VLDB 2026 Research / reviewers in the wild / expert
Po-Ching Lin
dblp:79/591
· DBLP profile ↗
36ranked-venue papers
4as first author
19since 2021 · last 2026
0000-0001-8294-5857ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 2 first-author · 6 since 2021Security and privacy · 9 · 7 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Detached-PQ: A Validator-Push Hybrid Transaction Framework for Storage-Efficient PoS Blockchains
Duc Van Nguyen, Cat Khanh Tran, Po-Ching Lin, Van Linh Nguyen |
ICBC | 3 |
| 2026 | T-MGA: Temporal GNNs with Global Attention for Smart Contract Vulnerability Detection
Syed Imran Hussain Shah, Yared Abera Ergu, Po-Ching Lin, Van Linh Nguyen |
ICBC | 3 |
| 2026 | Communication-Efficient Quantum Federated Learning for Privacy-Preserving IIoT Network Intrusion Detection
Abhishek Vyas, Ren-Hung Hwang, Po-Ching Lin, Meenakshi Tripathi |
INFOCOM | 3 |
| 2026 | Q-Sentinel: Towards Adversarial Robustness for Quantum-Classical xApps in Intelligent O-RAN
Yared Abera Ergu, Po-Ching Lin, Ren-Hung Hwang, Van Linh Nguyen |
WCNC | 2 |
| 2025 | TRACE: Relationship Analysis and Causal Factor Extraction in Cyber Threat Intelligence ReportsabstractCyber Threat Intelligence (CTI) reports provide valuable insights into cybersecurity attack techniques, which are essential for understanding threat execution. Identifying the root causes of these techniques is crucial for developing effective defense mechanisms. However, the unstructured nature and inconsistent terminology of CTI reports pose significant challenges in extracting causal factors, such as Common Weakness Enumerations (CWEs) and vulnerable data components, limiting proactive responses and the understanding of attack interdependencies. To address these challenges, we propose TRACE, a novel framework that extracts causal factors linked to adversarial techniques and generates comprehensive causal graphs revealing interdependencies within CTI reports. TRACE combines pattern extraction and tagging methods to address the limitations of existing approaches. Utilizing Sentence-based Bidirectional Encoder Representations from Transformers (SBERT) embeddings enhanced with knowledge mappings and deep learning techniques, TRACE discovers and models causal relationships between attack techniques within the reports. By bridging the gap between attack techniques and their underlying vulnerabilities, TRACE provides actionable insights to enhance cybersecurity defenses. Evaluated on 710 CTI reports, TRACE achieved an F1 score of 0.87, demonstrating its accuracy in extracting causal factors and its potential to advance automated causal analysis in cybersecurity. R. Vaitheeshwari, Eric Hsiao-Kuang Wu, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Yuan-Cheng Lai |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Imperceptible adversarial attack via spectral sensitivity of human visual system
Chen-Kuo Chiang, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Shih-Ya Chang, Hao-Ting Li |
Multim. Tools Appl. | 4 |
| 2024 | MITREtrieval: Retrieving MITRE Techniques From Unstructured Threat Reports by Fusion of Deep Learning and OntologyabstractCyber Threat Intelligence (CTI) plays a crucial role in understanding and preemptively defending against emerging threats. Typically disseminated through unstructured reports, CTI encompasses detailed insights into threat actors, their actions, and attack patterns. The MITRE ATT&CK framework offers a comprehensive catalog of adversary tactics, techniques, and procedures (TTPs), serving as a valuable resource for deciphering attacker behavior and enhancing defensive measures. Addressing the challenge of time-consuming manual analysis of MITRE TTPs in unstructured CTI reports, this paper presents MITREtrieval, a novel system that leverages deep learning and ontology to efficiently extract MITRE techniques. This approach mitigates issues related to the implicit nature of TTPs, textual semantic dependencies, and the scarcity of adequately labeled datasets, enabling more effective analysis even with limited sample sizes. Our approach combines a sophisticated sentence-level BERT deep learning model with ontology knowledge to address sparse data challenges, using a voting algorithm to merge outcomes. This results in a more accurate classification of MITRE techniques, capturing contextual nuances effectively. Our evaluation confirms MITREtrieval’s effectiveness in identifying techniques, regardless of their representation in training samples. MITREtrieval has surpassed benchmarks, achieving F2 scores of 58%, 62%, and 69% in multi-label technique identification across 113, 46, and 23 CTI reports, respectively, thereby streamlining CTI analysis and improving threat intelligence. Yi-Ting Huang, R. Vaitheeshwari, Meng Chang Chen, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Yuan-Cheng Lai, Eric Hsiao-Kuang Wu, Chung-Hsuan Chen, Zi-Jie Liao, Chung-Kuan Chen |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2023 | Efficient Aerial Relaying Station Path Planning for Emergency Event-based CommunicationsabstractFor critical applications such as emergency medical rescue missions or telehealth in remote areas, stable network connectivity is vital for patient state monitoring and proper temporary care. Unexpected connection interruption or network lag can cause trouble for skilled doctors in remote care centers to predict the progress of a patient’s condition. Network quality is variable in many areas because of signal power degradation (zones without purple coverage) in rural areas with many building obstacles. As a result, many current emergency services still rely on on-site first aid efforts. The idea of unmanned aerial vehicles (UAVs) serving as aerial relaying stations to provide connectivity for ground users has received much attention over the years. However, controlling UAVs via cellular networks is still a challenging issue. In this work, we consider the mission of dispatching UAVbased relaying stations as a path-planning scheme, where the UAVs go to planned locations and serve the EVs with a certain connectivity requirement. The core novelty of this work is a novel searching scheme that can suggest a deployment plan for the swarm of UAVs at the time of the EVs’ departure. The search is also robust for path planning with real-time applications or dynamic environments. Van Linh Nguyen, Lan-Huong Nguyen, Ren-Hung Hwang, Jian-Jhih Kuo, Po-Ching Lin |
CCNC | 5 |
| 2023 | Deep Learning-Based Localization and Outlier Removal Integration Model for Indoor SurveillanceabstractDirectional antenna technologies are crucial to enhance high-speed data transmission in emerging wireless communications such as mmWave. These technologies can enable high-accuracy radio positioning by exploiting spatial-temporal signal processing in wideband beamforming space. However, the radio positioning technique potentially poses surveillance risks to mobile users, particularly being tracked illegally. This work presents a novel scheme to track a user in a building based on passively received signals. The scheme includes a Deep Convolutional Neural Network (DCNN) localization module to train on the accumulated channel impulse responses (CIR) and corresponding Angle-Delay profiles. The user's estimated locations from the DCNN localization are then refined with an Unscented Kalman filter (UKF) data fusion module to eliminate outlier data points. Simulations indicate that the proposed scheme can accurately regenerate the user trajectory, even without the attacker's physical intrusion into the building. This poses a new concern of surveillance risks in directional wireless communications, given their expected popularity in 5G and beyond. Van Linh Nguyen, Lan-Huong Nguyen, Po-Ching Lin, Ren-Hung Hwang |
ICC | 3 |
| 2023 | Correlation of cyber threat intelligence with sightings for intelligence assessment and augmentation
Po-Ching Lin, Wen-Hao Hsu, Ying-Dar Lin, Ren-Hung Hwang, Eric Hsiao-Kuang Wu, Yuan-Cheng Lai, Chung-Kuan Chen |
Comput. Networks | 1 |
| 2023 | Two-phase Defense Against Poisoning Attacks on Federated Learning-based Intrusion Detection
Yuan-Cheng Lai, Jheng-Yan Lin, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Eric Hsiao-Kuang Wu, Chung-Kuan Chen |
Comput. Secur. | 5 |
| 2023 | Vehicle theft detection by generative adversarial networks on driving behavior
Pei-Yu Tseng, Po-Ching Lin, Edy Kristianto |
Eng. Appl. Artif. Intell. | 2 |
| 2023 | Host-based intrusion detection with multi-datasource and deep learning
Ren-Hung Hwang, Chieh-Lun Lee, Ying-Dar Lin, Po-Ching Lin, Eric Hsiao-Kuang Wu, Yuan-Cheng Lai, Chung-Kuan Chen |
J. Inf. Secur. Appl. | 4 |
| 2022 | ELAT: Ensemble Learning with Adversarial Training in defending against evaded intrusions
Ying-Dar Lin, Jehoshua-Hanky Pratama, Didik Sudyana, Yuan-Cheng Lai, Ren-Hung Hwang, Po-Ching Lin, Hsuan-Yu Lin, Wei-Bin Lee, Chen-Kuo Chiang |
J. Inf. Secur. Appl. | 6 |
| 2022 | Multi-datasource machine learning in intrusion detection: Packet flows, system logs and host statistics
Ying-Dar Lin, Ze-Yu Wang, Po-Ching Lin, Van Linh Nguyen, Ren-Hung Hwang, Yuan-Cheng Lai |
J. Inf. Secur. Appl. | 3 |
| 2022 | Controllable Path Planning and Traffic Scheduling for Emergency Services in the Internet of VehiclesabstractDispatching emergency vehicles (EVs) to fatal accidents or fires as fast as possible is vital to save lives; however, minimizing an EV’s travel time to the rescue spot is still an open challenge. This work presents a path planning and traffic clear-out scheduling scheme to lessen the EV’s travel time in the vision of the Internet of Vehicles (IoV). Initially, the system searches a list of candidate paths to the rescue spot with the estimated time of arrival (ETA) at the EVs’ maximum speed, regardless of the traffic conditions. After that, a vehicle clear-out process evaluates the delay time of clearing out the traffic obstacles on each path to identify the fastest driving path. Finally, the system estimates and issues the signal preemption schedules for the junctions of the selected route to coordinate the traffic flows and let the EV pass through smoothly. From the macro perspective, this work seeks tocontrol the dynamic traffic proactively to reserve a lane for the EV– a feasible approach in the future of connected vehicles. This controllable model apparently contrasts with the conventional techniques of finding the least-cost paths with the uncertainty of traffic state prediction or traffic light preemption alone at the intersections. The simulation shows that our approach can outperform the state-of-the-art solutions in terms of the EV’s travel time reduction, particularly if the congestion or heavy load road segments appear on the selected route but far from the departure location of the EV. Van Linh Nguyen, Ren-Hung Hwang, Po-Ching Lin |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2021 | Platoon-based Vehicle Coordination Scheme for Resolving Sudden Traffic Jam in the IoV EraabstractIn the next decades, the popularity of Internet of Vehicles (IoV) technologies and autonomous driving promises to fundamentally change the way of handling the traffic flow on the streets. Traffic separation can be entirely carried out from a remote traffic control center without the police. This work introduces a sequential coordination algorithm, namely SCA, to form and sort platoons of vehicles to quickly exit traffic bottleneck areas caused by temporary situations, such as vehicular accidents and a slow tractor. By exploiting maneuver information from IoV data sharing, SCA schedules the vehicles in a queue by their arrival and lane priority and then instructs them to safely drive through in order. The experimental results demonstrate our approach can reduce up to 32% waiting time for the vehicles to exit accident spots. Ren-Hung Hwang, Van Linh Nguyen, Chia-Che Tsai, Po-Ching Lin |
VTC Fall | 4 |
| 2021 | Robust Positioning-based Verification Scheme for Enhancing Reliability of Vehicle Platoon ControlabstractVehicle platooning is a promising technology to bring up significant benefits of improved fuel economy and fewer traffic collisions. However, many security attacks such as beacon message falsification have been exposed, creating grave concerns about maintaining a vehicle platoon stably. This work introduces a robust positioning-based verification scheme, namely PVS, to enhance reliability of vehicle platoon control in vehicular networks. By exploiting geographic and maneuver information from 5G radio-based positioning, PVS can detect whether a vehicle is honest in reporting its location for platoon joining preparation or collision avoidance, with up to 96% accuracy. Lan-Huong Nguyen, Ren-Hung Hwang, Po-Ching Lin, Van Linh Nguyen, Jian-Jhih Kuo |
VTC Fall | 3 |
| 2021 | CREME: A toolchain of automatic dataset collection for machine learning in intrusion detection
Huu-Khoi Bui, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Van Linh Nguyen, Yuan-Cheng Lai |
J. Netw. Comput. Appl. | 4 |
| 2018 | Towards load-balanced service chaining by Hash-based Traffic Steering on Softswitches
Minh-Tuan Thai, Ying-Dar Lin, Po-Ching Lin, Yuan-Cheng Lai |
J. Netw. Comput. Appl. | 3 |
| 2018 | Toward Optimal Resource Allocation of Virtualized Network Functions for Hierarchical DatacentersabstractTelecommunications service providers (TSPs) previously provided network functions to end users with dedicated hardware, but they are resorting to virtualized infrastructure for reducing costs and increasing flexibility in resource allocation. A representative case is the Central Office Re-architected as Datacenter (CORD) project from AT&T, which aims to deploy virtualized network functions (VNFs) to over 4000 central offices (COs) across the U.S. However, there is a wide spectrum of options for deploying VNFs over the COs, varying from highly distributed to highly centralized manners. The former benefits end users with short response time but has its inherent limitation on utilizing geographically dispersed resources, while the latter allows resources to be better utilized at a cost of longer response time. In this work, we model the TSP's virtualized infrastructure as hierarchical datacenters, namely hierarchical CORD, and provide a resource allocation solution to strike the optimal balance between the two extreme options. Our evaluations reveal that in general, the 3-tier architecture incurs the least cost in case of deploying VNFs under moderate or loose delay constraints. Furthermore, the margin of improvement on the resource allocation cost increases inversely with the overall system utilization rate. Our results also suggest that as heavy request load overwhelms the network infrastructure, the relevant VNFs shall be migrated to lower-tier edge datacenters or to some nearby datacenters with superior network capacity. The evaluations also demonstrate that the proposed model allows highly adaptive VNF deployment in the hierarchical architecture under various conditions. Chih-Chiang Wang 0001, Ying-Dar Lin, Jang-Jiin Wu, Po-Ching Lin, Ren-Hung Hwang |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2017 | Hash-based load balanced traffic steering on softswitches for chaining virtualized network functionsabstractPrior load balancing solutions for chaining virtualized network functions cause significant control and data plane overheads and demand special requirements on network hardware. In this study, we present the design, implementation, and evaluation of Hash-based Traffic Steering on Softswitches (HATS), a load balancing mechanism that aims at mitigating such drawbacks. The method exploits flow hashing technique implemented on softswitches to perform server and network load balancing without triggering the control plane. We have implemented this design using OpenDayLight controller and Open vSwitch platform. The implementation demonstrates that HATS can be readily implemented with commodity network hardware. Furthermore, the experiment results confirm that HATS can reduce the number of flow entries and service chaining time up to 85% and 93%, respectively, when compared with Least Load First (LLF), a controller-based service chaining algorithm. Minh-Tuan Thai, Ying-Dar Lin, Po-Ching Lin, Yuan-Cheng Lai |
ICC | 3 |
| 2017 | Detecting Web-Based Botnets Using Bot Communication Traffic FeaturesabstractWeb-based botnets are popular nowadays. A Web-based botnet is a botnet whose C&C server and bots use HTTP protocol, the most universal and supported network protocol, to communicate with each other. Because the botnet communication can be hidden easily by attackers behind the relatively massive HTTP traffic, administrators of network equipment, such as routers and switches, cannot block such suspicious traffic directly regardless of costs. Based on the clients constituent of a Web server and characteristics of HTTP responses sent to clients from the server, this paper proposes a traffic inspection solution, called Web-based Botnet Detector (WBD). WBD is able to detect suspicious C&C (Command-and-Control) servers of HTTP botnets regardless of whether the botnet commands are encrypted or hidden in normal Web pages. More than 500 GB real network traces collected from 11 backbone routers are used to evaluate our method. Experimental results show that the false positive rate of WBD is 0.42%. Fu-Hau Hsu, Chih-Wen Ou, Yanling Hwang, Ya-Ching Chang, Po-Ching Lin |
Secur. Commun. Networks | 5 |
| 2016 | VRS: a values-based reputation system for web servicesabstractAbstract The reputation system is used to display the reputation of entities based on the ratings or appraisals given by users who have used or purchased those entities. Web service providers supply various reputation systems for their users. However, these promising reputation systems face some challenges. First, even though different persons have different preference andvalues(values are a person's beliefs about what things are good or bad), these systems still give the same rating to the same entity for all users. Second, they may be greatly influenced by Sybil attacks. In this paper, we propose a reputation system, called values‐based reputation system (VRS), to solve the aforementioned problems. VRS customizes the rating of an entity for each user based on the ratings of the entities provided by other users who have similarvaluesor preference to the user. Experimental results on 256 users show that compared with existing reputation systems VRS is more robust to Sybil attacks and provides a recommendation rating that is closer to the rating given by the user after it used the related entity. Copyright © 2016 John Wiley & Sons, Ltd. Fu-Hau Hsu, Yu-Liang Hsu, Yanling Hwang, Li-Han Chen, Chuan-Sheng Wang, Chang-Kuo Tso, Szu-Chi Liu, Po-Ching Lin, Chi-Hsien Hsu |
Secur. Commun. Networks | 8 |
| 2015 | A Resource-Constrained Asymmetric Redundancy Elimination AlgorithmabstractWe focus on the problem of efficient communications over access networks with asymmetric bandwidth and capability. We propose a resource-constrained asymmetric redundancy elimination algorithm (RCARE) to leverage downlink bandwidth and receiver capability to accelerate the uplink data transfer. RCARE can be deployed on a client or a proxy. Different from existing asymmetric algorithms, RCARE uses a flexible matching mechanism to identify redundant data and allocates a small sender cache to absorb the high downlink traffic overhead. Compared to existing redundancy elimination algorithms, RCARE provides a scalable sender cache that is adaptive based on resource and performance. We evaluate RCARE with real traffic traces collected from multiple servers and a campus gateway. The trace-driven simulation results indicate that RCARE achieves higher goodput gains and reduces downlink traffic compared to existing asymmetric communication algorithms. We design an adaptation algorithm for resource-constrained senders sending multiple data streams. Our algorithm takes samples from data streams and predicts how to invest cache size on individual data streams to achieve maximal uplink goodput gain. The adaptation algorithm improves the goodput gain by up to 87% compared to the baseline. In first 10% of data streams (sorted by the optimal goodput gains), RCARE achieves up to 42% goodput gain on average. Yu-Sian Li, Trang Cao Minh, Shu-Ting Wang, Xin Huang 0008, Cheng-Hsin Hsu, Po-Ching Lin |
IEEE/ACM Trans. Netw. | 6 |
| 2014 | Guest Editorial Deep Packet Inspection: Algorithms, Hardware, and ApplicationsabstractThe thirteen articles in this special section explore the technology of deep packet inspection (DPI). DPI examines the content in packet payloads to search for signatures of network applications, signs of malicious activities, and leaks of sensitive information, rather than just examine packet headers for information such as IP addresses and port numbers. The inspection provides network devices with rich information of application protocol messages in packet payloads, and enables them to make intelligent decisions in packet processing based on the information. The papers are organized into the following four sections: (1) Scalable Algorithms and Architectures for DPI, (2) Network Traffic Analysis with DPI, (3) Network Protocol Identification with DPI, and (4) Network Security Analysis with DPI. Ying-Dar Lin, Po-Ching Lin, Viktor Prasanna 0001, H. Jonathan Chao, John W. Lockwood |
IEEE J. Sel. Areas Commun. | 2 |
| 2014 | On-the-Fly Capture and Replay Mechanisms for Multi-Port Network Devices in Operational NetworksabstractTesting network devices in a live environment is desirable due to its reality. However, the defects are not reproducible, and the network connectivity will be broken if the device is down. For effective defect reproduction from real traffic, we design a new mechanism, which allows the device under test (DUT) to be automatically online/offline, and supports multi-port replay for multi-port network devices with an OpenFlow switch. The defect traces are captured when the DUT is online. When a DUT failure is detected, the DUT will be offline, and the defect-triggering traces will be replayed to identify the defect. For efficient replay, we keep only partial payloads in a reduced number of packets in the defect traces that are sufficient to trigger the defects. For defect identification, reduction based on a binary search algorithm is presented to deal with the defects caused by payload anomalies and by overloading. The downsizing ratios in the cases of payload anomalies and overloading are up to 98.8% and 96%, respectively. The minimum outage time of the failover during the DUT failure is obtained when the check interval is 1 second and the number of tolerable consecutive failures is 2. Ying-Dar Lin, Po-Ching Lin, Yuan-Cheng Lai |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2013 | Re-examining the performance bottleneck in a NIDS with detailed profiling
Po-Ching Lin, Jia-Hau Lee |
J. Netw. Comput. Appl. | 1 |
| 2012 | CacheQuery: A practical asymmetric communication algorithmabstractWe consider the problem of asymmetric communications, which are common in many access networks. We propose a new asymmetric communication algorithm, called CacheQuery, to leverage on the already deployed downlink bandwidth and receiver capability to accelerate the uplink data transfer from one or multiple senders to a receiver. The design of CacheQuery differs from all previous asymmetric communication algorithms in two ways: (i) CacheQuery supports more flexible matching mechanism to identify redundant packet payload and (ii) CacheQuery allocates a small sender cache to absorb the potentially high downlink traffic overhead incurred by asymmetric communications. The trace-driven simulations indicate that, compared to existing asymmetric communication algorithms, CacheQuery achieves higher uplink transfer speed, yet reduces downlink traffic overhead. Yu-Sian Li, Trang Cao Minh, Xin Huang 0008, Cheng-Hsin Hsu, Po-Ching Lin |
GLOBECOM | 5 |
| 2011 | A Hybrid Algorithm of Backward Hashing and Automaton Tracking for Virus ScanningabstractVirus scanning involves computationally intensive string matching against a large number of signatures of different characteristics. Matching a variety of signatures challenges the selection of matching algorithms, as each approach has better performance than others for different signature characteristics. We propose a hybrid approach that partitions the signatures into long and short ones in the open-source ClamAV for virus scanning. An algorithm enhanced from the Wu-Manber algorithm, namely the Backward Hashing algorithm, is responsible for only long patterns to lengthen the average skip distance, while the Aho-Corasick algorithm scans for only short patterns to reduce the automaton sizes. The former utilizes the bad-block heuristic to exploit long shift distance and reduce the verification frequency, so it is much faster than the original WM implementation in ClamAV. The latter increases the AC performance by around 50 percent due to better cache locality. We also rank the factors to indicate their importance for the string matching performance. Po-Ching Lin, Ying-Dar Lin, Yuan-Cheng Lai |
IEEE Trans. Computers | 1 |
| 2009 | Extracting Attack Sessions from Real Traffic with Intrusion Prevention SystemsabstractFalse Positive (FP) and False Negative (FN) happen to every Intrusion Prevention System (IPS). No one could do better judgment than others all the time. This work proposes a system of Attack Session Extraction (ASE) to create a pool of suspicious traffic traces which cause potential FNs (abbreviated as P-FNs) and potential FPs (abbreviated as P-FPs) to IPSes. Developers of IPSes can use these suspicious traffic traces to improve the accuracy of their products. Traffic traces are called suspicious since what they cause are P-FNs and P-FPs which need to be confirmed by the developers of IPSes whether P-FNs are FNs and P-FPs are FPs. First, the ASE captures real traffic and replays captured traffic traces to multiple IPSes. By comparing the logs of IPSes, we can find that some attack logs are logged or not logged only at certain IPS. The former is P-FPs, while the latter is P-FNs to that IPS. The ASE then starts to extract this suspicious traffic from replayed traffic traces. The extracted traffic traces can then be used for further analysis by IPS developers. Some of the traces may prove to be guilty, i.e. confirmed to be FNs and FPs. To completely extract a suspicious session, the ASE uses an association mechanism based on anchor packets, five-tuple and time, and similarity for the first packet, first connection, and whole session, respectively. It calculates the degree of similarity among packets to extract a suspicious session containing multiple connections. We define variation and completeness/purity as the performance indexes to evaluate ASE. The experiments demonstrate that 95% of extracted sessions have low variation, and the average completeness/purity is around 80%. I-Wei Chen, Po-Ching Lin, Chi-Chung Luo, Tsung-Huan Cheng, Ying-Dar Lin, Yuan-Cheng Lai, Frank C. Lin |
ICC | 2 |
| 2009 | Application classification using packet size distribution and port association
Ying-Dar Lin, Chun-Nan Lu, Yuan-Cheng Lai, Wei-Hao Peng, Po-Ching Lin |
J. Netw. Comput. Appl. | 5 |
| 2009 | Realizing a Sub-Linear Time String-Matching Algorithm With a Hardware Accelerator Using Bloom FiltersabstractMany network security applications rely on string matching to detect intrusions, viruses, spam, and so on. Since software implementation may not keep pace with the high-speed demand, turning to hardware-based solutions becomes promising. This work presents an innovative architecture to realize string matching in sub-linear time based on algorithmic heuristics, which come from parallel queries to a set of space-efficient Bloom filters. The algorithm allows skipping characters not in a match in the text, and in turn simultaneously inspect multiple characters in effect. The techniques to reduce the impact of certain bad situations on performance are also proposed: thebad-blockheuristic, a linear worst-case time method and a non-blocking interface to hand over the verification job to a verification module. This architecture is simulated with both behavior simulation in C and timing simulation in HDL for antivirus applications. The simulation shows that the throughput of scanning Windows executable files for more than 10000 virus signatures can achieve 5.64 Gb/s, while the worst-case performance is 1.2 Gb/s if the signatures are properly specified. Po-Ching Lin, Ying-Dar Lin, Yuan-Cheng Lai, Yi-Jun Zheng, Tsern-Huei Lee |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2008 | Designing and evaluating interleaving decompressing and virus scanning in a stream-based mail proxy
Ying-Dar Lin, Szu-Hao Chen, Po-Ching Lin, Yuan-Cheng Lai |
J. Syst. Softw. | 3 |
| 2007 | kP2PADM: An In-kernel Gateway Architecture for Managing P2P TrafficabstractThis work presents an in-kernel gateway architecture on Linux, namely kP2PADM, for managing P2P traffic on dynamic ports. This design can effectively eliminate redundant data passing between the kernel space and the user space. The management functions include: (1) classifying and filtering P2P traffic, (2) scanning viruses on shared files, (3) auditing chatting messages and transferred files, and (4) bandwidth control. Practical implementation issues and techniques in the system design are discussed herein. This design proposes a dual-queue architecture to handle packet reassembly and resolve head-of-line blocking. A connection cache accelerates handling the reconnection requests from the peers. The throughput can achieve up to 185.73 Mbps even with content filtering, and remains around 79.09 Mbps when virus scanning is enabled. The impacts of each management function and out-of-order packets on performance are also analyzed through the internal benchmarks. Ying-Dar Lin, Po-Ching Lin, Meng-Fu Tsai, Tsao-Jiang Chang, Yuan-Cheng Lai |
IPDPS | 2 |
| 2003 | Direct Web switch routing with state migration, TCP masquerade, and cookie name rewritingabstractExisting layer 4 load balancers are content-blind and often have difficulty in redirecting HTTP requests to the appropriate server in the session manner. Layer 7 load balancers, also referred to as Web switches, are content-aware and support session persistence. However, most Web switches employ a bidirectional architecture, which means that request and response traffic must both pass through the load balancer. This means a Web switch can easily become a bottleneck. We present a direct routing architecture to prevent response traffic from passing through the Web switch. Our solution is highly scalable in the number of back-end servers. In addition, two simple but effective mechanisms, one-packet TCP state migration and cookie name rewriting to packet filter, are presented to support persistent connection and session persistence. Through the external benchmark, we prove that our system outperforms existing solutions. The internal benchmark investigates the bottlenecks of our system and suggests areas for future improvement. Ying-Dar Lin, Ping-Tsai Tsai, Po-Ching Lin, Ching-Ming Tien |
GLOBECOM | 3 |