Kaiyang Zhao 0004

dblp:260/8424-4 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-0077-6848ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 4 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Towards High-Performance Intrusion Detection with Robustness Guarantees on Programmable Switches at ISP Scale
abstract
In order to provide security connections to the enterprise campus sites, internet service providers are offering comprehensive intrusion detection services at the network layer. However, existing network intrusion detection systems (NIDS) are either ineffective or inefficient for high-speed network protection, especially for encrypted traffic analysis. In this paper, we design and implement SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP. SiteGuard proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed. SiteGuard also proposes a lightweight one-class classification model that trains the best parameters exclusively on benign traffic to identify malicious traffic. In addition, SiteGuard introduces an online update mechanism that aims to dynamically adjust the detection model in response to environmental changes. SiteGuard has been in production for more than three years. Our production and testbed evaluations demonstrate SiteGuard can detect malicious traffic with approximately 90% accuracy in minutes.
Han Zhang 0009, Linqiang Qian, Guyue Liu, Kaiyang Zhao 0004, Yantu Tong, Zeji Xiao, Dongbiao He, Ke Ruan, Jilong Wang 0001, Xia Yin 0001
SIGCOMM6
2026 Glint: Localization of Gray Violations in Untrusted and Unreliable SRv6 Networks
abstract
In the Segment Routing over IPv6 (SRv6) network, a wide range of network events (e.g., attacks, intrusions, violations, malicious route announcements) may occur. Network management requires real-time monitoring of untrusted and unreliable environments (e.g., unsafe components and devices). Early localization of abnormal links causing violations in the SRv6 network helps minimize the compensation required for service unavailability. However, the overhead of the state-of-the-art methods does not scale efficiently to large-scale SRv6 networks and exhibit poor robustness to addressing various disturbances from unreliable networks. To cope with these challenges, we propose Glint, an in-band network telemetry framework to localize abnormal links in SRv6 networks. The key idea of Glint is sampling part of the information while the overall information is known. Glint provides probabilistic in-band collection to gather segment-level telemetry data, reducing overhead and improving efficiency. Glint also proposes distributed verification-based detection to enhance the trustworthiness of security assessments, further improving robustness against disturbances. In addition, we design selective telemetry that reduces telemetry reports while preserving security-relevant visibility. Our evaluations demonstrate that, compared to the state-of-the-art frameworks, Glint significantly reduces header bandwidth overhead by 75.6% and memory overhead by 48.7% while reducing false positives. We also implement Glint on the Intel Tofino switch, achieving over a 50% reduction in hardware resource consumption compared to existing methods.
Kaiyang Zhao 0004, Han Zhang 0009, Xingang Shi, Xia Yin 0001, Jiankun Hu
IEEE Trans. Inf. Forensics Secur.1
2026 VBGP: Flexible Multipath Selection for the Inter-Domain Routing Evolution
abstract
The rapid development of the Internet catalyzes emerging applications and diverse requirements. However, the single best-effort path selection paradigm of BGP impedes the inter-domain routing system for addressing such demands. Despite numerous protocols designed for optimization, they manifest limitations: 1) a single protocol often fails to cater to the broad spectrum of AS requirements, and 2) the adoption of multiple protocols occurs disjointedly, leading to partial-deployment issues. In addressing these challenges, we propose Vinculum-BGP ($\textsf {VBGP}$), enabling ASes to flexibly optimize routes and fostering the evolution of inter-domain routing. The core of$\textsf {VBGP}$is a low-cost vinculum (named as$\textsf {rra}$) scheme for bi-directional path negotiation. This scheme improves upon current multipath routing protocols by allowing ASes to discover unpropagated but beneficial paths, ensuring seamless integration with a majority of routers and adaptability to various requirements. We formally prove the stability of routing under$\textsf {rra}$, showing that$\textsf {VBGP}$facilitates the optimization between different protocols without compromising routing stability. We also introduce some simple-to-implement$\textsf {rra}$policies, so that$\textsf {VBGP}$ASes can achieve comparable results to existing complex protocols in terms of pathavailabilityandquality. Finally, we assess the efficacy of$\textsf {VBGP}$through Internet-scale simulations spanning various deployment scenarios, showcasing its substantial benefits to ASes during the initial deployment phase with minimal costs.
Zitong Jin, Xingang Shi, Zhaozhen Wang, Kaiyang Zhao 0004, Xia Yin 0001
IEEE Trans. Netw.4
2026 Efficient Slice-Parallel Distributed Probing in SRv6 Networks
abstract
Segment Routing over IPv6 (SRv6) is widely deployed, where operators construct numerous parallel SR-based network slices. An accurate diagnosis of latency bottlenecks in SRv6 tunnels is essential to maintain service-level objectives. However, building a distributed, at-scale probing system is non-trivial: SRv6 priority policies, SR-aware multipath forwarding, and slice isolation collectively invalidate assumptions made by existing diagnostic methods. In this paper, we present SRmesh, a distributed system for diagnosing latency bottleneck links in SRv6 networks. First, we adopt distributed SR-based probing agents to control routing paths and ensure that probe packets emulate per-slice production traffic. Second, we employ a latency-based multipath inference that runs in parallel across slices to resolve SR-induced routing ambiguities. Third, we introduce a sliceparallel progressive diagnosis that incrementally reuses probe results to reduce redundant measurements, optimizing diagnostic overhead for large-scale SRv6 overlay networks. We implement a prototype of SRmesh and conduct extensive evaluations on 247 real network topologies. The results indicate that SRmesh achieves high diagnostic accuracy with a 93.4% reduction in probe overhead, demonstrating its practicality and scalability in large-scale SRv6 environments.
Kaiyang Zhao 0004, Han Zhang 0009, Xingang Shi, Xia Yin 0001
IEEE Trans. Netw.1
2025 SRmesh: Deterministic and Efficient Diagnosis of Latency Bottleneck Links in SRv6 Networks
abstract
Segment Routing over IPv6 (SRv6) has attracted more attention from network operators. Diagnosing performance bottlenecks for SRv6 tunnels is critical to maintaining network quality. However, SRv6 introduces priority policies, special forms of multipath routing, and SR-based network slicing, all of which make existing methods difficult to apply. In this paper, we present SRmesh, a framework for diagnosing latency bottleneck links specifically tailored for SRv6 tunnel performance analysis. First, we adopt SR-based probing to deterministically control routing paths and ensure that probe packets emulate real production traffic. Second, we employ a latency-based multipath inference to resolve routing ambiguities caused by SR. Third, we introduce a topology-independent progressive diagnosis that incrementally reuses probe results to reduce redundant measurements, optimizing diagnostic overhead for large-scale SRv6 overlay networks. We implement a prototype of SRmesh and conduct extensive evaluations on real network topologies. The results indicate that SRmesh achieves high diagnostic accuracy with up to a 91.9% reduction in probe overhead, demonstrating its practicality and scalability in large-scale SRv6 environments.
Kaiyang Zhao 0004, Han Zhang 0009, Xingang Shi, Xia Yin 0001
ICNP1