VLDB 2026 Research / reviewers in the wild / expert
Guanhua Yan
dblp:13/4177
· DBLP profile ↗
62ranked-venue papers
23as first author
9since 2021 · last 2025
0000-0001-7482-4043ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 11 first-author · 7 since 2021Computer networks · 23 · 7 first-author · 1 since 2021Systems, architecture and hardware · 12 · 5 first-author · 2 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-authorArtificial intelligence and machine learning · 3Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | OMAD5G: Online Malware Detection in 5G Networks using Compound Paths
Zhixin Wen, Guanhua Yan |
AsiaCCS | 2 |
| 2025 | ACGuard5GC: Privacy-Preserving Prevention of Access Control Attacks within 5G Core Networks
Harsh Sanjay Pacherkar, Guanhua Yan |
SACMAT | 2 |
| 2024 | Graphite: Real-Time Graph-Based Detection of Windows Fileless Malware Attacks
Priti Prabhakar Wakodikar, Joon-Young Gwak, Guanhua Yan, Xiaokui Shu, Scott D. Stoller, Ping Yang 0002 |
SecureComm (3) | 4 |
| 2024 | HiP4-UPF: Towards High-Performance Comprehensive 5G User Plane Function on P4 Programmable Switches
Zhixin Wen, Guanhua Yan |
USENIX ATC | 2 |
| 2024 | PROV5GC: Hardening 5G Core Network Security with Attack Detection and Attribution Based on Provenance GraphsabstractAs 5G networks become part of the critical infrastructures whose dysfunctions can cause severe damages to society, their security has been increasingly scrutinized. Recent works have revealed multiple specification-level flaws in 5G core networks but there are no easy solutions to patch the vulnerabilities in practice. Against this backdrop, this work proposes a unified framework called PROV5GC to detect and attribute various attacks that exploit these vulnerabilities in real-world 5G networks. PROV5GC tackles three technical challenges faced when deploying existing intrusion detection system (IDS) frameworks to protect 5G core networks, namely, message encryption, partial observability, and identity ephemerality. The key idea of PROV5GC is to use provenance graphs, which are constructed from the communication messages logged by various 5G core network functions. Based on these graphs, PROV5GC infers the original call flows to identify those with malicious intentions. We demonstrate how PROV5GC can be used to detect three different kinds of attacks, which aim to compromise the confidentiality, integrity, and/or availability of 5G core networks. We build a prototype of PROV5GC and evaluate its execution performance on commodity cluster servers. We observe that due to stateless instrumentation, the logging overhead incurred to each network function is low. We also show that PROV5GC can be used to detect the three 5G-specific attacks with high accuracy. Harsh Sanjay Pacherkar, Guanhua Yan |
WISEC | 2 |
| 2024 | EAGLE: Evasion Attacks Guided by Local Explanations Against Android Malware ClassificationabstractWith machine learning techniques widely used to automate Android malware detection, it is important to investigate the robustness of these methods against evasion attacks. A recent work has proposed a novel problem-space attack on Android malware classifiers, where adversarial examples are generated by transforming Android malware samples while satisfying practical constraints. Aimed to address its limitations, we propose a new attack called EAGLE (EvasionAttacksGuided byLocalExplanations), whose key idea is to leverage local explanations to guide the search for adversarial examples. We present a generic algorithmic framework for EAGLE attacks, which can be customized with specific feature increase and decrease operations to evade Android malware classifiers trained on different types of count features. We overcome practical challenges in implementing these operations for four different types of Android malware classifiers. Using two Android malware datasets, our results show that EAGLE attacks can be highly effective at finding functionable adversarial examples. We study the attack transferrability of malware variants created by EAGLE attacks across classifiers built with different classification models or trained on different types of count features. Our research further demonstrates that ensemble classifiers trained from multiple types of count features are not immune to EAGLE attacks. We also discuss possible defense mechanisms against EAGLE attacks. Zhan Shu 0002, Guanhua Yan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | CFGExplainer: Explaining Graph Neural Network-Based Malware Classification from Control Flow GraphsabstractWith the ever increasing threat of malware, extensive research effort has been put on applying Deep Learning for malware classification tasks. Graph Neural Networks (GNNs) that process malware as Control Flow Graphs (CFGs) have shown great promise for malware classification. However, these models are viewed as black-boxes, which makes it hard to validate and identify malicious patterns. To that end, we propose CFG-Explainer, a deep learning based model for interpreting GNN-oriented malware classification results. CFGExplainer identifies a subgraph of the malware CFG that contributes most towards classification and provides insight into importance of the nodes (i.e., basic blocks) within it. To the best of our knowledge, CFGExplainer is the first work that explains GNN-based mal-ware classification. We compared CFGExplainer against three explainers, namely GNNExplainer, SubgraphX and PGExplainer, and showed that CFGExplainer is able to identify top equisized subgraphs with higher classification accuracy than the other three models. Jerome Dinal Herath, Priti Prabhakar Wakodikar, Ping Yang 0002, Guanhua Yan |
DSN | 4 |
| 2022 | IoTInfer: Automated Blackbox Fuzz Testing of IoT Network Protocols Guided by Finite State Machine InferenceabstractThe popularity of Internet of Things (IoT) devices calls for effective yet efficient methods to assess the security and resilience of IoT devices. In this work, we explore a new heuristic based on finite state machine (FSM) inference to guide generation of test cases for blackbox fuzzing tests of IoT network protocol implementations. Our method, which is called IoTInfer, balances exploration and exploitation by continuously monitoring how likely mutation of an input message leads to counterexamples conflicting with the prediction by the current FSM. IoTInfer also applies clustering techniques to coarsen the FSM inferred when there are limited computational resources provisioned for fuzzing tests. We implement IoTInfer for both Bluetooth and Telnet protocols, which are widely used by existing IoT devices. Our experimental results with a variety of IoT devices reveal that IoTInfer is efficient at generating meaningful test cases, some of which can expose previously unknown vulnerabilities or implementation deviations from protocol specifications. We also compare IoTInfer with two other state-of-the-art blackbox IoT device fuzzing tools and find that IoTInfer is better at eliciting different types of responses from the fuzzing targets. Zhan Shu 0002, Guanhua Yan |
IEEE Internet Things J. | 2 |
| 2021 | Real-Time Evasion Attacks against Deep Learning-Based Anomaly Detection from Distributed System LogsabstractDistributed system logs, which record states and events that occurred during the execution of a distributed system, provide valuable information for troubleshooting and diagnosis of its operational issues. Due to the complexity of such systems, there have been some recent research efforts on automating anomaly detection from distributed system logs using deep learning models. As these anomaly detection models can also be used to detect malicious activities inside distributed systems, it is important to understand their robustness against evasive manipulations in adversarial environments. Although there are various attacks against deep learning models in domains such as natural language processing and image classification, they cannot be applied directly to evade anomaly detection from distributed system logs. In this work, we explore the adversarial robustness of deep learning-based anomaly detection models on distributed system logs. We propose a real-time attack method called LAM (Log Anomaly Mask) to perturb streaming logs with minimal modifications in an online fashion so that the attacks can evade anomaly detection by even the state-of-the-art deep learning models. To overcome the search space complexity challenge, LAM models the perturber as a reinforcement learning agent that operates in a partially observable environment to predict the best perturbation action. We have evaluated the effectiveness of LAM on two log-based anomaly detection systems for distributed systems: DeepLog and an AutoEncoder-based anomaly detection system. Our experimental results show that LAM significantly reduces the true positive rate of these two models while achieving attack imperceptibility and real-time responsiveness. Jerome Dinal Herath, Ping Yang 0002, Guanhua Yan |
CODASPY | 3 |
| 2020 | Deceiving Portable Executable Malware Classifiers into Targeted Misclassification with Practical Adversarial ExamplesabstractDue to voluminous malware attacks in the cyberspace, machine learning has become popular for automating malware detection and classification. In this work we play devil's advocate by investigating a new type of threats aimed at deceiving multi-class Portable Executable (PE) malware classifiers into targeted misclassification with practical adversarial samples. Using a malware dataset with tens of thousands of samples, we construct three types of PE malware classifiers, the first one based on frequencies of opcodes in the disassembled malware code (opcode classifier), the second one the list of API functions imported by each PE sample (API classifier), and the third one the list of system calls observed in dynamic execution (system call classifier). We develop a genetic algorithm augmented with different support functions to deceive these classifiers into misclassifying a PE sample into any target family. Using an Rbot malware sample whose source code is publicly available, we are able to create practical adversarial samples that can deceive the opcode classifier into targeted misclassification with a successful rate of 75%, the API classifier with a successful rate of 83.3%, and the system call classifier with a successful rate of 91.7%. Yunus Kucuk, Guanhua Yan |
CODASPY | 2 |
| 2020 | IoTReplay: Troubleshooting COTS IoT Devices with Record and ReplayabstractInternet-of-Things (IoT) devices have been expanding at a blistering pace in recent years. Many of these devices have not been thoroughly tested for their security and dependability prior to shipment. These COTS (Commercial-Off-The-Shelf) IoT devices pose severe security threats to not only their users but also critical infrastructures, as evidenced by the infamous Mirai botnet attack. This work explores how to use the record and replay technique to troubleshoot COTS devices. To this end, we have developed an edge-assisted system called IoTReplay, which identifies contextual events in an IoT system that may affect the operations of the target IoT device. These contextual events are recorded when the IoT device is operating in the real world and then replayed in a test environment. We evaluate the performance of IoTReplay for troubleshooting four different types of COTS IoT devices. Our experiments demonstrate that IoTReplay is able to replay execution sequences of these devices with high fidelity while causing negligible interference with the operations of these IoT devices in the real world. Kaiming Fang, Guanhua Yan |
SEC | 2 |
| 2020 | Paging storm attacks against 4G/LTE networks from regional Android botnets: rationale, practicality, and implicationsabstractAlthough the impact of mobile botnet attacks against cellular networks has been studied in a number of previous works, little attention has been paid to regional botnets, where bot-infected mobile devices are geographically concentrated at local areas. In this work we investigate a new type of threats called paging storm attacks, which can be launched from a regional botnet to exhaust the limited paging capacity of cells in a 4G/LTE (Long-Term Evolution) network. As paging storm attacks can delay paging requests for legitimate time-critical voice or video calls in a target area, their real-life implications include user annoyance, distortion of call center analytics, and loss of productivity. To demonstrate the feasibility of such attacks, we design and implement a proof-of-concept Android botnet that can coordinate bot activities to create pulsating paging requests within a short period of time. We mathematically analyze the probability that normal paging requests are delayed due to a botnet attack. Experimental results observed from a high-fidelity emulation testbed reveal that paging storm attacks launched from a regional botnet can create repetitive surges of paging requests in the target LTE network, thereby delaying time-critical voice/video calls by several seconds. Kaiming Fang, Guanhua Yan |
WISEC | 2 |
| 2019 | RAMP: Real-Time Anomaly Detection in Scientific WorkflowsabstractResearch integrity is crucial to ensuring the trustworthiness of scientific discoveries. This work is aimed at detecting misbehaviors targeting scientific workflows, which are computing paradigms widely used to facilitate scientific collaborations across multiple geographically distributed research sites. We develop a new system called RAMP(Real-Time Aggregated Matrix Profile) for real-time anomaly detection in scientific workflow systems. RAMP builds upon an existing time series data analysis technique called Matrix Profile to detect anomalous distances among subsequences of event streams collected from scientific workflows in an online manner. Using an adaptive uncertainty function, the anomaly detection model is dynamically adjusted to prevent high false alarm rates. RAMP can incorporate user feedback on reported anomalies and modify model parameters to improve anomaly detection accuracy. Our experimental results from applying RAMP to the logs generated by DATAVIEW, a scientific workflow platform, show that RAMP is able to identify a varied range of anomalies with high accuracy for both interleaved and non-interleaved workflow executions in real time. Jerome Dinal Herath, Changxin Bai, Guanhua Yan, Ping Yang 0002, Shiyong Lu |
IEEE BigData | 3 |
| 2019 | Classifying Malware Represented as Control Flow Graphs using Deep Graph Convolutional Neural NetworkabstractMalware have been one of the biggest cyber threats in the digital world for a long time. Existing machine learning based malware classification methods rely on handcrafted features extracted from raw binary files or disassembled code. The diversity of such features created has made it hard to build generic malware classification systems that work effectively across different operational environments. To strike a balance between generality and performance, we explore new machine learning techniques to classify malware programs represented as their control flow graphs (CFGs). To overcome the drawbacks of existing malware analysis methods using inefficient and nonadaptive graph matching techniques, in this work, we build a new system that uses deep graph convolutional neural network to embed structural information inherent in CFGs for effective yet efficient malware classification. We use two large independent datasets that contain more than 20K malware samples to evaluate our proposed system and the experimental results show that it can classify CFG-represented malware programs with performance comparable to those of the state-of-the-art methods applied on handcrafted malware features. Guanhua Yan |
DSN | 2 |
| 2018 | Emulation-Instrumented Fuzz Testing of 4G/LTE Android Mobile Devices Guided by Reinforcement Learning
Kaiming Fang, Guanhua Yan |
ESORICS (2) | 2 |
| 2018 | The Rise of Social Botnets: Attacks and CountermeasuresabstractOnline social networks (OSNs) are increasingly threatened by social bots which are software-controlled OSN accounts that mimic human users with malicious intentions. A social botnet refers to a group of social bots under the control of a single botmaster, which collaborate to conduct malicious behavior while mimicking the interactions among normal OSN users to reduce their individual risk of being detected. We demonstrate the effectiveness and advantages of exploiting a social botnet for spam distribution and digital-influence manipulation through real experiments on Twitter and also trace-driven simulations. We also propose the corresponding countermeasures and evaluate their effectiveness. Our results can help understand the potentially detrimental effects of social botnets and help OSNs improve their bot(net) detection systems. Jinxue Zhang, Rui Zhang 0007, Guanhua Yan |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2017 | Improving Efficiency of Link Clustering on Multi-core Machines
Guanhua Yan |
ICDCS | 1 |
| 2016 | A Bayesian Cogntive Approach to Quantifying Software Exploitability Based on Reachability Testing
Guanhua Yan, Yunus Kucuk, Max Slocum, David C. Last |
ISC | 1 |
| 2015 | Be Sensitive to Your Errors: Chaining Neyman-Pearson Criteria for Automated Malware ClassificationabstractThwarting the severe threat posed by the voluminous malware variants demands effective, yet efficient, techniques for malware classification. Although machine learning offers a promising approach to automating malware classification, existing methods are oblivious of the costs associated with the different types of errors in malware classification, i.e., false positive errors and false negative errors. Such treatment adversely affects later applications of per-family malware analysis such as trend analysis. Against this backdrop, we propose a unified cost-sensitive framework for automated malware classification. This framework enforces the Neyman-Pearson criterion, which aims to maximize the detection rate under the constraint that the false positive rate should be no greater than a certain threshold. We develop a novel scheme to chain multiple Neyman-Pearson criteria on heterogeneous malware features, some of which may have missing values. Using a large malware dataset with labelled samples belonging to 12 families, we show that our method offers great flexibility in controlling different types of errors involved in malware classification and thus provides a valuable tool for malware defense. Guanhua Yan |
AsiaCCS | 1 |
| 2014 | Sim-Watchdog: Leveraging Temporal Similarity for Anomaly Detection in Dynamic GraphsabstractGraphs are widely used to characterize relationships or information flows among entities in large networks or distributed systems. In this work, we propose a systematic framework that leverages temporal similarity inherent in dynamic graphs for anomaly detection. This framework relies on the Neyman-Pearson criterion to choose similarity measures with high discriminative power for online anomaly detection in dynamic graphs. We formulate the problem rigorously, and after establishing its inapproximibility result, we develop a greedy algorithm for similarity measure selection. We apply this framework to dynamic graphs generated from email communications among thousands of employees in a large research institution and demonstrate that it works effectively on a set of more than 100 candidate graph similarity measures. Guanhua Yan, Stephan J. Eidenbenz |
ICDCS | 1 |
| 2014 | Finding common ground among experts' opinions on data clustering: With applications in malware analysisabstractData clustering is a basic technique for knowledge discovery and data mining. As the volume of data grows significantly, data clustering becomes computationally prohibitive and resource demanding, and sometimes it is necessary to outsource these tasks to third party experts who specialize in data clustering. The goal of this work is to develop techniques that find common ground among experts' opinions on data clustering, which may be biased due to the features or algorithms used in clustering. Our work differs from the large body of existing approaches to consensus clustering, as we do not require all data objects be grouped into clusters. Rather, our work is motivated by real-world applications that demand high confidence in how data objects - if they are selected - are grouped together.We formulate the problem rigorously and show that it is NP-complete. We further develop a lightweight technique based on finding a maximum independent set in a 3-uniform hypergraph to select data objects that do not form conflicts among experts' opinions. We apply our proposed method to a real-world malware dataset with hundreds of thousands of instances to find malware clusters based on how multiple major AV (Anti-Virus) software classify these samples. Our work offers a new direction for consensus clustering by striking a balance between the clustering quality and the amount of data objects chosen to be clustered. Guanhua Yan |
ICDE | 1 |
| 2014 | Transductive malware label propagation: Find your lineage from your neighborsabstractThe numerous malware variants existing in the cyberspace have posed severe threats to its security. Supervised learning techniques have been applied to automate the process of classifying malware variants. Supervised learning, however, suffers in situations where we have only scarce labeled malware samples. In this work, we propose a transductive malware classification framework, which propagates label information from labeled instances to unlabeled ones. We improve the existing Harmonic function approach based on the maximum confidence principle. We apply this framework on the structural information collected from malware programs, and propose a PageRank-like algorithm to evaluate the distance between two malware programs. We evaluate the performance of our method against the standard Harmonic function method as well as two popular supervised learning techniques. Experimental results suggest that our method outperforms these existing approaches in classifying malware variants when only a small number of labeled samples are available. Deguang Kong, Guanhua Yan |
INFOCOM | 2 |
| 2013 | Exploring Discriminatory Features for Automated Malware Classification
Guanhua Yan, Deguang Kong |
DIMVA | 1 |
| 2013 | Discriminant malware distance learning on structural information for automated malware classificationabstractThe voluminous malware variants that appear in the Internet have posed severe threats to its security. In this work, we explore techniques that can automatically classify malware variants into their corresponding families. We present a generic framework that extracts structural information from malware programs as attributed function call graphs, in which rich malware features are encoded as attributes at the function level. Our framework further learns discriminant malware distance metrics that evaluate the similarity between the attributed function call graphs of two malware programs. To combine various types of malware attributes, our method adaptively learns the confidence level associated with the classification capability of each attribute type and then adopts an ensemble of classifiers for automated malware classification. We evaluate our approach with a number of Windows-based malware instances belonging to 11 families, and experimental results show that our automated malware classification method is able to achieve high classification accuracy. Deguang Kong, Guanhua Yan |
KDD | 2 |
| 2013 | Discriminant malware distance learning on structuralinformation for automated malware classificationabstractIn this work, we explore techniques that can automatically classify malware variants into their corresponding families. Our framework extracts structural information from malware programs as attributed function call graphs, further learns discriminant malware distance metrics, finally adopts an ensemble of classifiers for automated malware classification. Experimental results show that our method is able to achieve high classification accuracy. Deguang Kong, Guanhua Yan |
SIGMETRICS | 2 |
| 2013 | Analysis of misinformation containment in online social networks
Nam P. Nguyen, Guanhua Yan, My T. Thai |
Comput. Networks | 2 |
| 2013 | Peri-Watchdog: Hunting for hidden botnets in the periphery of online social networks
Guanhua Yan |
Comput. Networks | 1 |
| 2013 | Privacy-Preserving Profile Matching for Proximity-Based Mobile Social NetworkingabstractProximity-based mobile social networking (PMSN) refers to the social interaction among physically proximate mobile users. The first step toward effective PMSN is for mobile users to choose whom to interact with. Profile matching refers to two users comparing their personal profiles and is promising for user selection in PMSN. It, however, conflicts with users' growing privacy concerns about disclosing their personal profiles to complete strangers. This paper tackles this open challenge by designing novel fine-grained private matching protocols. Our protocols enable two users to perform profile matching without disclosing any information about their profiles beyond the comparison result. In contrast to existing coarse-grained private matching schemes for PMSN, our protocols allow finer differentiation between PMSN users and can support a wide range of matching metrics at different privacy levels. The performance of our protocols is thoroughly analyzed and evaluated via real smartphone experiments. Rui Zhang 0007, Jinxue Zhang, Jinyuan Sun, Guanhua Yan |
IEEE J. Sel. Areas Commun. | 5 |
| 2013 | iDispatcher: A unified platform for secure planet-scale information dissemination
Md. Sazzadur Rahman, Guanhua Yan, Harsha V. Madhyastha, Michalis Faloutsos, Stephan J. Eidenbenz, Mike Fisk |
Peer-to-Peer Netw. Appl. | 2 |
| 2013 | SmartAssoc: Decentralized Access Point Selection Algorithm to Improve ThroughputabstractAs the first step of the communication procedure in 802.11, an unwise selection of the access point (AP) hurts one client's throughput. This performance downgrade is usually hard to be offset by other methods, such as efficient rate adaptations. In this paper, we study this AP selection problem in a decentralized manner, with the objective of maximizing the minimum throughput among all clients. We reveal through theoretical analysis that the selfish strategy, which commonly applies in decentralized systems, cannot effectively achieve this objective. Accordingly, we propose an online AP association strategy that not only achieves a minimum throughput (among all clients) that is provably close to the optimum, but also works effectively in practice with reasonable computation and transmission overhead. The association protocol applying this strategy is implemented on the commercial hardware and compatible with legacy APs without any modification. We demonstrate its feasibility and performance through real experiments and intensive simulations. Fengyuan Xu, Xiaojun Zhu 0001, Chiu C. Tan 0001, Qun Li 0001, Guanhua Yan, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2012 | Towards a bayesian network game framework for evaluating DDoS attacks and defenseabstractWith a long history of compromising Internet security, Distributed Denial-of-Service (DDoS) attacks have been intensively investigated and numerous countermeasures have been proposed to defend against them. In this work, we propose a non-standard game-theoretic framework that facilitates evaluation of DDoS attacks and defense. Our framework can be used to study diverse DDoS attack scenarios where multiple layers of protection are deployed and a number of uncertain factors affect the decision making of the players, and it also allows us to model different sophistication levels of reasoning by both the attacker and the defender. We conduct a variety of experiments to evaluate DDoS attack and defense scenarios where one or more layers of defense mechanisms are deployed, and demonstrate that our framework sheds light on the interplay between decision makings of both the attacker and the defender, as well as how they affect the outcomes of DDoS attack and defense games. Guanhua Yan, Ritchie Lee, Alex Kent, David H. Wolpert |
CCS | 1 |
| 2012 | Fine-grained private matching for proximity-based mobile social networkingabstractProximity-based mobile social networking (PMSN) refers to the social interaction among physically proximate mobile users directly through the Bluetooth/WiFi interfaces on their smartphones or other mobile devices. It becomes increasingly popular due to the recently explosive growth of smartphone users. Profile matching means two users comparing their personal profiles and is often the first step towards effective PMSN. It, however, conflicts with users' growing privacy concerns about disclosing their personal profiles to complete strangers before deciding to interact with them. This paper tackles this open challenge by designing a suite of novel fine-grained private matching protocols. Our protocols enable two users to perform profile matching without disclosing any information about their profiles beyond the comparison result. In contrast to existing coarse-grained private matching schemes for PMSN, our protocols allow finer differentiation between PMSN users and can support a wide range of matching metrics at different privacy levels. The security and communication/computation overhead of our protocols are thoroughly analyzed and evaluated via detailed simulations. Rui Zhang 0007, Jinyuan Sun, Guanhua Yan |
INFOCOM | 4 |
| 2012 | Chrome Extensions: Threat Analysis and Countermeasures
Lei Liu 0021, Xinwen Zhang, Guanhua Yan, Songqing Chen |
NDSS | 3 |
| 2012 | Detection of Selfish Manipulation of Carrier Sensing in 802.11 NetworksabstractRecently, tuning the clear channel assessment (CCA) threshold in conjunction with power control has been considered for improving the performance of WLANs. However, we show that, CCA tuning can be exploited by selfish nodes to obtain an unfair share of the available bandwidth. Specifically, a selfish entity can manipulate the CCA threshold to ignore ongoing transmissions; this increases the probability of accessing the medium and provides the entity a higher, unfair share of the bandwidth. We experiment on our 802.11 testbed to characterize the effects of CCA tuning on both isolated links and in 802.11 WLAN configurations. We focus on AP-client(s) configurations, proposing a novel approach to detect this misbehavior. A misbehaving client is unlikely to recognize low power receptions as legitimate packets; by intelligently sending low power probe messages, an AP can efficiently detect a misbehaving node. Our key contributions are: 1) We are the first to quantify the impact of selfish CCA tuning via extensive experimentation on various 802.11 configurations. 2) We propose a lightweight scheme for detecting selfish nodes that inappropriately increase their CCAs. 3) We extensively evaluate our system on our testbed; its accuracy is 95 percent while the false positive rate is less than 5 percent. Konstantinos Pelechrinis, Guanhua Yan, Stephan J. Eidenbenz, Srikanth V. Krishnamurthy |
IEEE Trans. Mob. Comput. | 2 |
| 2011 | Malware propagation in online social networks: nature, dynamics, and defense implicationsabstractOnline social networks, which have been expanding at a blistering speed recently, have emerged as a popular communication infrastructure for Internet users. Meanwhile, malware that specifically target these online social networks are also on the rise. In this work, we aim to investigate the characteristics of malware propagation in online social networks. Our study is based on a dataset collected from a real-world location-based online social network, which includes not only the social graph formed by its users but also the users' activity events. We analyze the social structure and user activity patterns of this network, and confirm that it is a typical online social network, suggesting that conclusions drawn from this specific network can be translated to other online social networks. We use extensive trace-driven simulation to study the impact of initial infection, user click probability, social structure, and activity patterns on malware propagation in online social networks. We also investigate the performance of a few user-oriented and server-oriented defense schemes against malware spreading in online social networks and identify key factors that affect their effectiveness. We believe that this comprehensive study has deepened our understanding of the nature of online social network malware and also shed light on how to defend against them effectively. Guanhua Yan, Stephan J. Eidenbenz, Nan Li 0040 |
AsiaCCS | 1 |
| 2011 | Geography-based analysis of the Internet infrastructureabstractIn this paper, we study some geographic aspects of the Internet. We base our analysis on a large set of geolocated IP hop-level session data (including about 300, 000 backbone routers, 130 million end hosts, and one billion sessions) that we synthesized from a variety of different input sources such as US census data, computer usage statistics, Internet market share data, IP geolocation data sets, CAIDA's Skitter data set for backbone connectivity, and BGP routing tables. We use this model to perform a nationwide and statewide geographic analysis of the Internet. Our main observations are: (1) There is a dominant coast-to-coast pattern in the US Internet traffic. In fact, in many instances even if the end-devices are not near either coast, still the traffic between them takes a long detour through the coasts. (2) More than half of the Internet paths are inflated by 100% or more compared to their corresponding geometric straight-line distance. This circuitousness makes the average ratio between the routing distance and geometric distance big (around 10). (3) The weighted mean hop count is around 5, but the hop counts are very loosely correlated with the distances. The weighted mean AS count (number of ASes traversed) is around 3. Shiva Prasad Kasiviswanathan, Stephan J. Eidenbenz, Guanhua Yan |
INFOCOM | 3 |
| 2011 | Privacy analysis of user association logs in a large-scale wireless LANabstractUser association logs play an important role in wireless network research. One concern of sharing such logs with other researchers, however, is that they pose potential privacy risks for the network users. Today, the common practice in sanitizing these logs before releasing them to the public is to anonymize users' sensitive information, such as their devices' MAC addresses and their exact association locations. In this work, we aim to study whether such sanitization measures are sufficient to protect user privacy. By simulating an adversary's role, we propose a novel type of correlation attack in which the adversary uses the anonymized association log to build signatures against each user, and when combined with auxiliary information, such signatures can help to identify users within the anonymized log. Using a user association log that contains more than four thousand users and millions of association records, we demonstrate that this attack technique, under certain circumstances, is able to pinpoint the victim's identity exactly with a probability as high as 70%, or narrow it down to a set of 20 candidates with a probability close to 100%.We further evaluate the effectiveness of standard anonymization techniques, including generalization and perturbation, in mitigating correlation attacks; our experimental results reveal only limited success of these methods, suggesting that more thorough treatment is needed when anonymizing wireless user association logs before public release. Keren Tan, Guanhua Yan, Jihwang Yeo, David Kotz |
INFOCOM | 2 |
| 2011 | RatBot: Anti-enumeration Peer-to-Peer Botnets
Guanhua Yan, Songqing Chen, Stephan J. Eidenbenz |
ISC | 1 |
| 2011 | Measuring the effectiveness of infrastructure-level detection of large-scale botnetsabstractBotnets are one of the most serious security threats to the Internet and its end users. In recent years, utilizing P2P as a Command and Control (C&C) protocol has become popular due to its decentralized nature that can help hide the botmaster's identity. Most bot detection approaches targeting P2P botnets either rely on behavior monitoring or traffic flow and packet analysis, requiring fine-grained information collected locally. This requirement limits the scale of detection. In this paper, we consider detection of P2P botnets at a high-level - the infrastructure level-by exploiting their structural properties from a graph analysis perspective. Using three different P2P overlay structures, we measure the effectiveness of detecting each structure at various locations (the Autonomous System (AS), the Point of Presence (PoP), and the router rendezvous) in the Internet infrastructure. Guanhua Yan, Stephan J. Eidenbenz, Kang G. Shin |
IWQoS | 2 |
| 2011 | Wiki-Watchdog: Anomaly Detection in Wikipedia Through a Distributional LensabstractWikipedia has become a standard source of reference online, and many people (some unknowingly) now trust this corpus of knowledge as an authority to fulfil their information requirements. In doing so they task the human contributors of Wikipedia with maintaining the accuracy of articles, a job that these contributors have been performing admirably. We study the problem of monitoring the Wikipedia corpus with the goal of automated, online anomaly detection. We present Wiki-watchdog, an efficient distribution-based methodology that monitors distributions of revision activity for changes. We show that using our methods it is possible to detect the activity of bots, flash events, and outages, as they occur. Our methods are proposed to support the monitoring of the contributors. They are useful to speed-up anomaly detection, and identify events that are hard to detect manually. We show the efficacy and the low false-positive rate of our methods by experiments on the revision history of Wikipedia. Our results show that distribution-based anomaly detection has a higher detection rate than traditional methods based on either volume or entropy alone. Unlike previous work on anomaly detection in information networks that worked with a static network graph, our methods consider the network as it evolves and monitors properties of the network for changes. Although our methodology is developed and evaluated on Wikipedia, we believe it is an effective generic anomaly detection framework in its own right. Chrisil Arackaparambil, Guanhua Yan |
Web Intelligence | 2 |
| 2011 | AntBot: Anti-pollution peer-to-peer botnets
Guanhua Yan, Duc T. Ha, Stephan J. Eidenbenz |
Comput. Networks | 1 |
| 2010 | Designing a Practical Access Point Association ProtocolabstractIn a Wireless Local Area Network (WLAN), the Access Point (AP) selection of a client heavily influences the performance of its own and others. Through theoretical analysis, we reveal that previously proposed association protocols are not effective in maximizing the minimal throughput among all clients. Accordingly, we propose an online AP association strategy that not only achieves a minimal throughput (among all clients) that is provably close to the optimum, but also works effectively in practice with a reasonable computational overhead. The association protocol applying this strategy is implemented on the commercial hardware and compatible with legacy APs without any modification. We demonstrate its feasibility and performance through real experiments. Fengyuan Xu, Chiu C. Tan 0001, Qun Li 0001, Guanhua Yan, Jie Wu 0001 |
INFOCOM | 4 |
| 2010 | Criticality analysis of Internet infrastructure
Guanhua Yan, Stephan J. Eidenbenz, Sunil Thulasidasan, Pallab Datta, Venkatesh Ramaswamy |
Comput. Networks | 1 |
| 2009 | Exploitation and threat analysis of open mobile devicesabstractThe increasingly open environment of mobile computing systems such as PDAs and smartphones brings rich applications and services to mobile users. Accompanied with this trend is the growing malicious activities against these mobile systems, such as information leakage, service stealing, and power exhaustion. Besides the threats posed against individual mobile users, these unveiled mobile devices also open the door for more serious damage such as disabling critical public cyber physical systems that are connected to the mobile/wireless infrastructure. The impact of such attacks, however, has not been fully recognized. Lei Liu 0021, Xinwen Zhang, Guanhua Yan, Songqing Chen |
ANCS | 3 |
| 2009 | On the effectiveness of structural detection and defense against P2P-based botnetsabstractRecently, peer-to-peer (P2P) networks have emerged as a covert communication platform for malicious programs known as bots. As popular distributed systems, they allow bots to communicate easily while protecting the botmaster from being discovered. Existing work on P2P-based botnets mainly focuses on measurement-based studies of botnet behaviors. In this work, through simulation, we study extensively the structure of P2P networks running Kademlia, one of a few widely used P2P protocols in practice. Our simulation testbed not only incorporates the actual code of a real Kademlia client software to achieve high realism, but also applies distributed event-driven simulation techniques to achieve high scalability. Using this testbed, we analyze the scaling, clustering, reachability, and various centrality properties of P2P-based botnets from a graph-theoretical perspective. We further demonstrate experimentally and theoretically that monitoring bot activities in a P2P network is difficult, suggesting that the P2P mechanism indeed helps botnets hide their communication effectively. Finally, we evaluate the effectiveness of some potential mitigation techniques, such as content poisoning, sybil-based and eclipse-based mitigation. Conclusions drawn from this work shed light on the structure of P2P botnets, how to monitor bot activities in P2P networks, and how to mitigate botnet operations effectively. Duc T. Ha, Guanhua Yan, Stephan J. Eidenbenz, Hung Q. Ngo 0001 |
DSN | 2 |
| 2009 | Blue-Watchdog: Detecting Bluetooth worm propagation in public areasabstractThe rising popularity of mobile devices, such as cellular phones and PDAs, has made them a lucrative playground for mobile malware propagation. One common infection vector exploited by these mobile malware is Bluetooth. In this paper, we propose an architecture called Blue-Watchdog that detects Bluetooth worm propagation in public areas based on statistical methods. To achieve fast and accurate Bluetooth worm detection, Blue-Watchdog monitors abrupt changes of average paging rate per Bluetooth device from both temporal and temporal-spatial perspectives. The temporal scheme relies on the CUSUM (Cumulative Sum) sequential test together with the generalized likelihood ratio (GLR), and the temporal-spatial scheme aims to identify spatial regions with abnormally frequent paging attempts. Experimental results show that Blue-Watchdog not only has low false alarm rates, but also effectively detects Bluetooth worms that spread quickly in areas where Bluetooth devices are greatly mixed due to high mobility and also those that propagate relatively slowly in a spatially constrained fashion. Guanhua Yan, Leticia Cuellar, Stephan J. Eidenbenz, Nicolas W. Hengartner |
DSN | 1 |
| 2009 | Detecting Selfish Exploitation of Carrier Sensing in 802.11 NetworksabstractRecently, tuning the clear channel assessment (CCA) threshold in conjunction with power control has been considered for improving the performance of Wireless LANs. However, CCA tuning can be exploited by selfish nodes in order to obtain an unfair share of the available bandwidth. In particular, by increasing the CCA threshold, a selfish client can manipulate the carrier sensing mechanism to ignore the presence of other transmissions on the medium; consequently, it increases the probability of accessing the medium and therefore obtains a higher, unfair share of the available bandwidth. In this paper, we propose a novel approach to detect this misbehavior in WLANs. A key insight that leads to our approach is that a misbehaving node that has increased its CCA is unlikely to recognize low power receptions as legitimate packets; by intelligently sending low power probe messages, an AP can detect a misbehaving node with high probability. In a nutshell, our contributions are as follows: (a) We are the first to quantify the impact of selfish CCA tuning via extensive experimentation (b) We propose a novel lightweight scheme for detecting selfish nodes that inappropriately increase their CCA thresholds; we call our scheme CMD (for carrier sensing misbehavior detection) (c) We perform extensive evaluations on an indoor 802.11 WLAN testbed to demonstrate that CMD detects misbehaving users with very high accuracy (approximately 95 % of the time). Furthermore, it only incurs a false positive rate of less than 5 %. Konstantinos Pelechrinis, Guanhua Yan, Stephan J. Eidenbenz, Srikanth V. Krishnamurthy |
INFOCOM | 2 |
| 2009 | VirusMeter: Preventing Your Cellphone from Spies
Lei Liu 0021, Guanhua Yan, Xinwen Zhang, Songqing Chen |
RAID | 2 |
| 2009 | SMS-Watchdog: Profiling Social Behaviors of SMS Users for Anomaly Detection
Guanhua Yan, Stephan J. Eidenbenz, Emanuele Galli |
RAID | 1 |
| 2009 | Mobi-watchdog: you can steal, but you can't run!abstractRecent years have witnessed widespread use of mobile devices such as cell phones, laptops, and PDAs. In this paper, we propose an architecture called Mobi-Watchdog to detect mobility anomalies of mobile devices in wireless networks that track their locations regularly. Given the past mobility records of a mobile device, Mobi-Watchdog uses clustering techniques to identify the high-level structure of its mobility and then trains a HHMM (hierarchical hidden Markov model). Mobi-Watchdog raises an alert by requesting the device holder to reauthenticate himself when it finds an observed mobility trace significantly deviates from the trained model. The time complexity of the original generalized Baum-Welch algorithm, which is used for HHMM parameter reestimation, scales linearly with T3, where T is the number of locations in an observed sequence. Such a high computational cost can significantly impede deployment of Mobi-Watchdog in large-scale wireless networks in practice. To achieve better scalability, we modify this algorithm to make it scale linearly with T instead. Experimental results with realistic mobility traces demonstrate that Mobi-Watchdog detects mobility anomalies with high probability and reasonably low false alarm rates. We also show that Mobi-Watchdog has very low computational overhead, which makes it a viable candidate for mobility anomaly detection in large wireless networks. Guanhua Yan, Stephan J. Eidenbenz, Bo Sun 0001 |
WISEC | 1 |
| 2009 | Self-propagating mal-packets in wireless sensor networks: Dynamics and defense implications
Bo Sun 0001, Guanhua Yan, Yang Xiao 0001, T. Andrew Yang |
Ad Hoc Networks | 2 |
| 2009 | Modeling Propagation Dynamics of Bluetooth Worms (Extended Version)abstractIn the last few years, the growing popularity of mobile devices has made them attractive to virus and worm writers. One communication channel often exploited by mobile malware is the Bluetooth interface. In this paper, we present a detailed analytical model that characterizes the propagation dynamics of Bluetooth worms. Our model captures not only the behavior of the Bluetooth protocol but also the impact of mobility patterns on the Bluetooth worm propagation. Validation experiments against a detailed discrete-event Bluetooth worm simulator reveal that our model predicts the propagation dynamics of Bluetooth worms with high accuracy. We further use our model to efficiently predict the propagation curve of Bluetooth worms in big cities such as Los Angeles. Our model not only sheds light on the propagation dynamics of Bluetooth worms, but also allows to predict spreading curves of Bluetooth worm propagation in large areas without the high computational cost of discrete-event simulation. Guanhua Yan, Stephan J. Eidenbenz |
IEEE Trans. Mob. Comput. | 1 |
| 2008 | Self-Propagate Mal-Packets in Wireless Sensor Networks: Dynamics and Defense ImplicationsabstractIn this paper, based on our proposed mal-packet self-propagation models in wireless sensor networks, we use TOSSIM to study their propagation dynamics. We also present a preliminary study of the feasibility of mal-packet defense in sensor networks. Specifically, based on random graph theory and percolation theory, we propose the immunization of the highly-connected nodes in order to partition the network into as many separate pieces as possible, thus preventing or slowing down the mal-packet propagation. We study the percolation threshold of different network densities and the effectiveness of immunization in terms of connection ratio, remaining link ratio, and distribution of component sizes. We also present an analysis of the distribution of component sizes. Bo Sun 0001, Dibesh Shrestha, Guanhua Yan, Yang Xiao 0001 |
GLOBECOM | 3 |
| 2008 | Worm Propagation Dynamics in Wireless Sensor NetworksabstractWorms have become an emergent threat towards information confidentiality, integrity, and service availability. While playing an important role for people to interact with surrounding environments, wireless sensor networks suffer from growing security concerns posed by worms because of sensor networks' low physical security, lack of resilience and robustness of underlying operating systems, and the ever increased complexity of deployed applications. In this paper, we study worm propagation in 802.15.4 based wireless sensor networks. First we present a baseline worm model in the context of wireless sensor networks. Then we describe a preliminary study of the impact of various protocol parameters and network scenarios on worm propagation dynamics. Our simulation study can provide insight into deriving a suitable model to characterize worm propagation in sensor networks. Bo Sun 0001, Guanhua Yan, Yang Xiao 0001 |
ICC | 2 |
| 2008 | BotTracer: Execution-Based Bot-Like Malware Detection
Lei Liu 0021, Songqing Chen, Guanhua Yan, Zhao Zhang 0010 |
ISC | 3 |
| 2008 | Dynamic Balancing of Packet Filtering Workloads on Distributed FirewallsabstractFirewalls are widely deployed nowadays to enforce security policies of enterprise networks. While having played crucial roles in securing these networks, firewalls themselves are subject to performance limitations. An overloaded firewall can cause severe damage to the protected enterprise network, because any legitimate communication through it is either degraded or even completely severed. In this paper, we address how to dynamically balance packet filtering workloads on distributed firewalls efficiently in large enterprise networks. We model dynamic load balancing on distributed firewalls as a minimax optimization problem, and show that it is strongly NP-complete even if we eliminate all precedence relationships among policy rules by rule rewriting. Accordingly, we propose a light-weight rule distribution scheme that quickly balances workloads among all firewalls. Our scheme is adaptive to incoming traffic. Moreover, dynamically placing and ordering policy rules on distributed firewalls reduces the probability that attackers successfully infer the rule distribution. Experimental results show that using a commodity PC, our approach can reduce the peak firewall workload in distributed firewall systems by 40% within less than five minutes, compared against alternative solutions that only optimize rule ordering on individual firewalls. Guanhua Yan, Songqing Chen, Stephan J. Eidenbenz |
IWQoS | 1 |
| 2008 | DDoS Mitigation in Non-cooperative Environments
Guanhua Yan, Stephan J. Eidenbenz |
Networking | 1 |
| 2007 | Bluetooth worm propagation: mobility pattern matters!abstractThe alarm that worms start to spread on increasingly popular mobile devices calls for an in-depth investigation of their propagation dynamics. In this paper, we study how mobility patterns affect Bluetooth worm spreading speeds. We find that the impact of mobility patterns is substantial over a large set of of changing Bluetooth and worm parameters. For instance, a mobility model under which devices move among a fixed set of activity locations can result in worm propagation speeds four times faster than a classical mobility model such as the random walk model. Our investigation reveals that the key factors affecting Bluetooth worm propagation speeds include spatial distributions of nodes, link duration distributions, degrees to which devices are mixed together, and even the burstiness of successive links. Guanhua Yan, Hector D. Flores, Leticia Cuellar, Nicolas W. Hengartner, Stephan J. Eidenbenz, Vincent Q. Vu |
AsiaCCS | 1 |
| 2007 | Modeling Propagation Dynamics of Bluetooth WormsabstractThe growing popularity of mobile devices in the last few years has made them attractive to virus and worm writers. One communication channel exploited by mobile malware is the Bluetooth interface. In this paper, we present a detailed analytical model that characterizes the propagation dynamics of Bluetooth worms. Our model captures not only the behavior of the Bluetooth protocol but also the impact of mobility patterns on the Bluetooth worm propagation. Validation experiments against a detailed discrete-event Bluetooth worm simulator reveal that our model predicts the propagation dynamics of Bluetooth worms with high accuracy. Guanhua Yan, Stephan J. Eidenbenz |
ICDCS | 1 |
| 2006 | Bluetooth Worms: Models, Dynamics, and Defense ImplicationsabstractThe occurrences of mobile worms like Cabir, Mabir and CommWarrior have created growing concerns over the security of data stored on mobile devices such as cell phones and PDAs. These worms have in common that they all use Bluetooth communication as their infection channel. In order to prepare effective defense strategies against such worms, we study the nature, characteristics, and spreading dynamics of Bluetooth worms in the safe environment of simulation. Our key findings are: (i) mobility may not boost the Bluetooth worm propagation; instead, link instability owing to it has negative impact on the worm spreading speed; (ii) the inherent capacity constraints imposed by the wireless channel (e.g. interference) and the specifics of the Bluetooth protocol can significantly slow down the Bluetooth worm propagation; (iii) intelligently designed worms can improve their propagation speed to a noticeable degree by strategically selecting worm model parameters or exploiting out-of-band propagation capabilities Guanhua Yan, Stephan J. Eidenbenz |
ACSAC | 1 |
| 2006 | Sluggish Calendar Queues for Network SimulationabstractDiscrete event simulation is an indispensable tool to understand the dynamics of communication networks and evaluate their performance. As the scale and complexity of these networks increases, simulation itself becomes a computationally prohibitive undertaking. Among all possible solutions, improving the performance of event manipulation operations is an important one. In this paper, we discover that in network simulation events are often inserted into the simulation kernel in their timestamp order. Based on this observation, we make some simple modifications on the conventional calendar queue. Experiments show that the new data structure can achieve two orders of execution speedup against the conventional calendar queue in some wireline network simulation and in wireless network simulation, the speedup scales well with the network size. Guanhua Yan, Stephan J. Eidenbenz |
MASCOTS | 1 |
| 2000 | An Efficient Method to Simulate Communication NetworksabstractPrecision and efficiency are the two most important goals of simulation. As far as communication networks are concerned, for the great complexity of their topologies, protocols and traffic, how to simulate them efficiently has been a hot spot in the recent research. This article first emphasizes the importance of the survey before the simulation begins, because it can make the target of simulation clear. Also, during the modeling phase prior to simulation, we should consider adequately the characteristics of the communication network to be simulated and adopt some methods in order to improve the simulation efficiency. Guanhua Yan, Yuehui Jin, Yulu Ma, Shiduan Cheng, Jian Ma 0001 |
ICC (1) | 1 |