Minzhao Lyu

dblp:202/9027 · DBLP profile ↗
← Back
15ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0001-8677-248XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 6 first-author · 9 since 2021Security and privacy · 3 · 3 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Systematic assessment of cloud game adaptability for network conditions and user experience
abstract
Cloud gaming platforms lower the access barriers to graphics-intensive games by rendering computationally heavy game scenes on cloud GPU servers and streaming them back to players as real-time video, which in turn places significant demands on carrier networks to deliver these video streams with high throughput, low latency and minimal packet loss. To achieve decent user experience, cloud gaming platforms adapt streaming behaviors based on network conditions and allow users to adjust their graphics settings. Knowing the level of game streaming adaptability offered by various cloud gaming providers is helpful for network operators to effectively provision network resources for subscriber satisfaction, and for game development community to incentivize cloud gaming providers to better optimize their streaming techniques. Toward this objective, we develop a systematic framework to assess the adaptability of a cloud gaming platform in reducing network demand for lower client graphics settings; and in adjusting streaming quality under constrained network conditions for smooth gaming experience. Focusing on four popular platforms (NVIDIA GFN, Xbox, PlayStation and Amazon Luna), we begin by empirically profiling and comparing how they adapt game streaming characteristics to various levels of client graphics settings and network conditions. Building on the insights, we develop our systematic assessment framework, which provides quantitative scores for both fine-grained metrics by processing labeled traffic traces, as well as aggregated scores tailored to an assessor’s preference. We showcase our quantitative assessments of the four platforms.
Minzhao Lyu, Yifan Wang 0034, Vijay Sivaraman
Comput. Networks1
2026 A Large-Scale Network Measurement Study of NVIDIA GeForce NOW Cloud Gaming in the Wild
Minzhao Lyu, Vijay Sivaraman
IEEE Trans. Netw.1
2025 Games Are Not Equal: Classifying Cloud Gaming Contexts for Effective User Experience Measurement
abstract
To tap into the growing market of cloud gaming, whereby game graphics is rendered in the cloud and streamed back to the user as a video feed, network operators are creating monetizable assurance services that dynamically provision network resources. However, without accurately measuring cloud gaming user experience, they cannot assess the effectiveness of their provisioning methods. Basic measures such as bandwidth and frame rate by themselves do not suffice, and can only be interpreted in the context of the game played and the player activity within the game. This paper equips the network operator with a method to obtain a real-time measure of cloud gaming experience by analyzing network traffic, including contextual factors such as the game title and player activity stage. Our method is able to classify the game title within the first five seconds of game launch, and continuously assess the player activity stage as being active, passive, or idle. We deploy it in an ISP hosting NVIDIA cloud gaming servers for the region. We provide insights from hundreds of thousands of cloud game streaming sessions over a three-month period into the dependence of bandwidth consumption and experience level on the gameplay contexts.
Yifan Wang 0034, Minzhao Lyu, Vijay Sivaraman
IMC2
2024 Characterizing User Platforms for Video Streaming in Broadband Networks
abstract
Internet Service Providers (ISPs) bear the brunt of being the first port of call for poor video streaming experience. ISPs can benefit from knowing the user's device type (e.g., Android, iOS) and software agent (e.g., native app, Chrome) to troubleshoot platform-specific issues, plan capacity and create custom bundles. Unfortunately, encryption and NAT have limited ISPs' visibility into user platforms across video streaming providers. We develop a methodology to identify user platforms for video streams from four popular providers, namely YouTube, Netflix, Disney, and Amazon, by analyzing network traffic in real-time. First, we study the anatomy of the connection establishment process to show how TCP/QUIC and TLS handshakes vary across user platforms. We then develop a classification pipeline that uses 62 attributes extracted from the handshake messages to determine the user device and software agent of video flows with over 96% accuracy. Our method is evaluated and deployed in a large campus network (mimicking a residential broadband network) serving users including dormitory residents. Analysis of 100+ million video streams over a four-month period reveals insights into the mix of user platforms across the video providers, variations in bandwidth consumption across operating systems and browsers, and differences in peak hours of usage.
Yifan Wang 0034, Minzhao Lyu, Vijay Sivaraman
IMC2
2024 Realizing Open and Decentralized Marketplace for Exchanging Data of Expected IoT Behaviors
abstract
As data marketplaces become popular in different domains, this paper proposes creating a special marketplace focused on IoT cybersecurity. The goal is to openly share knowledge about IoT devices’ behavior, using structured data formats like Manufacturer Usage Description (MUD) files. To make this work1, we employ technologies like blockchain and smart contracts to build a practical and secure foundation for sharing and accessing important information about how IoT devices should behave on the network. Our contributions are two-fold. (1) We develop a smart contract on the Ethereum blockchain with five concrete functions that realize the essential features of an effective marketplace for sharing data related to the expected behaviors of IoT devices. (2) We implement a prototype of our marketplace in a private chain environment—our codes are publicly released. We demonstrate how effectively our marketplace functions through experiments involving MUD files from consumer IoT devices. Our marketplace enables suppliers and consumers to share MUD data on the Ethereum blockchain for under a hundred dollars, promoting accessibility and participation.
Minzhao Lyu, Hassan Habibi Gharakheili
NOMS2
2024 Network Anatomy and Real-Time Measurement of Nvidia GeForce NOW Cloud Gaming
Minzhao Lyu, Sharat Chandra Madanapalli, Arun Vishwanath, Vijay Sivaraman
PAM (1)1
2023 PEDDA: Practical and Effective Detection of Distributed Attacks on enterprise networks via progressive multi-stage inference
Minzhao Lyu, Hassan Habibi Gharakheili, Vijay Sivaraman
Comput. Networks1
2023 Enterprise DNS Asset Mapping and Cyber-Health Tracking via Passive Traffic Analysis
abstract
The Domain Name System (DNS) is a critical service that enables domain names to be converted to IP addresses (or vice versa); consequently, it is generally permitted through enterprise security systems (e.g.,firewalls) with little restriction. This has exposed organizational networks to DDoS, exfiltration, and reflection attacks, inflicting significant financial and reputational damage. Large organizations with loosely federated IT departments (e.g.,Universities and Research Institutes) often are not fully aware of all their DNS assets and vulnerabilities, let alone the attack surface they expose to the outside world. In this paper, we address the “DNS blind spot” by developing methods to passively analyze live DNS traffic, identify organizational DNS assets, and monitor their health on a continuous basis. Our contributions are threefold. First, we perform a comprehensive analysis of all DNS traffic in two large organizations (a University Campus and a Government Research Institute) for over a month, and identify key behavioral profiles for various asset types such as recursive resolvers, authoritative name servers, and mixed DNS servers. Second, we develop an unsupervised clustering method that classifies enterprise DNS assets using the behavioral attributes identified, and demonstrate that our method successfully classifies over 100 DNS assets across the two organizations. Third, our method continuously tracks various health metrics across the organizational DNS assets and identifies several instances of improper configuration, data exfiltration, DDoS, and reflection attacks. We believe the passive analysis methods in this paper can help enterprises monitor organizational DNS health in an automated and risk-free manner.
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.1
2022 Classifying and tracking enterprise assets via dual-grained network behavioral analysis
Minzhao Lyu, Hassan Habibi Gharakheili, Vijay Sivaraman
Comput. Networks1
2021 A Security Awareness and Protection System for 5G Smart Healthcare Based on Zero-Trust Architecture
abstract
The key features of 5G network (i.e., high bandwidth, low latency, and high concurrency) along with the capability of supporting big data platforms with high mobility make it valuable in coping with emerging medical needs, such as COVID-19 and future healthcare challenges. However, enforcing the security aspect of a 5G-based smart healthcare system that hosts critical data and services is becoming more urgent and critical. Passive security mechanisms (e.g., data encryption and isolation) used in legacy medical platforms cannot provide sufficient protection for a healthcare system that is deployed in a distributed manner and fail to meet the need for data/service sharing across "cloud-edge-terminal" in the 5G era. In this article, we propose a security awareness and protection system that leverages zero-trust architecture for a 5G-based smart medical platform. Driven by the four key dimensions of 5G smart healthcare including "subject" (i.e., users, terminals, and applications), "object" (i.e., data, platforms, and services), "behavior," and "environment," our system constructs trustable dynamic access control models and achieves real-time network security situational awareness, continuous identity authentication, analysis of access behavior, and fine-grained access control. The proposed security system is implemented and tested thoroughly at industrial-grade, which proves that it satisfies the needs of active defense and end-to-end security enforcement of data, users, and services involved in a 5G-based smart medical system.
BaoZhan Chen, Siyuan Qiao, Dongqing Liu, Xiaobing Shi, Minzhao Lyu, Huimin Lu 0001, Yunkai Zhai
IEEE Internet Things J.6
2021 Hierarchical Anomaly-Based Detection of Distributed DNS Attacks on Enterprise Networks
abstract
Domain Name System (DNS) is a critical service for enterprise operations, and is often made openly accessible across firewalls. Malicious actors use this fact to attack organizational DNS servers, or use them as reflectors to attack other victims. Further, attackers can operate with little resources, can hide behind open recursive resolvers, and can amplify their attack volume manifold. The rising frequency and effectiveness of DNS-based DDoS attacks make this a growing concern for organizations. Solutions available today, such as firewalls and intrusion detection systems, use combinations of black-lists of malicious sources and thresholds on DNS traffic volumes to detect and defend against volumetric attacks, which are not robust to attack sources that morph their identity or adapt their rates to evade detection. We propose a method for detecting distributed DNS attacks that uses a hierarchical graph structure to track DNS traffic at three levels of host, subnet, and autonomous system (AS), combined with machine learning that identifies anomalous behaviors at various levels of the hierarchy. Our method can detect distributed attacks even with low rates and stealthy patterns. Our contributions are three-fold: (1) We analyze real DNS traffic over a week (nearly 400M packets) from the edges of two large enterprise networks to highlight various types of incoming DNS queries and the behavior of malicious entities generating query scans and floods; (2) We develop a hierarchical graph structure to monitor DNS activity, identify key attributes, and train/tune/evaluate anomaly detection models for various levels of the hierarchy, yielding more than 99% accuracy at each level; and (3) We apply our scheme to a month's worth of DNS data from the two enterprises and compare the results against blacklists and firewall logs to demonstrate its ability in detecting distributed attacks that might be missed by legacy methods while maintaining a decent real-time performance.
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.1
2019 Mapping an Enterprise Network by Analyzing DNS Traffic
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
PAM1
2019 iTeleScope: Softwarized Network Middle-Box for Real-Time Video Telemetry and Classification
abstract
Video continues to dominate network traffic, yet operators today have poor visibility into the number, duration, and resolutions of the video streams traversing their domain. Current monitoring approaches are inaccurate, expensive, or unscalable, as they rely on statistical sampling, middle-box hardware, or packet inspection software. We present iTelescope, the first intelligent, inexpensive, and scalable softwarized network middle-box solution for identifying and classifying video flows in realtime. Our solution is novel in combining dynamic flow rules with telemetry and machine learning, and is built on commodity OpenFlow switches and open-source software. We develop a fully functional system, train it in the lab using multiple machine learning algorithms, and validate its performance to show over 95% accuracy in identifying and classifying video streams from many providers, including YouTube and Netflix. Lastly, we conduct tests to demonstrate its scalability to tens of thousands of concurrent streams, and deploy it live on a campus network serving several hundred real users. Our traffic monitoring system gives unprecedented fine-grained real-time visibility of video streaming performance to operators of enterprise and carrier networks at very low cost.
Hassan Habibi Gharakheili, Minzhao Lyu, Yu Wang 0131, Himal Kumar, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.2
2018 Real-time detection, isolation and monitoring of elephant flows using commodity SDN system
abstract
Operators of enterprise and carrier networks in-creasingly require real-time visibility into traffic patterns in their network, so they can do better resource management (congestion detection, dynamic routing, capacity scheduling) and security protection (detection of intrusions and volumetric attacks). Of particular interest are elephant flows that transfer large volumes, since they demand most resources and can inflict most damage. Today's techniques for detecting and monitoring elephant flows are based on software-based packet analysis or hardware-based inspection, which are either unscalable or expensive. In this paper we design, implement, and evaluate an SDN-based solution that is scalable (to tens of Gigabits-per-second) and inexpensive (built using commodity OpenFlow switches). We first develop a system architecture that judiciously combines software packet inspection with hardware flow-table counters to identify and monitor heavy flows. We then use real traffic traces taken from a campus network to tune our algorithm parameters for desired trade-off between software load and hardware table size. Finally, we prototype our solution on a commodity OpenFlow hardware switch together with open-source controller and packet inspection software, and demonstrate operation at 10Gbps in a real campus network.
Sharat Chandra Madanapalli, Minzhao Lyu, Himal Kumar, Hassan Habibi Gharakheili, Vijay Sivaraman
NOMS2
2017 Quantifying the reflective DDoS attack capability of household IoT devices
abstract
Distributed Denial-of-Service (DDoS) attacks are increasing in frequency and volume on the Internet, and there is evidence that cyber-criminals are turning to Internet-of-Things (IoT) devices such as cameras and vending machines as easy launchpads for large-scale attacks. This paper quantifies the capability of consumer IoT devices to participate in reflective DDoS attacks. We first show that household devices can be exposed to Internet reflection even if they are secured behind home gateways. We then evaluate eight household devices available on the market today, including lightbulbs, webcams, and printers, and experimentally profile their reflective capability, amplification factor, duration, and intensity rate for TCP, SNMP, and SSDP based attacks. Lastly, we demonstrate reflection attacks in a real-world setting involving three IoT-equipped smart-homes, emphasising the imminent need to address this problem before it becomes widespread.
Minzhao Lyu, Daniel Sherratt, Arunan Sivanathan, Hassan Habibi Gharakheili, Adam Radford, Vijay Sivaraman
WISEC1