VLDB 2026 Research / reviewers in the wild / expert
Carol J. Fung
dblp:43/6355
· DBLP profile ↗
85ranked-venue papers
15as first author
24since 2021 · last 2026
0000-0001-5726-4371ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 42 · 6 first-author · 10 since 2021Security and privacy · 7 · 1 first-author · 2 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Efficient and Secure Smart Parking System With Conditional Preservation of Citizens Privacy for Smart CitiesabstractThe ever-increasing world population and the number of vehicles in use have made it more difficult for drivers to find suitable parking lots in large cities. When public parking is insufficient, private parking space sharing could be a solution to alleviate the problem. In the context of private parking reservation, parking owners and drivers share their parking offers and inquiries that consist of private information, such as identity, parking spot, and desired location. Hence, cyber attacks and data leaks can reveal sensitive information about citizens. Therefore, it could be a major barrier to utilize private parking spots. To address this issue, we propose an efficient, secure, and privacy-preserving smart parking system. We use robust security methods, such as proxy re-encryption and certificateless public-key cryptography, to achieve security. We also employ cutting-edge privacy-enhancing technologies, such as (partially) blind signature and symmetric private information retrieval (SPIR), to preserve citizens’ privacy. Moreover, Shamir’s threshold secret sharing is used to provide conditional privacy. Comprehensive security and privacy analysis using the Random Oracle model and the Scyther tool demonstrates that our design is robust against relevant attacks and effectively protects citizens’ privacy. Ultimately, our performance analysis indicates that the proposed scheme is efficient, lightweight, and feasible. In particular, it achieves an average reduction of approximately 73% in communication overhead. Mohammad Rasool Momeni, Abdollah Jabbari, Carol J. Fung |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2026 | An Efficient, Secure, and Privacy-Preserving Communication Protocol for Drone-Assisted Disaster Management in Smart CitiesabstractDrones (also referred to as unmanned aerial vehicles) have attracted significant attention within smart city ecosystems due to their ability to detect crises promptly and provide real-time support for disaster management. However, the increasing risks of cyber and physical attacks, along with potential private data leaks, present substantial challenges to their deployment in smart city environments. In this paper, we propose a secure communication protocol that leverages a novel group authentication scheme (GAS), tailored for disaster management scenarios in smart cities. The proposed scheme enables both group key agreement among drones and individual session key establishment between each drone and the control center (CC). Hence, our protocol preserves data confidentiality, message integrity, and data privacy, and verifies the authenticity of communicating parties. We employ physically unclonable functions (PUFs) and reverse fuzzy extractors to withstand critical threats, including machine learning (ML)-based modeling attacks and physical attacks. Our protocol also uses lightweight cryptographic primitives, such as hash-based message authentication codes (HMAC) and exclusive-OR (XOR) operations to ensure efficiency. Comprehensive security analysis using the formal proof and the Scyther tool demonstrates that our scheme resists corresponding attacks and protects data privacy. Ultimately, performance analysis results confirm that the proposed protocol is efficient and feasible. Mohammad Rasool Momeni, Abdollah Jabbari, Carol J. Fung |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Exploiting Congestion Control Parameter Manipulation in QUIC for Security ImplicationsabstractQUIC has emerged as a fundamental transport protocol for modern Internet infrastructure, serving as the foundation for HTTP/3. Although QUIC implements congestion control algorithms ($C C A$) to ensure fair network resource allocation, its user-space implementation architecture creates significant security vulnerabilities through accessible parameter manipulation. As transport layers become increasingly programmable, these vulnerabilities represent a broader security challenge for future network infrastructures where applications may deploy custom transport implementations. This paper presents a systematic analysis of selfish behaviors in QUIC through deliberate congestion control parameter (CCPM). Using the aioquic implementation, we experimentally demonstrate how strategic parameter manipulation in both NewReno and CUBIC algorithms provides substantial unfair bandwidth ($\boldsymbol{B} \boldsymbol{W}$) advantages. NewReno exhibits a major vulnerability with Loss Reduction Factor (LRF) and Congestion Avoidance Growth Rate (CAGR) manipulation, while CUBIC demonstrates better resilience, but remains exploitable, with combined LRF ($\beta_{\text {cubic }}$) and Maximum Idle Time (MIT) manipulations. Y A Joarder, Surajit Sinha, Guillaume Doyen, Carol J. Fung |
CNSM | 4 |
| 2025 | DroidScour: an Android Application for IoT Device Data CollectionabstractThe significant increase in the use of Internet of Things (IoT) devices in our society has introduced new challenges related to security and privacy. In this context, identification of IoT devices is necessary for the implementation of protection rules and control measures. Although many solutions have been proposed to identify and classify IoT devices, most rely on outdated or limited datasets, which compromises the effectiveness of these models. Therefore, an up-to-date and well-labeled IoT dataset is necessary for the public research community. This paper presents DroidScour, an Android app developed in Kotlin to collect network traffic, identify, and label IoT devices connected to a smartphone that acts as a hotspot. The IoT data collected by the smartphone is automatically uploaded to the Firebase services online, supporting training and future research. In this way, DroidScour allows the generation of high-quality real datasets of IoT devices, providing a data collection tool for researchers. Brenda S. Schussler, Abdul Fareed Jamali, Weverton Luis da Costa Cordeiro, Carol J. Fung |
CNSM | 4 |
| 2025 | Evaluating Website Data Leaks through Spam Collection on HoneypotsabstractNowadays, people rely heavily on online services in their daily lives such as communication, education, shopping, and entertainment.While online services offer convenience in daily living, users often receive a large number of spams as a result.While previous studies have linked spam receipt primarily to user behavior, this research proposes that spam can serve as a forensic indicator of data leaks by websites.To test our hypothesis, we conducted an experiment to deploy 148 honeypots across 370 websites spanning 12 communities.We monitored and audited the spams received by our honeypots for 47 weeks and analyzed their nature, pattern and origin.The results reveal that some legitimate websites leak user data despite having privacy policy statements.The findings also highlight that some websites automatically enroll users in newsletters or mailing lists without asking consent during the sign-up.This issue arises from conflating privacy policies with spam subscription and third party share agreements.To address these issues we suggest that regulators enforce websites to separate subscription agreement from privacy policy statements, and direct consent for third party share be requested at sign up.Also, websites should evaluate third party chain to ensure user data protection. Oghenerukevwe Elohor Oyinloye, Carol J. Fung |
CODASPY | 2 |
| 2025 | LogMoE: Lightweight Expert Mixture for Cross-System Log Anomaly DetectionabstractRobust anomaly detection in system logs plays a crucial role in maintaining stable and reliable software operations. However, existing methods often struggle to accommodate evolving log formats and distributional shifts across systems, as they heavily rely on large volumes of labeled data, log parsing, and predefined event templates. To address these challenges, we propose LogMoE, a scalable and parsing-free log anomaly detection framework. LogMoE utilizes labeled logs from multiple mature systems to train a set of lightweight expert models, which are integrated via a gating mechanism within a Mixture-of-Experts (MoE) architecture. This design enables LogMoE to generalize effectively to previously unseen target systems. By eliminating the need for log parsing, our approach remains robust against the heterogeneity of log formats and syntactic structures. We conduct extensive evaluations on eight log datasets under varying generalization scenarios: single-system, homogeneous-system, and heterogeneous-system. Experimental results demonstrate that LogMoE consistently achieves robust generalization, particularly under conditions with scarce labeled data in the target system. As such, LogMoE provides a scalable, parsing-free, and generalization-capable solution tailored for complex and continuously evolving software system environments, positioning it as a future-ready approach to log anomaly detection. Jiaxing Qi, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Aibin Wang, Hailong Yang 0002, Depei Qian 0001 |
ASE | 4 |
| 2025 | Joint Optimization of AAV Deployment and Task Scheduling in Multi-AAV-Enabled Mobile Edge Computing SystemsabstractMobile edge computing (MEC) is a highly promising approach for achieving low-latency and high-performance computing services for mobile users. However, traditional MEC systems face challenges in meeting the increasing demands of mobile users due to the limited coverage and flexibility of fixed MEC servers. Integrating unmanned aerial vehicles (UAVs) with MEC has gained significant attention as a promising way to improve the MEC networks’ performances and meet the demands of next-generation networks. UAVs can act as flying edge servers, providing mobile users with flexible and on-demand computing resources. This article shows a new way to use the grey wolf optimizer (JDTS-GWO) algorithm to improve both the placement of UAVs and the scheduling of tasks in a multi-UAV MEC system. The objective is to minimize the overall system’s energy consumption while meeting various constraints, such as UAV coverage, collision avoidance, and task execution requirements. The proposed approach formulates the joint optimization approach, considering the deployment of UAVs, offloading decisions, and resource allocation. An encoding scheme is proposed to represent UAV deployment and task allocation within the JDTS-GWO framework. Simulations demonstrate significant improvements in energy efficiency and task completion compared to existing benchmarks, with up to 35% energy savings and a 98% task completion rate. Sensitivity analysis confirms the approach’s scalability and robustness. The problem is modeled as a mixed-integer nonlinear programming (MINLP) problem, taking into account the consumed energy of mobile nodes, UAVs, and the MEC system. The JDTS-GWO algorithm is adapted to solve the optimization problem efficiently. Muhammad Ejaz, Jinsong Gui, Muhammad Asim 0002, Ahmed A. Abd El-Latif 0001, Mohammed Ahmed El-Affendi, Carol J. Fung, Abdelhamied A. Ateya, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 6 |
| 2025 | Toward a Privacy-Preserving and Secure Smart City: Recent Advances in User-Centric ApplicationsabstractThe ever-increasing global population has caused rapid urbanization in recent decades. Many cities around the world are trying to leverage information and communication technologies to resolve the resulting problems, such as traffic congestion and high energy consumption. This trend is part of the movement towards the development of the so-called smart cities that provide efficient, comfortable, and happy lives to their residents. In this respect, smart cities are indeed promising but have significant underlying complexity due to the number of variety of domains involved, including living, economy, mobility, governance, etc. However, in recent years, numerous cyber attacks and privacy leaks have been major obstacles to the widespread adoption and deployment of smart city applications. In general, smart city domains can be classified into user-centric applications and non-user-centric applications, such as critical infrastructures. This paper examines the key security and privacy challenges associated with recently trending user-centric smart city applications. First, we study the leading technologies along with superior security methods and privacy-enhancing technologies in smart cities. We also provide a critical survey of the security and privacy of novel user-centric smart city applications, namely smart parking, smart charging, and smart home. Our survey provides a detailed review of recent, relevant, and state-of-the-art research works to assist readers in gaining a comprehensive understanding of security and privacy challenges associated with smart cities. Finally, it outlines some research directions worth investigating in the future. The ultimate goal of this survey is to shed light on the pressing security and privacy challenges in smart cities and to provide insights for the development of secure and privacy-preserving smart cities. Mohammad Rasool Momeni, Abdollah Jabbari, Carol J. Fung, Raouf Boutaba |
IEEE Internet Things J. | 3 |
| 2024 | Gloss: Guiding Large Language Models to Answer Questions from System LogsabstractSystem logs contain valuable information and they have emerged as one of the most crucial data sources for system monitoring aimed at enhancing service quality. IT support teams and system administrators are in dire need of an intelligent log-based QA system to help them quickly identify, diagnose, and resolve issues. In this paper, we propose a novel method for constructing log-based question-answering (QA) data using large language models, addressing challenges associated with limited dataset size and diversity in existing log-based QA systems. Our pipeline consists of three steps: generating questions, answering log questions, and refining question-answer pairs. The purpose of the generating questions is to create a diverse set of log-related queries that cover a wide range of potential issues. The second step, answering log questions, aims to extract relevant information from the logs to address the generated questions. This step ensures accurate and context-aware responses. Refining question-answer pairs is intended to improve the overall quality and consistency of the generated log-based QA data. We present a case study using ChatGPT to generate a new dataset, LogQuAD, containing over 28,000 question-answer pairs derived from more than 31,000 raw logs, representing a significant increase compared to existing datasets like LogQA. In our experimental setting, we sample half of the data as the training set and use memory-effect fine-tuning to fine-tune the model, named Gloss. Experimental results show that our method can generate high-quality log-based QA data, leading to improved performance of log-based QA models. Notably, our fine-tuned 7B model outperforms the LLaMA-65B model. This approach can potentially save valuable time for IT support teams and system administrators, enabling proactive problem resolution and optimal system performance. Shaohan Huang, Yi Liu 0013, Jiaxing Qi, Jing Shang 0001, Zhiwen Xiao, Carol J. Fung, Hailong Yang 0002, Zhongzhi Luan, Depei Qian 0001 |
SANER | 6 |
| 2024 | LogSay: An Efficient Comprehension System for Log Numerical ReasoningabstractWith the growth of smart systems and applications, high volume logs are generated that record important data for system maintenance. System developers are usually required to analyze logs to track the status of the system or applications. Therefore, it is essential to find the answers in large-scale logs when they have some questions. In this work, we design a multi-step“Retriever-Reader”question-answering system, namely LogSay, which aims at predicting answers accurately and efficiently. Our system can not only answers simple questions, such as a segment log or span, but also can answer complex logical questions through numerical reasoning. LogSay has two key components:Log RetrieverandLog Reasoner, and we designed five operators to implement them.Log Retrieveraims at retrieving some relevant logs based on a question. Then,Log Reasonerperforms numerical reasoning to infer the final answer. In addition, due to the lack of available question-answering datasets for system logs, we constructed question-answering datasets based on three public log datasets and will make them publicly available. Our evaluation results show that LogSay outperforms the state-of-the-art works in terms of accuracy and efficiency. Jiaxing Qi, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Hailong Yang 0002 |
IEEE Trans. Computers | 4 |
| 2024 | SpikeLog: Log-Based Anomaly Detection via Potential-Assisted Spiking Neuron NetworkabstractThe increasing volume and complexity of log data generated by modern systems have made it challenging to analyze and extract useful insights manually. To address this problem, many machine learning methods have been proposed for log-based anomaly detection. However, most of these methods lack interpretability, and their underlying premises do not always reflect real scenarios. In this paper, we consider a more reasonable premise scenario where a large number of logs are unlabeled, while only a small number of anomalous logs are labeled. Moreover, a small proportion of anomaly contamination may be present. To handle this practical scenario, we propose a novel hybrid potential-assisted framework (SpikeLog) using the membrane potential of spiking neurons. SpikeLog adopts a weakly supervised approach to train an anomaly score model, which effectively utilizes a limited number of labeled anomalies alongside abundant unlabeled logs while ensuring computational efficiency without compromising accuracy. Extensive experiments have demonstrated that SpikeLog outperforms baseline methods in terms of performance, robustness, interpretability, and energy consumption. Jiaxing Qi, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Hailong Yang 0002, Depei Qian 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2024 | RL-Planner: Reinforcement Learning-Enabled Efficient Path Planning in Multi-UAV MEC SystemsabstractMobile edge computing (MEC), located at the networks edge, enhances distributed computing. However, its fixed position presents limitations during emergencies. Integrating unmanned aerial vehicles (UAVs) into MEC systems offers a solution but introduces challenges in managing UAV collaboration. This paper proposes a Reinforcement Deep Q-Learning based multi-UAV MEC framework to optimize quality of service (QoS) and route planning. The proposed framework addresses these challenges by modeling user demand and using multi-factor optimization considering user demand, risk, and distance. A Markov Decision Process (MDP) models user demand for higher QoS. The reinforcement learning reward matrix incorporates terminal user demand, risk, and distance for efficient energy use and resource allocation. Simulations demonstrate the effectiveness of our proposed method, offering valuable insights for future research in this domain. Muhammad Ejaz, Jinsong Gui, Muhammad Asim 0002, Mohammed Ahmed El-Affendi, Carol J. Fung, Ahmed A. Abd El-Latif 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | Exploring QUIC Security and Privacy: A Comprehensive Survey on QUIC Security and Privacy Vulnerabilities, Threats, Attacks, and Future Research DirectionsabstractQUIC is a modern transport protocol aiming to improve Web connection performance and security. It is the transport layer for HTTP/3. QUIC offers numerous advantages over traditional transport layer protocols, such as TCP and UDP, including reduced latency, improved congestion control, connection migration and encryption by default. However, these benefits introduce new security and privacy challenges that need to be addressed, as cyber attackers can exploit weaknesses in the protocol. QUIC’s security and privacy issues have been largely unexplored, as existing research on QUIC primarily focuses on performance upgrades. This survey paper addresses the knowledge gap in QUIC’s security and privacy challenges while proposing directions for future research to enhance its security and privacy. Our comprehensive analysis covers QUIC’s history, architecture, core mechanisms (such as cryptographic design and handshaking process), security model, and threat landscape. We examine QUIC’s significant vulnerabilities, critical security and privacy attacks, emerging threats, advanced security and privacy challenges, and mitigation strategies. Furthermore, we outline future research directions to improve QUIC’s security and privacy. By exploring the protocol’s security and privacy implications, this paper informs decision-making processes and enhances online safety for users and professionals. Our research identifies key risks, vulnerabilities, threats, and attacks targeting QUIC, providing actionable insights to strengthen the protocol. Through this comprehensive analysis, we contribute to developing and deploying a faster, more secure next-generation Internet infrastructure. We hope this investigation serves as a foundation for future Internet security and privacy innovations, ensuring robust protection for modern digital communications. Y A Joarder, Carol J. Fung |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | An Empirical Approach to Evaluate the Resilience of QUIC Protocol Against Handshake Flood AttacksabstractQUIC is a new transport protocol aiming to enhance web connection performance and security. It was gaining popularity quickly in recent years and has been adopted by a number of prominent tech companies, including Facebook, Amazon, and Google. However, the resilience of QUIC Protocol against various cyber attacks has not been fully tested yet. In this paper, we investigate the resilience of QUIC Protocol against handshake flood attacks. We conducted comprehensive experiments to evaluate the resource consumptions of both the attacker and the target during incomplete handshake attacks, including CPU, memory, and bandwidth. The DDoS amplification factor was measured and analyzed based on the results. We compared the results against TCP Syn Cookies under Syn flood attacks. We show that the QUIC Protocol design has a much larger DDoS amplification factor compared to the TCP Syn Cookies, which means QUIC is more vulnerable to handshake DDoS attacks. Also, the CPU resource of QUIC servers is most likely the bottleneck during the handshake flood attacks. To the best of our knowledge, this is the first study to thoroughly investigate resilience of QUIC to handshake DDoS attacks. Benjamin Teyssier, Y A Joarder, Carol J. Fung |
CNSM | 3 |
| 2023 | A Study on the Conspiracy Theory Propagation Network on TwitterabstractIn recent years, conspiracy theories are getting popular on social media. Due to the nature of the information, conspiracy theories can attract a large number of loyal followers and spread misinformation among them. However, study social media conspiracy theory networks in large scale is a challenging problem. In this work, we investigate conspiracy theories on Twitter starting from a small set of seed posts and propose a novel scoring algorithm to automatically search for likely conspiracy theory posts based on their connectives. Our evaluation results demonstrate that our algorithm can effectively find other conspiracy theory posts. We also discovered new conspiracy categories through the common hashtags shared among the likely conspiracy theory posts. Our research does not only provide an overview on the current popular conspiracy theories spread on Twitter, it also provides an automatic tool to pull conspiracy theory posts and followers in a large scale. Kshitij Kokkera, Aileen Chen, Chythra Malapati, Alex Demchenko, Carol J. Fung |
NOMS | 5 |
| 2023 | Improving Log-Based Anomaly Detection by Pre-Training Hierarchical TransformersabstractPre-trained models, such as BERT, have resulted in significant pre-trained models, such as BERT, have resulted in significant improvements in many natural language processing (NLP) applications. However, due to differences in word distribution and domain data distribution, applying NLP advancements to log analysis directly faces some performance challenges. This paper studies how to adapt the recently introduced pre-trained language model BERT for log analysis. In this work, we propose a pre-trained log representation model with hierarchical bidirectional encoder transformers (namely, HilBERT). Unlike previous work, which used raw text as pre-training data, we parse logs into templates before using the log templates to pre-train HilBERT. We also design a hierarchical transformers model to capture log template sequence-level information. We use log-based anomaly detection for downstream tasks and fine-tune our model with different log data. Our experiments demonstrate that HilBERT outperforms other baseline techniques on unstable log data. While BERT obtains performance comparable to that of previous state-of-the-art models, HilBERT can significantly address the problem of log instability and achieve accurate and robust results. Shaohan Huang, Yi Liu 0013, Carol J. Fung, Hailong Yang 0002, Zhongzhi Luan |
IEEE Trans. Computers | 3 |
| 2023 | LogEncoder: Log-Based Contrastive Representation Learning for Anomaly DetectionabstractIn recent years, cloud computing centers have grown rapidly in size. Analyzing system logs is an important way for the quality of service monitoring. However, systems produce massive amounts of logs, and it is impractical to analyze them manually. Automatic and accurate log analysis to detect abnormal events in systems has become extremely important. However, due to the nature of the log analysis problem, such as discrete property, class imbalance, and quality of log, log-based anomaly detection remains a difficult problem. To address these challenges, we propose LogEncoder, a framework of log sequence encoding for semi-supervised anomaly detection. LogEncoder utilizes a pre-trained model to obtain a semantic vector for each log event. To separate normal and abnormal log event sequences and preserve their contextual information, we integrate one-class and contrastive learning objectives training into the representation model. Finally, we propose two methods, one for offline and one for online, to detect system anomalies. Compared to six state-of-the-art baselines on three benchmark datasets, LogEncoder outperforms five unsupervised and semi-supervised methods, and the performance is comparable to the supervised method LogRobust. Jiaxing Qi, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Hailong Yang 0002, Hanlu Li, Danfeng Zhu, Depei Qian 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | Privacy Guarantees of BLE Contact Tracing for COVID-19 and Beyond: A Case Study on COVIDWISEabstractGoogle and Apple jointly introduced a digital contact tracing technology and an API called "exposure notification,'' to help health organizations and governments with contact tracing. The technology and its interplay with security and privacy constraints require investigation. In this study, we examine and analyze the security, privacy, and reliability of the technology with actual and typical scenarios (and expected typical adversary in mind), and quite realistic use cases. We do it in the context of Virginia's COVIDWISE app. This experimental analysis validates the properties of the system under the above conditions, a result that seems crucial for the peace of mind of the exposure notification technology adopting authorities, and may also help with the system's transparency and overall user trust. Salman Ahmed 0001, Ya Xiao 0002, Taejoong Chung, Carol J. Fung, Moti Yung, Danfeng Yao |
AsiaCCS | 4 |
| 2022 | Black-box Attacks to Log-based Anomaly DetectionabstractAnomaly detection is the key to Quality of Service (QoS) in many modern systems. Logs, which record the runtime information of system, are widely used for anomaly detection. The security of the log-based anomaly detection has not been well investigated. In this paper, we conduct an empirical study on black-box attacks on log-based anomaly detection. We investigate eight different methods on log attacking and compare their performance on various log parsing methods and log anomaly detection models. We propose a method to evaluate the imperceptibility of log attacking methods. In our experiments, we evaluate the performance on the attack methods on two real log datasets. The results of our experiments show that LogBug outperforms the others in almost all situations. We also compare the imperceptibility of various attack methods and find a trade-off between performance and imperceptibility, where better attack performance means worse imperceptibility. To the best of our knowledge, this is the first work to investigate and compare the attack models on log-based anomaly detection. Shaohan Huang, Yi Liu 0013, Carol J. Fung, Hailong Yang 0002, Zhongzhi Luan |
CNSM | 3 |
| 2022 | A Game-Theoretic Model for DDoS Mitigation Strategies with Cloud ServicesabstractAs DDoS (Distributed Denial of Service) attacks constantly evolve and bombard businesses and organizations from time to time, DDoS mitigation cloud service is a popular solution to defend against DDoS attacks. Decision makers can select which services to deploy given the associated risk and the deployment cost. In this work, we establish a game-theoretic model to simulate the decision making of attackers and defenders under the context of DDoS attacks. We simulate the attacker/defender game under different scenarios and demonstrate that the efficacy of using external services is impacted by several factors including the resources of the organization, the potential damage and the attacker cost/reward. We find that under different scenarios, the Nash Equilibrium may vary drastically from no attack at all to definite attack. Our study can provide useful insights to decision makers and stakeholders on their DDoS defense strategy planning. To the best of our knowledge, this is the first game model to investigate the DDoS attack/defense strategy involving third-party services. Maher Al Islam, Carol J. Fung, Ashraf Tantawy, Sherif Abdelwahed |
NOMS | 2 |
| 2022 | Adanomaly: Adaptive Anomaly Detection for System Logs with Adversarial LearningabstractLogs are commonly used to record the running status of application service systems. Log-based anomaly detection in the system can significantly improve the quality of system services by avoiding catastrophic failures. However, existing log-based anomaly detection methods do not consider class imbalance, which is a common challenge in anomaly detection. In addition, existing methods require hyperparameters in the detection stage, which negatively impacts the accuracy of detection. In this paper, we propose a novel log-based anomaly detection method named Adanomaly, which uses the BiGAN model to extract features and use the ensemble method to detect anomalies. Experimental demonstrate that Adanomaly can detect system abnormalities efficiently, and outperform recall and accuracy compared to other methods. Jiaxing Qi, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Hailong Yang 0002, Depei Qian 0001 |
NOMS | 5 |
| 2022 | Guest Editors Introduction: Special Section on Recent Advances in Network Security ManagementabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Sandra Scott-Hayward, Qi Li 0002, Fulvio Valenza, Cristian Hesselman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | REVAL: Recommend Which Variables to Log With Pretrained Model and Graph Neural NetworkabstractVariable logging plays a vital role in software service management. Developers usually print a set of selected variables in logs to record software system status. Due to the lack of strict logging instructions and domain-specific knowledge, it is challenging for developers to decide which variables to log. Therefore, a technology that enables developers to log high- quality log variables is desirable. There are two reasons that make such a technology feasible. First, there exists semantic relevance between logged variables and other code statements. Second, the structural relationship between variables helps technology learn more information. In this paper, we propose a novel method to recommend variables to log — given a code snippet that needs to be followed by a logging statement, our method will tag every token in this code snippet to indicate whether it should be logged. Our method utilizes a pre-trained model to encode semantic information and a graph neural network to encode graph structure information. Given a code snippet without logging statements, our method first extracts graph structure information by graph neural network, then fuses the graph structure information with semantic information extracted by the pre-trained model to recommend logging variables. We use nine open-source projects’ java files to evaluate our method. The experimental results demonstrate that our method outperforms other baseline methods in terms of Hits@1, MRR, and MAP, which indicate that the quality of the first recommended variable and all recommended variables is superior to other baseline models. Moreover this benefits from encoding better semantic information and incorporating graph structure information. Shaozhi Dai, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Hailong Yang 0002, Depei Qian 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | Guest Editors' Introduction: Special Issue on Latest Developments for Security Management of Networks and ServicesabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Sandra Scott-Hayward, Qi Li 0002, Jie Zhang 0002, Cristian Hesselman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | An Effective Policy Sharing Mechanism for Smart Home NetworksabstractThe rapid advancement of the Internet of Things has brought new technologies to smart homes and smart hospitals. In a smart home environment, devices may be configured to accomplish certain tasks along with other devices and digital services through user configuration. The configured policy by one user can be further shared to the other users in the network. In this work, we study the policy control application and propose a novel user policy propagation mechanism that allows quality IoT policies to spread to more users than their ineffective counterparts, by integrating user and policy reputation tracking. We evaluated the proposed mechanism using a simulated framework. Experimental results demonstrate that under our designed policy propagation mechanism, high quality policies spread much more widely than low quality policies when the system is configured properly. At the same time, reputable users can have a higher impact and thus their policies can spread further. Carol J. Fung, Bill McCormick |
CNSM | 1 |
| 2020 | Transfer Log-based Anomaly Detection with Pseudo LabelsabstractLog-based anomaly detection is an important task for service management and system maintenance. Although anomaly labels are valuable to learn anomaly detection model, they are difficult to collect due to their rarity. To tackle this problem, existing methods employ domain adaptation algorithms to transfer anomaly detectors from labeled source domain to unlabeled target domain. However, most of those methods focus on key performance indicator anomaly detection. The semantic information in logs plays an important role in log-based anomaly detection. Therefore, adaptation methods need to consider how to transfer the semantic information in logs. In this paper, we propose a simple and effective adaptation method to transfer log-based anomaly detection model with pseudo labels. In our work, we first train a detection model with labeled samples as a pseudo-label annotator. Then we use it to assign pseudo-labels to unlabeled samples and train anomaly detectors as if they are true labels. Both models share the same feature extraction part, which can help model to transfer the semantic information in logs. We evaluated our proposed method on three log datasets. Our experimental results demonstrate that our method has outperformed other baseline methods. Shaohan Huang, Yi Liu 0013, Carol J. Fung, Hailong Yang 0002, Zhongzhi Luan |
CNSM | 3 |
| 2020 | A Privacy-Aware Collaborative DDoS Defence NetworkabstractDistributed denial of service (DDoS) attacks can bring tremendous damage to online services and ISPs. Existing adopted mitigation methods either require the victim to have a sufficient number of resources for traffic filtering or to pay a third party cloud service to filter the traffic. In our previous work we proposed CoFence, a collaborative network that allows member domains to help each other in terms of DDoS traffic handling. In that network, victim servers facing a DDoS attack can redirect excessive connection requests to other helping servers in different domains for filtering. Only filtered traffic will continue to interact with the victim server. However, sending traffic to third party servers brings up the issue of privacy: specifically leaked client source IP addresses. In this work we propose a privacy protection mechanism for defense so that the helping servers will not be able to see the IP address of the client traffic while it has minimum impact to the data filtering function. We implemented the design through a test bed to demonstrated the feasibility of the proposed design. Carol J. Fung, Yadunandan Pillai |
NOMS | 1 |
| 2020 | Paddy: An Event Log Parsing Approach using Dynamic DictionaryabstractLarge enterprise systems often produce a large volume of event logs, and event log parsing is an important log management task. The goal of log parsing is to construct log templates from log messages and convert raw log messages into structured log messages. A log parser can help engineers monitor their systems and detect anomalous behaviors and errors. Most existing log parsing methods focus on offline methods, which require all log data to be available before parsing. In addition, the massive volume of log messages makes the process complex and time-consuming. In this paper, we propose Paddy, an online event log parsing method. Paddy uses a dynamic dictionary structure to build an inverted index, which can search the template candidates efficiently with a high rate of recall. The use of Jaccard similarity and length feature to rank candidates can improve parsing precision. We evaluated our proposed method on 16 real log datasets from various sources including distributed systems, supercomputers, operating systems, mobile systems, and standalone software. Our experimental results demonstrate that Paddy achieves the highest accuracy on eight data sets out of sixteen datasets compared to other baseline methods. We also evaluated the robustness and runtime efficiency of the methods and the experimental results show that our method Paddy achieves superior stableness and is scalable with a large volume of log messages. Shaohan Huang, Yi Liu 0013, Carol J. Fung, Hailong Yang 0002, Zhongzhi Luan |
NOMS | 3 |
| 2020 | Guest Editorial: Special Section on Cybersecurity Techniques for Managing Networked SystemsabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Qi Li 0002, Sandra Scott-Hayward |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Secure Data Encryption Based on Quantum Walks for 5G Internet of Things ScenarioabstractFifth generation (5G) networks are the base communication technology for connecting objects in the Internet of Things (IoT) environment. 5G is being developed to provide extremely large capacity, robust integrity, high bandwidth, and low latency. With the development and innovating new techniques for 5G-IoT, it surely will drive to new enormous security and privacy challenges. Consequently, secure techniques for data transmissions will be needed as the basis for 5G-IoT technology to address these arising challenges. Therefore, various traditional security mechanisms are provided for 5G-IoT technologies and most of them are built on mathematical foundations. With the growth of quantum technologies, traditional cryptographic techniques may be compromised due to their mathematical computation based construction. Quantum walks (QWs) is a universal quantum computational model, which possesses inherent cryptographic features that can be utilized to build efficient cryptographic mechanisms. In this paper, we use the features of quantum walk to construct a new S-box method which plays a significant role in block cipher techniques for 5G-IoT technologies. As an application of the presented S-box mechanism and controlled alternate quantum walks (CAQWs) for 5G-IoT technologies a new robust video encryption mechanism is proposed. As well as to fulfill needs of encryption for varied files in 5G-IoT, we utilize the features of quantum walk to propose a novel encryption strategy for secure transmission of sensitive files in 5G-IoT paradigm. The analyses and results of the proposed cryptosystems show that it has better security properties and efficacy in terms of cryptographic performance. Ahmed A. Abd El-Latif 0001, Bassem Abd-El-Atty, Wojciech Mazurczyk, Carol J. Fung, Salvador Elías Venegas-Andraca |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | HitAnomaly: Hierarchical Transformers for Anomaly Detection in System LogabstractEnterprise systems often produce a large volume of logs to record runtime status and events. Anomaly detection from system logs is crucial for service management and system maintenance. Most existing log-based anomaly detection methods use log event indexes parsed from log data to detect anomalies. Those methods cannot handle unseen log templates and lead to inaccurate anomaly detection. Some recent studies focused on the semantics of log templates but ignored the information of parameter values. Therefore, their approaches failed to address the abnormal logs caused by parameter values. In this article, we propose HitAnomaly, a log-based anomaly detection model utilizing a hierarchical transformer structure to model both log template sequences and parameter values. We designed a log sequence encoder and a parameter value encoder to obtain their representations correspondingly. We then use an attention mechanism as our final classification model. In this way, HitAnomaly is able to capture the semantic information in both log template sequence and parameter values and handle various types of anomalies. We evaluated our proposed method on three log datasets. Our experimental results demonstrate that HitAnomaly has outperformed other existing log-based anomaly detection methods. We also assess the robustness of our proposed model on unstable log data. Shaohan Huang, Yi Liu 0013, Carol J. Fung, Hailong Yang 0002, Zhongzhi Luan |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Fine-Grained Cloud Resource Provisioning for Virtual Network FunctionabstractThe deployment of Virtualized Network Functions is expected to be dynamic and swift when using Network Function Virtualization technology. The dynamic nature of workload from users requires the resource allocation of underlying infrastructure to be flexible to cope with the changes. Existing works investigated elastic NFV solutions by dynamically creating and dismantling Virtual Machine (VM) replicas, while maintaining balanced workload among VMs. However, those solutions are coarse-grained which may cause unnecessary resource over-provisioning as different network functions consume different amount of resources. In this paper, we present ElasticNFV, a dynamic and fine-grained cloud resource provisioning solution for VNF. ElasticNFV takes real-time resource demand of multiple service chains and allocates resources through an elastic provision mechanism. When a scaling conflict occurs, ElasticNFV provides a two-phase minimal migration algorithm to optimize the migration time and embedding cost of VNF instances. We implement ElasticNFV on top of the KVM platform to provide elastic VM for each VNF instance and Open vSwitch to form elastic intra-cloud network with virtual links between VNF instances. Our evaluation results show that ElasticNFV can improve VNF performance significantly, and achieve high resource utilization and fast migration time with low cost. Hui Yu 0004, Jiahai Yang 0001, Carol J. Fung |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2019 | Anomaly Detection Models Based on Context-Aware Sequential Long Short-Term Memory LearningabstractFor a large and complex system that provides services to users, an exception can cause cascading failures if it is not detected and handled in time. System monitoring and anomaly detection can be used to identify system malfunctioning. However, as the size and the complexity of the online service system increases, anomaly detection becomes a challenging problem. This is because the size, complexity and correlation among the data bring great difficulties to anomaly detection process. To address the above challenges, we propose three context-aware sequential Long Short-Term Memory (LSTM) learning models for multi-dimensional anomaly detection, namely, LastLSTM model, AvgLSTM model and CirclLSTM model. In particular, the CirclLSTM model is a period-related LSTM model that can integrate cyclical system historical information into anomaly learning. We evaluated our methods based on three real-world datasets. Our experimental results show that our method can achieve a higher accuracy than other baseline methods such as the Gaussian Naive Bayes (GaussianNB) model, k-nearest neighbors (KNN) algorithm and Logistic Regression (LR) model. Zhongzhi Luan, Carol J. Fung, Da Ye, Depei Qian 0001 |
GLOBECOM | 3 |
| 2019 | Distributed Orchestration in Cloud Data Centers
Bill McCormick, Hassan Halabian, Carol J. Fung |
IM | 3 |
| 2019 | Demo: DroidNet - An Android Permission Control Recommendation System Based on Crowdsourcing
Pulkit Rustgi, Carol J. Fung |
IM | 2 |
| 2019 | A Risk-defined Trust Transitivity Model for Group Decisions in Social Networks
Carol J. Fung |
IM | 2 |
| 2019 | A Requirement-Oriented Design of NFV Topology by Formal SynthesisabstractComputer networks today heavily depend on expensive and proprietary hardware deployed at fixed locations. Network functions virtualization (NFV), one of the fastest emerging topics in networking, reduces the limitations of these vendor-specific hardware with respect to the flexibility of network architecture and elasticity in handling varying traffic patterns. Many defense mechanisms against cyberattacks, as well as quality enhancing techniques have been proposed by leveraging the capabilities of the NFV architecture. NFV allows a flexible and dynamic implementation of virtual network functions in virtual machines running on commercial-off-the-shelf (COTS) servers. These quality enhancing network functions often work as a filter to distinguish between a legitimate packet and an attack packet and can be deployed dynamically to balance the variable attack load. However, allocating resources to these virtual machines is an NP-hard problem. In this paper, we propose a solution to this problem and determine the number and placement of the virtual machines (VMs) hosted on COTS servers. We design and implement two separate automated frameworks for defense and quality maintenance that model the resource specifications, incoming packet processing requirements, and network bandwidth constraints. It uses satisfiability modulo theories (SMT) for modeling this synthesis problem and provides a satisfiable solution. A. H. M. Jakaria, Mohammad Ashiqur Rahman, Carol J. Fung |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | Outlier Detection for Distributed Services using Multi-Frequency Patterns
Zhongzhi Luan, Carol J. Fung, Guang Wei, Depei Qian 0001 |
CNSM | 3 |
| 2018 | Elastic Network Service Chain with Fine-Grained Vertical ScalingabstractBy moving network functions from dedicated hardware to software, Network Function Virtualization (NFV) is expected to bring the advantages of cloud computing to network management. Frequent workload changes require the underlying infrastructure to be dynamic and agile to cope with the changes. Some existing studies have investigated elastic virtual machine (VM) positioning solutions by dynamically creating and destroying VM replicas, while maintaining balanced workload among VMs. However, those solutions are coarse-grained which may cause unnecessary resource over-provisioning and low resource utilization. In this paper, we propose ElasticNFV, a dynamic solution that achieves fine-grained cloud resource provisioning for Virtual Network Functions (VNFs). ElasticNFV analyzes realtime resource demand of multiple service chains and allocates resource through an elastic provision mechanism. When a scaling conflict occurs, ElasticNFV provides a Two-Phase Minimal Migration (TPMM) algorithm to optimize migration time and embedding cost of VNFs based on prediction. We implemented ElasticNFV on top of a KVM virtualization platform and Open vSwitch. Through simulation and testbed evaluation, we show that ElasticNFV can achieve high resource utilization and short migration time with low cost. Hui Yu 0004, Jiahai Yang 0001, Carol J. Fung |
GLOBECOM | 3 |
| 2018 | ENSC: Multi-Resource Hybrid Scaling for Elastic Network Service Chain in CloudsabstractSoftware-based network service chains in Network Function Virtualization (NFV) need to be dynamically allocated and scaled on hardware resources. This is because the resource demand of virtual network functions (VNFs) typically varies as a results of network flow volume. NFV elastic solutions by coarse-grained horizontal scaling or fine-grained vertical scaling have been investigated in recent years. However, none of the existing solutions can achieve both efficiency and scalability. To address this challenge, we propose elastic network service chain (ENSC), which utilizes a fine-grained hybrid scaling method to achieve both NFV efficiency and scalability. We systematically compare horizontal scaling with vertical scaling from six aspects and determine the priority within hybrid scaling. We formulate the resource allocation problem in the cloud datacenter as an integer linear programming (ILP) model and develop a heuristic algorithm called Rubik. Our evaluation results show that ENSC achieves higher acceptance ratios and resource utilization than horizontal scaling and vertical scaling methods. Hui Yu 0004, Jiahai Yang 0001, Carol J. Fung, Raouf Boutaba |
ICPADS | 3 |
| 2018 | HoneyV: A virtualized honeynet system based on network softwarizationabstractIntrusion detection in modern enterprise networks faces challenges due to the increasing large volume of data and insufficient training data for anomaly detections. In this work, we propose a novel network topology for improved intrusion detection through multi-phase data monitoring system. Rather than the all-or-nothing approach to terminate all sessions identified as suspicious, the topology route traffic to different servers replicas with different monitoring intensity level based on their likelihood of attacks. This topology leverages recent advances in software-defined networking (SDN) to dynamically route such sessions into risk-appropriate computing environments. These environments offer enhanced training opportunities intrusion detection systems (IDSes) by exposing data streams that would not have been observable had the session merely been terminated at the first sign of maliciousness. They also afford defenders finer- grained risk management by supporting a continuum of endpoint environments, ranging from fully trusted, to semi-trusted, to fully untrusted, for example. Bahman Rashidi, Carol J. Fung, Kevin W. Hamlen, Andrzej Kamisinski |
NOMS | 2 |
| 2018 | A scalable and flexible DDoS mitigation system using network function virtualizationabstractDistributed Denial of Service (DDoS) attacks remain one of the top threats to enterprise networks and ISPs nowadays. It can cause tremendous damage by bringing down online websites or services. Existing DDoS defense solutions either brings high cost such as upgrading existing firewall or IPS, or bring excessive traffic delay by using third-party cloud-based DDoS filtering services. In this work, we propose a DDoS defense framework that utilizes Network Function Virtualization (NFV) architecture to provide low cost and highly flexible solutions for enterprises. In particular, the system uses virtual network agents to perform attack traffic filtering before they are forwarded to the target server. Agents are created on demand to verify the authenticity of the source of packets, and drop spoofed packets in order protect the target server. Furthermore, we design a scalable and flexible dispatcher to forward packets to corresponding agents for processing. A bucket-based forwarding mechanism is used to improve the scalability of the dispatcher through batching forwarding. The dispatcher can also adapt to agent addition and removal. Our simulation results demonstrate that the dispatcher can effectively serve a large volume of traffic with low dropping rate. The system can successfully mitigate SYN flood attack by introducing minimal performance degradation to legitimate traffic. Bahman Rashidi, Carol J. Fung, Mohammad Ashiqur Rahman |
NOMS | 2 |
| 2018 | Android User Privacy Preserving Through CrowdsourcingabstractIn current Android architecture, users have to decide whether an app is safe to use or not. Expert users can make savvy decisions to avoid unnecessary privacy breach. However, the majority of normal users are not technically capable or do not care to consider privacy implications to make safe decisions. To assist the technically incapable crowd, we propose DroidNet, an Android permission control framework based on crowdsourcing. At its core, DroidNet runs new apps under probation mode without granting their permission requests up-front. It provides recommendations on whether to accept or reject the permission requests based on decisions from peer expert users. To seek expert users, we propose an expertise ranking algorithm using a transitional Bayesian inference model. The recommendation is based on the aggregated expert responses and its confidence level. Our simulation and real user experimental results demonstrate that DroidNet provides accurate recommendations and cover the majority of app requests given a small coverage from a small set of initial experts. Bahman Rashidi, Carol J. Fung, Anh Nguyen 0001, Tam Vu 0001, Elisa Bertino |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Arena: Adaptive real-time update anomaly prediction in cloud systemsabstractIn current cloud systems, their monitoring relies strongly on rule-based and supervised-learning-based detection methods for anomaly detection. These methods require either some knowledge provided by an expert system or monitoring data to be labeled as a training set. In practice, the systems behavior changes over time. It is difficult to adjust the rules or re-train detection model for these methods. In this paper, we present an Adaptive REal-time update uNsupervised Anomaly prediction system (Arena) for cloud systems. Arena uses a clustering technique based on a density spatial clustering algorithm to identify clusters and outliers. We propose two prediction strategies to improve the ability to predict anomaly and a real-time update strategy by adding new monitoring points into Arenas model. To improve the prediction efficiency and reduce the scale of the model, we adopt a pruning method to remove redundant points. The anomaly data used in the experiments was collected from the Yahoo Lab and the component based system of enterprise T. The experimental results show that our proposed methods can achieve high prediction accuracy compared to existing methods. Realtime update strategy can improve the prediction performance. The pruning method can further reduce the scale of the model and demonstrates the prediction efficiency. Shaohan Huang, Carol J. Fung, Shupeng Zhang, Guang Wei, Zhongzhi Luan, Depei Qian 0001 |
CNSM | 2 |
| 2017 | Automated synthesis of NFV topology: A security requirement-oriented designabstractCyber defense today heavily depends on expensive and proprietary hardware deployed at fixed locations. Network functions virtualization (NFV) reduces the limitations of these vendor specific hardware by allowing a flexible and dynamic implementation of virtual network functions in virtual machines running on commercial off-the-shelf servers. These network functions can work as a filter to distinguish between a legitimate packet and an attack packet, and can be deployed dynamically to balance the variable attack load. However, allocating resources to these virtual machines is an NP-hard problem. In this work, we propose a solution to this problem and determine the number and placement of the VMs. We design and implement NFVSynth, an automated framework that models the resource specifications, incoming packet processing requirements, and network bandwidth constraints. It uses satisfiability modulo theories (SMT) for modeling this synthesis problem and provides a satisfiable solution. We also present simulated experiments to demonstrate the scalability and usability of the solution. A. H. M. Jakaria, Mohammad Ashiqur Rahman, Carol J. Fung |
CNSM | 3 |
| 2017 | Android malicious application detection using support vector machine and active learningabstractThe increasing popularity of Android phones and its open app market system have caused the proliferation of malicious Android apps. The increasing sophistication and diversity of the malicious Android apps render the conventional malware detection techniques ineffective, which results in a large number of malicious applications remaining undetected. This calls for more effective techniques for detection and classification of Android malware. Hence, in this paper, we present an Android malicious application detection framework based on the Support Vector Machine (SVM) and Active Learning technologies. In our approach, we extract applications' activities while in execution and map them into a feature set, we then attach timestamps to some features in the set. We show that our novel use of time-dependent behavior tracking can significantly improve the malware detection accuracy. In particular, we build an active learning model using Expected error reduction query strategy to integrate new informative instances of Android malware and retrain the model to be able to do adaptive online learning. We evaluate our model through a set of experiments on the DREBIN benchmark malware dataset. Our evaluation results show that the proposed approach can accurately detect malicious applications and improve updatability against new malware. Bahman Rashidi, Carol J. Fung, Elisa Bertino |
CNSM | 2 |
| 2017 | An efficient fuzzy path selection approach to mitigate selective forwarding attacks in wireless sensor networksabstractWireless Sensor Networks (WSNs) facilitate efficient data gathering requirements occurring in indoor and outdoor environments. A great deal of WSNs operates by sensing the area-of-interest (AOI) and transmitting the obtained data to a sink/(s). The transmitted data is then utilized in decision making processes. In this regard, security of raw and relayed data is both crucial and susceptible to malicious attempts targeting the task of the network which occurs on the wireless transmission medium. A node, when compromised, may deliberately forward data packets selectively. When this happens, nodes adjacent to the malicious nodes cannot identify the malevolent node and mitigate the effects of the attacks. In this study, we introduce a fuzzy path selection approach that efficiently mitigates single selective forwarding attacks in WSNs. Performance of our proposed approach and its evaluations are simulated and obtained. Our experimental results show that our approach is an effective solution to serve as a defense mechanism in terms of the efficiency metrics, such as Half of the Nodes Alive (HNA), Total Remaining Energy (TRE), and Packet Drop Ratio (PDR). S. Alper Sert, Carol J. Fung, Roy George, Adnan Yazici |
FUZZ-IEEE | 2 |
| 2017 | DroidVisor: An Android secure application recommendation systemabstractIn current Android systems, the application recommendation function is an important feature that users can use to find a similar application to replace a targeted one. The current recommendation system provided through Google and the Google Play store presumably recommends applications similar to a target application while accounting for the popularity of each application. However, it does not take the security features of each application or users preferences into consideration when doing so. In this paper, we propose DroidVisor, an Android tool that provides users with fine-grained and customizable application recommendations. Compared to the Google store recommendation function, DroidVisor does not only use the similarity to a preselected target application, but also considers other metrics such as popularity, security, and usability. More specifically, DroidVisor provides an interface for users to configure the weight of each metric and a recommendation algorithm that generates a list of recommended applications based on the combined scores. We evaluate our proposed criteria and the quality of recommendation through use case studies. Finally, we present our findings through a discussion of accuracy as well as possible ways to improve our recommendation results. Pulkit Rustgi, Carol J. Fung, Bahman Rashidi, Bridget T. McInnes |
IM | 2 |
| 2017 | PSOM: Periodic Self-Organizing Maps for unsupervised anomaly detection in periodic time seriesabstractNowadays, systems providing user-oriented services often demonstrate periodic patterns due to the repetitive behaviors from people's daily routines. The monitoring data of such systems are time series of observations that record observed system status at sampled times during each day. The periodic feature and multidimensional character of such monitoring data can be well utilized by anomaly detection algorithms to enhance their detection capability. The data periodicity can be used to provide proactive anomaly prediction capability and the correlation among multidimensional series can provide more accurate results than processing the observations separately. However, existing anomaly detection methods only handle one dimensional series and do not consider the data periodicity. In addition, they often require sufficient labelled data to train the models before they can be used. In this paper, we present an unsupervised anomaly detection algorithm called Periodic Self-Organizing Maps (PSOM) to detect anomalies in periodic time series. PSOMs can be used to detect anomalies in multidimensional periodic series as well as one dimensional periodic series and aperiodic series. Our real data evaluation shows that the PSOM outperforms other supervised methods such as SARIMA and Holt-Winters method. Shupeng Zhang, Carol J. Fung, Shaohan Huang, Zhongzhi Luan, Depei Qian 0001 |
IWQoS | 2 |
| 2017 | Android resource usage risk assessment using hidden Markov model and online learning
Bahman Rashidi, Carol J. Fung, Elisa Bertino |
Comput. Secur. | 2 |
| 2017 | A Collaborative DDoS Defence Framework Using Network Function VirtualizationabstractHigh-profile and often destructive distributed denial of service (DDoS) attacks continue to be one of the top security concerns as the DDoS attacks volumes are increasing constantly. Among them, the SYN Flood attack is the most common type. Conventional DDoS defense solutions may not be preferable, since they demand highly capable hardware resources, which induce high cost and long deployment cycle. The emerging of network function virtualization (NFV) technology introduces new opportunities to decrease the amount of proprietary hardware that is needed to launch and operate network services. In this paper, we propose a DDoS defense mechanism named CoFence, which facilitates a “domain-helps-domain” collaboration network among NFV-based domain networks. CoFence allows domain networks to help each other in handling large volume of DDoS attacks through resource sharing. Specifically, we design a dynamic resource allocation mechanism for domains so that the resource allocation is fair, efficient, and incentive-compatible. The resource sharing mechanism is modeled as a multi-leader-follower Stackelberg game. In this game, all domains have a degree of control to maximize their own utility. The resource supplier domains determine the amount of resource to each requesting peer based on optimizing a reciprocal-based utility function. On the other hand, the resource requesting domains decide the level of demand to send to the resource supplier domains in order to reach sufficient support. Our simulation results demonstrate that the designed resource allocation game is effective, incentive compatible, fair, and reciprocal under its Nash equilibrium. Bahman Rashidi, Carol J. Fung, Elisa Bertino |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | CoFence: A collaborative DDoS defence using network function virtualizationabstractWith the exponential growth of the Internet use, the impact of cyber attacks are growing rapidly. Distributed Denial of Service (DDoS) attacks are the most common but damaging type of cyber attacks. Among them SYN Flood attack is the most common type. Existing DDoS defense strategies are encountering obstacles due to their high cost and low flexibility. The emerging of Network Function Virtualization (NFV) technology introduces new opportunities for low-cost and flexible DDoS defense solutions. In this work, we propose CoFence - a DDoS defense mechanism which facilitates a collaboration framework among NFV-based peer domain networks. CoFence allows domain networks help each others handle large volumes of DDoS attacks through resource sharing. Specifically, we focus on the resource allocation problem in the collaboration framework. Through CoFence a domain network decides the amount of resource to share with other peers based on a reciprocal-based utility function. Our simulation results demonstrate the designed resource allocation system is effective, incentive compatible, fair, and reciprocal. Bahman Rashidi, Carol J. Fung |
CNSM | 2 |
| 2016 | Android Permission Recommendation Using Transitive Bayesian Inference Model
Bahman Rashidi, Carol J. Fung, Anh Nguyen 0001, Tam Vu 0001 |
ESORICS (1) | 2 |
| 2016 | Using recurrent neural networks toward black-box system anomaly predictionabstractComponent based enterprise systems are becoming extremely complex in which the availability and usability are influenced intensively by the system's anomalies. Anomaly prediction is highly important for ensuring a system's stability, which aims at preventing anomaly from occurring through pre-failure warning. However, due to the system's complex nature and the noise from monitoring, capturing pre-failure symptoms is a challenging problem. In this paper, we present a sequential and an averaged recurrent neural networks (RNN) models for distributed systems and component based systems. Specifically, we use cycle representation to capture cyclical system behaviors, which can be used to improve prediction accuracy. The anomaly data used in the experiments is collected from RUBis, IBM System S, and the component based system of enterprise T. The experimental results show that our proposed methods can achieve high prediction accuracy with satisfying lead time. Our recurrent neural networks model also demonstrates time efficiency for monitoring large-scale systems. Shaohan Huang, Carol J. Fung, Polo Pei, Zhongzhi Luan, Depei Qian 0001 |
IWQoS | 2 |
| 2016 | BotTracer: Bot user detection using clustering method in RecDroidabstractRecDroid is a smartphone permission management system which provides users with a fine-grained real-time app permission control and a recommendation system regarding whether to grant the permission or not based on expert users' responses in the network. However, in such a system, malware owners may create multiple bot users to misguide the recommendation system by providing untruthful responses on the malicious app. Threshold-based detection method can detect malicious users which are dishonest on many apps, but it cannot detect malicious users that target on some specific apps. In this work, we present a clustering-based method called BotTracer to finding groups of bot users controlled by the same masters, which can be used to detect bot users with high reputation scores. The key part of the proposed method is to map the users into a graph based on their similarity and apply a clustering algorithm to group users together. We evaluate our method using a set of simulated users' profiles, including malicious users and regular ones. Our experimental results demonstrate high accuracy in terms of detecting malicious users. Finally, we discuss several clustering features and their impact on the clustering results. Bahman Rashidi, Carol J. Fung |
NOMS | 2 |
| 2016 | FACID: A trust-based collaborative decision framework for intrusion detection networks
Carol J. Fung, Quanyan Zhu |
Ad Hoc Networks | 1 |
| 2016 | An incentive-compatible and trust-aware multi-provider path computation element (PCE)
Molka Gharbaoui, Barbara Martini, Carol J. Fung, Francesco Paolucci, Alessio Giorgetti, Piero Castoldi |
Comput. Networks | 3 |
| 2016 | Android fine-grained permission control system with real-time expert recommendations
Bahman Rashidi, Carol J. Fung, Tam Vu 0001 |
Pervasive Mob. Comput. | 2 |
| 2015 | Improving Sybil Detection via Graph Pruning and Regularization Techniques
Jie Zhang 0002, Carol J. Fung, Chang Xu 0003 |
ACML | 3 |
| 2015 | VGuard: A distributed denial of service attack mitigation method using network function virtualizationabstractDistributed denial of service (DDoS) attacks have caused tremendous damage to ISPs and online services. They can be divided into attacks using spoofed IPs and attacks using real IPs (botnet). Among them the attacks from real IPs are much harder to mitigate since the attack traffic can be fabricated to be similar to legitimate traffic. The corresponding DDoS defence strategies proposed in past few years have not been proven to be highly effective due to the limitation of participating devices. However, the emergence of the next generation networking technologies such a network function virtualization (NFV) provide a new opportunity for researchers to design DDoS mitigation solutions. In this paper we propose VGuard, a dynamic traffic engineering solution based on prioritization, which is implemented on a DDoS virtual network function (VNF). The flows from the external zone are directed to different tunnels based on their priority levels. This way trusted legitimate flows are served with guaranteed quality of service, while attack flows and suspicious flows compete for resources with each other. We propose two methods for flow direction: the static method and the dynamic method. We evaluated the performance of both methods through simulation. Our results show that both methods can effectively provide satisfying service to trusted flows under DDoS attacks, and both methods have their pros and cons under different situations. Carol J. Fung, Bill McCormick |
CNSM | 1 |
| 2015 | FlowRanger: A request prioritizing algorithm for controller DoS attacks in Software Defined NetworksabstractSoftware Defined Networking (SDN) introduces a new communication network management paradigm and has gained much attention from academia and industry. However, the centralized nature of SDN is a potential vulnerability to the system since attackers may launch denial of services (DoS) attacks against the controller. Existing solutions limit requests rate to the controller by dropping overflowed requests, but they also drop legitimate requests to the controller. To address this problem, we propose FlowRanger, a buffer prioritizing solution for controllers to handle routing requests based on their likelihood to be attacking requests, which derives the trust values of the requesting sources. Based on their trust values, FlowRanger classifies routing requests into multiple buffer queues with different priorities. Thus, attacking requests are served with a lower priority than regular requests. Our simulation results demonstrates that FlowRanger can significantly enhance the request serving rate of regular users under DoS attacks against the controller. To the best of our knowledge, our work is the first solution to battle against controller DoS attacks on the controller side. Carol J. Fung |
ICC | 2 |
| 2015 | Enhancing Twitter spam accounts discovery using cross-account pattern miningabstractTwitter generates the majority of its revenue from advertising. Third parties usually pay to have their products advertised on Twitter through tweets, accounts and trends. However, spammers can use Sybil accounts (fake accounts) to advertise and avoid paying for it. Sybil accounts are highly active on Twitter performing advertising campaigns to serve their clients. They aggressively try to reach a large audience to maximize their influence. These accounts have similar behavior if controlled by the same master. Most of their spam tweets include a shortened URL to trick users into clicking on it. Also, since they share resources with each other, they tend to tweet similar trending topics to attract a larger audience. However, some Sybil accounts do not spam aggressively to avoid being detected, rendering it difficult for traditional spam detectors to be effective in detecting Sybil accounts with low spamming activities. In this paper, we investigate additional criteria - spam patterns, to measure the similarity across accounts on Twitter. We propose an algorithm to define the correlation among accounts by investigating their tweeting patterns and content. Our real data evaluation reveals that, given known some initially labelled spam tweets, this approach can detect additional spam tweets and spam accounts that are correlated to the initially labelled spam tweets, which are not detected by traditional spam detection approaches otherwise. Ioana-Alexandra Bara, Carol J. Fung, Thang N. Dinh |
IM | 2 |
| 2015 | A game-theoretic model for defending against malicious users in RecDroidabstractRecDroid is a smartphone permission response recommendation system which utilizes the responses from expert users in the network to help inexperienced users. However, in such system, malicious users can mislead the recommendation system by providing untruthful responses. Although detection system can be deployed to detect the malicious users, and exclude them from recommendation system, there are still undetected malicious users that may cause damage to RecDroid. Therefore, relying on environment knowledge to detect the malicious users is not sufficient. In this work, we present a game-theoretic model to analyze the interaction (request/response) between RecDroid users and RecDroid system using a static Bayesian game formulation. In the game RecDroid system chooses the best response strategy to minimize its loss from malicious users. We analyze the game model and explain the Nash equilibrium in a static scenario under different conditions. Through the static game model we discuss the strategy that RecDroid can adopt to disincentivize attackers in the system, so that attackers are discouraged to perform malicious users attack. Finally, we discuss several game parameters and their impact on players' outcome. Bahman Rashidi, Carol J. Fung |
IM | 2 |
| 2015 | Dude, ask the experts!: Android resource access permission recommendation with RecDroidabstractWith the exponential growth of smartphone apps, it is prohibitive for apps market places, such as Google App Store for example, to thoroughly verify if an app is legitimate or malicious. As a result, mobile users are left to decide for themselves whether an app is safe to use. Even worse, recent studies have shown that most apps in markets request to collect data irrelevant to the main functions of the apps, which could cause leaking of private information or inefficient use of mobile resources. To assist users to make a right decision as for whether a permission request should be accepted, we propose RecDroid. RecDroid is a crowdsourcing recommendation framework that collects apps' permission requests and users' permission responses, from which a ranking algorithm is used to evaluate the expertise level of users and a voting algorithm is used to compute an appropriate response to the permission request (accept or reject). To bootstrap the recommendation system, RecDroid relies on a small set of seed expert users that could make reliable recommendations for a small set of application. Our evaluation results show that RecDroid can provide high accuracy and satisfying coverage with careful selection of parameters. The results also show that a small coverage from seed experts is sufficient for RecDroid to cover the majority of the app requests. Bahman Rashidi, Carol J. Fung, Tam Vu 0001 |
IM | 2 |
| 2015 | A methodology for root-cause analysis in component based systemsabstractIn component based enterprise systems, anomaly detectors are commonly deployed on application-level components, but not on lower-level functional components. When anomaly alarms are triggered, system managers are expected to handle them in a timely manner to avoid cascading failures. Excessive large volume of anomaly alarms makes them impractical to handle manually. Most existing root cause analysis methods are based on the assumption that all components are monitored and analysis are performed based on the time correlation of the generated alarms. However, full monitoring coverage may not be practical due to cost and complexity. In this paper, we present RCSF, a root cause analysis method that targets at systems where only application-level components are monitored by anomaly detectors. The method analyzes the components performance log on functional components and seek for most probable fault propagation sequences based on anomaly analysis. We evaluate the RCSF method based on real enterprise system data and compare it with some baseline methods. Experimental results show that our proposed method can effectively anchor the root causes of failures by providing a short list of most probable causes, and the performance is significantly improved compared to the baseline methods. Carol J. Fung, Polo Pei, Shaohan Huang, Zhongzhi Luan, Depei Qian 0001 |
IWQoS | 2 |
| 2015 | Demo: RecDroid: An Android Resource Access Permission Recommendation SystemabstractNowadays, it is prohibitive for apps market places, such as Google App Store, to thoroughly verify an app's resource permission requests to be legitimate or malicious. As a result, mobile users are left to decide for themselves whether an app is safe to use or not. To assist users to make correct decisions as for whether to accept a permission request or not, we propose RecDroid. RecDroid is a crowdsourcing recommendation framework that collects apps' permission requests and users' responses to those requests, from which an experts ranking algorithm is used to seek expert users in the system and a recommendation algorithm is used to suggest appropriate responses to permission requests (accept or reject) based on experts' responses. In this demo, we demonstrate a user case to show how the RecDroid system assists users in permission control. We also explain the major principles and processes behind that support the RecDroid recommendation system. Bahman Rashidi, Carol J. Fung, Gerrit Bond, Steven Jackson, Marcus Pare, Tam Vu 0001 |
MobiHoc | 2 |
| 2014 | Quality of interaction among path computation elements for trust-aware inter-provider cooperationabstractPath Computation Element (PCE) architecture enables effective traffic engineering in multi-domain networks while limiting the exposure of intra-domain information. However, returned path computations might reveal confidential information if artfully correlated by a malicious PCE. Thus, the selection of domains sequence as the result of PCEs cooperation should depend not only on the capability of providing quality paths but also on factors related to expected revenues or perceived risks. In this scenario, cooperation among PCEs could benefit from a trust model by evaluating the quality of the past interactions. This work introduces the concepts of Quality of Interaction and trust ranking and elaborates a trust management model including effectiveness and security objectives regulating the cooperation among PCEs. Specifically, the proposed trust model aims at stimulating effective interactions among PCEs as a result of a common interest in contributing to successful and profitable path computations while avoiding misuse of path computation services. The simulation results show that our trust model is effective in detecting malicious PCE thereby tuning the amount of information returned in the path computation replies. Carol J. Fung, Barbara Martini, Molka Gharbaoui, Francesco Paolucci, Alessio Giorgetti, Piero Castoldi |
ICC | 1 |
| 2014 | RevMatch: An efficient and robust decision model for collaborative malware detectionabstractThis work falls in the area of collaborative malware detection systems which rely on expertise and knowledge from multiple different antivirus software for malware detection. A critical component of such systems is the collaborative malware detection decision process. In this paper, we propose a novel decision model, RevMatch, where collaborative malware decisions are made based on labeled malware detection history from participating antiviruses. We evaluate our proposal using real-world malware data sets and demonstrate that collaborative malware detection techniques can improve the malware detection accuracy compared to using a single albeit the best antivirus. Moreover, we demonstrate how RevMatch outperforms all other existing collaborative decision models in terms of detection accuracy while being computationally efficient and robust against various malicious insider attacks. Carol J. Fung, Disney Yan Lam, Raouf Boutaba |
NOMS | 1 |
| 2013 | Design and management of collaborative intrusion detection networks
Carol J. Fung, Raouf Boutaba |
IM | 1 |
| 2012 | GUIDEX: A Game-Theoretic Incentive-Based Mechanism for Intrusion Detection NetworksabstractTraditional intrusion detection systems (IDSs) work in isolation and can be easily compromised by unknown threats. An intrusion detection network (IDN) is a collaborative IDS network intended to overcome this weakness by allowing IDS peers to share detection knowledge and experience, and hence improve the overall accuracy of intrusion assessment. In this work, we design an IDN system, called GUIDEX, using game-theoretic modeling and trust management for peers to collaborate truthfully and actively. We first describe the system architecture and its individual components, and then establish a game-theoretic framework for the resource management component of GUIDEX. We establish the existence and uniqueness of a Nash equilibrium under which peers can communicate in a reciprocal incentive compatible manner. Based on the duality of the problem, we develop an iterative algorithm that converges geometrically to the equilibrium. Our numerical experiments and discrete event simulation demonstrate the convergence to the Nash equilibrium and the security features of GUIDEX against free riders, dishonest insiders and DoS attacks. Quanyan Zhu, Carol J. Fung, Raouf Boutaba, Tamer Basar |
IEEE J. Sel. Areas Commun. | 2 |
| 2012 | Effective Acquaintance Management based on Bayesian Learning for Distributed Intrusion Detection NetworksabstractAn effective Collaborative Intrusion Detection Network (CIDN) allows distributed Intrusion Detection Systems (IDSes) to collaborate and share their knowledge and opinions about intrusions, to enhance the overall accuracy of intrusion assessment as well as the ability of detecting new classes of intrusions. Toward this goal, we propose a distributed Host-based IDS (HIDS) collaboration system, particularly focusing on acquaintance management where each HIDS selects and maintains a list of collaborators from which they can consult about intrusions. Specifically, each HIDS evaluates both the false positive (FP) rate and false negative (FN) rate of its neighboring HIDSes' opinions about intrusions using Bayesian learning, and aggregates these opinions using a Bayesian decision model. Our dynamic acquaintance management algorithm allows each HIDS to effectively select a set of collaborators. We evaluate our system based on a simulated collaborative HIDS network. The experimental results demonstrate the convergence, stability, robustness, and incentive-compatibility of our system. Carol J. Fung, Jie Zhang 0002, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2011 | Poster: SMURFEN: a rule sharing collaborative intrusion detection network
Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
CCS | 1 |
| 2011 | SMURFEN: A system framework for rule sharing collaborative intrusion detection
Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
CNSM | 1 |
| 2011 | Dirichlet-Based Trust Management for Effective Collaborative Intrusion Detection NetworksabstractThe accuracy of detecting intrusions within a Collaborative Intrusion Detection Network (CIDN) depends on the efficiency of collaboration between peer Intrusion Detection Systems (IDSes) as well as the security itself of the CIDN. In this paper, we propose Dirichlet-based trust management to measure the level of trust among IDSes according to their mutual experience. An acquaintance management algorithm is also proposed to allow each IDS to manage its acquaintances according to their trustworthiness. Our approach achieves strong scalability properties and is robust against common insider threats, resulting in an effective CIDN. We evaluate our approach based on a simulated CIDN, demonstrating its improved robustness, efficiency and scalability for collaborative intrusion detection in comparison with other existing models. Carol J. Fung, Jie Zhang 0002, Issam Aib, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2010 | Effective acquaintance management for Collaborative Intrusion Detection NetworksabstractAn effective Collaborative Intrusion Detection Network (CIDN) allows distributed Intrusion Detection Systems (IDSes) to collaborate and share their knowledge and opinions about intrusions, to enhance the overall accuracy of intrusion assessment as well as the ability of detecting new classes of intrusions. Towards this goal, we propose a distributed Host-based IDS (HIDS) collaboration system, particularly focusing on acquaintance management where each HIDS selects and maintains a list of collaborators from which they can consult about intrusions. More specifically, each HIDS evaluates both the false positive (FP) rate and false negative (FN) rate of its neighboring HIDSes' opinions about intrusions using Bayesian learning, and aggregates their opinions about intrusions using a Bayesian decision model. Our dynamic acquaintance management algorithm allows each HIDS to effectively select a set of collaborators. We evaluate our system based on a simulated collaborative HIDS network. The experimental results demonstrate the convergence, stability and incentive of our system. Carol J. Fung, Jie Zhang 0002, Raouf Boutaba |
CNSM | 1 |
| 2010 | A Distributed Sequential Algorithm for Collaborative Intrusion Detection NetworksabstractCollaborative intrusion detection networks are often used to gain better detection accuracy and cost efficiency as compared to a single host-based intrusion detection system (IDS). Through cooperation, it is possible for a local IDS to detect new attacks that may be known to other experienced acquaintances. In this paper, we present a sequential hypothesis testing method for feedback aggregation for each individual IDS in the network. Our simulation results corroborate our theoretical results and demonstrate the properties of cost efficiency and accuracy compared to other heuristic methods. The analytical result on the lower-bound of the average number of acquaintances for consultation is essential for the design and configuration of IDSs in a collaborative environment. Quanyan Zhu, Carol J. Fung, Raouf Boutaba, Tamer Basar |
ICC | 2 |
| 2010 | Bayesian decision aggregation in collaborative intrusion detection networksabstractCooperation between intrusion detection systems (IDSs) allow collective information and experience from a network of IDSs to be shared for improving the accuracy of detection. A critical component of a collaborative network is the mechanism of feedback aggregation in which each IDS makes an overall security evaluation based on peer opinions and assessments. In this paper, we propose a collaboration framework for intrusion detection networks (CIDNs) and use a Bayesian approach for feedback aggregation by minimizing the combined costs of missed detection and false alarm. The proposed model is highly scalable, robust, and cost effective. Experimental results demonstrate an improvement in the true positive detection rate and a reduction in the average cost of our mechanism compared to existing models. Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
NOMS | 1 |
| 2009 | Robust and scalable trust management for collaborative intrusion detectionabstractThe accuracy of detecting intrusions within an intrusion detection network (IDN) depends on the efficiency of collaboration between the peer intrusion detection systems (IDSes) as well as the security itself of the IDN against insider threats. In this paper, we study host-based IDNs and introduce a Dirichlet-based model to measure the level of trustworthiness among peer IDSes according to their mutual experience. The model has strong scalability properties and is robust against common insider threats, such as a compromised or malfunctioning peer. We evaluate our system based on a simulated collaborative host-based IDS network. The experimental results demonstrate the improved robustness, efficiency, and scalability of our system in detecting intrusions in comparison with existing models. Carol J. Fung, Jie Zhang 0002, Issam Aib, Raouf Boutaba |
Integrated Network Management | 1 |
| 2008 | Lifetime Estimation of Large IEEE 802.15.4 Compliant Wireless Sensor Networks
Carol J. Fung, Yanni Ellen Liu |
MASCOTS | 1 |
| 2007 | The impact of master-slave bridge access mode on the performance of multi-cluster 802.15.4 network
Jelena V. Misic, Carol J. Fung |
Comput. Networks | 2 |
| 2006 | On Bridge Residence Times in Master-Slave Connected 802.15.4 ClustersabstractIndividual 802.15.4 beacon enabled clusters can be interconnected in a master-slave manner where the bridging function is performed by the cluster coordinator of one of the clusters. The bridge can deliver its data to the sink by using the CSMA-CA access just like an ordinary node, or through dedicated GTS access. We compare the performance of the two mechanisms and investigate the impact of bridge residence time on performance. Distinct regions can be identified in which either of the access mechanisms performs better, but in either case, best performance is obtained when the bridge residence time in the sink cluster is as short as possible. Jelena V. Misic, Carol J. Fung, Vojislav B. Misic |
AINA (2) | 2 |
| 2006 | On Node Population in a Multi-Level 802.15.4 Sensor NetworkabstractWe consider the problem of maintaining the prescribed event sensing reliability while maximizing cluster and network lifetime in a multi-cluster 802.15.4 sensor network. Clusters are connected through bridges which also act as cluster coordinators; both ordinary nodes and bridges resolve contention using the CSMA-CA algorithm. Cluster lifetime is maximized through the use of redundant sensors which are periodically sent to sleep using a simple distributed activity management algorithm. Network lifetime is maximized by equalizing lifetimes of individual clusters through the adjustment of the number of nodes. We model this problem analytically and derive the probability distribution of the network lifetime. We also derive the expression for node count that compensates for the increased load due to contention caused by the bridge. Experiments show that this technique easily equalizes cluster lifetimes. Jelena V. Misic, Carol J. Fung, Vojislav B. Misic |
GLOBECOM | 2 |
| 2006 | Interconnecting 802.15.4 clusters in slotted CSMA-CA modeabstractPerformance of collision-based MAC algorithms such as CSMA-CA, as used in networks compliant with IEEE 802.15.4 standard, rapidly deteriorates with the increase of the number of nodes. A promising remedy to this problem is hierarchical partitioning, in which the parent cluster communicates with its child clusters through bridge nodes. The network sink is the coordinator of the parent cluster, while the bridges act as coordinators for their respective child clusters. In this paper, we investigate the performance of the simplest network with two clusters, both of which operate in beacon enabled, slotted CSMA-CA regime, using discrete event simulation. We examine the impact of different traffic and network parameters and identify the conditions that lead to saturation. We show that non-acknowledged transfers offer much better performance in a wide range of traffic and network parameters. Jelena V. Misic, Carol J. Fung, Vojislav B. Misic |
ICC | 2 |
| 2006 | Network lifetime equalization in interconnected 802.15.4 clustersabstractWe consider the problem of maintaining the prescribed event sensing reliability in a network formed by two 802.15.4 sensor clusters (child and parent). In order to maximize cluster lifetime, both clusters have redundant sensors which are periodically sent to sleep through distributed activity management. The clusters are connected through a bridge which also takes on the role of the coordinator in one of the clusters. In order to maximize the network lifetime, the lifetime of both clusters should be nearly the same, but the increased contention caused by the bridge reduces the lifetime of the parent cluster. We model this problem analytically and derive the probability distribution of the network lifetime. We also derive the expression for node count in the parent cluster that compensates for the interaction with the bridge. The use of this technique ensures that both clusters have nearly the same lifetime, with all the nodes dying within a short time period centered around the mean lifetime. Jelena V. Misic, Carol J. Fung, Vojislav B. Misic |
QSHINE | 2 |
| 2006 | Faster Lanes, Longer Lifetimes: Activity Management in Interconnected 802.15.4 Sensor Clusters
Jelena V. Misic, Vojislav B. Misic, Carol J. Fung, Shairmina Shafi |
Mob. Networks Appl. | 3 |