Kyushu University · Computer Science
야오카이 펑 교수의 연구실은 인공지능 기반의 사이버 보안 기술, 특히 IoT 환경에서의 라이트웨이트 기반 악성 트래픽 탐지와 봇넷 공격 탐지에 초점을 맞추고 있습니다. 특히 자원이 제한된 디바이스에서 실시간으로 작동할 수 있도록 최적화된 머신러닝 기반 이상 탐지 시스템과 특성 선택 기법을 개발하고 있으며, C&C 통신 탐지 및 분산 스캔 공격 탐지 기술 등 실질적인 사이버 위협 대응 기술을 연구하고 있습니다.
Figures are computed from collected data and may differ slightly.
With the rapid development and popularization of Internet of Things (IoT) devices, an increasing number of cyber-attacks are targeting such devices. It was said that most of the attacks in IoT environments are botnet-based attacks. Many security weaknesses still exist on the IoT devices because most of them have not enough memory and computational resource for robust security mechanisms. Moreover, many existing rule-based detection systems can be circumvented by attackers. In this study, we prop
The application of a large number of Internet of Things (IoT) devices makes our life more convenient and industries more efficient. However, it also makes cyber-attacks much easier to occur because so many IoT devices are deployed and most of them do not have enough resources (i.e., computation and storage capacity) to carry out ordinary intrusion detection systems (IDSs). In this study, a lightweight machine learning-based IDS using a new feature selection algorithm is designed and implemented
Cyber attack detection technology plays a vital role today, since cyber attacks have been causing great harm and loss to organizations and individuals. Feature selection is a necessary step for many cyber-attack detection systems, because it can reduce training costs, improve detection performance, and make the detection system lightweight. Many techniques related to feature selection for cyber attack detection have been proposed, and each technique has advantages and disadvantages. Determining
It is well known that distributed cyber attacks simultaneously launched from many hosts have caused the most serious problems in recent years including problems of privacy leakage and denial of services. Thus, how to detect those attacks at early stage has become an important and urgent topic in the cyber security community. For this purpose, recognizing C&C (Command & Control) communication between compromised bots and the C&C server becomes a crucially important issue, because C&C communicatio
The technologies used by attackers in the Internet environment are becoming more and more sophisticated. Of the many kinds of attacks, distributed scan attacks have become one of the most serious problems. In this study, we propose a novel method based on normal behavior modes of traffic to detect distributed scan attacks in darknet environments. In our proposed method, all the possible destination TCP and UDP ports are monitored, and when a port is attacked by a distributed scan, an alert is gi
Nearest Neighbor (NN) search has been widely used in spatial databases and multimedia databases. Incremental NN (INN) search is regarded as the optimal NN search because of the minimum number of node accesses and it can be used no matter whether the number of objects to be retrieved is fixed or not in advance. R*-tree is still regarded as being among the best high- dimensional indices. This paper presents an analytical model for estimating performance of the INN search algorithm on R*-tree. The
The rapid growth of the Internet of Vehicles (IoV) requires secure, efficient, and reliable data exchanges among multiple stakeholders. Traditional centralized database systems can hardly address the challenges associated with data privacy, integrity, and scalability in this decentralized ecosystem. In this paper, we propose a Hyperledger Fabric-Based Multi-Channel Structure to overcome these limitations. By leveraging the blockchain architecture, the system ensures data confidentiality and inte
Distributed attacks have reportedly caused the most serious losses in the modern cyber environment. Thus, how to avoid and detect distributed attacks has become one of the most important topics in the cyber security community. Of many approaches for avoiding and detecting cyber-attacks, behavior-based method has been attracting great attentions from many researchers and developers. It is well known that, for behavior-based cyber-attack detections, the algorithm for extracting normal modes from h
Low-rate attacks can conceal their traffic because their packets are at very low rates, which make it easy to bury themselves into the normal traffic. Thus, although a number of volume-based detection techniques are able to identify anomalies that trigger significant changes in traffic volume, they are not applicable to detecting low-rate attacks. Because of this, the problem of low-rate attacks has been attracting many researchers in the community of network security. In this study, for the fir
In recent years, with the development of the Internet of Things and distributed computing, the “server-edge device” architecture has been widely deployed. This study focuses on leveraging autoencoder technology to address the binary classification problem in network intrusion detection, aiming to develop a lightweight model suitable for edge devices. Traditional intrusion detection models face two main challenges when directly ported to edge devices: inadequate computational resources to support
Along with Kansei information being successfully introduced to information retrieval systems, particularly multimedia retrieval systems, many Kansei retrieval systems have been implemented in the past two decades. And, it has become clear that the traditional multimedia retrieval systems using key-words or/and other text information are not enough in many applications, because that they can not deal with sensitive words reflecting user’s subjectivity. In this chapter, Kansei retrieval systems ef
Open papers in the app to read, cite, and organize with AI.