VLDB 2026 Research / reviewers in the wild / expert
Lin He 0004
dblp:73/2845-4
· DBLP profile ↗
60ranked-venue papers
6as first author
53since 2021 · last 2026
0000-0002-7348-5833ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 46 · 6 first-author · 42 since 2021Systems, architecture and hardware · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Understanding the IPv6 Address Usage Strategies of Top Internet Services
Lin He 0004, Zedong Jia, Daguo Cheng, Jinlong E, Yuhan Du, Guanglei Song, Ying Liu 0024, Xingang Shi, Shenglin Zhang, Jiahai Yang 0001, Mingwei Xu 0001 |
ICC | 1 |
| 2026 | Beyond Clustering: A Hybrid Framework for Target Generation in Sparse IPv6 Networks
Gang Ren 0003, Xia Yin 0001, Lin He 0004, Haoxiang Yang |
ICC | 4 |
| 2026 | Divide, Predict, Conquer: Adaptive Internet-wide Service Discovery with Limited Seeds
Daguo Cheng, Zedong Jia, Ying Liu 0024, Lin He 0004, Le Gai, Jiuzhou Zhang, Chentian Wei, Zhaoan Wang, Jinlong E |
INFOCOM | 4 |
| 2026 | Breaking the Seed Barrier: Discovering Active IPv6 Addresses in Seedless Scenarios
Wenjian Zhang, Guanglei Song, Binkai Ma, Lin He 0004, Songyun Wu, Jiahai Yang 0001 |
INFOCOM | 4 |
| 2026 | SpecNet-Agent: Network-Aware Speculation Control for QoS in Agentic Generative AI Services
Le Gai, Lin He 0004, Chentian Wei, Zedong Jia, Daguo Cheng, Ying Liu 0024 |
IWQoS | 2 |
| 2026 | SwitchTAD: Defending deep learning-based website fingerprinting attacks with programmable switches
Lin He 0004, Xiaoyi Shi, Yifan Yang 0009, Jinlong E, Ying Liu 0024 |
Comput. Networks | 2 |
| 2026 | AddrProbe: An Internet-Wide Active IPv6 Address Probing System With Limited SeedsabstractWith the large-scale deployment of IPv6, it is becoming more and more important to probe active IPv6 addresses on the global Internet. However, the vast address space and the random distribution of active addresses make the probing process full of challenges, especially for the probing of IPv6 prefixes without seed addresses. Furthermore, the widespread existence of IPv6 aliased prefixes also causes significant trouble for probing. In this paper, we presentAddrProbe, an active IPv6 address probing system, which dynamically probes all global routing prefixes based on learned fine-grained address patterns from limited seed addresses and quickly detects aliased prefixes during probing. The evaluation results show thatAddrProbeachieves a hit rate of 23%-45% with all routing prefixes announced by the BGP system, which is 6.6-13× that of current state-of-the-art approaches (no more than 4%). Moreover, we find 1.2×1033aliased addresses characterized by the detected aliased prefixes, covering 6,412 routing prefixes, which is a 107× and 5.9× improvement over existing methods, respectively. Finally, an IPv6 Hitlist is constructed based on the long-term probing results, which contains 562M addresses covering 190K routing prefixes and 29K ASes. These widely distributed addresses are meaningful for analyzing IPv6 address assignments and some other IPv6 measurement activities. Daguo Cheng, Lin He 0004, Qilei Yin, Guangxing Han, Boran Jin, Ying Liu 0024, Guanglei Song, Jinlong E, Tiankai Yang 0001, Jiahai Yang 0001 |
IEEE Trans. Netw. | 2 |
| 2026 | Do Not Fall Into the Trap: Efficiently Discovering IPv6 Fully Responsive Prefixes in the Wild
Lin He 0004, Chentian Wei, Daguo Cheng, Qilei Yin, Boran Jin, Zhaoan Wang, Xiaoteng Pan, Sixu Zhou, Ying Liu 0024, Shenglin Zhang, Fuchao Tan, Wenmao Liu |
IEEE Trans. Netw. | 1 |
| 2025 | TopoMiner: Efficient IPv6 Topology DiscoveryabstractTopology discovery can be used to obtain the connectivity and operational status of network devices by discovered interfaces. By performing topology discovery on networks, administrators can better understand and manage networks and improve network reliability and security. However, the large IPv6 address space, sparse address distribution, and unknown address assignment policies make it infeasible to simply and roughly probe the IPv6 network topology. To this end, we design an efficient IPv6 interface-level topology discovery method called TopoMiner. It performs multiple rounds of probing the IPv6 topology with the given set of IPv6 prefixes and locates the high-density interface regions based on the results of each round of topology discovery. TopoMiner then performs prefix expansion and address generation for the high-density interface address regions. At the same time, TopoMiner also uses some of the prefixes that have been probed to regenerate the target addresses. In this way, TopoMiner can dynamically adjust the breadth and depth of topology discovery and thus complete multiple rounds of topology discovery within the packetsending budget. In real-word probing, TopoMiner achieves a$3 \sim 7 \times$enhancement in probing efficiency compared to state-of-the-art topology discovery methods. Hongwei Li 0021, Lin He 0004, Guanglei Song, Daguo Cheng, Jiahai Yang 0001, Ying Liu 0024 |
ICC | 3 |
| 2025 | Gungnir: Autoregressive Model for Unified Generation of IPv6 Fully Responsive PrefixesabstractWith the widespread adoption of IPv6, its vast address space presents significant challenges for network asset discovery. Traditional exhaustive scanning approaches are no longer practical, while strategies based on target generation algorithms are increasingly undermined by the existence of Fully Responsive Prefixes (FRPs)—prefixes in which all addresses appear responsive to probing. FRPs distort scanning results, introducing bias and inefficiency. Existing FRP probing techniques suffer from limited scalability, poor accuracy, and restricted applicability in large-scale IPv6 environments.To this end, we propose Gungnir, a multi-protocol unified FRP probing algorithm based on autoregressive semantic modeling. Gungnir captures the intricate relationships between FRP patterns and their influencing factors through a deep semantic learning architecture. It leverages prefix inference and a granularity correction mechanism to accurately predict and validate FRPs, while mitigating errors from incorrect prefix-length estimation. Extensive experiments demonstrate that Gungnir outperforms state-of-the-art techniques, achieving up to 27× higher efficiency, 4.2× wider address space coverage, and broader coverage of both autonomous systems and routing prefixes under the same probing budget. Beyond performance, we further analyze the service and port distributions of the discovered FRPs, uncovering operational patterns and potential security implications. These insights offer valuable guidance for IPv6 measurement, address discovery, and network defense. Chentian Wei, Ying Liu 0024, Lin He 0004, Daguo Cheng |
ICNP | 3 |
| 2025 | PMAPD: A Passive-Enhanced Multi-Level Aliased Prefix Detection Approach for IPv6 ScanningabstractIPv6 scanning is a critical technique for network security assessment and Internet measurement. However, the prevalence of aliased prefixes significantly distorts scan results and severely interferes with target generation algorithms (TGAs) that rely on dynamic density feedback. To address the limitations of existing aliased prefix detection methods, such as insufficient accuracy and excessive overhead, this paper proposes PMAPD, a Passive-Enhanced Multi-Level Aliased Prefix Detection approach. PMAPD integrates passive analysis with active probing. The passive analysis component reuses existing scan data—primarily host responsiveness obtained at no extra cost from the main address scan, and opportunistically uses port and service information if available, to enhance detection accuracy and efficiency. The active probing component builds upon the strengths of prior active methods while incorporating optimizations to achieve a better balance between detection precision and cost. Experimental results demonstrate PMAPD’s superiority in improving the discovery of de-aliased active addresses, reducing aliased addresses in scanning results, and significantly lowering detection overhead. Across three different TGAs tested (6Tree, DET, 6Sense), PMAPD significantly outperforms the widely used traditional method MAPD: it improves the de-aliased hits by 12% to 57%, substantially reduces the aliased ratio in scan results by over 9% to 94%, and dramatically lowers detection overhead, costing only 3% to 17% of MAPD’s overhead. PMAPD offers a novel and effective aliased prefix detection solution for efficient and accurate IPv6 network scanning. Gang Ren 0003, Xia Yin 0001, Lin He 0004 |
ICNP | 4 |
| 2025 | Lightning in the Dark: Uncovering Global IPv6 Router Interfaces and Their Security ImplicationsabstractThe IPv6 routing infrastructure is an important part of the modern Internet, and the collection of its interface addresses is greatly significant in network security, performance optimization, and measurement analysis. However, existing methods suffer from two major problems: the lack of flexibility in budget allocation across probing rounds and the absence of a dynamic hop limit adjustment mechanism based on feedback. These problems lead to the low hit rate and inefficiency of existing methods for discovering router interfaces, which seriously hinders the comprehensive knowledge of IPv6 routing infrastructure.To this end, we propose Helixir, a feedback-based, high hit-rate, and efficient IPv6 router interface discovery system. Helixir’s core design includes a dynamic budget allocation mechanism across probing rounds, an inter-prefix budget allocation strategy that adequately trades off exploration and exploitation, and a hop limit selection method based on Thompson sampling. Real-world experiments show that with a 100M budget, Helixir achieves a hit rate 3.64× that of state-of-the-art methods on the BGP prefixes dataset, and Helixir successfully discovers over 31 million IPv6 router interface addresses in total within half an hour. In addition, a systematic security analysis of the discovered router interfaces shows that many devices open sensitive ports and expose hundreds of potential CVE vulnerabilities, highlighting the security risks in the IPv6 network. Ying Liu 0024, Lin He 0004, Xiaoyi Shi, Yifan Yang 0009, Chentian Wei, Daguo Cheng, Jiahai Yang 0001 |
ICNP | 3 |
| 2025 | SubRecon: Efficient Internet-Wide IPv6 Subnet Discovery and Its ApplicationsabstractThe vastness of the IPv6 address space has led to the common practice of allocating prefixes to end users rather than individual addresses. Users can assign these prefixes as a single subnet or divide them into multiple subnets for different purposes. Allocation strategies vary significantly in terms of prefix granularity, and identifying the actual granularity of subnet assignments is crucial for improving measurement efficiency, accuracy, and for better IPv6 network management. However, no existing method can discover IPv6 subnets at an Internet-Wide scale.To this end, we propose SubRecon, an Internet-Wide IPv6 subnet discovery system. SubRecon consists of two key phases: subnet delimitation and target expansion. In the subnet delimitation phase, we perform a systematic scan across the entire IPv6 address space without relying on any existing seed dataset. This phase adopts a top-down approach, probing prefixes from the shortest to the longest in a hierarchical manner. At each level, we recursively refine prefixes and discard sub-prefixes that do not meet the convergence condition. This pruning strategy eliminates redundant probes in unallocated regions, significantly reducing the search space and improving probing efficiency. To further improve coverage, the target expansion phase leverages the active address dataset as an auxiliary input. It identifies active addresses not covered by previously discovered subnets, expands them into new candidate target prefixes, and performs another round of subnet delimitation. This helps enhance the completeness and coverage of the final discovered subnet set. Experimental results show that SubRecon discovers 8,381,974 IPv6 subnets across 14,147 autonomous systems, and the resulting subnet list can serve as high-quality input for topology discovery. Additionally, during the subnet discovery process, SubRecon identifies a large number of last-hop router interfaces, discovering approximately 10 million more than the current state-of-the-art methods. Ying Liu 0024, Lin He 0004, Yifan Yang 0009, Xiaoyi Shi, Daguo Cheng, Chentian Wei, Yun Fan, Guanglei Song |
ICNP | 3 |
| 2025 | Poster: TopoHunter: Enabling Efficient and High-Coverage Active IPv6 Topology DiscoveryabstractWe introduce TopoHunter, an efficient IPv6 Internet topology discovery system. The central concept of TopoHunter is to allocate more probing resources to target prefix spaces that yield greater topological benefits, as well as to their surrounding areas. To achieve this, we design a feedback-based target generation module comprised of a Target Prefix Probing Value Forest that maintains the estimated probing values of hierarchical target prefix spaces. Our system has successfully discovered the most extensive and complete IPv6 topology map to date, comprising over 144 million router interfaces and 251 million edges, covering 72.83% of autonomous systems and 43.36% of routing prefixes announced by the BGP system. Lin He 0004, Hongwei Li 0021, Guanglei Song, Wentong Wang, Daguo Cheng, Enhuan Dong, Chenglong Li 0006, Hui Zhang 0141, Jinlong E, Ying Liu 0024, Jiahai Yang 0001 |
IMC | 2 |
| 2025 | 6Map: Enabling Fast Active IPv6 Address Discovery with Programmable Switches
Lin He 0004, Yifan Yang 0009, Xiaoyi Shi, Daguo Cheng, Jinlong E, Ying Liu 0024, Dong Zhang 0010 |
INFOCOM | 2 |
| 2025 | Bringing New Life to Old Tools: Measuring Source Address Validation Deployment with 6in4 TunnelsabstractSource Address Validation (SAV) is a security mechanism deployed at network boundaries to prevent packets with illegal source addresses from crossing these boundaries. While SAV plays an important role in mitigating source address spoofing, its deployment across the global Internet remains limited. Measuring SAV deployment is essential for enhancing the understanding of the security landscape of networks. In this study, we propose a novel method for measuring SAV deployment based on 6 in 4 tunnels, complementing existing measurement work. Using this method, we measure inbound SAV for IPv4 and outbound SAV for IPv6, obtaining results from 12,417 and 2,104 Autonomous Systems (ASes), respectively. Based on our measurements, we analyze factors that may influence SAV deployment, including network address space size, AS type, and geographical location. Additionally, we provide a global heatmap of spoofable rates for networks in different countries and regions. Note that the measuring method using bin4 tunnels we introduce is not only applicable to SAV measurements but also holds potential for other measurement tasks, such as connectivity testing and transmission path discovery. This method offers a new way for large-scale measurement tasks across different networks, which may benefit future research. Jiaxing Guo, Lin He 0004, Daguo Cheng, Xingang Shi, Ying Liu 0024 |
IWQoS | 2 |
| 2025 | APCC: Enabling Reliable IPv6 Covert Communication with Aliased PrefixesabstractCovert communication ensures undetectable information exchange between parties while posing risks when exploited for malicious purposes. Existing network covert channels face challenges in reliability, throughput, and stealthiness due to packet loss, limited capacity, and detectable anomalies. This paper proposes APCC, a reliable covert communication system that leverages IPv6 aliased prefixes for the first time, where secret data is embedded in the Interface Identifier field of IPv6 addresses. APCC enhances stealthiness through encryption and camouflage strategies (e.g., traffic blending and rate control). Additionally, it employs a reliable transmission mechanism incorporating sequence numbering, acknowledgment, and retransmission to mitigate packet loss and reordering. It ensures deployment flexibility across ICMPv6, UDP, or TCP protocols. Evaluations in real-world and simulated environments demonstrate that APCC achieves 100% accuracy under high latency ($\mathbf{8 0 0 ~ m s ~ R T T}$) and packet loss (10%), with throughput up to 34.7 Kbps. Detection tests show APCC evades major intrusion detection systems (Snort, Zeek) except for Suricata's TCP alerts. We also propose mitigation measures to reduce APCC's potential negative impact. This work highlights critical vulnerabilities in IPv6 infrastructure while advancing robust covert communication methodologies for high-stakes scenarios. Zhaoan Wang, Lin He 0004, Daguo Cheng, Ying Liu 0024 |
IWQoS | 2 |
| 2025 | RGen: A Real-Time Pattern Mining Approach to Target Generation for Internet-Wide IPv6 ScanningabstractTarget generation is a crucial step for efficient Internet-wide IPv6 scanning, yet existing techniques are hindered by limited pattern discovery and biased target distribution. We introduce RGen, a novel target generation algorithm employing real-time pattern mining and a stochastic generation strategy. RGen minimizes pattern loss, dynamically incorporates new addresses, and promotes balanced target distribution, overcoming prior limitations. Experiments show RGen achieves the highest overall hit rate (58%), surpassing the previous best (AddrMiner-S) by 60%, while simultaneously leading in network discovery, finding the most new BGP prefixes and new / 64 prefixes. Gang Ren 0003, Xia Yin 0001, Lin He 0004 |
IWQoS | 4 |
| 2025 | 6RV: Incremental Learning-Based Continuous Identification of IPv6 Router VendorsabstractThe growth of IPv6 networks has led to an expanding number of network routers, but there is not enough research on vendors of these devices. Existing router vendor identification algorithms are based on IPv4, and these static analysis algorithms cannot adapt to dynamically changing IPv6 networks. In this paper, we develop 6RV, a framework for IPv6 router vendors continuous identification based on incremental learning. First, we count the addresses of newly discovered router interfaces every month and obtain router device fingerprints through active probing, and then analyze these data fingerprints through an incremental learning approach to identify the router vendors of new nodes. We validate our identification framework on the ITDK dataset over a period of 8 months, obtaining more than 500K router vendor labels with 94% correctness. Finally, we also analyze the IPv6 router vendor dataset from different perspectives and draw some interesting conclusions. Shenao Li, Jiahai Yang 0001, Enhuan Dong, Chenglong Li 0006, Lin He 0004, Hui Zhang 0052, Guanglei Song |
NOMS | 6 |
| 2025 | Wisely Optimizing Short Video Streaming for a User-Vendor Win-Win OutcomeabstractShort video streaming platforms widely employ video prefetching to ensure users' quality of experience (QoE), but frequent user swipes lead to massive data wastage, creating a significant financial burden for vendors. Existing academic and industrial solutions fail to strike a balance, often sacrificing either data savings or the authentic user-perceived QoE. We introduce a framework that intelligently reduces streaming data consumption without compromising user experience. The core idea is to make prefetching decisions adaptive to both user swiping behavior and dynamic network conditions. Real-world evaluations show our framework significantly outperforms the state-of-the-art solutions on data wastage as well as user-perceived QoE. Jinlong E, Wei Xu 0057, Jianfei Bi, Lin He 0004, Anqi Gu, Yunpeng Chai |
SIGCOMM | 4 |
| 2025 | TGW: Operating an Efficient and Resilient Cloud Gateway at Scale
Yifan Yang 0009, Lin He 0004, Xiaoyi Shi, Yichi Xu, Jinlong E, Ying Liu 0024, Zhuang Yuan, Hengyang Xu |
USENIX ATC | 2 |
| 2025 | IPdb: A High-Precision IP Level Industry Categorization of Web ServicesabstractIP addresses with web services are crucial in the Internet ecosystem. Classifying these addresses by industry and organization offers valuable insights into the entities utilizing them, enabling more efficient network management and enhanced security. Previous work in website classification and Internet management struggles to offer an IP-level perspective of the industries of web services due to their limited industry categories or potential industry inconsistencies between IP address owners and AS owners. To this end, we present IPdb, an IP-level industry categorization dataset. To construct the dataset, we developed LLMIC, a Large Language Model-based Industry Categorization framework with a precision of nearly 96%. IPdb serves as a labeled database for future endeavors in developing IP-level industry classifiers, encompassing over 200 million IP addresses. Furthermore, our study indicates that 30% ~ 50% of organizations within critical infrastructure industries deploy web servers across multiple ASes. Our study also validates the problem of mismatched granularity in industry categorization at the AS level with 87.83% ASes in IPv4 and 72.96% ASes in IPv6 containing IP addresses from different industries. Guanglei Song, Jiahai Yang 0001, Songyun Wu, Jinlei Lin, Lin He 0004, Chenglong Li 0006 |
WWW | 7 |
| 2025 | Miresga: Accelerating Layer-7 Load Balancing with Programmable SwitchesabstractAs online cloud services expand rapidly, layer-7 load balancing has become indispensable for maintaining service availability and performance. The emergence of programmable switches with both high performance and a certain degree of flexibility has made it possible to apply programmable switches to load balancing. Nevertheless, the limited memory capacity and the relatively sluggish speed of table entry insertion and deletion of programmable switches have severely constrained their performance. Xiaoyi Shi, Lin He 0004, Yifan Yang 0009, Ying Liu 0024 |
WWW | 2 |
| 2024 | Luori: Active Probing and Evaluation of Internet-Wide IPv6 Fully Responsive PrefixesabstractWith the large-scale deployment and application of IPv6, IPv6 network measurements will become increasingly important. However, a special type of IPv6 prefix called Fully Responsive Prefix (FRP) is having a significant impact on IPv6 measurement campaigns, which is defined as all addresses under a prefix responding to scans. Obviously, there cannot be a real responder behind each of these addresses. To reveal the current status and impact of Internet-wide IPv6 FRPs, we propose for the first time an active probing method for Internet-wide IPv6 FRPs, Luori, which transforms the active probing process under IPv6 huge prefix space (potential range of prefix presence) into a dynamic search process in a tree based on reinforcement learning, achieving efficient probing of arbitrary routing prefixes. The evaluation results show that Luori found 31.7K largest FRPs in a single Internet-wide probing with 11 M budget, covering$1.5 \times 10^{30}$address space, which is$10^{6} \times$that of existing methods. More importantly, after six months of Internet-wide probing, we have found 516 K largest FRPs, which covers$1.3 \times 10^{33}$address space and 795 ASes, making it the largest publicly known FRP list. Based on this list, we screen out$20 \%$of the addresses covered by FRPs from a well-known IPv6 active address dataset. Furthermore, we further analyze and find that the distribution of these FRPs is extensive and their implementation methods are diverse, which can provide beneficial references for the practical application of FRPs. We also make this list publicly available and maintain it long-term for use and study by relevant researchers. Daguo Cheng, Lin He 0004, Chentian Wei, Qilei Yin, Boran Jin, Zhaoan Wang, Xiaoteng Pan, Sixu Zhou, Ying Liu 0024, Shenglin Zhang, Fuchao Tan, Wenmao Liu |
ICNP | 2 |
| 2024 | 6Vision: Image-Encoding-Based IPv6 Target Generation in Few-Seed ScenariosabstractEfficient global Internet scanning is crucial for network measurement and security analysis. While existing target generation algorithms verify remarkable performance in largescale detection, their efficiency notably diminishes in few-seed scenarios. This decline is primarily attributed to the intricate configuration rules and sampling bias of seed addresses. Moreover, instances where BGP prefixes have few seed addresses are widespread, constituting$63.65 \%$of occurrences. We introduce 6 Vision to tackle this challenge by introducing a novel approach to encoding IPv6 addresses into images, facilitating comprehensive analysis of intricate configuration rules. Through feature stitching, 6 Vision not only improves the learnable features but also amalgamates addresses associated with configuration patterns for enhanced learning. Moreover, it integrates an environmental feedback mechanism to refine model parameters based on identified active addresses, thereby alleviating the sampling bias inherent in seed addresses. As a result, 6Vision achieves high-accuracy detection even in few-seed scenarios. The HitRate of 6 Vision is improved by$181 \% \sim 2,490 \%$compared to existing algorithms, while the CoverNum is$1.18 \sim 11.20$times that of them. Additionally, 6Vision can function as a preliminary detection module for existing algorithms, yielding a conversion gain (CG) ranging from$242 \% \sim 2,081 \%$. Ultimately, we achieve a conversion rate (CR) of$28.97 \%$for few-seed scenarios. We enrich the IPv6 hitlist, not only enhancing current target generation algorithms for large-scale address detection in few-seed scenarios but also effectively supporting IPv6 network measurement and security analysis. Wenjian Zhang, Guanglei Song, Lin He 0004, Jinlei Lin, Songyun Wu, Chenglong Li 0006, Jiahai Yang 0001 |
ICNP | 3 |
| 2024 | AggDeliv: Aggregating Multiple Wireless Links for Efficient Mobile Live Video DeliveryabstractMobile live-streaming applications with stringent latency and bandwidth requirements have gained tremendous attention in recent years. Encountered with bandwidth insufficiency and congestion instability of the wireless uplinks, multi-access networking provides opportunities to achieve fast and robust connectivity. However, the state-of-the-art multi-path transmission solutions are lack of adaptivity to the heterogeneous and dynamic nature of wireless networks. Meanwhile, the indispensable video coding and transformation bring about extra latency and make the video delivery vulnerable to network throughput fluctuation. This paper presents AggDeliv, a framework that provides efficient and robust multi-path transmission for mobile live video delivery. The key idea is to relate multi-path packet scheduling to congestion control optimization over diverse wireless links and adapt it to the mobile video characteristics. This is achieved by probabilistic packet allocation based on links’ congestion windows, wireless-oriented delay and loss aware congestion control, as well as lightweight video frame coding and network-adaptive frame-packet transformation. Real-world evaluations demonstrate that our framework significantly outperforms the state-of-the-art solutions on aggregate goodput and streaming video bitrate. Jinlong E, Lin He 0004, Zongyi Zhao, Yachen Wang, Gonglong Chen |
INFOCOM | 2 |
| 2024 | Overlooked Backdoors: Investigating 6to4 Tunnel Nodes and Their Exploitation in the WildabstractAs native IPv6 adoption increases, the use of 6to4 tunnels has declined, yet they remain a significant security concern in today’s Internet. This study investigates the real-world deployment of 6to4 tunnels, revealing their current scale, characteristics, and security implications. We identify open 6to4 relays in 216 countries and 13,114 autonomous systems, noting stable short-term counts but a long-term decline. We analyze the security of these nodes and find over 578k nodes vulnerable to address spoofing and packet injection. Additionally, we present several under-emphasized scenarios where open 6to4 nodes are abused, including leveraging services on 6to4 nodes as traffic amplifiers, circumventing restrictions using multiple 6to4 addresses, and connecting 6to4 nodes to render attacks untraceable. Jiaxing Guo, Lin He 0004, Ying Liu 0024 |
IPCCC | 2 |
| 2024 | P4runpro: Enabling Runtime Programmability for RMT Programmable SwitchesabstractProgrammable switches have revolutionized network operations by enabling the flexible customization of packet processing logic using language like P4. However, changing the programs running on the switch requires disturbing traffic and suspending other unrelated programs. In this paper, we present P4runpro, enabling runtime data plane updates with dynamic resource allocation. The P4runpro data plane abstracts hardware resources and defines dynamically reconfigurable atomic operations that form packet processing logic. P4runpro provides runtime programming interfaces called P4runpro primitives for the operator to write high-level programs. We have designed the P4runpro compiler to automatically and consistently link the P4runpro programs to the running data plane. We implement our prototype on a Tofino switch. We implement 15 example runtime programs using P4runpro to demonstrate its generality and expressiveness. Our evaluation results show that compared to the state-of-the-art, P4runpro can respond within hundreds of milliseconds, achieve an average of 60% to 80% dynamic resource utilization, concurrently run ≈0.6K to ≈2.8K programs, and introduce lower overhead. Our case studies illustrate the benefit of runtime programming and prove the same functionality between P4runpro and conventional P4 programs. Yifan Yang 0009, Lin He 0004, Xiaoyi Shi, Jiamin Cao, Ying Liu 0024 |
SIGCOMM | 2 |
| 2024 | WiseCam: A Systematic Approach to Intelligent Pan-Tilt Cameras for Moving Object TrackingabstractWith the desired functionality of moving object tracking, wireless pan-tilt cameras are able to play critical roles in a growing diversity of surveillance environments. However, today's pan-tilt cameras oftentimes underperform when tracking frequently moving objects like humans – they are prone to lose sight of objects and bring about excessive mechanical rotations that are especially detrimental to those energy-constrained outdoor scenarios. The ineffectiveness and high cost of all state-of-the-art tracking approaches are rooted in their adherence to the industry's simplicity principle, which leads to their stateless nature, performing gimbal rotations based only on the latest object detection. To address the issues, we design and implement WiseCam that wisely tunes the pan-tilt cameras to minimize mechanical rotation costs while maintaining long-term object tracking. This systematic tracking approach also tackles issues of motion-rotation speed gap and scattered moving objects, which is universally applicable to complex tracking scenarios. We examine the performance of WiseCam by experiments on two types of pan-tilt cameras with different motors. Results show that it significantly outperforms the state-of-the-art tracking approaches on both tracking duration and power consumption. Jinlong E, Fangshuo Han, Lin He 0004, Wei Xu 0057, Zhenhua Li 0001, Yunpeng Chai, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | PMap: Reinforcement Learning-Based Internet-Wide Port ScanningabstractInternet-wide scanning is a commonly used research technique in various network surveys, such as measuring service deployment and security vulnerabilities. However, these network surveys are limited to the given port set, not comprehensively obtaining the real network landscape, and even misleading survey conclusions. In this work, we introduce PMap, a port scanning tool that efficiently discovers the most open ports from all 65K ports in the whole network. PMap uses the correlation of ports to build an open port correlation graph of each network, using a reinforcement learning framework to update the correlation graph based on feedback results and dynamically adjust the order of port scanning. Compared to current port scanning methods, PMap performs better on hit rate, coverage, and intrusiveness. Our experiments over real networks show that PMap can find 90% open ports by only scanning 125 ports (90%@125) to each address, which is 99.3% less than the state-of-the-art port scanning methods. It reduces the number of scanned ports to decrease the intrusive nature of port scanning. In addition, PMap is highly parallel and lightweight. It scans 500 networks in parallel, achieving a port recommendation rate of up to 18 million per second, consuming only 7GB of memory. PMap is the first effective practice for scanning open ports using reinforcement learning. It bridges the gap of existing scanning tools and effectively supports subsequent service discovery and security research. Guanglei Song, Lin He 0004, Jinlei Lin, Linna Fan, Jiahai Yang 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2024 | AddrMiner: A Fast, Efficient, and Comprehensive Global Active IPv6 Address Detection SystemabstractFast Internet-wide scanning is essential for network situational awareness and asset evaluation. However, the vast IPv6 address space makes brute-force scanning infeasible. Despite advancements in state-of-the-art methods, they do not work in seedless regions and suffer low detection efficiency and speed in regions with known active IPv6 addresses (i.e., seed addresses). Moreover, the collected active address list (i.e., IPv6 hitlist) with low coverage cannot truly represent the active IPv6 address landscape of the Internet. This paper introduces AddrMiner, a fast, efficient, and comprehensive global active IPv6 address detection system. We design a systematic active IPv6 address detection strategy that divides the IPv6 space into two detection scenarios based on the presence or absence of seed addresses to discover active IPv6 addresses from scratch and from few to many. In the seedless regions, we present AddrMiner-N, leveraging a multi-level association policy to probe active addresses. It fills the gap of address detection in seedless regions and successfully discovers active addresses in 39,899 BGP prefixes without seed addresses, with a$1.03\times $higher hit rate,$30\sim 911\times $higher speed, and$2.7\times $broader coverage, compared to existing solutions. In the regions with seed addresses, our method AddrMiner-S dynamically generates target addresses using reinforcement learning. Compared to state-of-the-art methods, AddrMiner-S achieves an impressive 56.3% hit rate and a discovery speed of 839.0/s, which is$1.9\sim 2153\times $and$1.5\sim 755\times $of existing works, respectively. Finally, we deploy AddrMiner and discover 2.1B active IPv6 addresses, including 1.7B de-aliased active addresses and 0.4B aliased addresses, through continuous probing for three years. Guanglei Song, Lin He 0004, Feiyu Zhu 0002, Jinlei Lin, Wenjian Zhang, Linna Fan, Chenglong Li 0006, Jiahai Yang 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | WiseCam: Wisely Tuning Wireless Pan-Tilt Cameras for Cost-Effective Moving Object Tracking
Jinlong E, Lin He 0004, Zhenhua Li 0001, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2023 | GraphIoT: Accurate IoT Identification based on Heterogeneous GraphabstractIoT devices deployed on campus and enterprise networks facilitate people's lives and work. However, these devices also bring serious network asset management and security management problems. IoT device identification is the premise to solve these problems. Although current IoT identification methods can identify devices with relatively high accuracy in ideal environments, it is difficult to accurately identify devices in real-world complex environments (e.g., campus networks, enterprise networks). Therefore, we propose to use exact features. To solve the problem of different dimensions of exact features, we creatively model the IoT identification problem as a heterogeneous graph representation learning problem and design a new representation learning algorithm. We are the first to propose an approach to accurately identify IoT devices in real-world complex environments and solve this problem through heterogeneous graphs. The evaluation shows that GraphIoT's macro F1 is on average 13.58% and 12.77% higher than the other methods on two public datasets. Linna Fan, Lin He 0004, Xiaoqing Sun, Enhuan Dong, Jiahai Yang 0001, Jinlei Lin, Guanglei Song |
IWQoS | 2 |
| 2023 | Which Doors Are Open: Reinforcement Learning-based Internet-wide Port ScanningabstractInternet-wide scanning is a commonly used research technique in various network surveys, such as measuring service deployment and security vulnerabilities. However, these network surveys are limited to the given port set, not comprehensively obtaining the real network landscape, and even misleading survey conclusions. In this work, we introduce PMap, a port scanning tool that efficiently discovers the majority of open ports from all 65K ports in the whole network. PMap uses the correlation of ports to build an open port correlation graph of each network, using a reinforcement learning framework to update the correlation graph based on feedback results and dynamically adjust the order of port scanning. Compared to current port scanning methods, PMap achieves better performance on hit rate, coverage, and intrusiveness. Our experiments over real-world networks show that PMap can find 90% open ports by only scanning 125 ports (90% @125) to each active address with 136× less than the state-of-the-art port probing methods. PMap reduces the number of scanned ports to decrease the intrusive nature of port scanning. PMap is the first effective practice for scanning open ports using reinforcement learning. It bridges the gap of existing scanning tools and effectively supports subsequent service discovery and security research. Guanglei Song, Lin He 0004, Tianyun Zhao, Yirui Luo, Yichao Wu, Linna Fan, Chenglong Li 0006, Jiahai Yang 0001 |
IWQoS | 2 |
| 2023 | Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side Channels
Long Pan, Jiahai Yang 0001, Lin He 0004, Leyao Nie, Guanglei Song, Yaozhong Liu |
NDSS | 3 |
| 2023 | AutoIoT: Automatically Updated IoT Device Identification With Semi-Supervised LearningabstractIoT devices bring great convenience to a person's life and industrial production. However, their rapid proliferation also troubles device management and network security. Network administrators usually need to know how many IoT devices are in the network and whether they behave normally. IoT device identification is the first step to achieving these goals. Previous IoT device identification methods reach high accuracy in a closed environment. But they are not applicable in the continuously changing environment. When new types of devices are plugged in, they cannot update themselves automatically. Besides, they usually rely on supervised learning and need lots of labeled data, which is costly. To solve these problems, we propose a novel IoT device identification model namedAutoIoT, updating itself automatically when new types of devices are plugged in. Besides, it only needs a few labeled data and identifies IoT devices with high accuracy. The evaluation on two public datasets shows thatAutoIoTcan identify new device types only using 1.5$\sim$2.5 hours’ traffic and still have high accuracy after updating. Moreover, it has a better performance than other works when there are only a few labeled data, especially in an environment with scanning traffic. Linna Fan, Lin He 0004, Yichao Wu, Shize Zhang, Jia Li 0033, Jiahai Yang 0001, Chaocan Xiang, Xiaoqian Ma |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | PerfTrace: A New Multi-metric Network Performance Monitoring ToolabstractWe present PerfTrace, an end-to-end tool for efficient, real-time, and multi-metric network performance monitoring. PerfTrace provides a high integration of different existing measurement functions, supporting the measurement of essential metrics such as latency, jitter, packet loss, and available bandwidth. More importantly, innovative schemes and algorithms are proposed to address the weaknesses of existing tools.After conducting comprehensive evaluations, we find that (i) PerfTrace measures one-way and two-way latency, jitter, and packet loss ∼9.4× faster and ∼3.6× more data-efficiently; (ii) PerfTrace measures available bandwidth in our testbed with minimal mean relative error (5.22%), outperforming all the tools compared (ranging from 8.17% to 37.24%). Meanwhile, PerfTrace consumes a more constant percentage of bandwidth resources than other tools when monitoring available bandwidth. PerfTrace’s data overhead is always only about 1/600 of the total bandwidth for a measurement frequency once per minute. Yaozhong Liu, Long Pan, Chenglong Li 0006, Lin He 0004, Yirui Luo, Guanglei Song, Jiahai Yang 0001 |
CNSM | 4 |
| 2022 | Towards a Behavioral and Privacy Analysis of ECS for IPv6 DNS ResolversabstractThe Domain Name System (DNS) is critical to Internet communications. EDNS Client Subnet (ECS), a DNS extension, allows recursive resolvers to include client subnet information in DNS queries to improve CDN end-user mapping, extending the visibility of client information to a broader range. Major content delivery network (CDN) vendors, content providers (CP), and public DNS service providers (PDNS) are accelerating their IPv6 infrastructure development. With the increasing deployment of IPv6-enabled services and DNS being the most foundational system of the Internet, it becomes important to analyze the behavioral and privacy status of IPv6 resolvers. However, there is a lack of research on ECS for IPv6 DNS resolvers.In this paper, we study the ECS deployment and compliance status of IPv6 resolvers. Our measurement shows that 11.12% IPv6 open resolvers implement ECS. We discuss abnormal noncompliant scenarios that exist in both IPv6 and IPv4 that raise privacy and performance issues. Additionally, we measured if the sacrifice of clients’ privacy can enhance IPv6 CDN performance. We find that in some cases ECS helps end-user mapping but with an unnecessary privacy loss. And even worse, the exposure of client address information can sometimes backfire, which deserves attention from both Internet users and PDNSes. Leyao Nie, Lin He 0004, Guanglei Song, Chenglong Li 0006, Jiahai Yang 0001 |
CNSM | 2 |
| 2022 | Both Efficient and Accurate: A Large-scale One-way Delay Measurement SchemeabstractOne-way delay (OWD) is one of the essential network performance metrics. In large-scale resilient overlay networks (RONs), OWD measurements can be used for shortest path selection and troubleshooting. However, OWD measurements remain difficult because of the need for precise time synchronization. Especially in large-scale networks, clock synchronization of all nodes has always been a considerable challenge. Therefore, in many cases, people use half of the round-trip time (RTT/2) as a rough substitute for the OWD. This paper presents an efficient and easy-to-deploy scheme for large-scale OWD measurements with the algorithm ClockConverger at its core. The scheme consists of three steps: Firstly, we perform low-precision time synchronization for all the measured nodes relying on network time protocol daemons (ntpd); Then, we use the open-source tool OWPing to perform OWD measurements; Finally, we correct the errors of the measured OWDs with our proposed ClockConverger. The theory and experiments show that our scheme's accuracy is significantly better than RTT/2. Meanwhile, the complexity of ClockConverger is$O(n^{2})$, which is much lower than the exponential complexity of the existing Maximum-Entropy algorithm. Yaozhong Liu, Jiahai Yang 0001, Long Pan, Lin He 0004, Jinlei Lin, Guanglei Song, Chenglong Li 0006 |
GLOBECOM | 5 |
| 2022 | What Causes Delay Asymmetry: A Large-scale One-way Delay Measurement and Empirical StudyabstractIn global communications, severe one-way delay (OWD) asymmetry often occurs. Due to the difficulties of OWD measurement (need to control both ends and synchronize their clocks), now RTT/2 is commonly used to estimate OWD. However, OWD asymmetry can lead to large errors in the halving RTT method, which in turn affects the end-to-end quality of service (QoS) guarantees. In this paper, we investigate OWD asymmetry through large-scale OWD measurements on a global scale. The measurements show that more than 11% of network paths have OWDs with a relative difference of more than 10% compared to RTT/2. By analyzing the measurement results in depth, we try to explain why the delay asymmetry occurs. We find that 67% is caused by hop inflation or a significant increase in propagation distance, and 33% is caused by variable queuing delays. We also find AS-level paths between node pairs with significant delay asymmetry are much more likely (~ 10 ×) to violate the well-known valley-free rule. Yaozhong Liu, Jiahai Yang 0001, Long Pan, Lin He 0004, Jinlei Lin, Guanglei Song, Chenglong Li 0006 |
GLOBECOM | 5 |
| 2022 | Firebolt: Finding Bugs in Programmable Data Plane Generators
Jiamin Cao, Yu Zhou 0008, Chen Sun 0005, Lin He 0004, Zhaowei Xi, Ying Liu 0024 |
USENIX ATC | 4 |
| 2022 | AddrMiner: A Comprehensive Global Active IPv6 Address Discovery System
Guanglei Song, Jiahai Yang 0001, Lin He 0004, Chenxin Duan, Yaozhong Liu, Zhongxiang Sun |
USENIX ATC | 3 |
| 2022 | EvoIoT: An evolutionary IoT and non-IoT classification model in open environments
Linna Fan, Lin He 0004, Enhuan Dong, Jiahai Yang 0001, Chenglong Li 0006, Jinlei Lin |
Comput. Networks | 2 |
| 2022 | TurboNet: Faithfully Emulating Networks With Programmable SwitchesabstractFaithfully emulating networks is critical for verifying the correctness and effectiveness of new networking-related designs. Existing network experiment platforms either cannot faithfully emulate the functionality and performance of production networks or cannot scale well due to cost constraints. In this paper, we proposeTurboNet, a new network emulator that utilizes one or more programmable switches to achieve faithful emulation of the network data plane and control plane. For data plane emulation, we propose a series of key designs, such as port mapper, queue mapper, and delayed queue, to emulate network topologies and performance metrics with high flexibility and accuracy. For control plane emulation, we support static routing configurations, distributed routing agents, and the centralized routing controllers. Meanwhile, we provide APIs for operators to simplify network emulation tasks. We implementTurboNeton Tofino switches. Evaluation results show that: (1) On the data plane,TurboNetcan flexibly emulate various topologies, such as an 8-ary fat-tree with only one programmable switch and a 10-ary fat-tree with four programmable switches; (2) On the control plane,TurboNetsupports about 200 BGP agents on a single programmable switch with a CPU usage of 25%; (3)TurboNetcan accurately emulate different network performance metrics such as 10−8link loss, and microsecond to millisecond link delay. Jiamin Cao, Ying Liu 0024, Yu Zhou 0008, Lin He 0004, Mingwei Xu 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | DET: Enabling Efficient Probing of IPv6 Active AddressesabstractFast IPv4 scanning significantly improves network measurement and security research. Nevertheless, it is infeasible to perform brute-force scanning of the IPv6 address space. Alternatively, one can find active IPv6 addresses through scanning the candidate addresses generated by state-of-the-art algorithms. However, the probing efficiency of such algorithms is often very low. In this paper, our objective is to improve the probing efficiency of IPv6 addresses. We first perform a longitudinal active measurement study and build a high-quality dataset, hitlist, including more than 1.95B IPv6 addresses distributed in 58.2K BGP prefixes and collected over 17 months period. Different from the previous works, we probe the announced BGP prefixes using a pattern-based algorithm. This results in a dataset without uneven address distribution and low active rates. Further, we propose an efficient address generation algorithm, DET, which builds a density space tree to learn high-density address regions of the seed addresses with linear time complexity and improves the active addresses’ probing efficiency. We then compare our algorithm DET against state-of-the-art algorithms on the public hitlist and our hitlist by scanning 50M addresses. Our analysis shows that DET increases the de-aliased active address ratio and active address (including aliased addresses) ratio by 10%, and 14%, respectively. Furthermore, we develop a fingerprint-based method to detect aliased prefixes. The proposed method for the first time directly verifies whether the prefix is aliased or not. Our method finds that 10.64% of the public aliased prefixes are false positive. Guanglei Song, Jiahai Yang 0001, Lin He 0004, Jinlei Lin, Long Pan, Chenxin Duan, Xiaowen Quan |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | CoFilter: High-Performance Switch-Accelerated Stateful Packet Filter for Bare-Metal ServersabstractAs one of the most critical cloud services, Bare-Metal Servers (BMS) introduce stringent performance requirements on data center networks (DCN). Stateful packet filter is an integral DCN component of ensuring connection security for BMS. However, the off-the-shelf stateful packet filters either are costly for cloud DCNs or introduce significant performance bottlenecks. In this article, we presentCoFilter, which leverages low-cost programmable switches to accelerate the stateful packet filter for BMS.CoFilteruses (1)stateful process partitionto enable complex stateful packet filtering logic on programmability-limited switching ASICs, (2)state compressionto track tens of millions of connections with constrained hardware memory, and (3)per-tenant packet rate limit and tenant-aware flow migrationto achieve efficient performance isolation among different tenants. Overall,CoFilterimplements a high-performance stateful packet filter via the co-design of programmable switching ASIC and CPU. We evaluateCoFilterunder various data center traffic traces with real-world flow distributions. The evaluation results show thatCoFilterremarkably outperforms NetFilter, i.e., forwarding packets at line rate (13x throughput of NetFilter), keeping packet delay within 1us, and freeing a significant quantity of CPU cores, with rather small memory usage, i.e., accommodating over$10^7$connections with only 16MB SRAM. Jiamin Cao, Ying Liu 0024, Yu Zhou 0008, Lin He 0004, Chen Sun 0005, Yangyang Wang 0001, Mingwei Xu 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Deception Maze: A Stackelberg Game-Theoretic Defense Mechanism for Intranet ThreatsabstractThe intranets in modern organizations are facing severe data breaches and critical resource misuses. By reusing user credentials from compromised systems, Advanced Persistent Threat (APT) attackers can move laterally within the internal network. A promising new approach called deception technology makes the network administrator (i.e., defender) able to deploy decoys to deceive the attacker in the intranet and trap him into a honeypot. Then the defender ought to reasonably allocate decoys to potentially insecure hosts. Unfortunately, existing APT-related defense resource allocation models are infeasible because of the neglect of many realistic factors.In this paper, we make the decoy deployment strategy feasible by proposing a game-theoretic model called the APT Deception Game to describe interactions between the defender and the attacker. More specifically, we decompose the decoy deployment problem into two subproblems and make the problem solvable. Considering the best response of the attacker who is aware of the defender’s deployment strategy, we provide an elitist reservation genetic algorithm to solve this game. Simulation results demonstrate the effectiveness of our deployment strategy compared with other heuristic strategies. Jieling Liu, Jiahai Yang 0001, Bo Wang 0066, Lin He 0004, Guanglei Song |
ICC | 5 |
| 2021 | CloudPin: A Root Cause Localization Framework of Shared Bandwidth Package Traffic Anomalies in Public Cloud NetworksabstractDue to the sharing nature of public cloud, most of the cloud services use a sharing bandwidth package (sBwp) model to conduct inbound/outbound communication. The sBwp model allows users to purchase a sharing bandwidth for plenty of virtual machines instead of purchasing bandwidth for each virtual machine separately. The advantage of sBwp is that it can provide users with convenient configuration and lower economic cost. However, the sBwp model brings new challenges for operators to localize the root cause of traffic anomalies of a sharing bandwidth, especially for a globally distributed large-scale public cloud with millions of users. In this paper, we first formalize the sBwp problem on the cloud and propose CloudPin, a root cause localization framework for this problem. Our framework solves all the challenges by employing a multi-dimensional algorithm with three sub-models of prediction deviation, anomaly ampli-tude, and shape similarity, and an overall ranking algorithm. Evaluations on real-world data, from one of the world-renowned public cloud vendors, show that our algorithm precision reaches 97.8% for the top 1 of the ranking list, outperforming multiple baseline algorithms. Shize Zhang, Jianyuan Lu, Biao Lyu, Shunmin Zhu, Jiahai Yang 0001, Lin He 0004 |
ISSRE | 8 |
| 2021 | pSAV: A Practical and Decentralized Inter-AS Source Address Validation Service FrameworkabstractSource IP address spoofing has been a major vulnerability of the Internet for many years. Although much work has been done to study the problem extensively, spoofing continues to occur frequently and has led to many serious network attacks. Inter-AS source address validation (SAV) is considered an important defense method for AS to filter spoofed packets. However, existing work has been unable to drive inter-AS SAV deployment into practice due to the lack of deployment incentives and trust foundation.In this paper, we propose a practical and decentralized inter-AS SAV service framework, pSAV, to promote inter-AS SAV deployment. pSAV increases deployment incentives by treating SAV as a payable service and dividing the participant ASes into service subscribers, providers, and auditors. On the control plane, pSAV leverages blockchain as a trust foundation to provide service subscriptions and audits with automatic incentive allocation. On the data plane, pSAV leverages P4-programmable switches to provide flexible and high-performance SAV services. We prototype the pSAV control plane based on Hyperledger Fabric and implement various SAV techniques on Barefoot Tofino switches. The evaluation results show that (1) on the control plane, pSAV blockchain can provide high-performance service transactions (hundreds of transactions per second with second latency), and (2) on the data plane, pSAV can provide various high-throughput (hundreds of Gbps) SAV services using only one programmable switch. Jiamin Cao, Ying Liu 0024, Mingxing Liu, Lin He 0004, Yihao Jia |
IWQoS | 4 |
| 2021 | Towards Chain-Aware Scaling Detection in NFV with Reinforcement LearningabstractElastic scaling enables dynamic and efficient re-source provisioning in Network Function Virtualization (NFV) to serve fluctuating network traffic. Scaling detection determines the appropriate time when a virtual network function (VNF) needs to be scaled, and its precision and agility profoundly affect system performance. Previous heuristics define fixed control rules based on a simplified or inaccurate understanding of deployment environments and workloads. Therefore, they fail to achieve optimal performance across a broad set of network conditions.In this paper, we propose a chain-aware scaling detection mechanism, namely CASD, which learns policies directly from experience using reinforcement learning (RL) techniques. Furthermore, CASD incorporates chain information into control policies to efficiently plan the scaling sequence of VNFs within a service function chain. This paper makes the following two key technical contributions. Firstly, we develop chain-aware representations, which embed global chains of arbitrary sizes and shapes into a set of embedding vectors based on graph embedding techniques. Secondly, we design an RL-based neural network model to make scaling decisions based on chain-aware representations. We implement a prototype of CASD, and its evaluation results demonstrate that CASD reduces the overall system cost and improves system performance over other baseline algorithms across different workloads and chains. Lin He 0004, Lishan Li, Ying Liu 0024 |
IWQoS | 1 |
| 2021 | TAP: A Traffic-Aware Probabilistic Packet Marking for Collaborative DDoS MitigationabstractIn recent years, Distributed Denial-of-Service (DDoS) attacks have become more rampant and continue to be one of the most serious security threats facing network infrastructure. In a classic DDoS attack, the attacker controls numerous bots from many sources to send a significant volume of traffic to flood the victim end or the bottleneck link. In practical networks, it is inefficient and costly to request all partner routers to collaboratively mitigate DDoS attacks. The common feature of DDoS attacks is the abnormal distribution of traffic to the victim. In this paper, we propose TAP, a collaborative DDoS mitigation framework, based on traffic-aware probabilistic packet marking (PPM). TAP enables the victim to select a few hit routers as collaborators to mitigate attack traffic efficiently depending on the traffic distribution. Our evaluation results show that TAP greatly reduces attack traffic within seconds and mitigate the damage caused by DDoS with less overhead, which demonstrates that TAP is an effective, efficient, and rapid-response scheme for collaborative DDoS mitigation. Mingxing Liu, Ying Liu 0024, Ke Xu 0002, Lin He 0004, Xiaoliang Wang 0004, Yangfei Guo, Weiyu Jiang |
MSN | 4 |
| 2021 | Towards securing Duplicate Address Detection using P4
Lin He 0004, Peng Kuang, Ying Liu 0024, Gang Ren 0003, Jiahai Yang 0001 |
Comput. Networks | 1 |
| 2021 | PAVI: Bootstrapping Accountability and Privacy to IPv6 InternetabstractAccountability and privacy are considered valuable but conflicting properties in the Internet, which at present does not provide native support for either. Past efforts to balance accountability and privacy in the Internet have unsatisfactory deployability due to the introduction of new communication identifiers, and because of large-scale modifications to fully deployed infrastructures and protocols. The IPv6 is being deployed around the world and this trend will accelerate. In this paper, we propose a private and accountable proposal based on IPv6 called PAVI that seeks to bootstrap accountability and privacy to the IPv6 Internet without introducing new communication identifiers and large-scale modifications to the deployed base. A dedicated quantitative analysis shows that the proposed PAVI achieves satisfactory levels of accountability and privacy. The results of the evaluation of a PAVI prototype show that it incurs little performance overhead, and is widely deployable. Lin He 0004, Gang Ren 0003, Ying Liu 0024, Jiahai Yang 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | P4DAD: Securing Duplicate Address Detection Using P4abstractDuplicate Address Detection (DAD) is an essential part of the Neighbor Discovery Protocol (NDP), which determines whether the IPv6 address of a node conflicts with those of other nodes. Due to the lack of verification of NDP messages, DAD is vulnerable to DoS attacks. Existing solutions suffer from high complexity, need to modify the NDP, or have a single point of failure.To solve the above problems, we propose P4DAD, a secure DAD mechanism described by P4. By creating and maintaining binding entries between IPv6 address and link-layer property of host, P4DAD can filter spoofed NDP messages in an in-network manner to prevent DoS attacks on DAD without modifications to the NDP or host stack. We implement a prototype of P4DAD and evaluate it in terms of functionality, performance, and scalability. Evaluation results show that P4DAD can prevent DoS attacks on DAD successfully with negligible overhead, and has satisfactory scalability. Peng Kuang, Ying Liu 0024, Lin He 0004 |
ICC | 3 |
| 2020 | Towards the Construction of Global IPv6 Hitlist and Efficient Probing of IPv6 Address SpaceabstractFast IPv4 scanning has made sufficient progress in network measurement and security research. However, it is infeasible to perform brute-force scanning of the IPv6 address space. We can find active IPv6 addresses through scanning candidate addresses generated by the state-of-the-art algorithms, whose probing efficiency of active IPv6 addresses, however, is still very low. In this paper, we aim to improve the probing efficiency of IPv6 addresses in two ways. Firstly, we perform a longitudinal active measurement study over four months, building a high-quality dataset called hitlist with more than 1.3 billion IPv6 addresses distributed in 45.2k BGP prefixes. Different from previous work, we probe the announced BGP prefixes using a pattern-based algorithm, which makes our dataset overcome the problems of uneven address distribution and low active rate. Secondly, we propose an efficient address generation algorithm DET, which builds a density space tree to learn high-density address regions of the seed addresses in linear time and improves the probing efficiency of active addresses. On the public hitlist and our hitlist, we compare our algorithm DET against state-of-the-art algorithms and find that DET increases the de-aliased active address ratio by 10%, and active address (including aliased addresses) ratio by 14%, by scanning 50 million addresses. Guanglei Song, Lin He 0004, Jiahai Yang 0001, Jieling Liu |
IWQoS | 2 |
| 2019 | Multi-modal Representation Learning for Successive POI RecommendationabstractSuccessive POI recommendation is a fundamental problem for location-based social networks (LBSNs). POI recommendation takes a variety of POI context information (e.g. spatial location and textual comment) and user preference into consideration. Existing POI recommendation systems mainly focus on part of the POI context and user preference with a specific modeling, which loses valuable information from other aspects. In this paper, we propose to construct a multi-modal check-in graph, a heterogeneous graph that combines five check-in aspects in a unified way. We further propose a multi-modal representation learning model based on the graph to jointly learn POI and user representations. Finally, we employ an attentional recurrent neural network based on the representations for successive POI recommendation. Experiments on a public dataset studies the effects of modeling different aspects of check-in records and demonstrates the effectiveness of the method in improving POI recommendation performance. Lishan Li, Ying Liu 0024, Lin He 0004, Gang Ren 0003 |
ACML | 4 |
| 2019 | Bootstrapping Accountability and Privacy to IPv6 Internet without Starting from ScratchabstractAccountability and privacy are considered valuable but conflicting properties in the Internet, which at present does not provide native support for either. Past efforts to balance accountability and privacy in the Internet have unsatisfactory deployability due to the introduction of new communication identifiers, and because of large-scale modifications to fully deployed infrastructures and protocols. The IPv6 is being deployed around the world and this trend will accelerate. In this paper, we propose a private and accountable proposal based on IPv6 called PAVI that seeks to bootstrap accountability and privacy to the IPv6 Internet without introducing new communication identifiers and large-scale modifications to the deployed base. A dedicated quantitative analysis shows that the proposed PAVI achieves satisfactory levels of accountability and privacy. The results of evaluation of a PAVI prototype show that it incurs little performance overhead, and is widely deployable. Lin He 0004, Gang Ren 0003, Ying Liu 0024 |
INFOCOM | 1 |
| 2018 | GAGMS: a requirement-driven general address generation and management system
Ying Liu 0024, Lin He 0004, Gang Ren 0003 |
Sci. China Inf. Sci. | 2 |
| 2017 | Revisiting inter-AS IP spoofing let the protection drive source address validationabstractIP spoofing, which is prevalently used for anonymity and reflection attacks, has shown increasing destructive power in recent years. Although certain source address validation solutions have been standardized by the Internet Engineering Task Force, few networks are willing to adopt them in view of the deficiency of deployment benefits. Actually, all the source address validation solutions face the problem of a lack of deployability. In this paper, we summarize the key points describing deployability and propose a new security service-inter-autonomous-system (AS) Source Address Protection (iSAP). Technically, by increasing the possibility of keeping the source address belonging to one AS from being the victim of reflection flooding, iSAP improves the deployers ability to prevent IP spoofing and increases incremental deployability. In reality, such a service can also be regarded as a new profit opportunity for ASes and it could progress gradually once it is well commercialized. Based on simulations with real Internet topology data, the results illustrate that iSAP can protect ASes from being reflected with only a few deployers, exhibiting a high potential to mitigate reflection flooding with modest resource consumption. Yihao Jia, Ying Liu 0024, Gang Ren 0003, Lin He 0004 |
IPCCC | 4 |
| 2015 | Building an IPv6 address generation and traceback system with NIDTGA in Address Driven Network
Ying Liu 0024, Gang Ren 0003, Shenglin Zhang, Lin He 0004, Yihao Jia |
Sci. China Inf. Sci. | 5 |