Kaiyu Hou

dblp:202/8464 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-7551-1345ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 FaaSTracker: Efficient Cross-Layer Provenance Tracking of Serverless Applications With Multi-Source Correlation
abstract
Serverless computing, also known as Function-as-a-Service (FaaS), has gained popularity due to its flexibility, scala bility, and transparent development. However, attacks against serverless are also increasing. Unfortunately, complex multi-layer FaaS architecture and frequently launched lightweight functions help attackers conceal their tracks. Specifically, (i) fully tracking the behavior of a function requires crossing multiple layers of FaaS. (ii) Intrusive auditing components in functions affect function startup latency and performance. (iii) Accurately provenance cross-layer function invocations require integrating data from multiple sources. In this paper, we propose FAASTRACKER, a cross-layer, non-intrusive, efficient provenance framework for accurately tracking user function behaviors in FaaS. FAASTRACKER tracks function behaviors across layers using a non-intrusive agent without any modifications to the function. In addition, it correlates data from multiple sources to construct a provenance graph of function workflows to locate attackers. We implement FAASTRACKER on the OpenFaaS platform and evaluate its performance using real-world serverless applications. Compared with state-of-the-art serverless provenance systems, FAASTRACKER provides a more accurate and complete view of provenance graphs and reduces 54.0% CPU and 48.9% memory resources.
Qingyang Zeng, Lianjie Wu, Kaiyu Hou, Xue Leng, Yan Chen 0004
IEEE Trans. Inf. Forensics Secur.3
2024 Property Guided Secure Configuration Space Search
You Li 0008, Kaiyu Hou, Yunqi He, Yan Chen 0004, Hai Zhou 0001
ISC (2)2
2024 DirectFaaS: A Clean-Slate Network Architecture for Efficient Serverless Chain Communications
abstract
Serverless computing, also known as Function-as-a-Service (FaaS), triggers web applications in the form of function chains. It uses a central orchestrator to route all requests from end-users and internal functions. Such architecture simplifies application deployment for developers. However, the convenient centralized network architecture compromises the efficiency of function chain communications. Specifically, (i) a centralized API gateway assists in routing requests between functions. This indirect routing scheme raises invocation latency. (ii) The control flow for invoking functions and the data flow for passing function data packets are both forwarded by the API gateway. This results in the API gateway consuming a significant amount of resources. (iii) All data packets of internal function communications go through the same API gateway. This expands the additional attack surface in multi-tenant scenarios.
Qingyang Zeng, Kaiyu Hou, Xue Leng, Yan Chen 0004
WWW2
2022 QFaaS: accelerating and securing serverless cloud networks with QUIC
abstract
Serverless computing has greatly simplified cloud programming. It liberates cloud tenants from various system administration and resource management tasks, such as configuration and provisioning. Under this new cloud computing paradigm, a single monolithic application is divided into separate stateless functions, i.e., function-as-a-service (FaaS), which are then orchestrated together to support complex business logic. But there is a fundamental cost associated with this enhanced flexibility. Internal network connections between functions are now initiated frequently, to support serverless features such as agile autoscaling and function chains, raising communication latency. To alleviate this cost, current serverless providers sacrifice security for performance, keeping internal function communications unencrypted.
Kaiyu Hou, Sen Lin 0009, Yan Chen 0004, Vinod Yegneswaran
SoCC1
2021 Accelerate and secure serverless networks with QUIC
abstract
In serverless computing [3], cloud providers manage responsibility for all server-related tasks, including both hardware resource allocation and software runtime preparation. Cloud tenants are thus free to simply focus on designing discrete stateless functions and orchestrate them together for their high-level business logic.
Kaiyu Hou, Sen Lin 0009, Yan Chen 0004, Vinod Yegneswaran
CoNEXT1
2021 Discovering emergency call pitfalls for cellular networks with formal methods
abstract
Availability and security problems in cellular emergency call systems can cost people their lives, yet this topic has not been thoroughly researched. Based on our proposed Seed-Assisted Specification method, we start to investigate this topic by looking closely into one emergency call failure case in China. Using what we learned from the case as prior knowledge, we build a formal model of emergency call systems with proper granularity. By running model checking, four public-unaware scenarios where emergency calls cannot be correctly routed are discovered. Additionally, we extract configurations of two major U.S. carriers and incorporate them as model constraints into the model. Based on the augmented model, we find two new attacks leveraging the privileges of emergency calls. Finally, we present a solution with marginal overhead to resolve issues we can foresee.
Kaiyu Hou, You Li 0008, Yinbo Yu, Yan Chen 0004, Hai Zhou 0001
MobiSys1
2020 Corrigendum to "COIN: A fast packet inspection method over compressed traffic" [J. Netw. Comput. Appl. 127(2019) 122-134]
Xiuwen Sun, Hao Li 0011, Xingxing Lu, Kaiyu Hou, Chengchen Hu
J. Netw. Comput. Appl.5
2019 A lightweight policy enforcement system for resource protection and management in the SDN-based cloud
Xue Leng, Kaiyu Hou, Yan Chen 0004, Kai Bu, Libin Song, You Li 0008
Comput. Networks2
2019 COIN: A fast packet inspection method over compressed traffic
Xiuwen Sun, Hao Li 0011, Xingxing Lu, Kaiyu Hou, Chengchen Hu
J. Netw. Comput. Appl.5
2018 SDNKeeper: Lightweight Resource Protection and Management System for SDN-Based Cloud
abstract
SDN-based cloud has the merit of allowing more flexibility in network management, however, the security of network accessing and the correctness of network configuration in SDN-based cloud have not been effectively addressed yet. In this paper, SDNKeeper, a generic and fine-grained policy enforcement system in SDN-based cloud is proposed, which can defend against unauthorized attacks and avoid network resource misconfiguration. With the usage of SDNKeeper, numerous flexible network management policies can be created by administrators, which give administrators the discretionary room on controlling the network resources. To be specific, SDNKeeper can reject any unauthorized network access request at Northbound Interface (NBI), which located between application plane and control plane. Moreover, compared with other traditional policy-based access control systems, SDNKeeper is totally application-transparent and lightweight, which is easy to implement, deploy and runtime configure. Based on the prototype implementation and evaluation, we conclude that SDNKeeper can perform access control accurately with negligible computation overhead whilst the throughput degradation is still within the acceptable range.
Xue Leng, Kaiyu Hou, Yan Chen 0004, Kai Bu, Libin Song
IWQoS2
2017 SoftRing: Taming the reactive model for software defined networks
abstract
The reactive model of Software Defined Networking (SDN) invokes controller to dynamically determine the behaviors of a new flow without any pre-knowledge in the data plane. However, the reactive events raised by such flexible model meanwhile consume lots of the bottleneck resources of the fast memory in switch and bandwidth between controller and switches. To address this problem, we propose SoftRing with the motivation to mitigate the overhead to handle a reactive event. In fact, the reactive packets are not necessarily stored in the switch or sent to the controller; instead, they are forwarded to traverse a pre-defined loop path. The packets will finally leave the loop path after the switch rules related to the packet flow being updated to switches in the loop with fewer flow entries. We have implemented a SoftRing system that integrates the controller and software/hardware SDN switches. The results show that SoftRing can eliminate the fast memory requirement for reactive packets and reduce the control channel bandwidth consumption up to 80%, with the cost of less than 5% data plane bandwidth, an average of three extra flow entries in each switch, and minor extra latency for the flow forwarding.
Chengchen Hu, Kaiyu Hou, Hao Li 0011, Ruilong Wang, Peng Zhang 0011, Huanzhao Wang
ICNP2
2017 Towards a fast packet inspection over compressed HTTP traffic
abstract
Matching multiple patterns is the key technology in firewall, Intrusion Detection Systems, etc. However, most of the web services nowadays tend to compress their traffic for less transferring data and better user experience, which has challenged the multi-pattern matching original working only on raw content. Naive and straightforward solutions towards this challenge either decompress the compressed data first and apply legacy multi-pattern matching methods, or have to scan redundant data during the matching., which are not fast and memory efficient. In this paper, we propose COmpression INspection (COIN) method for multi-pattern matching on compressed HTTP traffic. COIN does not decompress the data before matching and only scans once each bit of the traffic under inspection. We have collected real traffic data from Alexa.com top 500 and Alexa.cn top 20000 web sites and have performed the experiments under 1430 SNORT patterns. The evaluation results show that COIN is 10–31% faster than state-of-the-art approach.
Xiuwen Sun, Kaiyu Hou, Hao Li 0011, Chengchen Hu
IWQoS2