VLDB 2026 Research / reviewers in the wild / expert
Xinwen Fu
dblp:49/2189
· DBLP profile ↗
167ranked-venue papers
8as first author
48since 2021 · last 2026
0000-0003-2391-7789ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 85 · 1 first-author · 16 since 2021Security and privacy · 36 · 2 first-author · 21 since 2021Systems, architecture and hardware · 27 · 5 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 7 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Detecting Rule Anomalies and Interference for Home Automation
Kai Dong 0001, Jianjie Zhou, Zhen Ling 0001, Ming Yang 0001, Xinwen Fu |
INFOCOM | 7 |
| 2026 | Cease at the Ultimate Goodness: Towards Efficient Website Fingerprinting Defense via Iterative Mutual Information Minimization
Zhen Ling 0001, Guangchi Liu, Shaofeng Li 0001, Junzhou Luo, Xinwen Fu |
NDSS | 6 |
| 2026 | Time will Tell: Large-scale De-anonymization of Hidden I2P Services via Live Behavior Alignment
Hongze Wang, Zhen Ling 0001, Xiangyu Xu 0001, Yumingzhi Pan, Guangchi Liu, Junzhou Luo, Xinwen Fu |
NDSS | 7 |
| 2026 | BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnet
Qiguang Zhang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Christopher Morales, Xinwen Fu |
NDSS | 7 |
| 2026 | Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor Flood
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Shan Wang 0008, Ming Yang 0001, Guangchi Liu, Xinwen Fu |
SP | 8 |
| 2026 | A Tor-Based Anonymous Network Covert ChannelabstractNetwork Covert Channels (NCC) enhance covertness by concealing the existence of information transmission. However, traditional NCCs remain vulnerable to traffic analysis. Once NCC is detected, adversaries can breach anonymity by uncovering users' network identities and even communication relationships. While certain indirect NCCs offer limited anonymity to protect the identity of at most one party and the relationship, this level proves insufficient. This paper proposes ANCC, an innovative Anonymous Network Covert Channel that is the first to achieve comprehensive anonymity for the sender, the receiver and the communication relationship. By leveraging the Tor network's Hidden Service Directories (HSDirs) as intermediate nodes, Tor-based ANCC modulates covert information through the publication and retrieval statuses of hidden services distributed on multiple HSDirs. This mechanism allows ANCC traffic to blend seamlessly into legitimate Tor traffic, ensuring both robust covertness and high-level anonymity. Theoretical analysis demonstrates that even against a powerful adversary compromising fifty intermediate nodes, the detection probability remains below 0.25%, with the risk of identity or relationship exposure staying negligible (under 0.0021% and 0.00002% respectively). Additionally, the multiple HSDirs supporting parallel transmission enhance the channel capacity and error correction encoding strengthens the robustness. Extensive evaluation within the real-world Tor network demonstrates a transmission accuracy exceeding 99.6% and a channel capacity of around 3 Kbps, proving its effectiveness for practical applications. Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Changwei Cao, Shan Wang 0008, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2026 | Toward Secure and Efficient Driver Support for Embedded TEE SystemsabstractTrusted execution environments (TEEs), like TrustZone, are pervasively employed to protect security sensitive programs and data from various attacks issued by untrusted rich execution environments (REEs) while they execute compact TEE operating systems which implement minimum security-critical operations but have poor device driver support. In this paper, we propose a twin driver approach where a pair of TEE and REE drivers is generated and cooperate to enable secure and efficient TEE driver support. To begin with, we propose a driver data flow analysis framework named driver analyzer (DrvAna) to automatically analyze the shared states between the TEE and REE driver where a novel data structure named value-type tree is investigated to facilitate field-sensitive data flow analysis upon the driver state. Furthermore, in order to maintain a minimal trusted computing base, we propose a Linux driver runtime (LDR) inside the TEE, a sandbox environment that confines the TEE driver based on the ARM domain access control features and mediates the driver's interaction with the TEE. We implement a DrvAna prototype based on LLVM as well as an LDR prototype on an NXP IMX6Q SABRE-SD evaluation board, adapt 6 existing Linux drivers into LDR, and evaluate their performance. The experimental results show that the LDR drivers can achieve comparable performance with their Linux counterparts with negligible overheads. Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | Toward Practical Headphones Eavesdropping Leveraging COTS mmWave RadarabstractHeadphones have become ubiquitous in daily work and communication, leading users to assume a sense of privacy and security during confidential conversations while overlooking the potential risk of eavesdropping. In this paper, we present mmEar, an end-to-end eavesdropping system that demonstrates the feasibility of compromising headphones using a commercial off-the-shelf (COTS) mmWave radar. Unlike previous approaches that rely on relatively strong vibrations, mmEar targets extremely faint, low-SNR speech-induced vibrations on headphone surfaces. To address this challenge, we introduce a Faint Vibration Emphasis (FVE) technique that amplifies phase variations on the IQ plane, followed by a deep denoising network for enhanced signal quality. Furthermore, we design a diffusion-based generative model within a pretrain–finetune framework, leveraging large-scale synthetic data to significantly improve generalization and robustness across diverse scenarios. Extensive experiments on multiple headphone and earphone models validate the practicality and effectiveness of the proposed attack, revealing that most tested devices can be compromised to recover intelligible speech. Xiangyu Xu 0001, Hao Kong 0004, Zhen Ling 0001, Jiadi Yu, Junzhou Luo, Xinwen Fu |
IEEE Trans. Mob. Comput. | 8 |
| 2025 | Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeabstractRemote Procedure Call (RPC) services have become a primary gateway for users to access public blockchains. While they offer significant convenience, RPC services also introduce critical privacy challenges that remain insufficiently examined. Existing deanonymization attacks either do not apply to blockchain RPC users or incur costs like transaction fees assuming an active network eavesdropper. In this paper, we propose a novel deanonymization attack that can link an IP address of a RPC user to this user's blockchain pseudonym. Our analysis reveals a temporal correlation between the timestamps of transaction confirmations recorded on the public ledger and those of TCP packets sent by the victim when querying transaction status. We assume a strong passive adversary with access to network infrastructure, capable of monitoring traffic at network border routers or Internet exchange points. By monitoring network traffic and analyzing public ledgers, the attacker can link the IP address of the TCP packet to the pseudonym of the transaction initiator by exploiting the temporal correlation. This deanonymization attack incurs zero transaction fee. We mathematically model and analyze the attack method, perform large-scale measurements of blockchain ledgers, and conduct real-world attacks to validate the attack. Our attack achieves a high success rate of over 95% against normal RPC users on various blockchain networks, including Ethereum, Bitcoin and Solana. Shan Wang 0008, Ming Yang 0001, Yu Liu 0168, Yue Zhang 0025, Shuaiqing Zhang, Zhen Ling 0001, Jiannong Cao 0001, Xinwen Fu |
CCS | 8 |
| 2025 | Enhancing Cybersecurity Education using Scoring Engines: A Practical Approach to Hands-On Learning and FeedbackabstractIn today's digital landscape, the demand for skilled cybersecurity professionals is higher than ever. However, many educational programs primarily focus on theoretical concepts, leaving students with insufficient practical skills. To address this gap, students need actionable feedback on their hands-on labs and assignments. We present an open-source scoring engine that provides iterative, step-by-step feedback, enabling students to solve complex cybersecurity problems progressively. Integrated into existing courses, this engine can enhance labs with detailed, structured feedback, bridging the gap between theoretical knowledge and practical application. A preliminary study with 11 students showed that all participants could complete complex tasks using the feedback provided by the engine, with limited instruction from the authors. Additionally, about 90% of the students reported high satisfaction with the structured feedback. This approach has the potential to transform cybersecurity education, making it more interactive, practical, and aligned with real-world requirements. Christopher Morales, Matthew Harper, Pranathi Rayavaram, Sashank Narain, Xinwen Fu |
SIGCSE (1) | 5 |
| 2025 | Practical Cybersecurity Education: A Course Model Using Experiential Learning TheoryabstractThe increasing sophistication of cybersecurity threats necessitates an educational approach that blends theoretical knowledge with practical experience. Many courses focus primarily on theoretical concepts, leaving students with limited hands-on experience with real-world challenges. This paper introduces a cybersecurity course model that integrates Experiential Learning Theory to provide a comprehensive hands-on learning environment. The course covers important cybersecurity topics, including SSH, VPNs, TLS, MFA, OpenID Connect, OAuth2, web server security, high availability, replication, distributed file systems, and orchestration with Docker and Kubernetes. These topics are explored through a mix of lectures, peer presentations, and weekly hands-on team practices. Over three years, the course has been offered at our large public university with 72 students enrolled, consistently receiving high course ratings between 4.8 and 5.0. This paper discusses the course design, methodology, and outcomes, offering insights for educators to replicate and adapt the model for their own institutions. Sashank Narain, Pranathi Rayavaram, Christopher Morales, Matthew Harper, Maryam Abbasalizadeh, Krishna Vellamchety, Xinwen Fu |
SIGCSE (1) | 7 |
| 2025 | Distributed Private Aggregation in Graph Neural Networks
Huanhuan Jia, Yuanbo Zhao, Kai Dong 0001, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 7 |
| 2025 | TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Yumingzhi Pan, Zhen Ling 0001, Yue Zhang 0025, Hongze Wang, Guangchi Liu, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 7 |
| 2025 | The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading Attacks
Xinhui Shao, Zhen Ling 0001, Yue Zhang 0025, Huaiyu Yan, Yumeng Wei, Zixia Liu, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 9 |
| 2025 | ACL: Account Linking in Online Social Networks With Robust Camera Fingerprint MatchingabstractPseudonyms used in Online social networks (OSNs) post a great challenge to fighting against cyber crimes. To build a strong case, law enforcement may want to link multiple user accounts with pseudonyms to a physical suspect. Images based camera fingerprinting has been used for account linking when a suspect takes pictures and videos with his camera and posts them online. However, image post-processing software may introduce noise into images. This noise is hard to eliminate by conventional strategies, is partly resident in the estimated photo-response non-uniformity (PRNU) fingerprints, and interferes with matching fingerprints. We define this noise as software noise, which pollutes PRNU fingerprints and affects accounts linking in online social networks. In this article, we propose new approaches for camera fingerprint matching given software noise. The key idea is to determine the PRNU hardware noise correlation component with our new test statistic–fingerprinttosoftware noise ratio (FITS). We performed extensive experiments and 10,000+ images taken by 90+ smartphones were used to validate our robust camera fingerprint matching system. The experiment results show FITS outperforms the state-of-the-art approaches for polluted fingerprints. This is the first work studying camera fingerprint matching with the presence of software noise. Xinwen Fu, Zhongjie Ba, Feng Lin 0004, Li Lu 0008, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Using Graph With Interconnection Intervals Embedding to Discover Potential Threats in the NetworkabstractGradually infiltrating through latent malicious connections to form cyberattacks has become a significant threat in cyberspace. Advanced persistent threats (APTs) are such cyberattacks, where intruders maintain a presence on networks to steal secrets. Detecting APTs by comparing user behavior with normal activity is challenging because attackers often mimic legitimate behavior sequences to evade detection. This article detects APTs by modeling the graph with interconnection intervals embedding to weaken attackers’ mimicry, namedCyberProber. We first construct an attack intent graph (AIG) to scale down the original network, while preserving key suspicious paths. Then, we embed the AIG by learning connection representations with interconnection interval features, capturing both structural and temporal dependencies. In this way, we can detect APTs in the small AIG, and further uncover more anomalies in the original network based on the identified compromised nodes in the AIG. Our experiments demonstrate that CyberProber outperforms baselines in APTs detection. Xiaorong Hao, Bo Liu 0004, Xiangguo Sun, Jiuxin Cao, Xinwen Fu |
IEEE Trans. Ind. Informatics | 6 |
| 2025 | Pivot: Panoramic-Image-Based VR User Authentication against Side-Channel AttacksabstractWith metaverse attracting increasing attention from both academic and industry, the application of virtual reality (VR) has extended beyond 3D immersive viewing/gaming to a broader range of areas, such as banking, shopping, tourism, education, and so on, which involves a growing amount of sensitive and private user data into VR systems. However, with current password-based user authentication schemes in mainstream VR devices, studies demonstrate that side-channel attacks can pose a severe threat to VR user privacy. To mitigate the threat, we propose a novel panoramic-image-based VR user authentication system, i.e., Pivot , to defend against such attacks, yet maintain high usability. Specifically, in Pivot , we design an image-random-pivoting-based user interaction mechanism to assist users in quickly and securely selecting memorable points of interest in a panoramic image. Then an image region segmentation algorithm is designed to automatically scatter the points to regions to form the customized graphic password for the user, which could ensure a sufficiently large password space and also reduce the near-region point misclicks. Afterward, the region indexes are used to generate the hashed password for authentication. Both theoretical security analysis and extensive user studies demonstrate that Pivot is secure and user-friendly in practice. Gui Xiao, Zhen Ling 0001, Qunqun Fan, Xiangyu Xu 0001, Wenjia Wu, Ding Ding 0002, Chen Chen 0147, Xinwen Fu |
ACM Trans. Multim. Comput. Commun. Appl. | 8 |
| 2024 | Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingabstractBuilding Automation Systems (BAS) play a pivotal role in modern smart buildings, integrating sensors, controllers, and software to manage crucial functions such as HVAC, lighting, and more. The global smart building market is on the rise, underscoring the importance of securing BAS networks. This paper introduces the Building Automation System Evaluator (BASE), a specialized fuzzer designed to assess the security of BAS networks. BAS networks typically involve a BAS client communicating with a BAS server through BAS protocols (e.g., BACnet, KNX), each presenting unique challenges in BAS network fuzzing. These challenges encompass complex packet structures and sequencing in BAS protocols, closed-source clients with indeterminable code coverage, and unobservable server status with limited throughput. BASE automatically identifies protocol structures, dynamically instruments clients for code coverage analysis, and monitors responses for new coverage areas. Collected timestamps are used to estimate the input scan intervals of servers, optimizing throughput. We evaluated BASE on various BAS servers and clients, uncovering 13 new vulnerabilities. Furthermore, we present three attack case studies, highlighting the real-world security implications of these vulnerabilities in BAS systems, such as delayed fire detection, loss of climate control, and security breaches. We reported our findings to the respective vendors, who acknowledged the implications, and some have subsequently patched their systems based on our reports. Yue Zhang 0025, Zhen Ling 0001, Michael Cash, Qiguang Zhang, Christopher Morales, Qun Zhou 0002, Xinwen Fu |
CCS | 7 |
| 2024 | RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT DevicesabstractDue to the diversity of architectures and peripherals of Internet of Things (IoT) systems, blackbox fuzzing stands out as a prime option for discovering vulnerabilities of IoT devices. Existing blackbox fuzzing tools often rely on companion apps to generate valid fuzzing packets. However, existing methods encounter the challenges of bypassing the cloud server side validation when it comes to fuzz devices that rely on cloud-based communication. Moreover, they tend to concentrate their efforts on Java components within Android companion apps, limiting their effectiveness in assessing non-Java components such as JavaScript-based mini-apps. In this paper, we introduce a novel blackbox fuzzing method, named RIoTFuzzer, designed to remotely uncover vulnerabilities of IoT devices with the assistance of companion apps, particularly those powered by All-in-one Apps with the JavaScript-based mini-apps feature enabled. Our approach utilizes document-based control command extraction, hybrid analysis for mutation point identification and side-channel-guided fuzzing to effectively address the challenges of fuzzing IoT devices remotely. We apply RIoTFuzzer to 27 IoT devices on prominent platforms and discovered 11 vulnerabilities. All of them have been acknowledged by the corresponding vendors. 8 have been confirmed by the vendors and have been assigned 4 CVE IDs. Our experiment results also demonstrate that side-channel-guided fuzzing can significantly enhance the efficiency of fuzzing packets sent to IoT devices, with an average increase of 76.62% and a maximum increase of 362.62%. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Junzhou Luo, Xinwen Fu |
CCS | 7 |
| 2024 | Evaluating the Efficacy of Productivity Tools in Engineering EducationabstractProductivity methodologies and tools are crucial in technology-focused organizations, fostering efficiency and collaboration. Industry practices, such as Scrum and Objectives and Key Results (OKRs), along with tools like Jira and Git, empower individuals and teams. Communication platforms like Zoom, Microsoft Teams, Slack, and Confluence bridge geographical gaps. Despite their significance, a noticeable gap exists in integrating these practices into academic institutions, hindering students' transitions to the professional realm. This research focuses on effectively integrating industry best practices—Scrum, OKRs, Jira, Git, Zoom, Microsoft Teams, Slack, and Confluence—into academic settings to improve students' individual and team performance in the classroom and to elevate their overall readiness for industry. The study presents practical guidelines derived from interviews with industry professionals, establishing parallels between industry and academia. These guidelines encompass supplemental learning, pairing students with experienced individuals, and recommending cost-effective tools like Discord for collaboration. Scrum principles, implemented through Taiga (a free alternative to Jira) and GitHub, along with OKRs, are endorsed for project and task tracking, providing a comprehensive framework for enhanced productivity in academic contexts. An assessment of these guidelines in an intensive cybersecurity course at a large public university reveals positive outcomes. Pairing students and leveraging Discord for communication prove effective. Methodologies like Scrum and OKRs receive positive responses, with Git emerging as a favorite for collaborative work. The role of Taiga in task accountability is acknowledged. Overall, the implementation of our guidelines demonstrates a positive impact on student and team performance, emphasizing the potential for the effective integration of industry-endorsed practices in academic settings. Christopher Morales, Matthew Harper, Pranathi Rayavaram, Manoj Yeddanapudi, Sashank Narain, Xinwen Fu |
EDUCON | 6 |
| 2024 | CORE: Transaction Commit-Controlled Release of Private Data Over BlockchainsabstractIn blockchain applications such as digital goods exchange, private data may be transmitted from a data owner to a recipient through a transfer transaction. However, these blockchain applications often assume the underlying blockchain system is secure and reliable, and thus do not consider transaction failures. We find that a failed transfer transaction may disclose the private data to the recipient, but the data owner may not receive tokens as payments or the ledger may not correctly record the data trail. To handle transaction failures and protect private data, we propose a novel transaction commit-controlled release (CORE) protocol. With CORE, the private data can only be obtained by an intended recipient after the transfer transaction is committed, the data owner receives tokens, and the ledger correctly records the data trail. We perform security analysis of CORE, implement CORE and evaluate its performance over representative public and permissioned blockchains. The results of our extensive experiments show CORE introduces minor overhead in terms of transaction latency and transaction fees. We are the first to identify and address the generic private data disclosure issues in both public and permissioned blockchains. Shan Wang 0008, Ming Yang 0001, Jiannong Cao 0001, Zhen Ling 0001, Qiang Tang 0005, Xinwen Fu |
ICDCS | 6 |
| 2024 | Samba: Detecting SSL/TLS API Misuses in IoT Binary ApplicationsabstractIoT devices are increasingly adopting Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols. However, the misuse of SSL/TLS libraries still threatens the communication. Existing tools for detecting SSL/TLS API misuses primarily rely on source code analysis while IoT applications are usually released as binaries with no source code. This paper presents Samba, a novel tool to automatically detect SSL/TLS API misuses in IoT binaries through static analysis. To overcome the path explosion problem and deal with various SSL/TLS implementations, we introduce a three-level reduction method to construct the SSL/TLS API-centric graph (SAG), which has a much smaller size compared with the conventional inter-procedural control flow graph. We propose a formal expression of API misuse signatures, which is capable of capturing different types of misuse, particularly those in the SSL/TLS connection establishment process. We successfully analyze 115 IoT binaries and find that 94 of them have the vulnerability of insecure certificate verification and 112 support deprecated SSL/TLS protocols. Samba is the first IoT binary analysis system for detecting SSL/TLS API misuses. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Yuan Zhang 0009, Chongqing Lei, Xinwen Fu |
INFOCOM | 7 |
| 2024 | Deanonymizing Ethereum Users behind Third-Party RPC ServicesabstractThird-party RPC services have become the mainstream way for users to access Ethereum. In this paper, we present a novel deanonymization attack that can link an Ethereum address to a real-world identity such as IP address of a user who accesses Ethereum via a third-party RPC service. We find that RPC API calls result in distinguishable sizes of encrypted TCP packets. An attacker can then find when a user sends a transaction to an RPC provider and immediately send a beacon transaction after the user transaction. By exploiting the differences in the distributions of inter-arrival time intervals of normal transactions and two simultaneously initiated transactions, the attacker can identify the victim transaction in the Ethereum network. This enables the attacker to correlate the Ethereum address of the victim transaction’s initiator with the source IP address of TCP packets from a victim user. We model the attack through empirical measurements and conduct extensive real-world experiments to validate the effectiveness of our attack. With three optimization strategies, the correlation accuracy can reach to 98.70% and 96.60% respectively in Ethereum testnet and mainnet. We are the first to study the deanonymization of Ethereum users behind third-party RPC services. Shan Wang 0008, Ming Yang 0001, Wenxuan Dai, Yu Liu 0168, Yue Zhang 0025, Xinwen Fu |
INFOCOM | 6 |
| 2024 | mmEar: Push the Limit of COTS mmWave Eavesdropping on HeadphonesabstractRecent years have witnessed a surge of headphones (including in-ear headphones) usage in works and communications. Because of the privacy-preserve property, people feel comfortable having confidential communication wearing headphones and pay little attention to speech leakage. In this paper, we present an end-to-end eavesdropping system, mmEar, which shows the feasibility of launching an eavesdropping attack on headphones leveraging a commercial mmWave radar. Different from previous works that realize eavesdropping by sensing speech-induced vibrations with reasonable amplitude, mmEar focuses on capturing the extremely faint vibrations with a low signal-to-noise ratio (SNR) on the surface of headphones. Toward this end, we propose a faint vibration emphasis (FVE) method that models and amplifies the mmWave responses to speech-induced vibrations on the In-phase and Quadrature (IQ) plane, followed by a deep denoising network to further improve the SNR. To achieve practical eavesdropping on various headphones and setups, we propose a cGAN model with a pretrain-finetune scheme, boosting the generalization ability and robustness of the attack by generating high-quality synthesis data. We evaluate mmEar with extensive experiments on different headphones and earphones and find that most of them can be compromised by the proposed attack for speech recovery. Xiangyu Xu 0001, Zhen Ling 0001, Li Lu 0008, Junzhou Luo, Xinwen Fu |
INFOCOM | 6 |
| 2024 | LDR: Secure and Efficient Linux Driver Runtime for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Kai Dong 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
NDSS | 10 |
| 2024 | Relation Mining Under Local Differential Privacy
Kai Dong 0001, Chuang Jia, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 7 |
| 2024 | A Friend's Eye is A Good Mirror: Synthesizing MCU Peripheral Models from Peripheral Drivers
Chongqing Lei, Zhen Ling 0001, Yue Zhang 0025, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 6 |
| 2024 | On building automation system securityabstractBuilding Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security. Christopher Morales, Matthew Harper, Michael Cash, Zhen Ling 0001, Qun Zhou 0002, Xinwen Fu |
High Confid. Comput. | 7 |
| 2024 | BBS: A secure and autonomous blockchain-based big-data sharing system
Shan Wang 0008, Ming Yang 0001, Shan Jiang 0005, Fei Chen 0003, Yue Zhang 0025, Xinwen Fu |
J. Syst. Archit. | 6 |
| 2023 | FITS: Matching Camera Fingerprints Subject to Software Noise PollutionabstractPhysically unclonable hardware fingerprints can be used for device authentication. The photo-response non-uniformity (PRNU) is the most reliable hardware fingerprint of digital cameras and can be conveniently extracted from images. However, we find image post-processing software may introduce extra noise into images. Part of this noise remains in the extracted PRNU fingerprints and is hard to be eliminated by traditional approaches, such as denoising filters. We define this noise as software noise, which pollutes PRNU fingerprints and interferes with authenticating a camera armed device. In this paper, we propose novel approaches for fingerprint matching, a critical step in device authentication, in the presence of software noise. We calculate the cross correlation between PRNU fingerprints of different cameras using a test statistic such as the Peak to Correlation Energy (PCE) so as to estimate software noise correlation. During fingerprint matching, we derive the ratio of the test statistic on two PRNU fingerprints of interest over the estimated software noise correlation. We denote this ratio as the fingerprint to software noise ratio (FITS), which allows us to detect the PRNU hardware noise correlation component in the test statistic for fingerprint matching. Extensive experiments over 10,000 images taken by more than 90 smartphones are conducted to validate our approaches, which outperform the state-of-the-art approaches significantly for polluted fingerprints. We are the first to study fingerprint matching with the existence of software noise. Xinwen Fu, Zhongjie Ba, Feng Lin 0004, Li Lu 0008, Kui Ren 0001 |
CCS | 2 |
| 2023 | A Greedy Algorithm-Based Self-Training Pipeline for Expansion of Dental Caries DatasetabstractDental caries, the most prevalent oral disease, poses a significant healthcare challenge. Deep Neural Network (DNN)-based object detection techniques offer promising solutions to improve the efficiency of dental caries diagnosis. It is widely acknowledged that the performance of DNN models heavily relies on the availability of sufficient and accurately labeled data. The collection and annotation of dental X-ray images encounter obstacles due to privacy concerns and the requirement for specialized expertise. Consequently, the limited access to labeled dental image datasets restricts the potential of DNNs in supporting oral and dental healthcare. Self-Training (ST) is a semi-supervised machine leaning approach that addresses this problem to a large extent. It repeats the procedures of training a model on the labeled dataset, and then applying it to generate pseudo labels on the unlabeled dataset, and further using the combined data with the original and pseudo labels to train new models. However, the latent errors of the pseudo labels can arise and even be amplified throughout the ST pipeline, which leads to a significant performance decline for DNN models. In this paper, we propose a Greedy algorithm-based Self-Training (Greedy-ST) pipeline to address this problem. At each iteration, the Greedy-ST selects an optimal confidence threshold to generate predictions as pseudo labels, and uses static fine-tuning (SFT) and dynamic fine-tuning (DFT) to refine them. Experimental results demonstrate that by utilizing the pseudo labels generated by the Greedy-ST pipeline, the selected baseline model achieves improved performance compared to using the pseudo labels generated by the vanilla ST approach. Qilei Chen, Yu Cao 0002, Xinwen Fu, Benyuan Liu |
HealthCom | 7 |
| 2023 | A Deep Learning Framework with Pruning RoI Proposal for Dental Caries Detection in Panoramic X-ray Images
Qilei Chen, Yu Cao 0002, Xinwen Fu, Benyuan Liu |
ICONIP (3) | 7 |
| 2023 | A Comprehensive and Long-term Evaluation of Tor V3 Onion Services
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Xinwen Fu |
INFOCOM | 5 |
| 2023 | Do Not Give a Dog Bread Every Time He Wags His Tail: Stealing Passwords through Content Queries (CONQUER) Attacks
Chongqing Lei, Zhen Ling 0001, Yue Zhang 0025, Kai Dong 0001, Kaizheng Liu, Junzhou Luo, Xinwen Fu |
NDSS | 7 |
| 2022 | fASLR: Function-Based ASLR for Resource-Constrained IoT Systems
Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu |
ESORICS (2) | 6 |
| 2022 | BBS: A Blockchain Big-Data Sharing SystemabstractChain of custody is needed to document the sequence of custody of sensitive big data. In this paper, we design a blockchain big-data sharing system (BBS) based on Hyperledger Fabric. We denote the data stored outside of a ledger for sharing as "off-state" and "big data" (referring to extremely large data) is in this category. In our off-state sharing protocol, a sender registers a file with BBS for sharing. To acquire the file, an authenticated and authorized receiver has to use transactions and interacts with BBS in four phases, including the file transfer request, encrypted file transfer, key retrieval, and file decryption. The corresponding transactions are recorded in the ledger and serve as chain of custody to document the trail of the data. Compared with related work, BBS can perform the four phases autonomously. It utilizes the permissioned blockchain, i.e. Hyperledger Fabric, for access control and can defeat dishonest receivers. We design and implement a prototype of BBS for big file sharing. Extensive experiments were performed to validate its feasibility and performance. Shan Wang 0008, Ming Yang 0001, Tingjian Ge, Yan Luo 0001, Xinwen Fu |
ICC | 5 |
| 2022 | Implication of Animation on Android SecurityabstractWe find that seemingly innocuous animations widely used in Android can pose great threats to user security and privacy. Both entrance and exit animations can be exploited. In our draw-and-destroy overlay attack, a malicious app periodically draws and destroys transparent UI-intercepting overlays, which can be put over victim apps to intercept user inputs stealthily. Although Android is patched to show alerts if there is an overlay over an app, quickly drawing and destroying malicious overlays can exploit the slow-in animation of the notification alert view and suppress the alert. In our draw-and-destroy toast attack, a malicious app periodically creates a new customized toast over a victim app before the previously customized toast disappears. This attack exploits the fade-out animation of the toast so that transition between two successive toasts cannot be observed. The two draw-and-destroy attacks can be building blocks of other attacks. We particularly study the password-stealing attack given its severe consequence, in which the draw-and-destroy toast attack displays a fake keyboard over the original keyboard and the draw-and-destroy overlay attack places transparent overlays over the fake keyboard to intercept user inputs. Extensive real-world experiments are conducted to validate the feasibility and effectiveness of the attacks. We also discuss defense measures mitigating the attacks. We are the first to discover the security implications of animation on Android security. Shan Wang 0008, Zhen Ling 0001, Yue Zhang 0025, Ruizhao Liu, Joshua Kraunelis, Kang Jia, Bryan Pearson, Xinwen Fu |
ICDCS | 8 |
| 2022 | Towards an Efficient Defense against Deep Learning based Website FingerprintingabstractWebsite fingerprinting (WF) attacks allow an attacker to eavesdrop on the encrypted network traffic between a victim and an anonymous communication system so as to infer the real destination websites visited by a victim. Recently, the deep learning (DL) based WF attacks are proposed to extract high level features by DL algorithms to achieve better performance than that of the traditional WF attacks and defeat the existing defense techniques. To mitigate this issue, we propose a-genetic-programming-based variant cover traffic search technique to generate defense strategies for effectively injecting dummy Tor cells into the raw Tor traffic. We randomly perform mutation operations on labeled original traffic traces by injecting dummy Tor cells into the traces to derive variant cover traffic. A high level feature distance based fitness function is designed to improve the mutation rate to discover successful variant traffic traces that can fool the DL-based WF classifiers. Then the dummy Tor cell injection patterns in the successful variant traces are extracted as defense strategies that can be applied to the Tor traffic. Extensive experiments demonstrate that we can introduce 8.1% of bandwidth overhead to significantly decrease the accuracy rate below 0.4% in the realistic open-world setting. Zhen Ling 0001, Gui Xiao, Wenjia Wu, Xiaodan Gu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 6 |
| 2022 | FUME: Fuzzing Message Queuing Telemetry Transport BrokersabstractMessage Queuing Telemetry Transport (MQTT) is a popular communication protocol used to interconnect devices with considerable network restraints, such as those found in Internet of Things (IoT). MQTT directly impacts a large number of devices, but the software security of its server ("broker") implementations is not well studied. In this paper, we design, implement, and evaluate a novel fuzz testing model for MQTT. The fuzzer combines aspects of mutation guided fuzzing and generation guided fuzzing to rigorously exhaust the MQTT protocol and identify vulnerabilities in servers. We introduce Markov chains for mutation guided fuzzing and generation guided fuzzing that model the fuzzing engine according to a finite Bernoulli process. We implement "response feedback", a novel technique which monitors network and console activity to learn which inputs trigger new responses from the broker. In total, we found 7 major vulnerabilities across 9 different MQTT implementations, including 6 zero-day vulnerabilities and 2 CVEs. We show that when fuzzing these popular MQTT targets, our fuzzer compares favorably with other state-of-the-art fuzzing frameworks, such as BooFuzz and AFLNet. Bryan Pearson, Yue Zhang 0025, Cliff C. Zou, Xinwen Fu |
INFOCOM | 4 |
| 2022 | Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryabstractTor is the largest anonymous communication system, providing anonymous communication services to approximately 2.8 million users and 170,000 hidden services per day. The Tor hidden service mechanism can protect a server from exposing its real identity during the communication. However, due to a design flaw of the Tor hidden service mechanism, adversaries can deploy malicious Tor hidden service directories (HSDirs) to covertly collect all onion addresses of hidden services and further probe the hidden services. To mitigate this issue, we design customized honeypot hidden services based on one-to-one and many-to-one HSDir monitoring approaches to luring and identifying the malicious HSDirs conducting the rapid and delayed probing attacks, respectively. By analyzing the probing behaviors and payloads, we investigate a novel semantic-based probing pattern clustering approach to classify the adversaries so as to shed light on the purposes of the malicious HSDirs. Moreover, we perform theoretical analysis of the capability and accuracy of our approaches. Large-scale experiments are conducted in the real-world Tor network by deploying hundreds of thousands of honeypots during a monitoring period of more than three months. Finally, we identify 8 groups of 32 malicious HSDirs, discover 25 probing pattern clusters and reveal 3 major probing purposes. Chunmian Wang, Zhen Ling 0001, Wenjia Wu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 6 |
| 2022 | fASLR: Function-Based ASLR via TrustZone-M and MPU for Resource-Constrained IoT SystemsabstractThe address space layout randomization (ASLR) has been widely deployed on modern operating systems against code reuse attacks (CRAs), such as return-oriented programming (ROP) and jump-oriented programming (JOP). However, porting ASLR to resource-constrained IoT devices is a great challenge due to the limited memory space for randomization. We propose a function-based ASLR scheme (fASLR) for IoT runtime security utilizing the ARM TrustZone-M technology and the memory protection unit (MPU) supported by ARM Cortex-M processors. fASLR loads a function from the flash and randomizes its base address in a randomization region in RAM when the function is being called. We design novel mechanisms on cleaning up finished functions from the RAM and memory addressing to tackle the complexity of function relocation and randomization. Optimizations are applied to effectively reduce overhead introduced by runtime memory management. We also formally prove that user applications will run correctly with fASLR enabled. Compared with the related work, a prominent advantage of fASLR is that fASLR can run an application even if the application code cannot be completely loaded into RAM for execution. We test fASLR with 21 applications. The experimental results show that fASLR achieves a high randomization entropy and incurs a runtime overhead of less than 10%. Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu |
IEEE Internet Things J. | 6 |
| 2022 | On Security of TrustZone-M-Based IoT SystemsabstractInternet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension designed specifically for MCUs, is an emerging hardware security technique fortifying software security of MCU-based IoT devices. This article introduces a comprehensive security framework for IoT devices using TrustZone-M-enabled MCUs, in which device security is protected in five dimensions, i.e., hardware, boot-time software, runtime software, network, and over-the-air (OTA) update. Along developing the framework, we also present the first security analysis of potential runtime software security issues in TrustZone-M-enabled MCUs. In particular, we explore the feasibility of launching stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against nonsecure callable (NSC) functions in the context of TrustZone-M. We validate these attacks using SAM L11, a microchip MCU with TrustZone-M and provide defense mechanisms in the runtime software dimension of the proposed framework. The security framework is implemented with a full-fledged secure and trustworthy air quality monitoring device using SAM L11 as its MCU. Yue Zhang 0025, Clayton White, Brandon Keating, Bryan Pearson, Xinhui Shao, Zhen Ling 0001, Haofei Yu, Cliff C. Zou, Xinwen Fu |
IEEE Internet Things J. | 10 |
| 2022 | Towards Incentive for Electrical Vehicles Demand Response With Location Privacy Guaranteeing in MicrogridsabstractThe rapid and wide adoption of microgrids (MGs) and the increasing popularity of electric vehicles (EVs) have created a unique opportunity for the integration of these technologies. In this article, we address the issue of demand response of EVs during MG outages by leveraging Vehicle-to-Grid (V2G) technology. Particularly, we investigate an auction trading market that allows EVs with surplus energy to act as sellers, and EVs that want to be charged to act as buyers. A novel distributed double auction scheme is proposed to allow each buyer EV to submit multiple bids to seller EVs in different parking lots. Nonetheless, the locations of buyer EVs could be inferred by an adversary through analyzing the valuations, posing serious privacy and security risks. In this regard, a valuation-based attack scheme is investigated to validate the potential privacy risk. To defend against such an attack, we present a location privacy-preserving double auction scheme, in which the MicroGrid Central Controller (MGCC) acts as the auctioneer, solving the social welfare maximization problem of matching buyers to sellers, and the cloud is used to conduct calculations for the auctioneer, protecting the privacy of participants via homomorphic encryption. Theoretical analysis is conducted to validate our auction scheme in satisfying the designed economic and privacy properties (e.g., strategy-proofness and$k$-anonymity). The experimental results show that our auction scheme can not only mitigate the demand response problem in MGs, but also provides good performance with respect to social welfare, satisfaction ratio, computational and communication overhead, and privacy leakage. Qingyu Yang 0003, Donghe Li, Dou An, Wei Yu 0002, Xinwen Fu, Xinyu Yang 0001, Wei Zhao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | On Automating BACnet Device Discovery and Property IdentificationabstractBACnet is the most popular inter-communication protocol in building automation systems (BAS) and has been deployed in a large scale. It is critical to scan and perform risk analysis of a BAS. Existing work identifies BACnet devices in a manual way and does not further discover their properties. In this paper, we design and implement an automatic tool to identify a BACnet device at a given IP and enumerate both standard and vendor-defined BACnet objects and properties. We applied our tool to a testbed real-world BAS system on a university campus and successfully validated the tool’s effectiveness. Our tool is the first of its kind for risk assessment of the BAS, e.g., automatically scanning open smart buildings on the Internet. The video at https://youtu.be/YUfO8GQILxQ demonstrates that our toolkit may be used to remotely move a damper controlling a building’s Heating, ventilation, and air conditioning (HVAC) system from the Internet and justifies the importance of using our tool for penetration testing of a BAS. Michael Cash, Shan Wang 0008, Bryan Pearson, Qun Zhou 0002, Xinwen Fu |
ICC | 5 |
| 2021 | On Private Data Collection of Hyperledger FabricabstractHyperledger Fabric is a popular permissioned Blockchain framework for a consortium of organizations to develop Blockchain based applications and transact within the consortium. Hyperledger Fabric introduces a fine-grained access control mechanism called the private data collection (PDC), which allows private data to be shared by only a subset of participants. In this paper, we analyze PDC and show three classes of use cases in which misuse of Hyperledger Fabric features may endanger implemented Hyperledger Fabric systems. We present two groups of potential attacks including fake PDC results injection and PDC leakage against the misuse of the policy based consensus protocol. We use prototype systems to validate the discovered attacks. We also collected 6392 Hyprledger Fabric projects on GitHub and built a tool to statically analyse them. We find that 86.51% of the PDC related projects are potentially vulnerable to the fake PDC results injection attacks, and 91.67% have PDC leakage issues. We design new features for the Hyper-ledger Fabric framework to mitigate the attacks and show that the new features have minor impact on the system performance. Shan Wang 0008, Ming Yang 0001, Yue Zhang 0025, Yan Luo 0001, Tingjian Ge, Xinwen Fu, Wei Zhao 0001 |
ICDCS | 6 |
| 2021 | Prison Break of Android Reflection Restriction and DefenseabstractJava reflection technique is pervasively used in the Android system. To reduce the risk of reflection abuse, Android restricts the use of reflection at the Android Runtime (ART) to hide potentially dangerous methods/fields. We perform the first comprehensive study of the reflection restrictions and have discovered three novel approaches to bypass the reflection restrictions. Novel reflection-based attacks are also presented, including the password stealing attack. To mitigate the threats, we analyze these restriction bypassing approaches and find three techniques crucial to these approaches, i.e., double reflection, memory manipulation, and inline hook. We propose a defense mechanism that consists of classloader double checker, ART variable protector, and ART method protector, to prohibit the reflection restriction bypassing. Finally, we design and implement an automatic reflection detection framework and have discovered 5,531 reflection powered apps out of 100,000 downloaded apps, which are installed on our defense enabled Android system of a Google Pixel 2 to evaluate the effectiveness and efficiency of our defense mechanism. Extensive empirical experiment results demonstrate that our defense enabled system can accurately obstruct the malicious reflection attempts. Zhen Ling 0001, Ruizhao Liu, Yue Zhang 0025, Kang Jia, Bryan Pearson, Xinwen Fu, Junzhou Luo |
INFOCOM | 6 |
| 2021 | On Manually Reverse Engineering Communication Protocols of Linux-Based IoT SystemsabstractIoT security and privacy has raised grave concerns. Efforts have been made to design tools to identify and understand vulnerabilities of IoT systems. Most of the existing protocol security analysis techniques rely on a well understanding of the underlying communication protocols. In this article, we systematically present the first manual reverse engineering framework for discovering communication protocols of embedded Linux-based IoT systems. We have successfully applied our framework to reverse engineer a number of IoT systems. As an example, we present a detailed use of the framework reverse engineering the WeMo smart plug communication protocol by extracting the firmware from the flash, performing static and dynamic analysis of the firmware, and analyzing network traffic. The discovered protocol exposes severe design flaws that allow attackers to control or deny the service of victim plugs. Our manual reverse engineering framework is generic and can be applied to both read-only and writable embedded Linux filesystems. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Huaiyu Yan, Yue Zhang 0025, Xinwen Fu, Wei Zhao 0001 |
IEEE Internet Things J. | 6 |
| 2021 | Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes
Zhen Ling 0001, Huaiyu Yan, Xinhui Shao, Junzhou Luo, Yiling Xu, Bryan Pearson, Xinwen Fu |
J. Syst. Archit. | 7 |
| 2020 | On Runtime Software Security of TrustZone-M Based IoT DevicesabstractInternet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension for MCUs, is an emerging security technique fortifying MCU based IoT devices. This paper presents the first security analysis of potential software security issues in TrustZone-M enabled MCUs. We explore the stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against Non-secure Callable (NSC) functions in the context of TrustZone-M. We validate these attacks using the Microchip SAM L11 MCU, which uses the ARM Cortex-M23 processor with the TrustZone-M technology. Strategies to mitigate these software attacks are also discussed. Yue Zhang 0025, Cliff C. Zou, Xinhui Shao, Zhen Ling 0001, Xinwen Fu |
GLOBECOM | 6 |
| 2020 | SIC2: Securing Microcontroller Based IoT Devices with Low-cost Crypto CoprocessorsabstractIn this paper, we explore the use of microcontrollers (MCUs) and crypto coprocessors to secure IoT applications, and show how developers may implement a low-cost platform that provides protects private keys against software attacks. We first demonstrate the plausibility of format string attacks on the ESP32, a popular MCU from Espressif that uses the Harvard architecture. The format string attacks can be used to remotely steal private keys hard-coded in the firmware. We then present a framework termed SIC2(Securing IoT with Crypto Coprocessors), for secure key provisioning that protects end users' private keys from both software attacks and untrustworthy manufacturers. As a proof of concept, we pair the ESP32 with the low-cost ATECC608A cryptographic coprocessor by Microchip and connect to Amazon Web Services (AWS) and Amazon Elastic Container Service (EC2) using a hardware-protected private key, which provides the security features of TLS communication including authentication, encryption and integrity. We have developed a prototype and performed extensive experiments to show that the ATECC608A crypto chip may significantly reduce the TLS handshake time by as much as 82% with the remote server, and it may lower the total energy consumption of the system by up to 70%. Our results indicate that securing IoT with crypto coprocessors is a practicable solution for low-cost MCU based IoT devices. Bryan Pearson, Cliff C. Zou, Yue Zhang 0025, Zhen Ling 0001, Xinwen Fu |
ICPADS | 5 |
| 2020 | BLESS: A BLE Application Security Scanning FrameworkabstractBluetooth Low Energy (BLE) is a widely adopted wireless communication technology in the Internet of Things (IoT). BLE offers secure communication through a set of pairing strategies. However, these pairing strategies are obsolete in the context of IoT. The security of BLE based devices relies on physical security, but a BLE enabled IoT device may be deployed in a public environment without physical security. Attackers who can physically access a BLE-based device will be able to pair with it and may control it thereafter. Therefore, manufacturers may implement extra authentication mechanisms at the application layer to address this issue. In this paper, we design and implement a BLE Security Scan (BLESS) framework to identify those BLE apps that do not implement encryption or authentication at the application layer. Taint analysis is used to track if BLE apps use nonces and cryptographic keys, which are critical to cryptographic protocols. We scan 1073 BLE apps and find that 93% of them are not secure. To mitigate this problem, we propose and implement an application-level defense with a low-cost $0.55 crypto co-processor using public key cryptography. Yue Zhang 0025, Jian Weng 0001, Zhen Ling 0001, Bryan Pearson, Xinwen Fu |
INFOCOM | 5 |
| 2020 | Breaking Secure Pairing of Bluetooth Low Energy Using Downgrade Attacks
Yue Zhang 0025, Jian Weng 0001, Rajib Dey, Yier Jin, Zhiqiang Lin 0001, Xinwen Fu |
USENIX Security Symposium | 6 |
| 2020 | STIR: A Smart and Trustworthy IoT System Interconnecting Legacy IR DevicesabstractLegacy-infrared (IR) devices are pervasively used. They are often controlled by IR remotes and cannot be controlled over the Internet. A trustworthy and cost-effective smart IR system that is able to change an IR controllable device into a smart Internet of Things (IoT) device and interconnect them for smart city/home applications is offered in this article. First, a printed circuit board (PCB) consisting of an IR receiver and multiple IR transmitters side by side which are capable of transmitting about 20 m indoors is designed and implemented. This IR transceiver board is the first of its kind. Second, the IR transceiver can be linked up with a Raspberry Pi, for which we develop two software tools, recording and replaying any IR signals so as to put the corresponding IR device in control. Third, a smartphone can be connected to the Pi by means of a message queuing telemetry transport (MQTT) cloud server so that the commands can be sent by the smartphone to the legacy IR device over the Internet. We have also identified the deficiency of TLS mutual authentication implemented by the popular MQTT open-source package Mosquitto for a trustworthy IoT system and patched the system. We analyze the factors that affect the IR signal transmission distance, discuss the security concerns of our IR transceiver, and illustrate the scenarios for attacks. For instance, TV can be turned off remotely by a drone equipped with the transceiver. Zhen Ling 0001, Chuta Sano, Chukpozohn Toe, Zupei Li, Xinwen Fu |
IEEE Internet Things J. | 6 |
| 2020 | Co-Detection of crowdturfing microblogs and spammers in online social networks
Bo Liu 0004, Xiangguo Sun, Zeyang Ni, Jiuxin Cao, Junzhou Luo, Benyuan Liu, Xinwen Fu |
World Wide Web | 7 |
| 2019 | On Misconception of Hardware and Cost in IoT Security and PrivacyabstractThe popularity of IoT has raised grave security and privacy concerns. There is a misconception that security and privacy issues of IoT systems are caused by the hardware and its cost. In this paper, we will explore the use of microcontrollers (MCUs) and crypto modules in IoT applications and demonstrate that hardware and cost may not be the bottleneck of IoT security and privacy in various application domains. We discuss how to implement hardware security, system/firmware security, network security, and data security with the low-cost Espressif's ESP32, TI's CC3220 and Microchip's cryptographic co-processor ATECC608A. We perform extensive experiments to validate the performance of cryptographic and networking operations of IoT devices based on those and other MCUs and crypto modules. We are the first to perform a comprehensive measurement and comparison of cryptographic and networking performance of these modern IoT MCUs and modules. Bryan Pearson, Yue Zhang 0025, Rajib Dey, Zhen Ling 0001, Mostafa A. Bassiouni, Xinwen Fu |
ICC | 7 |
| 2019 | Towards Deep Learning-Based Detection Scheme with Raw ECG Signal for Wearable Telehealth SystemsabstractThe electrocardiogram (ECG) signal, as one of the most important vital signs, can provide indications of many heart-related diseases. Nonetheless, in the case of telehealth context, the automated analysis and accurate detection of ECG signals remain unsolved issues, because the poor data quality collected by the wearable devices and unprofessional users further increases the complexity of hand-crafted feature extraction, ultimately affecting the efficiency of feature extraction and the detection accuracy. To address this issue and improve the detection accuracy, in this paper we present a novel detection scheme with the raw ECG signal in wearable telehealth system. Our system benefits from the concept of big data, sensing and pervasive computing and the emerging deep learning technology. In particular, a Deep Heartbeat Classification (DHC) scheme is proposed to analyze the ECG signal for arrhythmia detection. Distinct from existing solutions, the detection model in DHC can be trained directly on the raw ECG signal without hand-crafted feature extraction. A cloud-based prototypical system is also designed and implemented with the functions of data acquisition, wireless transmission, back-end data management, and ECG detection. The experimental results demonstrate that our prototypical system is feasible and effective in real-world practice, and extensive experimentation based on the MIT-BIH database demonstrates that the proposed DHC scheme outperforms baseline schemes. Peng Zhao 0001, Dekui Quan, Wei Yu 0002, Xinyu Yang 0001, Xinwen Fu |
ICCCN | 5 |
| 2019 | Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous NetworksabstractDiverse anonymous communication systems are widely deployed as they can provide the online privacy protection and Internet anti-censorship service. However, these systems are severely abused and a large amount of anonymous traffic is malicious. To mitigate this issue, we propose a novel and practical traceback technique to confirm the communication relationship between the suspicious server and the user. We leverage the software-defined network (SDN) switch at a destination server side to intercept target traffic towards the server and alter the advertised TCP window sizes so as to stealthily vary the traffic rate at the server. By carefully varying the traffic rate, we can successfully modulate a secret signal into the traffic. The traffic carrying the signal passes through the anonymous communication system and reaches the SDN switch at the user side. Then we can detect the modulated signal from the traffic so as to confirm the communication relationship between the server and the user. To validate the feasibility and effectiveness of our technique, extensive real-world experiments are performed using three popular anonymous communication systems, i.e., SSH tunnel, OpenVPN tunnel, and Tor. The results demonstrate that the detection rates approach 100% for SSH and Open VPN and 95% for Tor while the false positive rates are significantly low, approaching 0% for these three systems. Zhen Ling 0001, Junzhou Luo, Danni Xu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 5 |
| 2019 | On Location Privacy-Preserving Online Double Auction for Electric Vehicles in MicrogridsabstractIn this paper, we address the issue of demand response (DR) in microgrids via vehicle-to-vehicle technology in the smart grid with consideration for location privacy protection supported by Internet of Vehicles. To enable effective DR, the online double auction is a viable approach to support energy trading between electric vehicles (EVs) that have surplus or insufficient energy, while the utility of each participant can be considered. Nonetheless, there are three primary challenges in designing such an online double auction approach. First, as EVs are allowed to enter the market at any time, the auctioneer should make the best decision without further information about bids and asks. Second, as EVs are allowed to enter the market in different places, the auctioneer should perform routing optimization for EV charging after determining the winner. Third, there is a risk of leakage in the location of EVs that needs to be protected. To tackle these issues, we present a new truthful online double auction scheme, which features multiunit energy trading among EVs, routing optimization for EV charging, and location privacy protection. We conduct a theoretical analysis and demonstrate that our online double auction scheme is capable of achieving several important economic properties as well as the privacy guarantee (i.e., k-anonymity). Our experimental results show that the proposed scheme can achieve good performance with respect to social welfare, satisfaction ratio, total profit of EV owners, peak load shifting, state of charge, driving distance satisfaction, and computing time, and can further ensure location privacy protection. Donghe Li, Qingyu Yang 0003, Dou An, Wei Yu 0002, Xinyu Yang 0001, Xinwen Fu |
IEEE Internet Things J. | 6 |
| 2019 | Your clicks reveal your secrets: a novel user-device linking method through network and visual data
Naixuan Guo, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Wenjia Wu, Xinwen Fu |
Multim. Tools Appl. | 6 |
| 2019 | CIM: Camera in Motion for Smartphone AuthenticationabstractThe photo response non-uniformity of a smartphone camera is a reliable hardware fingerprint that can be used to authenticate the smartphone owner. This type of camera-based authentication is convenient and of low cost since it requires only pictures taken by a smartphone. However, as shown in this paper, existing camera-based authentication systems are either impractical or subject to fingerprint forgery attacks, in which an adversary intentionally submits forged pictures with fake fingerprints. We propose Camera in Motion (CIM), a practical and reliable camera-based smartphone authentication system. In CIM, a user is asked to move his/her smartphone along a specific route, take pictures of QR codes displayed on the verifier's interface in burst mode, and submit particular burst pictures to the verifier for authentication. We find that, because burst images are captured in rapid succession, the random noise components of a captured image can be partially preserved across multiple images that are captured in a row. The preserved noise forms a forgery-sensitive noisechain embedded in burst images. We also find that there exists various correlations between the movement of the camera and the noise components of the captured images. The noisechain and these correlations are then explored for forgery detection. We performed extensive experiments with 22 smartphones of 5 different models. Our experiment results show that CIM can achieve 100% true acceptance rate at 0% false acceptance rate in both fingerprint matching and forgery detection. Zhongjie Ba, Zhan Qin, Xinwen Fu, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Analysis of and defense against crowd-retweeting based spam in social networks
Bo Liu 0004, Zeyang Ni, Junzhou Luo, Jiuxin Cao, Xudong Ni, Benyuan Liu, Xinwen Fu |
World Wide Web | 7 |
| 2018 | The Peeping Eye in the SkyabstractIn this paper, we investigate the threat of drones equipped with recording devices, which capture videos of individuals typing on their mobile devices and extract the touch input such as passcodes from the videos. Deploying this kind of attack from the air is significantly challenging because of camera vibration and movement caused by drone dynamics and the wind. Our algorithms can estimate the motion trajectory of the touching finger, and derive the typing pattern and then touch inputs. Our experiments show that we can achieve a high success rate against both tablets and smartphones with a DJI Phantom drone from a long distance. A 2.5" NEUTRON mini drone flies outside a window and also achieves a high success rate against tablets behind the window. To the best of our knowledge, we are the first to systematically study drones revealing user inputs on mobile devices and use the finger motion trajectory alone to recover passcodes typed on mobile devices. Qinggang Yue, Zupei Li, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
GLOBECOM | 5 |
| 2018 | A Framework for Detecting and Countering Android UI Attacks via Inspection of IPC TrafficabstractAndroid represents an ever-increasing share of the worldwide smart device market. The platform's ubiquity and open nature make Android a prime target for malicious actors. Unfortunately, device fragmentation among manufacturers makes maintaining cyber security difficult, invoking the need for third party security software. We present a framework for detecting and countering deceptive user interface attacks on the Android platform via inspection and analysis of inter-process communication transactions in the operating system. We evaluate our proof of concept implementation on a known class of malware that exploits the Android display system, allowing a malicious application to control the screen and mimic any application launched by the user. We achieve 100% detection rate of this malicious behavior with no false alarms. Joshua Kraunelis, Xinwen Fu, Wei Yu 0002, Wei Zhao 0001 |
ICC | 2 |
| 2018 | Towards 3D Deployment of UAV Base Stations in Uneven TerrainabstractUnmanned Aerial Vehicles (UAVs), also known as drones, have become a new paradigm to provide emergency wireless communication infrastructure when conventional base stations are damaged or unavailable. In this paper, we propose new schemes to enable the 3D deployment of drones, which can provide network coverage and connectivity services for users located in uneven terrain. We formalize two models, including optimal coverage model and optimal connectivity model, which belong to NP-hard. To be specific, we first consider both the quality of service (QoS) requirements of users and the capacity of drones. We then formalize the problem and design a heuristic scheme, called Particle Swarm Optimization (PSO) algorithm to achieve a cost-effective solution. We also address the optimal connectivity problem in a scenario, in which a number of isolated local networks have been established by users through ad hoc communication and/or device-to-device (D2D) communication. We further develop the cost-effective heuristic algorithm to effectively minimize the total number of required drones. Via extensive performance evaluation, our experimental results demonstrate that the proposed schemes can achieve the effective deployment of drones for users in uneven terrain with respect to the number of required drones. Xiaofei He 0002, Wei Yu 0002, Hansong Xu, Jie Lin 0002, Xinyu Yang 0001, Chao Lu 0002, Xinwen Fu |
ICCCN | 7 |
| 2018 | SecTap: Secure Back of Device Input System for Mobile DevicesabstractSmart mobile devices have become an integral part of people's life and users often input sensitive information on these devices. However, various side channel attacks against mobile devices pose a plethora of serious threats against user security and privacy. To mitigate these attacks, we present a novel secure Back-of-Device (BoD) input system, SecTap, for mobile devices. To use SecTap, a user tilts her mobile device to move a cursor on the keyboard and tap the back of the device to secretly input data. We design a tap detection method by processing the stream of accelerometer readings to identify the user's taps in real time. The orientation sensor of the mobile device is used to control the direction and the speed of cursor movement. We also propose an obfuscation technique to randomly and effectively accelerate the cursor movement. This technique not only preserves the input performance but also keeps the adversary from inferring the tapped keys. Extensive empirical experiments were conducted on different smart phones to demonstrate the usability and security on both Android and iOS platforms. Zhen Ling 0001, Junzhou Luo, Yaowen Liu, Ming Yang 0001, Kui Wu 0001, Xinwen Fu |
INFOCOM | 6 |
| 2018 | Towards Incentive Mechanism for Taxi Services Allocation with Privacy GuaranteeabstractWith the development of online taxi-hailing systems (DiDi, Uber Lyft, etc.), how to effectively allocate taxis has attracted great attention in the recent past. Meanwhile, with the rapid increase of taxi-related crimes, the privacy of passengers' sensitive information such as location remains a critical concern. In this paper, we present a novel incentive-based scheme, which provides the differential privacy guarantee for passengers' locations in taxi-hailing systems. To be specific, to allocate limited taxis to passengers, we first present the Vickrey-Clarke-Groves (VCG)-based online auction mechanism for determining the winning passengers. Then, to match the taxis and winning passengers as well as to protect the location privacy of passengers, we present the new allocating rule based on the exponential differential privacy-based mechanism. Further, we prove that the proposed incentive-based scheme satisfies both economic properties and 2-ε differential privacy guarantee. Finally, we evaluate the performance of our proposed scheme. The experimental data confirms that our proposed scheme not only achieves better performance than the two baseline schemes with respect to social welfare and satisfaction ratio, but also is capable of protecting the location privacy of passengers with low privacy disclosure. Donghe Li, Qingyu Yang 0003, Wei Yu 0002, Dou An, Xinwen Fu |
IPCCC | 5 |
| 2018 | SecT: A Lightweight Secure Thing-Centered IoT Communication SystemabstractIn this paper, we propose a secure lightweight and thing-centered IoT communication system based on MQTT, SecT, in which a device/thing authenticates users. Compared with a server-centered IoT system in which a cloud server authenticates users, a thing-centered system preserves user privacy since the cloud server is primarily a relay between things and users and does not store or see user data in plaintext. The contributions of this work are three-fold. First, we explicitly identify critical functionalities in bootstrapping a thing and design secure pairing and binding strategies. Second, we design a strategy of end-to-end encrypted communication between users and things for the sake of user privacy and even the server cannot see the communication content in plaintext. Third, we design a strong authentication system that can defeat known device scanning attack, brute force attack and device spoofing attack against IoT. We implemented a prototype of SecT on a $10 Raspberry Pi Zero W and performed extensive experiments to validate its performance. The experiment results show that SecT is both cost-effective and practical. Although we design SecT for the smart home application, it can be easily extended to other IoT application domains. Zhen Ling 0001, Biao Chen 0002, Xinwen Fu, Wei Zhao 0001 |
MASS | 4 |
| 2018 | ABC: Enabling Smartphone Authentication with Built-in Camera
Zhongjie Ba, Sixu Piao, Xinwen Fu, Dimitrios Koutsonikolas, David Mohaisen, Kui Ren 0001 |
NDSS | 3 |
| 2018 | Turning Legacy IR Devices into Smart IoT Devices
Chuta Sano, Zupei Li, Zhen Ling 0001, Xinwen Fu |
WASA | 5 |
| 2018 | User Differentiated Verifiable File Search on the CloudabstractCloud storage security has been gaining research interest in recent years. Although considerable work has been conducted on verifying the integrity of the outsourced data in the cloud, how to efficiently verify the file search results returned from the cloud is still a challenge to be resolved. Towards this direction, we tackle the verifiable file search problem in this paper. We formulate and solve this problem by proposing two protocols. The first protocol enables verifying the correctness of the file search result when all users have the same security privilege in accessing the outsourced data. The second protocol, which builds on the first protocol, further enables user differentiation, i.e., different users can only access files that fit their security privileges. In our protocols, we employ two key strategies in enabling file search verifiability. One is to separate all possible filenames into two finite sets and the other is to embed some secret information in the outsourced data. Further, we leverage the key chaining and recursion mechanisms to enable user differentiation. We have conducted experiments to validate the effectiveness of our proposed protocols. Our results show that both protocols are efficient in terms of computation, storage, and communication cost. Fei Chen 0003, Tao Xiang 0001, Xinwen Fu, Wei Yu 0002 |
IEEE Trans. Serv. Comput. | 3 |
| 2018 | SODA: Strategy-Proof Online Double Auction Scheme for Multimicrogrids BiddingabstractIn this paper, we present theory and a design of the online double auction for the trading of energy within a smart grid with microgrids (MGs). The online double auction has the potential to enable the allocation of surplus electricity to the MGs that need electricity with the highest gain in the real-time market. Nonetheless, two critical issues remain challenging when designing an effective online double auction scheme in such a system. First, as the agents are allowed to arrive and depart at any time, the auctioneer needs to make decisions without the information of further bids and asks. Second, the economic properties of strategy-proof, individual rational, and (weak) budget balance should be satisfied. To address these issues and enable multiunit electricity trading among local MGs, in this paper, we propose a strategy-proof online double auction (SODA) scheme, in which the surplus and insufficient MGs in the system are treated as sellers and buyers, respectively, and the MG center controller is capable of maximizing the social welfare of MGs by appropriately matching buyers and sellers. Via theoretical analysis, we prove that SODA can achieve the properties of individual rationality, (weak) budget balance, strategy-proofness, and computational efficiency. Experiments also show that SODA is capable of reducing the energy purchasing cost of the MGs and shifting the peak-load, while achieving great performance with respect to social welfare, seller/buyer satisfaction ratio, social efficiency, and computation overhead. Dou An, Qingyu Yang 0003, Wei Yu 0002, Xinyu Yang 0001, Xinwen Fu, Wei Zhao 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 5 |
| 2017 | An End-to-End View of IoT Security and PrivacyabstractIn this paper, we present an end-to-end view of IoT security and privacy and a case study. Our contribution is twofold. First, we present our end-to-end view of an IoT system and this view can guide risk assessment and design of an IoT system. We identify 10 basic IoT functionalities that are related to security and privacy. Based on this view, we systematically present security and privacy requirements in terms of IoT system, software, networking and big data analytics in the cloud. Second, using the end-to-end view of IoT security and privacy, we present a vulnerability analysis of the Edimax IP camera system. We are the first to exploit this system and have identified various attacks that can fully control all the cameras from the manufacturer. Our real- world experiments demonstrate the effectiveness of the discovered attacks and raise the alarms again for the IoT manufacturers. Zhen Ling 0001, Kaizheng Liu, Yiling Xu, Yier Jin, Xinwen Fu |
GLOBECOM | 5 |
| 2017 | 3D vision attack against authenticationabstractIn this paper, we introduce a computer vision-based attack using stereo cameras against authentication approaches for touch-enabled devices. In the attack, an attacker uses a stereo camera (such as one on the HTC Evo 3D smartphone) and takes a video of a victim entering passwords on the touch screen of the victim's mobile device. We focus on challenging scenarios where the victim holds the device up and the attacker cannot see the victim's fingertip or the device screen. Since the stereo camera provides depth and distance information of objects in video frames, we can build a 3D scene to analyze the victim's hand movement and automatically recover the victim's passcode. The 3D vision attack is stealthy in daily settings like a classroom or a coffee shop since the attacker does not need to take a suspicious angle and see the touch screen of the victim. Without loss of generality, we use graphical passwords as an example and perform extensive experiments to demonstrate the effectiveness of the attack. The success rate of the 3D vision attack reaches 90% when the camera is across a table from a victim in a typical gathering scene. Zupei Li, Qinggang Yue, Chuta Sano, Wei Yu 0002, Xinwen Fu |
ICC | 5 |
| 2017 | A Case Study of Usable Security: Usability Testing of Android Privacy Enhancing Keyboard
Zhen Ling 0001, Melanie Borgeest, Chuta Sano, Sirong Lin, Mogahid Fadl, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
WASA | 7 |
| 2017 | A User Incentive-Based Scheme Against Dishonest Reporting in Privacy-Preserving Mobile Crowdsensing Systems
Xinyu Yang 0001, Cong Zhao 0001, Wei Yu 0002, Xianghua Yao, Xinwen Fu |
WASA | 5 |
| 2017 | Sto2Auc: A Stochastic Optimal Bidding Strategy for MicrogridsabstractMicrogrids (MGs) have attracted growing attention due to self-sufficiency and self-healing properties. Nonetheless, the intermittent nature and uncertainty of distributed energy resources and load demands remain challenging issues in balancing demands and managing energy resources in MGs. Existing research efforts mainly focus on developing techniques to enable interactions between local MGs and the utility grid, which leads to high line power losses and operation costs. In this paper, we present the Sto2Auc framework to address the issue of stochastic optimal bidding problem for a system with MGs. First, the optimal bidding problem is formulated as a two-stage stochastic programming process, which aims to minimize the system operation cost and obtain optimal energy capacity of MGs by the MG center controller (MGCC). Uncertainties arise from both energy supply and demand, which are considered in the stochastic model, and random parameters representing those uncertainties are captured by using the Monte Carlo method. Second, to enable optimal electricity trading between the insufficient and surplus MGs, we propose a distributed double auction (DDA)-based scheme, which is proven to converge to the optimal social welfare of the system with MGs, and achieves the economical properties of being strategy-proof, individually rational, and (weak) budget balanced. Extensive experiments on an MG system composed of IEEE-33 buses demonstrate the effectiveness of proposed scheme. The experimental results show that Sto2Auc framework is capable of reducing the operational cost of MG systems, while the implemented DDA scheme achieves good performance with respect to social welfare, demand insufficiency, and MGCC profit. Dou An, Qingyu Yang 0003, Wei Yu 0002, Xinyu Yang 0001, Xinwen Fu, Wei Zhao 0001 |
IEEE Internet Things J. | 5 |
| 2017 | Security Vulnerabilities of Internet of Things: A Case Study of the Smart Plug SystemabstractWith the rapid development of the Internet of Things, more and more small devices are connected into the Internet for monitoring and control purposes. One such type of devices, smart plugs, have been extensively deployed worldwide in millions of homes for home automation. These smart plugs, however, would pose serious security problems if their vulnerabilities were not carefully investigated. Indeed, we discovered that some popular smart home plugs have severe security vulnerabilities which could be fixed but unfortunately are left open. In this paper, we case study a smart plug system of a known brand by exploiting its communication protocols and successfully launching four attacks: 1) device scanning attack; 2) brute force attack; 3) spoofing attack; and 4) firmware attack. Our real-world experimental results show that we can obtain the authentication credentials from the users by performing these attacks. We also present guidelines for securing smart plugs. Zhen Ling 0001, Junzhou Luo, Yiling Xu, Kui Wu 0001, Xinwen Fu |
IEEE Internet Things J. | 6 |
| 2017 | Guest Editorial Special Issue on Security and Privacy in Cyber-Physical SystemsabstractA typical cyber-physical system (CPS) refers to a system that features a tight integration of computation, networking, and physical elements for interactions between cyber and physical spaces. The Internet of Things (IoT) is considered to be the networking infrastructure of CPS. Applications of CPS cover numerous smart-world research areas that our daily life depends upon, including smart transportation, smart electrical power grid, smart cities, smart medical systems, smart manufacturing systems, and others. While major research on improving the efficiency and reliability of CPS by using advanced information and communication technologies has been conducted, the risks of cyberspace security and privacy breaches in CPS need to be seriously investigated before a massive deployment of CPS technologies can or should be realized. Wei Yu 0002, Xinwen Fu, Houbing Song, Anastasios A. Economides, Minho Jo 0001, Wei Zhao 0001 |
IEEE Internet Things J. | 2 |
| 2017 | The Onion Name SystemabstractAbstract Tor onion services, also known as hidden services, are anonymous servers of unknown location and ownership that can be accessed through any Torenabled client. They have gained popularity over the years, but since their introduction in 2002 still suffer from major usability challenges primarily due to their cryptographically-generated non-memorable addresses. In response to this difficulty, in this work we introduce the Onion Name System (OnioNS), a privacy-enhanced decentralized name resolution service. OnioNS allows Tor users to reference an onion service by a meaningful globally-unique verifiable domain name chosen by the onion service administrator.We construct OnioNS as an optional backwards-compatible plugin for Tor, simplify our design and threat model by embedding OnioNS within the Tor network, and provide mechanisms for authenticated denial-of-existence with minimal networking costs. We introduce a lottery-like system to reduce the threat of land rushes and domain squatting. Finally, we provide a security analysis, integrate our software with the Tor Browser, and conduct performance tests of our prototype. Jesse Victors, Xinwen Fu |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Privacy Enhancing Keyboard: Design, Implementation, and Usability TestingabstractTo protect users from numerous password inference attacks, we invent a novel context aware privacy enhancing keyboard (PEK) for Android touch-based devices. Usually PEK would show a QWERTY keyboard when users input text like an email or a message. Nevertheless, whenever users enter a password in the input box on his or her touch-enabled device, a keyboard will be shown to them with the positions of the characters shuffled at random. PEK has been released on the Google Play since 2014. However, the number of installations has not lived up to our expectation. For the purpose of usable security and privacy, we designed a two-stage usability test and performed two rounds of iterative usability testing in 2016 and 2017 summer with continuous improvements of PEK. The observations from the usability testing are educational: (1) convenience plays a critical role when users select an input method; (2) people think those attacks that PEK prevents are remote from them. Zhen Ling 0001, Melanie Borgeest, Chuta Sano, Jazmyn Fuller, Anthony Cuomo, Sirong Lin, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
Wirel. Commun. Mob. Comput. | 8 |
| 2016 | On crowd-retweeting spamming campaign in social networksabstractCrowdsourcing is often used to solicit contributions from an online community for ideas, evaluation and opinions. However, spamming can pollute such a system and manipulate the results of crowdsourcing. For detection of those spammers, the training data used in previous studies is often derived by experts labeling collected data and manually identifying spammers. The reliability of such training data is questionable. In this paper, we utilize two web based service providers Zhubajie (ZBJ) and Sandaha (SDH) and obtain reliable data about the spammers. We use such data to investigate the crowd-retweeting spam in Sina Weibo. We analyze profile features, social relationship and retweeting behavior of such spammers. We find that although these spammers are likely to connect more closely than legitimate users, the underlying social tie is different from the social relationship in other spam campaigns because of the unique retweeting features with the information cascade effect. Based on these findings, we propose retweeting-aware link based ranking algorithms to detect suspect spam accounts using seeds of identified spammers. Our evaluation shows that our algorithm is more effective than other link-based methods. Bo Liu 0004, Junzhou Luo, Jiuxin Cao, Xudong Ni, Benyuan Liu, Xinwen Fu |
ICC | 6 |
| 2016 | Secure fingertip mouse for mobile devicesabstractVarious attacks may disclose sensitive information such as passwords of mobile devices. Residue-based attacks exploit oily or heat residues on the touch screen, computer vision based attacks analyze the hand movement on a keyboard, and sensor based attacks measure a device's motion difference via motion sensors as different keys are tapped. A randomized soft keyboard may defeat these attacks. However, a randomized key layout is counter-intuitive and users may be reluctant to adopt it. In this paper, we introduce a novel and intuitive input system, secure finger mouse, which uses a mobile device's camera sensing the fingertip movement, moves an on-screen cursor and performs clicks by sensing click gestures. We design a randomized mouse acceleration algorithm so that the adversary cannot infer keys clicked on the soft keyboard by observing the finger movement. The secure finger mouse can defeat attacks including residue, computer vision and motion based attacks too. We perform both theoretical analysis and real-world experiments to demonstrate the security and usability of the secure fingertip mouse. Zhen Ling 0001, Junzhou Luo, Qinggang Yue, Ming Yang 0001, Wei Yu 0002, Xinwen Fu |
INFOCOM | 7 |
| 2016 | Data integrity attacks against the distributed real-time pricing in the smart gridabstractIn this paper, we address the issue of designing an effective distributed real-time pricing scheme in the smart grid and investigating its security resilience when the data integrity attack is in place. Different from existing research efforts, in this paper we develop a distributed real-time pricing scheme, which can maximize the welfare of all participants and improve the resilience to system failures, as well as consider both renewable and traditional power resources. By leveraging the distributed approach, we leverage the gradient projection mechanism to solve the distributed real-time pricing problem in participants' smart meters to improve the resilience to system failures. We also investigate the vulnerabilities of the distributed real-time pricing scheme by considering one typical data integrity attack, which can inject false data into communication interfaces. Via a combination of both theoretical analysis and performance evaluation, we demonstrate that the proposed distributed scheme can effectively guide the participants to achieve individual welfare maximization. Our findings also show that data integrity attacks can disrupt the distributed real-time pricing, posing a damage to the welfare of participants. Xinyu Yang 0001, Xialei Zhang, Jie Lin 0002, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
IPCCC | 5 |
| 2016 | On the security of binary arithmetic coding based on interval shrinking
Tao Xiang 0001, Jianglin Sun, Xinwen Fu |
Multim. Tools Appl. | 3 |
| 2016 | Password Extraction via Reconstructed Wireless Mouse TrajectoryabstractLogitech made the following statement in 2009: “Since the displacements of a mouse would not give any useful information to a hacker, the mouse reports are not encrypted.” In this paper, we prove the exact opposite is true-i.e., it is indeed possible to leak sensitive information such as passwords through the displacements of a Bluetooth mouse. Our results can be easily extended to other wireless mice using different radio links. We begin by presenting multiple ways to sniff unencrypted Bluetooth packets containing raw mouse movement data. We then show that such data may reveal text-based passwords entered by clicking on software keyboards. We propose two attacks, the prediction attack and replay attack, which can reconstruct the on-screen cursor trajectories from sniffed mouse movement data. Two inference strategies are used to discover passwords from cursor trajectories. We conducted a holistic study over all popular operating systems and analyzed how mouse acceleration algorithms and packet losses may affect the reconstruction results. Our real-world experiments demonstrate the severity of privacy leakage from unencrypted Bluetooth mice. We also discuss countermeasures to prevent privacy leakage from wireless mice. To the best of our knowledge, our work is the first to demonstrate privacy leakage from raw mouse data. Xian Pan, Zhen Ling 0001, Aniket Pingley, Wei Yu 0002, Nan Zhang 0004, Kui Ren 0001, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2016 | SBVLC: Secure Barcode-Based Visible Light Communication for Smartphonesabstract2D barcodes have enjoyed a significant penetration rate in mobile applications. This is largely due to the extremely low barrier to adoption-almost every camera-enabled smartphone can scan 2D barcodes. As an alternative to NFC technology, 2D barcodes have been increasingly used for security-sensitive mobile applications including mobile payments and personal identification. However, the security of barcode-based communication in mobile applications has not been systematically studied. Due to the visual nature, 2D barcodes are subject to eavesdropping when they are displayed on the smartphone screens. On the other hand, the fundamental design principles of 2D barcodes make it difficult to add security features. In this paper, we propose SBVLC-a secure system for barcode-based visible light communication (VLC) between smartphones. We formally analyze the security of SBVLC based on geometric models and propose physical security enhancement mechanisms for barcode communication by manipulating screen view angles and leveraging user-induced motions. We then develop three secure data exchange schemes that encode information in barcode streams. These schemes are useful in many security-sensitive mobile applications including private information sharing, secure device pairing, and contactless payment. SBVLC is evaluated through extensive experiments on both Android and iOS smartphones. Bingsheng Zhang, Kui Ren 0001, Guoliang Xing, Xinwen Fu, Cong Wang 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2015 | A Systematic Key Management mechanism for practical Body Sensor NetworksabstractSecurity plays a vital role in promoting the practicality of Wireless Body Sensor Networks (BSNs), which provides a promising solution to precise human physiological status monitoring. A fundamental security issue in BSN is key management, including establishment and maintenance of the key system. However, current BSN key management solutions are either designed for specific phases of a BSN's life-time or restricted to strong assumptions such as homogeneous BSN composition, pre-deployed key materials, and existing secure path, which limits their applications in real-world BSNs. In this paper, we develop the Systematic Key Management (SKM) for practical BSNs, where basic human interactions are conducted for non-predeployed secure BSN initialization, and authenticated key agreement is achieved using lightweight non-pairing certificateless public key cryptography. We construct a BSN prototype consisting of self-designed motes and Android phones to evaluate the real-world performance of SKM. Through extensive simulations and test-bed experiments, we demonstrate that our lightweight SKM scheme manages to provide high security guarantee while outperforming state-of-the-art approaches in terms of both computation and storage efficiency. Xinyu Yang 0001, Cong Zhao 0001, Shusen Yang, Xinwen Fu, Julie A. McCann |
ICC | 4 |
| 2015 | INCOR: Inter-flow Network Coding based Opportunistic Routing in wireless mesh networksabstractBoth opportunistic routing and inter-flow network coding are useful mechanisms for improving the performance of wireless networks. Both of them exploit the broadcast nature of the wireless medium and the spatial diversity of multi-hop wireless networks. In this paper, we aim at incorporating interflow network coding into opportunistic routing for further improving the performance of wireless mesh networks (WMNs). The main issue in designing such a scheme is candidate set selection and prioritization based on a proper metric for opportunistic routing. To this end, in this paper, we first present a new metric to determine the prioritization of the forwarders in the set of candidates and then design an Inter-flow Network Coding-based Opportunistic Routing (INCOR) scheme using the defined metric. Our proposed INCOR scheme can integrate the characteristics of inter-flow network coding and opportunistic routing effectively to make full use of the broadcast nature of the wireless medium. We carry out extensive simulations to evaluate the effectiveness of the INCOR method. Our data shows that INCOR outperforms both opportunistic routing and inter-flow network coding schemes. Donghai Zhu, Xinyu Yang 0001, Wei Yu 0002, Chao Lu 0002, Xinwen Fu |
ICC | 5 |
| 2015 | A Novel Dynamic En-Route Decision Real-Time Route Guidance Scheme in Intelligent Transportation SystemsabstractIn an intelligence transportation system (ITS), to increase traffic efficiency, a number of dynamic route guidance schemes have been designed to assist drivers in determining the optimal route for their travels. In order to determine optimal routes, it is critical to effectively predict the traffic condition of roads along the guided routes based on real-time traffic information to mitigate traffic congestion and improve traffic efficiency. In this paper, we propose a Dynamic En-route Decision real-time Route guidance (DEDR) scheme to effectively mitigate road congestion caused by the sudden increase of vehicles and reduce travel time. Particularly, DEDR considers real-time traffic information generation and transmission. Based on the shared traffic information, DEDR introduces Trust Probability to predict traffic conditions and dynamically en-route determine alternative optimal routes. In addition, DEDR considers multiple metrics to comprehensively assess traffic conditions and drivers can determine optimal route with individual preference of these metrics during travel. DEDR also considers effects of external factors (e.g., Bad weather, incidents, etc.) on traffic conditions. Through a combination of extensive theoretical analysis and simulation experiments, our data shows that DEDR can greatly increase the efficiency of an ITS in terms of great time efficiency and balancing efficiency in comparison with existing schemes. Jie Lin 0002, Wei Yu 0002, Xinyu Yang 0001, Qingyu Yang 0003, Xinwen Fu, Wei Zhao 0001 |
ICDCS | 5 |
| 2015 | Pricing and revenue sharing in secondary market of mobile internet accessabstractThere is a fast growing number of public spaces offering Wi-Fi access to meet the rising demands for Internet access. It is common for such service to be offered to users at no charge or for a flat fee. Both situations provide very little incentive for Wi-Fi providers to offer better service to the users. Similarly, Wi-Fi providers pay a monthly flat rate to ISP for Internet access and, this too does not incentivize ISP to offer better service to Wi-Fi users. As a result, Wi-Fi users may experience poor connection when network becomes congested during peak hours. In this paper we propose a dynamic pricing scheme for Internet access and a revenue sharing mechanism that provides incentives for both ISP and Wi-Fi providers to offer better service to their users. We build our revenue sharing model based on Shapley value mechanism. Importantly, our proposed revenue sharing mechanism captures the power negotiation between ISP and Wi-Fi providers, and how shifts in power influences revenue division. Specifically, the model assures that the party who contributes more receives a higher portion of the revenue. In addition, our simulation demonstrates that our model captures the bargaining power shifts between Wi-Fi providers and ISP, and shows that the division of revenue asymptotically converges to a percentage value. Hengky Susanto, Benyuan Liu, Byung-Guk Kim, Honggang Zhang 0003, Xinwen Fu |
IPCCC | 5 |
| 2015 | On stochastic optimal bidding strategy for microgridsabstractIn this paper, we addressed the issue of a stochastic optimal bidding problem for a system with microgrids (MGs). The optimal bidding problem is formulated as a two-stage stochastic programming process, which aims to minimize the system operation cost and to expand energy interactions among local MGs that are geographically close. Uncertainties come from both energy supply and demand sides (e.g., wind, solar, and load demand) are considered in the stochastic model and random parameters to represent those uncertainties are captured by using the Monte Carlo method. To enable an optimal electricity trading between local MGs, we presented two bidding schemes: (i) Cournot equilibrium based Dynamic Backtrack Energy Trading (DBET), and (ii) double auction based Dual Decomposition Auction (DDA). Experimental results on an IEEE-33 bus based system with MGs were presented to show the effectiveness of our proposed schemes. Experimental results show that our proposed bidding schemes can reduce the operation cost of the system, while the DDA scheme achieves better performance in terms of system social welfare than the DBET scheme. Qingyu Yang 0003, Dou An, Wei Yu 0002, Xinyu Yang 0001, Xinwen Fu |
IPCCC | 5 |
| 2015 | Secondary Market Mobile Users for Internet AccessabstractThere is a fast growing number of public spaces offering Wi-Fi access to meet the rising demands for the Internet. It is common for such service to be offered to users at no charge or for a flat fee. Both situations provide very little incentive for Wi-Fi providers to offer better service to the users. Similarly, Wi-Fi providers pay a monthly flat-rate to ISP for Internet access, which does not incentivize ISP to offer better service to Wi-Fi users. As a result, Wi-Fi users may experience poor Internet connection when network becomes congested during peak hours. In this paper, we propose a dynamic pricing mechanism for both ISP and Wi-Fi providers in order to give mobile Wi-Fi users better service, while providing economic incentive for both ISP and Wi-Fi provider. Hengky Susanto, Benyuan Liu, Byung-Guk Kim, Honggang Zhang 0003, Biao Chen 0002, Junda Zhu 0001, Xinwen Fu |
NCA | 7 |
| 2015 | Rise of the Indoor Crowd: Reconstruction of Building Interior View via Mobile CrowdsourcingabstractCrowdsourcing is a technology with the potential to revolutionize large-scale data gathering in an extremely cost-effective manner. It provides an unprecedented means of collecting data from the physical world, particularly through the use of modern smartphones, which are equipped with high-resolution cameras and various micro-electrical sensors. In this paper, we address the critical task of reconstructing the indoor interior view of a building from crowdsourced data. We propose, design, and prototype IndoorCrowd2D, a smartphone-empowered crowdsourcing system for indoor scene reconstruction. We first formulate the problem via trackable models and then employ a divide and conquer approach to address the inherently incomplete, opportunistic, and noisy crowdsourced data. By utilizing the image information and sensory data in a coordinated way, our system demonstrates high result-accuracy, as well as allows a gradual build-up procedure of the hallway skeleton. Our evaluation result shows that IndoorCrowd2D achieves a precision around 85%, a 100% recall and a F-score around 95% for reconstructing college buildings from 1,151 datasets uploaded by 25 users. This reveals that our image and sensor hybrid method is more robust to overcome errors and outliers as compared to image-only method. Si Chen 0009, Muyuan Li, Kui Ren 0001, Xinwen Fu, Chunming Qiao |
SenSys | 4 |
| 2015 | On Computing Multi-Agent Itinerary Planning in Distributed Wireless Sensor Networks
Bo Liu 0004, Jiuxin Cao, Wei Yu 0002, Benyuan Liu, Xinwen Fu |
WASA | 6 |
| 2015 | A Novel En-Route Filtering Scheme Against False Data Injection Attacks in Cyber-Physical Networked SystemsabstractIn Cyber-Physical Networked Systems (CPNS), the adversary can inject false measurements into the controller through compromised sensor nodes, which not only threaten the security of the system, but also consume network resources. To deal with this issue, a number of en-route filtering schemes have been designed for wireless sensor networks. However, these schemes either lack resilience to the number of compromised nodes or depend on the statically configured routes and node localization, which are not suitable for CPNS. In this paper, we propose a Polynomial-based Compromise-Resilient En-route Filtering scheme (PCREF), which can filter false injected data effectively and achieve a high resilience to the number of compromised nodes without relying on static routes and node localization. PCREF adopts polynomials instead of Message Authentication Codes (MACs) for endorsing measurement reports to achieve resilience to attacks. Each node stores two types of polynomials: authentication polynomial and check polynomial, derived from the primitive polynomial, and used for endorsing and verifying the measurement reports. Through extensive theoretical analysis and experiments, our data shows that PCREF achieves better filtering capacity and resilience to the large number of compromised nodes in comparison to the existing schemes. Xinyu Yang 0001, Jie Lin 0002, Wei Yu 0002, Paul Moulema, Xinwen Fu, Wei Zhao 0001 |
IEEE Trans. Computers | 5 |
| 2015 | TorWard: Discovery, Blocking, and Traceback of Malicious Traffic Over TorabstractTor is a popular low-latency anonymous communication system. It is, however, currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we designed and implemented a novel system, TorWard, for the discovery and the systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints, and allows the investigation to be performed in a sensitive environment such as a university campus. An intrusion detection system (IDS) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard. Our results show that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), denial-of-service attack traffic, spam, and others. Around 200 known malwares have been identified. To mitigate the abuse of Tor, we implemented a defense system, which processes IDS alerts, tears down, and blocks suspect connections. To facilitate forensic traceback of malicious traffic, we implemented a dual-tone multi-frequency signaling-based approach to correlate botnet traffic at Tor entry routers and that at exit routers. We carried out theoretical analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard for discovery, blocking, and traceback of malicious traffic. Zhen Ling 0001, Junzhou Luo, Kui Wu 0001, Wei Yu 0002, Xinwen Fu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2015 | Tor Bridge Discovery: Extensive Analysis and Large-scale Empirical EvaluationabstractTor is a well-known low-latency anonymous communication system that is able to bypass the Internet censorship. However, publicly announced Tor routers are being blocked by various parties. To counter the censorship blocking, Tor introduced non-public bridges as the first-hop relay into its core network. In this paper, we investigated the effectiveness of two categories of bridge-discovery approaches: 1) enumerating bridges from bridge HTTPS and email servers, and 2) inferring bridges by malicious Tor middle routers. Large-scale real-world experiments were conducted and validated our theoretic findings. We discovered 2365 Tor bridges through the two enumeration approaches and 2369 bridges by only one Tor middle router in 14 days. Our study shows that the bridge discovery based on malicious middle routers is simple, efficient, and effective to discover bridges with little overhead. We also discussed issues related to bridge discovery and mechanisms to counter the malicious bridge discovery. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Ming Yang 0001, Xinwen Fu |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2014 | CollabAssure: A Collaborative Market Based Data Service Assurance Framework for Mobile DevicesabstractConcomitant to the growing popularity of Internet enabled mobile devices such as smartphones, tablets, PDAs, portable media players etc., however, are the concerns about availability of Internet access points for these devices. Mobile users often either overpay for service availability such as (3G or LTE) or suffer incapability of accessing Internet services due to limited hardware resources (3G or LTE) or exhaustion of carrier enforced data plans. In this paper we introduce Collab Assure, an auction based, ad-hoc market model assuring service for users with no Internet access capability. Collab Assure framework provides service assurance through opportunistic ad-hoc networks formed by spatio-temporally co-existing mobile users. The system allows users to "sublet" their surplus data plans to the users without Internet access. We discuss the design and implementation of Collab Assure technology in Android framework. Our simulation results advocate the success of this approach on real world traces, where mobile users need to participate in auctions for achieving on-demand and low-cost data service. Bhanu Kaushik, Honggang Zhang 0003, Xinyu Yang 0001, Xinwen Fu, Benyuan Liu |
AINA | 4 |
| 2014 | Blind Recognition of Touched Keys on Mobile DevicesabstractIn this paper, we introduce a novel computer vision based attack that automatically discloses inputs on a touch-enabled device while the attacker cannot see any text or popup in a video of the victim tapping on the touch screen. We carefully analyze the shadow formation around the fingertip, apply the optical flow, deformable part-based model (DPM), k-means clustering and other computer vision techniques to automatically locate the touched points. Planar homography is then applied to map the estimated touched points to a reference image of software keyboard keys. Recognition of passwords is extremely challenging given that no language model can be applied to correct estimated touched keys. Our threat model is that a webcam, smartphone or Google Glass is used for stealthy attack in scenarios such as conferences and similar gathering places. We address both cases of tapping with one finger and tapping with multiple fingers and two hands. Extensive experiments were performed to demonstrate the impact of this attack. The per-character (or per-digit) success rate is over 97% while the success rate of recognizing 4-character passcodes is more than 90%. Our work is the first to automatically and blindly recognize random passwords (or passcodes) typed on the touch screen of mobile devices with a very high success rate. Qinggang Yue, Zhen Ling 0001, Xinwen Fu, Benyuan Liu, Kui Ren 0001, Wei Zhao 0001 |
CCS | 3 |
| 2014 | Privacy-preserving outsourcing of image global feature detectionabstractThe amount and availability of user-contributed image data have been dramatically increased during the past ten years. Popular multimedia social networks, e.g. Flicker, commonly utilize user image data to construct user behavior models, social preferences, etc., for the purpose of effective advertisement, better user retention and attraction, and many others. Existing practices of data utilization, however, seriously deteriorate users' personal privacy and have led to increasing criticisms and legislation pressures. In this paper, we aim to construct a privacy-preserving feature detection scheme over encrypted image data. The proposed system enables an interested party to perform a variety of image feature detection tasks, including visual descriptors in MPEG-7 standard, while protecting user privacy relating to image contents. We implement a prototype system based on somewhat homomorphic encryption scheme and the benchmark Caltech256 database. The experimental results show that our system can guarantee effective image feature detection without sacrificing user privacy. Zhan Qin, Jingbo Yan, Kui Ren 0001, Chang Wen Chen, Cong Wang 0001, Xinwen Fu |
GLOBECOM | 6 |
| 2014 | Analyzing mobile phone vulnerabilities caused by cameraabstractNowadays mobile phones have been widely used, and Android is one of the most popular mobile operating system. The security issue of Android has caught great concerns among mobile users and researchers. In this paper, we study the vulnerabilities related of phone cameras. Specifically, we discover and present several camera-based attacks including the basic camera attack and advanced passcode inference attacks. We implement these attacks on real phones (with anti-virus software installed) and demonstrate the feasibility and effectiveness of the attacks. Furthermore, a lightweight defense scheme is proposed to secure phones against these attacks. Longfei Wu, Xiaojiang Du, Xinwen Fu, Ralph Oyini Mbouna, Seong G. Kong |
GLOBECOM | 4 |
| 2014 | On simulation studies of cyber attacks against LTE networksabstractBecause of ever-increasing performance and capacity gains, the popularity of LTE as a 4G technology has skyrocketed. Unfortunately, cyber adversaries may launch attacks against the LTE network. In this paper, we develop a theoretical framework to systematically explore the attack space which consists of three dimensions: communication services attacked, planes of attack, and network components under attack. Based on the developed framework, we carried out extensive simulations to evaluate the impact of some representative attacks on LTE network performance. Our developed framework and simulation models enables a foundation for advancing the understanding of threats on the LTE network and assists in developing counter-measures to secure LTE networks. Sulabh Bhattarai, Stephen Rook, Linqiang Ge, Sixiao Wei, Wei Yu 0002, Xinwen Fu |
ICCCN | 6 |
| 2014 | TorWard: Discovery of malicious traffic over TorabstractTor is a popular low-latency anonymous communication system. However, it is currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we design and implement a novel system, TorWard, for the discovery and systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints and allows the investigation to be performed in a sensitive environment such as a university campus. An IDS (Intrusion Detection System) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and effectiveness of TorWard. Our data shows that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), DoS (Denial-of-Service) attack traffic, spam, and others. Around 200 known malware have been identified. To the best of our knowledge, we are the first to perform malicious traffic categorization over Tor. Zhen Ling 0001, Junzhou Luo, Kui Wu 0001, Wei Yu 0002, Xinwen Fu |
INFOCOM | 5 |
| 2014 | SBVLC: Secure barcode-based visible light communication for smartphonesabstractAs an alternative to NFC technology, 2D barcodes have been increasingly used for security-sensitive applications including payments and personal identification. However, the security of barcode-based communication in mobile applications has not been systematically studied. Due to the visual nature, 2D barcodes are subject to eavesdropping when they are displayed on the screen of a smartphone. On the other hand, the fundamental design principles of 2D barcodes make it difficult to add security features. In this paper, we propose SBVLC - a secure system for barcode-based visible light communication (VLC) between smartphones. We formally analyze the security of SBVLC based on geometric models and propose physical security enhancement mechanisms for barcode communication by manipulating screen view angles and leveraging user-induced motions. We then develop two secure data exchange schemes. These schemes are useful in many security-sensitive mobile applications including private information sharing, secure device pairing, and mobile payment. SBVLC is evaluated through extensive experiments on both Android and iOS smartphones. Bingsheng Zhang, Kui Ren 0001, Guoliang Xing, Xinwen Fu, Cong Wang 0001 |
INFOCOM | 4 |
| 2014 | Network coding versus traditional routing in adversarial wireless networks
Donghai Zhu, Xinyu Yang 0001, Wei Yu 0002, Xinwen Fu |
Ad Hoc Networks | 4 |
| 2014 | Providing service assurance in mobile opportunistic networks
Bhanu Kaushik, Honggang Zhang 0003, Xinyu Yang 0001, Xinwen Fu, Benyuan Liu, Jie Wang 0002 |
Comput. Networks | 4 |
| 2014 | HAWK: An Unmanned Mini-Helicopter-Based Aerial Wireless Kit for LocalizationabstractThis paper presents a fully functional and highly portable mini Unmanned Aerial Vehicle (UAV) system, HAWK, for conducting aerial localization. HAWK is a programmable mini helicopter Draganflyer X6 armed with a wireless sniffer Nokia N900. We developed custom PI-Control laws to implement a robust waypoint algorithm for the mini helicopter to fly a planned route. A Moore space filling curve is designed as a flight route for HAWK to survey a specific area. A set of theorems were derived to calculate the minimum Moore curve level for sensing all targets in the area with minimum flight distance. With such a flight strategy, we can confine the location of a target of interest to a small hot area. We can recursively apply the Moore curve-based flight route to the hot area for a fine-grained localization of a target of interest. We have conducted extensive experiments to validate the feasibility of HAWK and our theory. A demo of HAWK in autonomous fly is available at http://www.youtube.com/watch?v=ju86xnHbEq0. Zhongli Liu, Yinjie Chen, Benyuan Liu, Chengyu Cao, Xinwen Fu |
IEEE Trans. Mob. Comput. | 5 |
| 2013 | On effective localization attacks against Internet Threat monitorsabstractInternet Threat Monitoring (ITM) systems have been widely deployed to detect and characterize dangerous Internet global threats such as botnet and malware propagation. Nonetheless, the effectiveness of ITM systems largely depends on the confidentiality of their monitor locations. In this paper, we investigate localization attacks aiming to identify ITM monitor location and propose the formal model of such attacks using communication channel theory. We also develop novel techniques that significantly increases the accuracy, efficiency, and secrecy of ITM localization attacks. Specifically, we introduce (i) a frequency-based modulation technique to effectively reduce the interference from the background traffic and achieve a high attack accuracy, (ii) both time and space hopping techniques to randomize signal pattern and make the attack hard to detect by the defender, and (iii) Multiple Input and Multiple Output (MIMO) based techniques to increase the attack efficiency of identifying multiple monitors simultaneously. We derive closed formulae for the performance analysis of our proposed techniques and conduct extensive simulations. Our data validate our theoretical findings and demonstrate that the adversary can identify ITM monitors accurately, efficiently, and secretly. Wei Yu 0002, Sixiao Wei, Guanhui Ma, Xinwen Fu, Nan Zhang 0004 |
ICC | 4 |
| 2013 | Theory underlying measurement of AOA with a rotating directional antennaabstractIn many wireless localization applications, we rotate a directional antenna to derive the angle of arrival (AOA) of wireless signals transmitted from a target mobile device. The AOA corresponds to the direction in which the maximum received signal strength (RSS) is sensed. However, an unanswered question is how to make sure the directional antenna picks up packets producing the maximum RSS while rotating. We propose a set of novel RSS sampling theory to answer this question. We recognize the process that a directional antenna measures RSS of wireless packets while rotating as the process that the radiation pattern of the directional antenna is sampled. Therefore, if RSS samples can reconstruct the antenna's radiation pattern, the direction corresponding to the peak of the radiation pattern is the AOA of the target. We derive mathematical models to determine the RSS sampling rate given the target's packet transmission rate. Our RSS sampling theory is applicable to various types of directional antennas. To validate our RSS sampling theory, we developed BotLoc, which is a programmable and self-coordinated robot armed with a wireless sniffer. We conducted extensive real-world experiments and the experimental results match the theory very well. A video of BotLoc is at www.youtube.com/watch?v=WtUt0IqhXRU&feature=youtu.be. Yinjie Chen, Zhongli Liu, Xinwen Fu, Benyuan Liu, Wei Zhao 0001 |
INFOCOM | 3 |
| 2013 | Protocol-level hidden server discoveryabstractTor hidden services are commonly used to provide a TCP based service to users without exposing the hidden server's IP address in order to achieve anonymity and anti-censorship. However, hidden services are currently abused in various ways. Illegal content such as child pornography has been discovered on various Tor hidden servers. In this paper, we propose a protocollevel hidden server discovery approach to locate the Tor hidden server that hosts the illegal website. We investigate the Tor hidden server protocol and develop a hidden server discovery system, which consists of a Tor client, a Tor rendezvous point, and several Tor entry onion routers. We manipulate Tor cells, the basic transmission unit over Tor, at the Tor rendezvous point to generate a protocol-level feature at the entry onion routers. Once our controlled entry onion routers detect such a feature, we can confirm the IP address of the hidden server. We conduct extensive analysis and experiments to demonstrate the feasibility and effectiveness of our approach. Zhen Ling 0001, Junzhou Luo, Kui Wu 0001, Xinwen Fu |
INFOCOM | 4 |
| 2013 | On Malware Leveraging the Android Accessibility Framework
Joshua Kraunelis, Yinjie Chen, Zhen Ling 0001, Xinwen Fu, Wei Zhao 0001 |
MobiQuitous | 4 |
| 2013 | How Privacy Leaks From Bluetooth Mouse?
Xian Pan, Zhen Ling 0001, Aniket Pingley, Wei Yu 0002, Kui Ren 0001, Nan Zhang 0004, Xinwen Fu |
NDSS | 7 |
| 2013 | On Effectiveness of Hopping-Based Spread Spectrum Techniques for Network Forensic TracebackabstractNetwork-based crime has been increasing in both extent and severity and network-based forensics encapsulates an essential part of legal surveillance. A key network forensics tool is trace back, which can be used to identify true sources of suspects. Both accuracy and secrecy are essential attributes of a successful forensic trace back. In this paper, we present a class of hopping based spread-spectrum techniques for forensic trace back, which fully use the benefits of the spread spectrum approach and preserves a greater degree of secrecy. Our proposed techniques, including Code Hopping-Direct Sequence Spread Spectrum (CHDSSS), Frequency Hopping-Direct Sequence Spread Spectrum (FH-DSSS), and Time Hopping-Spread Spectrum (TH-DSSS), operate to randomize the effects of marking traffic through both the time and frequency domains. Our simulation study validates these techniques in terms of accuracy and secrecy. Wei Yu 0002, Xinwen Fu, Erik Blasch, Khanh D. Pham, Dan Shen 0004, Genshe Chen, Chao Lu 0002 |
SNPD | 2 |
| 2013 | Effective RSS Sampling for Forensic Wireless Localization
Yinjie Chen, Zhongli Liu, Xinwen Fu, Wei Zhao 0001 |
WASA | 3 |
| 2013 | Protocol-level attacks against Tor
Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu, Weijia Jia 0001, Wei Zhao 0001 |
Comput. Networks | 4 |
| 2013 | Blind detection of spread spectrum flow watermarksabstractABSTRACT Recently, the direct sequence spread spectrum (DSSS)‐based technique has been proposed to trace anonymous network flows. In this technique, homogeneous pseudo‐noise (PN) codes are used to modulate multiple bit signals that are embedded into the target flow as watermarks. This technique could be maliciously used to degrade an anonymous communication network. In this paper, we propose an effective single flow‐based scheme to detect the existence of these watermarks. Our investigation shows that, even if we have no knowledge of the applied PN code, we are still able to detect malicious DSSS watermarks via mean‐square autocorrelation (MSAC) of a single modulated flow's traffic rate time series. MSAC shows periodic peaks because of self‐similarity in the modulated traffic caused by homogeneous PN codes that are used in modulating multiple bit signals. Our scheme has low complexity and does not require any PN code synchronization. We evaluate this detection scheme's effectiveness via simulations. Our results demonstrate a high detection rate with a low false positive rate. Real‐world experiments on Tor also validate the feasibility of the detection scheme. Our scheme is more flexible and accurate than the existing multiflow‐based approach in DSSS watermark detection. We also present a theory for reconstructing the DSSS code once the DSSS code length is known and simulations validate the feasibility. Copyright © 2012 John Wiley & Sons, Ltd. Weijia Jia 0001, Fung Po Tso 0001, Zhen Ling 0001, Xinwen Fu, Dong Xuan, Wei Yu 0002 |
Secur. Commun. Networks | 4 |
| 2013 | Novel Packet Size-Based Covert Channel Attacks against AnonymizerabstractIn this paper, we present a study on the anonymity of Anonymizer, a well-known commercial anonymous communication system. We discovered the architecture of Anonymizer and found that the size of web packets in the Anonymizer network can be very dynamic at the client. Motivated by this finding, we investigated a class of novel packet size-based covert channel attacks against Anonymizer. The attacker between a website and the Anonymizer server can manipulate the web packet size and embed secret signal symbols into the target traffic. An accomplice at the user side can sniff the traffic and recognize the secret signal. In this way, the anonymity provided by Anonymizer is compromised. We developed intelligent and robust algorithms to cope with the packet size distortion incurred by Anonymizer and Internet. We developed techniques to make the attack harder to detect: 1) We pick up right packets of web objects to manipulate to preserve the regularity of the TCP packet size dynamics, which can be measured by the Hurst parameter; 2) We adopt the Monte Carlo sampling technique to preserve the distribution of the web packet size despite manipulation. We have implemented the attack over Anonymizer and conducted extensive analytical and experimental evaluations. It is observed that the attack is highly efficient and requires only tens of packets to compromise the anonymous web surfing via Anonymizer. The experimental results are consistent with our theoretical analysis. Zhen Ling 0001, Xinwen Fu, Weijia Jia 0001, Wei Yu 0002, Dong Xuan, Junzhou Luo |
IEEE Trans. Computers | 2 |
| 2013 | How to block Tor's hidden bridges: detecting methods and countermeasures
Ming Yang 0001, Junzhou Luo, Lu Zhang 0030, Xiaogang Wang 0012, Xinwen Fu |
J. Supercomput. | 5 |
| 2012 | How privacy leaks from bluetooth mouse?abstractRaw mouse movement data can be sniffed via off-the-shelf tools. In this demo, we show that such data, while seemingly harmless, may reveal extremely sensitive information such as passwords. Nonetheless, such a Bluetooth-mouse-sniffing attack can be challenging to perform mainly because of two reasons: (i) packet loss is common for Bluetooth traffic, and (ii) modern operating systems use complex mouse acceleration strategies, which make it extremely difficult, if not impossible, to reconstruct the precise on-screen cursor coordinates from raw mouse movements. To address those challenges, we have conducted an extensive and careful study, over multiple operating systems, on the reconstruction of mouse cursor trajectory from raw mouse data and the inference of privacy-sensitive information - e.g., user password - from the reconstructed trajectory. Our experimental data demonstrate the severity of privacy leaking from un-encrypted Bluetooth mouse. To the best of our knowledge, our work is the first to retrieve sensitive information from sniffed mouse raw data. Video links of successful replay attack for different target OS are given in Section 3.2. Xian Pan, Zhen Ling 0001, Aniket Pingley, Wei Yu 0002, Nan Zhang 0004, Xinwen Fu |
CCS | 6 |
| 2012 | A Novel En-route Filtering Scheme against False Data Injection Attacks in Cyber-Physical Networked SystemsabstractIn Cyber-Physical Networked Systems (CPNS), attackers could inject false measurements to the controller through compromised sensor nodes, which not only threaten the security of the system, but also consumes network resources. To deal with this issue, a number of en-route filtering schemes have been designed for wireless sensor networks. However, these schemes either lack resilience to the number of compromised nodes or depend on the statically configured routes and node localization, which are not suitable for CPNS. In this paper, we propose a Polynomial-based Compromised-Resilient En-route Filtering scheme (PCREF), which can filter false injected data effectively and achieve a high resilience to the number of compromised nodes without relying on static routes and node localization. Particularly, PCREF adopts polynomials instead of MACs (message authentication codes) for endorsing measurement reports to achieve the resilience to attacks. Each node stores two types of polynomials: authentication polynomial and check polynomial derived from the primitive polynomial, and used for endorsing and verifying the measurement reports. Via extensive theoretical analysis and simulation experiments, our data show that PCREF achieves better filtering capacity and resilience to the large number of compromised nodes in comparison to the existing schemes. Xinyu Yang 0001, Jie Lin 0002, Paul Moulema, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
ICDCS | 5 |
| 2012 | Extensive analysis and large-scale empirical evaluation of tor bridge discoveryabstractTor is a well-known low-latency anonymous communication system that is able to bypass Internet censorship. However, publicly announced Tor routers are being blocked by various parties. To counter the censorship blocking, Tor introduced nonpublic bridges as the first-hop relay into its core network. In this paper, we analyzed the effectiveness of two categories of bridge-discovery approaches: (i) enumerating bridges from bridge https and email servers, and (ii) inferring bridges by malicious Tor middle routers. Large-scale experiments were conducted and validated our theoretic findings. We discovered 2365 Tor bridges through the two enumeration approaches and 2369 bridges by only one Tor middle router in 14 days. Our study shows that the bridge discovery based on malicious middle routers is simple, efficient and effective to discover bridges with little overhead. We also discussed the mechanisms to counter the malicious bridge discovery. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Ming Yang 0001, Xinwen Fu |
INFOCOM | 5 |
| 2012 | A novel network delay based side-channel attack: Modeling and defenseabstractInformation leakage via side channels has become a primary security threat to encrypted web traffic. Existing side channel attacks and corresponding countermeasures focus primarily on packet length, packet timing, web object size and web flow size. However, we found that encrypted web traffic can also leak information via network delay between a user and the web sites that she visits. Motivated by this observation, we investigate a novel network-delay based side-channel attack to infer web sites visited by a user. The adversary can utilize pattern recognition techniques to differentiate web sites by measuring sample mean and sample variance of the round-trip time (RTT) between a victim user and web sites. We theoretically analyzed the damage caused by such an adversary and derived closed-form formulae for detection rate, the probability that the adversary correctly recognizes a web site. To defeat this side-channel attack, we proposed several countermeasures. The basic idea is to shape traffic from different web sites so that they have similar RTT statistics. We proposed the strategies based on the k-means clustering and K-Anonymity to ensure that traffic shaping will not cause excessive delay while providing a predictable degree of anonymity. We conducted extensive experiments and our empirical results match our theory very well. Zhen Ling 0001, Junzhou Luo, Yang Zhang 0072, Ming Yang 0001, Xinwen Fu, Wei Yu 0002 |
INFOCOM | 5 |
| 2012 | HAWK: An unmanned mini helicopter-based aerial wireless kit for localizationabstractThis paper presents a fully functional and highly portable mini Unmanned Aerial Vehicle (UAV) system, HAWK, for conducting aerial localization. HAWK is a programmable mini helicopter - Draganflyer X6 - armed with a wireless sniffer - Nokia N900. We developed custom PI-Control laws to implement a robust waypoint algorithm for the mini helicopter to fly a planned route. A Moore space filling curve is designed as a flight route for HAWK to survey a specific area. A set of theorems were derived to calculate the minimum Moore curve level for sensing all targets in the area with minimum flight distance. With such a flight strategy, we can confine the location of a target of interest to a small hot area. We can recursively apply the Moore curve based flight route to the hot area for a fine-grained localization of a target of interest. Therefore, HAWK does not rely on a positioning infrastructure for localization. We have conducted extensive experiments to validate the feasibility of HAWK and our theory. A demo of HAWK in autonomous fly is available at http://www.youtube.com/watch?v=ju86xnHbEq0. Zhongli Liu, Yinjie Chen, Benyuan Liu, Chengyu Cao, Xinwen Fu |
INFOCOM | 5 |
| 2012 | Aerial Localization with Smartphone
Zhongli Liu, Yinjie Chen, Benyuan Liu, Jie Wang 0002, Xinwen Fu |
WASA | 5 |
| 2012 | A context-aware scheme for privacy-preserving location-based services
Aniket Pingley, Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Wei Zhao 0001 |
Comput. Networks | 4 |
| 2012 | HLLS: A History information based Light Location Service for MANETs
Xinyu Yang 0001, Xiaojing Fan, Wei Yu 0002, Xinwen Fu, Shusen Yang |
Comput. Networks | 4 |
| 2012 | The Digital Marauder's Map: A WiFi Forensic Positioning Toolabstract"The Marauder's Map,” a magical map in J.K. Rowling's fantasy series Harry Potter and the Prisoner of Azkaban [CHECK END OF SENTENCE], can be used as a surveillance tool to show all moving objects within the boundary of "Hogwarts School of Witchcraft and Wizardry” at a spell. In this paper, we introduce a similar forensic surveillance tool for wireless networks. Our system, the digital Marauder's map, can reveal the locations of WiFi-enabled mobile devices within the coverage area of a high-gain antenna. The digital Marauder's map is built solely with off-the-shelf wireless equipments, and features a mobile design that can be quickly deployed to a new location for instant usage without training. We present a comprehensive set of theoretical analysis and experimental results which demonstrate the coverage and localization accuracy of the digital Marauder's map. Xinwen Fu, Nan Zhang 0004, Aniket Pingley, Wei Yu 0002, Jie Wang 0002, Wei Zhao 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2012 | A New Cell-Counting-Based Attack Against TorabstractVarious low-latency anonymous communication systems such as Tor and Anonymizer have been designed to provide anonymity service for users. In order to hide the communication of users, most of the anonymity systems pack the application data into equal-sized cells (e.g., 512 B for Tor, a known real-world, circuit-based, low-latency anonymous communication network). Via extensive experiments on Tor, we found that the size of IP packets in the Tor network can be very dynamic because a cell is an application concept and the IP layer may repack cells. Based on this finding, we investigate a new cell-counting-based attack against Tor, which allows the attacker to confirm anonymous communication relationship among users very quickly. In this attack, by marginally varying the number of cells in the target traffic at the malicious exit onion router, the attacker can embed a secret signal into the variation of cell counter of the target traffic. The embedded signal will be carried along with the target traffic and arrive at the malicious entry onion router. Then, an accomplice of the attacker at the malicious entry onion router will detect the embedded signal based on the received cells and confirm the communication relationship among users. We have implemented this attack against Tor, and our experimental data validate its feasibility and effectiveness. There are several unique features of this attack. First, this attack is highly efficient and can confirm very short communication sessions with only tens of cells. Second, this attack is effective, and its detection rate approaches 100% with a very low false positive rate. Third, it is possible to implement the attack in a way that appears to be very difficult for honest participants to detect (e.g., using our hopping-based signal embedding). Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu, Dong Xuan, Weijia Jia 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2011 | Towards Effective En-Route Filtering against Injected False Data in Wireless Sensor NetworksabstractIn wireless sensor networks (WSNs), attackers could inject false data into the networks by compromising the sensor nodes. False data injected by the compromised nodes, if undetected, could not only cause false alarms but also consume the limited energy of the sensor nodes, posing serious threats to the lifetime of networks. To mitigate this type of attacks, a number of en-route filtering schemes to filter false data inside the networks have been developed in the past. However, there is lack of a systematical strategy to evaluate those schemes and establishing a foundation for designing en-route filtering techniques. To address these issues, we compare the pros and cons of the existing enroute filtering schemes. To fairly compare the performance of those schemes, we conduct theoretical analysis and derive a set of closed formulae for them. Our extensive simulations validate our findings. Our research summarizes the state-of-art research development and lay out future directions in this area. Jie Lin 0002, Xinyu Yang 0001, Wei Yu 0002, Xinwen Fu |
GLOBECOM | 4 |
| 2011 | Equal-Sized Cells Mean Equal-Sized Packets in Tor?abstractTor is a well-known low-latency anonymous communication system. To prevent the traffic analysis attack, Tor packs application data into equal-sized cells. However, we found that equal-sized cells at the application layer do not necessarily produce equal-sized packets at the network layer. Therefore, we introduced a packet size based attack that compromises Tor's communication anonymity with no need of controlling Tor routers. An attacker can manipulate size of packets between a web site and an exit onion router and embeds a signal into the target traffic. An accomplice at the user side can sniff the traffic and recognize this signal. To cope with the signal distortion incurred by Tor and Internet, we developed an effective signal recovery mechanism. Our real-world experiments validate the effectiveness of our attack against Tor. Our work demonstrates the need for re-considering the issue of padding anonymous communication data into equal size. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu |
ICC | 4 |
| 2011 | Identifying mobiles hiding behind wireless routersabstractThe network address translation technique (NAT) is widely used in wireless routers. It is a low cost solution to IPv4 address space limitations. However, cyber criminals may abuse NAT and hide behind wireless routers to use mobile devices and conduct crimes. To identify a suspect mobile device, we should be able to map the suspect public traffic on the Internet to the private traffic behind the wireless router in WLAN. In this paper, we propose a suite of novel packet size based traffic marking techniques to identify suspect mobiles in encrypted wireless networks as well as open wireless networks. To cope with severe packet loss during wireless sniffing, we proposed to use error correcting codes to improve detection rate. We conducted extensive analysis and experiments to demonstrate the efficiency and accuracy of our schemes, which achieve high detection rate and very small false positive rate. The proposed strategies can be used for law enforcement for combatting cyber crimes in wireless network crime scene investigations. Yinjie Chen, Zhongli Liu, Benyuan Liu, Xinwen Fu, Wei Zhao 0001 |
INFOCOM | 4 |
| 2011 | Long PN code based DSSS watermarkingabstractCyber crimes often involve complicated scenes. In this paper, we investigate unidentified crimes committed through anonymous communication networks. We developed a long Pseudo-Noise (PN) code based Direct Sequence Spread Spectrum (DSSS) flow marking technique for invisibly tracing suspect anonymous flows. By interfering with a sender's traffic and marginally varying its rate, an investigator can embed a secret spread spectrum signal into the sender's traffic. Each signal bit is modulated with a small segment of a long PN code. By tracing where the embedded signal goes, the investigator can trace the sender and receiver of the suspect flow despite the use of anonymous networks. Benefits of the Long PN code include its resistance to previous discovered detection approaches. We may also use the vast number of long PN code at different phases to conduct parallel tracback without worrying about the interference between codes. Using a combination of analytical modeling and experiments on Anonymizer, we demonstrate the effectiveness of the long PN code based DSSS watermarking technique. Junwei Huang, Xian Pan, Xinwen Fu, Jie Wang 0002 |
INFOCOM | 3 |
| 2011 | A novel packet size based covert channel attack against anonymizerabstractAnonymizer is a proprietary anonymous communication system. We discovered its architecture and found that the size of web packets through Anonymizer are very dynamic at the client. Motivated by this finding, we investigated a novel packet size based covert channel attack, against the anonymity service. In the attack, one attacker manipulates the web packet size between the web server and Anonymizer and embed signal symbols into the target traffic. An accomplice at the user side can sniff the traffic and recognize the secret signal. We developed intelligent and robust algorithms to cope with the packet size distortion incurred by Anonymizer and Internet. We developed several techniques to make the attack harder to detect: (i) We pick up right packets of web objects to manipulate in order to preserve the regularity of the TCP packet size dynamics; (ii) We adopt the Monte Carlo sampling technique to preserve the distribution of the web packet size despite manipulation. We have implemented the attack over Anonymizer and conducted extensive analysis and experimental evaluations. It is observed that the attack is highly efficient and requires only tens of packets to compromise the anonymous web surfing. The experimental results are consistent with our theoretical analysis. Zhen Ling 0001, Xinwen Fu, Weijia Jia 0001, Wei Yu 0002, Dong Xuan |
INFOCOM | 2 |
| 2011 | Protection of query privacy for continuous location based servicesabstractLocation-based services (LBS) have become an immensely valuable source of real-time information and guidance. Nonetheless, the potential abuse of users' sensitive personal data by an LBS server is evolving into a serious concern. Privacy concerns in LBS exist on two fronts: location privacy and query privacy. In this paper we investigate issues related to query privacy. In particular, we aim to prevent the LBS server from correlating the service attribute, e.g., bar/tavern, in the query to the user's real-world identity. Location obfuscation using spatial generalization aided by anonymization of LBS queries is a conventional means to this end. However, effectiveness of this technique would abate in continuous LBS scenarios, i.e., where users are moving and recurrently requesting for LBS. In this paper, we present a novel query-perturbation-based scheme that protects query privacy in continuous LBS even when user-identities are revealed. Unlike most exiting works, our scheme does not require the presence of a trusted third party. Aniket Pingley, Nan Zhang 0004, Xinwen Fu, Hyeong-Ah Choi, Suresh Subramaniam 0001, Wei Zhao 0001 |
INFOCOM | 3 |
| 2011 | On sampling signal strength for localization using a directional antennaabstractPositioning wireless mobiles has been widely studied. However, issues on efficiency and accuracy are not fully considered in the design of most positioning techniques. In this paper, we analyze the performance of localization of wireless mobiles with the knowledge of signal sampling theory. We propose a general approach of locating a wireless mobile device using a directional antenna, and we prove that the correctness of localization depends on the setting of the signal sampling rate. We derived a set of theorems to judge the time cost of localization in order to achieve a certain degree of accuracy. These theorems cover different types of directional antennas for signal strength sampling so that we can utilize them to enhance the positioning accuracy. We conduct extensive simulations to demonstrate the effectiveness and accuracy of our theory. Yinjie Chen, Zhongli Liu, Xinwen Fu |
WOWMOM | 4 |
| 2010 | HLLS: A History Information Based Light Location Service for MANETsabstractIn mobile ad hoc networks, location service (LS) is critical and provides the fundamental service for geographic routing. However, most existing schemes for location service incur a high overhead because of the periodical updates of location information. In this paper, we intend to address this issue. Using the temporal relationship among historical locations of mobiles in the network, we propose a novel History information based Light Location Service (HLLS). In HLLS, location information of mobiles is propagated via Hello beacons locally, and location query is performed in a tracing manner with the aid of historical locations. In such a way, HLLS can eliminate the tremendous periodical location updates and significantly reduce the overhead for location service. Using extensive simulations, we demonstrate the effectiveness of HLLS in terms of high accuracy and low overhead. Xiaojing Fan, Xinyu Yang 0001, Wei Yu 0002, Xinwen Fu |
ICC | 4 |
| 2010 | 3DLoc: Three Dimensional Wireless Localization ToolkitabstractIn this paper, we present 3DLoc: an integrated system of hardware and software toolkits for locating an 802.11-compliant mobile device in a three dimensional (3D) space. 3DLoc features two specialized antennas: an azimuth antenna and an elevation antenna, for detecting the azimuth and elevation angles of a mobile device respectively in real time. To improve positioning accuracy in real-world urban settings, we propose various signal processing techniques such as clustering and wavelet-transform based denoising, and present theoretical analysis of the accuracy of these techniques. With different antenna configurations, 3DLoc is able to track single or multiple targets in one round of azimuth scanning and elevation scanning. We conduct extensive experiments to demonstrate the efficiency and accuracy of 3DLoc. 3DLoc can be used in various applications, including wireless network forensics for locating anonymous criminal mobile devices. Jizhi Wang, Yinjie Chen, Xinwen Fu, Jie Wang 0002, Wei Yu 0002, Nan Zhang 0004 |
ICDCS | 3 |
| 2010 | Barrier coverage with sensors of limited mobilityabstractBarrier coverage is a critical issue in wireless sensor networks for various battlefield and homeland security applications. The goal is to effectively detect intruders that attempt to penetrate the region of interest. A sensor barrier is formed by a connected sensor cluster across the entire deployed region, acting as a "trip wire" to detect any crossing intruders. In this paper we study how to efficiently improve barrier coverage using mobile sensors with limited mobility. After the initial deployment, mobile sensors can move to desired locations and connect with other sensors in order to create new barriers. However, simply moving sensors to form a large local cluster does not necessarily yield a global barrier. This global nature of barrier coverage makes it a challenging task to devise effective sensor mobility schemes. Moreover, a good sensor mobility scheme should efficiently improve barrier coverage under the constraints of available mobile sensors and their moving range. We first explore the fundamental limits of sensor mobility on barrier coverage and present a sensor mobility scheme that constructs the maximum number of barriers with minimum sensor moving distance. We then present an efficient algorithm to compute the existence of barrier coverage with sensors of limited mobility, and examine the effects of the number of mobile sensors and their moving ranges on the barrier coverage improvement. Both the analytical results and performance of the algorithms are evaluated via extensive simulations. Anwar Saipulla, Benyuan Liu, Guoliang Xing, Xinwen Fu, Jie Wang 0002 |
MobiHoc | 4 |
| 2010 | Generic network forensic data acquisition from household and small business wireless routersabstractPeople are benefiting tremendously from pervasively deployed WiFi networks. However, criminals may exploit the anonymity of WiFi communication and wireless routers to access illegal content such as child porn videos. It's becoming an urgent topic as regards to how to preserve and acquire network forensic data from household and small business wireless routers in order to track down criminals. In this paper, we first survey the forensic capacity of nearly all household wireless routers which are available on market. We present our analysis for people who are willing to choose a wireless router to monitor their network. Secondly, we develop a generic network forensic data logging mechanism to monitor traffic into and out of wireless routers which support OpenWrt. Our code running in the wireless routers could log network traffic and send connection information to the administrator via email. Zhongli Liu, Yinjie Chen, Wei Yu 0002, Xinwen Fu |
WOWMOM | 4 |
| 2010 | Localization Attacks to Internet Threat Monitors: Modeling and CountermeasuresabstractAbstract—Internet Threat Monitoring (ITM) systems are a widely deployed facility to detect, analyze, and characterize dangerous Internet threats such as worms and distributed denial-of-service (DDoS) attacks. Nonetheless, an ITM system can also become the target of attacks. In this paper, we address localization attacks against ITM systems in which an attacker impairs the effectiveness of an ITM system by identifying the locations of ITM monitors. We propose an information-theoretic framework that models localization attacks as communication channels. Based on this model, we generalize all existing attacks as “temporal attacks”, derive closed formulae of their performance, and propose an effective attack detection approach. The information-theoretic model also inspires a new attack called a spatial attack and motivates the corresponding detection approach. We show simulation results that support our theoretic findings. Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Computers | 3 |
| 2010 | Self-Disciplinary Worms and Countermeasures: Modeling and AnalysisabstractIn this paper, we address issues related to the modeling, analysis, and countermeasures of worm attacks on the Internet. Most previous work assumed that a worm always propagates itself at the highest possible speed. Some newly developed worms (e.g., “Atak” worm) contradict this assumption by deliberately reducing the propagation speed in order to avoid detection. As such, we study a new class of worms, referred to as self-disciplinary worms. These worms adapt their propagation patterns in order to reduce the probability of detection, and eventually, to infect more computers. We demonstrate that existing worm detection schemes based on traffic volume and variance cannot effectively defend against these self-disciplinary worms. To develop proper countermeasures, we introduce a game-theoretic formulation to model the interaction between the worm propagator and the defender. We show that an effective integration of multiple countermeasure schemes (e.g., worm detection and forensics analysis) is critical for defending against self-disciplinary worms. We propose different integrated schemes for fighting different self-disciplinary worms, and evaluate their performance via real-world traffic data. Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Wei Zhao 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2010 | Correlation-Based Traffic Analysis Attacks on Anonymity NetworksabstractIn this paper, we address attacks that exploit the timing behavior of TCP and other protocols and applications in low-latency anonymity networks. Mixes have been used in many anonymous communication systems and are supposed to provide countermeasures to defeat traffic analysis attacks. In this paper, we focus on a particular class of traffic analysis attacks, flow-correlation attacks, by which an adversary attempts to analyze the network traffic and correlate the traffic of a flow over an input link with that over an output link. Two classes of correlation methods are considered, namely time-domain methods and frequency-domain methods. Based on our threat model and known strategies in existing mix networks, we perform extensive experiments to analyze the performance of mixes. We find that all but a few batching strategies fail against flow-correlation attacks, allowing the adversary to either identify ingress and egress points of a flow or to reconstruct the path used by the flow. Counterintuitively, some batching strategies are actually detrimental against attacks. The empirical results provided in this paper give an indication to designers of Mix networks about appropriate configurations and mechanisms to be used to counter flow-correlation attacks. Ye Zhu 0001, Xinwen Fu, Bryan Graham, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2010 | Maintaining Defender's Reputation in Anomaly Detection Against Insider AttacksabstractWe address issues related to establishing a defender's reputation in anomaly detection against two types of attackers: 1) smart insiders, who learn from historic attacks and adapt their strategies to avoid detection/punishment, and 2) naïve attackers, who blindly launch their attacks without knowledge of the history. In this paper, we propose two novel algorithms for reputation establishment--one for systems solely consisting of smart insiders and the other for systems in which both smart insiders and naïve attackers are present. The theoretical analysis and performance evaluation show that our reputation-establishment algorithms can significantly improve the performance of anomaly detection against insider attacks in terms of the tradeoff between detection and false positives. Nan Zhang 0004, Wei Yu 0002, Xinwen Fu, Sajal K. Das 0001 |
IEEE Trans. Syst. Man Cybern. Part B | 3 |
| 2009 | A new cell counter based attack against torabstractVarious low-latency anonymous communication systems such as Tor and Anoymizer have been designed to provide anonymity service for users. In order to hide the communication of users, many anonymity systems pack the application data into equal-sized cells (e.g., 512 bytes for Tor, a known real-world, circuit-based low-latency anonymous communication network). In this paper, we investigate a new cell counter based attack against Tor, which allows the attacker to confirm anonymous communication relationship among users very quickly. In this attack, by marginally varying the counter of cells in the target traffic at the malicious exit onion router, the attacker can embed a secret signal into the variation of cell counter of the target traffic. The embedded signal will be carried along with the target traffic and arrive at the malicious entry onion router. Then an accomplice of the attacker at the malicious entry onion router will detect the embedded signal based on the received cells and confirm the communication relationship among users. We have implemented this attack against Tor and our experimental data validate its feasibility and effectiveness. There are several unique features of this attack. First, this attack is highly efficient and can confirm very short communication sessions with only tens of cells. Second, this attack is effective and its detection rate approaches 100% with a very low false positive rate. Third, it is possible to implement the attack in a way that appears to be very difficult for honest participants to detect (e.g. using our hopping-based signal embedding). Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu, Dong Xuan, Weijia Jia 0001 |
CCS | 4 |
| 2009 | The Digital Marauder's Map: A New Threat to Location Privacyabstract"The Marauder's Map" is a magical map in J. K. Rowling's fantasy series, "Harry Potter and the Prisoner of Azkaban". It shows all moving objects within the boundary of the "Hogwarts School of Witchcraft and Wizardry". In this paper, we introduce a similar attack to location privacy in wireless networks. Our system, namely the digital Marauder's map, can reveal the locations of WiFi-enabled mobile devices within the coverage area of a single high-gain antenna. The digital Marauder's map is built solely with off-the-shelf wireless equipments, and features a mobile design that can be quickly deployed to a new location and instantly used without training. We present a comprehensive set of theoretical analysis and experimental results which demonstrate the coverage and localization accuracy of the digital Marauder's map. Xinwen Fu, Nan Zhang 0004, Aniket Pingley, Wei Yu 0002, Jie Wang 0002, Wei Zhao 0001 |
ICDCS | 1 |
| 2009 | CAP: A Context-Aware Privacy Protection System for Location-Based ServicesabstractWe address issues related to privacy protection in location-based services (LBS). Most existing research in this field either requires a trusted third-party (anonymizer) or uses oblivious protocols that are computationally and communicationally expensive. Our design of privacy-preserving techniques is principled on not requiring a trusted third-party while being highly efficient in terms of time and space complexities. The problem has two interesting and challenging characteristics: First, the degree of privacy protection and LBS accuracy depends on the context, such as population and road density, around a user's location. Second, an adversary may violate a user's location privacy in two ways: (i) based on the user's location information contained in the LBS query payload, and (ii) by inferring a user's geographical location based on its device's IP address. To address these challenges, we introduce CAP, a Context-Aware Privacy-preserving LBS system with integrated protection for data privacy and communication anonymity. We have implemented CAP and integrated it with Google Maps, a popular LBS system. Theoretical analysis and experimental results validate CAP's effectiveness on privacy protection, LBS accuracy, and communication Quality-of-Service. Aniket Pingley, Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Wei Zhao 0001 |
ICDCS | 4 |
| 2009 | Blind Detection of Spread Spectrum Flow WatermarksabstractRecently, the direct sequence spread-spectrum (DSSS)-based technique has been proposed to trace anonymous network flows. In this technique, homogeneous pseudo-noise (PN) codes are used to modulate multiple-bit signals that are embedded into the target flow as watermarks. This technique could be maliciously used to degrade an anonymous communication network. In this paper, we propose a simple single flow-based scheme to detect the existence of these watermarks. Our investigation shows that even if we have no knowledge of the applied PN code, we are still able to detect malicious DSSS watermarks via mean-square autocorrelation (MSAC) of a single modulated flow's traffic rate time series. MSAC shows periodic peaks due to self-similarity in the modulated traffic caused by homogeneous PN codes that are used in modulating multiple-bit signals. Our scheme has low complexity and does not require any PN-code synchronization. We evaluate this detection scheme's effectiveness via simulations and real-world experiments on Tor. Our results demonstrate a high detection rate with a low false positive rate. Our scheme is more flexible and accurate than an existing multi-flow-based approach in DSSS watermark detection. Weijia Jia 0001, Fung Po Tso 0001, Zhen Ling 0001, Xinwen Fu, Dong Xuan, Wei Yu 0002 |
INFOCOM | 4 |
| 2009 | Utopia Providing Trusted Social Network Relationships within an Un-trusted Environment
William Gauvin, Benyuan Liu, Xinwen Fu, Jie Wang 0002 |
WASA | 3 |
| 2009 | Discovery and Protection of Sensitive Linkage Information for Online Social Networks Services
Nan Zhang 0004, Min Song 0002, Xinwen Fu, Wei Yu 0002 |
WASA | 3 |
| 2009 | TCP Performance in Flow-Based Mix Networks: Modeling and AnalysisabstractAnonymity technologies such as mix networks have gained increasing attention as a way to provide communication privacy. Mix networks were developed for message-based applications such as e-mail, but researchers have adapted mix techniques to low-latency flow-based applications such as anonymous Web browsing. Although a significant effort has been directed at discovering attacks against anonymity networks and developing countermeasures to those attacks, there is little systematic analysis of the quality of service (QoS) for such security and privacy systems. In this paper, we systematically address TCP performance issues of flow-based mix networks. A mix's batching and reordering schemes can dramatically reduce TCP throughput due to out-of-order packet delivery. We developed a theoretical model to analyze such impact and present formulas for approximate TCP throughput in mix networks. To improve TCP performance, we examined the approach of increasing TCP's duplicate threshold parameter and derived formulas for the performance gains. Our proposed approaches will not degrade the system anonymity degree since they do not change the underlying anonymity mechanism. Our data matched our theoretical analysis well. Our developed theoretical model can guide the deployment of batching and reordering schemes in flow-based mix networks and can also be used to investigate a broad range of reordering schemes. Xinwen Fu, Wei Yu 0002, Steve Graham |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2009 | An Invisible Localization Attack to Internet Threat MonitorsabstractInternet threat monitoring (ITM) systems have been deployed to detect widespread attacks on the Internet in recent years. However, the effectiveness of ITM systems critically depends on the confidentiality of the location of their monitors. If adversaries learn the monitor locations of an ITM system, they can bypass the monitors and focus on the uncovered IP address space without being detected. In this paper, we study a new class of attacks, the invisible LOCalization (iLOC) attack. The iLOC attack can accurately and invisibly localize monitors of ITM systems. In the iLOC attack, the attacker launches low-rate port-scan traffic, encoded with a selected pseudonoise code (PN-code), to targeted networks. While the secret PN-code is invisible to others, the attacker can accurately determine the existence of monitors in the targeted networks based on whether the PN-code is embedded in the report data queried from the data center of the ITM system. We formally analyze the impact of various parameters on attack effectiveness. We implement the iLOC attack and conduct the performance evaluation on a real-world ITM system to demonstrate the possibility of such attacks. We also conduct extensive simulations on the iLOC attack using real-world traces. Our data show that the iLOC attack can accurately identify monitors while being invisible to ITM systems. Finally, we present a set of guidelines to counteract the iLOC attack. Wei Yu 0002, Xun Wang 0009, Xinwen Fu, Dong Xuan, Wei Zhao 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2008 | On localization attacks to Internet Threat Monitors: An information-theoretic frameworkabstractInternet threat monitoring (ITM) systems are a widely deployed facility to detect, analyze, and characterize dangerous Internet threats such as worms and distributed denial-of-service (DDoS) attacks. Nonetheless, an ITM system can also become the target of attack. In this paper, we address localization attacks against ITM systems in which an attacker impairs the effectiveness of ITM systems by identifying the locations of ITM monitors. We propose an information-theoretic framework for the modeling of localization attacks as communication channels. Based on the information-theoretic model, we generalize all existing attacks as ldquotemporal attacksrdquo, derive closed formulae of their performance, and propose an effective detection approach. The information-theoretic model also inspires a new attack called a spatial attack and motivates the corresponding detection approach. We show simulation results that support our theoretic findings. Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
DSN | 3 |
| 2008 | A New Replay Attack Against Anonymous Communication NetworksabstractTor is a real-world, circuit-based low-latency anonymous communication network, supporting TCP applications on the Internet. In this paper, we present a new class of attack, the replay attack, against Tor. Compared with other existing attacks, the replay attack can confirm communication relationships quickly and accurately and poses a serious threat against Tor. In this attack, a malicious entry onion router duplicates cells of a stream from a sender. The original cell and duplicate cell traverse middle onion routers and arrive at an exit onion router along a circuit. Since Tor uses the counter mode AES (AES-CTR) for encryption of cells, the duplicate cell disrupts the normal counter at middle and exit onion routers and the decryption at the exit onion router incurs cell recognition errors. If an accomplice of the attacker at the entry onion router controls the exit onion router and detects such decryption errors, the communication relationship between the sender and receiver will be discovered. The replay attack can also be used as a denial of service attack. We implement the replay attack on Tor and our experiments validate the feasibility and effectiveness of the attack. We also present guidelines to defending against the replay attack. Ryan Pries, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
ICC | 3 |
| 2008 | Towards Effective Defense Against Insider Attacks: The Establishment of Defender's ReputationabstractWe address issues related to the establishment of defender's reputation in anomaly detection against insider attacks. We consider two types of attackers: smart insiders, which learn from historic attacks and adapt their strategies to avoid detection/punishment, and naive attackers, which blindly launch their attacks. We introduce two novel reputation-establishment algorithms for systems with solely smart insiders and systems with both smart insiders and naive attackers, respectively. Theoretical analysis and simulation results show that our reputation-establishment algorithms can significantly improve the performance of anomaly detection against insider attacks in terms of the tradeoff between detection and false positives. Nan Zhang 0004, Wei Yu 0002, Xinwen Fu, Sajal K. Das 0001 |
ICPADS | 3 |
| 2008 | iLOC: An invisible LOCalization Attack to Internet Threat Monitoring SystemsabstractIn this paper, we study a new class of attacks, theinvisibleLOCalization (iLOC) attack, which can accurately and invisibly localize monitors of Internet threat monitoring (ITM) systems, a class of widely deployed facilities to characterize Internet threats, such as worm propagation, denial-of-service (DoS) attacks. In theiLOCattack, the attacker launches low-rate port-scan traffic, encoded with a selectedpseudo-noisecode(PN- code), to targeted networks. While the secret PN-code is invisible to others, the attacker can accurately determine the existence of monitors in the targeted networks based on whether the PN-code is embedded in the report data queried from the data center of the ITM system. We conduct extensive simulations on theiLOCattack using real-world traces. Our data demonstrate that theiLOCattack can accurately identify monitors while remaining invisible to the ITM. Finally, we present a set of guidelines to counteract theiLOCattack. Xun Wang 0009, Wei Yu 0002, Xinwen Fu, Dong Xuan, Wei Zhao 0001 |
INFOCOM | 3 |
| 2008 | On performance bottleneck of anonymous communication networksabstractAlthough a significant amount of effort has been directed at discovering attacks against anonymity communication networks and developing countermeasures to those attacks, there is little systematic analysis of the Quality of Service (QoS) for such privacy preserving systems. In this paper, we initiate the effort to study the QoS of Tor, a popular and representative implementation of anonymous communication networks on the Internet. We find that Tor suffers severe TCP performance degradation because of its random path selection strategy. Our investigation shows that Tor’s bandwidth weighted path selection algorithm can only improve the performance to a very limited extent. We analyze this performance issue from the perspective of overlay networks and model the TCP throughput of Tor. We conduct extensive experiments on the real-world Tor network and the experimental results validate our theory. We also discuss possible remedies to this performance issue. Ryan Pries, Wei Yu 0002, Steve Graham, Xinwen Fu |
IPDPS | 4 |
| 2007 | On TCP Performance in Flow-Based Mix NetworksabstractAnonymity technologies such as mix networks have gained increasing attention as a way to provide communication privacy. Mix networks were developed for message-based applications such as email, but researchers have adapted mix techniques to low-latency, flow-based applications such as anonymous web browsing. In this paper, we systematically address TCP performance issues of flow-based mix networks. We explain why a mix's batching and reordering schemes can dramatically reduce TCP throughput due to out-of-order packet delivery. We developed a theoretical model to analyze such impact and present closed formulae for TCP throughput in mix networks. To improve TCP performance, we examined the approach of increasing TCP's duplicate threshold parameter and derived closed formulae for the performance gains. Our simulation results matched our theoretical analysis well. Xinwen Fu, Wei Yu 0002, Steve Graham |
DASC | 1 |
| 2007 | DSSS-Based Flow Marking Technique for Invisible TracebackabstractLaw enforcement agencies need the ability to conduct electronic surveillance to combat crime, terrorism, or other malicious activities exploiting the Internet. However, the proliferation of anonymous communication systems on the Internet has posed significant challenges to providing such traceback capability. In this paper, we develop a new class of flow marking technique for invisible traceback based on direct sequence spread spectrum (DSSS), utilizing a pseudo-noise (PN) code. By interfering with a sender's traffic and marginally varying its rate, an investigator can embed a secret spread spectrum signal into the sender's traffic. The embedded signal is carried along with the traffic from the sender to the receiver, so the investigator can recognize the corresponding communication relationship, tracing the messages despite the use of anonymous networks. The secret PN code makes it difficult for others to detect the presence of such embedded signals, so the traceback, while available to investigators is, effectively invisible. We demonstrate a practical flow marking system which requires no training, and can achieve both high detection and low false positive rates. Using a combination of analytical modeling, simulations, and experiments on Tor (a popular Internet anonymous communication system), we demonstrate the effectiveness of the DSSS-basedflow marking technique. Wei Yu 0002, Xinwen Fu, Steve Graham, Dong Xuan, Wei Zhao 0001 |
S&P | 2 |
| 2006 | On Recognizing Virtual Honeypots and CountermeasuresabstractHoneypots are decoys designed to trap, delay, and gather information about attackers. We can use honeypot logs to analyze attackers' behaviors and design new defenses. A virtual honeypot can emulate multiple honeypots on one physical machine and provide great flexibility in repesenting one or more networks of machines. But when attackers recognize a honeypot, it becomes useless. In this paper, we address issues related to detecting and "camouflaging" virtual honeypots, in particular Honeyd, which can emulate any size of network on physical machines. We find that an attacker may remotely fingerprint Honeyd by measuring the latency of the network links emulated by Honeyd. We analyze the threat from this fingerprint attack based on the Neyman-Pearson decision theory and find that this class of attack can achieve a high detection rate and low false alarm rate. In order to counter this fingerprint attack, we make virtual honeypots behave like their surrounding networks and blend in with their surroundings. We design a camouflaged Honeyd by revising a small part of the Honeyd toolkit code and by appropriately patching the operating system. Our experiments demonstrate the effectiveness of our approach to camouflaging Honeyd. Xinwen Fu, Wei Yu 0002, Dan Cheng, Xuejun Tan, Kevin Streff, Steve Graham |
DASC | 1 |
| 2005 | Anonymity analysis of mix networks against flow-correlation attacksabstractMix networks are designed to provide anonymity for users in a variety of applications, including anonymous Web browsing and numerous E-commerce systems. Such networks have been shown to be susceptible to flow correlation attacks empirically. In this paper, we model the effectiveness of flow correlation attacks. Our results illustrate the quantitative relationship among system parameters such as sample size, noise level, payload flow rate, and detection rate. Our analysis quantitatively predicts how existing flow-based anonymous systems would fail under flow-correlation attacks, thus providing useful guidelines for the design of future anonymous systems. Ye Zhu 0001, Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
GLOBECOM | 2 |
| 2005 | On Flow Marking Attacks in Wireless Anonymous Communication NetworksabstractThis paper studies the degradation of anonymity in a flow-based wireless mix network under flow marking attacks, in which an adversary embeds a recognizable pattern of marks into wireless traffic flows by electromagnetic interference. We find that traditional mix technologies are not effective in defeating flow marking attacks, and it may take an adversary only a few seconds to recognize the communication relationship between hosts by tracking such artificial marks. Flow marking attacks utilize frequency domain analytical techniques and convert time domain marks into invariant feature frequencies. To counter flow marking attacks, we propose a new countermeasure based on digital filtering technology, and show that this filter-based counter-measure can effectively defend a wireless mix network from flow marking attacks. Xinwen Fu, Ye Zhu 0001, Bryan Graham, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 1 |
| 2005 | On the Effectiveness of Continuous-Time Mixes under Flow-Correlation Based Anonymity AttacksabstractIn flow-based mix networks, so-called flow correlation attacks have been proposed earlier and have been shown empirically to seriously degrade mix-based anonymous communication systems. In this paper, we theoretically analyze the effectiveness of a mix network under flow correlation attacks. Our formulae clearly show how a mix network will ultimately fail when an adversary has access to sufficiently long flow samples, independently of the type of flows (TCP or UDP). We illustrate the analysis methodology by modeling a continuous-time mix, which randomly delays each incoming packet. Our queuing-model-based analysis captures the essence of flow correlation attacks and can provide useful guidelines for designers who develop and deploy anonymity systems Ye Zhu 0001, Xinwen Fu, Riccardo Bettati |
NCA | 2 |
| 2004 | A quantitative analysis of anonymous communicationsabstractThis paper quantitatively analyzes anonymous communication systems (ACS) with regard to anonymity properties. Various ACS have been designed & implemented. However, there are few formal & quantitative analyzes on how these systems perform. System developers argue the security goals which their systems can achieve. Such results are vague & not persuasive. This paper uses a probabilistic method to investigate the anonymity behavior of ACS. In particular, this paper studies the probability that the true identity of a sender can be discovered in an ACS, given that some nodes have been compromised. It is through this analysis that design guidelines can be identified for systems aimed at providing communication anonymity. For example, contrary to what one would intuitively expect, these analytic results show that the probability that the true identity of a sender can be discovered might not always decrease as the length of communication path increases. Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Reliab. | 2 |
| 2003 | On Effectiveness of Link Padding for Statistical Traffic Analysis AttacksabstractTraffic analysis attacks aim at deriving mission critical information from the analysis of the traffic transmitted over a network. Countermeasures for such attacks are usually realized by properly "padding" the payload traffic so that the statistics of the overall traffic become significantly different from that of the payload traffic. In this paper, we propose a analytical framework for traffic analysis attacks based on statistical pattern recognition techniques. We study the effectiveness of countermeasures for traffic analysis attacks within our proposed framework. Two basic countermeasure strategies are (a) to pad the traffic with constant interarrival times of packets (CIT) or (b) to pad the traffic with variable interarrival times (VIT). Our experiments show that CIT countermeasures fail when the adversary uses sample variance or sample entropy of packet interarrival times for statistical analysis. On the other hand, VIT countermeasures are effective regardless of which sample statistics are used by the adversary. These observations are validated by analysis of detection rates based on sample distributions of packet interarrival times. Xinwen Fu, Bryan Graham, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 1 |
| 2003 | Analytical and Empirical Analysis of Countermeasures to Traffic Analysis AttacksabstractWe study countermeasures to traffic analysis attacks. A common strategy for such countermeasures is link padding. We consider systems where payload traffic is padded so that packets have either constant inter-arrival times or variable inter-arrival times. The adversary applies statistical recognition techniques to detect the payload traffic rates by using statistical measures like sample mean, sample variance, or sample entropy. We evaluate quantitatively the ability of the adversary to make a correct detection and derive closed-form formulas for the detection rate based on analytical models. Extensive experiments were carried out to validate the system performance predicted by the analytical method. Based on the systematic evaluations, we develop design guidelines for the proper configuration of a system in order to minimize the detection rate Xinwen Fu, Bryan Graham, Riccardo Bettati, Wei Zhao 0001, Dong Xuan |
ICPP | 1 |
| 2002 | An Optimal Strategy for Anonymous Communication ProtocolsabstractFor many Internet applications, the ability to protect the identity of participants in a distributed applications is critical. For such applications, a number of anonymous communication systems have been realized over the recent years. The effectiveness of these systems relies greatly on the way messages are routed among the participants. (We call this the route selection strategy.) In this paper we describe how to select routes so as to maximize the ability of the anonymous communication systems to protect anonymity To measure this ability, we define a metric (anonymity degree), and we design and evaluate an optimal route selection strategy that maximizes the anonymity degree of a system. Our analytical and experimental data shows that the anonymity degree may not always monotonically increase as the length of communication paths increase. We also found that variable path-length strategies perform better than fixed-length strategies. Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 2 |
| 2001 | NetCamo: camouflaging network traffic for QoS-guaranteed mission critical applicationsabstractThis paper presents the general approach, design, implementation, and evaluation of NetCamo, which is a system to prevent traffic analysis in systems with real-time requirements. Integrated support for both security and real-time is becoming necessary for computer networks that support mission critical applications. This study focuses on how to integrate both the prevention of traffic analysis and guarantees for worst-case delays in an internetwork. We propose and analyze techniques that efficiently camouflage network traffic and correctly plan and schedule the transmission of payload traffic so that both security and real-time requirements are met. The performance evaluation shows that our NetCamo system is effective and efficient. By using the error between target camouflaged traffic and the observed (camouflaged) traffic as metric to measure the quality of the camouflaging, we show that NetCamo achieves very high levels of camouflaging without compromising real-time requirements. Xinwen Fu, Dong Xuan, P. U. Shenoy, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Syst. Man Cybern. Part A | 2 |