Changsheng Hou

dblp:287/8321 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-3039-4325ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 BIFM: an effective similar payload attribution approach for cybercriminal detection using bitmap index table and fuzzy matching
abstract
Abstract The payload attribution system has been proposed to analyze network traffic and assist investigators in identifying flows containing specific excerpts to locate criminals and potential victims. However, various attacks or data leakage behaviors can obscure and scatter the crucial portion of flow payloads to evade detection. Although existing payload attribution techniques strive to enhance the data reduction ratio and reduce false positive rates, research on similar payload querying is notably lacking. In this study, we introduce bitmap index table fuzzy matching (BIFM), a method for digesting network traffic to query and trace variants of malicious traffic. Unlike deterministic bitmap-index PAS that require deterministic bit co-occurrence/alignment between the query excerpt and the stored flow bitmap, an assumption violated when payloads are split or jumbled, BIFM overcomes this limitation via progressive relaxation with fuzzy matching and verification. Leveraging the bitmap index table and fuzzy matching, BIFM efficiently identifies flows containing excerpts or their variants (excerpts that change their appearance by splitting or jumbling) by relaxing the matching conditions for candidate malicious flows. To enhance BIFM’s accuracy, we also propose no-shingling and packet caching mechanisms. We extensively evaluate BIFM’s performance using a dataset constructed from real campus network IP-trace data. Our results demonstrate that BIFM outperforms existing state-of-the-art solutions, achieving an accuracy improvement of $\sim $10% without significantly increasing processing time.
Changsheng Hou, Ling Hu 0001, Xionglve Li, Bingnan Hou, Zhiping Cai
Comput. J.2
2024 DRL-Tomo: a deep reinforcement learning-based approach to augmented data generation for network tomography
abstract
Abstract Accurate and current comprehension of network status is crucial for efficient network management. Nevertheless, direct network measurement strategies entail substantial traffic overhead and demand intricate coordination among network entities, making them impractical. Network tomography, an indirect measurement approach, utilizes insights garnered from measured parts to deduce characteristics of the entire network. Past studies frequently depend on acquiring challenging-to-access information, such as the complete network topology or support from specialized protocols. Unfortunately, these constraints pose challenges in non-cooperative scenarios where obtaining such information is difficult. Recent endeavors pursue emancipating tomography from dependence on copious information, striving to predict unmeasured path performance using limited data. Nevertheless, the disparity between the measured data and actual performance has hindered the accuracy. In response, we introduce an innovative tomography framework named DRL-Tomo, designed to alleviate potential biases. DRL-Tomo initiates by generating augmented data through deep reinforcement learning, gradually approximating the genuine performance of unmeasured paths. Subsequently, a neural network model is trained using this augmented data, enabling precise inferences. Our experiments, encompassing both real-world and synthetic datasets, vividly demonstrate DRL-Tomo’s remarkable enhancement. Specifically, it achieves a substantial 10%–67% improvement in path delay prediction and an impressive 30%–98% enhancement in path loss rate prediction.
Changsheng Hou, Bingnan Hou, Xionglve Li, Tongqing Zhou, Yingwen Chen 0001, Zhiping Cai
Comput. J.1
2024 A Sketch Framework for Fast, Accurate and Fine-Grained Analysis of Application Traffic
abstract
Abstract Nowadays, with the continuous increase in internet traffic, the demand for real-time and high-speed traffic analysis has grown significantly. However, existing traffic analysis technologies are either limited by specific applications or data, unable to expand for widespread implementation, or in offline mode are unable to keep up with dynamic adjustments required in certain network management scenarios. A promising approach is to utilize sketch technology to enhance real-time traffic analysis. Unfortunately, existing technologies suffer from defects, such as overly coarse-grained statistics that cannot perform precise application-level traffic analysis, and irreversibility, which cannot support real-time queries in a friendly way. To achieve real-time fine-grained application traffic analysis in general scenarios, we propose AppSketch, a real-time network traffic measurement tool. AppSketch adopts a one-pass approach to classify and label the application information of each packet in the network flows. It then hashes the flow, identified with the application tag, into a carefully designed multiple-key sketch, for gathering application-specific statistics. We conducted extensive experiments using a real-world network traffic dataset collected on a university campus. The results showed that AppSketch achieved high accuracy while requiring less update time than other alternatives. Moreover, AppSketch occupies limited memory ($ {\leq }$64KB), making it suitable for online network devices.
Changsheng Hou, Chunbo Jia, Bingnan Hou, Tongqing Zhou, Yingwen Chen 0001, Zhiping Cai
Comput. J.1
2023 6Search: A reinforcement learning-based traceroute approach for efficient IPv6 topology discovery
Ning Liu 0015, Chunbo Jia, Bingnan Hou, Changsheng Hou, Yingwen Chen 0001, Zhiping Cai
Comput. Networks4
2021 2prong: Adaptive Video Streaming with DNN and MPC
abstract
Adaptive bitrate (ABR) algorithms are often used to optimize the quality of user experience (QoE) during video playback. In the client-side video player, the buffer size and predicted throughput are mainly used to improve user's QoE. However, due to the randomness of mobile network traffic and the heavy-tail effect of the network, it is very difficult to predict throughput. We innovatively use Bayesian neural network to dynamically evaluate video signals. Unlike previous neural network solutions, we use probability distributions instead of point estimates to predict throughput, which can effectively evaluate QoE metrics. Our contributions are to first (i) use of Bayesian neural network to guide video adaptive bitrate adaptation, and then (ii) propose a bitrate adaptive algorithm denoted 2prong, which utilizes high-dimensional contextual information such as buffer occupancy, predicted throughput and video quality to find the most valuable information for quality adaption in real time. We demonstrate the effectiveness of the 2prong algorithm using a simulation testbed. By comparing with other methods, it is demonstrated that 2prong can improve the video quality of video streaming transmission.
Yipeng Wang 0010, Tongqing Zhou, Changsheng Hou, Bingnan Hou, Zhiping Cai
MSN3
2021 DMatrix: Toward fast and accurate queries in graph stream
Changsheng Hou, Bingnan Hou, Tongqing Zhou, Zhiping Cai
Comput. Networks1
2021 Detection and Characterization of Network Anomalies in Large-Scale RTT Time Series
abstract
Network anomalies, such as wide-area congestion and packet loss, can seriously degrade network performance. To this end, it is critical to accurately identify network anomalies on end-to-end paths for high quality network services in practice. In this work, we propose an unsupervised two-step method for the detection and characterization of general network anomalies. It first finds the change-points in large-scale RTT time series by formalizing an optimization problem in terms of data series segmentation. Then we mark the segments as normal or abnormal on different sides of a change-point through exploitation of their distribution statistics. After detecting an anomaly, a further step is introduced to analyze the relations between links with state changes and localize the entities (nodes or links) that most likely cause the corresponding event. We believe such unsupervised and light-weighed method can provide valuable insights on anomaly mining in large-scale time series data. Extensive experiments on both simulated (artificial time series with ground truth) and real-network (RIPE Atlas traceroute measurements) datasets are performed. The results demonstrate that the proposed method can achieve better performance, w.r.t. accuracy and efficiency, than existing solutions.
Bingnan Hou, Changsheng Hou, Tongqing Zhou, Zhiping Cai, Fang Liu 0002
IEEE Trans. Netw. Serv. Manag.2