VLDB 2026 Research / reviewers in the wild / expert
Wenjun Fan
dblp:65/8876
· DBLP profile ↗
43ranked-venue papers
15as first author
32since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 21 · 6 first-author · 17 since 2021Security and privacy · 11 · 5 first-author · 8 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PentestLLM: A Cyber Kill Chain-driven Multi-Agent Large Language Model Framework Enabling Automatic Penetration Testing
Hiroyuki Sato 0002, Zhenzhen Jiang, Lekun Liu, Wenjun Fan |
COMPSAC | 7 |
| 2026 | Link State-enabled IFA Threat Detection and Tracing in Named Data Networking
Wenjun Fan, Sang-Yoon Chang |
ICC | 1 |
| 2026 | CTFAgent: An LLM-powered Agent for CTF Challenge Solving
Yuwen Zou, Wenjun Fan |
J. Inf. Secur. Appl. | 3 |
| 2026 | PP-TDD: Privacy protection towards secure vehicle semantic trajectory data dissemination
Na Fan 0003, Wenjun Fan, Xing Liang, Zhiquan Liu 0001 |
Knowl. Based Syst. | 2 |
| 2026 | ML-BF: Responsive and Dynamic Intrusion Detection towards Intelligent Connected Vehicles
Jia Liu 0074, Wenjun Fan, Eng Gee Lim, Yifan Dai 0006, Alexei Lisitsa 0001 |
Peer Peer Netw. Appl. | 2 |
| 2025 | PETS2025: Multi-Authority Multi-Sensor Maritime Surveillance Challenge and EvaluationabstractThis paper presents the outcomes of the PETS2025 challenge, held in conjunction with AVSS 2025 and sponsored by the EU-funded EURMARS project. The challenge introduces a novel maritime surveillance dataset comprising image sequences captured by diverse multi-altitude, multimodal sensors, reflecting the real-world multi-authority environment. The key tasks include: (1) object detection using various sensors across different platforms (ground-based and low-altitude aerial) and spectral ranges (visible, thermal, ultraviolet (UV), and short-wave infrared (SWIR)); (2) long-term tracking of targets in maritime environments spanning both sea and land; and (3) approximating target geolocations by using sensor imagery and telemetry data. Performance evaluations of results submitted by 12 international participants are discussed. The results show the effectiveness of these submissions and highlight ongoing challenges posed by heterogeneous sensors and complex environments. These challenges emphasise the need to further improve detection, tracking, and geolocation approximation for maritime and coastal surveillance. Thanet Markchom, Jonathan N. Boyle, Lulu Chen, James M. Ferryman, Matteo Marturini, Stephan Veigl, Andreas Opitz, Andreas Kriechbaum-Zabini, Romaios Bratskas, Anastasios Gkamaris, Dimitris Papachristos, George Leventakis, Wenjun Fan, Hsiang-Wei Huang, Jeng-Neng Hwang, Pyong-Kun Kim, Kwangju Kim, Chung-I Huang, Kenta Saito, Shunta Kaneko, Kyoko Sudo, Nguyen Thanh Thien, Meng-Yu Kao, Jun-Wei Hsieh, Teepakorn Lilek, Tossapol Pomsuwan, Jinjie Gu, Tianyang Xu 0001, Xuefeng Zhu 0003, Xiaojun Wu 0001, Josef Kittler, Stephanie Stacy, Alfredo Gabaldon, Peter Tu, Dongyoung Kim, Kyoungoh Lee |
AVSS | 13 |
| 2025 | Multi-Attack Identification and Mitigation mechanism based on multi-agent collaboration in Vehicular Named Data Networking
Na Fan 0003, Zhiquan Liu 0001, Wenjun Fan |
Comput. Networks | 5 |
| 2025 | Securing VNDN With Multi-Indicator Intrusion Detection Approach Against the IFA ThreatabstractOn vehicular named data network (VNDN), Interest Flooding Attack (IFA) can exhaust the computing resources by sending a large number of malicious Interest packets, which leads to the failure of satisfying the legitimate requests and seriously hazards the operation of Internet of Vehicles (IoV). To solve this problem, this paper proposes a distributed network traffic monitoring-enabled multi-indicator detection and prevention approach for VNDN to detect and resist the IFA attacks. In order for facilitating this approach, a distributed network traffic monitoring layer based on road side unit (RSU) is constructed. With such a monitoring layer, a multi-indicator detection approach is designed, which consists of three indicators: information entropy, self-similarity, and singularity, whereby the thresholds are tweaked by the real-time density of traffic flow. Apart from the detection, a blacklisting based prevention approach is realized to mitigate the attack impact.We validate the proposed approach via prototyping it on our VNDN experimental platform using realistic parameters setting and leveraging the original NDN packet structure to corroborate the usage of the required Source ID for identifying the source of the Interest packet, which consolidates the practicability of the approach. The experimental results show that our multi-indicator detection approach has a greatly higher detection performance than those of using indicators individually, and the blacklisting-based prevention can effectively mitigate the attack impact as well. Wenjun Fan, Na Fan 0003, Jia Liu 0074, Yifan Dai 0006 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | Unveiling Vulnerabilities in Bitcoin's Misbehavior-Score Mechanism: Attack and DefenseabstractThe Bitcoin network is susceptible to various attacks due to its openness, decentralization, and plaintext connections. Bitcoin created a misbehavior-score mechanism for monitoring and tracking peer misconduct. In this paper, we uncover several vulnerabilities of this mechanism, leading to potential Bitcoin-Message-based Denial-of-Service (BitMsg-DoS) attacks on Bitcoin nodes and Slander attacks by maligning innocent nodes. We prototype these attacks for our experiments by testing real nodes connected to the Bitcoin main network (while we do not exfiltrate our attacks to the real-world main network). The experimental results show that the attacks exert varying degrees of impact on mining and non-mining nodes, notably reducing mining rates by up to half for affected mining nodes and decreasing the synchronization speed of blocks for non-mining nodes. To address these drawbacks, this study proposes corresponding countermeasures targeting the identified vulnerabilities in the misbehavior-score mechanism. Furthermore, we explore the Peer-to-Peer (P2P) encrypted transport protocol with experimental support in the latest Bitcoin Core 26.0, but find it insufficient in mitigating the Slander attacks. Yuwen Zou, Wenjun Fan |
ARES | 2 |
| 2024 | A Keyless Authentication Based on Zero-Knowledge Proof with SDN Link Information to Secure Permissionless P2P NetworkingabstractMost trust models are identity based, which how-ever are not appropriate to the permissionless peer-to-peer (P2P) networking since anonymity is a built-in property in the cryptocurrency system (e.g., Bitcoin). Hence, there exists an inherent trade-off between anonymity and trust in the context of permissionless P2P networking system. This paper is motivated to propose a keyless authentication based on zero-knowledge proof. With this, peers can authenticate each other without disclosing any sensitive information. To this end, this approach leverages the software-defined networking (SDN) technique to facilitate the zero-knowledge proof so that the peer's link information can be identified while the proving process will never reveal any identity information. Therefore, the challenge-response exchange can prevent Man-in-the-Middle (MITM) attacks with minimal communication overhead. The experimental results built on the prototype show that this approach is efficient. Wenjun Fan, Yuwen Zou |
ICC | 1 |
| 2024 | HoneyLLM: A Large Language Model-Powered Medium-Interaction Honeypot
Wenjun Fan, Zichen Yang, Yuanzhen Liu |
ICICS (2) | 1 |
| 2024 | A Lightweight and Responsive On-Line IDS Towards Intelligent Connected Vehicles System
Jia Liu 0074, Wenjun Fan, Yifan Dai 0006, Eng Gee Lim, Alexei Lisitsa 0001 |
SAFECOMP | 2 |
| 2024 | Exploiting the Vulnerabilities in MAVLink Protocol for UAV HijackingabstractThe MAVLink protocol serves as the cornerstone for control communications between ground control systems (GCS) and unmanned aerial vehicles (UAVs), facilitating essential control communication. Despite its widespread adoption, the protocol's security mechanisms have raised significant concerns. This work focuses on the design vulnerabilities of the MAVLink protocol v2.0 including the deficiency in message authentication code (MAC) mechanism and lapses in sequence number verification. Also, this research reveals the implementation loopholes (as findings) in the well-known GCS software (Mission Planner) for updating the secret key and in the widely used UAV emulation (ArduPilot) for examining invalid timestamps. This breach paves the way for the injection of malicious messages, culminating in the potential hijacking of the UAV. In response to these issues, we propose several countermeasures including a solution using the public key-based signature. The efficacy of both the attack methods and the countermeasures is validated through a series of experiments conducted within a controlled testbed environment. Jinai Ge, Yuwen Zou, Sang-Yoon Chang, Wenjun Fan |
SIN | 6 |
| 2024 | Leveraging Semi-supervised Learning for Enhancing Anomaly-based IDS in Automotive Ethernet
Jia Liu 0074, Wenjun Fan, Yifan Dai 0006, Eng Gee Lim, Zhoujin Pan, Alexei Lisitsa 0001 |
TrustCom | 2 |
| 2024 | Leveraging Large Language Models for Challenge Solving in Capture-the-FlagabstractCapture-the-Flag (CTF) competitions are a prominent method in cybersecurity for practical attack and defense exercises. Despite the rapid advancements in Large Language Models (LLMs), their potential for solving CTF challenges remains underexplored. In this paper, we first propose a flexible CTF platform designed to reflect real-world penetration testing scenarios, bridging the gap between theoretical learning and practical cybersecurity challenges. Our platform is highly customizable, freely deployable, and capable of generating scenarios that closely mirror real network vulnerabilities. More importantly, we introduce an automated LLM agent framework that tackles CTF challenges using an integrated toolchain and various plugins to enhance problem-solving efficiency. In addition, we propose a human-validated LLM agent framework to address the potential limitations of the fully automated LLM agent, providing a clearer evaluation of the LLMs’ intrinsic capabilities. We evaluate the agent’s performance using four LLMs: GPT-4o, GPT-4o mini, o1-preview, and o1-mini. Although the LLMs’ performance on dynamic and complex penetration tests reveals certain limitations, which need further exploration, our experimental results demonstrate that LLMs can leverage their extensive knowledge bases to effectively solve CTF challenges. Yuwen Zou, Lekun Liu, Wenjun Fan |
TrustCom | 5 |
| 2024 | Secure and Efficient Authentication using Linkage for permissionless Bitcoin network
Hsiang-Jen Hong, Sang-Yoon Chang, Wenjun Fan, Simeon Wuthier, Xiaobo Zhou 0002 |
Comput. Networks | 3 |
| 2024 | TLPP: Deep-Learning-Based Two-Layer Privacy Preserving Mechanism for Protecting Vehicle Trajectory DataabstractWith the popularity of the global positioning system (GPS) and mobile Internet, a large amount of vehicle trajectory data has been generated and applied in intelligent transportation systems. The collected trajectory data often contains sensitive user information, which poses a risk of user privacy disclosure. To enhance the privacy of vehicle trajectory data, this article proposes a novel two-layer privacy preserving (TLPP) mechanism that leverages clustering features. Initially, density-based clustering is employed to derive regional attributes and density characteristics of trajectory points. Subsequently, a generative adversarial network (GAN) incorporating a long short-term memory (LSTM) network is utilized to learn the distribution of clustered trajectories, facilitating the generation of synthetic trajectories. These synthetic trajectories are then substituted for the original trajectories, constituting the first layer of privacy protection. To ensure the fidelity of the synthetic data, a novel generator loss function is designed, utilizing the Wasserstein distance to quantify the spatial similarity between the real and synthetic trajectories. Furthermore, to accommodate the personalized privacy requirements, a tailored differential privacy mechanism is introduced. This mechanism provides a second layer of privacy protection by introducing the region-specific perturbations to the data. The experimental results show that, compared with the other models, our approach can effectively protect the user privacy while ensuring the trajectory data utility. Na Fan 0003, Jia Liu 0074, Shudi Zhao, Yifan Dai 0006, Wenjun Fan |
IEEE Internet Things J. | 5 |
| 2024 | Data-Driven Fault Diagnosis of Internal Short Circuit for Series-Connected Battery Packs Using Partial Voltage CurvesabstractInternal short circuit (ISC) fault diagnosis of battery packs in electric vehicles is of great significance for the effective and safe operation of battery systems. This article presents a new ISC diagnosis method based on a machine learning algorithm. In this method, the incremental capacity curves are employed to divide the voltage curves into multiple sections. The dynamic time warping (DTW) algorithm is used to describe the similarity between partial voltage curves of different cells. Furthermore, four features are selected to describe the DTW distribution and statistics characteristics, and then the ISC diagnosis model based on the gradient boosting decision tree (GBDT) algorithm is constructed. The GBDT algorithm-based method realizes the accurate detection and location of early ISC fault using only partial voltage curves under arbitrary operating conditions, rather than relying on complete charging/discharging curves under specific operating conditions, and the final detection accuracy can be up to 99.4%. Dongdong Qiao, Xuezhe Wei, Wenjun Fan, Hui Gong, Xin Lai 0004, Yuejiu Zheng, Haifeng Dai |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | QKD-based Secure Communication for UAV
Zhenxu Gao, Wenjun Fan, Ruxue Luo |
APNOMS | 2 |
| 2023 | Machine Learning-based Approach for Enhancing Multi-step Attack Prediction
Wenjun Fan, Ruxue Luo |
APNOMS | 2 |
| 2023 | A Machine Learning-Based Intrusion Detection Approach for Intelligent Connected Vehicles
Wenjun Fan |
APNOMS | 2 |
| 2023 | A Honey-imprint enabled Approach for Resisting Social Engineering Attacks
Zhaoxi Zhong, Wenjun Fan |
APNOMS | 2 |
| 2023 | Still Not Aware of the Loophole of Unintentional Access to Docker? A Proof of ConceptabstractDue to the ease of management and the high performance of the containerization, many services have been deployed on container, e.g., Web server running in Docker. However, the Docker implementation suffers several fatal loopholes. In this paper, we study a persistent security problem of Docker, i.e., the port mapping statement results in a wrong IPTABLES rule, which has been disclosed for a while but is still not solved. Therefore, we are motivated to provide a technical primer as well as a proof of concept for this issue. Nevertheless, we discuss several methods to mitigate the security problem. Further, we apply our network testbed for demonstrating the loophole and the effectiveness of the defense methods. The experimental results show that our approach not only increase the time cost for the attacker to identify the target but also bring negligible overhead for deploying the countermeasures. Ruxue Luo, Wenjun Fan |
ISCC | 5 |
| 2023 | An SDN-NFV-enabled Honeypot for Manipulating Command & Control Shell TCP ConnectionabstractA honeypot is a dedicated security tool for enticing and deceiving adversaries. With a successful intrusion, an adversary would often obtain a shell (that is bind or reverse in accordance with the attack sort), which is used to command and control (C&C) the compromised machine. The serious consequence of C&C must be controlled. As is well-known, the C&C shell is often sustained by a TCP connection. However, many honeypots lack the capability to control the shell TCP connections, i.e., a high-interaction honeypot (HIH) is often unable to migrate the bind shell TCP connection, and a low-/medium-interaction honeypot (LIH/MIH) even does not support creating a reverse shell TCP connection. In this paper, we use Software Defined Network (SDN) and Network Function Virtualization (NFV) to propose an SDN-NFV-enabled honeypot system for providing a container-based covert attack-connection manipulation mechanism to address the above issue. Taking advantage of the SDN/NFV technology, the proposed honeypot is able to respond dynamically to build a shell-container to deceive the adversary following the moving-target defense principle. To consolidate the proposal, a prototype is implemented, and a number of experiments are conducted. The experimental results show that the proposed honeypot system is effective and efficient. Wenjun Fan |
NOMS | 2 |
| 2023 | Lightweight and Identifier-Oblivious Engine for Cryptocurrency Networking Anomaly DetectionabstractThe distributed cryptocurrency networking is critical because the information delivered through it drives the mining consensus protocol and the rest of the operations. However, the cryptocurrency peer-to-peer (P2P) network remains vulnerable, and the existing security approaches are either ineffective or inefficient because of the permissionless requirement and the broadcasting overhead. We design and build a Lightweight and Identifier-Oblivious eNgine (LION) for the anomaly detection of the cryptocurrency networking. LION is not only effective in permissionless networking but is also lightweight and practical for the computation-intensive miners. We build LION for anomaly detection and use traffic analyses so that it minimally affects the mining rate and is substantially superior in its computational efficiency than the previous approaches based on machine learning. We implement a LION prototype on an active Bitcoin node to show that LION yields less than 1% of mining rate reduction subject to our prototype, in contrast to the state-of-the-art machine-learning approaches costing 12% or more depending on the algorithms subject to our prototype as well, while having detection accuracy of greater than 97% F1-score against the attack prototypes and real-world anomalies. LION therefore can be deployed on the existing miners without the need to introduce new entities in the cryptocurrency ecosystem. Wenjun Fan, Hsiang-Jen Hong, Jinoh Kim, Simeon Wuthier, Makiya Nakashima, Xiaobo Zhou 0002, C. Edward Chow, Sang-Yoon Chang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | The Security Investigation of Ban Score and Misbehavior Tracking in Bitcoin NetworkabstractBitcoin P2P networking is especially vulnerable to networking threats because it is permissionless and does not have the security protections based on the trust in identities, which enables the attackers to manipulate the identities for Sybil and spoofing attacks. The Bitcoin node keeps track of its peer’s networking misbehaviors through ban scores. In this paper, we investigate the security problems of the ban-score mechanism and discover that the ban score is not only ineffective against the Bitcoin Message-based DoS (BM-DoS) attacks but also vulnerable to the Defamation attack as the network adversary can exploit the ban score to defame innocent peers. To defend against these threats, we design an anomaly detection approach that is effective, lightweight, and tailored to the networking threats exploiting Bitcoin’s ban-score mechanism. We prototype our threat discoveries against a real-world Bitcoin node connected to the Bitcoin Mainnet and conduct experiments based on the prototype implementation. The experimental results show that the attacks have devastating impacts on the targeted victim while being cost-effective on the attacker side. For example, an attacker can ban a peer in two milliseconds and reduce the victim’s mining rate by hundreds of thousands of hash computations per second. Furthermore, to counter the threats, we empirically validate our detection countermeasure’s effectiveness and performances against the BM-DoS and Defamation attacks. Wenjun Fan, Simeon Wuthier, Hsiang-Jen Hong, Xiaobo Zhou 0002, Sang-Yoon Chang |
ICDCS | 1 |
| 2022 | Robust P2P networking connectivity estimation engine for permissionless Bitcoin cryptocurrency
Hsiang-Jen Hong, Wenjun Fan, Simeon Wuthier, Jinoh Kim, C. Edward Chow, Xiaobo Zhou 0002, Sang-Yoon Chang |
Comput. Networks | 2 |
| 2022 | A Machine Learning Approach to Anomaly Detection Based on Traffic Monitoring for Secure Blockchain NetworkingabstractWhile blockchain technology provides strong cryptographic protection on the ledger and the system operations, the underlying blockchain networking remains vulnerable due to potential threats such as denial of service (DoS), Eclipse, spoofing, and Sybil attacks. Effectively detecting such malicious events should thus be an essential task for securing blockchain networks and services. Due to its importance, several studies investigated anomaly detection in Bitcoin and blockchain networks, but their analyses mainly focused on the blockchain ledger in the application context (e.g., transactions) and targets specific types of attacks (e.g., double-spending, deanonymization, etc). In this study, we present a security mechanism based on the analysis of blockchain network traffic statistics (rather than ledger data) to detect malicious events, through the functions of data collection and anomaly detection. The data collection engine senses the underlying blockchain traffic and generates multi-dimensional data streams in a periodic, real-time manner. The anomaly detection engine then detects anomalies from the created data instances based on semi-supervised learning, which is capable of detecting previously unseen patterns, and we introduce our profiling-based detection engine implemented on top of AutoEncoder (AE). Our experimental results evaluated with real and simulated traffic data support the effectiveness of our security mechanism and design choices based on the AE structure, with the approximate detection performance to the supervised learning methods only through the profiling of normal instances. The measured time complexity is sufficiently cheap to perform real-time analysis, with less than 1.4 msec for per-instance testing on a single core setting. Jinoh Kim, Makiya Nakashima, Wenjun Fan, Simeon Wuthier, Xiaobo Zhou 0002, Ikkyun Kim, Sang-Yoon Chang |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | A Generic Blockchain Framework to Secure Decentralized ApplicationsabstractBlockchain technology is gaining popularity in industries and governments for information monitoring, distribution, and tracking. Thanks to the built-in security properties, blockchain provides security integrity to various decentralized applications (dApps) involving distributed operations including supply chain, healthcare, banking, internet of things (IoT), and networking. In this paper, we propose a generic blockchain framework (GBF) for applying two blockchains to the dApp systems, one to establish trust and the other to use the trust for securing applications. GBF provides a generally applicable framework and addresses the foundational questions of the blockchain objectives, participants, and the underlying distributed consensus protocol in use. We apply GBF to various case studies from the recent blockchain research to show its effectiveness and generality. We also prototype GBF using smart contract and experiment on CloudLab for preliminary evaluations focusing on the application-general metrics. We propose GBF to facilitate blockchain/dApp research and development by providing the initial framework and enable the preliminary analyses so that the decentralized applications with specific aims can build on GBF. Wenjun Fan, Hsiang-Jen Hong, Xiaobo Zhou 0002, Sang-Yoon Chang |
ICC | 1 |
| 2021 | Robust P2P Connectivity Estimation for Permissionless Bitcoin NetworkabstractBlockchain relies on the underlying peer-to-peer (p2p) networking to broadcast and get up-to-date on the blocks and transactions. It is therefore imperative to have high p2p connectivity for the quality of the blockchain system operations. High p2p networking connectivity ensures that a peer node is connected to multiple other peers providing a diverse set of observers of the current state of the blockchain and transactions. However, in a permissionless blockchain network, using the peer identifiers—including the current approach of counting the number of distinct IP addresses and port numbers—can be ineffective in measuring the number of peer connections and estimating the networking connectivity. Such current approach is further challenged by the networking threats manipulating the identifiers. We build a robust estimation engine for the p2p networking connectivity by sensing and processing the p2p networking traffic. We implement a working Bitcoin prototype connected to the Bitcoin Mainnet to validate and improve our engine’s performances and evaluate the estimation accuracy and cost efficiency of our estimation engine. Hsiang-Jen Hong, Wenjun Fan, Simeon Wuthier, Jinoh Kim, Xiaobo Zhou 0002, C. Edward Chow, Sang-Yoon Chang |
IWQoS | 2 |
| 2021 | A Machine Learning Approach to Peer Connectivity Estimation for Reliable Blockchain NetworkingabstractPeer connectivity plays a significant role in a blockchain network since any poor connectivity may result in the nodes operating on outdated data (e.g., cryptocurrency transactions). Although connectivity information is maintained by individual nodes, such identifier-based information might be unreliable due to the possibility of bogus identifiers. This paper tackles the problem of peer connectivity estimation through data-driven analytics of blockchain traffic for reliable blockchain networking. We define a set of variables to represent traffic characteristics and estimate peer connectivity from the collected data using a machine learning methodology. We also investigate the feasibility of feature prioritization to minimize estimation complexities. Our experimental results show that the presented estimation mechanism makes accurate predictions, with less than 0.1 difference between the measurement and estimation for over 99.7% of predictions. The time complexity measured on a commodity machine shows a microsecond scale for completing a single prediction task, enabling real-time operations. Jinoh Kim, Makiya Nakashima, Wenjun Fan, Simeon Wuthier, Xiaobo Zhou 0002, Ikkyun Kim, Sang-Yoon Chang |
LCN | 3 |
| 2021 | Blockchain-based Secure Coordination for Distributed SDN Control PlaneabstractSoftware-defined wide-area network (SD-WAN) is an emerging and advanced networking platform extending software-defined networking (SDN) across multiple networking domains. Because SD-WAN manages the data plane in the networking domains separated by the public Internet, SDWAN provides a distinct environment and challenges from SDN, including greater risks for the security threats injecting control plane communications from attackers residing outside of the SDN domain. We design and build blockchain-coordinating controllers (BCC) to secure control communications of the SD-WAN controller network formed by the distributed controllers spread across multiple domains. BCC provides resiliency against the security threats in the control plane where an attacker compromises controller communications to manipulate the coordination and the operations of the other controllers. More specifically, BCC provides secure control communications even when up to n controllers’ networking credentials are compromised. BCC is also designed for modularity so that it applies generally across the controller implementations. We prototype BCC using Ethereum and smart contract on CloudLab to validate its effectiveness and efficiency. We experiment on geographically separate nodes on CloudLab and show that BCC achieves the distributed consensus at sub-second level for certificate/key distribution and for network-wide control communication synchronization. Wenjun Fan, Sang-Yoon Chang, Xiaobo Zhou 0002, Younghee Park |
NetSoft | 1 |
| 2020 | Blockchain-based Distributed Banking for Permissioned and Accountable Financial Transaction ProcessingabstractDistributed banking platforms and services forgo centralized banks to process financial transactions. For example, M-Pesa provides distributed banking service in the developing regions so that the people without a bank account can deposit, withdraw, or transfer money. The current distributed banking systems lack the transparency in monitoring and tracking of distributed banking transactions and thus do not support auditing of distributed banking transactions for accountability. To address this issue, this paper proposes a blockchain-based distributed banking (BDB) scheme, which uses blockchain technology to leverage its built-in properties to record and track immutable transactions. BDB supports distributed financial transaction processing but is significantly different from cryptocurrencies in its design properties, simplicity, and computational efficiency. We implement a prototype of BDB using smart contract and conduct experiments to show BDB’s effectiveness and performance. We further compare our prototype with the Ethereum cryptocurrency to highlight the fundamental differences and demonstrate the BDB’s superior computational efficiency. Wenjun Fan, Sang-Yoon Chang, Shawn Emery, Xiaobo Zhou 0002 |
ICCCN | 1 |
| 2020 | Optimizing Social Welfare for Task Offloading in Mobile Edge Computing
Hsiang-Jen Hong, Wenjun Fan, C. Edward Chow, Xiaobo Zhou 0002, Sang-Yoon Chang |
Networking | 2 |
| 2020 | Voting Credential Management System for Electronic Voting Privacy
Arijet Sarker, SangHyun Byun, Wenjun Fan, Maria Psarakis, Sang-Yoon Chang |
Networking | 3 |
| 2020 | Blockchain-enabled Collaborative Intrusion Detection in Software Defined NetworksabstractCollaborative intrusion detection system (CIDS) shares the critical detection-control information across the nodes for improved and coordinated defense. Software-defined network (SDN) introduces the controllers for the networking control, including for the networks spanning across multiple autonomous systems, and therefore provides a prime platform for CIDS application. Although previous research studies have focused on CIDS in SDN, the real-time secure exchange of the detection-relevant information (e.g., the detection signature) remains a critical challenge. In particular, the CIDS research still lacks robust trust management of the SDN controllers and the integrity protection of the collaborative defense information to resist against the insider attacks transmitting untruthful and malicious detection signatures to other participating controllers. In this paper, we propose a blockchain-enabled collaborative intrusion detection in SDN, taking advantage of the blockchain's security properties. Our scheme achieves three important security goals: to establish the trust of the participating controllers by using the permissioned blockchain to register the controller and manage digital certificates, to protect the integrity of the detection signatures against malicious detection signature injection, and to attest the delivery/update of the detection signature to other controllers. Our experiments in CloudLab based on a prototype built on Ethereum, Smart Contract, and IPFS demonstrates that our approach efficiently shares and distributes detection signatures in real-time through the trustworthy distributed platform. Wenjun Fan, Younghee Park, Priyatham Ganta, Xiaobo Zhou 0002, Sang-Yoon Chang |
TrustCom | 1 |
| 2020 | A cloud-edge based data security architecture for sharing and analysing cyber threat informationabstractCyber-attacks affect every aspect of our lives. These attacks have serious consequences, not only for cyber-security, but also for safety, as the cyber and physical worlds are increasingly linked. Providing effective cyber-security requires cooperation and collaboration among all the entities involved. Increasing the amount of cyber threat information (CTI) available for analysis allows better prediction, prevention and mitigation of cyber-attacks. However, organizations are deterred from sharing their CTI over concerns that sensitive and confidential information may be revealed to others. We address this concern by providing a flexible framework that allows the confidential sharing of CTI for analysis between collaborators. We propose a five-level trust model for a cloud-edge based data sharing infrastructure. The data owner can choose an appropriate trust level and CTI data sanitization approach, ranging from plain text, through anonymization/pseudonymization to homomorphic encryption, in order to manipulate the CTI data prior to sharing it for analysis. Furthermore, this sanitization can be performed by either an edge device or by the cloud service provider, depending upon the level of trust the organization has in the latter. We describe our trust model, our cloud-edge infrastructure, and its deployment model, which are designed to satisfy the broadest range of requirements for confidential CTI data sharing. Finally we briefly describe our implementation and the testing that has been carried out so far by four pilot projects that are validating our infrastructure. David W. Chadwick, Wenjun Fan, Gianpiero Costantino, Rogério de Lemos, Francesco Di Cerbo, Ian Herwono, Mirko Manea, Paolo Mori, Ali Sajjad, Xiao-Si Wang |
Future Gener. Comput. Syst. | 2 |
| 2019 | HoneyDOC: An Efficient Honeypot Architecture Enabling All-Round DesignabstractHoneypots are designed to trap the attacker with the purpose of investigating its malicious behavior. Owing to the increasing variety and sophistication of cyber attacks, how to capture high-quality attack data has become a challenge in the context of honeypot area. All-round honeypots, which mean a significant improvement in sensibility, countermeasure, and stealth, are necessary to tackle the problem. In this paper, we propose a novel honeypot architecture termed HoneyDOC to support all-round honeypot design and implementation. Our HoneyDOC architecture clearly identifies three essential independent and collaborative modules, Decoy, Captor, and Orchestrator. Based on the efficient architecture, a software-defined networking-enabled honeypot system is designed, which supplies a high programmability for technically sustaining the features for capturing high-quality data. A proof-of-concept system is implemented to validate its feasibility and effectiveness. The experimental results show the benefits by using the proposed architecture compared with the previous honeypot solutions. Wenjun Fan, Zhihui Du, Max Smith-Creasey, David Fernández 0002 |
IEEE J. Sel. Areas Commun. | 1 |
| 2017 | A novel SDN based stealthy TCP connection handover mechanism for hybrid honeypot systemsabstractHoneypots have been largely used to capture and investigate malicious behavior through deliberately sacrificing their own resources in order to be attacked. Hybrid honeypot architectures consisting of frontends and backends are widely used in the research area, specially due to the benefits of their high scalability and fidelity for detailed attacking data collection. A hybrid honeypot system often needs a facility aimed to tightly control the network traffic, for purposes such as redirecting the traffic from the frontends to the backends for in-depth attack analysis. However, the current traffic redirection approaches, particularly the TCP connection handover mechanisms, are not stealthy and they can be easily detected by attackers. This paper proposes an SDN based network data controller for hybrid honeypot systems that uses a transparent TCP connection handover mechanism and provides a traffic filtering approach based on the Snort alert functionality. The controller is implemented as an application based on the open-source Ryu SDN framework. It allows the users to configure their own network data control rules, which based on the Snort alert messages will forward or redirect the traffic to the corresponding honeypots. The experiments validate the proposed mechanism and the testing results show that the controller can efficiently perform the stealthy TCP connection handover as well. Wenjun Fan, David Fernández 0002 |
NetSoft | 1 |
| 2017 | Versatile virtual honeynet management frameworkabstractHoneypots are designed to investigate malicious behaviour. Each type of homogeneous honeypot system has its own characteristics in respect of specific security functionality, and also suffers functional drawbacks that restrict its application scenario. In practical scenarios, therefore, security researchers always need to apply heterogeneous honeypots to cope with different attacks. However, there is a lack of general tools or platforms that can support versatile honeynet deployment in order to investigate the malicious behavior. In this study, the authors propose a versatile virtual honeynet management tool to address this problem. It is a flexible tool that offers security researchers the versatility to deploy various types of honeypots. It can also generate and manage the virtual honeynet through a dynamic configuration approach adapting to the mutable network environment. The experimental results demonstrate that this tool is effective to perform automated honeynet deployment toward a variety of heterogeneous honeypots. Wenjun Fan, David Fernández 0002, Zhihui Du |
IET Inf. Secur. | 1 |
| 2015 | Dynamic Hybrid Honeypot System Based Transparent Traffic Redirection Mechanism
Wenjun Fan, Zhihui Du, David Fernández 0002, Xinning Hui |
ICICS | 1 |
| 2015 | Technology Independent Honeynet Description LanguageabstractSeveral languages have been proposed for the task of describing networks of systems, either to help on managing, simulate or deploy testbeds for testing purposes. However, there is no one specifically designed to describe the honeynets, covering the specific characteristics in terms of applications and tools included in the honeypot systems that make the honeynet. In this paper, the requirements of honeynet description are studied and a survey of existing description languages is presented, concluding that a CIM (Common Information Model) match the basic requirements. Thus, a CIM like technology independent honeynet description language (TIHDL) is proposed. The language is defined being independent of the platform where the honeynet will be deployed later, and it can be translated, either using model-driven techniques or other translation mechanisms, into the description languages of honeynet deployment platforms and tools. This approach gives flexibility to allow the use of a combination of heterogeneous deployment platforms. Besides, a flexible virtual honeynet generation tool (HoneyGen) based on the approach and description language proposed and capable of deploying honeynets over VNX (Virtual Networks over LinuX) and Honeyd platforms is presented for validation purposes. Wenjun Fan, David Fernández 0002, Víctor A. Villagrá |
MODELSWARD | 1 |
| 2013 | Three-state disk model for high quality and energy efficient streaming media serversabstractEnergy conservation and emission reduction is an increasingly prominent and global issue in green computing. Among the various components of a streaming media server, the storage system is the biggest power consumer. In this paper, a Three-State Disk Model (3SDM) is proposed to conserve energy for streaming media servers without losing quality. According to the load threshold, the disks are dynamically divided into three states: overload, normal and standby. With the requests arriving and departing, the disk state transition among these three states. The purpose of 3SDM is to skew the load among the disks to achieve high quality and energy efficiency for streaming media applications. The load of disks in overload state will move to disks in normal state to improve the quality of service (QoS) level. The load of disks in normal state will be packed together to switch some disks into standby state to save energy. The key problem here is to identify the blocks that need migrating among disks. A sliding window replacement (SWR) algorithm is developed for this purpose, which calculates the block weight based on the request frequency falling within the window of a block. Employing a validated simulator, this paper evaluates the SWR algorithm for conventional disks based on the proposed 3SDM model. The results show that this scheme is able to yield energy efficient streaming media servers. Zhihui Du, Wenjun Fan, Yunpeng Chai |
ISADS | 2 |