|
|
|
题名
|
作者
|
年代
|
出处
|
被引量
|
| 1 | A static technique for detecting input validation vulnerabilities in Android apps显示文摘Input validation vulnerabilities are common in Android apps, especially in inter-component communications. Malicious attacks can exploit this kind of vulnerability to bypass Android security mechanism and compromise the integrity, confidentiality and availability of Android devices. However, so far there is not a sound approach at the source code level for app developers aiming to detect input validation vulnerabilities in Android apps. In this paper, we propose a novel approach for detecting input validation flaws in Android apps and we implement a prototype named Easy IVD, which provides practical static analysis of Java source code.Easy IVD leverages backward program slicing to extract transaction and constraint slices from Java source code.Then Easy IVD validates these slices with predefined security rules to detect vulnerabilities in a known pattern.To detect vulnerabilities in an unknown pattern, Easy IVD extracts implicit security specifications as frequent patterns from the duplicated slices and verifies them. Then Easy IVD semi-automatically confirms the suspicious rule violations and reports the confirmed ones as vulnerabilities. We evaluate Easy IVD on four versions of original Android apps spanning from version 2.2 to 5.0. It detects 58 vulnerabilities including confused deputy attacks and denial of service attacks. Our results prove that Easy IVD can provide a practical defensive solution for app developers. | Zhejun FANG Qixu LIU Yuqing ZHANG Kai WANG Zhiqiang WANG Qianru WU | 2017 | Science China(Information Sciences)2017,60,5: | 5 |
| 2 | Exo-celiac liver in Glyptosternum maculatum显示文摘A unique structure in the fish of Glyptosternum maculatum(Regan)(Siluriformes:Sisoridae)is reported.It was identified as a part of the liver named 'exo-celiac liver'.This new organ is located between skin and muscle and connected with the celiac liver by a funiform tissue,'joint belt'.It has similar histological features and isozyme electrophoretogramic bands of lactate dehydrogenase,esterase,malate dehydrogenase and alcohol dehydrogenase as in the celiac liver.This unique organ has biological research value and could serve as an important tool for studying organogenesis and evolution. | Li Hongjing Xie Congxin Li Dapeng Chai Yi Liu Hongyan Fan Qixue Zhu Bangke | 2007 | Progress in Natural Science:Materials International2007,17,9: | 3 |
| 3 | Tracking Your Browser with High-Performance Browser Fingerprint Recognition Model显示文摘As the cyber security has attracted great attention in recent years,and with all kinds of tools’(such as Network Agent,VPN and so on)help,traditional methods of tracking users like log analysis and cookie have been not that effective.Especially for some privacy sensitive users who changed their browser configuration frequently to hide themselves.The Browser Fingerprinting technology proposed by Electronic Frontier Foundation(EFF)gives a new approach of tracking users,and then our team designed an enhanced fingerprint dealing solution based on browser fingerprinting technology.Our enhanced solution plays well in recognizing the similar fingerprints,but it is not that efficient.Nowadays we improve the algorithm and propose a high-performance,efficient Browser Fingerprint Recognition Model.Our new model reforms the fingerprint items set by EFF and propose a Fingerprint Tracking Algorithm(FTA)to deal with collected data.It can associate users with some browser configuration changes in different periods of time quickly and precisely.Through testing with the experimental website built on the public network,we prove the high-performance and efficiency of our algorithm with a 20%time-consuming decrease than ever. | Wei Jiang Xiaoxi Wang Xinfang Song Qixu Liu Xiaofeng Liu | 2020 | China Communications2020,17,3: | 2 |
| 4 | TFTP vulnerability finding technique based on fuzzing显示文摘 | Liu Qixu Zhang Yuqing | | 0,,14: | 1 |
| 5 | Distally Based Dorsal Pedal Neurocutaneous Flap for Forefoot Coverage显示文摘 | Wengang Huang Dong Liu Geoffrey L. Robb Qixu Zhang | 2011 | Annals of Plastic Surgery2011,,3: | 1 |
| 6 | Automatic Network Protocol Analysis and Vulnerability Discovery Based on Symbolic Expression显示文摘 | Luo Cheng Yuqing Zhang Long Wang and Qixu Liu | | Journal of the Graduate School of the Academy of Sciences0,,2: | 1 |
| 7 | Driving Android apps to trigger target API invocations based on activity and GUI filtering显示文摘机器人,图形用户界面图形用户界面,图形用户界面,机器人,机器人,,机器人,机器人 API, API 机器人,,,,图形用户界面。 | Hongzhou YUE Yuqing ZHANG Wenjie WANG Qixu LIU | 2017 | Science China(Information Sciences)2017,60,7: | 0 |
| 8 | Identification of the E2F1-RAD51AP1 axis as a key factor in MGMT-methylated GBM TMZ resistance显示文摘Objective:Epidermal growth factor receptor variant III(EGFRvIII)is a constitutively-activated mutation of EGFR that contributes to the malignant progression of glioblastoma multiforme(GBM).Temozolomide(TMZ)is a standard chemotherapeutic for GBM,but TMZ treatment benefits are compromised by chemoresistance.This study aimed to elucidate the crucial mechanisms leading to EGFRvIII and TMZ resistance.Methods:CRISPR-Cas13a single-cell RNA-seq was performed to thoroughly mine EGFRvIII function in GBM.Western blot,realtime PCR,flow cytometry,and immunofluorescence were used to determine the chemoresistance role of E2F1 and RAD51-associated protein 1(RAD51AP1).Results:Bioinformatic analysis identified E2F1 as the key transcription factor in EGFRvIII-positive living cells.Bulk RNA-seq analysis revealed that E2F1 is a crucial transcription factor under TMZ treatment.Western blot suggested enhanced expression of E2F1 in EGFRvIII-positive and TMZ-treated glioma cells.Knockdown of E2F1 increased sensitivity to TMZ.Venn diagram profiling showed that RAD51AP1 is positively correlated with E2F1,mediates TMZ resistance,and has a potential E2F1 binding site on the promoter.Knockdown of RAD51AP1 enhanced the sensitivity of TMZ;however,overexpression of RAD51AP1 was not sufficient to cause chemotherapy resistance in glioma cells.Furthermore,RAD51AP1 did not impact TMZ sensitivity in GBM cells with high O6-methylguanine-DNA methyltransferase(MGMT)expression.The level of RAD51AP1 expression correlated with the survival rate in MGMT-methylated,but not MGMT-unmethylated TMZ-treated GBM patients.Conclusions:Our results suggest that E2F1 is a key transcription factor in EGFRvIII-positive glioma cells and quickly responds to TMZ treatment.RAD51AP1 was shown to be upregulated by E2F1 for DNA double strand break repair.Targeting RAD51AP1 could facilitate achieving an ideal therapeutic effect in MGMT-methylated GBM cells. | Junhu Zhou Fei Tong Jixing Zhao Xiaoteng Cui Yunfei Wang Guangxiu Wang Chunsheng Kang Xiaomin Liu Qixue Wang | 2023 | Cancer Biology & Medicine2023,20,5: | 0 |
| 9 | Detecting compromised email accounts via login behavior characterization显示文摘The illegal use of compromised email accounts by adversaries can have severe consequences for enterprises and society.Detecting compromised email accounts is more challenging than in the social network field,where email accounts have only a few interaction events(sending and receiving).To address the issue of insufficient features,we propose a novel approach to detecting compromised accounts by combining time zone differences and alternate logins to identify abnormal behavior.Based on this approach,we propose a compromised email account detection framework that relies on widely available and less sensitive login logs and does not require labels.Our framework characterizes login behaviors to identify logins that do not belong to the account owner and outputs a list of account-subnet pairs ranked by their likelihood of having abnormal login relationships.This approach reduces the number of account-subnet pairs that need to be investigated and provides a reference for investigation priority.Our evaluation demonstrates that our method can detect most email accounts that have been accessed by disclosed malicious IP addresses and outperforms similar research.Additionally,our framework has the capability to uncover undisclosed malicious IP addresses. | Jianjun Zhao Can Yang Di Wu Yaqin Cao Yuling Liu Xiang Cui Qixu Liu | 2024 | Cybersecurity2024,7,1: | 0 |
| 10 | MRm-DLDet:a memory-resident malware detection framework based on memory forensics and deep neural network显示文摘Cyber attackers have constantly updated their attack techniques to evade antivirus software detection in recent years.One popular evasion method is to execute malicious code and perform malicious actions only in memory.Mali-cious programs that use this attack method are called memory-resident malware,with excellent evasion capability,and have posed huge threats to cyber security.Traditional static and dynamic methods are not effective in detect-ing memory-resident malware.In addition,existing memory forensics detection solutions perform unsatisfactorily in detection rate and depend on massive expert knowledge in memory analysis.This paper proposes MRm-DLDet,a state-of-the-art memory-resident malware detection framework,to overcome these drawbacks.MRm-DLDet first builds a virtual machine environment and captures memory dumps,then creatively processes the memory dumps into RGB images using a pre-processing technique that combines deduplication and ultra-high resolution image cropping,followed by our neural network MRmNet in MRm-DLDet to fully extract high-dimensional features from memory dump files and detect them.MRmNet receives the labeled sub-images of the cropped high-resolution RGB images as input of ResNet-18,which extracts the features of the sub-images.Then trains a network of gated recurrent units with an attention mechanism.Finally,it determines whether a program is memory-resident malware based on the detection results of each sub-image through a specially designed voting layer.We created a high-quality dataset consisting of 2,060 benign and memory-resident programs.In other words,the dataset contains 1,287,500 labeled sub-images cut from the MRm-DLDet transformed ultra-high resolution RGB images.We implement MRm-DLDet for Windows 10,and it performs better than the latest methods,with a detection accuracy of up to 98.34%.Moreover,we measured the effects of mimicry and adversarial attacks on MRm-DLDet,and the experimental results demonstrated the robustness of MRm-DLDet. | Jiaxi Liu Yun Feng Xinyu Liu Jianjun Zhao Qixu Liu | 2024 | Cybersecurity2024,7,1: | 0 |
| 11 | Existence of Positive Periodic Solutions for the SIV Epidemic Model with Impulsive Vaccination and Infection-Age显示文摘 | Helong Liu Qixue Dai Jingyuan Yu Guangtian Zhu | 2006 | Journal of Systems Science and Information2006,4,1: | 0 |
| 12 | A lightweight DDoS detection scheme under SDN context显示文摘Software-defined networking(SDN),a novel network paradigm,separates the control plane and data plane into dif-ferent network equipment to realize the flexible control of network traffic.Its excellent programmability and global view present many new opportunities.DDoS detection under the SDN context is an important and challenging research field.Some previous works attempted to collect and analyze statistics related to flows,usually recorded in switches,to address DDoS threats.In contrast,other works applied machine learning-based solutions to identify DDos and achieved promising results.Generally,most previous works need to periodically request flow rules or packets to obtain flow statistics or features to detect stealthy exceptions.Nevertheless,the request for flow rules is very time-consuming and CPU-consuming;moreover may congest the communication channel between the controller and the switches.Therefore,we present FORT,a lightweight DDoS detection scheme,which spreads the rule-based detection algorithm at edge switches and determines whether to start it by periodically retrieving the ports state.A time-series algorithm,ARIMA,is utilized to determine the port statistics adaptively,and an SVM algorithm is applied to detect whether a DDoS attack does occur.Representative experiments demonstrate that FORT can significantly reduce the controller load and provide a reliable detection accuracy.Referring to the false alarm rate of 1.24%in the comparison scheme,the false alarm rate of this scheme is only 0.039%,which significantly reduces the probability of false alarm.Besides,by introducing the alarm mechanism,this scheme can reduce the load of the southbound chan-nel by more than 60%in the normal state. | Kun Jia Chaoge Liu Qixu Liu Junnan Wang Jiazhi Liu Feng Liu | 2023 | Cybersecurity2023,6,1: | 0 |
| 13 | Nitromethane-Enabled Fluorination of Styrenes and Arenes显示文摘The electrophilic fluorination of unsaturated compounds provides a reliable approach to the generation of organofluorides,which are used widely in agrochemicals,pharmaceuticals,and other materials.Numerous active electrophilic fluorine reagents,such as the fluorine molecule(F_(2))or xenon difluoride(XeF_(2)),have been applied in fluorination.However,these reagents suffer from their hazardous,toxic,corrosive,and poor selective properties,and the relatively weak electrophilicity of Selectfluor or N-fluorobenzenesulfonimide(NFSI)usually limits their broad applications.Herein,we disclose nitromethane(MeNO_(2))as an efficient activator of Selectfluor and NFSI,as well as a stabilizer of carbocations.Therefore,the fluoro-azidation,fluoroamination,fluoroesterification of styrenes,and C–H fluorination of(hetero)arenes were well realized just by the facilitation of MeNO_(2).The mild reaction conditions and practicability made our current method a versatile protocol for accessing organofluorides. | Weijin Wang Tongyu Huo Xinyi Zhao Qixue Qin Yujie Liang Song Song Guosheng Liu Ning Jiao | 2020 | CCS Chemistry2020,2,6: | 0 |
| 14 | Practice,Existing Problems and Countermeasures of Tobacco Planting Insurance in Qianxinan Prefecture显示文摘The cultivation of the economic crop flue-cured tobacco is greatly impacted by natural climates,making it a risk industry.In recent years,flue-cured tobacco production is influenced by extreme weather such as typhoon,low temperature,hail,frost,drought,plant diseases and insect pests.It is imperative to establish a sound insurance system for tobacco planting.In this paper,the practice and functions of tobacco planting insurance in Qianxinan Prefecture were summarized,the experience and existing problems in the practice process were analyzed,and finally the countermeasures and suggestions were proposed to further improve the tobacco planting insurance. | Qing MU Yang LIU Binhua ZHAN Feng DING Qixue CHEN Chuanjiang FEI | 2018 | Agricultural Biotechnology2018,7,6: | 0 |
| 15 | XAS:Cross-API scripting attacks in social ecosystems显示文摘With the rapid development of online social networks, various Web application programming interfaces(APIs) on social platforms are released to share profitable social data with all kinds of third-party online services. However, it also brings new risks to social networks once Web APIs are insecurely designed,implemented, and invoked. The focused topic in this paper is security analysis of a new type of cross-site scripting(XSS) which is based on Web APIs in new complicated social ecosystems which consist of social networks,third-party apps, and other online services. In this paper, we refer to Web API-based XSS as cross-API scripting(XAS). For the first time, we take typical XAS attacks in diversified context as cases to demonstrate the new exploiting opportunities and threats in social ecosystems. Also, we design a tool to identify the design and implementation flaws of Web APIs in 11 popular social networks. We discover several security flaws of API via our experiment. According to the results, we conclude causes of XAS flaws in depth. We also examined 143Web-based apps and verified the prevalence of XAS flaws. Finally, we proposed preliminary measures both in social networks and third-party applications to alleviate XAS. | ZHANG YuQing LIU QiXu LUO QiHan WANG XiaLi | 2015 | Science China(Information Sciences)2015,58,1: | 0 |
| 16 | PIMS:An Efficient Process Integrity Monitoring System Based on Blockchain and Trusted Computing in Cloud-Native Context显示文摘With the advantages of lightweight and high resource utilization,cloud-native technology with containers as the core is gradually becoming themainstreamtechnical architecture for information infrastructure.However,malware attacks such as Doki and Symbiote threaten the container runtime’s security.Malware initiates various types of runtime anomalies based on process form(e.g.,modifying the process of a container,and opening the external ports).Fortunately,dynamic monitoring mechanisms have proven to be a feasible solution for verifying the trusted state of containers at runtime.Nevertheless,the current routine dynamic monitoring mechanisms for baseline data protection are still based on strong security assumptions.As a result,the existing dynamicmonitoringmechanismis still not practical enough.To ensure the trustworthiness of the baseline value data and,simultaneously,to achieve the integrity verification of the monitored process,we combine blockchain and trusted computing to propose a process integrity monitoring system named IPMS.Firstly,the hardware TPM 2.0 module is applied to construct a trusted security foundation for the integrity of the process code segment due to its tamper-proof feature.Then,design a new format for storing measurement logs,easily distinguishing files with the same name in different containers from log information.Meanwhile,the baseline value data is stored on the blockchain to avoidmalicious damage.Finally,trusted computing technology is used to perform fine-grained integrity measurement and remote attestation of processes in a container,detect abnormal containers in time and control them.We have implemented a prototype system and performed extensive simulation experiments to test and analyze the functionality and performance of the PIMS.Experimental results show that PIMS can accurately and efficiently detect tampered processes with only 3.57% performance loss to the container. | Miaomiao Yang Guosheng Huang Junwei Liu Yanshuang Gui Qixu Wang Xingshu Chen | 2023 | Computer Modeling in Engineering & Sciences2023,,8: | 0 |
| 17 | An adaptive system for detecting malicious queries in web attacks显示文摘Web request query strings(queries), which pass parameters to a referenced resource, are always manipulated by attackers to retrieve sensitive data and even take full control of victim web servers and web applications. However, existing malicious query detection approaches in the literature cannot cope with changing web attacks. In this paper, we introduce a novel adaptive system(AMOD) that can adaptively detect web-based code injection attacks, which are the majority of web attacks, by analyzing queries. We also present a new adaptive learning strategy, called SVM HYBRID, leveraged by our system to minimize manual work. In the evaluation, an up-to-date detection model is trained on a ten-day query dataset collected from an academic institute's web server logs. The evaluation shows our approach overwhelms existing approaches in two respects. Firstly, AMOD outperforms existing web attack detection methods with an F-value of 99.50%and FP rate of 0.001%. Secondly, the total number of malicious queries obtained by SVM HYBRID is3.07 times that by the popular support vector machine adaptive learning(SVM AL) method. The malicious queries obtained can be used to update the web application firewall(WAF) signature library. | Ying DONG Yuqing ZHANG Hua MA Qianru WU Qixu LIU Kai WANG Wenjie WANG | 2018 | Science China(Information Sciences)2018,61,3: | 0 |