Benjamin E. Ujcich

dblp:205/3765 · DBLP profile ↗
← Back
13ranked-venue papers
7as first author
6since 2021 · last 2025
0009-0001-3433-9972ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 4 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Chimera: Fuzzing P4 Network Infrastructure for Multi-Plane Bug Detection and Vulnerability Discovery
abstract
Programmable network data planes, such as P4, offer flexibility in defining network forwarding behavior. However, such programmability introduces a new attack surface for bugs and security vulnerabilities. Most P4 security research has focused solely on the data plane, overlooking its integration with the control plane. We investigated past bug reports in open-source P4 implementations across both control and data planes, and we observed that many P4 network bugs and vulnerabilities arise from the interplay between these planes. We present Chimera, a comprehensive P4 fuzzer that targets bugs requiring multi-plane inputs and impacts. Unlike existing network fuzzers that operate separately on each plane, Chimera uses concolic execution to capture control-data plane interactions. Chimera introduces two novel input mutation strategies to exploit interdependencies across both planes and P4 programs: parser-aware packet mutation (PAPM) and header-guided rule generation (HGRG). Evaluating Chimera on ONOS, Stratum, and BMv2, we discovered 7 new bugs, including 3 security-critical vulnerabilities, 2 bugs triggered by multi-plane inputs, and 2 cross-plane bugs. Chimera outperforms state-of-the-art single-plane fuzzers with higher coverage and a 3.5x higher bug detection rate.
Jiwon Kim 0001, Jing (Dave) Tian, Benjamin E. Ujcich
SP3
2024 Exploiting Temporal Vulnerabilities for Unauthorized Access in Intent-based Networking
abstract
Intent-based networking (IBN) enables network administrators to express high-level goals and network policies without needing to specify low-level forwarding configurations, topologies, or protocols. Administrators can define intents that capture the overall behavior they want from the network, and an IBN controller compiles such intents into low-level configurations that get installed in the network and implement the desired behavior.
Ben Weintraub, Jiwon Kim 0001, Cristina Nita-Rotaru, Hamed Okhravi, Jing (Dave) Tian, Benjamin E. Ujcich
CCS7
2024 NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge
abstract
NetShuffle is a censorship resistance system that offers "shuffle proxies," where regular proxy services (e.g., HTTPS proxies, Tor bridges) are decoupled from their addresses via continuous in-network change. This makes shuffle proxies significantly more difficult to block compared to their traditional counterparts, because the network locations are now in constant flux. NetShuffle is also designed to engage a new class of support base—edge networks—which have received scant attention from existing work. NetShuffle uses emerging programmable switches to provide the shuffle, while staying otherwise transparent to services and clients, enabling it to be applied as a drop-in network appliance to help promote Internet freedom. We have prototyped NetShuffle in testbed environments and operated it seamlessly on a slice of a live campus network for more than a month, showing that it provides network shuffles in a way that is transparent and incurs negligible overheads.
Patrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Diogo Barradas, Ang Chen 0001, Micah Sherr, Benjamin E. Ujcich
SP8
2024 Provenance-Enabled Explainable AI
abstract
Machine learning (ML) algorithms have advanced significantly in recent years, progressively evolving into artificial intelligence (AI) agents capable of solving complex, human-like intellectual challenges. Despite the advancements, the interpretability of these sophisticated models lags behind, with many ML architectures remaining "black boxes" that are too intricate and expansive for human interpretation. Recognizing this issue, there has been a revived interest in the field of explainable AI (XAI) aimed at explaining these opaque ML models. However, XAI tools often suffer from being tightly coupled with the underlying ML models and are inefficient due to redundant computations. We introduce provenance-enabled explainable AI (PXAI). PXAI decouples XAI computation from ML models through a provenance graph that tracks the creation and transformation of all data within the model. PXAI improves XAI computational efficiency by excluding irrelevant and insignificant variables and computation in the provenance graph. Through various case studies, we demonstrate how PXAI enhances computational efficiency when interpreting complex ML models, confirming its potential as a valuable tool in the field of XAI.
Jiachi Zhang 0002, Wenchao Zhou, Benjamin E. Ujcich
Proc. ACM Manag. Data3
2023 Intender: Fuzzing Intent-Based Networking with Intent-State Transition Guidance
Jiwon Kim 0001, Benjamin E. Ujcich, Jing (Dave) Tian
USENIX Security Symposium2
2021 Causal Analysis for Software-Defined Networking Attacks
Benjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates 0001, William H. Sanders, Hamed Okhravi
USENIX Security Symposium1
2020 Automated Discovery of Cross-Plane Event-Based Vulnerabilities in Software-Defined Networking
Benjamin E. Ujcich, Samuel Jero, Richard Skowyra, Steven R. Gomez, Adam Bates 0001, William H. Sanders, Hamed Okhravi
NDSS1
2020 Provenance for Intent-Based Networking
abstract
Intent-based networking (IBN) promises to simplify the network management and automated orchestration of high-level policies in future networking architectures such as software-defined networking (SDN). However, such abstraction and automation creates new network visibility challenges. Existing SDN network forensics and diagnostics tools operate at a lower level of network abstraction, which makes intent-level reasoning difficult. We present PRovINTENT, a framework extension for SDN control plane tools that accounts for intent semantics. PRovINTENT records the provenance and evolution of intents as the network's state and apps' requests change over time and enables reasoning at multiple abstractions. We define an intent provenance model, we implement a proof-of-concept tool, and we evaluate the efficacy of PRovINTENT'S explanatory capabilities by using a representative intent-driven network application.
Benjamin E. Ujcich, Adam Bates 0001, William H. Sanders
NetSoft1
2019 Data Protection Intents for Software-Defined Networking
abstract
The rise of intent-based networking (IBN) allows enterprises to use software-defined networking (SDN) architectures to specify what network requirements are needed rather than specify how such requirements will be implemented. For enterprises that process personal data, those network requirements must necessarily consider data protection by design to comply with new regulations such as the European Union's GDPR. We argue that the centralized data plane view of SDN architectures and the network intent abstractions of IBN can aid in the design of systems that require data protection. We propose a data protection intent framework that leverages SDN and network intents. We use the GDPR as a representative data protection framework and identify the applicable regulatory requirements for system and network design. Based on those requirements, we design an SDN-based architecture for data protection intents that allows data services to request network resources by using data protection abstractions. We implement a proof-of-concept network application for the ONOS SDN controller and explain how our framework can be useful in a representative data breach case study to aid in responding to regulator requests.
Benjamin E. Ujcich, William H. Sanders
NetSoft1
2018 Cross-App Poisoning in Software-Defined Networking
abstract
Software-defined networking (SDN) continues to grow in popularity because of its programmable and extensible control plane realized through network applications (apps). However, apps introduce significant security challenges that can systemically disrupt network operations, since apps must access or modify data in a shared control plane state. If our understanding of how such data propagate within the control plane is inadequate, apps can co-opt other apps, causing them to poison the control plane's integrity. We present a class of SDN control plane integrity attacks that we call cross-app poisoning (CAP), in which an unprivileged app manipulates the shared control plane state to trick a privileged app into taking actions on its behalf. We demonstrate how role-based access control (RBAC) schemes are insufficient for preventing such attacks because they neither track information flow nor enforce information flow control (IFC). We also present a defense, ProvSDN, that uses data provenance to track information flow and serves as an online reference monitor to prevent CAP attacks. We implement ProvSDN on the ONOS SDN controller and demonstrate that information flow can be tracked with low-latency overheads.
Benjamin E. Ujcich, Samuel Jero, Anne Edmundson, Qi Wang 0017, Richard Skowyra, James Landry, Adam Bates 0001, William H. Sanders, Cristina Nita-Rotaru, Hamed Okhravi
CCS1
2017 REMAX: Reachability-Maximizing P2P Detection of Erroneous Readings in Wireless Sensor Networks
abstract
Wireless sensor networks (WSNs) should collect accurate readings to reliably capture an environment's state. However, readings may become erroneous because of sensor hardware failures or degradation. In remote deployments, centrally detecting those reading errors can result in many message transmissions, which in turn dramatically decreases sensor battery life. In this paper, we address this issue through three main contributions. First, we propose REMAX, a peer-to-peer (P2P) error detection protocol that extends the WSN's life by minimizing message transmissions. Second, we propose a low-overhead error detection approach that helps minimize communication complexity. Third, we evaluate our approach via a trace-driven, discrete-event simulator, using two datasets from real WSN deployments that measure indoor air temperature and seismic wave amplitude. Our results show that REMAX can accurately detect errors and extend the WSN's reachability (effective lifetime) compared to the centralized approach.
Varun Badrinath Krishna, Michael J. Rausch, Benjamin E. Ujcich, Indranil Gupta, William H. Sanders
DSN3
2017 ATTAIN: An Attack Injection Framework for Software-Defined Networking
abstract
Software-defined networking (SDN) has recently attracted interest as a way to provide cyber resiliency because of its programmable and logically centralized nature. However, the security of the SDN architecture itself against malicious attacks is not well understood and must be ensured in order to provide cyber resiliency to systems that use SDNs. In this paper, we present ATTAIN, an attack injection framework for OpenFlow-based SDN architectures. First, we define an attack model that relates system components to an attacker's capability to influence control plane behavior. Second, we define an attack language for writing control plane attacks that can be used to evaluate SDN implementations. Third, we describe an attack injector architecture that actuates attacks in networks. Finally, we evaluate our framework with an enterprise network case study by writing and running attacks with popular SDN controllers.
Benjamin E. Ujcich, Uttam Thakore, William H. Sanders
DSN1
2012 Thoughts on the Internet architecture from a modern enterprise network outage
abstract
Today's state-of-the-art enterprise networks follow a distributed architecture that provides a high degree of reliability in most instances. These networks, however, have limitations in their ability to function in certain catastrophic conditions. In this paper, we provide a detailed study of a recent systemic network outage that affected Clemson University's enterprise network to show the shortcomings of the distributed Internet architecture. Of particular note are the LAN spanning tree implementations, access control list implementations, and redundancy protocols. The observations shed light on opportunities where the emerging software-defined networking (SDN) paradigm may help avoid such difficult situations through a centralized control plane.
Benjamin E. Ujcich, Kuang-Ching Wang, Brian Parker, Daniel Schmiedt
NOMS1