Yan Zhang 0014

dblp:04/3348-14 · DBLP profile ↗
← Back
31ranked-venue papers
0as first author
17since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 4 since 2021Security and privacy · 7 · 6 since 2021Systems, architecture and hardware · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 BKPIR: Keyword PIR for Private Boolean Retrieval
Zhen Xu 0009, Yan Zhang 0014, Pengwei Zhan, Shuai Ma 0001, Ru Xie
NDSS3
2025 Adaptive Layered-Trust Robust Defense Mechanism for Personalized Federated Learning
abstract
Personalized Federated Learning (PFL) is confronted with escalating security threats, yet existing defense strategies primarily concentrate on traditional federated learning, lacking robust defense mechanisms tailored for PFL. To fortify the robustness of PFL against stealthy malicious attacks, we propose an adaptive layered-trust robust defense mechanism, PFL-ALB. Firstly, we employ a layer gradient parameter similarity matrix to detect the malicious parameters of advanced stealthy backdoor attacks, and then conduct layer-wise robust aggregation on the server to enhance the robustness of the global model. Subsequently, we propose a client-adaptive personalized layering method, which adaptively partitions each client’s model into personalized and shared layers. This approach balances accuracy and robustness under heterogeneous data conditions while mitigating the impact of malicious attacks. Experimental results demonstrate that PFL-ALB significantly enhances robustness (with ASR remarkably reduced to within 1%-10%) under three types of advanced stealthy backdoor attacks and exhibits superior performance compared to existing defense schemes.
Zhen Xu 0009, Yan Zhang 0014, Yu Wang 0243
ICASSP3
2025 VaniKG: Vanishing Key Gradient Attack and Defense for Robust Federated Aggregation
Hongjia Li 0002, Leshui Lv, Ding Tang, Yan Zhang 0014, Weiping Wang 0005, Xinghua Yang
INFOCOM4
2025 A Heterogeneous GNN Based Trust Evaluation Method for Remote Desktop Access
abstract
The remote desktop is widely used in enterprise environments. To improve its security, Zero Trust is generally introduced to replace the traditional perimeter-based model with dynamic trust evaluation and continuous verification. However, for the remote desktop system, where access chain topology can be abstracted as a graph consists of users, terminals, VMs and connections between them, classical dynamic trust evaluation approaches rely simply on users’ features collected from user-terminal interactions. They ignore features from remained parts of graph, such as terminal itself (as access medium) and status of virtual machines (as access target). Recent graph neural network (GNN) models are dedicated to fusing features from multiple sources in graph structure; however, they are often designed for low-heterogeneity domains and are thus not well suited to the heterogeneous interactions in remote desktop access. To address these challenges, we propose a heterogeneous graph neural network (HGNN) framework for trust evaluation in remote desktop systems. In particular, we model users, terminals, and virtual machines as distinct node types and represent their interactions as a heterogeneous graph, upon which we apply HGNN to aggregating multi-type relational information. This enables comprehensive and adaptive trust estimation tailored to the characteristics of remote desktop environments. Experiments on real-world datasets demonstrate that our method consistently outperforms baselines in terms of accuracy, precision, recall, and F1-score in the trust-level prediction task, confirming the effectiveness of heterogeneous graph modeling and neural-based aggregation in improving trust evaluation performance.
Haishuo Zhang, Huiran Yang, Hongjia Li 0002, Yan Zhang 0014, Weiping Wang 0005, Ding Tang
TrustCom4
2025 PEAR: privacy-preserving and effective aggregation for byzantine-robust federated learning in real-world scenarios
abstract
Abstract Federated learning (FL) enables collaborative training of global models among distributed clients without sharing local data. Secure aggregation, a new security primitive of FL, enhances the confidentiality of data and model parameters. Unfortunately, privacy-preserving (PP) FL is vulnerable to common poisoning attacks by Byzantine adversaries. Existing defense strategies mainly focus on identifying abnormal local gradients over plaintexts, which provides a weak privacy guarantee. In PPFL, adversaries can escape existing defenses by uploading encrypted poisonous gradients. In addition, most mainstream aggregation algorithms assume that clients’ local training data is uniformly distributed, Independent and Identically Distributed (IID), which is unrealistic for real-world FL scenarios where data are only stored on large-scale terminal devices. To address these issues, we propose PEAR, a PP aggregation strategy based on single key-dual server CKKS full homomorphic encryption in real-world distributed scenarios, which can resist encrypted poisoning attacks. Specifically, we use cosine similarity to measure the distance between encrypted gradients. Then, we propose a novel Byzantine-tolerance aggregation mechanism using cosine similarity, which includes trust score generation that can tolerate differentiated local gradients and a two-step weight generation method that considers both the degree of gradient deviation in direction and training data size. This mechanism can achieve robustness for both IID and non-IID data without compromising privacy. Our extensive evaluations for two typical poisoning attacks on different datasets show that PEAR is robust and effective in IID and non-IID data and outperforms existing mainstream Byzantine-robust algorithms, especially achieving 16.4% to 53.2% testing error rate reduction in non-IID settings with significant label distribution and quantity skew while maintaining the same efficiency as FedAvg.
Yan Zhang 0014, Huiping Zhuang, Zhen Xu 0009, Liji Wu
Comput. J.2
2024 ConProv: A Container-Aware Provenance System for Attack Investigation
abstract
With high resource utilization and flexibility, containers have gained widespread adoption across various computing environments. However, container security has emerged as a primary concern as container-based services grow rapidly. Identifying intrusions’ root cause and impact remains a foundational challenge in container security. Provenance reflects the causal relationships of events, which can significantly aid security personnel in analyzing container attacks. Despite existing provenance-based solutions providing extensive system information, there remains a lack of provenance systems specifically focused on container security. We present ConProv, which offers concise and precise provenance analysis of in--container activities, making it highly suitable for container security investigations. Through our analysis of container escape attack techniques, it is found that most attacks are caused by excessive permissions and incomplete file subsystem isolation. Based on this insight, we identified the key role that capabilities and file path attributes play in container provenance, which helps guide investigators to pinpoint suspicious events quickly. We developed a prototype implementation of ConProv and designed methods to capture these essential attributes accurately. Our evaluation shows that ConProv outperforms existing provenance systems in container attack investigations while incurring low overhead (<10%).
Qiqing Deng, Yanqiang Zhang, Zhen Xu 0009, Yan Zhang 0014
ACSAC5
2024 5GC-SDP: Security Enhancement of 5G Core Networks With Zero Trust
abstract
The 5G core network (5GC) architecture based on Service-Based Architecture (SBA) has brought unprecedented flexibility and innovation. However, this architecture also comes with potential security challenges. The integration of different signaling protocols and the complexity of virtualization in 5GC have increased security risks within the core network. The concept of zero trust is considered a new solution, and Software-Defined Perimeter (SDP) represents a best practice for zero trust. In this paper, we propose a 5GC-SDP architecture that provides secure communication within the core network through authentication-based methods. Single Package Authorization (SPA) is the key technology of this study. Only Network Functions (NF) that have been authenticated and authorized by SPA can access each other. To the best of our knowledge, this is the first study to combine SDP with StandAlone (SA) 5GC. At the same time, we fully consider that although SPA technology can withstand most DoS attacks, DoS attacks caused by SPA packets will still become a problem. Therefore, we design a SPA enhancement module, and machine learning algorithms are used for SPA-DoS detection. We have conducted practical exploration on the proposed 5GC-SDP architecture and implemented testing on port scanning, DoS, and DDoS attacks. The experiments have shown that 5GC-SDP achieves enhanced protection of the core network by limiting network exposure and implementing fine-grained access control.
Zeqing Yan, Guangxi Yu, Mengqi Zhan, Yan Zhang 0014, Jiaxi Hu
CSCWD4
2024 Rumor Detection with News Environment Enhanced Propagation Structure
Yanqiang Zhang, Zhen Xu 0009, Yan Zhang 0014, Pengwei Zhan
ICIC (13)5
2023 CP Decomposition and Set Theory based Root Cause Analysis in Online Service Systems
abstract
As cloud-native technologies continue to proliferate, fault diagnosis has become a critical aspect of online service systems. Operators tasked with fault diagnosis face the challenge of analyzing a wide range of monitoring metrics. These metrics often have missing data, adding complexity to the process. Their main goal is to locate faults among multiple components and find similar faults to develop effective solutions. However, prevailing methodologies fail to tightly integrate fault localization and fault correlation technologies, leading to suboptimal performance in root cause analysis. In this paper, we present a root cause analysis framework, SetRCA, that accurately localizes faults and offers interpretable identification of similar faults. To achieve this, we integrate the correlations between each pair of metrics with their temporal features for data interpolation using CP decomposition. Subsequently, the components in online service systems are ranked based on scores derived from the Personalized PageRank algorithm, using the filled data. Innovatively, the inclusion relationships between sets of abnormal metrics are employed to locate system faults. Ultimately, the solution is determined by examining the similarity between the current fault components and historical faults. An extensive study on two public datasets demonstrates the accuracy and interpretability of our proposed model.
Qianbo Wei, Yan Zhang 0014, Zhen Xu 0009, Hongyan Tan
APSEC3
2023 MK-FLFHNN: A Privacy-Preserving Vertical Federated Learning Framework For Heterogeneous Neural Network Via Multi-Key Homomorphic Encryption
abstract
The security and privacy of Vertical federated learning (VFL) deserve attention due to the computationally strong dependency between participants, which requires frequent and direct interactions. The existing Privacy-preserving (PP) VFL schemes are often limited by the model types supported, the communication cost and the number of participants. To alleviate this issue, we propose MK-FLFHNN, a novel PP framework for heterogeneous neural networks based on xMK-CKKS multi-key homomorphic encryption. The algorithm eliminates the limitation of traditional algorithms limited to generalized linear models and prevents the privacy leakage of shared information while solving the problem of potential leakage from the aggregated values of federated learning, adapting according to the number of participants and supporting flexible expansion to multi-party scenarios. Most importantly, for three-party and above scenarios, the framework is robust to collusion between K
Yan Zhang 0014, Zhen Xu 0009, Runmei Zhang
CSCWD2
2023 CACluster: A Clustering Approach for IoT Attack Activities Based on Contextual Analysis
abstract
Attacks against IoT have shown a rapid increase in both quantity and complexity. Analysts must handle massive alerts and determine the type of attack manually. In addition, the same attack activity may present polymorphism alert sequences due to overlapping attacks, adaptive attack strategy, error alerts, etc, which poses a severe challenge for human analysis. This manual-dependent and scenario-by-scenario security model is seriously overwhelming security analysts. This paper proposes a contextual-analysis-based clustering approach, CACluster, to aggregate similar attack activities end-to-end. It embeds alert context into vector space and uses an unsupervised clustering method to find similar attack activities based on domain matching and vector distance. Experimental results demonstrate that the CACluster could accurately aggregate similar attack activities, with 0.888 purity, reducing the number of attack activities by 84.8%. It will significantly cut down analysts’ workload.
Huiran Yang, Yan Zhang 0014, Yueyue Dai, Jiyan Sun, Huajun Cui, Can Ma, Weiping Wang 0005
ICPADS2
2023 LActDet: An Automatic Network Attack Activity Detection Framework for Multi-step Attacks
abstract
With the evolution of attack tactics, cyber-attacks are presenting a sophisticated trend. The multi-step attack has become the mainstream attack form, where adversaries implement multiple attack steps to achieve their goals, which poses server challenges to attack detection. Traditional research mainly concentrates on how a particular attack step is exploited but fails to identify the whole attack activity automatically. Manual analysis is required to correlate multiple steps and determine the fine-grained type of attack activities, which is a heavy workload. In addition, the high error rate of alerts results in a negative impact on attack-activity detection performance.To address these challenges, we propose a framework, LActDet, to automatically identify attack activities from the raw alerts end-to-end. Firstly, it utilizes a document-embedding method to vectorize attack-event descriptions. Second, a seq2seq model is implemented to embed the attack-event sequence into the attack-phase sequence to represent the framework of attack activity, aiming at improving the fault tolerance for error alerts. In the end, we propose a temporal-sequence-based classifier to identify attack activities. Our experimental results demonstrate that LActDet achieves higher detection accuracy, lower artificial dependence, and less system overhead.
Huiran Yang, Jiaqi Kang, Yueyue Dai, Jiyan Sun, Yan Zhang 0014, Huajun Cui, Can Ma
TrustCom5
2023 GuardBox: A High-Performance Middlebox Providing Confidentiality and Integrity for Packets
abstract
The deepening of digital transformation has led to an increasing amount of data from industries being transmitted over the Internet. However, packets in plaintext originally designed for transmission in private networks suffer from significant security threats on the Internet. Unfortunately, existing encryption schemes, such as the representative TLS, are difficult to be applied to these industrial protocols due to their specific requirements and conditions such as low latency requirements and restricted operating environments. In this paper, we present a high-performance encryption/decryption middlebox called GuardBox to provide confidentiality and integrity for packets. GuardBox is expected to transparently encrypt/decrypt packets sent/received by protected industrial equipment with low latency and supports almost any application-layer protocol. To do that, we design a high-performance packet I/O framework and an optimized encryption/decryption scheme for GuardBox. More importantly, we use commodity trusted hardware, Intel SGX, to ensure the security of keys and the encryption/decryption process. Our extensive evaluation demonstrates that GuardBox can provide confidentiality and integrity for packets transmitted over the Internet with low latency and a near-native throughput.
Mengqi Zhan, Yang Li 0192, Guangxi Yu, Yan Zhang 0014, Bo Li 0063, Weiping Wang 0005
IEEE Trans. Inf. Forensics Secur.4
2023 Website-Aware Protocol Confusion Network for Emergent HTTP/3 Website Fingerprinting
abstract
Website fingerprinting is exploited to analyze encrypted traffic traces and infer the visited website. Existing website fingerprinting methods can achieve satisfying performance for the HTTP traffic visiting websites over TCP. Recently, a new protocol QUIC has been proposed, and HTTP-over-QUIC has been formalized as the next generation HTTP, named HTTP/3. Thus, it is necessary to classify HTTP/3 traces. However, since HTTP/3 is newly proposed and is being deployed, it is difficult to collect a large number of HTTP/3 traces. Intuitively, we can use sufficient TCP traces to improve the performance of the QUIC trace classifier. Unfortunately, the protocol discrepancy exists between TCP and QUIC traces, which undermines the generalization ability of the classifier. In this paper, for practical website fingerprinting of HTTP/3, we propose a Website-Aware Protocol Confusion Network (WAPCN), which exploits only a few QUIC traces to train a website classifier with the help of lots of available TCP traces. It consists of four main parts: a feature extractor, a website classifier, a protocol discriminator, and a website-aware adaptor. The feature extractor aims to extract trace representations from both TCP and QUIC traces. It cooperates with the website classifier to learn the discriminative representation for the website classification. The role of the protocol discriminator is to confuse protocols and guide the feature extractor to learn protocol-invariant representations. The website-aware adaptor can enhance protocol-invariant representations to be aware of the website classification boundary. Extensive experiments are conducted on various tasks to demonstrate the effectiveness of WAPCN.
Mengqi Zhan, Yang Li 0192, Yongchun Zhu, Guangxi Yu, Yan Zhang 0014, Bo Li 0063, Weiping Wang 0005
IEEE Trans. Inf. Forensics Secur.5
2022 LibHunter: An Unsupervised Approach for Third-party Library Detection without Prior Knowledge
abstract
Third-party libraries (TPLs) are a significant component of mobile apps. They provide various functionalities, and developers employ them to facilitate app development. TPL detection is a fundamental task in security research, as it can impact other security studies. TPL can act as an assistant to malware detection, privacy leakage detection, etc. Because if a TPL carries malicious code, all apps that integrate the TPL can be considered risky. However, in some studies, TPLs can also act as noise, like app traffic fingerprinting. The TPL and app traffic are mixed during app runtime, making it difficult to fingerprint the app traffic accurately. Unfortunately, all existing TPL detection studies are working with prior knowledge of TPLs, as they need a whitelist or a train on known TPLs. However, new TPLs keep emerging, and it is not feasible for existing works to identify them-especially those who have network behaviors, as they may transfer inappropriate contents in the network. To this end, we propose LibHunter - an approach to identify TPLs without prior knowledge. LibHunter inspects the HTTP(S) traffic, logs the corresponding code execution traces, extracts features from the collected data, and performs a clustering algorithm to obtain TPLs. We apply LibHunter to 3000 apps. Results demonstrate that LibHunter can identify 79 TPLs, and about 60% of them are not detected by all existing works. We perform an analysis to show how important these TPLs are; we also present the visiting graph of these TPLs. Our findings bring light to the research community that existing tools are not accurate when encountering contemporary apps.
Huajun Cui, Guozhu Meng, Yuejun Li, Yan Zhang 0014, Jiyan Sun, Dali Zhu, Weiping Wang 0005
ISCC5
2022 ActDetector: A Sequence-based Framework for Network Attack Activity Detection
abstract
The cyber security situation is not optimistic in recent years due to the rapid growth of security threats. What's more worrying is that threats are tending to be more sophis-ticated, which poses challenges to attack activity analysis. It is quite important for analysts to understand attack activities from a holistic perspective, rather than just pay attention to alerts. Currently, the attack activity analysis generally relies on human resources, which is a heavy workload for manual analysis. Besides, it's difficult to achieve high detection accuracy due to the missing and false-positive alerts. In this paper, we propose a new framework, ActDetector, to detect attack activities automatically from the raw Network Intrusion Detection System (NIDS) alerts, which will greatly reduce the workload of security analysts. We extract attack phase descriptions from alerts and embed attack activity descriptions to obtain their numerical expression. Finally, we use a temporal-sequence-based model to detect potential attack activities. We evaluate ActDetector with three datasets. Experimental results demonstrate that ActDetector can detect attack activities from the raw NIDS alerts with an average of 94.8% Precision, 95.0% Recall, and 94.6% F1-score.
Jiaqi Kang, Huiran Yang, Yan Zhang 0014, Yueyue Dai, Mengqi Zhan, Weiping Wang 0005
ISCC3
2022 Automated Privacy Network Traffic Detection via Self-labeling and Learning
abstract
With the increasing popularity of mobile devices, privacy leakage has become more and more serious. The inappropriate behaviors of mobile APPs have brought substantial security risks to the public (e.g., location leakage). Existing solutions detect privacy leakage based on network traffic analysis. However, they can only detect unencrypted traffic, which leads to failures in the face of encrypted traffic. To solve this challenge, we designed an Automated Privacy Traffic Detection system (APTD). APTD can automatically generate self-labeling privacy traffic datasets, learn to identify the encrypted privacy traffic, and accurately assess the risk of privacy leakage. Due to its automation capability, APTD can directly support privacy leakage detection for newly-emerged applications without any system changes. To comprehensively evaluate APTD, we conducted an experiment on 2327 real-world mobile APPs. APTD automatically generated a labeled dataset containing 27343 real-world encrypted traffic traces. Based on the dataset, APTD identifies privacy traffic, and performs a privacy leakage risk assessment of APPs. The results show that APTD achieves 97% accuracy and 99% recall on our dataset and identifies 12 APPs that transmit high-risk privacy data.
Yuejun Li, Huajun Cui, Jiyan Sun, Yan Zhang 0014, Guozhu Meng, Weiping Wang 0005
ISCC4
2020 A Feedback Mechanism for Prediction-based Anomaly Detection In Content Delivery Networks
abstract
CDN (Content Delivery Network) has become an important infrastructure of the Internet. However, building an anomaly detection system to monitor and guarantee CDN service quality is non-trivial. Current anomaly detection system usually suffers from undesirable performance in terms of high rate of false positive and false negative, which consequently impacts on its practical deployment. Identifying the root cause of a false detection is critical for diagnosing and improving the performance of anomaly detection. In this paper, we propose a novel feedback mechanism for prediction-based anomaly detection in CDN . Specifically, we introduce a carefully-designed metric named Fittingscore to diagnose whether the prediction model can fit the data well. Further, a threshold adjustment mechanism is proposed to dynamically adjust the thresholds of residual errors. Extensive experiments employing a three-month real CDN dataset collected from a top ISP-operated CDN in China show our proposed method can significantly improve the performance of anomaly detection.
Zhilei Liu, Tao Lin 0001, Jiyan Sun, Yanjie Hu, Yan Zhang 0014, Zhen Xu 0009
ISCC6
2019 Towards Homograph-Confusable Domain Name Detection Using Dual-Channel CNN
Guangxi Yu, Xinghua Yang, Yan Zhang 0014, Huajun Cui, Huiran Yang, Yang Li 0192
ICICS3
2019 Mitigating Negative Impacts on DNS Caches Caused by Disposable Domain Names
abstract
DNS caches play an important role in DNS querying. However, the performance of DNS caches will be remarkably influenced by disposable domain names, which are generated by services of cloud storage, social networks, etc., and belong to a new class of misused case of DNS. In this paper, we proposed a novel solution named DC3(Domain Classification and Cascade Cache) to mitigate the negative impact. Domain Classification adopts a classifier which is based on a long short-term memory (LSTM) network to prevent disposable domains from being cached. Cascade Cache is a refined cascade LRU policy considering cache size allocation to process the remaining disposable domains. By querying the real DNS traces collected from a large ISP network, experiment results show that this solution can detect disposable domain names and mitigate their negative impacts on DNS caches effectively. Specifically, in our dataset, 67.4% of all distinct domain names are detected as disposable domain names. Correspondingly, when getting rid of them by using this solution, we can raise the cache hit rate more than double.
Guangxi Yu, Yan Zhang 0014, Huajun Cui, Xinghua Yang, Yang Li 0192
ISCC2
2018 Virtualized Security Function Placement for Security Service Chaining in Cloud
abstract
Security Service Chaining (SSC) has recently shown great potential to address cloud security problems. A key point to implement SSC is Virtualized Security Functions (VSF) placement, which is a special kind of VNF placement. However, the existing solutions of VNF placement have not considered traffic reachability problem and policy conflict problem, which should be addressed for SSC. In this paper, we study the issue of VSF placement for SSC in cloud, and propose a solution named MCE (Map, Check reachability, and Eliminate conflict). In the framework of MCE, we first formulate an optimization model for VSF and VL mapping, which is NP-hard and can be solved by existing mapping algorithms. Next, we propose to use HSA method to find and delete some improper mapping results where traffic reachability can't be satisfied. Finally, we propose a scheme named BSIS-RC (Bit Sequence Intersection and Subtraction based Rule Computation), which is based on our work on the formula expression of security policies, the definition of policy spaces, bit sequence subtraction rule and the definition of policy relationships. BSIS-RC can check and eliminate policy conflicts quickly and effectively. We combine MCE with three existing mapping algorithms and compare the performance of six solutions through simulations. Results show that, compared with three solutions not considering the problems of traffic reachability and policy conflict, MCE can improve 38% of the SSC request success rate on average and reduce 15% of the total bandwidth consumption per SSC request on average. Moreover, among the three MCE solutions with three different mapping algorithms, MCE with Genetic algorithm has the best performance.
Hongjing Wu, Yan Zhang 0014, Huiran Yang, Guangxi Yu, Jiuyue Cao
ICPADS2
2017 DC2-MTCP: Light-Weight Coding for Efficient Multi-Path Transmission in Data Center Network
abstract
Multi-path TCP has recently shown great potential to take advantage of the rich path diversity in data center networks (DCN) to increase transmission throughput. However, the small flows, which take a large fraction of data center traffic, will easily get a timeout when split onto multiple paths. Moreover, the dynamic congestions and node failures in DCN will exacerbate the reorder problem of parallel multi-path transmissions for large flows. In this paper, we propose DC2-MTCP (Data Center Coded Multi-path TCP), which employs a fast and light-weight coding method to address the above challenges while maintaining the benefit of parallel multi-path transmissions. To meet the high flow performance in DCN, we insert a very low ratio of coded packets with a careful selection of the packets to be coded. We further present a progressive decoding algorithm to decode the packets online with a low time complexity. Extensive ns2-based simulations show that with two orders of magnitude lower coding delay, DC2-MTCP can reduce on average 40% flow completion time for small flows and increase 30% flow throughput for large flows compared to the peer schemes in varying network conditions.
Jiyan Sun, Yan Zhang 0014, Xin Wang 0001, Shihan Xiao, Zhen Xu 0009, Hongjing Wu, Xin Chen 0019, Yanni Han
IPDPS2
2017 Multiple service function chaining under load balance in SDN/NFV networks
abstract
Service Function Chaining (SFC) has received considerable attentions due to its potential in improving the flexibility and efficiency of networks. Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) bring new opportunities for flexibly implementing SFCs by dynamically composing network functions in SDN/NFV networks. In this paper, we first introduce the SFC instantiation for a single path and formulate this procedure as a model of the Shortest Path Tour Problem, and find the minimum delay path for an SFC by exploiting a constructed auxiliary multistage graph. Next, we present a polynomial-time algorithm for finding minimum delay paths for multiple SFCs under the load balance constraint of link utilization. Finally, some experiments are carried out and the results show the effectiveness and efficiency of our proposed method.
Faqiang Liu, Xin Chen 0019, Wei An 0002, Jiuyue Cao, Yan Zhang 0014
PIMRC6
2017 Minimizing transmission cost for multiple service function chains in SDN/NFV networks
abstract
Service Function Chaining (SFC) has received considerable attentions due to its potential in remarkably improving the flexibility and efficiency of networks. Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) are becoming promising ways for realizing SFC. A key feature in SDN/NFV networks is the capability of dynamically composing network functions into complex services. In this paper, we first introduce SFC instantiation and form it as the model of the Shortest Path Tour Problem, then find the minimum transmission cost path with network function order constraints for a single SFC by exploiting a constructed multistage graph. Next, we derive minimum transmission cost paths for multiple SFC classes using the Dijkstra's Shortest Path Algorithm with resource constraints in a flexible way. Finally, some experiments are carried out and the results show the effectiveness and efficiency of our proposed method.
Faqiang Liu, Xin Chen 0019, Wei An 0002, Jiuyue Cao, Yan Zhang 0014
PIMRC6
2017 VNF-FG design and VNF placement for 5G mobile networks
Jiuyue Cao, Yan Zhang 0014, Wei An 0002, Xin Chen 0019, Jiyan Sun, Yanni Han
Sci. China Inf. Sci.2
2016 VNF Placement in Hybrid NFV Environment: Modeling and Genetic Algorithms
abstract
In this paper, we study the VNF placement problem in hybrid NFV environment, which is important during the transition from traditional networks to NFV networks. We first propose a new concept of hybrid NFV environment, which is more comprehensive and realistic than the former works. Then, we give out a novel model of VNF placement optimization to achieve lower bandwidth consumption and lower maximum link utilization simultaneously, with consideration of VNF combination. Next, to solve this problem, we propose four genetic algorithms, which are combinations of the frameworks of two existing algorithms (MOGA and NSGA-II) and our novel modifications. Simulation results show that, in our 4 algorithms Greedy-NSGA-II has the best performance. When compared with other two non-genetic algorithms (BM and Random), the average total bandwidth consumption of Greedy-NSGA-II is only 12.24% and 2.96% of theirs respectively, and the average maximum link utilization of Greedy-NSGA-II is only 25.04% and 13.81% of theirs respectively.
Jiuyue Cao, Yan Zhang 0014, Wei An 0002, Xin Chen 0019, Yanni Han, Jiyan Sun
ICPADS2
2015 TCP-FNC: A novel TCP with network coding for wireless networks
abstract
In this paper, we propose TCP-FNC (TCP with fast network coding), which is designed to reduce the decoding delay for TCP with network coding. TCP-FNC retains the framework of TCP/NC and includes two schemes to meet the demand of online network coding. First, we develop a feedback based scheme named FCWL, which can efficiently reduce the waiting delay and work well with both RTT-based and loss-based TCP variants. Second, we propose an optimized progressive decoding algorithm named EFU for Gaussian-Jordan elimination, which can further reduce the computation delay from O(n2) to O(n). Evaluation results indicate that our TCP-FNC can achieve shorter decoding delay than TCP/NC and VON without trading off its goodput performance. We verify that TCP-FNC can reduce the decoding delay by 33% on average.
Jiyan Sun, Yan Zhang 0014, Ding Tang, Shuli Zhang, Zhijun Zhao, Song Ci
ICC2
2015 OSDT: A scalable application-level scheduling scheme for TCP Incast problem
abstract
TCP Incast refers to the phenomenon of goodput collapse when multiple synchronized servers send data to the same client in parallel. In this paper, we propose a novel application-level scheduling approach named OSDT (Optimal Staggering Data Transfers) for TCP Incast problem. OSDT limits the number of concurrent TCP flows as well as servers' sending rate to optimal values so that the utilization of link capacity can be maximized without any packet losses. To achieve this, we build an optimization model with the usage of network and application information. Based on this model we can get the optimal values for the parameters in OSDT. Simulation results indicate that OSDT can achieve the highest goodput among all existing application-level scheduling approaches in a wide range of network and application parameters, and its performance is stable. So OSDT can be seen as an effective and scalable solution for TCP Incast problem.
Shuli Zhang, Yan Zhang 0014, Yifang Qin, Yanni Han, Zhijun Zhao, Song Ci
ICC2
2015 Improving TCP performance in data center networks with Adaptive Complementary Coding
abstract
TCP suffers from low throughput and high latency because of its expensive timeout based loss recovery mechanism in data center networks (DCNs). In this paper, we propose TCP with Adaptive Complementary Coding (TCP-ACC) to effectively address these problems. Without revising existing TCP congestion control, we first design a light-weight complementary coding scheme to avoid TCP timeout which will result in higher throughput and lower latency. In our scheme, the redundancy setting is adaptive to the real-time packet loss rate. Then we introduce Lyapunov optimization framework to find the optimal number of redundant coding packets for TCP-ACC, and we also prove that TCP-ACC can reduce the flow timeout probability close to that of the optimal complementary coding solution. Extensive NS2 simulations show that, compared with other three solutions for TCP's problems in DCNs, TCP-ACC can reduce the flow completion time by 45% and improve the flow throughput by 40% on average.
Jiyan Sun, Yan Zhang 0014, Ding Tang, Shuli Zhang, Zhen Xu 0009, Jingguo Ge
LCN2
2015 A partial-decentralized coflow scheduling scheme in data center networks
abstract
In this paper, we propose CGM-PS, a partial-decentralized, un-starving, work-conservative, and preemptive coflow scheduling scheme to shorten the Coflow Completion Time (CCT) for TCP flows in data center networks (DCNs). In CGMPS, we propose both inter- and intra- coflow scheduling policies. In inter-coflow scheduling, we present P-SEBF, which adopts a connected-graph model based novel concept Partialcoflow, to achieve approximate SEBF scheduling in a partial-decentralized manner. In intra-coflow scheduling, we present FP-MDFS to give flow-level priorities and appropriate rates to TCP flows for finishing the coflows as quick as possible without wasting network capacities in a decentralized manner. Trace-based simulation results show that, among existing coflow scheduling schemes, CGM-PS can achieve the minimal CCTs both on average and in the 90th percentile. In brief, CGM-PS only brings about similar scheduling overhead with the decentralized schemes, while it can achieve the CCT performance even better than the near optimal centralized scheme.
Shuli Zhang, Yan Zhang 0014, Ding Tang, Zhen Xu 0009, Jingguo Ge, Zhijun Zhao
LCN2
2014 Modeling and Understanding TCP's Fairness Problem in Data Center Networks
abstract
Due to the special topologies and communication pattern, in today's data center networks it is common that a large set of TCP flows and a small set of TCP flows get into different ingress ports of a switch and compete for a same egress port. However, in this case the throughput share of flows in the two sets will not be fair even though all flows have the same RTT. In this paper, we study this problem and find that TCP's fairness in data center networks is related with not only the network capacity but also the number of flows in the two sets. We propose a mathematical model of the average throughput ratio of the large set of flows to the small set of flows. This model can reveal the variation of TCP's fairness along with the change of network parameters (including buffer size, bandwidth, and propagation delay) as well as the number of flows in the two sets. We validate our model by comparing its numerical results with simulation results, finding that they match well.
Shuli Zhang, Yan Zhang 0014, Yifang Qin, Yanni Han, Song Ci
CloudCom2