Guangwu Hu

dblp:87/11301 · DBLP profile ↗
← Back
50ranked-venue papers
6as first author
32since 2021 · last 2026
0000-0003-3947-9998ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 11 · 1 first-author · 10 since 2021Security and privacy · 10 · 9 since 2021Databases, data management, data science and information retrieval · 7 · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 MTFuzz: A Novel Efficacy Fuzzing Framework for Aerospace Monolithic Firmware
Shuai Wang 0012, Xi Xiao 0001, Guangwu Hu, Kehuan Zhang, Le Yu 0002, Chengpei Tang, Qing Li 0006, Qizhen Xu
DSN3
2026 Traffic burst relational graph attention network combined position encoding for traffic classification
Xi Xiao 0001, Siji Chen, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan
Comput. Networks4
2026 Privacy-preserving collective reinforcement learning using fully homomorphic encryption in usage-based insurance
Guangwu Hu, Zoe Lin Jiang
Inf. Sci.4
2025 High-Efficiency Fuzzing Technique Using Hooked I/O System Calls for Targeted Input Analysis
Wenju Sun, Xi Xiao 0001, Guangwu Hu, Qing Li 0006
ESORICS (3)4
2025 CLRDMMF: A Contrastive Learning-based Rumor Detection Model with Multi-feature Fusion
Guangwu Hu, Xi Xiao 0001, Zongchen Cai, Yuzhang Huang
ICNP1
2025 Relational Graph Attention Network Combined with Burst Position Encoding for Traffic Classification
abstract
Network traffic classification has become an essential technology for information service providers. While existing methods predominantly focus on packet-level features such as port numbers and payload content, they fundamentally overlook the dynamic interaction patterns revealed by traffic burst sequences and the inherent relational characteristics between consecutive traffic bursts. To overcome the limitation of existing methods, we design a new burst position relational graph attention network (BP-RGAT) for traffic classification. We introduce the Heterogeneous Traffic Burst Graph (HTBG) to obtain more traffic interaction information. We also incorporate Relative Traffic Burst Position Encoding (RBPE) to capture sequence information between bursts. To evaluate the performance of BPRGAT, we conduct experiments with ISCX-VPN and USTC-TFC datasets. The results show that BP-RGAT achieves the highest F1 score compared to existing baseline methods (e.g. NetMamba, ET-BERT, BehavSniffer, TFE-GNN).
Siji Chen, Xi Xiao 0001, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan, Dengpan Ye
IWQoS3
2025 DTPN: A Diffusion-based Traffic Purification Network for Tor Website Fingerprinting
abstract
Website Fingerprinting attack is a type of method used to classify network traffic generated by users on the Tor (The Onion Router) based on the websites they visit, leading to the leakage of individuals' privacy . For Website Fingerprinting attack, network traffic defense methods involve adding noise to the original network traffic to render the attacker's methods ineffective. Previous attack methods primarily focused on improving classification accuracy by enhancing the attack model, with adversarial training being the most common approach. However, adversarial training requires frequent updates and exhibits poor generalization when dealing with previously unseen network traffic protection methods. In order to address the limitations of adversarial training, a novel method is proposed leveraging a diffusion model for network traffic purification. This paper is the first to use a diffusion model to resist network traffic defense based on adversarial perturbations. The diffusion models are theoretically suited for data purification in the training mode, i.e., removing noises generated by adversarial perturbations from the data. Our method enables existing network traffic classification methods to maintain effective classification of network traffic after protection without requiring retraining, while also achieving good generalization performance with previously unseen network traffic defense methods. The purified network traffic data can effectively improve the robustness of existing website fingerprinting methods. Experiments conducted under various network traffic defense strategies demonstrate that the proposed method increases accuracy by up to 60.8% on DF dataset and 50.3% on CW100 dataset, respectively, compared to adversarial training.
Xi Xiao 0001, Guangwu Hu, Zhen Ling 0001, Hao Li 0027, Bin Zhang 0048
WSDM3
2025 A novel high-accuracy graph neural network-based rumor detection method
Xi Xiao 0001, Chengzong Cai, Tian Bian, Guangwu Hu, Qing Li 0006
Eng. Appl. Artif. Intell.5
2025 RBLJAN: Robust Byte-Label Joint Attention Network for Network Traffic Classification
abstract
Network traffic classification plays a crucial role in network management and cyberspace security. As the Internet evolves with new applications and protocols, traditional machine learning-based methods relying on feature mining have become obsolete. Instead, deep learning-based methods are becoming more popular in the field of traffic classification due to their end-to-end processing approach. However, the vulnerability of neural networks to adversarial examples significantly compromises their performance. In this paper, we propose Robust Byte-Label Joint Attention Network (RBLJAN), an efficient and robust deep learning-based framework for encrypted network traffic classification at both the packet-level and the flow-level. RBLJAN comprises a classifier and an adversarial traffic generator. The classifier utilizes mechanisms such as header-payload parallel processing and byte-label joint attention learning to capture implicit correlations between bytes and labels, enabling the construction of powerful packet representations. The generator produces adversarial examples that are fed to the classifier to enhance its robustness. Experimental results demonstrate that RBLJAN achieves over 99% average F1-score on real-world legitimate traffic datasets and achieves 97.86% average F1-score on malware identification. Moreover, RBLJAN exhibits superior performance in terms of detection speed and robustness compared to state-of-the-art methods in real-world scenarios.
Xi Xiao 0001, Shuo Wang 0012, Guangwu Hu, Qing Li 0006, Kelong Mao, Xiapu Luo, Bin Zhang 0048, Shutao Xia
IEEE Trans. Dependable Secur. Comput.3
2024 CapsuleFormer: A Capsule and Transformer combined model for Decentralized Application encrypted traffic classification
abstract
Network traffic classification plays a crucial role in both network management and monitoring. Recently, an increasing number of Decentralized Applications (DApps) are appearing on various blockchain platforms. DApps employ encryption techniques such as SSL/TLS to safeguard the data transmitted over the network, making it more challenging to do traffic classification. In this paper, to tackle the challenge of insufficient classification accuracy in the existing classification of encrypted DApp traffic, we present Capsule-Former, a novel encrypted traffic classification model for DApps. CapsuleFormer utilizes capsule neurons instead of traditional scalar neurons, where the neurons within the capsule embody various attributes of particular entities. Furthermore, Transformer blocks are adopted to generate a high-dimensional representation of the capsule activation vector. Thus, CapsuleFormer has the capability to extract potential features from the encrypted traffic patterns of DApps. Moreover, we collect and open a dataset of more than 700,000 encrypted traffic flows from 10 different types of DApps. The results of the experiments on the dataset demonstrate that CapsuleFormer is superior to the current methods, with an accuracy rate of 98.7%.
Xi Xiao 0001, Qing Li 0006, Bin Zhang 0048, Guangwu Hu, Xiapu Luo, Tianwei Zhang 0004
AsiaCCS5
2024 Understanding the Influence of Extremely High-Degree Nodes on Graph Anomaly Detection
Xi Xiao 0001, Guangwu Hu, Xuhui Jiang, Bin Zhang 0048, Hao Li 0027
ICPR (7)4
2024 CNN-KOA-BiGRU: A high-accuracy APT detection model based on deep learning networks
Chaoqin Zhang, Maoqi Sun, Guangwu Hu
TrustCom3
2023 DetOH: An Anchor-Free Object Detector with Only Heatmaps
Ruohao Wu, Xi Xiao 0001, Guangwu Hu, Yongqing Peng
ADMA (2)3
2023 ReviewLocator: Enhance User Review-Based Bug Localization with Bug Reports
Renjie Xiao, Xi Xiao 0001, Le Yu 0002, Bin Zhang 0048, Guangwu Hu, Qing Li 0006
ADMA (5)5
2023 AAP: Defending Against Website Fingerprinting Through Burst Obfuscation
Xi Xiao 0001, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Qixu Liu
ADMA (5)4
2023 Fibonet: A Light-weight and Efficient Neural Network for Image Segmentation
abstract
In recent years, accurate models for image segmentation have become larger and more complex. However, it is hard to apply them into embedded devices which usually have limited space for data, energy and computing. Meanwhile, since many embedded devices do not support modifications of computing units, simple models with such requirements cannot be adapted to these devices. To achieve high accuracy for image segmentation in embedded devices, we propose a light-weight and efficient neural network, named Fibonet. Fibonet is constructed by cascading two Fiboblocks, with the Fibonacci structure which adjusts the combination of basic computing units through skip connections and feature reusing so that it is less computationally intensive and dataset-demanding. The experiments demonstrate that Fibonet can be embedded to the mobile terminal for real-time segmentation and can effectively balance accuracy and computing resources. Compared with Resnet18, Fibonet achieves 10.8% higher accuracy performance (mIoU: 0.533 vs. 0.481) with 84.4% fewer parameters (0.441M vs. 2.82M) using similar model width and depth.
Ruohao Wu, Xi Xiao 0001, Guangwu Hu, Yongqing Peng
ICIP3
2023 Phish2vec: A Temporal and Heterogeneous Network Embedding Approach for Detecting Phishing Scams on Ethereum
abstract
The exponential growth of Ethereum transactions has resulted in a significant increase in phishing scams, leading to substantial financial losses in recent years. Current machine/deep learning-based approaches for classification have been found to be inadequate for large-scale and label-imbalanced Ethereum scenarios. To address this issue, we propose Phish2vec, a novel network embedding approach that takes into account the transaction temporality and heterogeneity in detecting phishing scams on Ethereum. Our approach begins by producing a transaction sub-network through data collection and preprocessing, which includes a novel Statistics-Based Sampling (SBS) method to address label leakage. To generate sequences that contain more comprehensive information, we then utilize two different types of sequences generators: Temporal-based Sequences Generator (TSG) and Heterogeneous-based Sequences Generator (HSG). By concatenating the sequences generated by TSG and HSG together, and feeding them into Word2vec and Fully Connected neural network (FC), our approach can identify phishing accounts with an Fl-score as high as 82.05%, which significantly outperforms classic schemes such as DeepWalk (67.29%), Trans2vec (74.78%), and Node2vec (70.91%).
Zhutian Lin, Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qixu Liu, Xiapu Luo
SECON3
2023 BehavSniffer: Sniff User Behaviors from the Encrypted Traffic by Traffic Burst Graphs
abstract
With the increasing popularity of encryption pro-tocols in application and the rapid development of network applications, traffic classification has become a major challenge for mobile service providers. The failure of traditional classification methods and low classification accuracy are the problems that need to be solved urgently in traffic classification research. Therefore, we propose the scheme of BehavSniffer to sniff user behaviors from the encrypted traffic. The core idea is to propose Traffic Burst Graph (TBG) for extracting multidimensional features from bidirectional interactive data flows, and do feature fusion based on Kernel Principal Component Analysis (KPCA) and Deep Neural Network (DNN). In this way, BehavSniffer can learn both high and low-order combined structural features from traffic patterns of user behavior. Meanwhile, we propose the user behavior dataset, named WWT, from three widely used social media applications (WeChat, WhatsApp, Telegram). Experimental results show that BehavSniffer outperforms stateof-the-art methods, with AUC of 0.987 and accuracy of 99.8%, respectively.
Tiru Wu, Xi Xiao 0001, Qing Li 0006, Qixu Liu, Guangwu Hu, Xiapu Luo, Yong Jiang 0001
SECON5
2023 A lightweight and high-precision approach for bulky JavaScript engines fuzzing
abstract
Traditional coverage-based fuzzing gives equal attention to every part of a code. Despite much progress, we observe that existing schemes still not comprehensively use the coverage feedback mechanism when fuzzing bulky JavaScript engines because of severe path collisions. To improve the precision of coverage feedback and target the vulnerable JIT compiler of Javascript engines, we presented our fuzzer, called LF(Light Fuzzer), a lightweight and high-precision fuzzer for bulky JavaScript engines fuzzing. First, LF advocates a technique to confine instrumentation to the JIT-related "critical functions" to mitigate collisions. Additionally, LF utilizes static analysis to establish dominant relationships between critical functions. Lastly, LF incorporates seed scheduling with feedback information of control flow at the function level to dynamically target JIT. These combined strategies make LF a lightweight and high-precision fuzzer for fuzzing bulky JavaScript engines. In our evaluation, LF outperforms the state-of-art coverage-guided JavaScript fuzzer DIE in different coverage types, and LF is also more effective in triggering unique crashes compared to DIE.
Lianpei Zhou, Xi Xiao 0001, Guangwu Hu, Hao Li 0027, Xiangbo Wu
TrustCom3
2023 GraphNEI: A GNN-based network entity identification method for IP geolocation
Zhaorui Ma, Tianao Li, Xinhao Hu, Qinglei Zhou, Fenlin Liu, Xiaowen Quan, Guangwu Hu, Shubo Zhang, Yaqi Zhai, Shuaibin Chen, Shuaiwei Zhang
Comput. Networks11
2023 Tracking phishing on Ethereum: Transaction network embedding approach for accounts representation learning
Zhutian Lin, Xi Xiao 0001, Guangwu Hu, Qing Li 0006, Bin Zhang 0048, Xiapu Luo
Comput. Secur.3
2023 TCGNN: Packet-grained network traffic classification via Graph Neural Networks
Guangwu Hu, Xi Xiao 0001, Bin Zhang 0048, Xia Yan
Eng. Appl. Artif. Intell.1
2023 HGL_GEO: Finer-grained IPv6 geolocation algorithm based on hypergraph learning
Zhaorui Ma, Xinhao Hu, Tianao Li, Fenlin Liu, Qinglei Zhou, Zhankui Tian, Guangwu Hu
Inf. Process. Manag.11
2023 GWS-Geo: A graph neural network based model for street-level IPv6 geolocation
Zhaorui Ma, Xinhao Hu, Qinglei Zhou, Fenlin Liu, Guangwu Hu, Qilin Dong
J. Inf. Secur. Appl.8
2022 Graph Data Augmentation for Node Classification
abstract
In recent years, Graph Neural Networks (GNNs) have emerged as powerful techniques for graph-structure data, which are essential for a wide range of graph-based tasks like link prediction and node classification. However, over-smoothing and over-fitting are two main challenges that impact negatively on model performance. Data augmentation is a good solution to these two problems, and it is also proven very effective in computer vision and nature language processing. But there is a relatively small body of literature when it comes to graph data augmentation. In this paper, we propose a Graph Data Augmentation (GDA) strategy to optimize the graph topology for node classification tasks. Our GDA approach consists of two operations: edge manipulation based on similarities of node pairs (GDA-E) and new nodes addition to under-informed old nodes (GDA-N). GDA-E is designed to add missing edges and remove noisy edges, while GDA-N is established to help nodes with low degree. Both operations can improve the information-to-noise ratio of the whole graph and lead to better performance of GNNs. The comparative results of experiments on three different datasets show that our GDA approach achieves considerable improvement (11.0% average) over origin graphs, and the ablation study verifies the effectiveness of both GDA-E and GDA-N.
Xi Xiao 0001, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Shutao Xia
ICPR4
2022 PTrustE: A high-accuracy knowledge graph noise detection method based on path trustworthiness and triple embedding
Jiangtao Ma, Chenyu Zhou 0001, Yanjun Wang 0007, Guangwu Hu, Yaqiong Qiao
Knowl. Based Syst.5
2021 Short and Distort Manipulations in the Cryptocurrency Market: Case Study, Patterns and Detection
Xi Xiao 0001, Wentao Xiao, Bin Zhang 0048, Guangwu Hu
ICA3PP (3)5
2021 A Novel and High-Accuracy Rumor Detection Approach using Kernel Subtree and Deep Learning Networks
abstract
Rumor detection is a task of identifying information that spread among people whose truth value is false or unverified, and it has been a great challenge due to the rapid development of social media. The traditional machine learning based detection methods can make full use of informative features but cannot extract high-level representations. Other methods involved deep learning neural networks exploit propagation structural information to achieve high accuracy, for example, Bi-Directional Graph Convolution Networks(BiGCN) achieved the best performance on rumor detection by operating on bottom-up and top-down structures. However, those deep learning methods ignore other useful features like content-based features. In this paper, we not only make full use of three aspects of features based on a new concept: kernel subtree, which focus more on informative features of influential nodes of an event, but also propose a new model, which consists of Separation Convolution blocks, Long Short Term Memory(LSTM) and Squeeze and Excitation Networks(SENet), to make comprehensive use of features extracted on the basis of kernel subtree. First, we utilize Separation Convolutions to learn more local information with different kernel size, then LSTM can learn high-level interactions among features and find more global information. After that, SENet applies attention mechanism to put more weights on informative channels of feature maps. Meanwhile, on test set, Gradient Boosting Decision Tree(GBDT) is used to assist our model with few events. The experiments on the PHEME dataset show that our approach can identify rumors with accuracy 95% which outperforms BiGCN by 10% at least.
Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qing Li 0006, Shutao Xia
IJCNN3
2021 Byte-Label Joint Attention Learning for Packet-grained Network Traffic Classification
abstract
Network traffic classification (TC) is to classify network traffic into a specific class which plays a fundamental role in terms of network measurement, network management, and so on. In this work, we focus on packet-grained traffic classification. We find that previous packet-grained methods based on the analogy between traffic packet and image or text are not sufficiently reasonable, leading to a sub-optimal performance on both accuracy and efficiency that still can be largely improved. In this paper, we devise a new method, called BLJAN, to jointly learn from byte sequence and labels for packet-grained traffic classification. BLJAN embeds the packet’s bytes and all labels into a joint embedding space to capture their implicit correlations with a dual attention mechanism. It finally builds a more powerful packet representation with an enhancement from label embeddings to achieve high classification accuracy and interpretability. Extensive experiments on two benchmark traffic classification tasks, including application identification and traffic characterization, with three real-world datasets, demonstrate that BLJAN can achieve high performance (96.2%, 96.7%, and 99.7% Macro F1-scores on three datasets) for packet-grained traffic classification, outperforming six representative state-of-the-art baselines in terms of both accuracy and detection speed.
Kelong Mao, Xi Xiao 0001, Guangwu Hu, Xiapu Luo, Bin Zhang 0048, Shutao Xia
IWQoS3
2021 A LambdaMart-Based High-Accuracy Approach for Software Automatic Fault Localization
Yunhao Xiao, Xi Xiao 0001, Guangwu Hu
WASA (2)4
2021 Phishing websites detection via CNN and multi-head self-attention on imbalanced datasets
Xi Xiao 0001, Wentao Xiao, Dianyan Zhang, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Shutao Xia
Comput. Secur.5
2021 ALBFL: A novel neural ranking model for software fault localization via combining static and dynamic features
Xi Xiao 0001, Yuqing Pan, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Runiu Lu
Inf. Softw. Technol.4
2020 ALBFL: A Novel Neural Ranking Model for Software Fault Localization via Combining Static and Dynamic Features
abstract
Automatic fault localization plays a significant role in assisting developers to fix software bugs efficiently. Although existing approaches, e.g., static methods and dynamic ones, have greatly alleviated this problem by analyzing static features in source code and diagnosing dynamic behaviors in software running state respectively, the fault localization accuracy still does not meet user requirements. To improve the fault locating ability with statement granularity, this paper proposes ALBFL, a novel neural ranking model that involves the attention mechanism and the LambdaRank model, which can integrate the static and dynamic features and achieve very high accuracy for identifying software faults. ALBFL first introduces a transformer encoder to learn the semantic features from software source code. Also, it leverages other static statistical features and dynamic features, i.e., eleven Spectrum-Based Fault Localization (SBFL) features, three mutation features, to evaluate software together. Specially, the two types of features are integrated through a self-attention layer, and fed into the LambdaRank model so as to rank a list of possible fault statements. Finally, thorough experiments are conducted on 5 open-source projects with 357 faulty programs in Defects4J. The results show that ALBFL outperforms 11 traditional SBFL methods (by three times) and 2 state-of-the-art approaches (by 13%) on ranking faulty statements in the first position.
Yuqing Pan, Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qing Li 0006, Hai-Tao Zheng 0002
TrustCom3
2020 A proactive auto-scaling scheme with latency guarantees for multi-tenant NFV cloud
Guangwu Hu, Qing Li 0006, Shuo Ai, Jingpu Duan, Yu Wu 0010
Comput. Networks1
2020 ABFL: An autoencoder based practical approach for software fault localization
Zhendong Peng, Xi Xiao 0001, Guangwu Hu, Arun Kumar Sangaiah, Mohammed Atiquzzaman, Shutao Xia
Inf. Sci.3
2020 CNN-MHSA: A Convolutional Neural Network and multi-head self-attention combined approach for detecting phishing websites
Xi Xiao 0001, Dianyan Zhang, Guangwu Hu, Yong Jiang 0001, Shutao Xia
Neural Networks3
2019 Non-local Self-attention Structure for Function Approximation in Deep Reinforcement Learning
abstract
Reinforcement learning is a framework to make sequential decisions. The combination with deep neural networks further improves the ability of this framework. Convolutional nerual networks make it possible to make sequential decisions based on raw pixels information directly and make reinforcement learning achieve satisfying performances in series of tasks. However, convolutional neural networks still have own limitations in representing geometric patterns and long-term dependencies that occur consistently in state inputs. To tackle with the limitation, we propose the self-attention architecture to augment the original network. It provides a better balance between ability to model long-range dependencies and computational efficiency. Experiments on Atari games illustrate that self-attention structure is significantly effective for function approximation in deep reinforcement learning.
Xi Xiao 0001, Guangwu Hu, Yao Yao 0006, Dianyan Zhang, Zhendong Peng, Qing Li 0006, Shutao Xia
ICASSP3
2019 Android malware detection based on system call sequences and LSTM
Xi Xiao 0001, Shaofeng Zhang, Francesco Mercaldo, Guangwu Hu, Arun Kumar Sangaiah
Multim. Tools Appl.4
2018 CenLocShare: A centralized privacy-preserving location-sharing system for mobile online social networks
Xi Xiao 0001, Chunhui Chen 0003, Arun Kumar Sangaiah, Guangwu Hu, Runguo Ye, Yong Jiang 0001
Future Gener. Comput. Syst.4
2018 New deep learning method to detect code injection attacks on hybrid applications
Ruibo Yan, Xi Xiao 0001, Guangwu Hu, Sancheng Peng, Yong Jiang 0001
J. Syst. Softw.3
2017 Balancer: A Traffic-Aware Hybrid Rule Allocation Scheme in Software Defined Networks
abstract
In Software Defined Networking (SDN), the severe conflict between rule number and memory size has attracted considerable academic attention. Ternary Content Addressable Memory (TCAM), generally used to guarantee the query speed, is a scarce and expensive resource, which limits the number of rules that the switch can support. However, the table miss may increase processing burden of the controller and cause latency issues. Therefore, it is significantly important to improve the efficiency of TCAM in SDN switches. In this paper, we propose BALANCER, a traffic-aware hybrid rule allocation scheme. In BALANCER, we logically split TCAM into two parts: reactive and proactive, which can be dynamically adjusted according to network traffic behavior. Also, we propose an algorithm to generate proactive rules with high entropy in the proactive part, and for the reactive part, we provide a rule caching approach and an efficient rule replacement algorithm, Multi-Bucket. To evaluate BALANCER, we conduct comprehensive experiments with both synthetic and real-world routing policies. Compared with the reactive mode and the proactive mode, results show that BALANCER achieves the least update costs while the number of table misses is extremely close to that in the proactive mode.
Dingmin Wang, Qing Li 0006, Yong Jiang 0001, Mingwei Xu 0001, Guangwu Hu
ICCCN5
2017 TrueID: A practical solution to enhance Internet accountability by assigning packets with creditable user identity code
Guangwu Hu, Qi Li 0002, Yong Jiang 0001, Ke Xu 0002
Future Gener. Comput. Syst.1
2016 Real-Time Dynamic Decomposition Storage of Routing Tables
Lijing Lan, Xiaolan Tang, Guangwu Hu
CollaborateCom5
2016 Routing Model Based on Service Degree and Residual Energy in WSN
Zhenzhen Sun, Xiaolan Tang, Guangwu Hu
CollaborateCom4
2016 SAVSH: IP source address validation for SDN hybrid networks
abstract
Current Internet packet forwarding only relies on destination IP address and thus neglects the validation of packet's IP source address for Internet accountability, which incurs many cyber-security threats. State-of-the-art solutions either have issues in spoofing packet filtering accuracy, e.g., false positive and false negative, or encounter scalability and deployment problems, i.e., end-host TCP/IP stack or router modification. In this article, we propose SAVSH, a practical IP source address validation scheme for Software Defined Networking (SDN) hybrid networks. SAVSH takes advantage of the SDN architecture which possesses global topological view and central control pattern, so that it can locate nodes for the SDN switch replacement and deploy filtering rules onto them with desirable IP prefix-level filtering accuracy. In the meantime, SAVSH also takes network dynamics (e.g., topology changes) into account. Finally, the established prototype experiment and typical topology simulations demonstrate SAVSH not only possesses desirable performance, but also owns the capability that trades the maximal validation effect with the minimal SDN switch deployment cost, which is up to more than 90% prefix coverage benefit to 15% deployment cost on average.
Guangwu Hu, Yong Jiang 0001, Chaoqin Zhang
ISCC2
2016 MSRT: Multi-Source Request and Transmission in Content-Centric Networks
abstract
In Content-Centric Networks (CCN), multiple routers may cache the same content, which makes it possible to retrieve the content chunks in parallel. In this paper, we propose Multi-Source Request and Transmission mechanism (MSRT) for CCN. We develop a MinMax problem to compute the optimal solution to retrieve all the chunks from multiple sources in the shortest time. We prove that the problem is NP complete and thus design a fully polynomial-time approximation algorithm to solve this problem. However, the previous works on multipath congestion control cannot be directly employed in MSRT. Therefore, we then propose the Half eXplicit Congestion Protocol (HXCP) to control the request/transmission pace in MSRT. To demonstrate the performance of MSRT, we construct comprehensive experiments. The results show that 1) our scheme reduces the content transmission time to at most 80%; 2) our multipath congestion control scheme HXCP effectively avoids congestion, improves the throughput and guarantees the fairness in the multi-source/multipath scenario.
Qing Li 0006, Bin Gan, Guangwu Hu, Yong Jiang 0001, Qingmin Liao, Mingwei Xu 0001
IWQoS3
2016 FICUS: Fast Incremental Consistent Update in SDN based on relation graph
abstract
In Software Defined Networking (SDN), the configuration inconsistency during updates is one main source of network instability. An efficient updating scheme with configuration consistency is required. In this paper, we propose the scheme of Fast Incremental Consistent Update for SDN (FICUS) based on the relation graph (RG). In our scheme, we analyse the relation between update operations, construct the relation graph and find a proper order of these update operations to avoid inconsistency. To solve the problem, we define two types of relations: the path dependency relation and the path rejection relation. We evaluate our scheme and algorithms by comprehensive experiments. The results show that our scheme needs only 10%–40% of the rules compared with the two-phase update scheme and speeds up the update process by 40% in average.
Qing Li 0006, Lei Wang 0071, Yong Jiang 0001, Guangwu Hu, Mingwei Xu 0001, Qingmin Liao
IWQoS4
2014 Towards evolvable Internet architecture-design constraints and models analysis
Ke Xu 0002, Guangwu Hu, Yifeng Zhong, Ying Liu 0024, Ning Wang 0001
Sci. China Inf. Sci.3
2012 MR-OLSR: A link state routing algorithm in multi-radio/multi-channel Wireless Mesh Networks
abstract
In order to improve throughput and perform load balancing, many routing algorithms in WMNs (Wireless Mesh Networks) have been applied to take full advantages of multi-radio, multi-channel and multi-path of WMNs. Even though a lot of proposals have already shown their merits like LQSR, MR-LQSR etc., up to now, few schemes could universally achieve all of these objectives. In this paper, we present MR-OLSR, an optimized link state routing algorithm in multi-radio/multi-channel WMNs. It was improved by OLSR (Optimized Link State Routing) protocol in MANET. It can distribute data traffic among diverse multiple paths to avoid congestion, and improve channel throughput substantially. It uses the novel metric named IWCETT (Improved Weighted Culminated Estimate Transfer Time) to evaluate path quality. Besides, the proposed channel allocation strategy and path scheduling algorithm offer it the ability of loading balance. MR-OLSR is experimented in OPNET simulation environment, and the results prove that our proposal not merely maintains the merits of robustness and scalability in OLSR scheme. What's more, the proposal enhances the stability and reliability in the situation of links failing, and keeps the promise of increasing network throughput apparently.
Guangwu Hu, Chaoqin Zhang
APCC1
2011 SAVT: A Practical Scheme for Source Address Validation and Traceback in Campus Network
abstract
In current network, as we all know, packets delivered by routers only rely on destination-address-directed forwarding, but their source addresses are not checked. Consequently, this incurs many serious network security breach events which are hard to trackback. Under this situation, a switch (we call it SAVI switch) followed SAVI (Source Address Validation Improvement) framework proposed by IETF was invented which dedicates to resolving this problem in user local subnet. SAVI switch is a direct and very effective anti-spoofing device, but because it just steps into a phase of industrialization and for economical and incremental deployment reasons, these switches are not fully covered in domain. This results in two issues at the same time: 1)how to filter out and abandon those packets whose source IP addresses belong to SAVI switches coverage, but actually not, otherwise, this will severely compromise the SAVI switch access users' motivation and SAVI's promotion. 2) how to traceback those packets' source router-the first hop routers of spoofed packets. In this paper, we present SAVT, a practical and smart scheme for source address validation and traceback in campus network for all outbound packets, it just need less 25% routers as filter router can resolve those two questions in most condition. Experiments illustrate our proposal keeps the promise of practicality, stability and efficiency.
Guangwu Hu, Ke Xu 0002
ICCCN1