AnalysisabstractAndroid, the most popular mobile operating system, has attracted millions of users around the world. Meanwhile, the number of new Android malware instances has grown exponentially in recent years. On the one hand, existing Android malware detection systems have shown that distilling the program semantics into a graph representation and detecting malicious programs by conducting graph matching are able to achieve high accuracy on detecting Android malware. However, these traditional graph-based approaches always perform expensive program analysis and suffer from low scalability on malware detection. On the other hand, because of the high scalability of social network analysis, it has been applied to complete large-scale malware detection. However, the social-network-analysis-based method only considers simple semantic information (i.e., centrality) for achieving market-wide mobile malware scanning, which may limit the detection effectiveness when benign apps show some similar behaviors as malware. In this article, we aim to combine the high accuracy of traditional graph-based method with the high scalability of social-network-analysis--based method for Android malware detection. Instead of using traditional heavyweight static analysis, we treat function call graphs of apps as complex social networks and apply social-network--based centrality analysis to unearth the central nodes within call graphs. After obtaining the central nodes, the average intimacies between sensitive API calls and central nodes are computed to represent the semantic features of the graphs. We implement our approach in a tool called IntDroid and evaluate it on a dataset of 3,988 benign samples and 4,265 malicious samples. Experimental results show that IntDroid is capable of detecting Android malware with an F-measure of 97.1% while maintaining a True-positive Rate of 99.1%. Although the scalability is not as fast as a social-network-analysis--based method (i.e., MalScan ), compared to a traditional graph-based method, IntDroid is more than six times faster than MaMaDroid . Moreover, in a corpus of apps collected from GooglePlay market, IntDroid is able to identify 28 zero-day malware that can evade detection of existing tools, one of which has been downloaded and installed by more than ten million users. This app has also been flagged as malware by six anti-virus scanners in VirusTotal, one of which is Symantec Mobile Insight . Deqing Zou, Yueming Wu 0001, Siru Yang, Anki Chauhan, Wei Yang 0013, Jiangying Zhong, Shihan Dou, Hai Jin 0001 |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2021 | Interpreting Deep Learning-based Vulnerability Detector Predictions Based on Heuristic SearchingabstractDetecting software vulnerabilities is an important problem and a recent development in tackling the problem is the use of deep learning models to detect software vulnerabilities. While effective, it is hard to explain why a deep learning model predicts a piece of code as vulnerable or not because of the black-box nature of deep learning models. Indeed, the interpretability of deep learning models is a daunting open problem. In this article, we make a significant step toward tackling the interpretability of deep learning model in vulnerability detection. Specifically, we introduce a high-fidelity explanation framework, which aims to identify a small number of tokens that make significant contributions to a detector’s prediction with respect to an example. Systematic experiments show that the framework indeed has a higher fidelity than existing methods, especially when features are not independent of each other (which often occurs in the real world). In particular, the framework can produce some vulnerability rules that can be understood by domain experts for accepting a detector’s outputs (i.e., true positives) or rejecting a detector’s outputs (i.e., false-positives and false-negatives). We also discuss limitations of the present study, which indicate interesting open problems for future research. Deqing Zou, Yawei Zhu, Shouhuai Xu, Zhen Li 0027, Hai Jin 0001, Hengkai Ye |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2020 | Klotski: Efficient Obfuscated Execution against Controlled-Channel AttacksabstractIntel Software Guard eXtensions (SGX) provides a hardware-based trusted execution environment for security-sensitive computations. A program running inside the trusted domain (an enclave) is protected against direct attacks from other software, including privileged software like the operating system (OS), the hypervisor, and low-level firmwares. However, recent research has shown that the SGX is vulnerable to a set of side-channel attacks that allow attackers to compromise the confidentiality of an enclave's execution, such as the controlled-channel attack. Unfortunately, existing defenses either provide an incomplete protection or impose too much performance overhead. In this work, we propose Klotski, an efficient obfuscated execution technique to defeat the controlled-channel attacks with a tunable trade-off between security and performance. From a high level, Klotski emulates a secure memory subsystem. It leverages an enhanced ORAM protocol to load code and data into two software caches with configurable size, which are re-randomized for after a configurable interval. More importantly, Klotski employs several optimizations to reduce the performance overhead caused by software-based address translation and software cache replacement. Evaluation results show that Klotski is secure against controlled-channel attacks and its performance overhead much lower than previous solutions. Chengyu Song, Heng Yin 0001, Deqing Zou, Elaine Shi, Hai Jin 0001 |
ASPLOS | 4 |
| 2020 | BED: A Block-Level Deduplication-Based Container Deployment Framework
Shiqiang Zhang, Song Wu 0001, Hao Fan 0006, Deqing Zou, Hai Jin 0001 |
GPC | 4 |
| 2020 | Automated Patch Correctness Assessment: How Far are We?abstractTest-based automated program repair (APR) has attracted huge attention from both industry and academia. Despite the significant progress made in recent studies, the overfitting problem (i.e., the generated patch is plausible but overfitting) is still a major and long-standing challenge. Therefore, plenty of techniques have been proposed to assess the correctness of patches either in the patch generation phase or in the evaluation of APR techniques. However, the effectiveness of existing techniques has not been systematically compared and little is known to their advantages and disadvantages. To fill this gap, we performed a large-scale empirical study in this paper. Specifically, we systematically investigated the effectiveness of existing automated patch correctness assessment techniques, including both static and dynamic ones, based on 902 patches automatically generated by 21 APR tools from 4 different categories. Our empirical study revealed the following major findings: (1) static code features with respect to patch syntax and semantics are generally effective in differentiating overfitting patches over correct ones; (2) dynamic techniques can generally achieve high precision while heuristics based on static code features are more effective towards recall; (3) existing techniques are more effective towards certain projects and types of APR techniques while less effective to the others; (4) existing techniques are highly complementary to each other. For instance, a single technique can only detect at most 53.5% of the overfitting patches while 93.3% of them can be detected by at least one technique when the oracle information is available. Based on our findings, we designed an integration strategy to first integrate static code features via learning, and then combine with others by the majority voting strategy. Our experiments show that the strategy can enhance the performance of existing patch correctness assessment techniques significantly. Shangwen Wang, Ming Wen 0001, Bo Lin 0011, Yihao Qin, Deqing Zou, Xiaoguang Mao, Hai Jin 0001 |
ASE | 6 |
| 2020 | SCDetector: Software Functional Clone Detection Based on Semantic Tokens AnalysisabstractCode clone detection is to find out code fragments with similar functionalities, which has been more and more important in software engineering. Many approaches have been proposed to detect code clones, in which token-based methods are the most scalable but cannot handle semantic clones because of the lack of consideration of program semantics. To address the issue, researchers conduct program analysis to distill the program semantics into a graph representation and detect clones by matching the graphs. However, such approaches suffer from low scalability since graph matching is typically time-consuming. Yueming Wu 0001, Deqing Zou, Shihan Dou, Siru Yang, Wei Yang 0013, Hai Jin 0001 |
ASE | 2 |
| 2020 | Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access Delegation
Bin Yuan 0002, Yan Jia 0009, Luyi Xing, Dongfang Zhao 0010, XiaoFeng Wang 0001, Deqing Zou, Hai Jin 0001, Yuqing Zhang 0001 |
USENIX Security Symposium | 6 |
| 2020 | Multi-layered intrusion detection and prevention in the SDN/NFV enabled cloud of 5G networks using AI-based defense mechanisms
Ihsan H. Abdulqadder, Shijie Zhou 0002, Deqing Zou, Israa T. Aziz, Syed Muhammad Abrar Akber |
Comput. Networks | 3 |
| 2020 | Static detection of real-world buffer overflow induced by loop
Deqing Zou, Yajuan Du, Hai Jin 0001, Changming Liu, Jinan Shen |
Comput. Secur. | 2 |
| 2020 | HostWatcher: Protecting hosts in cloud data centers through software-defined networking
Bin Yuan 0002, Deqing Zou, Hai Jin 0001, Shui Yu 0001, Laurence T. Yang |
Future Gener. Comput. Syst. | 2 |
| 2020 | Secure Data Transportation With Software-Defined Networking and k-n Secret Sharing for High-Confidence IoT ServicesabstractInternet of Things (IoT) has become a critical infrastructure in smart city services. Unlike traditional network nodes, most of the current IoT devices are constrained with limited capabilities. Moreover, frequent changes in the network status (e.g., nodes turns into the sleep mode to save battery) make it even more difficult to set up a stable, secure transmission among smart city IoT devices. On the one hand, these weaknesses make the IoT more vulnerable to attacks, such as data eavesdropping, which can monitor, tamper, and obtain the transporting data. On the other hand, the high-confidence smart city service strongly relies on the security of data transporting among the IoT devices, e.g., data being tempered would reduce the reliability of smart city services and data being monitored or stolen would infringe the privacy of smart city services. Toward high-confidence smart city IoT services, we proposed an approach to secure the data transportation among the smart city IoT devices, which combines a k-n secret-sharing mechanism and software-defined networking (SDN) technique to securely transport IoT data. Specifically, the data are transported by multiple routes calculated by the SDN controller adaptively. Data safety is guaranteed by the all-or-nothing feature of the k-n secret-sharing mechanism. Two SDN-based transmission strategies, which leverage the SDN's advantages on network management, and scheduling, are applied to overcome the challenges of the unstable network state in IoT. Extensive experiments conducted from many aspects show that the proposed approach can remarkably reduce the attack success rate with reasonable and acceptable overhead. Bin Yuan 0002, Chen Lin 0006, Deqing Zou, Laurence T. Yang, Hai Jin 0001, Chunming Rong |
IEEE Internet Things J. | 4 |
| 2020 | FSFC: An input filter-based secure framework for smart contract
Zeli Wang, Weiqi Dai, Kim-Kwang Raymond Choo, Hai Jin 0001, Deqing Zou |
J. Netw. Comput. Appl. | 5 |
| 2020 | SDTE: A Secure Blockchain-Based Data Trading EcosystemabstractData, a key asset in our data-driven economy, has fueled the emergence of a new data trading industry. However, there are a number of limitations in conventional data trading platforms due to the existence of dishonest buyer/data broker. To mitigate these limitations, we posit the importance of a data processing-as-a-service model, which complements the conventional data hosting/exchange-as-a-service model. Specifically, in this paper, we introduce a secure data trading ecosystem and present a new blockchain-based data trading ecosystem (hereafter referred to as SDTE). In the ecosystem, both data broker and buyer are not able to obtain access to the seller's raw data, as they are only getting access to the analysis findings that they require. In other words, we reduce the challenge of securing the dataset to the challenge to secure the data processing. We also build a security model to analyze the data trading market and describe a new set of trading protocols for the entire data trading market. To demonstrate utility, we implement our proposed secure data trading platform (SDTP) on Ethereum & Intel's Software Guard Extensions (SGX) and perform an in-depth analysis. Weiqi Dai, Chunkai Dai, Kim-Kwang Raymond Choo, Changze Cui, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Exploring New Opportunities to Defeat Low-Rate DDoS Attack in Container-Based Cloud EnvironmentabstractDDoS attacks are rampant in cloud environments and continually evolve into more sophisticated and intelligent modalities, such as low-rate DDoS attacks. But meanwhile, the cloud environment is also developing in constant. Now container technology and microservice architecture are widely applied in cloud environment and compose container-based cloud environment. Comparing with traditional cloud environments, the container-based cloud environment is more lightweight in virtualization and more flexible in scaling service. Naturally, a question that arises is whether these new features of container-based cloud environment will bring new possibilities to defeat DDoS attacks. In this paper, we establish a mathematical model based on queueing theory to analyze the strengths and weaknesses of the container-based cloud environment in defeating low-rate DDoS attack. Based on this, we propose a dynamic DDoS mitigation strategy, which can dynamically regulate the number of container instances serving for different users and coordinate the resource allocation for these instances to maximize the quality of service. And extensive simulations and testbed-based experiments demonstrate our strategy can make the limited system resources be utilized sufficiently to maintain the quality of service acceptable and defeat DDoS attack effectively in the container-based cloud environment. Zhi Li 0048, Hai Jin 0001, Deqing Zou, Bin Yuan 0002 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2019 | AutoCVSS: An Approach for Automatic Assessment of Vulnerability Severity Based on Attack Process
Deqing Zou, Ju Yang, Zhen Li 0027, Hai Jin 0001, Xiaojing Ma 0002 |
GPC | 1 |
| 2019 | MalScan: Fast Market-Wide Mobile Malware Scanning by Social-Network Centrality AnalysisabstractMalware scanning of an app market is expected to be scalable and effective. However, existing approaches use either syntax-based features which can be evaded by transformation attacks or semantic-based features which are usually extracted by performing expensive program analysis. Therefor, in this paper, we propose a lightweight graph-based approach to perform Android malware detection. Instead of traditional heavyweight static analysis, we treat function call graphs of apps as social networks and perform social-network-based centrality analysis to represent the semantic features of the graphs. Our key insight is that centrality provides a succinct and fault-tolerant representation of graph semantics, especially for graphs with certain amount of inaccurate information (e.g., inaccurate call graphs). We implement a prototype system, MalScan, and evaluate it on datasets of 15,285 benign samples and 15,430 malicious samples. Experimental results show that MalScan is capable of detecting Android malware with up to 98% accuracy under one second which is more than 100 times faster than two state-of-the-art approaches, namely MaMaDroid and Drebin. We also demonstrate the feasibility of MalScan on market-wide malware scanning by performing a statistical study on over 3 million apps. Finally, in a corpus of dataset collected from Google-Play app market, MalScan is able to identify 18 zero-day malware including malware samples that can evade detection of existing tools. Yueming Wu 0001, Xiaodi Li 0002, Deqing Zou, Wei Yang 0013, Hai Jin 0001 |
ASE | 3 |
| 2019 | A Multigranularity Forensics and Analysis Method on Privacy Leakage in Cloud EnvironmentabstractThe problem of cloud forensics aims at processing multidimensional, massive, and heterogeneous data to collect and recover evidence in cloud environment. Existing approaches focus on excavating all suspicious behaviors from data and ignore privacy leakage details and behavioral characteristics. In order to conduct privacy leakage analysis in cloud specifically, we propose a multigranularity privacy leakage forensics method to analyze privacy violations caused by malware in cloud environment. By simulating the target virtual machine environment, our method can detect privacy leakage behaviors of malware without touching user's privacy data. We combine continuous RAM mirroring technology and dynamic taint analysis to assist the forensics investigation. To demonstrate the efficacy and utility of our method, we evaluate its performance with some real-world malware samples by comparing with some state-of-the-art malware analysis systems. Experimental results indicate that our method can identify more privacy leakage paths and behaviors. Deqing Zou, Jian Zhao 0012, Yueming Wu 0001, Weizhong Qiang, Hai Jin 0001 |
IEEE Internet Things J. | 1 |
| 2019 | A Secure High-Order Lanczos-Based Orthogonal Tensor SVD for Big Data Reduction in Cloud EnvironmentabstractSingular value decomposition (SVD) has been applied to cyber security and cyber forensics since it can reduce data. However, SVD is hard to reduce high-order big data because it is designed for only matrix data initially. Reducing high-order big data is desired for cyber security applications, and is a very challenging issue. In this paper, we propose a novel orthogonal tensor SVD method using big data techniques for high-order big data (naturally represented as tensors) reduction, which can be extensively used in big data applications of cyber security and cyber forensics. More specifically, we first present a high-order lanczos-based orthogonal tensor SVD algorithm to reduce high-order data. Then, for utilizing the incomparable benefits of cloud, we develop a secure orthogonal tensor SVD method to outsource the computation task of the orthogonal tensor SVD algorithm to cloud. The secure orthogonal tensor SVD method can protect data security from untrusted cloud by applying garbled circuits to the orthogonal tensor SVD algorithm. This is, to our best knowledge, the first work to address high-order big data reduction by employing cloud computing. Finally, we analyze the security and efficiency of our proposed orthogonal tensor SVD on synthetic dataset and real network intrusion detection dataset, and the results demonstrate that our proposed method is very promising for big data reduction. Jun Feng 0007, Laurence T. Yang, Guohui Dai, Wei Wang 0088, Deqing Zou |
IEEE Trans. Big Data | 5 |
| 2019 | A domain-divided configurable security model for cloud computing-based telecommunication services
Jinan Shen, Deqing Zou, Hai Jin 0001, Bin Yuan 0002, Weiqi Dai |
J. Supercomput. | 2 |
| 2019 | Defending Against Flow Table Overloading Attack in Software-Defined NetworksabstractThe Software-Defined Network (SDN) is a new and promising network architecture. At the same time, SDN will surely become a new target of cyber attackers. In this paper, we point out one critical vulnerability in SDNs, the size of flow table, which is most likely to be attacked. Due to the expensive and power-hungry features of Ternary Content Addressable Memory (TCAM), a flow table usually has a limited size, which can be easily disabled by a flow table overloading attack (a transformed DDoS attack). To provide a security service in SDN, we proposed a QoS-aware mitigation strategy, namely, peer support strategy, which integrates the available idle flow table resource of the whole SDN system to mitigate such an attack on a single switch of the system. We established a practical mathematical model to represent the studied system, and conducted a thorough analysis for the system in various circumstances. Based on our analysis, we found that the proposed strategy can effectively defeat the flow table overloading attacks. Extensive simulations and testbed-based experiments solidly support our claims. Moreover, our work also shed light on the implementation of SDN networks against possible brute-force attacks. Bin Yuan 0002, Deqing Zou, Shui Yu 0001, Hai Jin 0001, Weizhong Qiang, Jinan Shen |
IEEE Trans. Serv. Comput. | 2 |
| 2018 | Automatically Identifying Security Bug Reports via Multitype Features Analysis
Deqing Zou, Zhijun Deng, Zhen Li 0027, Hai Jin 0001 |
ACISP | 1 |
| 2018 | A Heuristic Framework to Detect Concurrency VulnerabilitiesabstractWith a growing demand of concurrent software to exploit multi-core hardware capability, concurrency vulnerabilities have become an inevitable threat to the security of today's IT industry. Existing concurrent program detection schemes focus mainly on detecting concurrency errors such as data races, atomicity violation, etc., with little attention paid to detect concurrency vulnerabilities that may be exploited to infringe security. In this paper, we propose a heuristic framework that combines both static analysis and fuzz testing to detect targeted concurrency vulnerabilities such as concurrency buffer overflow, double free, and use-after-free. The static analysis locates sensitive concurrent operations in a concurrent program, categorizes each finding into a potential type of concurrency vulnerability, and determines the execution order of the sensitive operations in each finding that would trigger the suspected concurrency vulnerability. The results are then plugged into the fuzzer with the execution order fixed by the static analysis in order to trigger the suspected concurrency vulnerabilities. Changming Liu, Deqing Zou, Bin B. Zhu, Hai Jin 0001 |
ACSAC | 2 |
| 2018 | Enhanced Attack Aware Security Provisioning Scheme in SDN/NFV Enabled over 5G NetworkabstractSoftware Defined Network (SDN) and Network Function Virtualization (NFV) are essential technologies that support next generation 5G networks. Security provisioning in 5G network is major issue due to involvement of numerous users. To provide security against major attacks in SDN and NFV enabled 5G network, in this paper an enhanced attack aware security provisioning scheme is proposed. In this work, security is provided by following process: (i) Initial Authentication process, (ii) Classification of packets, and (iii) Switch migration process. Initial authentication is performed at Access Point (AP) for each user by Secure ID based Authentication (SIA) scheme. The suspected packets are detected in controller and classified at Virtual Network Function (VNF). For packet classification, the optimal packet features are selected using Genetic Algorithm with Correlation (GAC) based feature selection algorithm. We have proposed a Radial Basis Function with Extreme Learning Machine (RBF-ELM) classifier. Then, the malicious packets are dropped at VNF and normal packets are redirected to destination address through controller. To mitigate flow table overloading attack, we have presented an Enhanced Artificial Bee Colony (EABC) algorithm in controller. Experimental result shows that our proposed security provisioning scheme shows better performance in terms of delay, amount of redirected packets, detection accuracy, packet transmission rate and packet loss ratio. Ihsan H. Abdulqadder, Deqing Zou, Israa T. Aziz, Bin Yuan 0002 |
ICCCN | 2 |
| 2018 | VulDeePecker: A Deep Learning-Based System for Vulnerability Detection
Zhen Li 0027, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin 0001, Sujuan Wang, Zhijun Deng, Yuyi Zhong |
NDSS | 2 |
| 2018 | TNGuard: Securing IoT Oriented Tenant Networks Based on SDNabstractIn the paradigm of infrastructure-as-a-service cloud computing involving an Internet of Things network, customers outsource their infrastructure to the cloud. An outsourced infrastructure is a virtual infrastructure that mimics the physical infrastructure of the precloud era; it is therefore referred to as a tenant network (TN) in this paper. This practice draws upon the notion of TN abstraction, which specifies how TNs should be managed. However, current virtual software-defined network (SDN) technology uses an SDN hypervisor to attain TNs, where the cloud administrator is given much-more-than-necessary privileges; thus, not only could violation of the security principle of least privilege occur, but the threat of a malicious or innocent-but-compromised administrator may be present. Motivated by this need, we propose the specification of TN abstraction, including its functions and security requirements. Then, we present a platform-independent concretization of this abstraction called TNGuard, which is an SDN-based architecture that protects the TNs while removing unnecessary privileges from the cloud administrator. In order to show that TNGuard concretizes the TN abstraction, we present an instantiation of TNGuard on the Xen virtualization platform with the Ryu controller. Experimental results show that the resulting system is practical, incurring a small performance overhead. Weiqi Dai, Weizhong Qiang, Laurence T. Yang, Deqing Zou, Hai Jin 0001, Shouhuai Xu, Zirong Huang |
IEEE Internet Things J. | 5 |
| 2018 | Validating User Flows to Protect Software Defined Network EnvironmentsabstractSoftware Defined Network is a promising network paradigm which has led to several security threats in SDN applications that involve user flows, switches, and controllers in the network. Threats as spoofing, tampering, information disclosure, Denial of Service, flow table overloading, and so on have been addressed by many researchers. In this paper, we present novel SDN design to solve three security threats: flow table overloading is solved by constructing a star topology-based architecture, unsupervised hashing method mitigates link spoofing attack, and fuzzy classifier combined with L1-ELM running on a neural network for isolating anomaly packets from normal packets. For effective flow migration Discrete-Time Finite-State Markov Chain model is applied. Extensive simulations using OMNeT++ demonstrate the performance of our proposed approach, which is better at preserving holding time than are other state-of-the-art works from the literature. Ihsan H. Abdulqadder, Deqing Zou, Israa T. Aziz, Bin Yuan 0002 |
Secur. Commun. Networks | 2 |
| 2018 | DigHR: precise dynamic detection of hidden races with weak causal relation analysis
Deqing Zou, Hai Jin 0001, Yajuan Du, Long Zheng 0003, Jinan Shen |
J. Supercomput. | 2 |
| 2018 | A Practical Byzantine-Based Approach for Faulty Switch Tolerance in Software-Defined NetworksabstractOver the past few years, software-defined networking (SDN) has stimulated worldwide interests in both academia and industry for its proven benefits. However, the reliability of SDN has become a significant barrier in adopting it. Many efforts have been made to enhance the reliability of SDNs. However, the research all assume a benign data plane, and overlook the fundamental question: what if the switches provide tainted network state information (controller's inputs) to the controller? To obtain a global view and produce networking decisions, SDN controllers must collect detailed and up-to-date network state information from the switches. Therefore, tainted inputs can easily disrupt the correctness of controller and reduce the reliability of SDN. In this paper, we argue that faulty switches can easily taint the controller's inputs in SDN, which would further mislead the controller. We investigate possible consequences of the existence of faulty switches with thorough analyses and practical examples. Aiming at enhancing the reliability of SDNs, we design and implement a prototype system that leverages Byzantine model to automatically tolerate faulty switches. Extensive experiments show that the proposed system can guarantee the correctness of the controller's inputs (specifically, flow statistics information) even when faulty switches exist with trivial overheads. Bin Yuan 0002, Hai Jin 0001, Deqing Zou, Laurence T. Yang, Shui Yu 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2017 | Fully Context-Sensitive CFI for COTS Binaries
Weizhong Qiang, Yingda Huang, Deqing Zou, Hai Jin 0001, Shizhen Wang, Guozhong Sun |
ACISP (2) | 3 |
| 2017 | Reducing LDPC Soft Sensing Latency by Lightweight Data Refresh for Flash Read Performance ImprovementabstractIn order to relieve reliability problem caused by technology scaling, LDPC codes have been widely applied in flash memories to provide high error correction capability. However, LDPC read performance slowdown along with data retention largely weakens the access speed advantage of flash memories. This paper considers to apply the concept of refresh, that were used for flash lifetime improvement, to optimize flash read performance. Exploiting data read characteristics, this paper proposes LDR, a lightweight data refresh method, that aggressively corrects errors in read-hot pages with long read latency and reprograms error-free data into new pages. Experimental results show that LDR can achieve 29% read performance improvement with only 0.2% extra P/E cycles on average, which causes negligible overhead on flash lifetime. Yajuan Du, Qiao Li 0001, Liang Shi 0001, Deqing Zou, Hai Jin 0001, Chun Jason Xue |
DAC | 4 |
| 2017 | SCVD: A New Semantics-Based Approach for Cloned Vulnerable Code Detection
Deqing Zou, Hanchao Qi, Zhen Li 0027, Song Wu 0001, Hai Jin 0001, Guozhong Sun, Sujuan Wang, Yuyi Zhong |
DIMVA | 1 |
| 2017 | Saudi cloud infrastructure: a security analysis
Wahid Rajeh, Hai Jin 0001, Deqing Zou |
Sci. China Inf. Sci. | 3 |
| 2017 | Fully Reversible Privacy Region Protection for Cloud Video SurveillanceabstractPrivacy becomes one of the major concerns of cloud-based multimedia applications such as cloud video surveillance. Privacy protection of surveillance videos aims to protect privacy information without hampering normal processing tasks of the cloud. Privacy Region Protection only protects the privacy region while keeping the non-privacy region visually intact to facilitate processing in the cloud. However, full reversibility, i.e. the complete recovery of the original video which is critical to digital investigation and law enforcement has not been properly addressed in privacy region protection. In this paper, we introduce fully reversible privacy region protection into cloud video surveillance and propose a novel fully reversible privacy protection method for H.264/AVC compressed video. All the operations are performed in the compressed domain and avoid lossy re-encoding, so the original H.264/AVC compressed video can be fully recovered. To our best knowledge, the proposed scheme is the first fully reversible one for privacy region protection. Experimental results and performance comparison demonstrate the effectiveness and efficiency of the proposed approach. Xiaojing Ma 0002, Laurence T. Yang, Yang Xiang 0001, Wenjun Zeng 0001, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Cloud Comput. | 5 |
| 2017 | A Secure, Usable, and Transparent Middleware for Permission Managers on AndroidabstractAndroid's permission system offers an all-or-nothing choice when installing an app. To make it more flexible and fine-grained, users may choose a popular app tool, called permission manager, to selectively grant or revoke an app's permissions at runtime. A fundamental requirement for such permission manager is that the granted or revoked permissions should be enforced faithfully. However, we discover that none of existing permission managers meet this requirement due to permission leaks, in which an unprivileged app can exercise certain permissions which are revoked or not-granted through communicating with a privileged app.To address this problem, we propose a secure, usable, and transparent OS-level middleware for any permission manager to defend against the permission leaks. The middleware is provably secure in a sense that it can effectively block all possible permission leaks.The middleware is designed to have a minimal impact on the usability of running apps. In addition, the middleware is transparent to users and app developers and it requires minor modifications on permission managers and Android OS. Finally, our evaluation shows that the middleware incurs relatively low performance overhead and power consumption. Daibin Wang, Haixia Yao, Yingjiu Li, Hai Jin 0001, Deqing Zou, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2017 | A dynamic predictive race detector for C/C++ programs
Deqing Zou, Hai Jin 0001, Yajuan Du, Jinan Shen |
J. Supercomput. | 2 |
| 2016 | VulPecker: an automated vulnerability detection system based on code similarity analysis
Zhen Li 0027, Deqing Zou, Shouhuai Xu, Hai Jin 0001, Hanchao Qi |
ACSAC | 2 |
| 2016 | Generally Hybrid Proxy Re-Encryption: A Secure Data Sharing among Cryptographic CloudsabstractProxy Re-Encryption (PRE) is a favorable primitive to realize a cryptographic cloud with secure and flexible data sharing mechanism. A number of PRE schemes with versatile capabilities have been proposed for different applications. The secure data sharing can be internally achieved in each PRE scheme. But no previous work can guarantee the secure data sharing among different PRE schemes in a general manner. Moreover, it is challenging to solve this problem due to huge differences among the existing PRE schemes in their algebraic systems and public-key types. To solve this problem more generally, this paper uniforms the definitions of the existing PRE and Public Key Encryption (PKE) schemes, and further uniforms their security definitions. Then taking any uniformly defined PRE scheme and any uniformly defined PKE scheme as two building blocks, this paper constructs a Generally Hybrid Proxy Re-Encryption (GHPRE) scheme with the idea of temporary public and private keys to achieve secure data sharing between these two underlying schemes. Since PKE is a more general definition than PRE, the proposed GHPRE scheme also is workable between any two PRE schemes. Moreover, the proposed GHPRE scheme can be transparently deployed even if the underlying PRE schemes are implementing. Peng Xu 0003, Wei Wang 0088, Hai Jin 0001, Willy Susilo, Deqing Zou |
AsiaCCS | 6 |
| 2016 | Towards Secure Private Image Matching
Zaid Ameen Abduljabbar, Hai Jin 0001, Ayad Ibrahim, Zaid Alaa Hussien, Mohammed Abdulridha Hussain, Salah H. Abbdal, Deqing Zou |
GPC | 7 |
| 2016 | Theory and methodology of research on cloud security
Hai Jin 0001, Weiqi Dai, Deqing Zou |
Sci. China Inf. Sci. | 3 |
| 2016 | UiLog: Improving Log-Based Fault Diagnosis by Log Analysis
Deqing Zou, Hai Jin 0001 |
J. Comput. Sci. Technol. | 1 |
| 2016 | CDMCR: multi-level fault-tolerant system for distributed applications in cloudabstractAbstract Cloud provides users with a new model of utilizing the computing infrastructure with the ability to perform parallel and distributed computations using elastic virtual cluster. However, the multi‐level and complex features make cloud computing system more prone to failure. In this paper, we present a multi‐level fault‐tolerant system for distributed applications in cloud named Distributed‐application oriented Multi‐level Checkpoint/Restart for Cloud (CDMCR). The CDMCR system backups the complete state of applications periodically with a snapshot‐based distributed checkpointing protocol, including file system state. Thus, we cannot only recover processes but also rollback data. A multi‐level recovery strategy is proposed, which includes process‐level recovery, virtual machine recreation, and host rescheduling, enabling comprehensive and efficient fault tolerance for different components in cloud. We deploy CDMCR as PaaS, so that users can be liberated from node management and system configuration and get access to fault‐tolerant service conveniently. We have implemented this system based on the Xen virtualization platform and the OpenNebula cloud platform. Experiments on the prototype demonstrate the correctness of the system. Analysis shows that CDMCR does not cause message loss or data loss, and the backup time remains nearly constant as the number of nodes increases on virtual cluster. Copyright © 2015 John Wiley & Sons, Ltd. Weizhong Qiang, Changqing Jiang, Longbo Ran, Deqing Zou, Hai Jin 0001 |
Secur. Commun. Networks | 4 |
| 2016 | Taming transitive permission attack via bytecode rewriting on Android applicationabstractAbstract Google Android is popular for mobile devices in recent years. The openness and popularity of Android make it a primary target for malware. Even though Android's security mechanisms could defend most malware, its permission model is vulnerable to transitive permission attack, a type of privilege escalation attacks. Many approaches have been proposed to detect this attack by modifying the Android OS. However, the Android's fragmentation problem and requiring rooting Android device hinder those approaches large‐scale adoption. In this paper, we present an instrumentation framework, called SEAPP, for Android applications (or “apps”) to detect the transitive permission attack on unmodified Android. SEAPP automatically rewrites an app without requiring its source codes and produces a security‐harden app. At runtime, call‐chains are built among these apps and detection process is executed before a privileged API is invoked. Our experimental results show that SEAPP could work on a large number of benign apps from the official Android market and malicious apps, with a repackaged success rate of over 99.8%. We also show that our framework effectively tracks call‐chains among apps and detects known transitive permission attack with low overhead. Copyright © 2016 John Wiley & Sons, Ltd. Daibin Wang, Hai Jin 0001, Deqing Zou, Peng Xu 0003, Tianqing Zhu |
Secur. Commun. Networks | 3 |
| 2016 | Privacy preserving in cloud computing environmentabstractPrivacy preserving in cloud computing environment Deqing Zou, Yang Xiang 0001, Geyong Min |
Secur. Commun. Networks | 1 |
| 2016 | CloudMon: Monitoring Virtual Machines in CloudsabstractIn the cloud platform, the startup security of guest virtual machines (VMs) can be guaranteed by existing techniques such as TBoot, however, how to monitor and guarantee their runtime security seems to be a non-trivial challenge, when they are exposed to the Internet. For a practical cloud system, security and performance are two important issues. In this paper, we propose a dynamic framework called CloudMon to detect kernel rootkits and guarantee the runtime security of guest VMs. CloudMon is transparent to a guest VM, neither requires its specific system information, nor has to one-on-one run with it. Meanwhile, CloudMon detects kernel rootkits through self-adjusting monitoring on memory with an acceptable overhead. A working prototype of CloudMon is implemented based on Xen. The case studies on security show that CloudMon is effective to detect kernel rootkits in guest VMs, while the performance experiments demonstrate that it brings a low performance overhead. Chuliang Weng, Kenli Li 0001, Deqing Zou |
IEEE Trans. Computers | 4 |
| 2016 | A Framework for Practical Dynamic Software UpdatingabstractDynamic software updating (DSU) enables a program to be patched on the fly without being shutdown. This paper addresses the practicality problem of the recent research on DSU systems, and presents Replus, a new DSU system that balances practicality and functionality. Replus aims to retain backward binary compatibility and support multi-threaded programs. In addition, it does not require customers to have developer-level software knowledge. More importantly, without specific compiler support, Replus can patch programs that are difficult to be updated at runtime, as well as programs that may incur an indefinite delay in DSU. The key technique of our solution is to update the stack elements for the patched program using two new mechanisms:Immediate Stack Updating, which immediately updates the stack of a thread, andtimely stack updating, which only updates the stack frames of the necessary functions without affecting others. Replus also develops anInstruction Level Updatingmechanism, which is more efficient for certain security patches. We used popular server applications as test suites to evaluate the effectiveness of Replus. The experimental results demonstrated that Replus can successfully update all the test suites with negligible impact on application performance. Hai Jin 0001, Deqing Zou, Zhenkai Liang, Bing Bing Zhou |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2015 | Robust image document authentication code with autonomous biometrie key generation, selection, and updating in cloud environmentabstractRecently, security issues are obstructing the development and using of cloud computing services. Authentication and integrity play an important role in the cloud security, and numerous concerns have been raised to recognize any tampering with exchanges of the image document between two entities (sender and receiver) within the cloud environment. However, none of the existing solutions reduce the probability of known attacks by combining cryptographic hash function with a strong factor that should be periodically changed. For this reason, in this paper we propose a robust one-time image document authentication scheme based on combining non-interactive onetime biometric key and a robust wavelet-based cryptographic hashing scheme. The result of the combination is one-time image document authentication code (OMAC). OMAC is hidden in an image document as a cover image through reversible data embedding steganography. The proposed scheme has several important security attributes, such as key agreement, biometric key management, robust OMAC, invulnerability, and efficiency. In biometric key management, key generation, key selection, and key update algorithms are performed autonomously by the sender and the receiver; thus, no interaction between them is needed. Zaid Ameen Abduljabbar, Hai Jin 0001, Zaid Alaa Hussien, Ali A. Yassin, Mohammed Abdulridha Hussain, Salah H. Abbdal, Deqing Zou |
IAS | 7 |
| 2015 | Public auditing for secure data storage in cloud through a third party auditor using modern ciphertextabstractOutsourced data in cloud and computation results are not always trustworthy because data owners lack physical possession and control over the data as a result of virtualization, replication, and migration techniques. Protecting outsourced data from security threats has become a challenging and potentially formidable task in cloud computing; hence, many schemes have focused on ameliorating this problem and on enabling public auditability for cloud data storage security. These schemes drop into two categories: total computation cost and burden on client side. Researchers have used bilinear map technology with public key cryptography. Although this technology is highly efficient, computation time is long and overhead cost is high. The client needs to perform numerous computations to ensure the integrity of data storage. To reduce auditing cost, we propose an efficient and robust scheme to maintain data integrity in cases that involve public auditing. Our scheme adopts modern cipher cryptography with a cryptographic hash function. We consider allowing a third party auditor to preprocess data on behalf of cloud users before uploading them to cloud service providers and then verifying data integrity afterward. Our proposed scheme has important security characteristics, such as privacy, key management, low cost computation, key exchange, low overhead cost, no burden on client side, inability of cloud service providers to create correct verifier respond without data, and one-time key. Finally, efficiency analysis shows that our scheme is faster and more cost-efficient than the bilinear map-based scheme. Zaid Alaa Hussien, Hai Jin 0001, Zaid Ameen Abduljabbar, Ali A. Yassin, Mohammed Abdulridha Hussain, Salah H. Abbdal, Deqing Zou |
IAS | 7 |
| 2015 | Multi-version Execution for the Dynamic Updating of Cloud ApplicationsabstractSoftwares usually need to be updated to fix bugs or add new features. On the other hand, some critical softwares, such as cloud applications, need to provide service continuously, thus should be updated without downtime. Conventional Dynamic Software Updating (DSU) systems try to update programs while running, but they hardly consider the communication of the program to be updated with other programs, which may lead to some inconsistency problems. We handle the problem with an improved DSU system by using multi-version execution. When a new update arrives, instead of updating the application to the new version, we fork a new process of the old version and dynamically update it to the new version, then make these two versions run concurrently until the update finishes. We implement a prototype system called MUC (Multi-vesion for Updating of Cloud) on Linux. To verify our prototype, we apply MUC to cloud applications Redis and Ice cast, and evaluate the overhead of MUC at runtime. Weizhong Qiang, Hai Jin 0001, Deqing Zou, Duoqiang Wang |
COMPSAC | 4 |
| 2015 | Evaluating Latency-Sensitive Applications: Performance Degradation in Datacenters with Restricted Power BudgetabstractFor data centers with limited power supply, restricting the servers' power budget (i.e., The maximal power provided to servers) is an efficient approach to increase the server density (the server quantity per rack), which can effectively improve the cost-effectiveness of the data centers. However, this approach may also affect the performance of applications in servers. Hence, the prerequisite of adopting the approach in data centers is to precisely evaluate the application performance degradation caused by restricting the servers' power budget. Unfortunately, existing evaluation methods are inaccurate because they are either improper or coarse-grained, especially for the latency-sensitive applications widely deployed in data centers. In this paper, we analyze the reasons why state-of-the-art methods are not appropriate for evaluating the performance degradation of latency-sensitive applications in case of power restriction, and we propose a new evaluation method which can provide a fine-grained way to precisely describe and evaluate such degradation. We verify our proposed method by a real-world application and the traces from Ten cent's date enter with 25328 servers. The experimental results show that our method is much more accurate compared with the state of the art, and we can significantly increase datacenter efficiency by saving servers' power budget while maintaining the applications' performance degradation within controllable and acceptable range. Song Wu 0001, Chuxiong Yan, Haibao Chen, Hai Jin 0001, Deqing Zou |
ICPP | 7 |
| 2015 | CICC: a fine-grained, semantic-aware, and transparent approach to preventing permission leaks for Android permission managersabstractAndroid's permission system offers an all-or-nothing installation choice for users. To make it more flexible, users may choose a popular app tool, called permission manager, to selectively grant or revoke an app's permissions at runtime. A fundamental requirement for such permission manager is that the granted or revoked permissions should be enforced faithfully. However, we discover that none of existing permission managers meet this requirement due to permission leaks. To address this problem, we propose CICC, a fine-grained, semantic-aware, and transparent approach for any permission managers to defend against the permission leaks. Compared to existing solutions, CICC is fine-grained because it detects the permission leaks using call-chain information at the component instance level, instead of at the app level or component level. The fine-grained feature enables it to generate a minimal impact on the usability of running apps. CICC is semantic-aware in a sense that it manages call-chains in the whole lifecycle of each component instance. CICC is transparent to users and app developers, and it requires minor modification to permission managers. Our evaluation shows that CICC incurs relatively low performance overhead and power consumption. Daibin Wang, Haixia Yao, Yingjiu Li, Hai Jin 0001, Deqing Zou, Robert H. Deng |
WISEC | 5 |
| 2015 | A lightweight software fault-tolerance system in the cloud environmentabstractSummary With the development of cloud computing, the demand of high availability for services is growing. Unfortunately, software failures greatly reduce system availability. This paper presents a lightweight software fault‐tolerance system, called SHelp, which can effectively recover programs from many types of software bugs in the cloud environment. With error virtualization techniques, it proposes ‘weighted’ rescue points techniques to effectively survive software failures through bypassing the faulty path. For multiple application instances running on different virtual machine, a three‐level storage hierarchy with several comprehensive cache updating algorithms for rescue points management is adopted to share error handling information. On the one hand, SHelp can reduce the redundancy for multiple application instances; on the other hand, it can more effectively and quickly recover from faults caused by the same bugs. A Linux prototype is implemented on an open‐source virtual machine monitor platform, Xen, and evaluated using four Web server applications that contain various types of bugs. The experimental results show that SHelp can recover server applications from these bugs in just a few seconds with modest performance overhead. Copyright © 2013 John Wiley & Sons, Ltd. Hai Jin 0001, Deqing Zou, Bing Bing Zhou, Weizhong Qiang |
Concurr. Comput. Pract. Exp. | 3 |
| 2015 | TEE: A virtual DRTM based execution environment for secure cloud-end computing
Weiqi Dai, Hai Jin 0001, Deqing Zou, Shouhuai Xu, Weide Zheng, Lei Shi 0001, Laurence T. Yang |
Future Gener. Comput. Syst. | 3 |
| 2015 | A privacy-preserving location tracking system for smartphones based on cloud storageabstractAbstract With the widespread use of smartphones, the loss of a device is a critical problem, which results both in disrupting daily communications and losing valuable property. As a result, tracking systems have been developed to track mobile devices. Previous tracking systems focus on recovering the device's locations after it goes missing, with security methods implemented on the clients. However, users' locations are stored in untrusted third‐party services, which may be attacked or eavesdropped. In this paper, we propose a system, named Android Cloud Tracker, to provide a privacy‐preserving tracking client and safe storing of user's locations. We use cloud storage controlled by users themselves as storage facilities, and they do not need to worry about any untrusted third party. We implement Android Cloud Tracker prototype on Android phones, and the evaluation shows that it is both practical and lightweight: it generates a small amount of data flow and its distributed architecture provides strong guarantees of location privacy while preserving the ability to efficiently track missing devices. Copyright © 2014 John Wiley & Sons, Ltd. Kao Zhao, Hai Jin 0001, Deqing Zou, Weiqi Dai, Yang Xiang 0001 |
Secur. Commun. Networks | 3 |
| 2014 | Improving Log-Based Fault Diagnosis by Log Classification
Deqing Zou, Hai Jin 0001, Weizhong Qiang, Zongfen Han, Xueguang Chen |
NPC | 1 |
| 2014 | ONHelp: Components in Building Secure Cloud Based on OpenNebulaabstractDue to the rapid development of cloud computing, several cloud computing platforms are developed to build cloud for individuals and companies. Open Nebula is known as one of the most popular open-source cloud computing software platforms. However, Open Nebula does not perform effectively in security. Virtual machines face risks of being attacked, which leads to services halt and data loss. We analyze the latest version of Open Nebula as well as some other similar products, and find out some functions are missing in these software platforms which turn out to be essential in secure cloud environment. We present ON Help, security components assisting Open Nebula to build a securer cloud platform, including trustworthiness attestation of computing nodes and VMs, deep monitoring of VMs, service-level fault tolerant service, cloud anti-virus in VMs and secure cloud storage. Our experimental results show that ON Help can be easily deployed with Open Nebula when constructing a cloud computing platform, and it can enhance the stability of cloud service and the security of cloud computing environment. Kao Zhao, Hai Jin 0001, Deqing Zou, Weiqi Dai |
TrustCom | 3 |
| 2014 | Towards Efficient Yet Privacy-Preserving Approximate Search in Cloud ComputingabstractOwing to the great advances in cloud computing and Internet technologies, data owners (DOs) have been motivated to outsource the storage of their data to remote cloud servers (CSs) in order to enjoy great data management service with an efficient cost. For security purposes, DOs usually have to encrypt their data prior to outsourcing it to the untrusted CSs. But encryption makes searching the encrypted data a challenging task. Recently, several approaches have been provided to enable searching over encrypted data. However, the majority of these systems are limited to handling an exact search, not a similarity search; but the latter is an important need for real-world applications. In this paper, we propose an efficient yet secure scheme to search encrypted cloud data, while recovering the misspellings and typographical errors that exist frequently both in the search request and in the source data. To do so, we use a metric space to construct a tree-based index, which allows retrieving only the relevant entries with a minimum number of distance evaluations. String embedding techniques are used to refine the relevant entries efficiently and securely. Our index construction maintains the privacy of the keyword trapdoors as well as the stored data. Comparing our scheme with other similarity searchable encryption systems via experiments shows that our scheme is efficient in terms of search time and storage overhead. Ayad Ibrahim, Hai Jin 0001, Ali A. Yassin, Deqing Zou, Peng Xu 0003 |
Comput. J. | 4 |
| 2014 | Developing resource consolidation frameworks for moldable virtual machines in clouds
Ligang He, Deqing Zou, Chao Chen 0011, Hai Jin 0001, Stephen A. Jarvis |
Future Gener. Comput. Syst. | 2 |
| 2014 | Memshepherd: comprehensive memory bug fault-tolerance systemabstractAbstract Among all software vulnerabilities, memory bugs are most common and dangerous. Programs written in unsafe languages such as C and C++ are vulnerable to stack‐based buffer overflow, heap buffer overflow, dangling pointer, and double free. Although there are a number of proposed solutions to tolerate heap related bugs, most of the existing solutions terminates the vulnerable program after a stack‐based buffer overflow attempt. There is no comprehensive solution to actively tolerate all of the four kinds of bugs mentioned previously currently. This paper presents Memshepherd, a system that can probabilistically prevent software from both stack and heap memory bugs and guarantee soundness of the software execution. It dynamically reallocates stack‐based buffers in the heap space during software execution, thus transforms a stack memory problem into a heap memory problem. By adaptively sizing buffers to be M times of their defined size and randomly placing them, Memshepherd keeps the buffers far from each other. When a buffer is to be deallocated, Memshepherd checks invalid and double frees. A Linux prototype is implemented and tested against four kinds of memory bugs. The experiment results prove that Memshepherd is effective in eliminating crashes, erroneous execution, as well as security vulnerability. Copyright © 2013 John Wiley & Sons, Ltd. Deqing Zou, Weide Zheng, Wenbin Jiang 0001, Hai Jin 0001 |
Secur. Commun. Networks | 1 |
| 2014 | CloudTaint: an elastic taint tracking framework for malware detection in the cloud
Jinfeng Yuan, Weizhong Qiang, Hai Jin 0001, Deqing Zou |
J. Supercomput. | 4 |
| 2013 | Design and implementation of a trusted monitoring framework for cloud platforms
Deqing Zou, Wenrong Zhang, Weizhong Qiang, Guofu Xiang, Laurence T. Yang, Hai Jin 0001, Kan Hu |
Future Gener. Comput. Syst. | 1 |
| 2013 | CloudAC: a cloud-oriented multilayer access control system for logic virtual domainabstractThe security issue has been a challenging concern for cloud computing because of the multitenant usage model. In cloud, each application normally runs on a dynamic coalition that is composed by multiple virtual machines (VMs) running on different virtualised service nodes, which the authors called logic virtual domain (LVD). Moreover, the owners of cloud applications, who are also the tenants of cloud, would specify some security policies to control the access to those resources that they have paid for. Therefore the owners of cloud infrastructures have to provide the tenants with the mechanism to correctly configure and enforce the access control policies on resources that are from multiple service nodes, to meet the security requirements from cloud applications. To address the above challenge, this study presents the design and implementation about a multilayer access control architecture for LVD, named CloudAC, aiming to provide isolation control, information flow control and resource‐sharing control among multiple VMs on Xen virtualisation platforms in cloud computing environment. The theory and technology this research formed will provide reliable security guarantee for resource configuration and application deployment on LVDs. Weizhong Qiang, Deqing Zou, Shenglan Wang, Laurence T. Yang, Hai Jin 0001, Lei Shi 0001 |
IET Inf. Secur. | 2 |
| 2013 | SafeStack: Automatically Patching Stack-Based Buffer Overflow VulnerabilitiesabstractBuffer overflow attacks still pose a significant threat to the security and availability of today's computer systems. Although there are a number of solutions proposed to provide adequate protection against buffer overflow attacks, most of existing solutions terminate the vulnerable program when the buffer overflow occurs, effectively rendering the program unavailable. The impact on availability is a serious problem on service-oriented platforms. This paper presents SafeStack, a system that can automatically diagnose and patch stack-based buffer overflow vulnerabilities. The key technique of our solution is to virtualize memory accesses and move the vulnerable buffer into protected memory regions, which provides a fundamental and effective protection against recurrence of the same attack without stopping normal system execution. We developed a prototype on a Linux system, and conducted extensive experiments to evaluate the effectiveness and performance of the system using a range of applications. Our experimental results showed that SafeStack can quickly generate runtime patches to successfully handle the attack's recurrence. Furthermore, SafeStack only incurs acceptable overhead for the patched applications. Hai Jin 0001, Deqing Zou, Bing Bing Zhou, Zhenkai Liang, Weide Zheng, Xuanhua Shi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2013 | A VMM-based intrusion prevention system in cloud computing environment
Hai Jin 0001, Guofu Xiang, Deqing Zou, Song Wu 0001, Feng Zhao 0003, Weide Zheng |
J. Supercomput. | 3 |
| 2012 | Secure Rank-Ordered Search of Multi-keyword Trapdoor over Encrypted Cloud DataabstractAdvances in cloud computing and Internet technologies have pushed more and more data owners to outsource their data to remote cloud servers to enjoy with huge data management services in an efficient cost. However, despite its technical advances, cloud computing introduces many new security challenges that need to be addressed well. This is because, data owners, under such new setting, loss the control over their sensitive data. To keep the confidentiality of their sensitive data, data owners usually outsource the encrypted format of their data to the untrusted cloud servers. Several approaches have been provided to enable searching the encrypted data. However, the majority of these approaches are limited to handle either a single keyword search or a Boolean search but not a multikeyword ranked search, a more efficient model to retrieve the top documents corresponding to the provided keywords. In this paper, we propose a secure multi-keyword ranked search scheme over the encrypted cloud data. Such scheme allows an authorized user to retrieve the most relevant documents in a descending order, while preserving the privacy of his search request and the contents of documents he retrieved. To do so, data owner builds his searchable index, and associates with each term document with a relevance score, which facilitates document ranking. The proposed scheme uses two distinct cloud servers, one for storing the secure index, while the other is used to store the encrypted document collection. Such new setting prevents leaking the search result, i.e. the document identifiers, to the adversary cloud servers. We have conducted several empirical analyses on a real dataset to demonstrate the performance of our proposed scheme. Ayad Ibrahim, Hai Jin 0001, Ali A. Yassin, Deqing Zou |
APSCC | 4 |
| 2012 | A Cloud Computing Management System Platform Based on Power-Sensitive ResourceabstractThis paper addresses the issue of hosting multiple clusters of Virtual Machines (i.e., multiple Virtual Clusters) in a single physical cluster system. Multiple Virtual Clusters (VCs) cohabit in the physical cluster, with different VCs serving different types of requests. There are two levels of VC managers in the framework: local manager and global manager. Every VC has its local manager. The framework developed in this paper aims to consume the minimal number of physical nodes (therefore minimized power consumption) to deliver desired QoS(Quality of Service) for all VCs. Huafeng Kong, YunTing Lei, Deqing Zou |
APSCC | 4 |
| 2012 | A standards-based interoperable single sign-on framework in ARC Grid middleware
Weizhong Qiang, Aleksandr Konstantinov, Deqing Zou, Laurence T. Yang |
J. Netw. Comput. Appl. | 3 |
| 2012 | Proactive recovery approach for intrusion tolerance with dynamic configuration of physical and virtual replicasabstractABSTRACT Proactive recovery mechanism has been widely used in building intrusion‐tolerant systems that are able to tolerate an arbitrary number of faults. However, previous proactive recovery methods seldom consider the dynamic in attacking power that may cause the increase in fault rate, resulting unguaranteed service availability. This paper describes an approach for tolerating intrusions, or more precisely, damages to replicated data, through dynamic configuration of physical and virtual replicas, which follows a general approach called proactive recovery, and proposes to dynamically adjust recovery frequency to handle potentially changing fault rate. This dynamic proactive recovery method takes the dynamic changes of attaching power into consideration to avoid/minimize the effect of intrusions. Our method is especially effective and useful in intrusion tolerance with physical replicas: it dynamically provides virtual replicas during rejuvenation phase. Copyright © 2012 John Wiley & Sons, Ltd. Feng Zhao 0003, Weizhong Qiang, Hai Jin 0001, Deqing Zou, Qin Zhang 0004 |
Secur. Commun. Networks | 5 |
| 2011 | Building Automated Trust Negotiation architecture in virtual computing environment
Deqing Zou, Shangxin Du, Weide Zheng, Hai Jin 0001 |
J. Supercomput. | 1 |
| 2010 | TEE: a virtual DRTM based execution environment for secure cloud-end computingabstractCloud computing is believed to be the next major paradigm of computing because it will substantially reduce the cost of IT systems. Ensuring security in the cloud-end is necessary because customers' data are stored and processed there. Previous studies have mainly focused on secure cloud-end storage, whereas secure cloud-end computing is much less investigated. The current practice is solely based on Virtual Machines (VM), and cannot offer adequate security because the guest Operating Systems (OS) often can be easily breached (e.g., by exploiting their vulnerabilities). This motivates the need of solutions for more secure cloud-end computing. This poster presents the design, implementation and analysis of a candidate solution, called Trusted Execution Environment (TEE), which takes advantage of both virtualization and trusted computing technologies simultaneously. The novelty behind TEE is the virtualization of the Dynamic Root of Trust for Measurement (DRTM). Weiqi Dai, Hai Jin 0001, Deqing Zou, Shouhuai Xu, Weide Zheng, Lei Shi 0001 |
CCS | 3 |
| 2010 | SHelp: Automatic Self-Healing for Multiple Application Instances in a Virtual Machine EnvironmentabstractWhen multiple instances of an application running on multiple virtual machines, an interesting problem is how to utilize the fault handling result from one application instance to heal the same fault occurred on other sibling instances, and hence to ensure high service availability in a cloud computing environment. This paper presents SHelp, a lightweight runtime system that can survive software failures in the framework of virtual machines. It applies weighted rescue points and error virtualization techniques to effectively make applications by-pass the faulty path. A two-level storage hierarchy is adopted in the rescue point database for applications running on different virtual machines to share error handling information to reduce the redundancy and to more effectively and quickly recover from future faults caused by the same bugs. A Linux prototype is implemented and evaluated using four web server applications that contain various types of bugs. Our experimental results show that SHelp can make server applications to recover from these bugs in just a few seconds with modest performance overhead. Hai Jin 0001, Deqing Zou, Bing Bing Zhou, Weizhong Qiang |
CLUSTER | 3 |
| 2010 | VMDriver: A Driver-Based Monitoring Mechanism for VirtualizationabstractMonitoring virtual machine (VM) is an essential function for virtualized platforms. Existing solutions are either coarse-grained - monitoring in granularity of VM level, or not general - only support specific monitoring functions for particular guest operating system (OS). Thus they do not satisfy the monitoring requirement in large-scale server cluster such as data center and public cloud platform, where each physical platform runs hundreds of VMs with different guest OSes. In this paper, we propose VMDriver, a general and fine-grained approach for virtualization monitoring. The novel design of VMDriver is the separation of event interception point in VMM level and rich guest OS semantic reconstructions in management domain. With this design, variant monitoring drivers in management domain can mask the differences of guest OSes. We implement VMDriver on Xen and our experimental study shows that it introduces very small performance overhead. We demonstrate its generality by inspecting four aspects information about the target virtual machines with different guest OSes. The unified interface of VMDriver brings convenience to develop complex monitoring tools for distributed virtualization environment. Guofu Xiang, Hai Jin 0001, Deqing Zou, Xinwen Zhang, Sha Wen, Feng Zhao 0003 |
SRDS | 3 |
| 2010 | Building dynamic and transparent integrity measurement and protection for virtualized platform in cloud computingabstractAbstract In the cloud computing infrastructure, there is an increasing demand to maintain and verify the integrity of software stacks running on remote systems and protect users' sensitive data. However, due to the fact that software stacks running on cloud platforms are usually provided and maintained by different authorities (or providers) who are potentially untrusting to each other, the problem of measuring and protecting runtime system integrity becomes very challenging and has not been well addressed yet. In this paper, we present an integrity measurement and protection architecture for software stacks running on a guest operating system (OS) of a virtualized platform in cloud environment. Our solution does not change the guest OS, and thus is transparent to the OS authority. Furthermore, our architecture ensures that sensitive information of users is protected once the integrity of software stacks is broken during runtime. We implement our solution on Xen, and present a simple prototype‐based Nimbus. We demonstrate the capability of dynamically detecting the integrity change of programs in cloud computing, and our evaluation results show that the solution is effective for integrity protection with acceptable performance overhead. Copyright © 2010 John Wiley & Sons, Ltd. Ge Cheng, Hai Jin 0001, Deqing Zou, Xinwen Zhang |
Concurr. Comput. Pract. Exp. | 3 |
| 2010 | Constructing trusted virtual execution environment in P2P grids
Deqing Zou, Weide Zheng, Jinjiu Long, Hai Jin 0001, Xueguang Chen |
Future Gener. Comput. Syst. | 1 |
| 2009 | DVM-MAC: A Mandatory Access Control System in Distributed Virtual Computing EnvironmentabstractWe design and implement a Mandatory Access Control (MAC) system in distributed virtual computing environment, named DVM-MAC, aiming to provide distributed trust through enforcing MAC policies. In DVM-MAC, Prioritized Chinese Wall (PCW) model is implemented to control potential covert channels between VMs in both single node and distributed environment. A policy enforcement module locates inside Xen VMM for better enforcing MAC locally rather than outside the VMM. DVM-MAC adopts centralized architecture for multi-level management and secure transmission of inter-node policy information. For performance consideration, a specific policy decision and enforcement module for controlling inter-node behaviors is moved out of Xen VMM and up to user space. DVM-MAC authorizes a specific center node named Central Security Server (CSS) to be responsible for the decision making between the nodes as well as leaves the inter-node policy enforcement module in each node. Through our experiments and data analysis, we verify the correctness, effectiveness, and efficiency in our prototype when implementing PCW model. Deqing Zou, Lei Shi 0001, Hai Jin 0001 |
ICPADS | 1 |
| 2009 | SH-CRBAC: Integrating Attribute and Status Constraints into the RBAC Model in Smart Home SystemsabstractThe requirements for access control have been increased significantly in smart home systems. Many factors such as user ID, user location, service usage conditions and so on, regarded as authorization attributes, are important in making authorization decision in smart home systems. We investigate into the dynamic characteristics of the authorization in smart home systems and propose a new access-control model, SH-CRBAC, which aims to combine the advantages of attribute-based authorization mechanism and role-based access-control mechanism, and imposes attribute and status constraints on the RBAC model and enhances the generality and flexibility of authorization significantly in smart home systems. The status consistency of SH-CRBAC is analysed, and we also analyse the characteristics of SH-CRBAC through comparison with other popular existing authorization models in smart home systems. Deqing Zou, Jong Hyuk Park 0001, Tai-Hoon Kim, Xueguang Chen |
Comput. J. | 1 |
| 2009 | CRBAC: Imposing multi-grained constraints on the RBAC model in the multi-application environment
Deqing Zou, Ligang He, Hai Jin 0001, Xueguang Chen |
J. Netw. Comput. Appl. | 1 |
| 2008 | Extending HLA/RTI to WAN Based on Grid ServiceabstractThe High Level Architecture (HLA) has been followed universally as a de facto standard for modeling and simulation. However, the design of HLA was not intended to manage simulation demanding resources from various organizations. At the same time, the resources of a distributed simulation can not be dynamic mapped during the process. The advantages of Grid service in collaborating and managing distributed resources provide a new opportunity to solve these problems. In this paper, a distributed simulation framework is proposed. The framework, based upon Grid service, extends HLA/RTI to Wide-Area-Network (WAN), and it can combine the advantages of both Grid service and HLA. Using this frame work, we provide a platform for traffic emergency response simulation over WAN. The results of experiments of the prototype show the feasibility and efficiency of this framework. The future research plan has been discussed in the end. Hu Wan 0002, Yu Wang 0005, Xueguang Chen, Deqing Zou |
APSCC | 5 |
| 2008 | A Trusted Group Signature Architecture in Virtual Computing Environment
Deqing Zou, Yunfa Li 0001, Song Wu 0001, Weizhong Qiang |
ATC | 1 |
| 2008 | A Formal Framework for Expressing Trust Negotiation in the Ubiquitous Computing Environment
Deqing Zou, Jong Hyuk Park 0001, Laurence T. Yang, Zhensong Liao, Tai-Hoon Kim |
UIC | 1 |
| 2008 | Trusted virtual machine monitor-based group signature architectureabstractGroup communication is an important technique for many network computing applications. In group communication, a member in a group sends a message to others normally by multicast. Group signature guarantees the integrity of the exchanged data and provides source authentication. In a virtual machine (VMs) based computing system, a virtual machine monitor (VMM) allows applications to run in different VMs strongly isolated from each other. A trusted VMM (TVMM) based platform can provide stronger security protection for group signature systems than traditional computing platforms can. The authors first introduce a TVMM-based group signature architecture and a TVMM security protection mechanism for group signature components. Then, the authors propose a group signature scheme using the function of message checking based on the discrete logarithm problem. Finally, the authors prove the correctness of the group signature scheme and analyse its security in virtual computing environments. Deqing Zou, Hai Jin 0001, Jong Hyuk Park 0001, Han-Chieh Chao, Yunfa Li 0001 |
IET Commun. | 1 |
| 2007 | An Authentication and Access Control Framework for Group Communication Systems in Grid EnvironmentabstractCollaboration is used for information sharing and activity coordinating, and it exists broadly in many fields. Group communication enables efficient communication between a set of processes logically organized into groups and communicating via multicast in an asynchronous environment. One of the key technologies for collaborative applications is secure group communication. Current research on secure group communication scarcely considers the existing security mechanism in local systems. As a result, group communication systems couldn 't provide general support for collaborative applications running on a specific system. Based on the existing grid security technologies, we propose an authentication and access control framework at virtual organization (VO) level for group communication in grid environment. By introducing role-based access control (RBAC) and attribute-based approach, we define group management policies and design group control protocols. The protocols are analyzed from three aspects: compatibility, performance, and security. Finally, we implement a prototype based on GridShib. Deqing Zou, Laurence T. Yang, Weizhong Qiang, Xueguang Chen, Zongfen Han |
AINA | 1 |
| 2007 | A Digital Signature Mechanism and Authentication Scheme for Group Communication in Grid
Yunfa Li 0001, Hai Jin 0001, Deqing Zou, Jieyun Chen, Zongfen Han |
ATC | 3 |
| 2007 | A Scalable Service Scheme for Secure Group Communication in GridabstractIn this paper, we propose a scalable service scheme for secure group communication in grid. In the service scheme, a series of methods and strategies are presented, such as the initialization methods for group member, administrative domain and virtual organization, the key distribution strategy and the rekeying strategy. In order to improve the scalability of this service scheme, the services for a group are logically divided into two hierarchical levels, which is in accordance with the characteristics of group communication in grid. In addition, in order to show the efficiency and the scalability of the service scheme, simulation experiments are done. The results show that the service scheme is efficient and scalable. Thus, the service scheme can satisfy the requirement of people in large-scale, dynamic grid environment. Yunfa Li 0001, Hai Jin 0001, Deqing Zou, Jieyun Chen, Zongfen Han |
COMPSAC (1) | 3 |
| 2006 | Daonity: An Experience on Enhancing Grid Security by Trusted Computing Technology
Weizhong Qiang, Zhi-Dong Shen, Chunrun Chen, Huanguo Zhang, Deqing Zou |
ATC | 6 |
| 2005 | VO-Sec: An Access Control Framework for Dynamic Virtual Organization
Hai Jin 0001, Weizhong Qiang, Xuanhua Shi, Deqing Zou |
ACISP | 4 |
| 2005 | A Formal General Framework and Service Access Model for Service GridabstractConstituent resources in a grid system need to be used in a coordinated fashion to deliver non trivial qualities of service. Various e-science and e-business use cases are investigated to guide how to create grid systems, and determine which functions grid systems should have. Web services emerge as a standard interoperable technology for grid systems. Although the motivations and goals for service grids are obvious, there is no clear definition for service grids to define and describe the general framework and service access model. In this paper, the general framework for service grids is defined in a formal approach, and the virtual organization based service access mechanism is modeled based on abstract state machines (ASM). In the service access model we proposed, the quality of service (QoS) issue is considered for the user request. This resulting serves as a theoretical base for our service grid system, HowU. Deqing Zou, Weizhong Qiang, Xuanhua Shi |
ICECCS | 1 |
| 2004 | Early Experience in QoS-Based Service Grid Architecture
Hanhua Chen, Hai Jin 0001, Minghu Zhang, Pengliu Tan, Deqing Zou, Pingpeng Yuan |
APWeb | 5 |
| 2004 | Real-Time Strategy and Practice in Service GridabstractThe emerging service grids bring together various distributed application-level services to a 'market' for clients to request and enable the integration of services across distributed, heterogeneous, dynamic virtual organizations. However, there are a number of applications with the requirement of time constraints. We propose a real-time strategy in service grid architecture. We also extend the OGSI grid service semantics for fault-tolerance. The real-time and fault-tolerant strategies seem efficient through experiments. Hai Jin 0001, Hanhua Chen, Jian Chen 0030, Ping Kuang, Deqing Zou |
COMPSAC | 6 |
| 2004 | RT-Grid: A QoS Oriented Service Grid Framework
Hai Jin 0001, Hanhua Chen, Minghu Zhang, Deqing Zou |
PDCAT | 4 |
| 2003 | A Data Mining Based Intrusion Detection Model
Jianhua Sun 0002, Hai Jin 0001, Hao Chen 0002, Zongfen Han, Deqing Zou |
IDEAL | 5 |
| 2003 | Fault-Tolerant Grid Architecture and Practice
Hai Jin 0001, Deqing Zou, Hanhua Chen, Jianhua Sun 0002, Song Wu 0001 |
J. Comput. Sci. Technol. | 2 |