VLDB 2026 Research / reviewers in the wild / expert
Guan-Hua Tu
dblp:63/2218
· DBLP profile ↗
36ranked-venue papers
5as first author
17since 2021 · last 2026
0000-0002-2542-4817ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 27 · 4 first-author · 14 since 2021Security and privacy · 6 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Insecurity of Lost/Stolen Phone Reporting Services: Vulnerabilities, Attacks, and CountermeasuresabstractLost and stolen phone reporting services are widely deployed to prevent unauthorized device use by blacklisting International Mobile Equipment Identities (IMEIs). However, through an extensive experimental study across three major U.S. carriers and diverse mobile devices, we discover that these services unexpectedly introduce severe and previously unexplored security risks. Specifically, we identify six new vulnerabilities spanning the device, carrier, and cross-carrier domains, which together enable attackers to arbitrarily block cellular devices from accessing carrier networks. Building on these findings, we design and validate two practical denial-of-service (DoS) attacks: Home Security System Freezing, which disables cellular-based home security gateways and blocks alarm delivery, and Zero-Day Flagship Phone Ambush, which preemptively blocks brand-new flagship phones from accessing mobile services at launch. Both attacks are experimentally validated on operational 5G/4G networks. Finally, we propose practical, backward-compatible countermeasures and implement a prototype to evaluate their effectiveness. Min-Yue Chen, Yiwen Hu 0002, Yu-An Chen, Chi-Yu Li 0001, Tian Xie 0001, Guan-Hua Tu |
MobiSys | 6 |
| 2026 | When Mobile Equipment Security Lags Behind Infrastructure: Vulnerabilities, Attacks, and Countermeasures in IMS Services
Jingwen Shi, Min-Yue Chen, Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Yiwen Hu 0002, Man-Hsin Chen, Haitian Yan, Chi-Yu Li 0001, Chunyi Peng 0001 |
IEEE Trans. Netw. | 4 |
| 2025 | PDCA: Practical Dynamic Client Association in Wi-Fi Mesh Networks Using EasymeshabstractWi-Fi mesh networks have become critical for extending Wi-Fi coverage. Their underlying technologies have evolved from the decentralized IEEE 802.11s standard to the newly introduced EasyMesh, which operates in a centralized manner. However, neither approach can dynamically adapt Access Point (AP) and client association control to optimize throughput performance. Although EasyMesh can steer clients to a mesh AP from a centralized controller based on Wi-Fi signal strength, it overlooks other key factors such as AP load, channel congestion, and backhaul link capacity. In this paper, we propose a practical solution called Practical Dynamic Client Association (PDCA), which offers dynamic client association control over time to achieve max-min fairness in throughput performance while accounting for these critical factors. PDCA employs a heuristic-based approach to determine the optimal AP-client associations and then uses the EasyMesh client steering feature to execute association control. Our prototype demonstrates that PDCA consistently outperforms the default EasyMesh operation, achieving improvements of up to 165.2 % in minimum throughput and 60.0 % in aggregate throughput. Yu-Shao Su, Ming-Huang Hsieh, Tzu-Chi Yu, Chi-Yu Li 0001, Guan-Hua Tu |
ICC | 6 |
| 2024 | Uncovering Problematic Designs Hindering Ubiquitous Cellular Emergency Services AccessabstractCellular networks provide the most accessible emergency services with ubiquitous coverage, yet their emergency-specific designs remain largely unexplored. To systematically explore potential design defects that lead to failures or delays in emergency services, we introduce M911-Verifier, an emergency-specific model checking tool. It reveals many counterintuitive findings regarding the ubiquitous access support for cellular emergency services. Our study shows that, despite sufficient wireless signal coverage, users may still experience prolonged emergency call setup times, call initiation failures, or call drops due to flaws in the design of cellular emergency services. These design defects arise from three major causes: problematic network selection for initiating emergency calls, emergency-unaware call operation, and network escalation forbidden during emergency calls. The impacts of these defects have been experimentally validated across three U.S. carriers and two Taiwan carriers using commodity smartphones. Finally, we propose solutions and evaluate their effectiveness. Yiwen Hu 0002, Min-Yue Chen, Haitian Yan, Chuan-Yi Cheng, Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Chunyi Peng 0001, Li Xiao 0001, Jiliang Tang |
MobiCom | 5 |
| 2024 | IMS is Not That Secure on Your 5G/4G PhonesabstractIMS (IP Multimedia Subsystem) is vital for delivering IP-based multimedia services in mobile networks. Despite constant upgrades by 3GPP over the past two decades to support heterogeneous radio access networks (e.g., 4G LTE, 5G NR, and Wi-Fi) and enhance IMS security, the focus has primarily been on cellular infrastructure. Consequently, IMS security measures on mobile equipment (ME), such as smartphones, lag behind rapid technological advancements. Our study reveals that mandated IMS security measures on ME fail to keep pace, resulting in new vulnerabilities and attack vectors, including denial of service (DoS) across all networks, named SMS source spoofing, and covert communications over Video-over-IMS attacks. All vulnerabilities and proof-of-concept attacks have been experimentally validated in operational 5G/4G networks across various phone models and network operators. Finally, we propose and prototype standard-compliant remedies for these vulnerabilities. Jingwen Shi, Sihan Wang 0002, Min-Yue Chen, Guan-Hua Tu, Tian Xie 0001, Man-Hsin Chen, Yiwen Hu 0002, Chi-Yu Li 0001, Chunyi Peng 0001 |
MobiCom | 4 |
| 2024 | Practical Latency-Aware Scheduling for Low-Latency Elephant VR Flows in Wi-Fi NetworksabstractVirtual reality (VR) applications are increasingly popular. With high-quality video streams and interactive content, they require both low-latency and high-bandwidth performance demands on the communication from the edge-based VR server to the VR headsets. Although most VR headsets are equipped with dedicated wired or wireless modules connected to the VR server, using common Wi-Fi networks to support them can be a promising trend due to convenience and low cost. However, current Wi-Fi Access Points (APs) cannot meet latency demands of low-latency elephant VR flows, especially in traffic congestion cases. We thus design a practical Wi-Fi scheduling solution, designated as LAST-PQ (Latency-Aware Scheduler with Two-level Priority Queueing), to support VR flows at the Wi-Fi AP. It monitors the runtime latency performance of VR flows while prioritizing scheduling for urgent flows, whose latency demands are at risk of violation. We implement LAST-PQ in Linux on a commodity Wi-Fi platform using an open-source Wi-Fi driver; it is compliant to the current Wi-Fi scheduling framework. The evaluation result shows that it can reduce latency by up to 79.89% in various congested scenarios; moreover, it consistently meets the latency demands of VR flows in cases of mobility at runtime. Shao-Jung Lu, Wei-Xun Chen, Yu-Shao Su, Yu-Shou Chang, Yao-Wen Liu, Chi-Yu Li 0001, Guan-Hua Tu |
PerCom | 7 |
| 2024 | Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure DesignsabstractCellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities. Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
IEEE/ACM Trans. Netw. | 3 |
| 2024 | Dissecting Operational Cellular IoT Service Security: Attacks and DefensesabstractMore than 150 cellular networks worldwide have rolled out LTE-M (LTE-Machine Type Communication) and/or NB-IoT (Narrow Band Internet of Things) technologies to support massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover several vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices, interrupt their power saving services, and launch various attacks, including data/text spamming, battery draining, device hibernation against them. We validate these vulnerabilities over five major cellular IoT carriers in the U.S. and Taiwan using their certified cellular IoT devices. The attack evaluation result shows that the adversary can raise an IoT data bill by up to${\$}226$with less than 120 MB spam traffic, increase an IoT text bill at a rate of${\$}5$per second, and prevent an IoT device from entering/leaving power saving mode; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions. Sihan Wang 0002, Tian Xie 0001, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2023 | MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked SystemsabstractNowadays, both Internet Application Service (IAS) providers and users face various security threats and legal issues. Due to the lack of reliable user information verification mechanisms, adversaries can abuse IASs to launch various cyberattacks, such as misinformation distributing and phishing, by using fake user accounts. IAS providers may thus inadvertently offer inappropriate content to restricted users, thereby suffering a serious risk of prosecution under local or international laws. Also, IAS users may suffer from nefarious ID theft attacks. In this paper, we proposed a novel security framework,${{\sf MPKIX}}$, designated as Mobile-assisted PKIX (Public-Key Infrastructure X.509).${{\sf MPKIX}}$secures both IAS providers and users by leveraging the broadly used PKIX services and mobile networked systems. It not only provides IAS providers with a reliable user verification mechanism while simultaneously enabling cross-IAS user privacy protection, but also largely mitigates the possibility of ID theft attacks and benefits other involved parties, such as cellular network operators and PKIX service providers. We further conduct a security analysis of${{\sf MPKIX}}$and implement an${{\sf MPKIX}}$prototype. The evaluation results based on the prototype confirm the effectiveness and efficiency of${{\sf MPKIX}}$with low overhead. Tian Xie 0001, Sihan Wang 0002, Jingwen Shi, Guan-Hua Tu, Chi-Yu Li 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | Insecurity of Operational IMS Call Systems: Vulnerabilities, Attacks, and CountermeasuresabstractIMS (IP Multimedia Subsystem) is an essential 4G/5G component to offer multimedia services. It is used worldwide to support two call services: VoLTE (Voice over LTE) and VoWiFi (Voice over WiFi). In this study, it is shown that the signaling and voice sessions of VoWiFi can both be hijacked by a malicious adversary. By hijacking the signaling session, s(he) gains the ability to make ghost calls to launch stealthy DoS (Denial of Service) or caller-ID spoofing attacks against specific cellular users. Such attacks can be carried out without any malware or network information, and require only the victim’s phone number to be known. It is shown that phones vulnerable to the call DoS attacks can be detected at run time by exploiting a vulnerability of cellular network infrastructures referred to as call information leakage, which is exposed based on a machine learning method. Especially, the call DoS attacks can prevent victims from receiving incoming calls for up to 99.0% time without user awareness. Moreover, by hijacking the voice session, an adversary can launch stealthy free data transfer attacks based on phone numbers alone rather than IP addresses. The identified vulnerabilities/attacks are validated in the operational 4G networks of four top-tier carriers across Asia and North America with seven phone brands. The study concludes by presenting a suite of solutions to address them. Yu-Han Lu, Sandy H. Hsiao, Chi-Yu Li 0001, Yi-Chen Hsieh, Po-Yi Chou, Yao-Yu Li, Tian Xie 0001, Guan-Hua Tu |
IEEE/ACM Trans. Netw. | 8 |
| 2022 | Uncovering insecure designs of cellular emergency services (911)abstractCellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities. Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
MobiCom | 3 |
| 2022 | Wi-Fi-Based Tracking of Human Walking for Home Health MonitoringabstractNeurodegenerative disorder diseases, such as Parkinson’s disease (PD), are progressive, and their motor symptoms develop slowly. Assessing the motor functions of PD patients relies on the physician’s experience and subjective judgment. However, the disease’s actual condition may not fully present during the clinical examination due to the motor fluctuation or symptom variation in a day. This article proposed a wireless detection method that can enable long-term monitoring and quantification of walking, one of the challenging metrics to be evaluated in clinics. We utilized the channel state information (CSI) from two Wi-Fi links to construct a 2-D coordinate system in space to locate, track, and capture the gait information of a walking subject, including walking distance, step length, and cadence. The results showed that the estimation errors were 0.02–0.16 m (17.84%–38.48%) for step length, 0.01–0.16 Hz (1%–11%) for cadence, and less than 8.84° for walking direction when a subject walked along a straight line. The method could also detect walking that constantly changes direction (circular path) with localization errors of 0.31 (CW) and 0.50 m (CCW). Moreover, the proposed method could distinguish two subjects when they simultaneously walked along nonpredefined paths. The method can be further developed as a home health monitoring technology to provide long-term and reliable data without personally identifiable information for physicians to make more precise treatments. Chi-Lun Lin, Wen-Jia Chang, Guan-Hua Tu |
IEEE Internet Things J. | 3 |
| 2021 | Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and CountermeasuresabstractNowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards. Yiwen Hu 0002, Sihan Wang 0002, Guan-Hua Tu, Li Xiao 0001, Tian Xie 0001, Chi-Yu Li 0001 |
CODASPY | 3 |
| 2021 | BFastPay: A Routing-free Protocol for Fast Payment in Bitcoin NetworkabstractBitcoin is the most popular cryptocurrency which supports payment services via the Bitcoin peer-to-peer network. However, Bitcoin suffers from a fundamental problem. In practice, a secure Bitcoin transaction requires the payee to wait for at least 6 block confirmations (one hour) to be validated. Such a long waiting time thwarts the wide deployment of the Bitcoin payment services because many usage scenarios require a much shorter waiting time. In this paper, we propose BFastPay to accelerate the Bitcoin payment validation. BFastPay employs a smart contract called BFPayArbitrator to host the payer's security deposit and fulfills the role of a trusted payment arbitrator which guarantees that a payee always receives the payment even if attacks occur. BFastpay is a routing-free solution that eliminates the requirement for payment routing in the traditional payment routing network (e.g., Lightning Network). The theoretical and experimental results show that BFast is able to significantly reduce the Bitcoin payment waiting time (e.g., from 60 mins to less than 1 second) with nearly no extra operation cost. Guan-Hua Tu, Tian Xie 0001, Sihan Wang 0002 |
CODASPY | 2 |
| 2021 | Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresabstractMore than 150 cellular networks worldwide have rolled out massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover five vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices and launch data/text spamming attacks against them. We experimentally validate these vulnerabilities and attacks with three major U.S. IoT carriers. The attack evaluation result shows that the adversary can raise an IoT data bill by up to $226 with less than 120 MB spam traffic and increase an IoT text bill at a rate of $5 per second; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions. Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001 |
MobiCom | 2 |
| 2021 | How Can IoT Services Pose New Security Threats In Operational Cellular Networks?abstractCarriers are rolling out Internet of Things (IoT) services including various IoT devices and use scenarios. Compared with conventional non-IoT devices such as smartphones and tablets, IoT devices have limited network capabilities (e.g., low rates) and specific use scenarios (e.g., inside vehicles only). These specialized use scenarios lead to carries often offering cheaper device access fees for IoT devices. However, the aforementioned disparity of service charging between IoT and non-IoT devices may lead to security issues. In this work, we conduct the first empirical security study on cellular IoT service charging over two major US carriers and make three major contributions. First, we discover four security vulnerabilities and analyze their root causes, which help us identify two significant security threats, IoT masquerading and IoT use scenario abuse. Second, we devise three proof-of-concept attacks and assess their real-world impact. We determine that they can be exploited to allow adversaries to pay 43.75-80.00 percent less for cellular data services. Third, we analyze the challenges in addressing these vulnerabilities and develop an anti-abuse solution to mitigate attack incentives. The solution is standard-compliant and can be used immediately in practice. Our prototype and evaluation confirm its effectiveness. Tian Xie 0001, Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2021 | The Untold Secrets of WiFi-Calling Services: Vulnerabilities, Attacks, and CountermeasuresabstractSince 2016, all of four major U.S. operators have rolled out Wi-Fi calling services. They enable mobile users to place cellular calls over Wi-Fi networks based on the 3GPP IMS technology. Compared with conventional cellular voice solutions, the major difference lies in that their traffic traverses untrusted Wi-Fi networks and the Internet. This exposure to insecure networks can cause the Wi-Fi calling users to suffer from security threats. Its security mechanisms are similar to the VoLTE, because both of them are supported by the IMS. They include SIM-based security, 3GPP AKA, IPSec, etc. However, are they sufficient to secure Wi-Fi calling services? Unfortunately, our study yields a negative answer. We conduct the first security study on the operational Wi-Fi calling services in three major U.S. operators networks using commodity devices. We disclose that current Wi-Fi calling security is not bullet-proof and uncover three vulnerabilities. By exploiting the vulnerabilities, we devise two proof-of-concept attacks: telephony harassment or denial of voice service and user privacy leakage; both of them can bypass the existing security defenses. We have confirmed their feasibility using real-world experiments, as well as assessed their potential damages and proposed a solution to address all identified vulnerabilities. Tian Xie 0001, Guan-Hua Tu, Bangjie Yin, Chi-Yu Li 0001, Chunyi Peng 0001, Mi Zhang 0002, Hui Liu 0031, Xiaoming Liu 0002 |
IEEE Trans. Mob. Comput. | 2 |
| 2020 | An Inter-blockchain Escrow Approach for Fast Bitcoin PaymentabstractIn recent years, the Bitcoin (BTC) payment is increasingly popular in retailers and service providers. A BTC transaction (tx) needs six confirmations (one hour) to be validated, making it not suitable for fast-pay scenarios. Theoretically, a shorter waiting time period increases the success possibility of a double-spending attack. To address this problem, we propose BTCFast scheme to support fast BTC tx. BTCFast is a novel, decentralized, escrow-based scheme on top of the programmable smart contract (PSC)-enabled blockchains (e.g. Ethereum, EOS). We develop a smart contract (PayJudger) to work as a trusted payment judger, which guarantees the tx fairness. In addition, we devise a proof-of-work (PoW)-based payment judgment mechanism for PayJudger to resolve a BTC payment dispute. Our theoretical and experimental results show that BTCFast can reduce the waiting time to be less than 1 second with comparable security as the current approach (i.e., waiting for six confirmations) with no extra operation fee. Tian Xie 0001, Guan-Hua Tu, Alex X. Liu |
ICDCS | 3 |
| 2020 | Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureabstractIMS (IP Multimedia Subsystem) is an essential framework for providing 4G/5G multimedia services. It has been deployed worldwide to support two call services: VoLTE (Voice over LTE) and VoWi-Fi (Voice over Wi-Fi). VoWi-Fi enables telephony calls over the Wi-Fi network to complement VoLTE. In this work, we uncover that the VoWi-Fi signaling session can be hijacked to maliciously manipulate the IMS call operation. An adversary can easily make ghost calls to launch a stealthy call DoS (Denial of Service) attack against specific cellular users. Only phone numbers, but not any malware or network information, are required from the victims. This sophisticated attack harnesses a design defect of the IMS call state machine, but not simply flooding or a crash trigger. To stealthily detect attackable phones at run time, we exploit a vulnerability of the 4G network infrastructure, call information leakage, which we explore using machine learning. We validate these vulnerabilities in operational 4G networks of 4 top-tier carriers across Asia and North America countries with 7 phone brands. Our result shows that the call DoS attack can prevent the victims from receiving incoming calls up to 99.0% time without user awareness. We finally propose and evaluate recommended solutions. Yu-Han Lu, Chi-Yu Li 0001, Yao-Yu Li, Sandy H. Hsiao, Tian Xie 0001, Guan-Hua Tu, Wei-Xun Chen |
MobiCom | 6 |
| 2020 | SecWIR: securing smart home IoT communications via wi-fi routers with embedded intelligenceabstractSmart home Wi-Fi IoT devices are prevalent nowadays and potentially bring significant improvements to daily life. However, they pose an attractive target for adversaries seeking to launch attacks. Since the secure IoT communications are the foundation of secure IoT devices, this study commences by examining the extent to which mainstream security protocols are supported by 40 of the best selling Wi-Fi smart home IoT devices on the Amazon platform. It is shown that 29 of these devices have either no security protocols deployed, or have problematic security protocol implementations. Seemingly, these vulnerabilities can be easily fixed by installing security patches. However, many IoT devices lack the requisite software/hardware resources to do so. To address this problem, the present study proposes a SecWIR (Secure Wi-Fi IoT communication Router) framework designed for implementation on top of the users' existing home Wi-Fi routers to provide IoT devices with a secure IoT communication capability. However, it is way challenging for SecWIR to function effectively on all home Wi-Fi routers since some routers are resource-constrained. Thus, several novel techniques for resolving this implementation issue are additionally proposed. The experimental results show that SecWIR performs well on a variety of commercial off-the-shelf (COTS) Wi-Fi routers at the expense of only a small reduction in the non-IoT data service throughput (less than 8%), and small increases in the CPU usage (4.5%~7%), RAM usage (1.9 MB~2.2 MB), and the IoT device access delay (24 ms~154 ms) while securing 250 IoT devices. Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Mi Zhang 0002 |
MobiSys | 2 |
| 2019 | SecEQP: A Secure and Efficient Scheme for SkNN Query Problem Over Encrypted Geodata on CloudabstractNowadays, location-based services are proliferating and being widely deployed. For example, a Yelp user can obtain a list of the recommended restaurants near his/her current location. For some small or medium location service providers, they may rely on commercial cloud services, e.g., Dropbox, to store the tremendous geospatial data and deal with a number of user queries. However, it is challenging to achieve a secure and efficient location-based query processing over encrypted geospatial data stored on the cloud. In this paper, we propose the Secure and Efficient Query Processing (SecEQP) scheme to address the secure k nearest neighbor (SkNN) query problem. SecEQP employs the projection function-based approach to code neighbor regions of a given location. Given the codes of two locations, the cloud server only needs to compare whether codes equal or not to check the proximity of the two locations. The codes are further embedded into an indistinguishable Bloom filter tree to build a secure and efficient index. The security of SecEQP is formally proved in the random oracle model. We further prototype SecEQP scheme and evaluate its performance on both real-world and synthetic datasets. Our evaluation results show that SecEQP is a highly efficient approach, e.g., top-10 NN query over 1 million datasets only needs less than 40 msec to get queried results. Alex X. Liu, Rui Li 0020, Guan-Hua Tu |
ICDE | 4 |
| 2018 | V2PSense: Enabling Cellular-Based V2P Collision Warning Service through Mobile SensingabstractThe C-V2X (Cellular Vehicle-to-Everything) technology is developing in full swing. One of its mainstream services can be the Vehicle-to- Pedestrian (V2P) service. It can protect pedestrians who are mostly vulnerable on the road. In this work, we seek to enable a V2P service that can identify which pedestrians may be nearby a dangerous driving event and then notify them of warning messages. To enable this V2P service, there are two major challenges. First, a low-latency V2P message transport is required for this infrastructure-based service. Second, the pedestrian's smartphone requires an energy- efficient outdoor positioning method instead of power-hungry GPS due to its limited battery life. We thus propose a novel solution, V2PSense, which trades off positioning precision for energy savings while achieving low-latency message transport with LTE high-priority bearers. It does a coarse-grained positioning by leveraging intermittent GPS information and mobile sensing data, which includes step count from the pedometer and cellular signal strength changes. Though the V2PSense's positioning is not as precise as the GPS, it can still ensure that all the pedestrians nearby dangerous spots can be notified. Our results show that it can achieve the average precision ratio 92.6% for estimating where the pedestrian is while saving 20.8% energy, compared with the GPS always-on case. Chi-Yu Li 0001, Giovanni Salinas, Po-Hao Huang, Guan-Hua Tu, Guo-Huang Hsu, Tien-Yuan Hsieh |
ICC | 4 |
| 2018 | How Voice Service Threatens Cellular-Connected IoT Devices in the Operational 4G LTE NetworksabstractLTE networks are rolling out cellular Internet-of- Things (IoT) services. Cellular-connected IoT devices are becoming increasingly popular and the number is forecasted to grow almost fourfold from 2015 to 2021. Since they share the same infrastructure with non-IoT devices such as smartphones, we may expect no big differences between them in terms of voice/data service accounting/charging (e.g., paying for what you get) and security risks. However, our study shows that cellular IoT users may pay more than what they get, as well as are vulnerable to voice signaling spams and thus suffer from an overcharging attack which leads to financial loss or denial of service. We validate our proof-of- concept attack in a major U.S. cellular network operator which takes higher than 35% market share. We finally propose a solution to address the identified security vulnerabilities. Tian Xie 0001, Chi-Yu Li 0001, Jiliang Tang, Guan-Hua Tu |
ICC | 4 |
| 2018 | Device-Customized Multi-Carrier Network Access on Commodity SmartphonesabstractAccessing multiple carrier networks (T-Mobile, Sprint, AT&T, and so on) offers a promising paradigm for smartphones to boost its mobile network quality. However, the current practice does not achieve the full potential of this approach because it has not utilized fine-grained, cellular-specific domain knowledge. Our experiments and code analysis discover three implementation-independent issues: 1) it may not trigger the anticipated switch when the serving carrier network is poor; 2) the switch takes a much longer time than needed; and 3) the device fails to choose the high-quality network (e.g., selecting 3G rather than 4G). To address them, we propose iCellular, which exploits low-level cellular information at the device to improve multi-carrier access. iCellular is proactive and adaptive in its multi-carrier selection by leveraging existing end-device mechanisms and standards-complaint procedures. It performs adaptive monitoring to ensure responsive selection and minimal service disruption and enhances carrier selection with online learning and runtime decision fault prevention. It is readily deployable on smartphones without infrastructure/hardware modifications. We implement iCellular on commodity phones and harness the efforts of Project Fi to assess multi-carrier access over two U.S. carriers: T-Mobile and Sprint. Our evaluation shows that, iCellular boosts the devices' throughput with up to 3.74× throughput improvement, 6.9× suspension reduction, and 1.9× latency decrement over the state of the art, with moderate CPU, and memory and energy overheads. Yuanjie Li, Chunyi Peng 0001, Haotian Deng 0001, Zengwen Yuan, Guan-Hua Tu, Songwu Lu, Xi Li 0003 |
IEEE/ACM Trans. Netw. | 5 |
| 2016 | New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksabstractSMS (Short Messaging Service) is a text messaging service for mobile users to exchange short text messages. It is also widely used to provide SMS-powered services (e.g., mobile banking). With the rapid deployment of all-IP 4G mobile networks, the underlying technology of SMS evolves from the legacy circuit-switched network to the IMS (IP Multimedia Subsystem) system over packet-switched network. In this work, we study the insecurity of the IMS-based SMS. We uncover its security vulnerabilities and exploit them to devise four SMS attacks: silent SMS abuse, SMS spoofing, SMS client DoS, and SMS spamming. We further discover that those SMS threats can propagate towards SMS-powered services, thereby leading to three malicious attacks: social network account hijacking, unauthorized donation, and unauthorized subscription. Our analysis reveals that the problems stem from the loose security regulations among mobile phones, carrier networks, and SMS-powered services. We finally propose remedies to the identified security issues. Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001, Yuanjie Li, Songwu Lu |
CCS | 1 |
| 2016 | iCellular: Device-Customized Cellular Network Access on Commodity Smartphones
Yuanjie Li, Haotian Deng 0001, Chunyi Peng 0001, Zengwen Yuan, Guan-Hua Tu, Songwu Lu |
NSDI | 5 |
| 2016 | Detecting Problematic Control-Plane Protocol Interactions in Mobile NetworksabstractThe control-plane protocols in 3G/4G mobile networks communicate with each other, and provide a rich set of control functions, such as radio resource control, mobility support, connectivity management, to name a few. Despite their significance, the problem of verifying protocol correctness remains largely unaddressed. In this paper, we examine control-plane protocol interactions in mobile networks. We propose CNetVerifier, a two-phase signaling diagnosis tool to detect problematic interactions in both design and practice. CNetVerifier first performs protocol screening based on 3GPP standards via domain-specific model checking, and then conducts phone-based empirical validation in operational 3G/4G networks. With CNetVerifier, we have uncovered seven types of troublesome interactions, along three dimensions of cross (protocol) layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. Some are caused by necessary yet problematic cooperation (i.e., protocol interactions are needed but they misbehave), whereas others are due to independent yet unnecessary coupled operations (i.e., protocols interactions are not required but actually coupled). These instances span both design defects in 3GPP standards and operational slips by carriers and vendors. They all result in performance penalties or functional incorrectness. We deduce root causes, present empirical results, propose solutions, and summarize learned lessons. Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
IEEE/ACM Trans. Netw. | 1 |
| 2015 | Insecurity of Voice Solution VoLTE in LTE Mobile NetworksabstractVoLTE (Voice-over-LTE) is the designated voice solution to the LTE mobile network, and its worldwide deployment is underway. It reshapes call services from the traditional circuit-switched telecom telephony to the packet-switched Internet VoIP. In this work, we conduct the first study on VoLTE security before its full rollout. We discover several vulnerabilities in both its control-plane and data-plane functions, which can be exploited to disrupt both data and voice in operational networks. In particular, we find that the adversary can easily gain free data access, shut down continuing data access, or subdue an ongoing call, etc. We validate these proof-of-concept attacks using commodity smartphones (rooted and unrooted) in two Tier-1 US mobile carriers. Our analysis reveals that, the problems stem from both the device and the network. The device OS and chipset fail to prohibit non-VoLTE apps from accessing and injecting packets into VoLTE control and data planes. The network infrastructure also lacks proper access control and runtime check. Chi-Yu Li 0001, Guan-Hua Tu, Chunyi Peng 0001, Zengwen Yuan, Yuanjie Li, Songwu Lu, Xinbing Wang |
CCS | 2 |
| 2014 | Real Threats to Your Data Bills: Security Loopholes and Defenses in Mobile Data ChargingabstractSecure mobile data charging (MDC) is critical to cellular network operations. It must charge the right user for the right volume that (s)he authorizes to consume (i.e., requirements of authentication, authorization, and accounting (AAA)). In this work, we conduct security analysis of the MDC system in cellular networks. We find that all three can be breached in both design and practice, and identify three concrete vulnerabilities: authentication bypass, authorization fraud and accounting volume inaccuracy. The root causes lie in technology fundamentals of cellular networks and the Internet IP design, as well as imprudent implementations. We devise three showcase attacks to demonstrate that, even simple attacks can easily penetrate the operational 3G/4G cellular networks. We further propose and evaluate defense solutions. Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu |
CCS | 4 |
| 2014 | Control-plane protocol interactions in cellular networksabstractControl-plane protocols are complex in cellular networks. They communicate with one another along three dimensions of cross layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. In this work, we propose signaling diagnosis tools and uncover six instances of problematic interactions. Such control-plane issues span both design defects in the 3GPP standards and operational slips by carriers. They are more damaging than data-plane failures. In the worst-case scenario, users may be out of service in 4G, or get stuck in 3G. We deduce root causes, propose solutions, and summarize learned lessons. Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
SIGCOMM | 1 |
| 2013 | How voice calls affect data in operational LTE networksabstractBoth voice and data are indispensable services in current cellular networks. In this work, we study the inter-play of voice and data in operational LTE networks. We assess how the popular CSFB-based voice service affects the IP-based data sessions in 4G LTE networks, and visa versa. Our findings reveal that the interference between them is mutual. On one hand, voice calls may incur throughput drop, lost 4G connectivity, and application aborts for data sessions. One the other hand, users may miss incoming voice calls when turning on data access. The fundamental problem is that, signaling and control for circuit-switched voice and packet-switched data have dependency and coupling effect via the LTE phone client. We further propose fixes to the identified issues. Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
MobiCom | 1 |
| 2013 | Accounting for roaming users on mobile data access: issues and root causesabstractIn this paper, we study how mobility affects mobile data accounting, which records the usage volume for each roaming user. We find out that, current 2G/3G/4G systems have well-tested mobility support solutions and generally work well. However, under certain biased, less common yet possible scenarios, accounting gap between the operator's log and the user's observation indeed exists. The gap can be as large as 69.6% in our road tests. We further discover that the root causes are diversified. In addition to the no-signal case reported in the prior work [23], they also include handoffs, as well as insufficient coverage of hybrid 2G/3G/4G systems. Inter-system handoffs (that migrate user devices between radio access technologies of 2G, 3G, and 4G) may incur non-negligible accounting discrepancy. Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Tao Wang 0004, Songwu Lu |
MobiSys | 1 |
| 2012 | Mobile data charging: new attacks and countermeasuresabstract3G/4G cellular networks adopt usage-based charging. Mobile users are billed based on the traffic volume when accessing data service. In this work, we assess both this metered accounting architecture and application-specific charging policies by operators from the security perspective. We have identified loopholes in both, and discovered two effective attacks exploiting the loopholes. The "toll-free-data-access-attack" enables the attacker to access any data service for free. The "stealth-spam-attack" incurs any large traffic volume to the victim, while the victim may not be even aware of such spam traffic.Our experiments on two operational 3G networks have confirmed the feasibility and simplicity of such attacks. We also propose defense remedies. Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu, Lixia Zhang 0001 |
CCS | 3 |
| 2012 | Can we pay for what we get in 3G data access?abstractData-plan subscribers are charged based on the used traffic volume in 3G/4G cellular networks. This usage-based charging system has been operational and received general success. In this work, we conduct experiments to critically assess both this usage-based accounting architecture and application-specific charging policies by operators. Our evaluation compares the network-recorded volume with the delivered traffic at the end device. We have found that, both generally work in common scenarios but may go wrong in the extreme cases: We are charged for what we never get, and we can get what we want for free. In one extreme case, we are charged for at least three hours and 450MB or more data despite receiving no single bit. In another extreme case, we are able to transfer 200MB or any amount we specify for free. The root causes lie in lack of both coordination between the charging system and the end device, and prudent policy enforcement by certain operators. We propose immediate fixes and discuss possible future directions. Chunyi Peng 0001, Guan-Hua Tu, Chi-Yu Li 0001, Songwu Lu |
MobiCom | 2 |
| 2006 | An Improved GGSN Failure Restoration Mechanism for UMTS
Phone Lin, Guan-Hua Tu |
Wirel. Networks | 2 |
| 2005 | An intelligent GGSN dispatching mechanism for UMTS
Shin-Ming Cheng, Phone Lin, Guan-Hua Tu, Li-Chen Fu, Ching-Feng Liang |
Comput. Commun. | 3 |