VLDB 2026 Research / reviewers in the wild / expert
Dijiang Huang
dblp:36/4573
· DBLP profile ↗
94ranked-venue papers
20as first author
12since 2021 · last 2025
0000-0003-3257-6349ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 48 · 14 first-author · 7 since 2021Security and privacy · 17 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 9 · 1 since 2021Systems, architecture and hardware · 7 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorArtificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Waterfall: Fast Network Flow Rules Checking and Conflict ResolutionabstractSoftware Defined Networking (SDN) enables a centralized manageable framework to control network devices and their policies using device-specific flow rules. When administrators deploy flow rules to support business policies, the network controller checks them against existing rules to detect conflicts and ensure consistency, security, and functionality in the data plane. Existing offline conflict detection methods are not scalable due to state explosion and often lead to networking chaos due to inefficiency. This paper presents Waterfall, designed to minimize the number of flow rule-checking operations. We propose a novel Equivalence Class (EC) creation and prioritization technique that simplifies conflict detection by organizing rules with similar patterns and processing them accordingly. Analogous to a multi-stage waterfall, our algorithm optimizes downstream stages by reducing unnecessary comparisons, ensuring efficient conflict detection. Our comprehensive evaluation demonstrates Waterfall’s effectiveness through significant reductions in computation time ($O(mKH)$, where m is the number of matched flow-rules which is far less than the total number of flow-rules, K is the number of attributes (headers) in flow rules, H is the number of hash functions in Bloom filter for attribute matching), making it ideal for real-time flow rule checking and conflict resolution in SDN environments. In our evaluation, Waterfall achieved a remarkable 1.3X improvement in conflict detection and 4.4X improvement for conflict resolution over the state-of-the-art solution for the Stanford topology which is a popular topology to represent real-world networking scenarios. We also evaluate the scalability of the solution using a synthetic dataset containing 15K flow rules that have three virtual network functions. Our solution achieved a$90.53~\mu $s conflict detection and resolution time for the large synthetic dataset. This lightweight approach promises substantial benefits for real-time flow rule checking in SDN environments. Neha Vadnere, Dijiang Huang, Abdulhakim Sabur, Jim Luo, Ming Zhao 0002 |
IEEE Trans. Netw. | 2 |
| 2024 | ILLATION: Improving Vulnerability Risk Prioritization by Learning From NetworkabstractNetwork administrators face the challenge of efficiently patching overwhelming volumes of vulnerabilities with limited time and resources. To address this issue, they must prioritize vulnerabilities based on the associated risk/severity measurements (i.e., CVSS). Existing solutions struggle to efficiently patch thousands of vulnerabilities on a network. This paper presents ILLATION, a proof-of-concept model that provides network-specific vulnerability risk prioritization to support efficient patching. ILLATION integrates AI techniques, such as neural networks and logical programming, to learn risk patterns from adversaries, vulnerability severity, and the network environment. It provides an integrated solution that learns and infers adversaries' motivation and ability in a network while also learning the constraints that restrict interactions between vulnerabilities and network elements. An evaluation of ILLATION against CVSS base and environmental metrics shows that it reflects changes in vulnerability scores and prioritization ranks as the same pattern as the CVSS model while identifying vulnerabilities with similar risk patterns to given adversaries better. On a simulated network with up to 10k vulnerable hosts and vulnerabilities, ILLATION can assess 1k vulnerabilities in about 4.5 minutes total, with an average running time of 0.19 seconds per vulnerability on a general-purpose computer. Dijiang Huang, Guoliang Xue, Yuli Deng, Neha Vadnere, Liguang Xie |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Semantic Privacy-Preserving for Video Surveillance Services on the EdgeabstractIntelligent Video surveillance systems, leveraging edge computing, have become increasingly prevalent in various facilities, providing advanced monitoring and management capabilities. However, these systems can inadvertently compromise personally identifiable information, such as human images, leading to privacy violations. We introduced a semantic privacy-preserving video surveillance service on the edge to address this critical issue. Unlike traditional centralized models, the solution operates as a decentralized machine learning framework within the video surveillance infrastructure at the edge. Its primary focus is protecting private information extracted from captured video streaming data. This research integrates cutting-edge machine learning techniques, including scene graph generation and semantic communication approaches, by enabling edge nodes to exchange parameters for training, referencing, and safeguarding data privacy and ownership. These innovations collectively contribute to the protection of human privacy. The performance evaluation confirms that the solution is an efficient and effective privacy protection platform, offering a significant advancement over conventional centralized solutions. Alexander Y. C. Huang, Dijiang Huang, Ming Zhao 0002 |
SEC | 3 |
| 2023 | Unraveled - A semi-synthetic dataset for Advanced Persistent ThreatsabstractUnraveled is a novel cybersecurity dataset capturing Advanced Persistent Threat (APT) attacks not available in the public domain. Existing cybersecurity datasets lack coherent information about sophisticated and persistent cyber-attack features, including attack planning and deployment, stealthiness of the attacker(s), longer dorm period between attack activities, etc. Our APT attack scenario in Unraveled is implemented on a real network system established on a cloud platform to emulate an organization’s network system. The new dataset provides a comprehensive network flow and host-level log information about the normal user(s) traffic and the cyber attacks traffic. To emulate realistic network traffic scenarios, Unraveled also includes attacks at different skills reflecting a typical organization’s threat posture, and by utilizing APT attack information from one of the well-known APT attack databases, i.e., MITRE’s APT-group database. Furthermore, we design and develop an Employee Behavior Generation (EBG) model to emulate multiple normal employees’ traffic and activities during a 6-week time period based on their pre-defined business functions. Using well-known machine learning models for anomaly detection, we show that the APT attack activities in Unraveled are hardly detected, indicating the need for more effective solutions that are based on datasets representing real world APT attacks. Sowmya Myneni, Kritshekhar Jha, Abdulhakim Sabur, Garima Agrawal, Yuli Deng, Ankur Chowdhary, Dijiang Huang |
Comput. Networks | 7 |
| 2022 | SmartDefense: A distributed deep defense against DDoS attacks with edge computing
Sowmya Myneni, Ankur Chowdhary, Dijiang Huang, Adel Alshamrani |
Comput. Networks | 3 |
| 2022 | Toward scalable graph-based security analysis for cloud networks
Abdulhakim Sabur, Ankur Chowdhary, Dijiang Huang, Adel Alshamrani |
Comput. Networks | 3 |
| 2022 | Object Oriented Policy Conflict Checking Framework in Cloud Networks (OOPC)abstractSoftware-Defined Networking (SDN) provides a programmable framework for multi-tenant cloud network management and orchestration. The end-to-end packet processing induced by virtual network functions (VNFs) like stateless firewall, load balancer, intrusion detection, and prevention system (IDPS) in a network involves the processing of network traffic through security policies matching the traffic pattern defined in security rules of individual VNF. The conflicting rules in terms of traffic match and conflicting actions can lead to a) violation of security requirements (authentication and authorization bypass) b) mission requirements - the presence of redundant rules (increased latency, reduced throughput). We present a new object-oriented policy conflict detection and resolution framework (OOPC), which analyzes the rule dependency relationships between the rules of heterogeneous virtual network functions (VNFs) and creates a VNF-Graph. The rules are analyzed using object-oriented dependencies between the address space and actions of VNF rules. OOPC utilizes a compact VNF-Graph, which leads to a reduction in search complexity when analyzing new security policies. Our security policy composition in our framework OOPC achieves 37 percent lower latency in policy graph composition than previous work. The proposed solution performs 20 percent faster security policy conflict detection on a cloud network with 60k OpenFlow rules than prior frameworks that serve a similar purpose. Ankur Chowdhary, Abdulhakim Sabur, Dijiang Huang, Myong H. Kang, James Kirby |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | SCVS: On AI and Edge Clouds Enabled Privacy-preserved Smart-city Video Surveillance ServicesabstractVideo surveillance systems are increasingly becoming common in many private and public campuses, city buildings, and facilities. They provide many useful smart campus/city monitoring and management services based on data captured from video sensors. However, the video surveillance services may also breach personally identifiable information, especially human face images being monitored; therefore, it may potentially violate the privacy of human subjects involved. To address this privacy issue, we introduced a large-scale distributed video surveillance service model, called Smart-city Video Surveillance (SCVS). SCVS is a video surveillance data collection and processing platform to identify important events, monitor, protect, and make decisions for smart campus/city applications. In this article, the specific research focus is on how to identify and anonymize human faces in a distributed edge cloud computing infrastructure. To preserve the privacy of data during video anonymization, SCVS utilizes a two-step approach: (i) parameter server-based distributed machine learning solution, which ensures that edge nodes can exchange parameters for machine learning-based training. Since the dataset is not located on a centralized location, the data privacy and ownership are protected and preserved. (ii) To improve the machine learning model’s accuracy, we presented an asynchronous training approach to protect data and model privacy for both data owners and data users, respectively. SCVS adopts an in-memory encryption approach, where edge computing nodes collect and process data in the memory of edge nodes in encrypted form. This approach can effectively prevent honest but curious attacks. The performance evaluation shows the presented privacy protection platform is efficient and effective compared to traditional centralized computing models as presented in Section 5 . Sowmya Myneni, Garima Agrawal, Yuli Deng, Ankur Chowdhary, Neha Vadnere, Dijiang Huang |
ACM Trans. Internet Things | 6 |
| 2022 | Intent-Driven Security Policy Management for Software-Defined SystemsabstractDifferent network controllers are utilized in a multi-domain software-defined systems (SDx) to manage the networking resources. However, these controllers operate using a different high-level language (intent). Thus, the admin needs to perform cross-layer translation from the user requirements to the underlying network controller format, increasing human-in-the-loop overhead. There are two primary security and management challenges involved in managing multi-domain controllers. The first challenge is how to design an SDN controller language that can effectively convert human-specified networking policies at the control plane into the network flow rules level at the data plane. The second challenge is how to reduce the complexity of network flow rules conflict checking at the data plane. To address these challenges, we present a new intent-based security policy enforcement solution called INTPOL. First, INTPOL provides a unified intent rules that abstracts the network admin from the underlying network controller’s format. Second, INTPOL develops a networking service solution to use a bounded formal model for network service compliance checking that significantly reduces the complexity of flow rules conflicts checking at the data plane level. Finally, INTPOL is expendable from a single SDN domain to multiple SDN domains and hybrid networks by applying network service function chaining (SFC) for inter-domain policy management. Ankur Chowdhary, Abdulhakim Sabur, Neha Vadnere, Dijiang Huang |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | LICALITY - Likelihood and Criticality: Vulnerability Risk Prioritization Through Logical Reasoning and Deep LearningabstractSecurity and risk assessment aims to prioritize detected vulnerabilities for remediation in a computer networking system. The widely used expert-based risk prioritization approach, e.g., Common Vulnerability Scoring System (CVSS), cannot realistically associate vulnerabilities to the likelihood of exploitation. The CVSS metrics are calculated from static formulas, and cannot easily integrate attackers’ motivations and capabilities w.r.t. the network environmental factors. To address this issue, this paper proposes LICALITY, a vulnerability risk prioritization system. LICALITY captures the attacker’s preference on exploiting vulnerabilities through a threat modeling method, and learns threat attributes that contribute to the exploitation of vulnerability. LICALITY creatively uses a neuro-symbolic model, with neural network (NN) and probabilistic logic programming (PLP) techniques, to learn such threat attributes. The risk of vulnerability is assessed from the criticality of exploitation and the likelihood of exploitation. LICALITY consolidates these two measurements by using a logic reasoning engine. In the evaluation, the historical threat and future threat are from real attack scenarios. The results reveal that LICALITY reduces the vulnerability remediation work of the future threat required by the CVSS by a factor of 2.89 in the first case study and by a factor of 1.85 in the second case study. Such future threats are identified as the top routinely exploited vulnerabilities and the APT attack chained vulnerabilities reported in the Cybersecurity and Infrastructure Security Agency (CISA) alerts. Zhun Yang, Dijiang Huang, Chun-Jen Chung |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | Global Feature Analysis and Comparative Evaluation of Freestyle In-Air-Handwriting Passcode for User AuthenticationabstractFreestyle in-air-handwriting passcode-based user authentication methods address the needs for Virtual Reality (VR) / Augmented Reality (AR) headsets, wearable devices, and game consoles where a physical keyboard cannot be provided for typing a password, but a gesture input interface is readily available. Such an authentication system can capture the hand movement of writing a passcode string in the air and verify the user identity using both the writing content (like a password) and the writing style (like a behavior biometric trait). However, distinguishing handwriting signals from different users is challenging in signal processing, feature extraction, and matching. In this paper, we provide a detailed analysis of the global features of in-air-handwriting signals and a comparative evaluation of such a user authentication framework. Also, we build a prototype system with two different types of hand motion capture devices, collect two datasets, and conduct an extensive evaluation. Duo Lu, Yuli Deng, Dijiang Huang |
ACSAC | 3 |
| 2021 | NeoCyberKG: Enhancing Cybersecurity Laboratories with a Machine Learning-enabled Knowledge GraphabstractThe hands-on lab is a critical component of cybersecurity education. There lacks of a coherent way to manage existing labs to provide a practical learning plan for learners in the cybersecurity area. Previous studies utilized the word embedding technologies to construct a knowledge graph and adopt it as a learning guide for students, but this approach has its limitations. In this paper, we present a new approach based on latent semantic analysis (LSA) method to replace word embedding in previous studies as it is more appropriate in a small-size corpus, and it is also able to create a mapping that connects both the topic of each lab and concepts contained in each lab. We use LSA to identify relevant semantic relations, extract relevant lab problems, and construct knowledge graphs from lab contents related to cybersecurity topics. We utilize the output of this study by establishing a web-based lab environment for students that: 1. providing lab index and searching, which contains concepts and knowledge extract from each lab. 2.building a recommendation/guidance system for cybersecurity labs and suggesting more relevant labs based on users learning preferences and past lab history to maximize learning outcomes. To measure the effectiveness of the proposed solution, we conducted a use case study and collected survey data from a graduate-level cybersecurity class at a public university. Our study shows that users tend to gain enhanced learning outcomes and express more interest in the cybersecurity area by leveraging the knowledge graph as a learning guide. Yuli Deng, Dijiang Huang |
ITiCSE (1) | 3 |
| 2020 | Autonomous Security Analysis and Penetration TestingabstractSecurity Assessment of large networks is a challenging task. Penetration testing (pentesting) is a method of analyzing the attack surface of a network to find security vulnerabilities. Current network pentesting techniques involve a combination of automated scanning tools and manual exploitation of security issues to identify possible threats in a network. The solution scales poorly on a large network. We propose an autonomous security analysis and penetration testing framework (ASAP) that creates a map of security threats and possible attack paths in the network using attack graphs. Our framework utilizes: (i) state of the art reinforcement learning algorithm based on Deep-Q Network (DQN) to identify optimal policy for performing pentesting testing, and (ii) incorporates domain-specific transition matrix and reward modeling to capture the importance of security vulnerabilities and difficulty inherent in exploiting them. ASAP framework generates autonomous attack plans and validates them against real-world networks. The attack plans are generalizable to complex enterprise network, and the framework scales well on a large network. Our empirical evaluation shows that ASAP identifies non-intuitive attack plans on an enterprise network. The DQN planning algorithm employed scales well on a large network ~ 60 -70(s) for generating an attack plan for network with 300 hosts. Ankur Chowdhary, Dijiang Huang, Jayasurya Sevalur Mahendran, Daniel Romo, Yuli Deng, Abdulhakim Sabur |
MSN | 2 |
| 2019 | TRUFL: Distributed Trust Management Framework in SDNabstractSoftware Defined Networking (SDN) has emerged as a revolutionary paradigm to manage cloud infrastructure. SDN lacks scalable trust setup and verification mechanism between Data Plane-Control Plane elements, Control Plane elements, and Control Plane-Application Plane. Trust management schemes like Public Key Infrastructure (PKI) used currently in SDN are slow for trust establishment in a larger cloud environment. We propose a distributed trust mechanism - TRUFL to establish and verify trust in SDN. The distributed framework utilizes parallelism in trust management, in effect faster transfer rates and reduced latency compared to centralized trust management. The TRUFL framework scales well with the number of OpenFlow rules when compared to existing research works. Ankur Chowdhary, Dijiang Huang, Adel Alshamrani, Myong H. Kang, Anya Kim, Alexander Velazquez |
ICC | 2 |
| 2019 | FMHash: Deep Hashing of In-Air-Handwriting for User IdentificationabstractMany mobile systems and wearable devices, such as Virtual Reality (VR) or Augmented Reality (AR) headsets, lack a keyboard or touchscreen to type an ID and password for signing into a virtual website. However, they are usually equipped with gesture capture interfaces to allow the user to interact with the system directly with hand gestures. Although gesture-based authentication has been well-studied, less attention is paid to the gesture-based user identification problem, which is essentially an input method of account ID and an efficient searching and indexing method of a database of gesture signals. In this paper, we propose FMHash (i.e., Finger Motion Hash), a user identification framework that can generate a compact binary hash code from a piece of in-air-handwriting of an ID string. This hash code enables indexing and fast search of a large account database using the in-air-handwriting by a hash table. To demonstrate the effectiveness of the framework, we implemented a prototype and achieved ≥99.5% precision and ≥92.6% recall with exact hash code match on a dataset of 200 accounts collected by us. The ability of hashing in-air-handwriting pattern to binary code can be used to achieve convenient sign-in and sign-up with in-air-handwriting gesture ID on future mobile and wearable systems connected to the Internet. Duo Lu, Dijiang Huang, Anshul Rai |
ICC | 2 |
| 2019 | S3: A DFW-based Scalable Security State Analysis Framework for Large-Scale Data Center Networks
Abdulhakim Sabur, Ankur Chowdhary, Dijiang Huang, Myong H. Kang, Anya Kim, Alexander Velazquez |
RAID | 3 |
| 2019 | Partially Overlapped Channel Detection in Heterogeneous Cognitive NetworksabstractA Partially Overlapped WiFi Channel (POC) is a type of WiFi channel whose spectrum is partially overlapping with other carriers. It has been empirically demonstrated that the throughput of heterogeneous cognitive network can be improved by utilizing POCs. POC detection is a prerequisite to POC utilization. Unfortunately, the existing Clear Channel Assessment (CCA) methods such as energy-based detection and preamble detection cannot accurately detect the POC in heterogeneous cognitive networks. As a result, POCs will not be used by most WiFi users. The spectrum in POCs is therefore under-utilized and wasted. In this article, we propose to detect a POC by statistically analyzing the bit-level information inside the payload of WiFi frames. The proposed approach is based on a series of measurements on bit errors under real-world IEEE 802.11ac channels. A POC can be accurately detected by analyzing the correlation between an unknown WiFi channel and a given POC in terms of their bit-error vectors. Our approach is evaluated by detecting fifty [1/2]-overlap WiFi channels among a hundred different real-world WiFi channels. The final results show that, our approach can achieve an accuracy of 96% and a false positive rate of 8% on POC detection, which is much better than the existing CCA methods. Tracy Yingying Cheng, Xiaohua Jia, Dijiang Huang |
WCNC | 4 |
| 2019 | Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud EnvironmentsabstractThe ease of programmability in Software-Defined Networking (SDN) makes it a great platform implementation of various initiatives that involve application deployment, dynamic topology changes, and decentralized network management in a multi-tenant data center environment. However, implementing security solutions in such an environment is fraught with policy conflicts and consistency issues with the hardness of this problem being affected by the distribution scheme for the SDN controllers. In this paper we present Brew, a security policy analysis framework implemented on an OpenDaylight SDN controller, that has comprehensive conflict detection and resolution modules to ensure that no two flow rules in a distributed SDN-based cloud environment have conflicts at any layer; thereby assuring consistent conflict-free security policy implementation and preventing information leakage. We present techniques for global prioritization of flow rules in a decentralized environment, extend firewall rule conflict classification from a traditional environment to SDN flow rule conflicts by recognizing and classifying conflicts stemming from cross-layer conflicts and provide strategies for unassisted resolution of these conflicts. Alternately, if administrator input is desired to resolve conflicts, a novel visualization scheme is implemented to help the administrators view the conflicts graphically. We demonstrate the correctness, feasibility and scalability of our framework through a proof-of-concept prototype. Sandeep Pisharody, Janakarajan Natarajan, Ankur Chowdhary, Abdullah Alshalan, Dijiang Huang |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2018 | MTD 2018: 5th ACM Workshop on Moving Target Defense (MTD)abstractThe objective of the 5th ACM Workshop on Moving Target Defense (MTD 2018) - held in Toronto, Canada on October 15, 2018, in conjunction with the 24th ACM Conference on Computer and Communications Security (ACM CCS 2018) - is to bring together researchers from academia, government, and industry to discuss novel randomization, diversification, and dynamism techniques for improving the security of computer systems and network, and new metric and analytical frameworks to assess and quantify the effectiveness of MTD techniques. As in previous editions, the 2018 workshop offers a forum to discuss the challenges and opportunities that such defenses provide. We have assembled an exciting and diverse program including nine refereed papers and one invited keynote talk that will provide participants with a vibrant and thought-provoking set of ideas and insights. Massimiliano Albanese, Dijiang Huang |
CCS | 2 |
| 2018 | Personalized Learning in a Virtual Hands-on Lab Platform for Computer Science EducationabstractThis Innovate Practice full paper presents a cloud-based personalized learning lab platform. Personalized learning is gaining popularity in online computer science education due to its characteristics of pacing the learning progress and adapting the instructional approach to each individual learner from a diverse background. Among various instructional methods in computer science education, hands-on labs have unique requirements of understanding learner's behavior and assessing learner's performance for personalization. However, it is rarely addressed in existing research. In this paper, we propose a personalized learning platform called ThoTh Lab specifically designed for computer science hands-on labs in a cloud environment. ThoTh Lab can identify the learning style from student activities and adapt learning material accordingly. With the awareness of student learning styles, instructors are able to use techniques more suitable for the specific student, and hence, improve the speed and quality of the learning process. With that in mind, ThoTh Lab also provides student performance prediction, which allows the instructors to change the learning progress and take other measurements to help the students timely. For example, instructors may provide more detailed instructions to help slow starters, while assigning more challenging labs to those quick learners in the same class. To evaluate ThoTh Lab, we conducted an experiment and collected data from an upper-division cybersecurity class for undergraduate students at Arizona State University in the US. The results show that ThoTh Lab can identify learning style with reasonable accuracy. By leveraging the personalized lab platform for a senior level cybersecurity course, our lab-use study also shows that the presented solution improves students engagement with better understanding of lab assignments, spending more effort on hands-on projects, and thus greatly enhancing learning outcomes. Yuli Deng, Duo Lu, Chun-Jen Chung, Dijiang Huang |
FIE | 4 |
| 2018 | Improving student learning performance in a virtual hands-on lab system in cybersecurity educationabstractThis Research Work in Progress paper presents a study on improving student learning performance in a virtual hands-on lab system in cybersecurity education. As the demand for cybersecurity-trained professionals rapidly increasing, virtual hands-on lab systems have been introduced into cybersecurity education as a tool to enhance students' learning. To improve learning in a virtual hands-on lab system, instructors need to understand: what learning activities are associated with students' learning performance in this system? What relationship exists between different learning activities? What instructors can do to improve learning outcomes in this system? However, few of these questions has been studied for using virtual hands-on lab in cybersecurity education. In this research, we present our recent findings by identifying that two learning activities are positively associated with students' learning performance. Notably, the learning activity of reading lab materials (p <; 0:01) plays a more significant role in hands-on learning than the learning activity of working on lab tasks (p <; 0:05) in cybersecurity education.In addition, a student, who spends longer time on reading lab materials, may work longer time on lab tasks (p <; 0:01). Yuli Deng, I-Han Hsiao, Dijiang Huang, Chun-Jen Chung |
FIE | 4 |
| 2018 | Combining Dynamic and Static Attack Information for Attack Tracing and Event CorrelationabstractMany sophisticated attacks, e.g. Advanced Persistent Threats (APTs), have emerged with a variety of different attack forms. APT employs a wide range of sophisticated reconnaissance and information-gathering tools, as well as attack tools and methods. The diversity and stealthiness of APT make it a challenging threat to current networking systems. The attackers are very skilled and try to hide in a system undetected for a long period of time with the incentive to steal and collect invaluable Current commonly used solutions (firewalls, Intrusion Detection Systems, proxies, etc.) show the limited efficiency of detecting APT. Thus, in this paper, we design a solution that is based on multi-source data combination to learn the adversarial behavior of suspicious users as well as to optimally select a proper countermeasure. Adel Alshamrani, Ankur Chowdhary, Oussama Mjihil, Sowmya Myneni, Dijiang Huang |
GLOBECOM | 5 |
| 2018 | Prompt Lightweight VPN Session Resumption for Rapid Client Mobility and MTD Enablement for VPN ServersabstractTLS-based VPN are increasingly used to establish a secure communication channel between VPN clients and server. However, they are not designed to handle the mobility VPN clients in efficient manner. OpenVPN, a widely deployed TLS VPN, binds VPN sessions with the clients and server IP addresses. A vertical handover will require an inactivity timeout to be triggered and full TLS handshake thereafter for the mobile client to resume the VPN session. Moreover, A VPN server that changes its IP address frequently as part of an MTD strategy will require the VPN clients to reconnect after their inactivity timeouts trigger with yet full TLS handshake. In this work, we developed and evaluated a lightweight VPN session resumption protocol that allows a VPN client or server to request an IP address update on-demand, maintaining the original TLS/VPN session. We implemented our protocol as part of MobiVPN which is a variation of OpenVPN. Our evaluation shows that VPN sessions can be maintained and resumed after an IP address change with an average of 97.19% decrease in time required to resume the VPN session in MobiVPN compared to the original OpenVPN. Abdullah Alshalan, Dijiang Huang |
ICC | 2 |
| 2018 | Fault Tolerant Controller Placement in Distributed SDN EnvironmentsabstractSoftware Defined Network (SDN) facilitates a centralized networking system where a controller manages the global view of the network. The introduction of Software-Defined Networks and standards such as OpenFlow spawn several questions regarding scalability and reliability. One such question is the controller placement problem; i.e. given a topology, the problem of determining how many controllers are needed, and where they should be placed. This question has been well-studied relative to performance, but there has not been a focus on maximizing fault-tolerance. In this paper, we present a model for controller placement to account for fault-tolerance and compare our algorithm to existing algorithms. Our proposed solution was analyzed to determine where controllers should be placed on a wide range of topologies from the Internet Topology Zoo. We further evaluated the dependence of fault-tolerance over the range of available number of controllers. Adel Alshamrani, Sayantan Guha, Sandeep Pisharody, Ankur Chowdhary, Dijiang Huang |
ICC | 5 |
| 2018 | Conceptualizing Student Engagement in Virtual Hands-on Lab: Preliminary Findings from a Computer Network Security Course (Abstract Only)abstractEngaged students are more likely to spend longer time on study, and obtain a better academic performance. Previous studies investigated the role of student engagement in virtual learning environments (e.g., online course, online discussion forum, and intelligent tutoring systems). However, it is still challenging to engage students on a virtual hands-on lab system. Comparing to other virtual learning environment, students have a unique learning model -- learning by doing in virtual hands-on lab. To successfully engage students in a large hands-on lab in cybersecurity education, instructors need to understand how students engage in a lab session, and how their engagement affect lab learning outcome in this specific educational setting. In this paper, we developed a conceptual model, especially for virtual hands-on lab education, to describe student engagement during learning processes in working on virtual hands-on lab tasks. This model adopts two existing educational models on engagement behavior. Preliminary data was collected from 109 students' lab project in a computer network security course at Arizona State University in 2016 Fall semester. Pearson correlation coefficient analysis results reveal two statistically significant preliminary results: the longer time a student spends on reading lab instructional material, the more likely the student works longer time on lab tasks (p < 0.01); the longer time a student works on lab tasks, a better learning performance the student archives (p < 0.01). Yuli Deng, I-Han Hsiao, Dijiang Huang, Chun-Jen Chung |
SIGCSE | 4 |
| 2018 | Privacy-preserving mobile crowd sensing in ad hoc networks
Zhijie Wang 0002, Dijiang Huang |
Ad Hoc Networks | 2 |
| 2018 | Dual-mode broadcast encryption
Yan Zhu 0010, Ruyun Yu, E. Chen 0001, Dijiang Huang |
Sci. China Inf. Sci. | 4 |
| 2018 | PHE: An Efficient Traitor Tracing and Revocation for Encrypted File Syncing-and-Sharing in CloudabstractRecently, many enterprises have moved their data into the cloud by using file syncing and sharing (FSS) services, which have been deployed for mobile users. However, Bring-Your-Own-Device (BYOD) solutions for increasingly deployed mobile devices have also in fact raised a new challenge for how to prevent users from abusing the FSS service. In this paper, we address this issue by using a new system model involving anomaly detection, tracing, and revocation approaches. The presented solution applies a new threshold public key based cryptosystem, called partially-ordered hierarchical encryption (PHE), which implements a partial-order key hierarchy and it is similar to role hierarchy widely used in RBAC. PHE provides two main security mechanisms, i.e., traitor tracing and key revocation, which can greatly improve the efficiency compared to previous approaches. The security and performance analysis shows that PHE is a provably secure threshold encryption and provides following salient management and performance benefits: it can promise to efficiently trace all possible traitor coalitions and support public revocation not only for the users but for the specified groups. Yan Zhu 0010, Guohua Gan, Dijiang Huang |
IEEE Trans. Cloud Comput. | 4 |
| 2018 | Attribute-based Access Control for ICN Naming SchemeabstractInformation Centric Networking (ICN) is a new network architecture that aims to overcome the weakness of existing IPbased networking architecture. Instead of establishing a connection between the communicating hosts, ICN focuses on the content, i.e., data, transmitted in network. Content copies in ICN can be cached at different locations. The content is out of its owner's control once it is published. Thus, enforcing access control policies on distributed content copies is crucial in ICN. Attribute-Based Encryption (ABE) is a feasible approach to enforce such control mechanisms in this environment. However, applying ABE in ICN faces two challenges: from management perspective, it is complicated to manage attributes in distributed manners; from privacy protection perspective, unlike in traditional networks, the enforced content access policies are public to all the ICN users. Thus, it is desirable that unauthorized content viewers are not able to retrieve the access policy. To this end, a privacy-preserving access control scheme for ICN and its corresponding attribute management solution are presented in this paper. The proposed approach is compatible with existing flat name based ICN architectures. Bing Li 0019, Dijiang Huang, Zhijie Wang 0002, Yan Zhu 0010 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | A data driven in-air-handwriting biometric authentication systemabstractThe gesture-based human-computer interface requires new user authentication technique because it does not have traditional input devices like keyboard and mouse. In this paper, we propose a new finger-gesture-based authentication method, where the in-air-handwriting of each user is captured by wearable inertial sensors. Our approach is featured with the utilization of both the content and the writing convention, which are proven to be essential for the user identification problem by the experiments. A support vector machine (SVM) classifier is built based on the features extracted from the hand motion signals. To quantitatively benchmark the proposed framework, we build a prototype system with a custom data glove device. The experiment result shows our system achieve a 0.1% equal error rate (EER) on a dataset containing 200 accounts that are created by 116 users. Compared to the existing gesture-based biometric authentication systems, the proposed method delivers a significant performance improvement. Duo Lu, Dijiang Huang |
IJCB | 3 |
| 2017 | Privacy-Preserving Matchmaking in Geosocial Networks with Untrusted ServersabstractAs a major branch of LBSs, geosocial networking services become popular. An important functionality of geosocial networking services is allowing people to find potential friends who have similar profile within close proximity and initiate communication with each other. However, in order to realize this functionality, most existing services require mobile users to reveal their profiles and location information to an untrusted service provider, which may expose LBSs to vulnerabilities for abuse and endanger mobile users' privacy. To address this problem, we propose to encrypt users' profile with a new searchable encryption scheme. Combining this searchable encryption scheme with other cryptographic techniques we construct a privacy- preserving matchmaking system. Compared with a previous one that aims to solve the same problem, ours is more secure, supports more flexible functionalities and moves computationally heavy key updates to resourceful service providers. Qiuxiang Dong, Dijiang Huang |
ICDCS | 2 |
| 2017 | ThoTh Lab: A Personalized Learning Framework for CS Hands-on Projects (Abstract Only)abstractPersonalized learning is often referred to a new learning approach by taking individual parameters such as learning preferences, abilities, skills and knowledge into account. In this poster, we present a personalized learning solution for computer networks, system, and cybersecurity focusing on hands-on projects. The personalized learning models are established in ThoTh Lab - a cloud-based hands-on virtual laboratory for Computer Science (CS) education. ThoTh Lab is a remote web-accessing virtual laboratory and it was originally designed to reduce lab management overhead for instructors and improve learning experience for CS students. By introducing new personalized learning capabilities, we can transfer ThoTh Lab from a traditional hands-on lab resource provisioning system to an active personalized e-learning platform for CS education. The system can track and assess students' hands-on projects' activities to monitor students' lab performance, and then provide intelligent suggestions or resources to improve students' learning experience and outcomes. Our personalized learning framework is distinguished from existing approaches by three salient features: (1) it is built into a hands-on and virtualized laboratory environment usually involving multiple virtual computers and their interconnections, (2) it has incorporated into a wide range of learners' characteristics such as individuals' learning style, prior knowledge and learning effectiveness, and it is designed to be able to include new and customizable features, (3) it uses machine learning approaches to model student characteristics during the learning process. Yuli Deng, Dijiang Huang, Chun-Jen Chung |
SIGCSE | 2 |
| 2017 | Platooning as a service of autonomous vehiclesabstractSmart vehicles equipped with computers and wireless communication devices are emerging on the road. These vehicles can drive themselves, communicate to other vehicles, connect to the Internet, and provide value-added services to the drivers and passengers. With the advent of such technology, it is possible to form a "platoon" of autonomous vehicles on the road, where they follow a common leader vehicle in the same lane on the highway and maintain close proximity to save fuel, improve road capacity and passenger comfort. However, realizing such vision faces difficulties on both software architecture and vehicle control. In this paper, we propose a service-oriented perspective for the software modules on the autonomous vehicles, where platooning is designed as an independent service interacting with other components of the vehicle. We also built a prototype system with low cost vehicle-like mobile robots and ran experiments to demonstrate the effectiveness of our service framework and our platooning control algorithm. Our hope is that the platooning as a service approach can help in the construction of more efficient, interoperable, and secure autonomous vehicles in the future. Duo Lu, Dijiang Huang |
WoWMoM | 3 |
| 2017 | iDoctor: Personalized and professionalized medical recommendations based on hybrid matrix factorization
Yin Zhang 0002, Min Chen 0003, Dijiang Huang, Di Wu 0001, Yong Li 0008 |
Future Gener. Comput. Syst. | 3 |
| 2016 | Guest Editors' Introduction: Special Issue on Reliable and Secure VANETsabstractVehicular ad-hoc networks (VANETs) has gained a significant attention during the last decades both from industrial and academia communities. Novel VANET enabled active safety automotive applications are heavily dependent on reliability and security of underlying intervehicle communication protocols. The error-prone nature of the wireless channel and its openness to external invasions as well as dynamic VANET environment, impose the need for intensive studies before applications like platooning or collision avoidance can become a part of our daily life. The aim of this special issue is to encompass research advances in all areas of reliability and security in VANETs. Alexey V. Vinel, Xiaomin Ma, Dijiang Huang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2015 | MTD 2015: Second ACM Workshop on Moving Target DefenseabstractThe second ACM workshop on cloud data management is held in Denver, Colorado, USA on October 12, 2015 and co-located with the ACM 22nd Conference on Computer and Communications Security (CCS). The main idea of moving-target defense (MTD) is to impose an asymmetric disadvantage on attackers by making systems dynamic and therefore harder to explore and predict. This workshop seeks to bring together researchers from academia, government, and industry to report on the latest research efforts on moving-target defense, and to have productive discussion and constructive debate on this topic. We have constructed an exciting program of 12 referred papers and two invited keynote talks that will give participants a comprehensive view of emerging research. George Cybenko, Dijiang Huang |
CCS | 2 |
| 2015 | Demo: LIVES: Learning through Interactive Video and Emotion-aware SystemabstractIn order to improve the accuracy and efficiency of emotion recognition, we design a novel system called Learning through Interactive Video and Emotion-aware System (LIVES). LIVES includes data collection, emotion recognition, and result validation, as well as emotion feedback. We adopt transfer learning to label and validate moods in LIVES, while the emotion can be classified into six types of mood in a reasonable accuracy. Through transfer learning, the time-consuming and labor-intensive processing cost on data collection and labeling can also be greatly reduced. In our prototype system, LIVES is used to enhance an emotion-aware robot's intelligence provided by cloud. LIVES-based emotion recognition is executed in the remote cloud while corresponding result is sent to the robot for emotion feedback. The experimental results demonstrate LIVES significantly improves the accuracy and effective of emotion classification. Min Chen 0003, Yixue Hao, Yong Li 0008, Di Wu 0001, Dijiang Huang |
MobiHoc | 5 |
| 2015 | Establishing A Personal On-Demand Execution Environment for Mobile Cloud Applications
Dijiang Huang, Yan Zhu 0010 |
Mob. Networks Appl. | 2 |
| 2015 | Efficient Attribute-Based Comparable Data Access ControlabstractWith the proliferation of mobile devices in recent years, there is a growing concern regarding secure data storage, secure computation, and fine-grained access control in data sharing for these resource-constrained devices in a cloud computing environment. In this work, we propose a new efficient framework named Constant-size Ciphertext Policy Comparative Attribute-Based Encryption (CCP-CABE) with the support of negative attributes and wildcards. It embeds the comparable attribute ranges of all the attributes into the user's key, and incorporates the attribute constraints of all the attributes into one piece of ciphertext during the encryption process to enforce flexible access control policies with various range relationships. Accordingly, CCP-CABE achieves the efficiency because it generates constant-size keys and ciphertext regardless of the number of involved attributes, and it also keeps the computation cost constant on lightweight mobile devices. We further discuss how to extend CCP-CABE to fit a scenario with multiple attribute domains, such that the decryption proceeds from the least privileged attribute domain to the most privileged one to help protect the privacy of the access policy. We provide security analysis and performance evaluation to demonstrate their efficiency at the end. Zhijie Wang 0002, Dijiang Huang, Yan Zhu 0010, Bing Li 0019, Chun-Jen Chung |
IEEE Trans. Computers | 2 |
| 2015 | Efficient Privacy-Preserving Ciphertext-Policy Attribute Based-Encryption and Broadcast EncryptionabstractCiphertext Policy Attribute-Based Encryption (CP-ABE) enforces expressive data access policies and each policy consists of a number of attributes. Most existing CP-ABE schemes incur a very large ciphertext size, which increases linearly with respect to the number of attributes in the access policy. Recently, Herranzproposed a construction of CP-ABE with constant ciphertext. However, Herranzdo not consider the recipients’ anonymity and the access policies are exposed to potential malicious attackers. On the other hand, existing privacy preserving schemes protect the anonymity but require bulky, linearly increasing ciphertext size. In this paper, we proposed a new construction of CP-ABE, named Privacy Preserving Constant CP-ABE (denoted as PP-CP-ABE) that significantly reduces the ciphertext to a constant size with any given number of attributes. Furthermore, PP-CP-ABE leverages a hidden policy construction such that the recipients’ privacy is preserved efficiently. As far as we know, PP-CP-ABE is the first construction with such properties. Furthermore, we developed a Privacy Preserving Attribute-Based Broadcast Encryption (PP-AB-BE) scheme. Compared to existing Broadcast Encryption (BE) schemes, PP-AB-BE is more flexible because a broadcasted message can be encrypted by an expressive hidden access policy, either with or without explicit specifying the receivers. Moreover, PP-AB-BE significantly reduces the storage and communication overhead to the order of${\mbi {O}}(\log {\mbi {N}})$, where${\mbi {N}}$is the system size. Also, we proved, using information theoretical approaches, PP-AB-BE attains minimal bound on storage overhead for each user to cover all possible subgroups in the communication system. Zhibin Zhou 0001, Dijiang Huang, Zhijie Wang 0002 |
IEEE Trans. Computers | 2 |
| 2015 | From RBAC to ABAC: Constructing Flexible Data Access Control for Cloud Storage ServicesabstractThis paper addresses how to construct an RBAC-compatible secure cloud storage service with a user-friendly and easy-to-manage attribute-based access control (ABAC) mechanism. Similar to role hierarchies in RBAC, attribute hierarchies (considered as partial ordering relations) are introduced into attribute-based encryption (ABE) in order to define a seniority relation among all values of an attribute, whereby a user holding senior attribute values acquires permissions of his/her juniors. Based on these notations, we present a new ABE scheme called attribute-based encryption with attribute hierarchies (ABE-AH) to provide an efficient approach to implement comparison operations between attribute values on a poset derived from an attribute lattice. By using bilinear groups of a composite order, we present a practical construction of ABE-AH based on forward and backward derivation functions. Compared with prior solutions, our scheme offers a compact policy representation approach that can significantly reduce the size of private-keys and ciphertexts. To demonstrate how to use the presented solution, we illustrate how to provide richer expressive access policies to facilitate flexible access control for data access services in clouds. Yan Zhu 0010, Dijiang Huang, Chang-Jyun Hu |
IEEE Trans. Serv. Comput. | 2 |
| 2014 | QoS-constrained sensing task assignment for mobile crowd sensingabstractThe ubiquitous sensing-capable mobile devices have been fuelling the new paradigm of Mobile Crowd Sensing (MCS) to collect data about their surrounding environment. To ensure the timeliness and quality of the data samples in MCS, it is critical to select qualified participants to maintain sensing coverage ratios over important spatial areas (i.e., hotspots) during time periods of interest and meet various Quality of Service (QoS) requirements of sensing applications. In this paper, we examine the problems of sensing task assignment to minimize the overall cost and maximize the total utility in MCS while adhering to the QoS constraints and prove that they are NP-hard problems. Consequently, we present heuristic greedy approaches as the baseline solutions and further propose new hybrid approaches with the greedy algorithm and bees algorithm combined to address them. We demonstrate that the hybrid approaches significantly outperform the greedy approaches through extensive simulation and the analysis is given in the end. Zhijie Wang 0002, Dijiang Huang, Yuli Deng, Ailixier Aikebaier, Yuuichi Teranishi |
GLOBECOM | 2 |
| 2014 | Towards distributed privacy-preserving mobile access controlabstractThe mobile marketing is growing exponentially worldwide due to the emerging high speed wireless Internet and the proliferation of smartphones with powerful processors. Consequently, the management of the massive volume of mobile identities has sparked a lot of interest in both industry and academia, as they turn out to be a heavy burden for many mobile application startups. The conventional federated identity management technologies have been developed to delegate the users' identity tasks across different security domains to reduce the burden over the identity service consumers (i.e., Relying Party). However, they also raises serious security and privacy issues, such as the vulnerability to Single Point of Failure (SPOF) and the privacy leakage with respect to users' historical access information. To address these issues, we architect a novel Distributed Privacy-preserving Mobile Access Control (DP-MAC) framework. This framework also leverages a dual-root trust model to prevent identity theft in case of mobile device loss. In the end, we give performance evaluation and prove its applicability by implementing our system in the Cloud Computing platform and android smartphones based on jPBC in real-world settings. Zhijie Wang 0002, Dijiang Huang, Bing Li 0019, Yuli Deng |
GLOBECOM | 2 |
| 2014 | A database oriented management for asynchronous and consistent reconfiguration in Software-Defined NetworksabstractSoftware-Defined Networking (SDN) is a new approach to manage the whole network flexibly by decoupling the control plane and the forwarding plane. While forwarding elements can be managed by a unified control, complexity arisen from the network size and scalability regarding the increase of the control traffic are notable problems. To deal with events of network reconfiguration that occur asynchronously and change frequently with intervals shorter than hours, a controller has to continue to asynchronously update the configuration of the whole network. However, it is hard to maintain the consistency of the configuration of the whole network because it needs to manage a huge amount of network information and to deal with user requests that occur asynchronously. In this paper, we propose a database oriented management for asynchronous reconfiguration to achieve the consistency of configuration in SDN. We design a structure of the database to store network information and two functional components. Finally, we adopt our management system to an OpenFlow-based network, and validate that our system can manage and control an OpenFlow network via the database. Yuki Kawai, Yasuhiro Sato, Shingo Ata, Dijiang Huang, Deep Medhi, Ikuo Oka |
NOMS | 4 |
| 2014 | SeRViTR: A framework, implementation, and a testbed for a trustworthy future Internet
Shingo Ata, Dijiang Huang, Xuan Liu 0002, Akira Wada, Tianyi Xing, Parikshit Juluri, Chun-Jen Chung, Yasuhiro Sato, Deep Medhi |
Comput. Networks | 2 |
| 2014 | STARS: A Statistical Traffic Pattern Discovery System for MANETsabstractMany anonymity enhancing techniques have been proposed based on packet encryption to protect the communication anonymity of mobile ad hoc networks (MANETs). However, in this paper, we show that MANETs are still vulnerable under passive statistical traffic analysis attacks. To demonstrate how to discover the communication patterns without decrypting the captured packets, we present a novel statistical traffic pattern discovery system (STARS). STARS works passively to perform traffic analysis based on statistical characteristics of captured raw traffic. STARS is capable of discovering the sources, the destinations, and the end-to-end communication relations. Empirical studies demonstrate that STARS achieves good accuracy in disclosing the hidden traffic patterns. Dijiang Huang, Bing Li 0019 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | Non-intrusive process-based monitoring system to mitigate and prevent VM vulnerability explorationsabstractCloud is gaining momentum but its true potential is hampered by the security concerns it has raised. Having vulnerable virtual machines in a virtualized environment is one such concern. Vulnerable virtual machines are an easy target and existence of such weak nodes in a network jeopardizes its enti Chun-Jen Chung, Jingsong Cui, Pankaj Khatkar, Dijiang Huang |
CollaborateCom | 4 |
| 2013 | Making offloading decisions resistant to network unavailability for mobile cloud collaborationabstractOffloading is one major type of collaborations between mobile devices and clouds to achieve less execution time and less energy consumption. Offloading decisions for mobile cloud collaboration involve many decision factors. One of important decision factors is the network unavailability that has not Dijiang Huang, Samia Bouzefrane 0001 |
CollaborateCom | 2 |
| 2013 | An Efficient and Anonymous Attribute-Based group setup schemeabstractIn many secure application scenarios, establishing a temporary group without revealing group member information is difficult but desirable. Secure group communication can significantly reduce the computation and communication overhead. Traditional group key management schemes are based on a hierarchical tree. Any network entity who wants to set up a group needs to know the keys of the other group members, i.e., the group key establishment must be done before starting the group communication. As a result, the group needs the group formation beforehand. In this paper, we propose a secure grouping scheme providing anonymity for group members to outsiders. Our approach is based on Attribute Based Encryption (ABE) schemes. In our scheme, each network entity is assigned with a set of attributes. Each group is identified by a logical combination of attributes, i.e., the group access policies. The presented solution has an advantage that there is no need for any prior knowledge of other group members. Instead, the sender just needs to focus on the group access policies. Our scheme further preserves the group formation policies by using a gradual exposure method on attributes. Compared to existing hidden-policy schemes, our solution can greatly reduce the computation and communication overhead. Bing Li 0019, Zhijie Wang 0002, Dijiang Huang |
GLOBECOM | 3 |
| 2013 | A behavior based policy management for adaptive trustworthiness assignment in future network
Akira Wada, Yasuhiro Sato, Xuan Liu 0002, Tianyi Xing, Shingo Ata, Deep Medhi, Dijiang Huang, Ikuo Oka |
IM | 7 |
| 2013 | MCC-OSGi: An OSGi-based mobile cloud service modelabstractIn this article, a new mobile Cloud service model is presented. It offers a dynamic and efficient remote access to information services and resources for mobile devices. Mobile Cloud computing has been evolved as a distributed service model, where individual mobile users are Cloud service providers. Compared to traditional Internet-centric Cloud service models, the complexity of mobile service management in a dynamic and distributed service environment is increased dramatically. To address this challenge, we propose to establish an OSGi-based mobile Cloud service model — MCC-OSGi — that uses OSGi Bundles as the basic mobile Cloud service building components. The proposed solution supports OSGi bundles running on both mobile devices and Cloud-side virtual machine OS platforms, and the bundles can be transferred and run on different platforms without compatibility issues. The presented solution is achieved: 1) by incorporating OSGi into Android software development platform, 2) by setting up a Remote-OSGi on the Cloud and on mobile devices, and 3) by defining three service architecture models. The presented solution is validated through a demonstrative application with relevant performance measurements. Fatiha Houacine, Samia Bouzefrane 0001, Dijiang Huang |
ISADS | 4 |
| 2013 | A cloud based dual-root trust model for secure mobile online transactionsabstractWith rapid growth of mobile devices and the emergency of mobile cloud services, it is a trend to use mobile devices for mobile-centric applications, and expand the mobile capabilities and provide needed security by mobile cloud services. However, due to the mobility of the device and the semitrust of the mobile cloud, how to build trust in the mobile applications is a big concern. In this paper, we propose a dual-root trust online transaction model that provides a dualroot trust model including both the user's mobile device and a delegation mobile cloud. We design a dual-root trust protocol by leveraging a modified CP-ABE cryptography and the trust execution environment embedded in a mobile device to provide device-specific transaction confirmations for online transactions initiated by the mobile user. The performance evaluation of the protocol demonstrates that it is a lightweight scheme for mobile devices since most cryptographic functions are delegated from users to the mobile cloud. Dijiang Huang, Zhidong Shen, Samia Bouzefrane 0001 |
WCNC | 2 |
| 2013 | NICE: Network Intrusion Detection and Countermeasure Selection in Virtual Network SystemsabstractCloud security is one of most important issues that has attracted a lot of research and development effort in past few years. Particularly, attackers can explore vulnerabilities of a cloud system and compromise virtual machines to deploy further large-scale Distributed Denial-of-Service (DDoS). DDoS attacks usually involve early stage actions such as multistep exploitation, low-frequency vulnerability scanning, and compromising identified vulnerable virtual machines as zombies, and finally DDoS attacks through the compromised zombies. Within the cloud system, especially the Infrastructure-as-a-Service (IaaS) clouds, the detection of zombie exploration attacks is extremely difficult. This is because cloud users may install vulnerable applications on their virtual machines. To prevent vulnerable virtual machines from being compromised in the cloud, we propose a multiphase distributed vulnerability detection, measurement, and countermeasure selection mechanism called NICE, which is built on attack graph-based analytical models and reconfigurable virtual network-based countermeasures. The proposed framework leverages OpenFlow network programming APIs to build a monitor and control plane over distributed programmable virtual switches to significantly improve attack detection and mitigate attack consequences. The system and security evaluations demonstrate the efficiency and effectiveness of the proposed solution. Chun-Jen Chung, Pankaj Khatkar, Tianyi Xing, Jeongkeun Lee, Dijiang Huang |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2012 | MobiCloud: A geo-distributed mobile cloud computing platform
Tianyi Xing, Dijiang Huang, Shingo Ata, Deep Medhi |
CNSM | 2 |
| 2012 | Efficient and secure data storage operations for mobile cloud computing
Zhibin Zhou 0001, Dijiang Huang |
CNSM | 2 |
| 2012 | Constructing a virtual networking environment in a Geo-distributed programmable layer-2 networking environment (G-PLaNE)abstractWith Cloud Computing technology occupying the majority of future Internet research and development work, research on deploying and extending existing capabilities onto a newly emerging infrastructure becomes more significant. For example, extending the virtual network provisioning capability onto a Geo-distributed programmable layer-2 networking environment (G-PLaNE) is a novel attempt and is different from in a single domain system. In this paper, we aim to illustrate how to construct the virtual networking environment upon our self-designed resource provisioning system consisting of multiple clusters through G-PLaNE. Experimenters and researchers are able to develop and explore their own mechanisms in our platform. Furthermore, a concrete example named Secure and Resilient Virtual Trust Routing (SeRViTR) is given to illustrate how this can be constructed over G-PLaNE. Tianyi Xing, Xuan Liu 0002, Chun-Jen Chung, Akira Wada, Shingo Ata, Dijiang Huang, Deep Medhi |
ICC | 6 |
| 2012 | Towards temporal access control in cloud computingabstractAbstract—Access control is one of the most important security mechanisms in cloud computing. Attribute-based access control provides a flexible approach that allows data owners to integrate data access policies within the encrypted data. However, little work has been done to explore temporal attributes in specifying and enforcing the data owner’s policy and the data user’s privileges in cloud-based environments. In this paper, we present an efficient temporal access control encryption scheme for cloud services with the help of crypto-graphic integer comparisons and a proxy-based re-encryption mechanism on the current time. We also provide a dual comparative expression of integer ranges to extend the power of attribute expression for implementing various temporal constraints. We prove the security strength of the proposed scheme and our experimental results not only validate the effectiveness of our scheme, but also show that the proposed integer comparison scheme performs significantly better than previous bitwise comparison scheme. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Dijiang Huang, Shan-Biao Wang |
INFOCOM | 4 |
| 2012 | V-lab: a cloud-based virtual laboratory platform for hands-on networking coursesabstractFor computer-network education, hands-on laboratories are essential in addition to lectures. Existing laboratory solutions are usually expensive to build, configure and maintain, while still lacking reusability, flexibility and scalability. This paper presents a cloud-based virtual laboratory education solution, called V-Lab, where instructors can use an interactive web GUI to configure computer network testbeds based on a set of dedicated virtual computers interconnected through VLAN-based virtual networks. The established virtual network system can be accessed by students via remote access using standard Secure Shell (SSH), Virtual Network Computing (VNC), or Remote Desktop Protocol (RDP). By using a flexible and re-configurable design, V-Lab greatly reduces the effort needed to establish and maintain a physical laboratory, while providing a secure and reliable environment that encourages students to use the resources based on their own schedule. V-Lab also helps re-design laboratory curriculum to focus on six educational factors, and the survey results show that V-Lab system is easy to use and setup and has satisfactory performance and reliability. It is also indicated that V-Lab helps students understand and solve real-world problems with sufficient laboratory resources and improved efficiency. Dijiang Huang, Wei-Tek Tsai |
ITiCSE | 2 |
| 2012 | SeRViTR: A framework for trust and policy management for a secure Internet and its proof-of-concept implementationabstractA secure network is considered to be an important goal of the Future Internet; one way this can be embodied is by having flexible and robust routing functionalities with intrinsic security mechanisms. It is also desirable to provide user-centric or service-centric routing capabilities to achieve service-oriented traffic controls as well as trust and policy management for security. Based on these potential needs, a flexible, scalable, and robust routing framework that enables fine-grained flow control under fixed or dynamic policies called the Virtual Trusted Routing and Provisioning Domain (VTRouPD)[11] has been recently proposed. In this paper, we present a framework called the Secure and Resilient Virtual Trust Routing (SeRViTR) framework, which is a proof-of-concept model of VTRouPD at the implementation level. SeRViTR has particular entities that are designed for policy management and trust management between different VTRouPDs to enable a secure Internet. We define the roles of each entity within the SeRViTR framework as well as the messages exchanged between them. We also discuss how policy management and trust negotiation can be achieved. Moreover, we present validation on the functional implementation of several SeRViTR components to illustrate how to create virtual domains and change of trust levels between virtual domains. Xuan Liu 0002, Akira Wada, Tianyi Xing, Parikshit Juluri, Yasuhiro Sato, Shingo Ata, Dijiang Huang, Deep Medhi |
NOMS | 7 |
| 2012 | Cheater Detection in Vehicular NetworksabstractIn this paper, we focus on congestion cheaters in vehicular networks who report non-existing high-way congestion information. In this solution, we require each vehicle to only detect its local highway traffic pattern to detect congestion and then identify cheaters. Vehicles can broadcast a congestion event to other vehicles. However, a rogue vehicle can also broadcast a bogus congestion message in order to get advantage over other vehicles for malicious purposes. To address this cheating problem, we develop a cheater detection protocol, in which each vehicle only depends on local velocity and distance measurements to validate the congestion event sent by a vehicle. Our presented protocol is based on the traffic flow theory to detect the Kinematic wave caused by congestion. The presented cheater detection solution is effective in that it only requires vehicles to communicate with its neighboring vehicles without relying on a centralized controlled congestion detection and prediction system. Dijiang Huang, Sean A. Williams, Swaroop Shere |
TrustCom | 1 |
| 2012 | VehiCloud: Cloud Computing Facilitating Routing in Vehicular NetworksabstractEstablishing reliable routing among highly mobile vehicles is a challenging problem in vehicular networks. Towards this issue, we present VehiCloud, a novel cloud computing architecture that leverages emerging cloud computing technologies to deal with unreliable inter-vehicle communications and extend the restricted computational capabilities of mobile devices. A way-point information framework (WIF) is devised within the VehiCloud architecture, aiming to provide routing service for vehicular network, where each vehicle serves as a mobile service node and predicts its future locations by generating way point messages, which describe the trajectory of the vehicle's movement. A decision module in VehiCloud collects vehicles' way points and makes routing decisions for inter-vehicle communication. Selected paths of the routing are globally optimized in terms of message delivery ratio by respecting the constraints of end-to-end delay and communication cost. Our implementation of VehiCloud and real-road experiments demonstrate that it is practical and efficient to address fundamental routing problems for vehicular networks. Dijiang Huang, Xinwen Zhang |
TrustCom | 2 |
| 2012 | Geographic-Based Service Request Scheduling Model for Mobile Cloud ComputingabstractWith Internet environment is getting optimized and users preferring mobile communications, Cloud Service Providers (CSP) aim to provide services to users depending on their geographic locations with higher service availability and faster access speed. Mobile cloud computing falls into this category, where mobile users can move around and request cloud services at any given geographic locations. To build such a geographic-based mobile cloud services, an effective mobile cloud resource allocation and service request scheduling scheme is highly desired. To this end, the presented service request scheduling scheme takes a comprehensive approach by considering system parameters from both CSP and mobile users such as computation, energy, connectivity, service payment, mobile users' satisfaction, etc. Finally, the performance evaluation of the proposed scheduling scheme is evaluated through simulations where the results show that the presented scheme achieves better system overall gain compared to traditional over-provisioning approaches. Tianyi Xing, Hongbin Liang, Dijiang Huang, Lin X. Cai |
TrustCom | 3 |
| 2011 | Least Squares Disclosure Attack in Mobile Ad Hoc NetworksabstractTraffic analysis is considered the most powerful strategy of disclosing the hidden communication relations in an anonymous communication system. Statistical traffic analysis attacks are even more subtle in that the attackers are usually eavesdroppers who do not modify the network's behaviors. Moreover, the attackers even do not need to look into the traffic content, which may be encrypted, in order to analyze the statistical characteristics. Such attacks have been thoroughly investigated for static wireline networks. However, none of these mechanisms can be directly applied to mobile ad hoc networks (MANETs) due to the inability to deal with mobility, the ad hoc infrastructure and the broadcasting nature of wireless transmissions. Recent research conducted on statistical traffic analysis attacks targeting MANETs is restricted to disclosing the end-to-end traffic distribution. In this paper, we present the least squares disclosure attack (LSDA), targeting a popular MANET routing strategy, that is, the position based routing (PBR, a.k.a geographic routing). LSDA utilizes the traffic distribution disclosed by existing solutions, and de-anonymizes the network communication on a per-flow basis by identifying the source and destination of each end-to-end flow. In LSDA, traffic disclosure is modeled as an efficiently solvable least squares problem subject to linear constraints. The empirical study demonstrates that, the proposed solution can de-anonymize the network flows in high accuracy. Dijiang Huang |
ICC | 2 |
| 2011 | PACP: An Efficient Pseudonymous Authentication-Based Conditional Privacy Protocol for VANETsabstractIn this paper, we propose a new privacy preservation scheme, named pseudonymous authentication-based conditional privacy (PACP), which allows vehicles in a vehicular ad hoc network (VANET) to use pseudonyms instead of their true identity to obtain provably good privacy. In our scheme, vehicles interact with roadside units to help them generate pseudonyms for anonymous communication. In our setup, the pseudonyms are only known to the vehicles but have no other entities in the network. In addition, our scheme provides an efficient revocation mechanism that allows vehicles to be identified and revoked from the network if needed. Thus, we provide conditional privacy to the vehicles in the system, that is, the vehicles will be anonymous in the network until they are revoked, at which point, they cease to be anonymous. Dijiang Huang, Satyajayant Misra, Mayank Verma, Guoliang Xue |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2010 | Establishing Email-Based Social Network Trust for Vehicular NetworksabstractWe propose a vehicular network trust model that integrates cryptography-based entity trust and email-based social trust. The entity trust provides security protections such as origin integrity, data integrity, and confidentiality. The social trust provides a level of belief on the data transmitted by an entity. To achieve the email-based social trust, we require each user to run an automated agent that performs trust evaluation checks and processes trust checking requests. The requests are from their highly trusted contacts or through a trusted proxy server maintained by the email service provider. We utilize identity-based cryptography (IBC) to integrate entity trust and social trust. This allows us to use a unique identity (e.g., an email address) for each entity. Further, we use the IBC based attribute based cryptography to develop secure group communications in vehicular networks. Finally, we present research challenges and potential research directions to extend this work. Dijiang Huang, Zhibin Zhou 0001, Xiaoyan Hong, Mario Gerla |
CCNC | 1 |
| 2010 | IEEE 802.11 Wireless LAN Control Frame ProtectionabstractIn the present communication scenario of 802.11 wireless local access network there is virtually no way to protect control frames and due to this a range of network allocation vector based denial of service attacks are possible. This paper proposes a novel approach for protecting control frames by generating a unique message authentication code using inter access point protocol for key distribution and key management. Evaluation results show that the denial of service attacks that are possible due to not securing the control frames will be countered by using this solution. Sowmya Myneni, Dijiang Huang |
CCNC | 2 |
| 2010 | Using Power Hopping to Counter MAC Spoof Attacks in WLANabstractIEEE 802.11-based wireless LANs (WLANs) are deployed in public places, universities, offices and shops. The main reason for the popularity is convenience of internetworking without wires. The increase in WLANs also resulted in increase of security threats. One of these threats is spoofing MAC address. Some WLANs use MAC filtering to allow stations with registered MAC addresses to use the network. The attacker has many tools like AirJack, WireShark to capture the packets in WLAN and find authorized MAC address. The attacker masquerades as an authorized station and can launch denial of service attack. This paper presents a power hopping technique which can be used by access points (AP) to discern the authorized packets from the masquerading packets and thus deny the attacker from using the system. Vijayakrishnan Nagarajan, Vetri Arasan, Dijiang Huang |
CCNC | 3 |
| 2010 | On efficient ciphertext-policy attribute based encryption and broadcast encryption: extended abstractabstractExisting CP-ABE schemes incur very large ciphertext size, which increases linearly with respect to the number of attributes in the access policy. Large ciphertext prevents CP-ABE from being adopted in the communication constrained environments. In this paper, we proposed a new construction of CP-ABE, named Constant-size CP-ABE (denoted as CCP-ABE) that significantly reduces the ciphertext to a constant size for an AND gate access policy with any given number of attributes. Each ciphertext in CCP-ABE requires only elements on a bilinear group. Zhibin Zhou 0001, Dijiang Huang |
CCS | 2 |
| 2010 | Anonymous Certification ServicesabstractThis paper describes Anonymous Communication Service (ACS), an PKI certificate service based system that permits the end user to access services offered by the service provider (SP) on the world-wide-web anonymously. ACS achieves end user anonymity by using pseudonym certificates issued to the user for the real certificates. The user can obtain multiple pseudonym certificates and use them for different transactions. Web servers or SP's are unable to determine the user's real identity or profile the user based upon the transactions. However, a user performing an illegal transaction can be revoked. Dijiang Huang |
GLOBECOM | 1 |
| 2010 | On Measuring Email-Based Social Network TrustabstractMeasuring trust among social network users is an important research issue. In this paper, we present a new trust model based on emails. We name this new trust model as Email Trust (EMT). EMT is constructed based on the interactions among users via their daily emails, which provides a level of belief on the data transmitted by a use. In EMT, we require each user to perform a trust checking procedure and process a received trust checking request from their highly trusted email contacts or through a trusted checking proxy server that is maintained by a trusted third party. We evaluate the EMT through a small EMT testing bed developed using Gmail services. Our preliminary evaluation results show that the EMT evaluation results can be used to represent users' trust among email users. Dijiang Huang, Vetri Arasan |
GLOBECOM | 1 |
| 2010 | Establishing Secure Virtual Trust Routing and Provisioning Domains for Future InternetabstractSecure virtualization is the enabling technique to protect both network providers and user services. Particularly, secure routing in the virtualized service domains is one of the key research areas that has not been explored in literature. In this paper, we present a new secure routing framework to address both network-centric and user-centric networking service models for the future Internet. We aim to provide a flexible network routing framework that has the capability to route traffic with different service requirements and constraints. In other words, it could be highly desirable that two types of network traffic should be isolated either physically or logically and trustworthy services should be avoided to share the bandwidth with normal traffic that may be prone to security attacks. To achieve this capability, we present how to establish a virtual trust routing framework to handle both network-centric routing and user-centric routing simultaneously by using attribute-based cryptography that can provide information-level protection for virtual routing domain isolation. Our performance evaluation on prioritized services through virtual routing domains and cryptography performance analysis demonstrates the viability of the proposed solution. Dijiang Huang, Shingo Ata, Deep Medhi |
GLOBECOM | 1 |
| 2010 | An Optimal Key Distribution Scheme for Secure Multicast Group CommunicationabstractMany IP multicast-based applications, such as multimedia conferencing, multiplayer games, require controlling the group memberships of senders and receivers. One common solution is to encrypt the data with a session key shared with all authorized senders/receivers. To efficiently update the session key in the event of member removal, many rooted-tree based group key distribution schemes have been proposed. However, most of the existing rooted-tree based schemes are not optimal. In other words, given the O(log N) storage overhead, the communication overhead is not minimized. On the other hand, although Flat Table scheme achieves optimality, it is rather dismissed due to the vulnerability to collusion attacks. In this paper, we propose a key distribution scheme - EGK that attains the same optimality as Flat Table without collusion vulnerability. Additionally, EGK provides constant message size and requires O(log N) storage overhead at the group controller, which makes EGK suitable for applications containing a large number of multicasting group members. Moreover, adding members in EGK requires just one multicasting message. EGK is the first work with such features and out- performs all existing schemes. Zhibin Zhou 0001, Dijiang Huang |
INFOCOM | 2 |
| 2009 | SeGCom: Secure Group Communication in VANETsabstractIn this paper, we propose a novel scheme to achieve secure, and efficient vehicular communication. In particular, SegCom provides two mechanisms to perform successive authentication of the vehicle with the road-side infrastructure units to expedite authentication for vehicle-to-infrastructure (V2I) communication. Furthermore, to enhance the efficiency of vehicle-to-vehicle (V2V) communication, SeGCom permits the vehicles to form group, which are also used for performing multi-hop V2V communication without any assistance from a trusted authority. Comparison with other existing schemes in the literature has been performed to show the efficiency and applicability of our scheme. Mayank Verma, Dijiang Huang |
CCNC | 2 |
| 2009 | Distributed Data-Theft Detection in Wireless Sensor NetworksabstractData theft in wireless sensor networks could prove disastrous and most of the time gets undetected due to no apparent abnormal behavior of malicious nodes. To counter such attacks, we propose an anomaly based distributed data-theft detection protocol. Our approach works at the MAC layer by effectively measuring the MAC control packets. In this paper, we present a novel detection metric, a centralized and a gossip-based distributed protocol whereby a network can self-heal itself of such malicious nodes. Our performance evaluation defines how we measure the rate of detection and false positives rate and shows that our approach to detect malicious nodes is reliable, inexpensive and accurate. Mukesh Jagasia, Dijiang Huang |
GLOBECOM | 2 |
| 2009 | Secret-Sharing Based Secure Communication Protocols for Passive RFIDsabstractWith increase in applicability of RFID technology, there is ever growing demand for security. The popularity of RFID applicability lies in its ability for automatic identification and low-cost of RFID tags. Most of the recent security protocols for RFID technology are based on cryptographic hash-based function which currently cannot be implemented on low-cost RFID tags. In this paper, we present a lightweight protocol based on key transportation and authentication using threshold secret sharing scheme which provides strong security on low-cost RFID tags without the need to connect to the backend server. Our solution is based on an asymmetric computation strategy allocating mathematical operations such as modular addition and XOR on passive RFID tags and move the computational complexity to the RFID interrogators. We believe a secure protocol on low-cost RFID tags would make RFID technology ubiquitous. Harsh Kapoor, Dijiang Huang |
GLOBECOM | 2 |
| 2009 | SEAS: A Secure and Efficient Anonymity Scheme for Low-Cost RFID TagsabstractIn this paper, we propose SEAS, a novel privacy preserving, anonymous authentication scheme for RFID tags, which allows the tags to use pseudonyms instead of their true identity for authentication. Using SEAS, a tag generates random numbers and uses them to create a pseudonym as its identity for authentication. The pseudonym does not reveal the identity of the tag and the pseudonyms of multiple authentications appear random and uncorrelated to the adversary. A pseudonym can only be deciphered by the back-end authentication authority to identify the tag. No other entity in the network can link the pseudonym to the identity of the tag. Our scheme is efficient, with a tag needing to perform only simple operations such as XOR, bits shifting, bits concatenation, and random number generation. We perform security analysis of our scheme to show its effectiveness against different forms of attacks. We also perform comparison of our scheme with existing schemes in terms of efficiency in the use of resources. Our scheme performs effectively, while at the same time being better than the other popular schemes in the literature in terms of cost and computation efficiency. Satyajayant Misra, Mayank Verma, Dijiang Huang, Guoliang Xue |
ICC | 3 |
| 2009 | On an information theoretic approach to model anonymous MANET communicationsabstractMeasuring communication anonymity (e.g., unlinkability) of anonymous communication systems is a critical, however, unsolved problem. To address this issue, we present an information theoretic model for unlinkability measure for MANETs. Our approach is based on evidence theory, where the basic measuring component is a ldquosetrdquo. We present a traffic slicing method to model mobility followed by theoretical models to evaluate sender and receiver unlinkability, path unlinkability, and system unlinkability. Dijiang Huang |
ISIT | 1 |
| 2009 | Towards Lightweight Secure Communication Protocols for Passive RFIDsabstractRFID technology has been applied to many business applications in the past few years. The popularity of RFID technology lies in its ability for automatic identification and low cost. Most existing RFID security protocols utilize cryptography based solutions relying on hash functions and symmetric-key based encryptions, which incur high computational overhead and thus are unsuitable for passive RFID tags. In this paper, we present a lightweight secure reader-tag communication protocol providing secure key lookup, key transportation, reader-tag mutual authentication, and data confidentiality without using traditional cryptography based encryption and hash functions. Our approach is based on light-weight exclusive-or (XOR) one-time pad and modulo addition on passive RFID tags and readers. Our security and performance analysis shows that the proposed solutions are suitable for low-power passive RFID tags. Dijiang Huang, Harsh Kapoor |
SECON | 1 |
| 2009 | ASPE: attribute-based secure policy enforcement in vehicular ad hoc networks
Dijiang Huang, Mayank Verma |
Ad Hoc Networks | 1 |
| 2008 | SRK: A Distributed RFID Data Access Control MechanismabstractExtremely limited in computational and energy capability, RFID tags, especially passive tags, can hardly authenticate the scanning readers. Thus, information leakage for RFID tags is one of the most challenging open problems holding back users' confidence in adopting RFID technologies. To solve this problem, we propose Smart RFID Keeper (SRK) - a distributed, off-tag RFID data access control Mechanism, which is installed in RFID enabled environments to regulate RFID scanning. To solve the information leakage threat, SRK is designed to (1) authenticate the user; (2) detect and counter unauthorized accesses to RFID tags and (3) enforce fine grained access policy. Zhibin Zhou 0001, Dijiang Huang |
ICC | 2 |
| 2008 | A secure group key management scheme for hierarchical mobile ad hoc networks
Dijiang Huang, Deep Medhi |
Ad Hoc Networks | 1 |
| 2008 | FPGA implementations of elliptic curve cryptography and Tate pairing over a binary field
Philip H. Sweany, Dijiang Huang |
J. Syst. Archit. | 4 |
| 2008 | Unlinkability Measure for IEEE 802.11 Based MANETsabstractIn this paper, we propose a two-step unlinkability measuring approach for MANET, i.e., (a) evidence collection using statistical packet-counting traffic analysis, (b) evidence theory-based unlinkability measure. We use IEEE 802.11b-based MANETs as our analytical systems. Using our approach, we can collect a set of evidence to set up a probability assignment for each possible communication relation (i.e., the data sender and corresponding receiver); and then we can apply the evidence theory-based unlinkability measuring methods to derive the unlinkability evaluations of the 802.11b MANET. Dijiang Huang |
IEEE Trans. Wirel. Commun. | 1 |
| 2007 | RFID Keeper: An RFID Data Access Control MechanismabstractAccess control for RFID tags is challenging due to the limited computational and energy capability of RFID tags. To solve this problem, we propose RFID Keeper - an RFID data access control mechanism based on RFID media access control protocols. RFID Keeper is designed to detect and counter unauthorized accesses to RFID tags. Zhibin Zhou 0001, Dijiang Huang |
GLOBECOM | 2 |
| 2007 | Modeling pairwise key establishment for random key predistribution in large-scale sensor networks
Dijiang Huang, Manish Mehta 0003, Appie van de Liefvoort, Deep Medhi |
IEEE/ACM Trans. Netw. | 1 |
| 2007 | Secure pairwise key establishment in large-scale sensor networks: An area partitioning and multigroup key predistribution approachabstractExisting pairwise key establishment schemes for large-scale sensor networks are vulnerable to various passive or active attacks. We classify attacks as selective node capture attacks, node fabrication attacks, and insider attacks. In order to improve the security robustness of random key predistribution and pairwise key establishment schemes against these attacks, we propose a five-phase pairwise key predistribution and pairwise key establishment approach by using area partitioning and multigroup key predistribution. Our security performance studies show that our proposed approach is resilient to selective node capture and node fabrication attacks, and restricts the consequence of any insider attack to a minimal level. Dijiang Huang, Deep Medhi |
ACM Trans. Sens. Networks | 1 |
| 2006 | On providing confidentiality in link state routing protocolabstractAbstract — In current network routing domains, routing information exchange usually lacks protection based on confidentiality. This makes network routing vulnerable to a variety of security attacks. In this paper, we present a framework to provide confidentiality for a link state routing protocol. This framework involves creation of a trust structure among routers as well as key management. Routing information is encrypted so that it can be accessed only by authorized routers. We present an implementation framework for our approach by extending Open Shortest Path First (OSPF), a commonly deployed link-state routing protocol. Based on our performance assessment, we have found that the additional cost in implementing our scheme has fairly moderate impact on the overall performance. I. Dijiang Huang, Amit Sinha, Deep Medhi |
CCNC | 1 |
| 2006 | On Measuring Anonymity For Wireless Mobile Ad-hoc NetworksabstractWe propose an evidence theory based anonymity measuring approach for wireless mobile ad-hoc networks. In our approach, an evidence is a measure of the number of detected packets within a given time period. Based on the collected evidence, we can set up basic probability assignments for all packet delivery paths and use evidence theory to quantify the anonymity in the number of bits. Our approach is more general and practical comparing to the traditional Shannon information theory based solutions where the probability assignments are predefined Dijiang Huang |
LCN | 1 |
| 2005 | Source routing based pairwise key establishment protocol for sensor networksabstractSensor networks are composed of a large number of low power sensor devices. For secure communication among sensors, secret keys must be established between them. The establishment of secret keys after deployment of sensors requires wireless communication. Because of the energy constraints, an efficient key establishment scheme cannot be designed without considering the power consumption factor in wireless communication. In order to reduce the communication overhead, we propose a source routing based pairwise key establishment protocol for large-scale sensor networks. We then use a probability model proposed in [D. Huang et al., (2004)] to analyze the communication overhead, and security strength of the scheme. Dijiang Huang, Manish Mehta 0003, Deep Medhi |
IPCCC | 1 |
| 2005 | A key distribution scheme for double authentication in link state routing protocolabstractThe double authentication (DA) scheme presented in D. Huang et al., (2003) is designed to provide security against impersonation attack to link state routing protocol at a lower computational cost as compared to the existing schemes, such as, digital signature scheme S. Murphy et al. (1997). In this paper, we present a key distribution scheme that can be used for generating and distributing keys to provide DA. This scheme leads to a storage complexity for each router that varies linearly with the number of routers in the network in the worst case (fully connected network with n nodes). Moreover, for router with four or less average number of links, the storage complexity falls below log/sub 2/n. This scheme also increases the security robustness of DA as the subverted routers can collude only if they are neighbors. Dijiang Huang, Amit Sinha, Deep Medhi |
IPCCC | 1 |
| 2005 | RINK-RKP: a scheme for key predistribution and shared-key discovery in sensor networksabstractEfficient schemes for key predistribution and shared-key discovery play a vital role in security and efficiency of pairwise key establishment in sensor networks. In this paper, we propose a scheme for key predistribution using hash-chain and subsequent shared-key discovery. We show potential active attacks on sensor networks due to key predistribution which can have severer consequences as compared to attacks described in existing proposals. We also show that as compared to the existing schemes, our scheme is more resilient to these active attacks. Manish Mehta 0003, Dijiang Huang, Lein Harn |
IPCCC | 2 |
| 2005 | Using Delaunay triangulation to construct obstacle detour mobility modelabstractWith the rapid growth in wireless communication technologies, mobility management research is in great demand. Simulation has become an effective method to study the performance of many mobility issues. A realistic mobility model not only reflects mobile user behavior, but also affects correctness of the simulation results. In a wireless environment, obstacles usually exist within the coverage area. We propose a new detour model by using Delaunay triangulation through the incorporation of obstacles. The proposed mobility model can create detour paths as long as there exist gaps among obstacles. Comparative studies show that our proposed model can construct more detour paths than the Voronoi model. Dijiang Huang |
WCNC | 1 |
| 2004 | A key-chain-based keying scheme for many-to-many secure group communicationabstractWe propose a novel secure group keying scheme using hash chain for many-to-many secure group communication. This scheme requires a key predistribution center to generate multiple hash chains and allocates exactly one hash value from each chain to a group member. A group member can use its allocated hash values (secrets) to generate group and subgroup keys. Key distribution can be offline or online via the key distribution protocol. Once keys are distributed, this scheme enables a group member to communicate with any possible subgroups without the help of the key distribution center, and without having to leave the overall group, thus avoiding any setup delay. Our scheme is suitable for applications where the population of a system is stable, group size is moderate, subgroup formation is frequent, and the application is delay sensitive. Through analysis, we present effectiveness of our approach. Dijiang Huang, Deep Medhi |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2003 | A double authentication scheme to detect impersonation attack in link state routing protocolsabstractIn this paper, we present an authentication scheme to prevent impersonation attack in link state routing protocol. The existing authentication schemes are either simple to compute but vulnerable to attacks of too robust against attacks but has exponential computation cost. We introduce a double authentication (DA) scheme which provides authentication to the routing information data carried by link state routing packets. In this scheme every router needs to sign the routing data twice with two different keys using a group keying scheme, which is based on one-way hash function. Based on our performance assessment, we found that this scheme is simpler to implement, computationally efficient and provides the degree of robustness desired with less communication overhead but has higher memory requirement. Dijiang Huang, Amit Sinha, Deep Medhi |
ICC | 1 |