首页 > 最新文献

IEEE Transactions on Dependable and Secure Computing最新文献

英文 中文
OFIDS : Online Learning-Enabled and Fingerprint-Based Intrusion Detection System in Controller Area Networks 控制器局域网中基于指纹的在线学习入侵检测系统
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2022.3230501
Y. Wei, Can Cheng, Guoqi Xie
As a widely used industrial field bus, the controller area network (CAN) lacks security mechanisms (e.g., encryption and authentication) and is vulnerable to security attacks (e.g., masquerade). A fingerprint-based intrusion detection system (IDS) in CAN networks can detect masquerade attacks by scanning the unique clock signals of CAN devices. However, most state-of-the-art fingerprint-based IDSs commonly use an analog-to-digital converter module with a low frequency of 60 MHz to sample CAN signals, lowering the detection accuracy of fingerprint-based IDSs. In addition, almost all fingerprint-based IDSs are trained offline and then detected online, ignoring that system clock signals of hardware change over time, resulting in degraded detection performance. This paper proposes an online learning-enabled and fingerprint-based IDS (OFIDS) in CAN networks to increase the sampling frequency, shorten the detection response time, and increase the detection accuracy. OFIDS uses a high-speed comparator (i.e., TLV3501) and FPGA (i.e., Xilinx ZYNQ-7010) to sample the CAN_High signal, achieving a low sampling delay time of 4.5 ns and a high sampling frequency of 1 GHz. The self-adaptability of the backpropagation neural network is taken advantage of and used to train the OFIDS model with a detection accuracy of 99.9992%. OFIDS is deployed to a CAN network prototype with five CAN devices (i.e., two Arduino UNO boards and three STM32 microcontrollers) and a real vehicle. Experimental results show that OFIDS can achieve at least 99.99% detection accuracy within 0.18μs in a CAN network prototype and can achieve 98% detection accuracy in a real vehicle.
{"title":"OFIDS : Online Learning-Enabled and Fingerprint-Based Intrusion Detection System in Controller Area Networks","authors":"Y. Wei, Can Cheng, Guoqi Xie","doi":"10.1109/tdsc.2022.3230501","DOIUrl":"https://doi.org/10.1109/tdsc.2022.3230501","url":null,"abstract":"As a widely used industrial field bus, the controller area network (CAN) lacks security mechanisms (e.g., encryption and authentication) and is vulnerable to security attacks (e.g., masquerade). A fingerprint-based intrusion detection system (IDS) in CAN networks can detect masquerade attacks by scanning the unique clock signals of CAN devices. However, most state-of-the-art fingerprint-based IDSs commonly use an analog-to-digital converter module with a low frequency of 60 MHz to sample CAN signals, lowering the detection accuracy of fingerprint-based IDSs. In addition, almost all fingerprint-based IDSs are trained offline and then detected online, ignoring that system clock signals of hardware change over time, resulting in degraded detection performance. This paper proposes an online learning-enabled and fingerprint-based IDS (OFIDS) in CAN networks to increase the sampling frequency, shorten the detection response time, and increase the detection accuracy. OFIDS uses a high-speed comparator (i.e., TLV3501) and FPGA (i.e., Xilinx ZYNQ-7010) to sample the CAN_High signal, achieving a low sampling delay time of 4.5 ns and a high sampling frequency of 1 GHz. The self-adaptability of the backpropagation neural network is taken advantage of and used to train the OFIDS model with a detection accuracy of 99.9992%. OFIDS is deployed to a CAN network prototype with five CAN devices (i.e., two Arduino UNO boards and three STM32 microcontrollers) and a real vehicle. Experimental results show that OFIDS can achieve at least 99.99% detection accuracy within 0.18μs in a CAN network prototype and can achieve 98% detection accuracy in a real vehicle.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"4607-4620"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62407522","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 3
Privacy-Preserving Decision-Making over Blockchain 隐私保护决策超过b区块链
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2022.3231237
Jiajie Zhang, Bingsheng Zhang, A. Nastenko, Hamed Balogun, R. Oliynykov
Many blockchain applications require democratic on-chain decision-making. In this work, we propose a community-inclusive decentralised collaborative decision-making system with privacy assurance. Its key component is a two-stage voting scheme inspired by choice architecture. Our decision-making system is compatible with most existing blockchain infrastructures. In addition, it supports liquid democracy/delegative voting for better collaborative intelligence. Namely, stake holders can either vote directly on proposals or delegate their voting power to experts. When majority of voting committee members are honest, no one can derive voters’ voting preferences or delegations with non-negligible probability. To support concurrent multiple voting events, we design a distributed batch key generation protocol that can generate multiple keys simultaneously by voting committee members with amortised communication cost of $mathcal {O}(n)$O(n) per key, where $n$n is the number of participants. Besides, our system supports “evolving committee”, i.e., voting committee members can be changed during the voting period. We implemented a pilot system in Scala, benchmark results indicate that our system can support large number of participants with high efficiency.
-许多bb0应用程序需要民主的链上决策。在这项工作中,我们提出了一个具有隐私保障的社区包容性分散协作决策系统。它的关键组成部分是受选择架构启发的两阶段投票方案。我们的决策系统与大多数现有区块链基础设施兼容。此外,它支持流动民主/代表投票,以获得更好的协作智能。也就是说,利益相关者可以直接对提案进行投票,也可以将他们的投票权委托给专家。当投票委员会的大多数成员都是诚实的时候,没有人能够以不可忽略的概率推断出选民的投票偏好或授权。为了支持并发多个投票事件,我们设计了一个分布式批量密钥生成协议,该协议可以通过投票委员会成员同时生成多个密钥,每个密钥的分摊通信成本为O (n),其中n为参与者的数量。此外,我们的系统支持“演进委员会”,即投票委员会的成员可以在投票期间更换。我们在Scala中实现了一个试点系统,测试结果表明我们的系统可以高效地支持大量参与者。
{"title":"Privacy-Preserving Decision-Making over Blockchain","authors":"Jiajie Zhang, Bingsheng Zhang, A. Nastenko, Hamed Balogun, R. Oliynykov","doi":"10.1109/tdsc.2022.3231237","DOIUrl":"https://doi.org/10.1109/tdsc.2022.3231237","url":null,"abstract":"Many blockchain applications require democratic on-chain decision-making. In this work, we propose a community-inclusive decentralised collaborative decision-making system with privacy assurance. Its key component is a two-stage voting scheme inspired by choice architecture. Our decision-making system is compatible with most existing blockchain infrastructures. In addition, it supports liquid democracy/delegative voting for better collaborative intelligence. Namely, stake holders can either vote directly on proposals or delegate their voting power to experts. When majority of voting committee members are honest, no one can derive voters’ voting preferences or delegations with non-negligible probability. To support concurrent multiple voting events, we design a distributed batch key generation protocol that can generate multiple keys simultaneously by voting committee members with amortised communication cost of <inline-formula><tex-math notation=\"LaTeX\">$mathcal {O}(n)$</tex-math><alternatives><mml:math><mml:mrow><mml:mi mathvariant=\"script\">O</mml:mi><mml:mo>(</mml:mo><mml:mi>n</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math><inline-graphic xlink:href=\"zhang-ieq1-3231237.gif\"/></alternatives></inline-formula> per key, where <inline-formula><tex-math notation=\"LaTeX\">$n$</tex-math><alternatives><mml:math><mml:mi>n</mml:mi></mml:math><inline-graphic xlink:href=\"zhang-ieq2-3231237.gif\"/></alternatives></inline-formula> is the number of participants. Besides, our system supports “evolving committee”, i.e., voting committee members can be changed during the voting period. We implemented a pilot system in Scala, benchmark results indicate that our system can support large number of participants with high efficiency.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"4648-4663"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62407495","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
FABRIC: Fast and Secure Unbounded Cross-System Encrypted Data Sharing in Cloud Computing FABRIC:云计算中快速安全的无界跨系统加密数据共享
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2023.3240820
Lili Wang, Ye Lin, Ting Yao, H. Xiong, K. Liang
Existing proxy re-encryption (PRE) schemes to secure cloud data sharing raise challenges such as supporting the heterogeneous system efficiently and achieving the unbounded feature. To address this problem, we proposed a fast and secure unbounded cross-domain proxy re-encryption scheme, named FABRIC, which enables the delegator to authorize the semi-trusted cloud server to convert one ciphertext of an identity-based encryption (IBE) scheme to another ciphertext of an attribute-based encryption (ABE) scheme. As the first scheme to achieve the feature mentioned above, FABRIC not only enjoys constant computation overhead in the encryption, decryption, and re-encryption phases when the quantity of attributes increases, but is also unbounded such that the new attributes or roles could be adopted into the system anytime. Furthermore, FABRIC achieves adaptive security under the decisional linear assumption (DLIN). Eventually, detailed theoretical and experimental analysis proved that FABRIC enjoys excellent performance in efficiency and practicality in the cloud computing scenario.
{"title":"FABRIC: Fast and Secure Unbounded Cross-System Encrypted Data Sharing in Cloud Computing","authors":"Lili Wang, Ye Lin, Ting Yao, H. Xiong, K. Liang","doi":"10.1109/tdsc.2023.3240820","DOIUrl":"https://doi.org/10.1109/tdsc.2023.3240820","url":null,"abstract":"Existing proxy re-encryption (PRE) schemes to secure cloud data sharing raise challenges such as supporting the heterogeneous system efficiently and achieving the unbounded feature. To address this problem, we proposed a fast and secure unbounded cross-domain proxy re-encryption scheme, named FABRIC, which enables the delegator to authorize the semi-trusted cloud server to convert one ciphertext of an identity-based encryption (IBE) scheme to another ciphertext of an attribute-based encryption (ABE) scheme. As the first scheme to achieve the feature mentioned above, FABRIC not only enjoys constant computation overhead in the encryption, decryption, and re-encryption phases when the quantity of attributes increases, but is also unbounded such that the new attributes or roles could be adopted into the system anytime. Furthermore, FABRIC achieves adaptive security under the decisional linear assumption (DLIN). Eventually, detailed theoretical and experimental analysis proved that FABRIC enjoys excellent performance in efficiency and practicality in the cloud computing scenario.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"5130-5142"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62410132","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
Heterogeneous Differential-Private Federated Learning: Trading Privacy for Utility Truthfully 异质差分-私有联合学习:以隐私交换效用真实
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2023.3241057
Xi Lin, Jun Wu, Jianhua Li, Chao Sang, Shiyan Hu, M. Deen
Differential-private federated learning (DP-FL) has emerged to prevent privacy leakage when disclosing encoded sensitive information in model parameters. However, the existing DP-FL frameworks usually preserve privacy homogeneously across clients, while ignoring the different privacy attitudes and expectations. Meanwhile, DP-FL is hard to guarantee that uncontrollable clients (i.e., stragglers) have truthfully added the expected DP noise. To tackle these challenges, we propose a heterogeneous differential-private federated learning framework, named HDP-FL, which captures the variation of privacy attitudes with truthful incentives. First, we investigate the impact of the HDP noise on the theoretical convergence of FL, showing a tradeoff between privacy loss and learning performance. Then, based on the privacy-utility tradeoff, we design a contract-based incentive mechanism, which encourages clients to truthfully reveal private attitudes and contribute to learning as desired. In particular, clients are classified into different privacy preference types and the optimal privacy-price contracts in the discrete-privacy-type model and continuous-privacy-type model are derived. Our extensive experiments with real datasets demonstrate that HDP-FL can maintain satisfactory learning performance while considering different privacy attitudes, which also validate the truthfulness, individual rationality, and effectiveness of our incentives.
{"title":"Heterogeneous Differential-Private Federated Learning: Trading Privacy for Utility Truthfully","authors":"Xi Lin, Jun Wu, Jianhua Li, Chao Sang, Shiyan Hu, M. Deen","doi":"10.1109/tdsc.2023.3241057","DOIUrl":"https://doi.org/10.1109/tdsc.2023.3241057","url":null,"abstract":"Differential-private federated learning (DP-FL) has emerged to prevent privacy leakage when disclosing encoded sensitive information in model parameters. However, the existing DP-FL frameworks usually preserve privacy homogeneously across clients, while ignoring the different privacy attitudes and expectations. Meanwhile, DP-FL is hard to guarantee that uncontrollable clients (i.e., stragglers) have truthfully added the expected DP noise. To tackle these challenges, we propose a heterogeneous differential-private federated learning framework, named HDP-FL, which captures the variation of privacy attitudes with truthful incentives. First, we investigate the impact of the HDP noise on the theoretical convergence of FL, showing a tradeoff between privacy loss and learning performance. Then, based on the privacy-utility tradeoff, we design a contract-based incentive mechanism, which encourages clients to truthfully reveal private attitudes and contribute to learning as desired. In particular, clients are classified into different privacy preference types and the optimal privacy-price contracts in the discrete-privacy-type model and continuous-privacy-type model are derived. Our extensive experiments with real datasets demonstrate that HDP-FL can maintain satisfactory learning performance while considering different privacy attitudes, which also validate the truthfulness, individual rationality, and effectiveness of our incentives.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"5113-5129"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62410371","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Reversible Data Hiding in Encrypted Images Based on Binary Symmetric Channel Model and Polar Code 基于二进制对称信道模型和极码的加密图像可逆数据隐藏
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2022.3228385
Kaimeng Chen, Qingxiao Guan, Weiming Zhang, Nenghai Yu
For vacating-room-after-encryption reversible data hiding in encrypted images (VRAE RDHEI), an essential problem is how to address potential errors in data extraction and image recovery. This problem significantly limits the capacities of the existing VRAE RDHEI methods. To solve the problem while losing as little capacity as possible, in this article, a novel method is proposed that uses the ideas of noisy channel model and channel code. By designing the data hiding mechanism appropriately, the embedding and extraction of data in the proposed method can be equivalent to the input and output of a virtual binary symmetric channel (BSC) model, so that the errors in data extraction are equivalent to the bit transitions in BSC. Based on the virtual BSC model, polar code is used to encode the secret data in the data hider's side. With the help of polar code, the receiver can decode the extracted bits containing errors to obtain correct secret data, then recover the error-free original image based on the corrected secret data. The experimental results proved that, compared with the existing VRAE methods, the proposed method can significantly improve the capacity and the quality of the decrypted images under the premise of complete reversibility.
{"title":"Reversible Data Hiding in Encrypted Images Based on Binary Symmetric Channel Model and Polar Code","authors":"Kaimeng Chen, Qingxiao Guan, Weiming Zhang, Nenghai Yu","doi":"10.1109/tdsc.2022.3228385","DOIUrl":"https://doi.org/10.1109/tdsc.2022.3228385","url":null,"abstract":"For vacating-room-after-encryption reversible data hiding in encrypted images (VRAE RDHEI), an essential problem is how to address potential errors in data extraction and image recovery. This problem significantly limits the capacities of the existing VRAE RDHEI methods. To solve the problem while losing as little capacity as possible, in this article, a novel method is proposed that uses the ideas of noisy channel model and channel code. By designing the data hiding mechanism appropriately, the embedding and extraction of data in the proposed method can be equivalent to the input and output of a virtual binary symmetric channel (BSC) model, so that the errors in data extraction are equivalent to the bit transitions in BSC. Based on the virtual BSC model, polar code is used to encode the secret data in the data hider's side. With the help of polar code, the receiver can decode the extracted bits containing errors to obtain correct secret data, then recover the error-free original image based on the corrected secret data. The experimental results proved that, compared with the existing VRAE methods, the proposed method can significantly improve the capacity and the quality of the decrypted images under the premise of complete reversibility.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"4519-4535"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62407423","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Window Canaries: Re-thinking Stack Canaries for Architectures with Register Windows 窗口金丝雀:重新思考带有注册窗口的体系结构中的堆栈金丝雀
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2022.3230748
Kai Lehniger, P. Langendorfer
This paper presents Window Canaries, a novel approach to Stack Canaries for architectures with a register window that protects return addresses and stack pointers without the need of adding additional instruction to each potentially vulnerable function. Instead, placement and check of the canary word is moved to window exception handlers that are responsible to handle register window overflows and underflows. The approach offers low performance overhead while guaranteeing that return addresses are protected by stack buffer overflows without relying on a heuristic that decides which functions to instrument. The contributions of this paper are a complete implementation of the approach for the Xtensa LX architecture with register window option as well as a performance evaluation and discussion of advantages and drawbacks.
{"title":"Window Canaries: Re-thinking Stack Canaries for Architectures with Register Windows","authors":"Kai Lehniger, P. Langendorfer","doi":"10.1109/tdsc.2022.3230748","DOIUrl":"https://doi.org/10.1109/tdsc.2022.3230748","url":null,"abstract":"This paper presents Window Canaries, a novel approach to Stack Canaries for architectures with a register window that protects return addresses and stack pointers without the need of adding additional instruction to each potentially vulnerable function. Instead, placement and check of the canary word is moved to window exception handlers that are responsible to handle register window overflows and underflows. The approach offers low performance overhead while guaranteeing that return addresses are protected by stack buffer overflows without relying on a heuristic that decides which functions to instrument. The contributions of this paper are a complete implementation of the approach for the Xtensa LX architecture with register window option as well as a performance evaluation and discussion of advantages and drawbacks.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"4637-4647"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62407602","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
Blockchain-Based Deduplication and Integrity Auditing over Encrypted Cloud Storage 基于区块链的加密云存储重复数据删除和完整性审计
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2023.3237221
M. Song, Zhongyun Hua, Yifeng Zheng, Hejiao Huang, Xiaohua Jia
Cloud computing promises great advantages in handling the exponential data growth. Secure deduplication can greatly improve cloud storage efficiency while protecting data confidentiality. In the meantime, when data are outsourced to the remote cloud, there is an imperative need to audit the integrity. Most existing works only consider the support for either secure deduplication or integrity auditing. Recently, there have been some research efforts aiming to integrate secure deduplication with integrity auditing. However, prior works are unsatisfactory in that they suffer from the leakage of ownership privacy and forgeability of auditing results for low-entropy data. In this paper, we propose a new scheme that delicately bridges secure deduplication and integrity auditing in encrypted cloud storage. In contrast with prior works, our scheme protects the ownership privacy and prevents the cloud service provider from forging the auditing results for low-entropy data. Furthermore, we propose a blockchain-based mechanism that helps to ensure key recoverability and reduce local storage cost of keys. Formal analysis is provided to justify the security guarantees. Experiment results demonstrate the modest performance overhead of our scheme.
{"title":"Blockchain-Based Deduplication and Integrity Auditing over Encrypted Cloud Storage","authors":"M. Song, Zhongyun Hua, Yifeng Zheng, Hejiao Huang, Xiaohua Jia","doi":"10.1109/tdsc.2023.3237221","DOIUrl":"https://doi.org/10.1109/tdsc.2023.3237221","url":null,"abstract":"Cloud computing promises great advantages in handling the exponential data growth. Secure deduplication can greatly improve cloud storage efficiency while protecting data confidentiality. In the meantime, when data are outsourced to the remote cloud, there is an imperative need to audit the integrity. Most existing works only consider the support for either secure deduplication or integrity auditing. Recently, there have been some research efforts aiming to integrate secure deduplication with integrity auditing. However, prior works are unsatisfactory in that they suffer from the leakage of ownership privacy and forgeability of auditing results for low-entropy data. In this paper, we propose a new scheme that delicately bridges secure deduplication and integrity auditing in encrypted cloud storage. In contrast with prior works, our scheme protects the ownership privacy and prevents the cloud service provider from forging the auditing results for low-entropy data. Furthermore, we propose a blockchain-based mechanism that helps to ensure key recoverability and reduce local storage cost of keys. Formal analysis is provided to justify the security guarantees. Experiment results demonstrate the modest performance overhead of our scheme.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"4928-4945"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62409938","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
Magma: Robust and Flexible Multi-Party Payment Channel Magma:稳健灵活的多方支付渠道
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2023.3238332
Zhong-Liang Ge, Yi Zhang, Yu Long, Dawu Gu
The lack of scalability is a leading issue of blockchain. By transferring transactions to off-chain, 2-party payment channels achieve instant transaction confirmation between channel users and enhance the blockchain throughput, thereby becoming a promising solution. By extending the channel from 2-party to multi-party, richer application scenarios could be supported. Meanwhile, new and exclusive requirements emerge in the multi-party off-chain payments, including robustness and flexibility. The robustness requires that the channel operation would not be impeded by any uncooperative channel member, and the flexibility guarantees that parties could join or exit the channel dynamically. However, all the current attempts either fail to achieve the new emerging properties or sacrifice some merits of 2-party channels. In this paper, we propose a new multi-party channel construction, Magma, which has good scalability. Magma outperforms the previous solutions to the multi-party payment channel for the following reasons. By canceling the heavy reliance on the cooperation of all channel members when implementing the channel operation, Magma achieves robustness. Magma also allows parties to join or exit one channel flexibly, without violating the balance security. Meanwhile, Magma's whole transaction process is performed off-chain, thereby inheriting the instant confirmation and low-cost features of 2-party channels. To guarantee the security of Magma, we formalize the multi-party channel's functionality and prove that Magma is secure in the UC framework. Moreover, our implementation and comparison show that Magma is practical and performs better than existing solutions in providing off-chain payment services.
{"title":"Magma: Robust and Flexible Multi-Party Payment Channel","authors":"Zhong-Liang Ge, Yi Zhang, Yu Long, Dawu Gu","doi":"10.1109/tdsc.2023.3238332","DOIUrl":"https://doi.org/10.1109/tdsc.2023.3238332","url":null,"abstract":"The lack of scalability is a leading issue of blockchain. By transferring transactions to off-chain, 2-party payment channels achieve instant transaction confirmation between channel users and enhance the blockchain throughput, thereby becoming a promising solution. By extending the channel from 2-party to multi-party, richer application scenarios could be supported. Meanwhile, new and exclusive requirements emerge in the multi-party off-chain payments, including robustness and flexibility. The robustness requires that the channel operation would not be impeded by any uncooperative channel member, and the flexibility guarantees that parties could join or exit the channel dynamically. However, all the current attempts either fail to achieve the new emerging properties or sacrifice some merits of 2-party channels. In this paper, we propose a new multi-party channel construction, Magma, which has good scalability. Magma outperforms the previous solutions to the multi-party payment channel for the following reasons. By canceling the heavy reliance on the cooperation of all channel members when implementing the channel operation, Magma achieves robustness. Magma also allows parties to join or exit one channel flexibly, without violating the balance security. Meanwhile, Magma's whole transaction process is performed off-chain, thereby inheriting the instant confirmation and low-cost features of 2-party channels. To guarantee the security of Magma, we formalize the multi-party channel's functionality and prove that Magma is secure in the UC framework. Moreover, our implementation and comparison show that Magma is practical and performs better than existing solutions in providing off-chain payment services.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"5024-5042"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62410227","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Pervasive Micro Information Flow Tracking 普适微信息流跟踪
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2023.3238547
S. Mallissery, Kun-Yi Chiang, Chun-An Bau, Yu-Sung Wu
Detection of advanced security attacks that exploit zero-day vulnerabilities or application-specific logic loopholes has been challenging due to the lack of attack signatures or substantial deviations in the overall system behavior. One has to zoom in to the affected code regions and look for local anomalies distinguishable from the benign workload to detect such attacks. We propose pervasive micro information flow tracking (PerMIT) that realizes variable-level online dynamic information flow tracking (DIFT) as a means to detect the attacks. The system uses hardware virtualization extension to monitor access to taint source variables and performs asynchronous code emulation to infer the local information flow. We demonstrate that the pervasive micro information flow can sufficiently capture the attacks and incurs only a small overhead. Given the program source code, the system can further enrich the semantics of micro information flow by embedding the variable names. We have integrated the system with machine learning algorithms to demonstrate the effectiveness of anomaly detection for zero-day attacks with pervasive micro information flow.
{"title":"Pervasive Micro Information Flow Tracking","authors":"S. Mallissery, Kun-Yi Chiang, Chun-An Bau, Yu-Sung Wu","doi":"10.1109/tdsc.2023.3238547","DOIUrl":"https://doi.org/10.1109/tdsc.2023.3238547","url":null,"abstract":"Detection of advanced security attacks that exploit zero-day vulnerabilities or application-specific logic loopholes has been challenging due to the lack of attack signatures or substantial deviations in the overall system behavior. One has to zoom in to the affected code regions and look for local anomalies distinguishable from the benign workload to detect such attacks. We propose pervasive micro information flow tracking (PerMIT) that realizes variable-level online dynamic information flow tracking (DIFT) as a means to detect the attacks. The system uses hardware virtualization extension to monitor access to taint source variables and performs asynchronous code emulation to infer the local information flow. We demonstrate that the pervasive micro information flow can sufficiently capture the attacks and incurs only a small overhead. Given the program source code, the system can further enrich the semantics of micro information flow by embedding the variable names. We have integrated the system with machine learning algorithms to demonstrate the effectiveness of anomaly detection for zero-day attacks with pervasive micro information flow.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"11 1","pages":"4957-4975"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62410343","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Exploiting Spatial-Temporal Behavior Patterns for Fraud Detection in Telecom Networks 利用时空行为模式进行电信网络欺诈检测
IF 7.3 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Pub Date : 2023-11-01 DOI: 10.1109/tdsc.2022.3228797
Guojun Chu, Jingyu Wang, Q. Qi, Haifeng Sun, Shimin Tao, Hao Yang, J. Liao, Zhu Han
Fraud detection in telecom network is a crucial problem that threatens users’ privacy and property security. In recent years, fraudsters adopt more advanced camouflage strategies to avoid being detected by traditional algorithms. To deal with these new types of fraud, it is necessary to analyze the integrated spatial-temporal features, which are rarely involved in existing literature. In this article, we propose a novel fraud detection model based on the intertwined spatial-temporal patterns of user behaviors. Specifically, we first introduce the extension of statistical and interactive features to dynamic call patterns, and build a probabilistic model to simulate users’ call behaviors. Then the sequential patterns reflecting users’ own behaviors are obtained by the mixture Hidden Markov Models, and the structural patterns reflecting the collaboration between users in the telecom network are obtained by the attention-based Graph-SAGE model. Finally, our model outputs a fraud score for each user to detect potential fraudsters. We conduct extensive experiments on a real-world telecom dataset. The experimental results demonstrate that our intertwined spatial-temporal call patterns can effectively represent user behavior and improve the accuracy of fraud detection compared with state-of-the-art methods. The results also validate the efficiency and the interpretability of our model.
{"title":"Exploiting Spatial-Temporal Behavior Patterns for Fraud Detection in Telecom Networks","authors":"Guojun Chu, Jingyu Wang, Q. Qi, Haifeng Sun, Shimin Tao, Hao Yang, J. Liao, Zhu Han","doi":"10.1109/tdsc.2022.3228797","DOIUrl":"https://doi.org/10.1109/tdsc.2022.3228797","url":null,"abstract":"Fraud detection in telecom network is a crucial problem that threatens users’ privacy and property security. In recent years, fraudsters adopt more advanced camouflage strategies to avoid being detected by traditional algorithms. To deal with these new types of fraud, it is necessary to analyze the integrated spatial-temporal features, which are rarely involved in existing literature. In this article, we propose a novel fraud detection model based on the intertwined spatial-temporal patterns of user behaviors. Specifically, we first introduce the extension of statistical and interactive features to dynamic call patterns, and build a probabilistic model to simulate users’ call behaviors. Then the sequential patterns reflecting users’ own behaviors are obtained by the mixture Hidden Markov Models, and the structural patterns reflecting the collaboration between users in the telecom network are obtained by the attention-based Graph-SAGE model. Finally, our model outputs a fraud score for each user to detect potential fraudsters. We conduct extensive experiments on a real-world telecom dataset. The experimental results demonstrate that our intertwined spatial-temporal call patterns can effectively represent user behavior and improve the accuracy of fraud detection compared with state-of-the-art methods. The results also validate the efficiency and the interpretability of our model.","PeriodicalId":13047,"journal":{"name":"IEEE Transactions on Dependable and Secure Computing","volume":"1 1","pages":"4564-4577"},"PeriodicalIF":7.3,"publicationDate":"2023-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"62407225","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 4
期刊
IEEE Transactions on Dependable and Secure Computing
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1