Qiumei Cheng

dblp:188/5659 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-8972-036XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 2 first-author · 5 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Toward Security-Enhanced In-Band Network Telemetry in Programmable Networks
abstract
In-band Network Telemetry (INT) is a widely used monitoring framework in modern large-scale networks. It provides packet-level visibility into network conditions by inserting telemetry data into packets, enabling unprecedented fine-grained network management. However, this mechanism also introduces new vulnerabilities that malicious attackers can exploit. In this paper, we present eight In-band Network Telemetry Manipulation Attacks that take advantage of INT’s weakness, demonstrating that attackers can cause severe damage with little effort by manipulating INT packets. To address this issue, we designed SecureINT, a security-enhanced INT prototype that provides encryption and integrity verification for INT packets. Specifically, SecureINT deploys Even-Mansour and SipHash for confidentiality and integrity, respectively. It also uses a zero-delay rotation mechanism, which enables administrators to dynamically change the version of the deployed Even-Mansour/SipHash running on programmable switches without the need to re-install new programs. In this way, SecureINT can provide lasting security for INT packets using the limited resources of programmable switches. According to the experiments, SecureINT can be deployed on programmable switches using a single pipeline. Besides, the overhead of the rotation mechanism running on the control plane is still minimal.
Dezhang Kong, Xiang Chen 0017, Zhengyan Zhou, Yi Shen 0012, Hongyan Liu 0001, Qiumei Cheng, Xuan Liu 0006, Dong Zhang 0010, Chunming Wu 0001, Muhammad Khurram Khan
IEEE Trans. Netw. Serv. Manag.7
2024 rDefender: A Lightweight and Robust Defense Against Flow Table Overflow Attacks in SDN
abstract
The flow table is a critical component of Software-Defined Networking (SDN). However, flow tables’ limited capacity makes them highly vulnerable to flow table overflow attacks (FTOAs). Due to the low attack cost and highly flexible attack forms, it is hard to eradicate FTOAs. This paper addresses three unsolved problems for table security and proposes a robust defense accordingly. First, we reveal that the existing defenses with fixed defense speeds will cause severe packet loss when handling diverse traffic. We prove that deleting multiple rules can efficiently solve this problem and give a rigorous derivation to calculate the suitable deletion number according to the environment. Second, we illustrate that abnormal table occupancy squeezing is a constant characteristic of FTOAs regardless of attack forms. It can be used to identify attacked ports accurately in different scenarios. Third, we mathematically prove that random deletion can guarantee the continuous decrease of malicious flow rules after confirming attacked ports. It achieves fast speed and robust effectiveness in different environments. Based on these findings, we design rDefender, a robust and lightweight defense prototype. We evaluate its effect by designing diverse, powerful attacks and using real-world datasets and topology. The results demonstrate that it achieves the best overall performance compared to six existing mainstream defenses, providing stable security for switch flow tables.
Dezhang Kong, Xiang Chen 0017, Chunming Wu 0001, Yi Shen 0012, Zhengyan Zhou, Qiumei Cheng, Xuan Liu 0006, Yubing Qiu, Dong Zhang 0010, Muhammad Khurram Khan
IEEE Trans. Inf. Forensics Secur.6
2023 In-band Network Telemetry Manipulation Attacks and Countermeasures in Programmable Networks
abstract
In-band Network Telemetry (INT) is a widely used monitoring framework in modern large-scale networks that provides fine-grained visibility into network conditions by inserting telemetry data into packets. However, this mechanism also introduces new vulnerabilities that malicious attackers can exploit. In this paper, we present four In-band Network Telemetry Manipulation Attacks that take advantage of INT's weakness, demonstrating that attackers can cause severe damage with little effort by manipulating INT packets. To address this issue, we design SecureINT, a novel INT prototype that ensures confidentiality and integrity for INT packets. To meet the stringent computational requirements of programmable switches, we comprehensively analyze possible attacks on the deployed encryption/hash algorithms and modify them accordingly without compromising their security. According to the experiments, SecureINT can be deployed on programmable switches using a single pipeline, providing encryption and integrity verification for INT packets with minimal overhead.
Dezhang Kong, Zhengyan Zhou, Yi Shen 0012, Xiang Chen 0017, Qiumei Cheng, Dong Zhang 0010, Chunming Wu 0001
IWQoS5
2023 Combination Attacks and Defenses on SDN Topology Discovery
abstract
The topology discovery service in Software-Defined Networking (SDN) provides the controller with a global view of the substrate network topology, allowing for central management of the entire network. Unfortunately, emerging topology attacks can poison the network topology and result in unforeseeable disasters. Although researchers have made great efforts to mitigate this problem, security hazards still exist. In this paper, we propose Invisible Assailant Attack (IAA), the first combination topology attack capable of injecting and maintaining fake links even when 12 existing defense strategies are deployed simultaneously. IAA consists of 14 attack phases that apply multiple attack strategies. Attackers skillfully disguise the attack traffic in each phase so that it looks like normal network traffic, and perform these phases in a well-planned sequence, thereby bypassing existing defenses step by step. To mitigate this attack, we propose a Route Path Verification (RPV) mechanism that orchestrates multiple defense strategies to identify fake links. According to the experiments, RPV can successfully detect IAA with low overhead: its detection completes within 1 ms while its per-flow storage consumption is only a few KB.
Dezhang Kong, Yi Shen 0012, Xiang Chen 0017, Qiumei Cheng, Hongyan Liu 0001, Dong Zhang 0010, Xuan Liu 0006, Shuangxi Chen, Chunming Wu 0001
IEEE/ACM Trans. Netw.4
2022 Efficient middlebox scaling for virtualized intrusion prevention systems in software-defined networks
Junchi Xing, Chunming Wu 0001, Haifeng Zhou, Qiumei Cheng, Danrui Yu, Mayra Alexandra Macas Carrasco
Sci. China Inf. Sci.4
2021 Machine learning based malicious payload identification in software-defined networking
abstract
Deep packet inspection (DPI) has been extensively investigated in software-defined networking (SDN) as complicated attacks may intractably inject malicious payloads in the packets. Existing proprietary pattern-based or port-based third-party DPI tools can suffer from limitations in efficiently processing a large volume of data traffic. In this paper, a novel OpenFlow-enabled deep packet inspection (OFDPI) approach is proposed based on the SDN paradigm to provide adaptive and efficient packet inspection. First, OFDPI prescribes an early detection at the flow-level granularity by checking the IP addresses of each new flow via OpenFlow protocols. Then, OFDPI allows for deep packet inspection at the packet-level granularity: (i) for unencrypted packets, OFDPI extracts the features of accessible payloads, including tri-gram frequency based on Term Frequency and Inverted Document Frequency (TF–IDF) and linguistic features. These features are concatenated into a sparse matrix representation and are then applied to train a binary classifier with logistic regression rather than matching with specific pattern combinations. In order to balance the detection accuracy and performance bottleneck of the SDN controller, OFDPI introduces an adaptive packet sampling window based on the linear prediction; and (ii) for encrypted packets, OFDPI extracts notable features of packets and then trains a binary classifier with a decision tree, instead of decrypting the encrypted traffic to weaken user privacy. A prototype of OFDPI is implemented on the Ryu SDN controller and the Mininet platform. The performance and the overhead of the proposed solution are assessed using the real-world datasets through experiments. The numerical results indicate that OFDPI can provide a significant improvement in detection accuracy with acceptable overheads.
Qiumei Cheng, Chunming Wu 0001, Haifeng Zhou, Dezhang Kong, Dong Zhang 0010, Junchi Xing
J. Netw. Comput. Appl.1
2021 Intrinsic Security and Self-Adaptive Cooperative Protection Enabling Cloud Native Network Slicing
abstract
With the emergence of cloud native technology, the network slicing enables automatic service orchestration, flexible network scheduling and scalable network resource allocation, which profoundly affects the traditional security solution. Security is regarded as a technology independent of the cloud native architecture in the initial design, traditional passive defense such as “reinforced” and “stacked” is relied on to achieve system security protection. The lack of intrinsic security mechanisms makes the system capability insufficient when faces the uncertain threat brought by vulnerabilities and backdoors under the ecosystem of opening-up and sharing. The static nature of existing networks and computing systems makes them easy to be compromised and hard to defend, and thus it is urgent to provide intrinsic security and proactive protection against the unpredictable attacks. To this end, this paper proposes a novel paradigm named intrinsic cloud security (iCS) from the perspective of dynamic defense. The dynamic defense provides component-level security, and has complementary and consistency with the cloud native environment. In particular, iCS introduces mimic defense and moving target defense (MTD), and makes full use of the new features introduced by cloud native to implement an intrinsic and proactive defense mechanism with acceptable costs and efficiency. The iCS paradigm achieves seamless integration and symbiosis evolution between security and cloud native. We implement a trial of iCS based on 5GC commercial system and evaluate its performance on costs, efficiency and attack success. The result shows that the iCS enhanced mode always can provide a better and more stable defense effects.
Qiang Wu 0018, Chunming Wu 0001, Xincheng Yan, Qiumei Cheng
IEEE Trans. Netw. Serv. Manag.4
2019 Think That Attackers Think: Using First-Order Theory of Mind in Intrusion Response System
abstract
The intrusion response system is dedicated to automatically respond to sophisticated network intrusions, which is a sequential decision-making problem for autonomous agents. The current Markov decision process (MDP) or stochastic games based solutions suffer from several weaknesses: (i) The MDP- based approach is unable to explicitly model the opponents; (ii) The Nash equilibrium approach of stochastic games cannot handle the condition with multi equilibria. Existing studies have not considered the cognitive ability of the agent and lack of explicit opponent modeling. Inspired by recursive reasoning, this paper introduces a theory of mind (ToM)-based stochastic game-theoretic approach to reason about the beliefs and behaviors of the attackers. Each agent maintains different order ToM beliefs concerning his opponent with explicit opponent modeling. In order to accurately predict the attacker's action with nested beliefs, we utilize the Bayesian attack graph (BAG) to model multi-step attacks scenarios. In addition, the agent is allowed to learn from new information to adjust his beliefs and learning speed. Simulation results validate that ToM modeling performs well in the intrusion response system than random defense actions. Besides, a defender with first-order ToM beliefs always wins an attacker with zero-order ToM beliefs.
Qiumei Cheng, Chunming Wu 0001, Dezhang Kong
GLOBECOM1
2018 SDN-RDCD: A Real-Time and Reliable Method for Detecting Compromised SDN Devices
Haifeng Zhou, Chunming Wu 0001, Zhouhao Lu, Qiumei Cheng
IEEE/ACM Trans. Netw.7
2017 SDN-LIRU: A Lossless and Seamless Method for SDN Inter-Domain Route Updates
abstract
Maintaining service availability during an inter-domain route update is a challenge in both conventional networks and software-defined networks (SDNs). In the update process, asynchronous reconfigurations to border forwarding devices in different domains will incur transient anomalies with numerous packet losses and service disruptions. Based on current SDN inter-domain routing mechanisms, we in this paper propose a lossless and seamless method for SDN inter-domain route updates. This method is lightweight, and it has no requirement to add extra switch functionality or to extend SDN southbound protocols. The primary idea of this method is to achieve a lossless inter-domain route update by communications and collaborations among relevant domains. Motivated by this idea, we first identify three different domain categories for the update, i.e., domains only on the new inter-domain route, domains on both the old and new inter-domain routes, and domains only on the old inter-domain route. We further find that the transient anomalies are able to be avoided by reconfiguring the related border switches of the three categories of domains in order. Four update steps are then designed to keep the orderly update. Furthermore, we present the theoretical proof of the effectiveness of this method. Finally, based on our prototype implementation, the proposed method is also validated by simulation studies, and the simulation results indicate that this method succeeds in avoiding packet loss and maintaining service availability during the update.
Haifeng Zhou, Chunming Wu 0001, Qiumei Cheng, Qianjun Liu
IEEE/ACM Trans. Netw.3