
Distributed Denial of Service (DDoS) attacks continue to pose a substantial threat to Internet services. The Moving Target Defense (MTD) presents a promising solution for DDoS defense. The existing researches focused on detecting DDoS attacks using characteristics of packets and traffics, which is not adaptive to proxy-based MTD system. This paper introduces MPDD, a model for detecting DDoS attacks via parameters of multiple proxy servers, leveraging the inherent benefits of the proxy-based MTD architecture. By dynamically monitoring network traffic across each proxy server, MPDD is a service-agnostic and adaptive system that is aware of potential DDoS attacks. When integrated with an actual MTD system, we validate the effectiveness and feasibility of our detection methods through rigorous experimentation.
With the development and application of the Internet of Things (IoT) and Artificial Intelligence (AI) and other high technologies that greatly expand the scope of time, space and people’s cognition. Humanity is entering an era of intelligent interconnection of all things with the ternary fusion of people, machines and things. The intelligent interconnection of everything is based on the Internet of Things, and OpenHarmony is an operating system that facilitates the intelligent connection of all things. Although various development tools and environments of Hongmeng system have been initially established, OpenHarmony ecosystem is still in the stage of development and improvement, and the supported third-party libraries are still relatively limited, Hongmeng ecosystem still has a long way to go. It is very important for the OpenHarmony ecosystem to have more functions or components to be ported to complete the OpenHarmony project. We ported the third-party package paho mqtt to the OpenHarmony standard system. The successful porting of MQTT in the OpenHarmony standard system complements the OpenHarmony IoT project with additional functions or components. Furthermore, based on the ported MQTT third-party library in the OpenHarmony standard system, we developed an IoT system application for smart flower pots. This application not only verifies the porting results of MQTT, but also proposes a complete bottom-up IoT system development proposal based on OpenHarmony, from third-party library porting, peripheral driver development, device-side development to cloud platform-side development and application-side development, which promotes the construction and prosperity of the OpenHarmony ecosystem.
Federated learning effectively solves the problems of data privacy leakage and communication overhead in centralized machine learning by transferring the model training process from a central server to local devices. Since most of the real world has multimodal data scenarios, the scalability of federated learning systems that can only deal with unimodal local data is limited. Recently, researchers have attempted to apply federated learning to multimodal tasks and have achieved good performance. However, existing multimodal federated learning methods still face some challenges, such as model drift, slow model convergence, insufficient labeled data at the client, and high communication costs. To this end, this paper proposes a new multimodal federated learning scheme, which adopts an embedded knowledge transfer mechanism and a semi-supervised learning method, and improves the client selection strategy and server aggregation mechanism. By quantifying the client update degree and introducing a weighted aggregation mechanism, more targeted model optimization is realized. The experimental results show that our method significantly improves the model performance and achieves satisfactory results in downstream tasks, providing new research ideas and a practical basis for developing multimodal federated learning.
To enhance the security, complexity, and applicability of cloud node programs, effectively hinder attackers from reverse engineering, and reduce the ability of detailed analysis and vulnerability discovery of applications, in this paper, we propose a code obfuscation protection strategy based on the LLVM compiler framework oriented to the run state of the program. The approach first implements obfuscation processing on the cloud node program at the code IR layer, including control flow obfuscation, data flow obfuscation, and code virtualization obfuscation, to generate a protected executable program. After deploying the program to the cloud server, process obfuscation and memory obfuscation are performed to implement strong protection of data when the program is running. This procedure effectively guarantees the security of applications in cloud computing environments by rendering the structure and logic of the internal operation of the program inaccessible to program attackers.
The Resource Public Key Infrastructure (RPKI) stands as the sole standardized solution to date for mitigating route prefix hijacking, playing a critically important role in maintaining network security order and addressing security vulnerabilities in route exchanges. With the global deployment of RPKI, ensuring the stable operation of the RPKI system becomes crucial. In order to solve the problem of affecting the stable operation of the RPKI system due to the disconnection of relying parties from the RPKI repository, this paper proposes an emergency synchronization scheme for relying party cache route origin authorization (ROA) information based on the Simplified Local Internet Number Resource Management (SLURM). The proposed solution automatically monitors the connection status between relying parties and the resource repository, initiating emergency synchronization of ROA data in case of a disconnection. Finally, the effectiveness of this solution is validated through further experimental testing.
This paper investigates the freshness of information for covert communication in a satellite-terrestrial system consisting of a satellite transmitter Alice, a terrestrial full-duplex receiver Bob, and a terrestrial warden Willie. Particularly, Alice tries to transmit covert information to Bob under the detection of Willie, while Bob emits jamming signals to confuse Willie simultaneously. We first provide theoretical modeling for the average age of information (AOI) of Bob and the covert constraint of Willie. Based on the theoretical model, we then drive a optimal transmit power of Alice to minimize the average AoI with the constraint of covertness requirement. Finally, numerical results are presented to verify the theoretical results and to illustrate the impacts of transmit and jamming power on the covertness and average AoI.
This paper proposes a frequency modulated continuous wave (FMCW) radar spoofing scheme by using spacetime coding metasurface (STCM) in a reconfigurable intelligent surface (RIS)-assisted communication system. Specifically, in this spoofing scheme STCM is employed to induce a time-varying phase to modify the FMCW radar signal frequency. Through frequency decoupling, the proposed scheme can spoof FMCW radar estimations of distance as well as velocity, and thus achieves the spoofing attack. Finally, we validate the performance of the proposed spoofing scheme through extensive simulations.
In the distributed cyber-physical systems (CPSs) within the industrial domain, the volume of data produced by interconnected devices is escalating at an unprecedented pace, presenting novel opportunities to enhance service quality through data sharing. Nevertheless, data privacy protection emerges as a significant challenge for data providers in wireless networks. This paper puts forward a solution integrating blockchain and lightweight federated learning, designated as LFL-COBC, which aims to tackle the issues related to data privacy and device performance optimization. We initially analyze multiple dimensions influencing the performance of computing devices, such as mining capacity, data quality, computational efficiency and local device deviation, which are crucial for augmenting user engagement. Based on these dimensions, we deduce a set of cooperation strategies for selecting the optimal committee members and rewarding the contributions of node devices equitably, thereby stimulating cooperation between users and servers. To intelligently and automatically detect device anomalies and alleviate the operational burden, a convolutional neural network (CNN) model is employed. Additionally, to address the escalating cost of customer participation and the potential data explosion issue, a near-optimal model pruning algorithm is designed. This algorithm can make the model obtained from the training of node equipment lightweight, thereby reducing the load of federated learning and the blockchain, as well as enhancing the overall efficiency of the system. The efficacy of our approach is demonstrated through numerical experiments on the HDFS and BGL public data sets. Experimental results indicate that the LFL-COBC scheme can effectively safeguard data privacy and optimize device performance concurrently, providing an effective solution for device anomaly detection in CPSs.
This paper proposes a privacy-preserving physical layer (PHY-layer) authentication scheme based on carrier frequency offset (CFO) to combat impersonation and eavesdropping attacks initiated by illegitimate unmanned aerial vehicles (UAVs) in UAV-aided communication system. First, we employ the MOOSE method to extract hardware fingerprints from the received signals. Second, encryption and decryption scheme is generated based on the extracted fingerprints to improve the privacy-preserving performance. Then, we construct the PHY-layer authentication problem into a binary hypothesis test and derive analytical expressions for detection probability theoretically. Finally, the authentication performance and privacy protection effectiveness of the proposed scheme are validated through extensive simulation experiments, confirming the correctness of the established theoretical model.
This paper investigates the covert communication in a mobile wireless system where a mobile transmitter wants to send covert messages to a full-duplex receiver without being detected by a warden. To assist the covert communication, the receiver emits artificial noise to confuse the warden. We first provide the theoretical modeling for the probabilities of false alarm and missed detection, and the detection error probability. Then, we analyze the optimal threshold and minimum detection error probability of the warden. Finally, extensive numerical results are presented to verify the correctness of our analysis and explore the impact of mobility on warden’s detection performance. We can have a deep insight that the mobile transmitter can significantly decrease the detection performance of warden and contribute to the covert communication.
To enhance the performance of Conversational recommendation systems, this paper proposes a method called Hierarchical Policy Learning with Noisy Networks (HPL-NN). First, it utilizes Transformer and global graph neural networks to encode the historical user Conversational information into states. Then, hierarchical policy models are employed for action selection. Finally, Noisy Networks are introduced into Dueling DQN to enhance the exploratory nature of the agent. Experimental results show that the HPL-NN can improve both the performance of the agent's exploration capabilities and the efficiency of the system, e.g., compared to the second-ranking DAHCR method, our proposed method achieved a 1.2% improvement in SR@15 and a 1.0% improvement in hDCG on the Amazon-Book dataset, while AT decreased by 3.3%; on the MovieLens dataset, SR@15 and hDCG increased by 1.3% and 1.7%, respectively.
Few shot malware detection methods can quickly deal with unknown software and secure the network environment. However, the existing methods face two major challenges: one is that the malware itself is characterized by complexity and variability, which makes it difficult for traditional detection methods to cope with it; and the other is that the model overfitting problem is highlighted in the case of limited number of samples. In this paper, we propose a few shot malware detection method based on malware variants and model enhancement. The malware is first converted into a three-channel image, after which a spatial transformation network is combined with an attention mechanism inside the model to address the problem of proliferation of malware variants. To overcome the model overfitting problem, a model training algorithm based on self-distillation is proposed to obtain more robust and discriminative prototype features. Experimental results show that the proposed scheme can effectively identify both known and unknown malware, and the performance and generalization ability are better than existing schemes.
In microservice architecture, system deployment usually adopts container environment. The container deployment method solves problems of rapid iteration, rapid deployment and automatic recovery of software. In addition, during software operation, to meet the changing visits at any time, it is necessary to expand and shrink software, and improve resource utilization rate. In relevant fields, although there are many researches on automatic deployment, automatic operation, automatic maintenance, automatic upgrade, and many methodologies, there are few comprehensive schemes that integrate horizontal expansion of microservice software with automatic deployment. This paper focuses on automatic horizontal expansion of container multi-instance system, and design a scheme of system automation horizontal expansion. A simple verification plan integrating software developing, software building, image production, system deployment, system maintenance, and horizontal expansion is designed. Through construction and testing of actual prototype system, the scheme utility and stability are verified. Meanwhile, this scheme is simple and easy to manage, and can meet expansion requirements of most system.
Sparse Code Multiple Access (SCMA) is a promising code-based multiple access technique for achieving higher spectral efficiency and massive connectivity that is crucially required in the B5G applications such as massive machine-type communication (mMTC). Traditional SCMA receivers use Maximum Likelihood (ML) and Message Passing Algorithm (MPA) for signal decoding, which nonetheless suffer from extremely high computational complexity. To resolve the issue, we propose to use Graph Neural Networks (GNN) to replace MPA for decoding, aiming at reducing the decoding complexity while maintaining satisfactory Bit Error Rate (BER) performance. Simulation results show that our proposed solution can achieve much higher decoding accuracy and faster decoding speed.
The use of mobile ad hoc networks (MANET) is increasingly widespread and the applications of this technology are numerous. MANETs are formed by a set of mobile nodes that form a dynamic structure and operate autonomously without requiring infrastructure. The capacity of nodes is restricted in terms of resources, energy, bandwidth, and memory. The performance of MANETs is influenced by the mobility of the nodes and the limitations of their resources. Energy consumption is one of the major drawbacks of MANETs because the nodes are equipped with limited batteries, which degrade their mobility. Additionally, node mobility leads to link instability, which reduces the data delivery ratio. In this paper, we propose an energy aware and link-stability routing protocol based on a differential evolution algorithm named ES-RPDE. Our routing protocol chooses the best path among the paths resulting after the end of the differential evolution algorithm according to the best fitness function, which is based on two constraints: energy and stability of the link. The performance of our solution is compared to the OPAOMDV-EE and AOMDV protocols. The results show that our ES-RPDE protocol improves network performance, provides more efficiency and reliability, and ensures minimal energy consumption.
In view of the increasingly prominent problem of malicious attacks in the current network security field, this study proposes a malicious attack detection and evaluation method based on entropy increase analysis. In the GNS3 virtual network experimental environment, malicious attacks are simulated and system performance is monitored. By applying the entropy increase calculation method, the attacked system is successfully identified and its stability is evaluated. The experimental results show that this entropy increase-based method is feasible and effective, and can detect malicious attacks more accurately and take timely countermeasures to protect the security and stability of the network system and improve the network security defense capability.
Millions of smart contracts are deployed on various blockchain platforms, involving extensive digital assets. However, vulnerabilities within these smart contracts have resulted in substantial exploitation and asset losses. Traditional methods for detecting smart contract vulnerabilities are limited by their narrow detection range and enormous computational cost. This paper investigates how large language models (LLMs), particularly ChatGPT 4, can be leveraged to detect vulnerabilities in smart contracts. We conduct a comprehensive survey of several existing detection methods for smart contract vulnerabilities. Meanwhile, we design a variety of prompt information, and added contract opcodes and expert rules as auxiliary information. Utilizing ChatGPT, we evaluate the effectiveness of the large language model in identifying vulnerabilities across two datasets. The experimental results demonstrate that ChatGPT, informed by specific prompts, can effectively pinpoint vulnerabilities, highlighting the utility of LLMs in enhancing the security of smart contracts.
This paper develops a physical layer authentication (PLA) scheme based on the channel characteristics of cascade channels in unmanned aerial vehicles (UAVs) communication systems augmented by intelligent reflective surface (IRS) to counteract identity spoofing attacks. Particularly, we model the cascade communication channel of the IRS-assisted UAV communication systems as an equivalent point-to-point Nakagami fading channel and formulate the PLA problem as a binary hypothesis test. We use the energy measurement of the received signal as a test statistic and derive its probability density function (PDF), conducted to validate the effectiveness of our proposed scheme.
This paper delves into the time-efficient covert multicast in a wireless communication system facilitated by Unmanned Aerial Vehicle (UAV), in which the UAV aims to disseminate a common covert information to multiple ground users (GUs) while suffering from the risk of detection by a ground warden (Willie). For a given flying location of the UAV, we first develop a theoretical framework for performance modeling of both the detection error probability at Willie and the transmission time at UAV, and then explore the optimal setting of UAV transmit power to achieve the minimum transmission time at this location. We further propose a Particle Swarm Optimization (PSO)-based algorithm to jointly optimize the UAV’s flying location and transmit power to achieve the overall minimum transmission time. Finally, the efficiency of the proposed PSO-based algorithm is substantiated through extensive numerical results.