|
|
|
题名
|
作者
|
年代
|
出处
|
被引量
|
| 1 | A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network显示文摘Command and control(C2)servers are used by attackers to operate communications.To perform attacks,attackers usually employee the Domain Generation Algorithm(DGA),with which to confirm rendezvous points to their C2 servers by generating various network locations.The detection of DGA domain names is one of the important technologies for command and control communication detection.Considering the randomness of the DGA domain names,recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names.However,these methods are insufficient to handle wordlist-based DGA threats,which generate domain names by randomly concatenating dictionary words according to a special set of rules.In this paper,we proposed a a deep learning framework ATT-CNN-BiLSTMfor identifying and detecting DGA domains to alleviate the threat.Firstly,the Convolutional Neural Network(CNN)and bidirectional Long Short-Term Memory(BiLSTM)neural network layer was used to extract the features of the domain sequences information;secondly,the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names.Finally,the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification.Our extensive experimental results demonstrate the effectiveness of the proposed model,both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones.To be precise,we got a F1 score of 98.79%for the detection and macro average precision and recall of 83%for the classification task of DGA domain names. | Fangli Ren Zhengwei Jiang Xuren Wang Jian Liu | 2020 | Cybersecurity2020,3,1: | 4 |
| 2 | Isolation of Mouse Marrow Mesenchymal Progenitors by a Novel and Reliable Method显示文摘 | Shengkun Sun Zikuan Guo Xuren Xiao | 2003 | Stem Cells2003,21,: | 1 |
| 3 | Composite repair to aluminum alloy plate by photoinitiated and thermal curing显示文摘 | Zhao Peizhong Hu Fangyou Huang Xuren | 2013 | Journal of Composite Materials2013,47,9: | 1 |
| 4 | Composite repair to aluminum alloy plate by photoinitiated and thermal curing显示文摘 | Zhao Peizhong Hu Fangyou Huang Xuren | 2013 | Journal of Composite Materials2013,47,9: | 1 |
| 5 | TriCTI:an actionable cyber threat intelligence discovery system via trigger-enhanced neural network显示文摘The cybersecurity report provides unstructured actionable cyber threat intelligence(CTI)with detailed threat attack procedures and indicators of compromise(IOCs),e.g.,malware hash or URL(uniform resource locator)of command and control server.The actionable CTI,integrated into intrusion detection systems,can not only prioritize the most urgent threats based on the campaign stages of attack vectors(i.e.,IOCs)but also take appropriate mitigation measures based on contextual information of the alerts.However,the dramatic growth in the number of cybersecurity reports makes it nearly impossible for security professionals to find an efficient way to use these massive amounts of threat intelligence.In this paper,we propose a trigger-enhanced actionable CTI discovery system(TriCTI)to portray a relationship between IOCs and campaign stages and generate actionable CTI from cybersecurity reports through natural language processing(NLP)technology.Specifically,we introduce the“campaign trigger”for an effective explanation of the campaign stages to improve the performance of the classification model.The campaign trigger phrases are the keywords in the sentence that imply the campaign stage.The trained final trigger vectors have similar space representations with the keywords in the unseen sentence and will help correct classification by increasing the weight of the keywords.We also meticulously devise a data augmentation specifically for cybersecurity training sets to cope with the challenge of the scarcity of annotation data sets.Compared with state-of-the-art text classification models,such as BERT,the trigger-enhanced classification model has better performance with accuracy(86.99%)and F1 score(87.02%).We run TriCTI on more than 29k cybersecurity reports,from which we automatically and efficiently collect 113,543 actionable CTI.In particular,we verify the actionability of discovered CTI by using large-scale field data from VirusTotal(VT).The results demonstrate that the threat intelligence provided by VT lacks a part of the threat context for IOCs,such as the Actions on Objectives campaign stage.As a comparison,our proposed method can completely identify the actionable CTI in all campaign stages.Accordingly,cyber threats can be identified and resisted at any campaign stage with the discovered actionable CTI. | Jian Lu Junjie Yan Jun Jiang Yitong He Xuren Wang Zhengwei jiang Peian Yang Ning Li | 2022 | Cybersecurity2022,5,3: | 1 |
| 6 | Isolation of mouse marrow mesenchymal progenitors by a novel and reli- able method 显示文摘 | SUN ShengKun GUO ZiKuan XIAO XuRen | 2003 | Stem cells2003,21,5: | 1 |
| 7 | SunXiang-jun(孙湘君),TaoJun-rong(陶君容),OnthediscoveryofaQuercussemicarpifoliabedinmountShihaPangmaanditssignificanceinbotanyandgeology显示文摘 | XuRen(徐仁) | | 植物学报0,,: | 1 |
| 8 | TIM: threat context-enhanced TTP intelligence mining on unstructured threat data显示文摘TTPs (Tactics, Techniques, and Procedures), which represent an attacker’s goals and methods, are the long period and essential feature of the attacker. Defenders can use TTP intelligence to perform the penetration test and compensate for defense deficiency. However, most TTP intelligence is described in unstructured threat data, such as APT analysis reports. Manually converting natural language TTPs descriptions to standard TTP names, such as ATT&CK TTP names and IDs, is time-consuming and requires deep expertise. In this paper, we define the TTP classification task as a sentence classification task. We annotate a new sentence-level TTP dataset with 6 categories and 6061 TTP descriptions from 10761 security analysis reports. We construct a threat context-enhanced TTP intelligence mining (TIM) framework to mine TTP intelligence from unstructured threat data. The TIM framework uses TCENet (Threat Context Enhanced Network) to find and classify TTP descriptions, which we define as three continuous sentences, from textual data. Meanwhile, we use the element features of TTP in the descriptions to enhance the TTPs classification accuracy of TCENet. The evaluation result shows that the average classification accuracy of our proposed method on the 6 TTP categories reaches 0.941. The evaluation results also show that adding TTP element features can improve our classification accuracy compared to using only text features. TCENet also achieved the best results compared to the previous document-level TTP classification works and other popular text classification methods, even in the case of few-shot training samples. Finally, the TIM framework organizes TTP descriptions and TTP elements into STIX 2.1 format as final TTP intelligence for sharing the long-period and essential attack behavior characteristics of attackers. In addition, we transform TTP intelligence into sigma detection rules for attack behavior detection. Such TTP intelligence and rules can help defenders deploy long-term effective threat detection and perform more realistic attack simulations to strengthen defense. | Yizhe You Jun Jiang Zhengwei Jiang Peian Yang Baoxu Liu Huamin Feng Xuren Wang Ning Li | 2022 | Cybersecurity2022,5,2: | 1 |
| 9 | MHD, Heat transfer and stress analysis for the ITER self-cooled blanket de sign显示文摘 | Mogahed E A Sviatoslavsky I N | 1994 | Fusion Engineering and design1994,24,4: | 1 |
| 10 | Survivin gene expression increases gastric cancer cell lymphatic metastasisby upregulating vascular endothelial growth factor-C expression levels显示文摘 | Junyan Zhang Zhi Zhu Zhe Sun Xuren Sun Zhenning Wang Huimian Xu | 2014 | Molecular Medicine Reports2014,,2: | 1 |
| 11 | A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network显示文摘Command and control(C2)servers are used by attackers to operate communications.To perform attacks,attackers usually employee the Domain Generation Algorithm(DGA),with which to confirm rendezvous points to their C2 servers by generating various network locations.The detection of DGA domain names is one of the important technologies for command and control communication detection.Considering the randomness of the DGA domain names,recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names.However,these methods are insufficient to handle wordlist-based DGA threats,which generate domain names by randomly concatenating dictionary words according to a special set of rules.In this paper,we proposed a a deep learning framework ATT-CNN-BiLSTMfor identifying and detecting DGA domains to alleviate the threat.Firstly,the Convolutional Neural Network(CNN)and bidirectional Long Short-Term Memory(BiLSTM)neural network layer was used to extract the features of the domain sequences information;secondly,the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names.Finally,the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification.Our extensive experimental results demonstrate the effectiveness of the proposed model,both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones.To be precise,we got a F1 score of 98.79% for the detection and macro average precision and recall of 83% for the classification task of DGA domain names. | Fangli Ren Zhengwei Jiang Xuren Wang Jian Liu | 2018 | Cybersecurity2018,1,1: | 0 |
| 12 | Identification of an kB-like motif at the 5' upstream region of human lymphotoxin gene显示文摘Lymphotoxin(LT) is a glycoprotein secreted by activated T cell. The expression of LT gene is mainly regulated at the level of transcription. By using human LT DNA as a probe, we carried out a RNA dot blotting test and found that the longer the time of Jurkat human Tlymphoma cells exposed to the PMA and PHA, the more endogenous LT mRNA could be produced. Results of gel retardation assay showed that the nuclear extract from Jurkat cells treated with PMA and PHA formed different DNA-protein complexes. Changes in complex patterns were observed at various time intervals of PMA and PHA induction. A specific protein-binding site was mapped out to be a 22-bp sequence at the 5’upstream regioll of human LT gene by DNase I footprinting analysis. This region was similar to the sequence recognized by the proteins of NFkB family The results of fragment competition and homology analysis indicated that the 22-bp sequence contains a kB-like motif only which is located at the base pairs -100 to -90 (5’-GGGGGCTTCCC-3’). Thus, the NF-kBlike factors were involved in the protein-DNA interaction.Furthermore, there were more than one retarded bands appearing in the gel retardation assay. It suggested that there may be several NF-kB-like factors involved in theregulation of LT gene transcription at the same site. | XURENER SHOUYUANZHAO | 1994 | Cell Research1994,4,1: | 0 |