most citedShrinking the Kernel Attack Surface Through Static and Dynamic Syscall Limitation

21 citations · 29 across the 6 of their papers we have counts for

collaborators

6 papers

cs.CR20258 cited

Securing Operating Systems Through Fine-grained Kernel Access Limitation for IoT Systems

Dongyang Zhan, Zhaofeng Yu, Xiangzhan Yu +3

With the development of Internet of Things (IoT), it is gaining a lot of attention. It is important to secure the embedded systems with low overhead. The Linux Seccomp is widely us…

cs.CR202521 cited

Shrinking the Kernel Attack Surface Through Static and Dynamic Syscall Limitation

Dongyang Zhan, Zhaofeng Yu, Xiangzhan Yu +2

Linux Seccomp is widely used by the program developers and the system maintainers to secure the operating systems, which can block unused syscalls for different applications and co…

cs.CR2025

A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection

Kai Tan, Dongyang Zhan, Lin Ye +3

As cloud computing continues to advance and become an integral part of modern IT infrastructure, container security has emerged as a critical factor in ensuring the smooth operatio…

cs.CR2025

A Practical Adversarial Attack against Sequence-based Deep Learning Malware Classifiers

Kai Tan, Dongyang Zhan, Lin Ye +2

Sequence-based deep learning models (e.g., RNNs), can detect malware by analyzing its behavioral sequences. Meanwhile, these models are susceptible to adversarial attacks. Attacker…

cs.CR2025

Anomaly Detection in Industrial Control Systems Based on Cross-Domain Representation Learning

Dongyang Zhan, Wenqi Zhang, Lin Ye +3

Industrial control systems (ICSs) are widely used in industry, and their security and stability are very important. Once the ICS is attacked, it may cause serious damage. Therefore…

cs.CR2025

Exploring and Exploiting the Resource Isolation Attack Surface of WebAssembly Containers

Zhaofeng Yu, Dongyang Zhan, Lin Ye +3

Recently, the WebAssembly (or Wasm) technology has been rapidly evolving, with many runtimes actively under development, providing cross-platform secure sandboxes for Wasm modules…