3 papers
cs.CR2025
Rethinking Broken Object Level Authorization Attacks Under Zero Trust Principle
Anbin Wu, Zhiyong Feng, Ruitao Feng +2
RESTful APIs facilitate data exchange between applications, but they also expose sensitive resources to potential exploitation. Broken Object Level Authorization (BOLA) is the top…
cs.CR2025
CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality Shift
Jiongchi Yu, Xiaofei Xie, Qiang Hu +6
With the rapid advancement of cloud-native computing, securing cloud environments has become an important task. Log-based Anomaly Detection (LAD) is the most representative techniq…
cs.CR2025
FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection
Shiwen Song, Xiaofei Xie, Ruitao Feng +2
Graph-based detection methods leveraging Function Call Graphs (FCGs) have shown promise for Android malware detection (AMD) due to their semantic insights. However, the deployment…