Shihan Lin

dblp:205/5888 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-7182-9041ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 2 first-author · 6 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Cost-effective and Reliable Global Internet Peering with Programmable Switches
Congcong Miao, Zhiyi Yao, Jianchao Lv, Jinglin Wang, Shihan Lin, Xinyi Zhang 0004, Yunming Xiao, Jiwu Bu, Yachen Wang, Xianneng Zou, Yong Jiang 0001, Marco Canini, Gaogang Xie
NSDI5
2026 XFir: Accelerating New-Flow Setup on Host Servers of a Large Cloud Network
abstract
In today's cloud networks, host servers widely deploy Data Processing Units (DPUs) as network accelerators under the "Sep-Path" paradigm. However, as server capabilities scale with increasing CPU cores and network bandwidth, the software slow path (executed on a DPU's CPU) has become a critical bottleneck for workloads with high new-flow rates. Meanwhile, new-flow setup logic on host servers must continuously evolve to meet diverse and changing customer demands, making flexibility a key requirement alongside performance. To address this gap, we present XFir, the first hardware-accelerated new-flow setup system for cloud host servers that delivers high CPS throughput while preserving sufficient flexibility. XFir leverages a next-generation DPU equipped with a Cloud Network co-Processor (CNP) to execute the host server's new-flow setup logic. XFir redesigns the host-server flow-setup datapath and table layout, optimizes LPM lookups, and introduces CPU-CNP collaboration mechanisms to further improve performance and reliability. Our evaluation shows that XFir achieves over 776K new-flow CPS on a single host server with 11.7μs slow-path latency. Compared to prior work (Fornax), XFir achieves 4.8x CPS and reduces latency by 69.2%. Moreover, XFir is cost-effective to deploy, requiring only a single DPU per host. Overall, XFir improves new-flow throughput while maintaining development flexibility at low financial cost.
Shihan Lin, Shunqiao Jiang, Chao Pei, Jian Zhao 0006, Wenjun Wu 0001, Lijun Zhuang, Qingmin Liu, Heng Yu 0005, Yibo Huang 0005, Yifei Zhu 0001, Yunming Xiao, Ang Chen 0001, Linghe Kong, Congcong Miao
SIGCOMM1
2025 PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery Networks
Shihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu, Aleksandar Kuzmanovic, Xiaowei Yang 0001
NSDI1
2025 Characterizing Anycast Flipping: Prevalence and Impact
Shihan Lin, Tingshan Huang, Bruce M. Maggs, Kyle Schomp, Xiaowei Yang 0001
PAM2
2024 Dissecting the Applicability of HTTP/3 in Content Delivery Networks
abstract
HTTP/3 (H3) has experienced significant growth and extensive adoption in various scenarios, especially in Content Delivery Networks (CDNs). Over the past few years, there have been numerous insightful studies on its deployment in industrial CDNs. However, these studies often separately analyze H3 and CDN, overlooking their synergistic integration. In this work, we explore the applicability of H3 in CDN from a holistic perspective. We analyze 325 websites hosted by seven CDN providers and identify three key characteristics where CDN align perfectly with H3's strengths. Firstly, CDN resources dominate the composition of webpages, where enabling H3 can amplify H3's benefits in connection acceleration. Secondly, CDN providers also exhibit a dominant characteristic, with the majority of CDN resources hosted by a few large providers. This phenomenon makes different webpages share the same provider. When browsing consecutively, H3 helps to skip the connection phase by resuming the connections to the same CDN provider across pages. Thirdly, H3 mitigates the congestion problem on webpages serving multiple CDN resources. This work provides a deeper insight into the applicability of H3 in large-scale distributed systems like CDNs, holding promise for informing the development and optimization of industrial H3.
Yang Chen 0001, Shihan Lin, Xin Wang 0002, Bingyang Liu, Aaron Yi Ding
ICDCS3
2024 Browsing without Third-Party Cookies: What Do You See?
abstract
Third-party web cookies are often used for privacy-invasive behavior tracking. Partly due to privacy concerns, browser vendors have started to block all third-party cookies in recent years. To understand the effects of such third-party cookieless browsing, we crawled and measured the top 10,000 Tranco websites. We developed a framework to remove third-party cookies and analyze the differences between the appearance of web pages with and without these cookies. We find that disabling third-party cookies has no substantial effect on website appearance including layouts, text, and images. This validates the industry-wide shift towards cookieless browsing as a way to protect user privacy without compromising on the user experience.
Maxwell Lin, Shihan Lin, Helen Wu, Karen Wang, Xiaowei Yang 0001
IMC2
2024 Demo: CTSim: A Scalable and Flexible Cybertwin Network Simulator for Internet of Things Scenarios
abstract
The future of networking must address the connectivity demands of billions of people and trillions of networked devices. The Intelligent Internet of Everything (IoE) is widely considered the next evolution of the Internet, yet it poses significant challenges to the current TCP/IP architecture. To overcome these challenges, the concept of the Cybertwin network has been proposed as a promising future Internet architecture. To facilitate the advancement of Cybertwin-related research, we have developed CTSim, a Cybertwin network simulator. Our demo demonstrates that the Cybertwin network could effectively enhances mobility, availability, and security in Internet of Things scenarios, making it a powerful tool for researchers in these fields.
Yuke Ma, Shihan Lin, Yang Chen 0001, Jun Wu 0006
SenSys2
2023 Remote Procedure Call as a Managed System Service
Jingrong Chen 0002, Shihan Lin, Yechen Xu, Xinhao Kong, Thomas E. Anderson, Matthew Lentz, Xiaowei Yang 0001, Danyang Zhuo
NSDI3
2023 Quantifying User Password Exposure to Third-Party CDNs
Rui Xin 0002, Shihan Lin, Xiaowei Yang 0001
PAM2
2022 InviCloak: An End-to-End Approach to Privacy and Performance in Web Content Distribution
abstract
In today's web ecosystem, a website that uses a Content Delivery Network (CDN) shares its Transport Layer Security (TLS) private key or session key with the CDN. In this paper, we present the design and implementation of InviCloak, a system that protects the confidentiality and integrity of a user and a website's private communications without changing TLS or upgrading a CDN. InviCloak builds a lightweight but secure and practical key distribution mechanism using the existing DNS infrastructure to distribute a new public key associated with a website's domain name. A web client and a website can use the new key pair to build an encryption channel inside TLS. InviCloak accommodates the current web ecosystem. A website can deploy InviCloak unilaterally without a client's involvement to prevent a passive attacker inside a CDN from eavesdropping on their communications. If a client also installs InviCloak's browser extension, the client and the website can achieve end-to-end confidential and untampered communications in the presence of an active attacker inside a CDN. Our evaluation shows that InviCloak increases the median page load times (PLTs) of realistic web pages from 2.0s to 2.1s, which is smaller than the median PLTs (2.8s) of a state-of-the-art TEE-based solution.
Shihan Lin, Rui Xin 0002, Aayush Goel, Xiaowei Yang 0001
CCS1
2019 Understanding Skout users' mobility patterns on a global scale: a data-driven study
Yang Chen 0001, Shihan Lin, Tianyong Zhang, Yu Xiao 0001, Xin Wang 0002
World Wide Web3