Xiuwen Sun

dblp:149/0556 · DBLP profile ↗
← Back
21ranked-venue papers
13as first author
15since 2021 · last 2026
0000-0001-8164-0576ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 9 first-author · 9 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Shadow: Accelerating Regular Expression Matching on VCDIFF Compressed Data
abstract
Data compression techniques significantly improve storage efficiency, bandwidth utilization, and energy efficiency, yet they introduce challenges for the rapid browsing and retrieval of valuable information within compressed data. Existing approaches achieve high-speed, lossless matching by exploiting the context-free property of automata. However, they are constrained by the recursive reference structures in compressed data, which necessitate state copying to ensure matching safety.
Xiuwen Sun, Tianxin Wang, Hao Li 0011, Jie Cui 0004, Hong Zhong 0001
DCC1
2026 Similarity-based Field Inference for Unknown Binary Network Protocols
Xiuwen Sun, Linlin Xia, Jie Cui 0004, Hong Zhong 0001
Comput. Networks1
2026 Plausible and robust counterfactual explanation via local distribution consistency
Yunyun Zhang, Xiuwen Sun, Peng Zhou 0008
Neurocomputing3
2026 Energy-Efficient Short-Packet Covert Communications for Full-Duplex Wireless Systems With AoI Constraint
Yangfan Xu, Bin Yang 0010, Xiuwen Sun, Shikai Shen, Haibao Chen, Bao Gui, Tarik Taleb
IEEE Internet Things J.4
2026 Length field recognition for unknown network protocol in static trace
Xiuwen Sun, Jie Cui 0004, Hong Zhong 0001
J. Netw. Comput. Appl.1
2025 Energy-Harvesting Jammer-Aided Covert Communications in Wireless Multirelay IoT Systems
abstract
This article investigates covert communications in a multirelay Internet of Things (IoT) system with multiple energy harvesting jammers, where a transmitter (Alice) attempts to covertly transmit confidential messages to its destination (Bob) through relay forwarding, while a warden (Willie) detects the existence of Alice’s transmission. Specifically, we employ a harvesting-then-jamming protocol with which the jammers first harvest energy from Alice and then send jamming signals to interfere with Willie’s detection. We propose a relay and jammer selection strategy, namely quality of service (QoS)-aware selection, and use the random selection strategy as a comparison strategy. Under these two selection strategies, we derive the optimal detection threshold and minimum detection error probability at Willie, respectively. We then model the covert throughput performance and obtain the maximum covert throughput by jointly optimizing covert transmit power and jamming transmit power. Extensive numerical results are provided to illustrate the impacts of system parameters on covert throughput performance.
Hao Lv 0006, Bin Yang 0010, Xiuwen Sun, Chan Gao, Bao Gui, Tarik Taleb
IEEE Internet Things J.3
2024 Variable-length Field Extraction for Unknown Binary Network Protocols
abstract
Protocol reverse engineering can infer the specification or behaviour of unknown network protocols, which is essential in analyzing and evaluating network functionality and performance. There are variable-length fields in many network protocols, and the field boundaries significantly impact subsequent analysis as well as the inferred results. The existing works focus on extracting protocol keyword fields without considering whether the fields' length is variable. In this paper, we propose BERRY for extracting variable-length field of unknown binary network protocols from static traces. At first, BERRY clusters the same type of messages from the input trace and extracts their headers with the help of the information entropy. Then, it combines the feature of message length and location-aware association analysis with to locate candidate variable fields. Finally, it infers the variable-length field by the sequence alignment. We evaluate BERRY with BinaryInferno using six groups of real network protocol traces. BERRY exhibits high accuracy and reliability on the metrics of precision, recall, and F1-score while extracting variable-length fields. It also performs similar results to the Binaryinferno on extracting all the fields.
Xiuwen Sun, Jie Cui 0004, Hong Zhong 0001
LCN1
2023 Extracting Length Field of Unknown Binary Network Protocol from Static Trace
abstract
Network protocol specification is essential in analyzing and evaluating network functionality, performance, and security. However, increasing private protocols become a hindrance to these features. The existing works study how to extract protocol keyword fields rather than infer the semantics of the fields, such as the length field, which can indicate the length associated with a message and is fundamental for deep analysis of network protocols. In this paper, we propose a nonparametric and unsupervised method, ROSE, to extract the length field of unknown binary network protocols from static traces. It segments the fields from the raw network trace and gets the inferred length of a subset of messages by clustering similar fields with k-means. Then, it generates candidate fields using n-gram and builds a multidimensional equation based on the length of the clustered messages and the candidate length fields. Finally, ROSE extracts the inferred length fields through linear regression. As far as we know, it is the first study on extracting length field from the static trace. The evaluation experiments using raw network traces exhibit high precision and recall in extracting the length field or identifying protocols without the length field.
Xiuwen Sun, Pengfei Fu, Jie Cui 0004, Hong Zhong 0001
TrustCom1
2023 Parallel Pattern Matching over Brotli Compressed Network Traffic
abstract
Pattern matching is a crucial technique for network traffic detection applications. As a fundamental computation model used by pattern matching, the finite state automata execute sequential matching due to the state dependence among transitions. Meanwhile, most services tend to compress their data to improve transmission or storage efficiency. The increased compressed data challenges the straightforward method of matching the whole decompressed data and incurs data dependence among the compression encodings. The related approaches either leverage techniques to break the state dependence of matching uncompressed data or accelerate matching compressed data in a single-threaded manner without considering the state and data dependence. None of them can perform parallel matching over compressed data. This paper provides PETALS, a parallel pattern matching method over Brotli compressed network traffic. PETALS partitions the original compressed traffic into fixed- length blocks for parallel matching and patches the broken compression encodings crossing blocks to break the data dependence. Then, it merges the compressed traffic matching method into path fusion, an enumerative parallelization of finite state automata, to present parallel matching over compressed traffic. Evaluation using real-world network traffic and regular expressions shows that PETALS can raise the speedup from 1.53x to 3.53x of the state-of-the-art parallelization schemes on a 56-cores machine.
Xiuwen Sun, Guangzheng Zhang, Qingying Yu, Jie Cui 0004, Hong Zhong 0001
TrustCom1
2023 Detecting DGA-based botnets through effective phonics-based features
Hao Li 0011, Xiuwen Sun, Yazhe Tang
Future Gener. Comput. Syst.3
2023 Efficient regular expression matching over hybrid dictionary-based compressed data
Xiuwen Sun, Da Mo, Chunhui Ye, Qingying Yu, Jie Cui 0004, Hong Zhong 0001
J. Netw. Comput. Appl.1
2022 Prediction-based dual-weight switch migration scheme for SDN load balancing
Hong Zhong 0001, Jinshan Xu, Jie Cui 0004, Xiuwen Sun, Chengjie Gu, Lu Liu 0001
Comput. Networks4
2021 Accelerating Knuth-Morris-Pratt String Matching over LZ77 Compressed Text
abstract
For comprehensive analyzing or efficient searching from massive data, string matching is widely used as a core technique of the network traffic detection applications and text editors. However, the increasing compressed text challenges string matching to achieve high-speed processing. In this paper, we propose KCM, a fast Knuth-Morris-Pratt based string matching method over LZ77 compressed text. It leverages the gathered heuristic information during scanning to skip the characters that should have been scanned. In our evaluation with real traffic, KCM skips more than 90% compression text, which nearly approaches the theoretical upper bound. It can achieve 1.61 Gbps throughput and boost 1.87 times than the classic string matching.
Xiuwen Sun, Da Mo, Jie Cui 0004, Hong Zhong 0001
DCC1
2021 DOLPHIN: Phonics based Detection of DGA Domain Names
abstract
Botnets are the machines that increasingly controlled by cybercriminals to perform various attacks. They use Domain Generation Algorithm (DGA) to frequently generate their illegitimate domains for preventing detection. To overcome such dynamics, existing solutions try to capture the characteristics of domain names, such that the automatically generated domains can be identified. However, those solutions are not conformed to the linguistic conventions of reading and writing. For a comprehensive understanding of strings of domain names, we present DOmain Linguistic PHonIcs detectioN (DOLPHIN), a novel method that can detect the illegitimate domain names generated by DGAs. Considering the correspondence between pronunciations and spellings, we design the DOLPHIN patterns. They are the classification of vowels and consonants in variable lengths as follow the principles of phonics. DOLPHIN recognizes strings of domain names and reconstructs them with the components of variable-length vowels and consonants following the DOLPHIN patterns. We implement the features used DOLPHIN in supervised learning methods and compare them to the fore-most method FANCI. Experimental results show that, compared to FANCI with RFs, DOLPHIN can achieve higher detection accuracy of 0.0238 in average with lower FPR without much overhead.
Hao Li 0011, Xiuwen Sun, Yazhe Tang
GLOBECOM3
2021 Scalable QoS-Aware Multicast for SVC Streams in Software-Defined Networks
abstract
Because network nodes are transparent in media streaming applications, traditional networks cannot utilize the scalability feature of Scalable video coding (SVC). Compared with the traditional network, SDN supports various flows in a more fine-grained and scalable manner via the OpenFlow protocol, making QoS requirements easier and more feasible. In previous studies, a Ternary Content-Addressable Memory (TCAM) space in the switch has not been considered. This paper proposes a scalable QoS-aware multicast scheme for SVC streams, and formulates the scalable QoS-aware multicast routing problem as a nonlinear programming model. Then, we design heuristic algorithms that reduce the TCAM space consumption and construct the multicast tree for SVC layers according to video streaming requests. To alleviate video quality degradation, a dynamic layered multicast routing algorithm is proposed. Our experimental results demonstrate the performance of this method in terms of the packet loss ratio, scalability, the average satisfaction, and system utility.
Jie Cui 0004, Lingbiao Kong, Hong Zhong 0001, Xiuwen Sun, Chengjie Gu, Jianfeng Ma 0001
ISCC4
2020 Efficient regular expression matching over compressed traffic
Xiuwen Sun, Hao Li 0011, Xingxing Lu, Zheng Peng 0003, Chengchen Hu
Comput. Networks1
2020 Corrigendum to "COIN: A fast packet inspection method over compressed traffic" [J. Netw. Comput. Appl. 127(2019) 122-134]
Xiuwen Sun, Hao Li 0011, Xingxing Lu, Kaiyu Hou, Chengchen Hu
J. Netw. Comput. Appl.1
2019 Bracelet: arms-down selection for Kinect mid-air gesture
abstract
Gesture-based interaction has become more affordable and ubiquitous as an interaction style in recent years. Since gesture-based interactions lead to fatigue and cause heaviness in upper limbs, a problem commonly known as ‘Gorilla-Arm Syndrome’ occurs. Then Bracelet is proposed, an arms-down selection method based on Kinect. Its purpose is reducing fatigue in a long mid-air gesture interaction session. An evaluation of 16 participants compared with previous methods such as mid-air gestures and other arms-down interactions showed the effectiveness of the Bracelet in reducing fatigue. As the Bracelet is helpful to alleviate fatigue in some situations where selection is intensive and has no time limit, it can be used as a ‘plug-in’ for other methods and applied for display in many public places such as airports, stations, shopping malls and waiting rooms.
Feng Han 0007, Xiuwen Sun
Behav. Inf. Technol.3
2019 COIN: A fast packet inspection method over compressed traffic
Xiuwen Sun, Hao Li 0011, Xingxing Lu, Kaiyu Hou, Chengchen Hu
J. Netw. Comput. Appl.1
2018 Towards a Fast Regular Expression Matching Method Over Compressed Traffic
abstract
Nowadays, Deep Packet Inspection (DPI) becomes a critical component of the network traffic detection applications. For comprehensive analysis of traffic, regular expression matching as the core technique of DPI is widely used. However, web services tend to compress their traffic for less data transmission, which challenges the regular expression matching to achieve wire-speed processing. In this paper, we propose Twins, a fast regular expression matching method over compressed traffic that leverages the returned states encoding in the compression to skip the bytes to be scanned. In our evaluation results, Twins can skip about 90% compression data and can achieve 1.5Gbps throughput, which gains 2.7~3.4 performance boost to the state-of-the-art work.
Xiuwen Sun, Hao Li 0011, Xingxing Lu, Zheng Peng 0003, Chengchen Hu
IWQoS1
2017 Towards a fast packet inspection over compressed HTTP traffic
abstract
Matching multiple patterns is the key technology in firewall, Intrusion Detection Systems, etc. However, most of the web services nowadays tend to compress their traffic for less transferring data and better user experience, which has challenged the multi-pattern matching original working only on raw content. Naive and straightforward solutions towards this challenge either decompress the compressed data first and apply legacy multi-pattern matching methods, or have to scan redundant data during the matching., which are not fast and memory efficient. In this paper, we propose COmpression INspection (COIN) method for multi-pattern matching on compressed HTTP traffic. COIN does not decompress the data before matching and only scans once each bit of the traffic under inspection. We have collected real traffic data from Alexa.com top 500 and Alexa.cn top 20000 web sites and have performed the experiments under 1430 SNORT patterns. The evaluation results show that COIN is 10–31% faster than state-of-the-art approach.
Xiuwen Sun, Kaiyu Hou, Hao Li 0011, Chengchen Hu
IWQoS1