Yangfei Guo

dblp:300/7087 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
6since 2021 · last 2026
0000-0002-5407-1133ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 6 since 2021
YearPublicationVenuePosition
2026 Desi: Revisiting Signature Verification in Blockchain-based Storage System
Songsong Xu, Xiaoliang Wang 0004, Yangfei Guo, Shenglin Jiang, Ke Xu 0002
IWQoS6
2025 Towards Internet-Scale Inter-Domain Path Verification
abstract
The Internet lacks mechanisms to verify the authenticity of packet forwarding paths, leading to numerous attacks that manipulate the data plane forwarding process. In response to such security threats, path verification is clearly essential. This security solution ensures that data packets remain untampered and their forwarding paths are authentic. However, existing path verification schemes are constrained by two major challenges: First, in large-scale deployment scenarios, each node must maintain a point-to-point trust relationship across the entire deployment, significantly increasing router processing delays and storage overhead. Second, a complete packet forwarding path often traverses regions with varying management and verification policies, which current path verification schemes struggle to unify. To address these issues, this paper proposes a novel data plane path verification scheme called HVTT(Hierarchical Path Verification with Trust Transfer). HVTT adopts the concept of Address Domain to facilitate cross-domain trust transfer, dividing the end-to-end forwarding process into collaborative efforts across several address domains. Different path verification methods can be employed between various Autonomous Systems (ASs) within an address domain. The verification and exchange of labels across address domains facilitate trust transfer. Its hierarchical design substantially reduces the number of trust relationship objects that need to be maintained. The trust transfer method enables cooperation between address domains, allowing effective adaptation to different security policy regions along the path. We implemented the HVTT prototype on VMware, and experiments showed that HVTT reduced forwarding verification delay by 40.47 % and increased throughput by 37.28 % compared to OPT in a four-hop Round-Trip Time (RTT) scenario.
Yangfei Guo
IWQoS3
2024 Toward Practical Inter-Domain Source Address Validation
abstract
The Internet Protocol (IP) is the most fundamental building block of the Internet. However, it provides no explicit notion of packet-level authenticity. Such a weakness allows malicious actors to spoof IP packet headers and launch a wide variety of attacks. Meanwhile, the highly decentralized management of Internet infrastructure makes large-scale source address validation challenging in terms of overhead, validity, and flexibility. This paper presents a practical anti-spoofing approach, Source Address Validation Architecture eXternal (SAVA-X). SAVA-X introduces the concept of Address Domain to enable address validation in finer, prefix-level granularity. The address domains are organized in nested hierarchies to provide higher scalability and lower maintenance costs for partial deployment. We implement SAVA-X on commercial backbone routers and the P4 platform. The experiments indicate that the hardware implementation of SAVA-X can achieve 98% throughput on 100 Gbps links and close to the native IP forwarding in per-packet overhead, with less than 10 microseconds additional processing latency.
Xiaoliang Wang 0004, Ke Xu 0002, Yangfei Guo, Songtao Fu, Qi Li 0002
IEEE/ACM Trans. Netw.3
2023 MASK: Practical Source and Path Verification Based on Multi-AS-Key
abstract
The source and path verification in Path-Aware Networking considers the two critical issues: (1) end hosts could verify that the network follows their forwarding decisions, and (2) both on-path routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the state-of-the-art mechanisms require heavy communication overhead in the network and computation overhead in the router; moreover, it is difficult to meet the dynamic requirements of the end host. We propose a user-driven mechanism, source and path verification based on Multi-AS-Key (MASK). MASK decreases the communication overhead by a short additional packet header and reduces the computation overhead by separating the control and data plane in terms of the cryptographic operation. Furthermore, it utilizes the stateful user to instruct the stateless routers to process the packet with a user-driven policy, thus satisfying the user’s requirements such as detecting the packet drop and replay attack. With the plausible design, the communication overhead for realistic path lengths is 1/2 to 1/10 compared with the state-of-the-art mechanisms. We implement MASK in the BMv2 environment and commodity Barefoot Tofino programmable switch, testify that MASK introduces significantly less overhead than the state-of-the-art mechanisms, and demonstrate that MASK could achieve the verification in the programmable switch at line rate.
Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du, Ke Xu 0002
IEEE/ACM Trans. Netw.6
2021 MASK: Practical Source and Path Verification based on Multi-AS-Key
abstract
The source and path verification in path-aware Internet consider the two critical issues: (1) end hosts could verify that their forwarding decisions followed by the network, (2) both intermediate routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the current verification mechanism requires validation operations in each router on the path in an inter-domain environment, thus requiring high communication and computation overhead, reducing its usefulness; besides, it is also difficult to meet the dynamic requirements of the end host. Ideally, the verification should be secure and provide the customized capability to meet the end host’s requirements. We propose a new mechanism called source and path verification based on Multi-AS-Key (MASK). Instead of each packet verified and marked at each router on the path, MASK improves the verification by empowering the end hosts to instruct the routers to achieve the verification, thus decreasing the router’s overhead while ensuring security performance to meet the end host’s requirements. With the plausible design, the communication overhead for realistic path lengths is 3–8 times smaller than the state-of-the-art mechanisms. The computation overhead in the routers is 2-5 times smaller. We implement our design in the BMv2 environment and commodity Barefoot Tofino programmable switch, demonstrating that MASK introduces significantly less overhead than the existing mechanisms.
Songtao Fu, Ke Xu 0002, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du
IWQoS6
2021 TAP: A Traffic-Aware Probabilistic Packet Marking for Collaborative DDoS Mitigation
abstract
In recent years, Distributed Denial-of-Service (DDoS) attacks have become more rampant and continue to be one of the most serious security threats facing network infrastructure. In a classic DDoS attack, the attacker controls numerous bots from many sources to send a significant volume of traffic to flood the victim end or the bottleneck link. In practical networks, it is inefficient and costly to request all partner routers to collaboratively mitigate DDoS attacks. The common feature of DDoS attacks is the abnormal distribution of traffic to the victim. In this paper, we propose TAP, a collaborative DDoS mitigation framework, based on traffic-aware probabilistic packet marking (PPM). TAP enables the victim to select a few hit routers as collaborators to mitigate attack traffic efficiently depending on the traffic distribution. Our evaluation results show that TAP greatly reduces attack traffic within seconds and mitigate the damage caused by DDoS with less overhead, which demonstrates that TAP is an effective, efficient, and rapid-response scheme for collaborative DDoS mitigation.
Mingxing Liu, Ying Liu 0024, Ke Xu 0002, Lin He 0004, Xiaoliang Wang 0004, Yangfei Guo, Weiyu Jiang
MSN6