Chin-Tser Huang

dblp:89/331 · DBLP profile ↗
← Back
46ranked-venue papers
8as first author
10since 2021 · last 2025
0000-0003-3983-972XORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 32 · 6 first-author · 5 since 2021Security and privacy · 9 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Weather-Aware Power Control for Decentralized V2V Communication
abstract
Vehicular networks rely on vehicle-to-vehicle (V2V) communication to enable real-time information sharing for collision avoidance, traffic efficiency and future autonomous driving systems. In V2V communication, vehicles constantly exchange messages; therefore, developing a power control method that saves energy and reduces interference is essential. Previous power control mechanisms typically rely on static configurations and neglect dynamic environmental factors such as weather conditions; some require feedback channels that may not be available in distributed V2V scenarios. As a result, those methods struggle to maintain reliable communication in rapidly changing conditions, particularly during adverse weather events. To address these limitations, this paper presents a novel weather-aware reinforcement learning-based power control algorithm to improve the robustness and efficiency of V2V communications. Unlike conventional open-loop power control schemes that rely solely on SINR-based heuristics, our algorithm incorporates weather-induced attenuation and vehicle density into the transmit power decision process to ensure reliable communication during link setup. Furthermore, we propose a reinforcement learning framework in which each vehicle autonomously learns optimal power control strategies over time by observing local SINR estimations, surrounding vehicle densities, and environmental variations. The learning agent dynamically adjusts the transmission power to maximize communication reliability and minimize interference between vehicles. We conducted simulations based on 3GPP TR37.885 scenarios, and the results show that our solution effectively addresses the impact of weather on power control in V2V networks and achieves better reliability and adaptability under challenging weather conditions.
Jian Liu 0031, Chin-Tser Huang
ICCCN2
2025 Techie: Tackling Video Prefetching at Edge Networks as POMDP Via an Intrinsically Motivated RL Agent
Nawras Alkassab, Chin-Tser Huang, Tania Lorido-Botran
SIGIR2
2024 SmartSSD-Accelerated Cryptographic Shuffling for Enhancing Database Security
Tieming Geng, Chin-Tser Huang
DBSec2
2024 DeePref: Deep Reinforcement Learning For Video Prefetching In Content Delivery Networks
abstract
Content Delivery Networks carry the majority of Internet traffic, and the increasing demand for video content as a major IP traffic across the Internet highlights the importance of caching and prefetching optimization algorithms. Prefetching aims to make data available in the cache before the requester places its request to reduce access time and improve the Quality of Experience on the user side. Traditional prefetching techniques are well adapted to a particular access pattern, but fail to adapt to sudden variations or randomization in workloads. This paper explores the use of deep reinforcement learning to tackle the changes in users' access patterns and automatically adapt over time to predict future requests. We propose DeePref, an auto-aggressive video prefetcher that is sensitive to different storage capacities at edge networks. DeePref is agnostic to hardware design, operating systems, and applications in which it utilizes only the video ID to make prefetching decisions online. DeePref outperforms baseline approaches that use video content popularity as a building block to statically or dynamically make prefetching decisions. Our results show that DeePref, using a real-world dataset, achieves 17% increase in terms of prefetching accuracy and 28% increase in prefetching coverage. We also study the possibility of transfer learning of statistical models from one edge network into another, where unseen user requests from unknown distribution are observed. Our results indicate that DeePref effectively adapts to distribution shifts where the increase in prefetching accuracy and prefetching coverage are [30%, 10%], respectively.
Nawras Alkassab, Chin-Tser Huang, Tania Lorido-Botran
ICCCN2
2024 The universal federator: A third-party authentication solution to federated cloud, edge, and fog
Ying-Dar Lin, Jian Liu 0031, Chin-Tser Huang
J. Netw. Comput. Appl.4
2023 SMHSDVS: A Secure and Mutual Heterogeneous Strong Designated Signature Between PKI and IBC
Chin-Tser Huang, Binhao Ma, Bo Meng 0004
ProvSec3
2022 A Survey of Blockchain-Based Electronic Voting Mechanisms in Sensor Networks
abstract
Electronic voting technology has the ability to accelerate the counting of ballots, reduce the cost of voting, and offer convenience for remote voters. Meanwhile, the efficiency of voting can be improved. Immutability, verifiability, and distribution are the main features blockchain can provide. Building an electronic voting system based on the blockchain can help to mitigate the security issues such as single-point failure and data manipulation. However, some blockchain systems are not feasible in the environment of sensor networks. In this paper, we propose a comparative analysis of blockchain-based electronic voting systems from the perspective of blockchain type, cryptography techniques, counting method, and security requirements. We also identify a possible new direction for the design of blockchain-based electronic voting systems for the reference of future research.
Tieming Geng, Laurent Njilla, Chin-Tser Huang
SenSys3
2022 Smarkchain: An Amendable and Correctable Blockchain Based on Smart Markers
abstract
Immutability is an important property of blockchain which ensures integrity and prevents forgery modification of previous transactions. However, immutability also prohibits the possibility of amending outdated codes and correcting typography or fraudulent data, both of which are common needs in many use cases. Therefore, a tradeoff that keeps the integrity guarantee but lifts the strict limitation of immutability is necessary to allow the practical applications of blockchain in areas other than cryptocurrencies. In this paper, we propose a novel scheme called Smarkchain, which will enhance blockchain technology with the features of amendment and correction by incorporating smart markers, an approach which enables multiway branching and merging in blockchain. Smarkchain has the unique advantages of allowing multiple consecutive blocks to be amended or corrected at one time, allowing multiple amendments or corrections over the same blocks, and not needing to modify existing blocks. Evaluation results of a prototype implementation show that our approach is practical.
Chin-Tser Huang, Laurent Njilla, Tieming Geng
TrustCom1
2021 Efficient and Trustworthy Authentication in 5G Networks Based on Blockchain
abstract
The global coronavirus pandemic is reshaping our daily lives and has forced many people to work and socialize remotely. This trend also increases the demand for highly available and trustworthy Internet access. Compared with 4G networks, 5G mobile networks are designed to accommodate the increasing number of mobile devices with higher transfer speed, lower latency and improved security. The 5G standard in USA uses millimeter waves, which is much shorter than 4G LTE signals. The shorter wavelength means 5G can transfer data much faster than 4G, but it also results in a much shorter travel range. When a user is moving among 5G cells, repeated authentications will increase delay time which contradicts 5G objective. The blockchain technology has the advantage of better transparency, enhanced security and high efficiency. In this paper, we propose an efficient authentication approach for 5G network using blockchain technology to reduce repeated authentications and keep the cost low and practical. We will compare it with some existing protocols and analyze its security against several possible attacks.
Jian Liu 0031, Chin-Tser Huang
ICCCN2
2021 Resilient User-Side Android Application Repackaging and Tampering Detection Using Cryptographically Obfuscated Logic Bombs
abstract
Application repackaging is a severe threat to Android users and the market. Not only does it infringe on intellectual property, but it is also one of the most common ways of propagating mobile malware. Existing countermeasures mostly detect repackaging based on app similarity measurement, which tends to be imprecise when obfuscations are applied to repackaged apps. Moreover, they rely on a central party, typically the hosting app store, to perform the detection, but many app stores fail to commit proper effort to piracy detection. We consider building the application repackaging detection capability into apps, such that user devices are made use to detect repackaging in a decentralized fashion.The main challenge is how to protect the detection code from being manipulated by attacks. We propose a creative use oflogic bombs, which are otherwise regularly used in malware. Thetrigger conditionsof bombs are constructed to exploit the differences between the attacker and users, such that a bomb that lies dormant on the attacker side will be activated on the user side. The detection code, which is part of the bombpayload, is executed only if the bomb is activated. We introducecryptographically obfuscated logic bombto enhance the bomb: (1) the detection code iswoveninto the neighboring original app code, (2) the mixed code gets encrypted using a key, and (3) the key is deleted from the app and can only be derived when the bomb is activated. Thus, attacks that try to modify or delete the detection code will corrupt the app itself, and searching the key in the application will be in vain. Moreover, we propose abomb sprayingtechnique that allows many bombs to be injected into an app, multiplying the needed adversary effort for bypassing the detection. In addition to repackaging detection, we present application tampering detection to fight attacks that insert malicious code into repackaged apps. We have implemented a prototype, namedBombDroid, that builds repackaging and tampering detection into apps through bytecode instrumentation. The evaluation and the security analysis show that the technique is effective, efficient, and resilient to various bomb analysis techniques including fuzzing, symbolic execution, multi-path exploration, and program slicing. Ethical issues due to the use of logic bombs are also discussed.
Qiang Zeng 0001, Lannan Luo, Zhiyun Qian, Xiaojiang Du, Zhoujun Li 0001, Chin-Tser Huang, Csilla Farkas
IEEE Trans. Dependable Secur. Comput.6
2020 Maximizing accuracy in multi-scanner malware detection systems
Muhammad N. Sakib, Chin-Tser Huang, Ying-Dar Lin
Comput. Networks2
2020 A Bayesian Game Theoretic Approach for Inspecting Web-Based Malvertising
abstract
Web-based advertising systems have been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply various redirection and evasion techniques. Meanwhile, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under resource and time constraints. Moreover, the ad network is disadvantaged because it has incomplete information about whether it is facing a benign or malicious advertiser. In this paper, we aim to apply the Bayesian game model by designing two games to formulate the problem of inspecting the Web-based maladvertising. The first game has two types of Advertisers, namely Malicious and Benign, and one type of Defender; the second game has two types of Attackers, Advanced and Simple, in terms of their capability of redirection and evasion, and one type of Defender. We define their strategies and payoff functions, and compute their Bayesian Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and we derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy.
Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
IEEE Trans. Dependable Secur. Comput.1
2017 A game theoretic approach for inspecting web-based malvertising
abstract
Web-based advertising system has become a convenient and efficient channel for advertisers to deliver ads to targeted Internet users. Unfortunately, this system has been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply a variety of evasion techniques such as fingerprinting the execution environment, redirecting to compromised IP addresses, and malware polymorphism. On the other hand, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under the constraints of resource and time. In this paper, we aim to apply game theory to formulate the problem of inspecting the malware inserted by the malvertisers into the Web-based advertising system. We design a normal form game between the malvertiser and the ad network, define their strategies and payoff functions, and compute their pure-strategy and mixed-strategy Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy.
Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
ICC1
2016 Using anomaly detection based techniques to detect HTTP-based botnet C&C traffic
abstract
HTTP is becoming the most preferred channel for command and control (C&C) communication of botnets. One of the main reasons is that it is very easy to hide the C&C traffic in the massive amount of browser generated Web traffic. However, detecting these HTTP-based C&C packets which constitute only a minuscule portion of the overall everyday HTTP traffic is a formidable task. In this paper, we present an anomaly detection based approach to detect HTTP-based C&C traffic using statistical features based on client generated HTTP request packets and DNS server generated response packets. We use three different unsupervised anomaly detection techniques to isolate suspicious communications that have a high probability of being part of a botnet's C&C communication. Results indicate that our method can achieve more than 90% detection rate while maintaining a reasonably low false positive rate.
Muhammad N. Sakib, Chin-Tser Huang
ICC2
2016 Jamming mobility in 802.11p networks: Modeling, evaluation, and detection
abstract
The development of wireless Vehicular Ad-Hoc Network (VANET) aimed to enhance road's safety and provide comfortable driving environment by delivering early warning and infotainment messages. Intentional jamming attacks target at undermining such a goal by disrupting wireless communications. While detecting jamming attacks is important towards enhancing road safety, it is challenging because VANET operates in outdoor environment (highly changeable road conditions and atmospheric phenomena), and encompasses volatile topology and high mobility of vehicles (traveling speed and directions). To overcome these challenges, in this work, we study jamming attack mobility and behaviors in IEEE802.11p networks. In particular, we focus on analyzing jamming impact based on jammers behaviors, and mobility patterns. Thus, in order to achieve reliable detection, first we identify the impact of vehicles' density on network performance. Then, we study jamming effectiveness when adopting different mobility patterns (stationary, random, or targeting) and behaviors (constant, random, and reactive). Finally, we propose a two phase detection algorithm and evaluate it in a simulation environment. Our approach shows promising results to detect different types of jammers accurately in IEEE802.11p networks.
Sharaf Jameel Malebary, Chin-Tser Huang
IPCCC3
2016 Countering Burst Header Packet Flooding Attack in Optical Burst Switching Network
Adel D. Rajab, Chin-Tser Huang, Mohammed Al-Shargabi, Jorge Arturo Cobb
ISPEC2
2014 A moving-target defense strategy for Cloud-based services with heterogeneous and dynamic attack surfaces
abstract
Due to deep automation, the configuration of many Cloud infrastructures is static and homogeneous, which, while easing administration, significantly decreases a potential attacker's uncertainty on a deployed Cloud-based service and hence increases the chance of the service being compromised. Moving-target defense (MTD) is a promising solution to the configuration staticity and homogeneity problem. This paper presents our findings on whether and to what extent MTD is effective in protecting a Cloud-based service with heterogeneous and dynamic attack surfaces — these attributes, which match the reality of current Cloud infrastructures, have not been investigated together in previous works on MTD in general network settings. We 1) formulate a Cloud-based service security model that incorporates Cloud-specific features such as VM migration/snapshotting and the diversity/compatibility of migration, 2) consider the accumulative effect of the attacker's intelligence on the target service's attack surface, 3) model the heterogeneity and dynamics of the service's attack surfaces, as defined by the (dynamic) probability of the service being compromised, as an S-shaped generalized logistic function, and 4) propose a probabilistic MTD service deployment strategy that exploits the dynamics and heterogeneity of attack surfaces for protecting the service against attackers. Through simulation, we identify the conditions and extent of the proposed MTD strategy's effectiveness in protecting Cloud-based services. Namely, 1) MTD is more effective when the service deployment is dense in the replacement pool and/or when the attack is strong, and 2) attack-surface heterogeneity-and-dynamics awareness helps in improving MTD's effectiveness.
Wei Peng 0007, Feng Li 0001, Chin-Tser Huang, Xukai Zou
ICC3
2014 Feedback-based smartphone strategic sampling for BYOD security
abstract
Bring Your Own Device (BYOD) is an information technology (IT) policy that allows employees to use their own wireless devices to access internal network at work. Mobile malware is a major security concern that impedes BYOD's further adoption in enterprises. Existing works identify the need for better BYOD security mechanisms that balance between the strength of such mechanisms and the costs of implementing such mechanisms. In this paper, based on the idea of self-reinforced feedback loop, we propose a periodic smartphone sampling mechanism that significantly improve BYOD security mechanism's effectiveness without incurring further costs. We quantify the likelihood that “a BYOD smartphone is infected by malware” by two metrics, vulnerability and uncertainty, and base the iterative sampling process on these two metrics; the updated values of these metrics are fed back into future rounds of the mechanism to complete the feedback loop. We validate the efficiency and effectiveness of the proposed strategic sampling via simulations driven by publicly available, real-world collected traces.
Feng Li 0001, Chin-Tser Huang, Wei Peng 0007
ICCCN2
2013 Smartphone strategic sampling in defending enterprise network security
abstract
Smartphones have made their inroads in enterprise environment, manifested in the Bring Your Own Device (BYOD) policy: More employees are bringing their own smartphones to work and are using them to access enterprise information assets. The dilemma between responsiveness to security incidents and convenience/cost-effectiveness demands BYOD security solutions beyond the straightforward all-inclusive full-scanning or uniformly random sampling approaches. In this paper, we propose a carefully planned but otherwise random, or strategic, sampling approach out of this dilemma. Strategic sampling provides a balance between security responsiveness and cost effectiveness by identifying and periodically sampling those representative smartphones (security-wise). We validate the efficiency and effectiveness of the proposed strategic sampling via simulations driven by publicly available, real-world collected traces.
Feng Li 0001, Wei Peng 0007, Chin-Tser Huang, Xukai Zou
ICC3
2013 PASSAGES: Preserving Anonymity of Sources and Sinks against Global Eavesdroppers
abstract
While many security schemes protect the content of messages in the Distributed Sensing Systems (DSS), the contextual information, such as communication patterns, is left vulnerable and can be utilized by attackers to identify critical information such as the locations of event sources and message sinks. Existing solutions for location anonymity are mostly designed to protect source or sink location anonymity individually against limited eavesdroppers on a small region at a time. However, they can be easily defeated by highly motivated global eavesdroppers that can monitor entire communication events on the DSS. To grapple with these challenges, we propose a mechanism for Preserving Anonymity of Sources and Sinks against Global Eavesdroppers (PASSAGES). PASSAGES uses a small number of stealthy permeability tunnels such as wormholes and message ferries to scatter and hide the communication patterns. Unlike prior schemes, PASSAGES effectively achieves a high anonymity level for both source and sink locations, without incurring extra communication overheads. We quantify the location anonymity level and evaluate the effectiveness of PASSAGES via analysis as well as extensive simulations. We also perform evaluations on the synergistic effect when PASSAGES is combined with other traditional solutions.
Hyungbae Park, Sejun Song, Baek-Young Choi, Chin-Tser Huang
INFOCOM4
2012 Textact: A text-action based web authentication scheme
abstract
World Wide Web has become an integral part of our life and the bulk of Web usage involves user authentication. Technology available in this area does not offer much variation. Much research has been done to improve security and user experience of Web authentication, but still the schemes are far from being perfect. In this paper, we present a novel Web authentication scheme, Textact, which can meet the desired level of competence in multiple criteria including password space, memorizability, and security against known attacks. We also give a comparative analysis on improvement over the existing authentication schemes.
Muhammad N. Sakib, Chin-Tser Huang
GLOBECOM2
2012 A Secure and Efficient Multi-Device and Multi-Service Authentication Protocol (SEMMAP) for 3GPP-LTE Networks
abstract
3GPP-LTE networks use the EAP-AKA protocol to authenticate and negotiate session keys with mobile users. However, with the popular trend of single user owning multiple devices and subscribing to multiple services, the EAP-AKA protocol appears inefficient because its authentication is device-oriented. In this paper, we propose a secure and efficient multi-device and multi-service authentication protocol, called SEMMAP, for 3GPP-LTE networks. SEMMAP makes use of a key hierarchy and an authority-issued license to enable an authenticating server to quickly verify the legitimacy of multiple devices belonging to the same mobile user and conduct a fast key negotiation between the server and the mobile user. Performance analysis shows that SEMMAP is more efficient than the current EAP-AKA protocol under the multi-device, multi-service scenario in terms of authentication delay and storage overhead for Authentication Vector (AV) at authenticating servers.
Chin-Tser Huang
ICCCN2
2011 Automatic Selection of Routers for Placing Early Filters of Malicious Traffic
abstract
Botnets have become the top threat to Internet security. Botnets generate and transmit huge amounts of malicious traffic for various purposes. In this paper, we propose a dynamic programming based algorithm to calculate a set of appropriate routers for placing early filters of malicious traffic in the network in order to maximize the benefits of early malicious traffic filtering. Moreover, we discuss how to combine our early filtering approach and the QoS routing of traffic so that the bandwidth saved by early filtering of malicious traffic can be efficiently utilized by legitimate traffic.
Chin-Tser Huang, Keesook J. Han, James Perretta
GLOBECOM1
2011 Secure Mutual Authentication Protocols for Mobile Multi-Hop Relay WiMAX Networks against Rogue Base/Relay Stations
abstract
Mobile multi-hop relay (MMR) WiMAX networks have attracted lots of interest in the wireless communication industry recently because of its scalable coverage, improved data rates and relatively low cost. However, security of MMR WiMAX networks is the main challenge. In this paper, we first identify a possible attack on MMR WiMAX networks in which a rogue base station (BS) or relay station (RS) can get authenticated and gain control over the connections. We also show that the current standard does not address this problem well. We then propose a set of new authentication protocols for protecting MMR WiMAX networks from rogue BS and rogue RS attacks. Our protocols provide centralized authentication by using a trusted authentication server to support mutual authentication between RS and BS, between RS and RS, and between MS and RS. Our protocols can also provide distributed authentication with a license issued by the trusted server.
Chin-Tser Huang
ICC2
2011 Look-Ahead Routing and Message Scheduling in Delay-Tolerant Networks
Yi Xian, Chin-Tser Huang, Jorge Arturo Cobb
Comput. Commun.2
2010 Analysis and Enhancement of Bandwidth Request Strategies in IEEE 802.16 Networks
abstract
IEEE 802.16 based broadband wireless access network is considered as one of the most promising wireless access technologies. It employs a request/grant scheme in bandwidth allocation where each subscriber station (SS) can send bandwidth requests (BRs) to the base station (BS) before bandwidth can be granted to SSs. The 802.16 standard defines two types of BR strategies, namely incremental requests and aggregate requests. In this paper, we first present an analytic model to analyze their performance and show that both types of BRs have rooms for improvement when facing two common types of traffic patterns, called the uphill traffic pattern and the periodic/bursty traffic pattern, in terms of overhead and data waiting time in the queue. Then, we propose two enhancement strategies, called the aggressive strategy and the conservative strategy, that exploit the property of the two traffic patterns to improve the performance. The simulation results show that the two enhancement strategies can effectively reduce the overhead and data waiting time, at the price of somewhat less bandwidth utilization in the case of conservative strategy.
Chin-Tser Huang, Chang-Ling Huang, J. Morris Chang
ICC1
2010 Look-ahead routing and Message Scheduling in delay-tolerant networks
abstract
Routing is one of the most challenging development issues in delay-tolerant networks (DTNs) because of lack of continuous connection. Existing routing schemes for DTNs provide best effort service, but are unable to optimize QoS and support message priority. In this paper, we present a Look-Ahead Routing and Message Scheduling approach (ALARMS) which exploits more accurate knowledge about various parameters regarding routing to achieve better QoS in the DTN. We assume a variation of the well-known ferry model, in which there are ferry nodes moving along pre-defined routes to exchange messages with the gateway node of each region on the route and also pass to the gateway nodes look-ahead routing information about when it will arrive at each gateway node on the route in the next two rounds and how long it will stay. The gateway nodes use this information to estimate the delivery delay of each message when being delivered by different ferries, and schedule the message to be delivered by the ferry which arrives earliest at the destination. Simulation results show that ALARMS outperforms three existing routing protocols: epidemic routing, spray-and-wait, and spray-and-focus, in terms of delay time, delivery ratio, and overhead. We also discuss three enhancement strategies on ALARMS and how ALARMS can support message priority.
Yi Xian, Chin-Tser Huang, Jorge Arturo Cobb
LCN2
2010 Stabilization of Flood Sequencing Protocols in Sensor Networks
abstract
Flood is a communication primitive that can be used by the base station of a sensor network to send a copy of a message to every sensor in the network. When a sensor receives a flood message, the sensor needs to check whether it has received this message for the first time and so this message is fresh, or it has received the same message earlier and so the message is redundant. In this paper, we discuss a family of four flood sequencing protocols that use sequence numbers to distinguish between fresh and redundant flood messages. These four protocols are: a sequencing free protocol, a linear sequencing protocol, a circular sequencing protocol, and a differentiated sequencing protocol. We analyze the self-stabilization properties of these four flood sequencing protocols. We also compare the performance of these flood sequencing protocols, using simulation, over various settings of sensor networks. We conclude that the differentiated sequencing protocol has better stabilization property and provides better performance than those of the other three protocols.
Young-ri Choi, Chin-Tser Huang, Mohamed G. Gouda
IEEE Trans. Parallel Distributed Syst.2
2009 P2F: A User-Centric Privacy Protection Framework
abstract
In this paper, we present an end-user tool called the privacy protection framework (P2F) which aims to support users in protecting their privacy when obtaining Web-based services. P2F acts as a recommendation tool that analyzes the user's transaction history and privacy preferences in addition to real-world privacy guidelines to prevent undesirable disclosure of personal data. The framework is based on a novel qualitative privacy compromise risk assessment approach designed to support decision-making in settings where server-side support for user-centric privacy protection frameworks is minimal or unkown. Our risk assessment model uses service provider properties, likelihood of collusion between providers, the sensitivity of the personal data to be released, and undesirable transaction linkability to determine the privacy compromise potential of a transaction.
Maryam Jafari-lafti, Chin-Tser Huang, Csilla Farkas
ARES2
2009 On the Benefits of Early Filtering of Botnet Unwanted Traffic
abstract
Unwanted traffic has become a worsening problem for the availability and reliability of the Internet. Today most unwanted traffic can be attributed to botnets, which can generate massive unwanted traffic to the victim using a huge number of bots. Although there exist techniques to filter and discard the unwanted packets at the destinations, these packets are still allowed to traverse the backbone of the Internet to cause severe traffic burdens and waste bandwidth resource of the Internet. In this paper, we propose a novel approach called Dynamic Early Filtering of Internet Traffic (DEFT). DEFT encodes unwanted traffic filtering rules as routing information using the flow specification (Flow-Spec) NLRI field in BGP Update messages, so that BGP routers not only can incorporate the filtering rules into their routing decision, but can also forward the rules to their neighboring routers, in order to reach routers that are closer to the sources and achieve early filtering of the offending traffic. We implement a prototype based on the Quagga routing software, and use the Deterlab testbed to conduct various experiments to evaluate the performance of DEFT on different degrees of attacking source distribution and different degrees of filtering rule dissemination. The experimental results show that with small overhead DEFT can effectively reduce the average transmission latency and increase the average throughput of legitimate traffic.
Prasanth Kalakota, Chin-Tser Huang
ICCCN2
2009 Stabilization of Maximal-Metric Routing without Knowledge of Network Size
abstract
We present a protocol for maintaining a spanning tree that is maximal with respect to any given (bounded and monotonic) routing metric. This protocol has two interesting adaptive properties. First, the protocol is stabilizing: starting from any state, the protocol stabilizes to a state where a maximal tree is present. Second, contrary to other approaches, the protocol converges in O(L * deg) time, where deg is the node degree in the network and L the longest network path. This is achieved without nodes assuming an upper bound on L.
Jorge Arturo Cobb, Chin-Tser Huang
PDCAT2
2009 Multi-dimensional credentialing using veiled certificates: Protecting privacy in the face of regulatory reporting requirements
John H. Gerdes Jr., Joakim Kalvenes, Chin-Tser Huang
Comput. Secur.3
2007 Improving Availability with Adaptive Roaming Replicas in Presence of Determined DoS Attacks
abstract
Static replicas have been proven useful in providing fault tolerance and load balancing, but they may not provide enough assurance on the continuous availability of mission- critical data in face of a determined denial-of-service (DoS) attacker. A roaming replica scheme can provide higher availability assurance, but the overhead associated with replica movement and lookup is high. In this paper, we propose ARRP, an adaptive roaming replication protocol in which static replicas are used normally but if a certain percentage of static replicas has already been shut down, then a small number of roaming replicas will be added and stored in randomly selected hosts that are changed periodically. In particular, we analyze the appropriate threshold when the roaming replica scheme should be enabled by empirically investigating the tradeoff between availability, performance, and overhead. Simulation results show that ARRP can effectively mitigate the impacts of DoS attacks and host failures to ensure continuous availability of critical data, with better performance and reasonable overhead compared to only using static replicas.
Chin-Tser Huang, Prasanth Kalakota, Alexander B. Alexandrov
GLOBECOM1
2007 Fates: A Granular Approach to Real-Time Anomaly Detection
abstract
Anomaly-based intrusion detection systems have the ability of detecting novel attacks, but in real-time detection, they face the challenges of producing many false alarms and failing to contend with the high speed of modern networks due to their computationally demanding algorithms. In this paper, we present Fates, an anomaly-based NIDS designed to alleviate the two challenges. Fates views the monitored network as a collection of individual hosts instead of as a single autonomous entity and uses dynamic, individual threshold for each monitored host, such that it can differentiate between characteristics of individual hosts and independently assess their threat to the network. Each packet to and from a monitored host is analyzed with an adaptive and efficient charging scheme that considers the packet's type, number of occurrences, source, and destination. The resulting charge is applied to the individual hosts' threat assessment, providing pinpointed analysis of anomalous activities. We use various datasets to validate Fates's ability to distinguish scanning behavior from benign traffic in real time.
Jeff Janies, Chin-Tser Huang
ICCCN2
2007 Containing Hitlist-Based Worms with Polymorphic Signatures
abstract
Worms are a significant threat to network systems, both through resource consumption and malicious activity. This paper examines the spread of a class of hitlist-based worms that attempt to propagate by searching for address book files on the host system and using the host's mail program to spread to the addresses found. This threat becomes more severe when the worms are assumed to be polymorphic in nature - able to dynamically change their signature to elude capture. Because the method of propagation for these worms is predictable, it is possible to contain their spread through the use of honeytoken e-mail addresses in the client address book. Any e-mail received by the honeytoken address will be immediately recognized as malicious and can therefore be used to flag client machines as infected. This paper provides a complete description of a method to allow for better containment of this class of worms. The results of the proposed method are examined and compared to a previous method of capturing this type of worm.
Theodor Richardson, Chin-Tser Huang
ICCCN2
2007 Summarization of Wearable Videos Based on User Activity Analysis
abstract
This paper presents a model for automatic summarization of videos recorded by wearable cameras. The proposed model detects various user activities by computing the transform of matching image features among video frames. Four basic types of user activities are proposed, including "moving closer /farther", "panning", "making a turn", and "rotation". Different summarization techniques are provided for different activity types, and a wearable video sequence can be summarized as a compact set of panoramic images. The user activity analysis is solely based on the analysis of images, without resorting to the information of other sensors. Experimental results on a 19- minute video sequence demonstrate the effectiveness of our proposed model.
Ravi Katpelly, Tiecheng Liu, Chin-Tser Huang
ISM3
2006 SUMP: A Secure Unicast Messaging Protocol for Wireless Ad Hoc Sensor Networks
abstract
Most wireless ad hoc sensor networks are susceptible to routing level attacks, in which an adversary masquerades as a legitimate node to convince neighboring nodes that it is the "logical" next hop or is on a "better" path for forwarding packets, and arbitrarily drops the packets forwarded by neighboring nodes. In this paper, we propose a secure unicast messaging protocol (SUMP) for wireless ad hoc sensor networks to mitigate the threat of routing level attacks. SUMP groups nodes into levels based on hop count to provide hop-by-hop group authentication using Merkel hash trees. This method allows for varied levels of security in accordance with a node's hop count from the base station and secure, directed unicast communications from the base station to individual nodes. Unlike other sensor network security protocols that require the storage of parent node information, a sensor node running SUMP does not store parent node information, therefore preventing an adversary from gaining information of other nodes from a compromised node.
Jeff Janies, Chin-Tser Huang, Nathan L. Johnson
ICC2
2006 On capturing and containing E-mail worms
abstract
Capturing an E-mail worm and containing its propagation as early as possible is desirable in order to provide better protection for the networks and hosts against severe damage that may be caused by the worm. In this paper, we propose a new approach that makes use of the propagating nature of E-mail worms. This approach inserts into each client's address book a dummy E-mail address that is not used by any registered user of the local domain, such that we can be confident that any E-mail destined to this dummy E-mail address is generated by an E-mail worm. The captured signatures can then be used to construct a user blacklist and a signature blacklist to contain the propagation of this E-mail worm. We also discuss how E-mail worms can attempt to bypass the dummy E-mail address, and propose countermeasures against these attempts. Our prototype implementation shows that this approach is easily deployable and is effective in containing E-mail worms
Chin-Tser Huang, Nathan L. Johnson, Jeff Janies, Alex X. Liu
IPCCC1
2006 Fault Masking in Tri-redundant Systems
Mohamed G. Gouda, Jorge Arturo Cobb, Chin-Tser Huang
SSS3
2005 A secure cookie protocol
abstract
Cookies are the primary means for Web applications to authenticate HTTP requests and to maintain client states. Many Web applications (such as electronic commerce) demand a secure cookie protocol. Such a protocol needs to provide the following four services: authentication, confidentiality, integrity and antireplay. Several secure cookie protocols have been proposed in previous literature; however, none of them are completely satisfactory. In this paper, we propose a secure cookie protocol that is effective, efficient, and easy to deploy. In terms of effectiveness, our protocol provides all of the above four security services. In terms of efficiency, our protocol does not involve any database lookup or public key cryptography. In terms of deployability, our protocol can be easily deployed on an existing Web server, and it does not require any change to the Internet cookie specification. We implemented our secure cookie protocol using PHP, and the experimental results show that our protocol is very efficient.
Alex X. Liu, Jason M. Kovacs, Chin-Tser Huang, Mohamed G. Gouda
ICCCN3
2003 A secure address resolution protocol
Mohamed G. Gouda, Chin-Tser Huang
Comput. Networks2
2002 Key Trees and the Security of Interval Multicast
abstract
A key tree is a distributed data structure of security keys that can be used by a group of users. In this paper we describe how any user in the group can use the different keys in the key tree to securely multicast data to different subgroups within the group. The cost of securely multicasting data to a subgroup whose users are "consecutive" is O(log n) encryptions, where n is the total number of users in the group. The cost of securely multicasting data to an arbitrary subgroup is O(n/2) encryptions. However this cost can be reduced to one encryption by introducing an additional key tree to the group.
Mohamed G. Gouda, Chin-Tser Huang, E. N. Elnozahy
ICDCS2
2002 Hop integrity in computer networks
abstract
A computer network is said to provide hop integrity if, when any router, p, in the network receives a message, m, supposedly from an adjacent router, q, then p can check that m was indeed sent by q, was not modified after it was sent and was not a replay of an old message sent from q to p. We describe three protocols that can be added to the routers in a computer network so that the network can provide hop integrity, and thus overcome most denial-of-service attacks. These three protocols are a secret exchange protocol, a weak integrity protocol and a strong integrity protocol. All three protocols are stateless, require small overhead and do not constrain the network protocol in the routers in any way.
Mohamed G. Gouda, E. N. Elnozahy, Chin-Tser Huang, Tommy M. McGuire
IEEE/ACM Trans. Netw.3
2001 An anti-replay window protocol with controlled shift
abstract
The anti-replay window protocol is used to secure IP against an adversary that can insert (possibly replayed) messages in the message stream from a source computer to a destination computer in the Internet. We discuss this important protocol and point out a potential problem faced by the protocol, in which severe reordering of messages can cause the protocol to discard a lot of good messages. We then introduce a controlled shift mechanism that can reduce the number of discarded good messages by sacrificing a relatively small number of messages. We use simulation to show that the modified protocol is more effective than the original protocol when a severe reordering of messages occurs. In particular, we show that the modified protocol reduces the number of discarded good messages by up to 70%.
Chin-Tser Huang, Mohamed G. Gouda
ICCCN1
2000 Anti-replay window protocols for secure IP
abstract
The anti-replay window protocol is used to secure IP against an adversary that can insert (possibly replayed) messages in the message stream from a source computer to a destination computer in the Internet. In this paper, we verify the correctness of this important protocol using standard methods (i.e. auxiliary variables, annotation, and invariants). We show that despite the adversary, the protocol delivers each message at most once, and discards a message only if another copy of this message has already been delivered, or the message has suffered a reorder of degree w or more, where w is the window size. We then develop another variation of this protocol that uses two windows of size w/2 each. This protocol delivers every message at most once, and discards a message only if another copy of this message has already been delivered, or the message has suffered a reorder of degree w+d or more, where d is the sum of current distances between successive windows in the protocol. We argue that the double-window protocol is more effective than the original single-window protocol.
Mohamed G. Gouda, Chin-Tser Huang
ICCCN2
2000 Hop Integrity in Computer Networks
abstract
A computer network is said to provide hop integrity iff when any router p in the network receives a message m supposedly from an adjacent router q, then p can check that m was indeed sent by q, was not modified after it was sent, and was not a replay of an old message sent from q to p. We describe three protocols that can be added to the routers in a computer network so that the network can provide hop integrity. These three protocols are a secret exchange protocol, a weak integrity protocol, and a strong integrity protocol. All three protocols are stateless, require small overhead, and do not constrain the network protocol in the routers in any way.
Mohamed G. Gouda, E. N. Elnozahy, Chin-Tser Huang, Tommy M. McGuire
ICNP3