VLDB 2026 Research / reviewers in the wild / expert
Ming Yang 0001
dblp:98/2604-1
· DBLP profile ↗
91ranked-venue papers
2as first author
46since 2021 · last 2026
0000-0002-8209-1000ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 35 · 22 since 2021Human-computer interaction and ubiquitous computing · 21 · 5 since 2021Security and privacy · 13 · 11 since 2021Systems, architecture and hardware · 12 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Your Outer Appearance Mirrors Your Inner Self: Exploiting Unobservable Node Internals to Deanonymize Uploaders in Freenet
Yonghuan Xu, Ming Yang 0001, Shan Wang 0008, Xiaodan Gu, Zixia Liu, Zhen Ling 0001 |
INFOCOM | 2 |
| 2026 | Detecting Rule Anomalies and Interference for Home Automation
Kai Dong 0001, Jianjie Zhou, Zhen Ling 0001, Ming Yang 0001, Xinwen Fu |
INFOCOM | 6 |
| 2026 | UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xuandong Chen, Xinhui Shao, Yier Jin, Ming Yang 0001, Junzhou Luo |
NDSS | 7 |
| 2026 | Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor Flood
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Shan Wang 0008, Ming Yang 0001, Guangchi Liu, Xinwen Fu |
SP | 6 |
| 2026 | A Tor-Based Anonymous Network Covert ChannelabstractNetwork Covert Channels (NCC) enhance covertness by concealing the existence of information transmission. However, traditional NCCs remain vulnerable to traffic analysis. Once NCC is detected, adversaries can breach anonymity by uncovering users' network identities and even communication relationships. While certain indirect NCCs offer limited anonymity to protect the identity of at most one party and the relationship, this level proves insufficient. This paper proposes ANCC, an innovative Anonymous Network Covert Channel that is the first to achieve comprehensive anonymity for the sender, the receiver and the communication relationship. By leveraging the Tor network's Hidden Service Directories (HSDirs) as intermediate nodes, Tor-based ANCC modulates covert information through the publication and retrieval statuses of hidden services distributed on multiple HSDirs. This mechanism allows ANCC traffic to blend seamlessly into legitimate Tor traffic, ensuring both robust covertness and high-level anonymity. Theoretical analysis demonstrates that even against a powerful adversary compromising fifty intermediate nodes, the detection probability remains below 0.25%, with the risk of identity or relationship exposure staying negligible (under 0.0021% and 0.00002% respectively). Additionally, the multiple HSDirs supporting parallel transmission enhance the channel capacity and error correction encoding strengthens the robustness. Extensive evaluation within the real-world Tor network demonstrates a transmission accuracy exceeding 99.6% and a channel capacity of around 3 Kbps, proving its effectiveness for practical applications. Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Changwei Cao, Shan Wang 0008, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Toward Secure and Efficient Driver Support for Embedded TEE SystemsabstractTrusted execution environments (TEEs), like TrustZone, are pervasively employed to protect security sensitive programs and data from various attacks issued by untrusted rich execution environments (REEs) while they execute compact TEE operating systems which implement minimum security-critical operations but have poor device driver support. In this paper, we propose a twin driver approach where a pair of TEE and REE drivers is generated and cooperate to enable secure and efficient TEE driver support. To begin with, we propose a driver data flow analysis framework named driver analyzer (DrvAna) to automatically analyze the shared states between the TEE and REE driver where a novel data structure named value-type tree is investigated to facilitate field-sensitive data flow analysis upon the driver state. Furthermore, in order to maintain a minimal trusted computing base, we propose a Linux driver runtime (LDR) inside the TEE, a sandbox environment that confines the TEE driver based on the ARM domain access control features and mediates the driver's interaction with the TEE. We implement a DrvAna prototype based on LLVM as well as an LDR prototype on an NXP IMX6Q SABRE-SD evaluation board, adapt 6 existing Linux drivers into LDR, and evaluate their performance. The experimental results show that the LDR drivers can achieve comparable performance with their Linux counterparts with negligible overheads. Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | PR-RFFI: Practical RF Fingerprint Injection Based Wi-Fi Device IdentificationabstractRecently, there has been an emerging radio frequency fingerprint identification (RFFI) technology that enhances fingerprint distinguishability by deliberately injecting an RF fingerprint into the device's Wi-Fi baseband signal. The current RF fingerprint injection methods are impractical, degrading the communication quality between Wi-Fi devices while offering limited improvements in distinguishability among a set of devices. To address these issues, we propose injecting I/Q imbalance into a short training field (STF) instead of the entire baseband signal. Our findings indicate that this method can effectively preserve the quality of the original wireless communication. Besides, a temperature-independent RF feature differential carrier frequency offset (DCFO) is proposed as an extended feature for the enhancement of fingerprint distinguishability. Building upon these, we introduce a fingerprinting scheme called PR-RFFI that generates distinguishable fingerprints for a set of devices by injecting appropriate I/Q imbalance and DCFO into the STF. Leveraging the short-term invariance of the channel, we design a practical I/Q imbalance extraction method based on the communication-quality preserving injection. Moreover, we design an optimal assignment method for I/Q imbalance and DCFO to maximize the distinguishability of RF fingerprints for all devices. Finally, we implement the PR-RFFI solution and conduct experiments in real-world and simulation scenarios. The experimental results demonstrate that PR-RFFI consistently maintains good communication quality, and achieves over 98% precision, recall, and F1-score. Xiaolin Gu, Wenjia Wu, Ming Yang 0001, Linqing Gui, Zhen Ling 0001, Fu Xiao 0001, Junzhou Luo |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | ODGMAC: On-Demand Grouping-Based MAC for Dense IoT NetworksabstractIn recent years, the Internet of Things (IoT) has rapidly advanced, with applications ranging from smart homes to industrial manufacturing, often involving densely deployed nodes such as temperature and humidity sensors. Since these nodes have limited computation and energy, the use of stuffed Wi-Fi management frames for data transmission has emerged as a promising way to avoid the association overhead of the traditional transmission mode. However, this unassociated data transmission mode continues to encounter significant channel contention in dense deployments. To this end, we propose ODGMAC, an on-demand grouping-based MAC solution that dynamically groups transmission-awaiting nodes and allocates time slots on a per-group basis, thereby enabling intra-group contention to improve transmission efficiency and reduce node energy consumption. Firstly, we present a fuzzy control-based algorithm at the access point (AP) to dynamically identify nodes with transmission demands in the current beacon period. On this basis, we then propose a hierarchical group-based time slot allocation methodology. Specifically, the nodes are initially clustered according to their per-packet airtime requirements. Within each cluster, we evenly partition nodes into multiple groups and assign each group to a unique time slot for channel contention, where the optimal slot count is determined by a renewal-theory-based analytical model with a discrete search over candidate counts. Finally, we implement the ODGMAC testbed with one AP and 100 IoT nodes, and conduct real-world experiments in a dense environment. The experimental results show that our solution outperforms existing methods in terms of both data delivery rate and node power consumption. Specifically, under severe channel collision conditions, our solution achieves an average increase of 14.77% in data delivery rate and an average reduction of 8.21% in node power consumption, while maintaining excellent fairness. Moreover, extended simulations show that our solution scales to 1000 nodes and maintains excellent performance under node mobility. Yusen Zhou, Wenjia Wu, Ming Yang 0001, Feng Shan, Junzhou Luo |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeabstractRemote Procedure Call (RPC) services have become a primary gateway for users to access public blockchains. While they offer significant convenience, RPC services also introduce critical privacy challenges that remain insufficiently examined. Existing deanonymization attacks either do not apply to blockchain RPC users or incur costs like transaction fees assuming an active network eavesdropper. In this paper, we propose a novel deanonymization attack that can link an IP address of a RPC user to this user's blockchain pseudonym. Our analysis reveals a temporal correlation between the timestamps of transaction confirmations recorded on the public ledger and those of TCP packets sent by the victim when querying transaction status. We assume a strong passive adversary with access to network infrastructure, capable of monitoring traffic at network border routers or Internet exchange points. By monitoring network traffic and analyzing public ledgers, the attacker can link the IP address of the TCP packet to the pseudonym of the transaction initiator by exploiting the temporal correlation. This deanonymization attack incurs zero transaction fee. We mathematically model and analyze the attack method, perform large-scale measurements of blockchain ledgers, and conduct real-world attacks to validate the attack. Our attack achieves a high success rate of over 95% against normal RPC users on various blockchain networks, including Ethereum, Bitcoin and Solana. Shan Wang 0008, Ming Yang 0001, Yu Liu 0168, Yue Zhang 0025, Shuaiqing Zhang, Zhen Ling 0001, Jiannong Cao 0001, Xinwen Fu |
CCS | 2 |
| 2025 | Distributed Private Aggregation in Graph Neural Networks
Huanhuan Jia, Yuanbo Zhao, Kai Dong 0001, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 5 |
| 2025 | Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionabstractThe Tor network, while offering anonymity through traffic routing across volunteer-operated nodes, remains vulnerable to attacks that aim to deanonymize users by correlating traffic patterns between colluded entry and exit nodes in circuits. This paper presents a novel approach for detecting anomalous circuits in the Tor network, and for the first time provides a more comprehensive identification of potential malicious accomplice nodes in Tor by taking roles of nodes in anomalous circuits into consideration. Our method strategically utilizes modified middle nodes to capture traffic data, followed by a novel circuit classification based on traffic patterns to pinpoint concerned circuits. Two kinds of anomalies are identified: routing anomalies and usage anomalies, that respectively represent the anomalies with explicit or implicit violation of Tor's circuit construction guidelines. This leads to a successful revealing of totally 1,960 anomalous nodes in Tor. Furthermore, we apply clustering analysis with considering corresponding anomalous circuits and other key characteristics to the detected anomalous nodes, revealing potential hidden organizations behind these nodes that can threaten the network's security. Our findings highlight the necessity for the Tor project to adopt targeted mitigation strategies to enhance overall network security and privacy. Yixuan Yao, Ming Yang 0001, Zixia Liu, Kai Dong 0001, Xiaodan Gu, Chunmian Wang |
WWW | 2 |
| 2024 | RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT DevicesabstractDue to the diversity of architectures and peripherals of Internet of Things (IoT) systems, blackbox fuzzing stands out as a prime option for discovering vulnerabilities of IoT devices. Existing blackbox fuzzing tools often rely on companion apps to generate valid fuzzing packets. However, existing methods encounter the challenges of bypassing the cloud server side validation when it comes to fuzz devices that rely on cloud-based communication. Moreover, they tend to concentrate their efforts on Java components within Android companion apps, limiting their effectiveness in assessing non-Java components such as JavaScript-based mini-apps. In this paper, we introduce a novel blackbox fuzzing method, named RIoTFuzzer, designed to remotely uncover vulnerabilities of IoT devices with the assistance of companion apps, particularly those powered by All-in-one Apps with the JavaScript-based mini-apps feature enabled. Our approach utilizes document-based control command extraction, hybrid analysis for mutation point identification and side-channel-guided fuzzing to effectively address the challenges of fuzzing IoT devices remotely. We apply RIoTFuzzer to 27 IoT devices on prominent platforms and discovered 11 vulnerabilities. All of them have been acknowledged by the corresponding vendors. 8 have been confirmed by the vendors and have been assigned 4 CVE IDs. Our experiment results also demonstrate that side-channel-guided fuzzing can significantly enhance the efficiency of fuzzing packets sent to IoT devices, with an average increase of 76.62% and a maximum increase of 362.62%. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Junzhou Luo, Xinwen Fu |
CCS | 2 |
| 2024 | CORE: Transaction Commit-Controlled Release of Private Data Over BlockchainsabstractIn blockchain applications such as digital goods exchange, private data may be transmitted from a data owner to a recipient through a transfer transaction. However, these blockchain applications often assume the underlying blockchain system is secure and reliable, and thus do not consider transaction failures. We find that a failed transfer transaction may disclose the private data to the recipient, but the data owner may not receive tokens as payments or the ledger may not correctly record the data trail. To handle transaction failures and protect private data, we propose a novel transaction commit-controlled release (CORE) protocol. With CORE, the private data can only be obtained by an intended recipient after the transfer transaction is committed, the data owner receives tokens, and the ledger correctly records the data trail. We perform security analysis of CORE, implement CORE and evaluate its performance over representative public and permissioned blockchains. The results of our extensive experiments show CORE introduces minor overhead in terms of transaction latency and transaction fees. We are the first to identify and address the generic private data disclosure issues in both public and permissioned blockchains. Shan Wang 0008, Ming Yang 0001, Jiannong Cao 0001, Zhen Ling 0001, Qiang Tang 0005, Xinwen Fu |
ICDCS | 2 |
| 2024 | Samba: Detecting SSL/TLS API Misuses in IoT Binary ApplicationsabstractIoT devices are increasingly adopting Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols. However, the misuse of SSL/TLS libraries still threatens the communication. Existing tools for detecting SSL/TLS API misuses primarily rely on source code analysis while IoT applications are usually released as binaries with no source code. This paper presents Samba, a novel tool to automatically detect SSL/TLS API misuses in IoT binaries through static analysis. To overcome the path explosion problem and deal with various SSL/TLS implementations, we introduce a three-level reduction method to construct the SSL/TLS API-centric graph (SAG), which has a much smaller size compared with the conventional inter-procedural control flow graph. We propose a formal expression of API misuse signatures, which is capable of capturing different types of misuse, particularly those in the SSL/TLS connection establishment process. We successfully analyze 115 IoT binaries and find that 94 of them have the vulnerability of insecure certificate verification and 112 support deprecated SSL/TLS protocols. Samba is the first IoT binary analysis system for detecting SSL/TLS API misuses. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Yuan Zhang 0009, Chongqing Lei, Xinwen Fu |
INFOCOM | 2 |
| 2024 | Deanonymizing Ethereum Users behind Third-Party RPC ServicesabstractThird-party RPC services have become the mainstream way for users to access Ethereum. In this paper, we present a novel deanonymization attack that can link an Ethereum address to a real-world identity such as IP address of a user who accesses Ethereum via a third-party RPC service. We find that RPC API calls result in distinguishable sizes of encrypted TCP packets. An attacker can then find when a user sends a transaction to an RPC provider and immediately send a beacon transaction after the user transaction. By exploiting the differences in the distributions of inter-arrival time intervals of normal transactions and two simultaneously initiated transactions, the attacker can identify the victim transaction in the Ethereum network. This enables the attacker to correlate the Ethereum address of the victim transaction’s initiator with the source IP address of TCP packets from a victim user. We model the attack through empirical measurements and conduct extensive real-world experiments to validate the effectiveness of our attack. With three optimization strategies, the correlation accuracy can reach to 98.70% and 96.60% respectively in Ethereum testnet and mainnet. We are the first to study the deanonymization of Ethereum users behind third-party RPC services. Shan Wang 0008, Ming Yang 0001, Wenxuan Dai, Yu Liu 0168, Yue Zhang 0025, Xinwen Fu |
INFOCOM | 2 |
| 2024 | A De-anonymization Attack against Downloaders in FreenetabstractFreenet is a well-known anonymous communication system that enables file sharing among users. It employs a probabilistic hops-to-live (HTL) decrement approach to hide the originator among nodes in a multi-hop path. Therefore, all nodes shall exhibit identical behaviors to preserve anonymity. However, we discover that the path folding mechanism in Freenet violates this principle due to behavior discrepancy between downloaders and intermediate nodes. The path folding mechanism is designed to optimize the network topology of Freenet. A delayed path folding message by a successor node may incur a timeout event at its predecessor, and an intermediate node reacts differently to such timeout with a downloader. Therefore, malicious nodes can deliberately trigger the timeout event to identify downloaders. The complex implementation of the path folding timeout detection mechanism in Freenet complicates our de-anonymization attack. We thoroughly analyze the underlying cause and develop three strategies to manipulate three types of messages respectively at the malicious node, minimizing the false positive rate. We conduct extensive real-world experiments to verify the feasibility and effectiveness of our attack. They show that our attack achieves a true positive rate of 100% and false positive rate of near 0% under two different Freenet download modes. Yonghuan Xu, Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Xiaodan Gu |
INFOCOM | 2 |
| 2024 | CQP-RFFI: Injecting a Communication-Quality Preserving RF Fingerprint for Wi-Fi Device IdentificationabstractRecently, there has been an emerging radio frequency fingerprint identification (RFFI) technology that enhances fingerprint distinguishability by deliberately injecting I/Q imbalance into the device’s Wi-Fi baseband signal. Due to the additional injection of I/Q imbalance, this approach inevitably impacts the communication quality between devices, as it reduces the accuracy of channel estimation. To address this issue, we propose injecting the I/Q imbalance into a short training field (STF) instead of the entire baseband signal. Our findings indicate that this method can effectively preserve the quality of the original wireless communication. Building upon this, we introduce a fingerprinting scheme called CQP-RFFI that generates distinguishable fingerprints for a set of devices by injecting appropriate I/Q imbalance into the STF. Leveraging the short-term invariance of the channel, we design a practical I/Q imbalance extraction method based on the communication-quality preserving injection. Moreover, we design an optimal assignment method for I/Q imbalance to maximize the distinguishability of RF fingerprints for all devices. Finally, we implement the CQP-RFFI solution and conduct experiments in real-world scenarios. The experimental results demonstrate that CQP-RFFI achieves 96% precision, recall, and F1-score, and can consistently maintain good communication quality. Xiaolin Gu, Wenjia Wu, Yusen Zhou, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
IWQoS | 5 |
| 2024 | LDR: Secure and Efficient Linux Driver Runtime for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Kai Dong 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
NDSS | 8 |
| 2024 | Relation Mining Under Local Differential Privacy
Kai Dong 0001, Chuang Jia, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 5 |
| 2024 | TEA-RFFI: Temperature adjusted radio frequency fingerprint-based smartphone identification
Xiaolin Gu, Wenjia Wu, Yusen Zhou, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
Comput. Networks | 5 |
| 2024 | AP-assisted adaptive video streaming in wireless networks with high-density clients
Wenjia Wu, Jiale Yuan, Sheng Ma, Ming Yang 0001 |
Comput. Commun. | 4 |
| 2024 | BBS: A secure and autonomous blockchain-based big-data sharing system
Shan Wang 0008, Ming Yang 0001, Shan Jiang 0005, Fei Chen 0003, Yue Zhang 0025, Xinwen Fu |
J. Syst. Archit. | 2 |
| 2024 | IdeNet: Making Neural Network Identify Camouflaged Objects Like CreaturesabstractCamouflaged objects often blend in with their surroundings, making the perception of a camouflaged object a more complex procedure. However, most neural-network-based methods that simulate the visual information processing pathway of creatures only roughly define the general process, which deficiently reproduces the process of identifying camouflaged objects. How to make modeled neural networks perceive camouflaged objects as effectively as creatures is a significant topic that deserves further consideration. After meticulous analysis of biological visual information processing, we propose an end-to-end prudent and comprehensive neural network, termed IdeNet, to model the critical information processing. Specifically, IdeNet divides the entire perception process into five stages: information collection, information augmentation, information filtering, information localization, and information correction and object identification. In addition, we design tailored visual information processing mechanisms for each stage, including the information augmentation module (IAM), the information filtering module (IFM), the information localization module (ILM), and the information correction module (ICM), to model the critical visual information processing and establish the inextricable association of biological behavior and visual information processing. The extensive experiments show that IdeNet outperforms state-of-the-art methods in all benchmarks, demonstrating the effectiveness of the five-stage partitioning of visual information processing pathway and the tailored visual information processing mechanisms for camouflaged object detection. Our code is publicly available at: https://github.com/whyandbecause/IdeNet. Juwei Guan, Xiaolin Fang 0001, Tongxin Zhu, Zhipeng Cai 0001, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo |
IEEE Trans. Image Process. | 6 |
| 2024 | RF-TESI: Radio Frequency Fingerprint-based Smartphone Identification under Temperature VariationabstractRadio frequency fingerprint identification (RFFI) is a promising technique for smartphone identification. However, we find that the temperature of the RF front end in smartphones can significantly impact the RF features, including the carrier frequency offset (CFO) and statistical RF features. The unstable RF features caused by temperature changes can negatively affect the performance of state-of-the-art RFFI approaches. To this end, we propose the RF-TESI solution for smartphone identification under temperature variation. First, we construct a dataset by extracting temperature and RF features. In the dataset, the extracted temperature values constitute a set of temperature values and each registered temperature value corresponds to a group of RF features. Next, we evaluate the distinctiveness of RF features across smartphones to select the most suitable RF fingerprint. Then, we train multiple random forest models, each tagged with a registered temperature. In addition, because there are still many temperatures out of the temperature set, we design an RF fingerprint estimation method to estimate RF fingerprints at unregistered temperatures. Finally, the experiments show RF-TESI demonstrates satisfactory performance under different scenarios, taking into account variations in temperature, time and position. Besides, our proposed approach is better than all state-of-the-art approaches in smartphone identification. Xiaolin Gu, Wenjia Wu, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
ACM Trans. Sens. Networks | 4 |
| 2023 | Evaluating the Distinguishability of Tor Traffic over Censorship Circumvention ToolsabstractPrevious research has shown that Tor traffic can be easily identified, making Tor connections frequently blocked. In order to access the Tor network successfully, some censorship circumvention tools such as Shadowsocks and OpenVPN are utilized as front-proxy to connect to Tor entry nodes. However, the distinguishability of Tor traffic over these censorship circumvention tools has not yet been fully evaluated. By analyzing the equal-size segmentation mechanism of Tor and the transmission mechanisms of circumvention tools, we find that the payload length distribution of Tor traffic encrypted and encapsulated through these tools displays a distinct pattern, which makes such Tor traffic retain distinguishable from regular encrypted traffic. To verify this finding, we develop an automated, large-scale Tor traffic collection system to capture Tor traffic forwarded by various circumvention tools, and then design corresponding algorithms to extract traffic features in terms of payload length distribution. Finally, we perform the evaluation on the distin-guishability between the captured Tor traffic and the normal non-Tor traffic through extracted features. The F1-Score can achieve 0.99 with the false positive rate close to 0 when using Support Vector Machines for training and classification. The experimental results prove that circumvention tools cannot mask the inherent features of Tor traffic, and thus the Tor traffic forwarded by these tools can still be clearly distinguished from normal non-Tor traffic. Yafeng Song, Ming Yang 0001, Xiaodan Gu, Yixuan Yao |
CSCWD | 2 |
| 2023 | Lightweight Gesture Based Trigger-Action Programming for Home Internet-of-ThingsabstractIFTTT is one of the most popular Trigger-Action Programming platforms. The rules generated in IFTTT are named IoT Applets. Despite the powerful programming interface provided by IFTTT, establishing an Applet requires technical skills and is not convenient enough for most users. To address this problem, we propose a gesture based programming method to help end users establish and manage IoT Applets in a convenient way. It requires employment of an RGB-D camera, and recognizes users’ pointing rays and hand actions. The obtained information is interpreted to certain devices and device events for Applet management. An experiment involving 20 participants validates the performance of our proposed method. Kai Dong 0001, Xiaodan Gu, Zhen Ling 0001, Ming Yang 0001 |
CSCWD | 5 |
| 2023 | TorDNS: A Novel Correlated Onion Address Generation Approach and ApplicationabstractThe onion service is the most important mechanism of the Tor network which enables service providers to publish anonymously various TCP services, such as web services. To access the target onion services, clients first know the 56-byte onion addresses. However, randomly generated onion addresses are difficult to memorize and can be easily used by attackers to generate phishing sites with similar onion addresses. In this paper, we propose a correlated onion address generation approach which is capable of generating a unique onion address via a customized string and a root onion address. This approach enables the generated onion addresses to be computed by clients using a human-memorable string, resulting in easier access to onion services. Based on this approach, we design and implement a Tor Domain Name System (TorDNS) that allows different service providers to register anonymously and clients to access anonymous services quickly through human-memorable pseudo-onion addresses. TorDNS is compatible with existing onion service mechanism and does not introduce additional privacy and security issues. In addition, similarity detection of pseudo-onion addresses can effectively reduce the risk of phishing sites on the Tor network. Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Xiaodan Gu, Yu Yao 0008 |
CSCWD | 4 |
| 2023 | Fast Robust Principle Component Analysis Using Gauss-Newton IterationsabstractRobust Principal Component Analysis (RPCA) is an optimization problem that decomposes a data matrix into a low-rank and a sparse matrix. However, solving this problem using alternating procedures requires sequentially computing singular value decompositions (SVDs) of large matrices, which is computationally expensive. In this work, we propose a computation protocol that leverages Gauss-Newton iterations to speed up the sequential computation of SVDs and accelerate the entire RPCA process. Our method is validated on synthetic and video data, benchmarked against established RPCA algorithms, and analyzed for stability with respect to hyperparameters. Our proposed protocol can also be applied to problems that require repeated computation of the proximal of functions that solely depend on singular values of the input matrix. William Chettleburgh, Zhishen Huang, Ming Yang 0001 |
ICASSP | 3 |
| 2023 | MASA: Measurement and Analysis of MAC Address Randomization with Sniffer ArrayabstractMAC address randomization is being adopted by an ever-increasing number of Wi-Fi-enabled devices, which aims to prevent users from being tracked by embedding random MAC addresses in probe request frames. Through measurement and analysis, researchers have found that its specific implementation mechanism differs for devices with different operating systems and obtained some analysis results. However, since the MAC address constantly changes, it is challenging to efficiently capture probe request frames of multiple target devices in an environment that typically has a large number of devices. Additionally, new devices are constantly emerging, making the results of previous analysis likely to be outdated. To address these issues, we propose a novel solution to measure and analyze Wi-Fi MAC address randomization with a sniffer array, called MASA. Firstly, we utilize a sniffer array to simultaneously capture probe request frames by multiple sniffers in the environment. Then, we propose a timeout bloom filter-based frame aggregation and processing method to aggregate the frames from the sniffer array, exclude frames of non-target devices, and split frames into their own set for the target device in real time. On this basis, we analyze the MAC address randomization mechanism in terms of address changing pattern, frame transmission frequency, and frame field/Information Element (IE) variation, considering devices’ association state, display status, and power-saving mode. Finally, we conduct corresponding experiments in real environments and make some new findings in the analysis. For example, all the latest iOS devices implement randomization strategies not only in the MAC address field but also in the Sequence Number field, while the MAC address randomization mechanism of some Android and HarmonyOS devices exhibits significantly different behaviors in the unassociated state and associated state. Yulian Pan, Wenjia Wu, Ming Yang 0001 |
MSN | 4 |
| 2023 | Sensor-based implicit authentication through learning user physiological and behavioral characteristics
Jinghui Zhang 0001, Hancheng Zhang, Zhen Ling 0001, Ming Yang 0001 |
Comput. Commun. | 6 |
| 2023 | Wi-Fi device identification based on multi-domain physical layer fingerprint
Jinghui Zhang 0001, Zhengjia Xu, Junhe Li, Qiangsheng Dai, Zhen Ling 0001, Ming Yang 0001 |
Comput. Commun. | 6 |
| 2023 | A practical multi-tab website fingerprinting attack
Xiaodan Gu, Ming Yang 0001, Bingchen Song, Zhen Ling 0001 |
J. Inf. Secur. Appl. | 2 |
| 2023 | Mobile applications identification using autoencoder based electromagnetic side channel analysis
Jinghui Zhang 0001, Boxi Liang, Hancheng Zhang, Zhen Ling 0001, Ming Yang 0001 |
J. Inf. Secur. Appl. | 6 |
| 2023 | Services Management and Distributed Multihop Requests Routing in Mobile Edge NetworksabstractMulti-access Edge Computing (MEC) is an emerging computing architecture to release the resource burden of the centralized cloud and reduce the mobile application latency. Services management and MEC requests routing is a major problem in MEC systems. Existing works mainly focus on the one-hop centralized request routing strategies. However, the centralized one-hop routing method is not suitable enough since the MEC network is a distributed system, and the number of MEC requests increases dramatically. In this paper, we have proposed an online problem. In such problem, we jointly consider the mobile edge service management and the distributed multi-hop requests routing in an MEC network in which the MEC requests randomly generate. We prove that such problem is NP-Hard even in the off-line scenario. Furthermore, we propose an approximation algorithm to manage the MEC services and two distributed online algorithms to route MEC requests. The approximation ratio and competitive ratio of these algorithms have been analyzed. Experiments are carried out to evaluate the performance of the algorithms and simulation results imply that these algorithms are effective and efficient. Zhipeng Cai 0001, Jianzhong Li 0001, Hong Gao 0001, Jiancheng Chen, Ming Yang 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2022 | BBS: A Blockchain Big-Data Sharing SystemabstractChain of custody is needed to document the sequence of custody of sensitive big data. In this paper, we design a blockchain big-data sharing system (BBS) based on Hyperledger Fabric. We denote the data stored outside of a ledger for sharing as "off-state" and "big data" (referring to extremely large data) is in this category. In our off-state sharing protocol, a sender registers a file with BBS for sharing. To acquire the file, an authenticated and authorized receiver has to use transactions and interacts with BBS in four phases, including the file transfer request, encrypted file transfer, key retrieval, and file decryption. The corresponding transactions are recorded in the ledger and serve as chain of custody to document the trail of the data. Compared with related work, BBS can perform the four phases autonomously. It utilizes the permissioned blockchain, i.e. Hyperledger Fabric, for access control and can defeat dishonest receivers. We design and implement a prototype of BBS for big file sharing. Extensive experiments were performed to validate its feasibility and performance. Shan Wang 0008, Ming Yang 0001, Tingjian Ge, Yan Luo 0001, Xinwen Fu |
ICC | 2 |
| 2022 | Towards an Efficient Defense against Deep Learning based Website FingerprintingabstractWebsite fingerprinting (WF) attacks allow an attacker to eavesdrop on the encrypted network traffic between a victim and an anonymous communication system so as to infer the real destination websites visited by a victim. Recently, the deep learning (DL) based WF attacks are proposed to extract high level features by DL algorithms to achieve better performance than that of the traditional WF attacks and defeat the existing defense techniques. To mitigate this issue, we propose a-genetic-programming-based variant cover traffic search technique to generate defense strategies for effectively injecting dummy Tor cells into the raw Tor traffic. We randomly perform mutation operations on labeled original traffic traces by injecting dummy Tor cells into the traces to derive variant cover traffic. A high level feature distance based fitness function is designed to improve the mutation rate to discover successful variant traffic traces that can fool the DL-based WF classifiers. Then the dummy Tor cell injection patterns in the successful variant traces are extracted as defense strategies that can be applied to the Tor traffic. Extensive experiments demonstrate that we can introduce 8.1% of bandwidth overhead to significantly decrease the accuracy rate below 0.4% in the realistic open-world setting. Zhen Ling 0001, Gui Xiao, Wenjia Wu, Xiaodan Gu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 5 |
| 2022 | Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryabstractTor is the largest anonymous communication system, providing anonymous communication services to approximately 2.8 million users and 170,000 hidden services per day. The Tor hidden service mechanism can protect a server from exposing its real identity during the communication. However, due to a design flaw of the Tor hidden service mechanism, adversaries can deploy malicious Tor hidden service directories (HSDirs) to covertly collect all onion addresses of hidden services and further probe the hidden services. To mitigate this issue, we design customized honeypot hidden services based on one-to-one and many-to-one HSDir monitoring approaches to luring and identifying the malicious HSDirs conducting the rapid and delayed probing attacks, respectively. By analyzing the probing behaviors and payloads, we investigate a novel semantic-based probing pattern clustering approach to classify the adversaries so as to shed light on the purposes of the malicious HSDirs. Moreover, we perform theoretical analysis of the capability and accuracy of our approaches. Large-scale experiments are conducted in the real-world Tor network by deploying hundreds of thousands of honeypots during a monitoring period of more than three months. Finally, we identify 8 groups of 32 malicious HSDirs, discover 25 probing pattern clusters and reveal 3 major probing purposes. Chunmian Wang, Zhen Ling 0001, Wenjia Wu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 5 |
| 2022 | TeRFF: Temperature-aware Radio Frequency Fingerprinting for SmartphonesabstractIn recent years, radio frequency (RF) fingerprinting has attracted more and more attention. Many different types of RF fingerprints have been proposed, such as carrier frequency offset (CFO), sampling frequency offset and error vector magnitude. Among them, the CFO fingerprint is recognized as a promising RF fingerprint. However, for commonly used smartphones, we find that its CFO fingerprint is unstable, because the temperature of crystal oscillator varies greatly and large fluctuations of temperature significantly affect its CFO fingerprint. Therefore, the solutions of CFO-based fingerprinting will no longer be effective for smartphones if the temperature of crystal oscillator is not involved. To this end, we propose a more reliable and applicable CFO-based fingerprinting approach called temperature-aware radio frequency fingerprinting (TeRFF). First, we construct a dataset by extracting crystal oscillator's temperature and the corresponding CFO value on multiple smartphones over a period. In the dataset, the extracted temperature values constitute a set of temperature values, and each registered temperature value corresponds to a group of CFO samples. On this basis, we train multiple Naive Bayes models, each tagged with a registered temperature value. Moreover, since there are many temperature values which are not in the temperature set, we design a CFO estimation method to estimate the CFO fingerprint at the unregistered temperature. Finally, the experimental results demonstrate that our proposed solution TeRFF makes the CFO fingerprinting still effective for smartphone identification, and its performance is better than other existing RF fingerprinting schemes. Xiaolin Gu, Wenjia Wu, Naixuan Guo, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
SECON | 6 |
| 2022 | Learning-aided client association control for high-density WLANs
Wenjia Wu, Jiazhi Yao, Xiaolin Fang 0001, Feng Shan, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
Comput. Networks | 6 |
| 2022 | MUTAA: An online trajectory optimization and task scheduling for UAV-aided edge computing
Weidu Ye, Junzhou Luo, Wenjia Wu, Feng Shan, Ming Yang 0001 |
Comput. Networks | 5 |
| 2022 | Small object detection in remote sensing images based on super-resolution
Xiaolin Fang 0001, Hu Fan, Ming Yang 0001, Tongxin Zhu, Ran Bi 0001, Zenghui Zhang |
Pattern Recognit. Lett. | 3 |
| 2022 | Correlation Aware Scheduling for Edge-Enabled Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) has attracted increasing attention for improving the efficiency of manufacturing. Plenty of computation-intensive and latency-sensitive applications are required by IIoT networks, which pose significant challenges for the computation capacities of IIoT networks. To address these challenges, Edge-enabled Industrial Internet of Things (E-IIoT) emerges. Edge devices located at the edge of IIoT networks enlarge computation capacities of IIoT networks and improve their efficiency accordingly. How to schedule computation resources wisely is a major problem in E-IIoT networks. Since IIoT devices in an E-IIoT network monitor the industrial site collaboratively, tasks for processing sensory data collected by them are correlated accordingly. That means, scheduling highly correlated tasks to be processed at the same device can improve computation efficiency. Inspired by this fact, we propose a correlation aware scheduling (CAS) algorithm for E-IIoT networks in this article. In specific, computation model decision and processing order decision are made by considering computation resources of devices and correlations among tasks in the algorithm to minimize latency of E-IIoT networks. The NP-hardness of correlation aware latency minimization scheduling problem in E-IIoT networks is first proved. Theoretical analysis on approximation ratio of the CAS algorithm is provided, and simulation results demonstrate the effectiveness of the proposed algorithm in reducing latency. Tongxin Zhu, Zhipeng Cai 0001, Xiaolin Fang 0001, Junzhou Luo, Ming Yang 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2021 | Preserving Privacy for Discrete Location InformationabstractWith the development of smart mobile devices, location privacy has gained attention from both academia and industry. In recent years, a variety of location privacy definitions from different perspectives have been proposed to quantify location privacy and compare location privacy protection mechanisms (LPPMs). These definitions, however, have some drawbacks. In this paper, we propose a location privacy metric for discrete location information which improves the quantification of distance between the prior and posterior distribution of an adversary who may hold background knowledge in differential privacy. Furthermore, we develop a non-convex optimization problem and construct a near-optimal mechanism. We evaluate our proposed metric by comparing it to the state-of-the-art definitions including Shokri's incorrectness, Andrés's geo-indistinguishability and Dong's DPLO. We also evaluate our proposed mechanism with the optimal mechanisms based on the afore mentioned existing definitions. We make experiments on both simulation and realworld dataset, and the results show that our proposed metric and mechanism have the ascendant position. Kai Dong 0001, Zhenyuan Tao, Xiangyu Xia, Zhouguo Chen, Ming Yang 0001 |
CSCWD | 5 |
| 2021 | 802.11ac Device Identification based on MAC Frame AnalysisabstractIn Wi-Fi networks, devices can be identified by physical features or MAC layer features, and the solutions of device identification can be used to enhance device authentication. Since 802.11ac Standard has been widely applied in Wi-Fi devices in recent years, the traditional identification methods designed for 802.11b/g/n devices will be no longer applicable. Therefore, it is necessary to design the corresponding 802.11ac device identification method. Compared with the physical feature-based method, the MAC layer-based method has advantages of low cost and easy deployment, so it has attracted more and more researchers' attention. In this paper, we use the fields from 802.11ac MAC frame as fingerprints. Through the analysis of 802.11ac MAC frame, a preprocessing method of the frame is proposed to mask strong and easy-to-modified identifiers. Then to overcome the difficulties caused by random changes in field values, we propose a device identification method based on the deep learning to select features automatically. Compared with the previous one using the transmitting rate as a feature, our method does not spend much time capturing packets in the device identification stage and has better performance whose average precision and recall exceed 99%. Xiaolin Gu, Wenjia Wu, Zhouguo Chen, Aibo Song, Zhen Ling 0001, Ming Yang 0001 |
CSCWD | 6 |
| 2021 | On Private Data Collection of Hyperledger FabricabstractHyperledger Fabric is a popular permissioned Blockchain framework for a consortium of organizations to develop Blockchain based applications and transact within the consortium. Hyperledger Fabric introduces a fine-grained access control mechanism called the private data collection (PDC), which allows private data to be shared by only a subset of participants. In this paper, we analyze PDC and show three classes of use cases in which misuse of Hyperledger Fabric features may endanger implemented Hyperledger Fabric systems. We present two groups of potential attacks including fake PDC results injection and PDC leakage against the misuse of the policy based consensus protocol. We use prototype systems to validate the discovered attacks. We also collected 6392 Hyprledger Fabric projects on GitHub and built a tool to statically analyse them. We find that 86.51% of the PDC related projects are potentially vulnerable to the fake PDC results injection attacks, and 91.67% have PDC leakage issues. We design new features for the Hyper-ledger Fabric framework to mitigate the attacks and show that the new features have minor impact on the system performance. Shan Wang 0008, Ming Yang 0001, Yue Zhang 0025, Yan Luo 0001, Tingjian Ge, Xinwen Fu, Wei Zhao 0001 |
ICDCS | 2 |
| 2021 | On Manually Reverse Engineering Communication Protocols of Linux-Based IoT SystemsabstractIoT security and privacy has raised grave concerns. Efforts have been made to design tools to identify and understand vulnerabilities of IoT systems. Most of the existing protocol security analysis techniques rely on a well understanding of the underlying communication protocols. In this article, we systematically present the first manual reverse engineering framework for discovering communication protocols of embedded Linux-based IoT systems. We have successfully applied our framework to reverse engineer a number of IoT systems. As an example, we present a detailed use of the framework reverse engineering the WeMo smart plug communication protocol by extracting the firmware from the flash, performing static and dynamic analysis of the firmware, and analyzing network traffic. The discovered protocol exposes severe design flaws that allow attackers to control or deny the service of victim plugs. Our manual reverse engineering framework is generic and can be applied to both read-only and writable embedded Linux filesystems. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Huaiyu Yan, Yue Zhang 0025, Xinwen Fu, Wei Zhao 0001 |
IEEE Internet Things J. | 2 |
| 2020 | Energy-efficient Trajectory Planning and Speed Scheduling for UAV-assisted Data CollectionabstractUnmanned aerial vehicle (UAV) assisted data collection is a promising technology, where a base station (BS) is mounted on a UAV to collect data from ground sensors (GSs). However, it is very challenging to save the energy of UAV while completing the tasks of data collection. In this work, a novel energy consumption model of UAV is adopted, where the UAV flies at a proper speed is the most energy efficient, i.e., the UAV will cost more energy when it flies faster or slower. According to this model, we investigate the Energy-efficient Trajectory Planning and Speed Scheduling (ETPSS) problem, aiming at minimizing the total energy consumption of UAV by determining flight trajectory and speed of UAV while completing the task of data collection for each GS. To solve this problem, we decompose it into two sub-problems, i.e., trajectory design and speed scheduling, and propose a three-step scheme named Energy-efficient Trajectory and Speed optimization (ETSO). Moreover, the second step of ETSO optimally solves the speed scheduling sub-problem. Finally, we conduct simulation experiments, and the results demonstrate that the ETSO performs well on energy efficiency. Weidu Ye, Wenjia Wu, Feng Shan, Ming Yang 0001, Junzhou Luo |
MSN | 4 |
| 2020 | Offspeeding: Optimal energy-efficient flight speed scheduling for UAV-assisted edge computing
Weidu Ye, Junzhou Luo, Feng Shan, Wenjia Wu, Ming Yang 0001 |
Comput. Networks | 5 |
| 2020 | Energy-efficient Link Scheduling in Time-variant Dual-Hop 60GHz Wireless NetworksabstractSummary Dual‐hop 60 GHz wireless networks which support relay‐assisted dual‐hop transmission have been widely adopted in the recent years, aiming to prolong communication distance and bypass obstacles in 60 GHz band. However, it is very challenging to perform link scheduling in such dual‐hop architecture while considering several factors, i.e., reducing network power consumption, avoiding overloaded APs/relays and adapting to network dynamics. To this end, we investigate the problem of energy‐efficient link scheduling with load constraints (ELL), and propose solutions to deal with network dynamics. First, we present a fine‐grained energy model for dual‐hop 60 GHz networks, and formulate the ELL problem as an integer linear programming model that aims to minimize the network power consumption, while satisfying AP/relay load constraints. Then, we propose a polynomial‐time global scheduling algorithm that obtains a near‐optimal link scheduling solution via iterative relaxation, and the load constraint at each AP/relay can only be violated by at most an additive constant of two. Moreover, we present a local adjustment algorithm to adjust link‐scheduling solutions efficiently, such as client arrival/departure and link blockage, and design a hybrid algorithm that combines global scheduling and local adjustment. Finally, we conduct simulation experiments that validate our algorithms' effectiveness and efficiency. Wenjia Wu, Zhouguo Chen, Ming Yang 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2020 | FingerAuth: 3D magnetic finger motion pattern based implicit authentication for mobile devices
Ming Yang 0001, Zhen Ling 0001, Yaowen Liu, Wenjia Wu |
Future Gener. Comput. Syst. | 2 |
| 2020 | A Novel IM Sync Message-Based Cross-Device TrackingabstractCybercrime is significantly growing as the development of internet technology. To mitigate this issue, the law enforcement adopts network surveillance technology to track a suspect and derive the online profile. However, the traditional network surveillance using the single-device tracking method can only acquire part of a suspect’s online activities. With the emergence of different types of devices (e.g., personal computers, mobile phones, and smart wearable devices) in the mobile edge computing (MEC) environment, one suspect can employ multiple devices to launch a cybercrime. In this paper, we investigate a novel cross-device tracking approach which is able to correlate one suspect’s different devices so as to help the law enforcement monitor a suspect’s online activities more comprehensively. Our approach is based on the network traffic analysis of instant messaging (IM) applications, which are typical commercial service providers (CSPs) in the MEC environment. We notice a new habit of using IM applications, that is, one individual logs in the same account on multiple devices. This habit brings about devices’ receiving sync messages, which can be utilized to correlate devices. We choose five popular apps (i.e., WhatsApp, Facebook Messenger, WeChat, QQ, and Skype) to prove our approach’s effectiveness. The experimental results show that our approach can identify IM messages with high F1 -scores (e.g., QQ’s PC message is 0.966, and QQ’s phone message is 0.924) and achieve an average correlating accuracy of 89.58% of five apps in an 8-people experiment, with the fastest correlation speed achieved in 100 s. Naixuan Guo, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Wenjia Wu, Xiaodan Gu |
Secur. Commun. Networks | 4 |
| 2019 | Data Anonymization Based on Natural Equivalent ClassabstractData anonymization is widely used to preserve the utility of published datasets without compromising privacy. The state-of-the-art data anonymization approaches are mainly single-record-based algorithms. They group similar records together one by one, then form equivalence classes through generalization. However, these algorithms didn't utilize equivalence classes which exist in the raw dataset. In this paper, we propose a new concept named natural equivalent class. It refers to the record set with the same quasi-identifier values naturally existing in the raw dataset. We theoretically prove that the natural equivalent class can effectively reduce the computational complexity of clustering algorithms as well as information loss. Then, we propose a novel clustering-based anonymization algorithm, which tries to cluster records without separating any natural equivalent class. Extensive experiments on real world datasets show that our approach outperforms the previous clustering-based anonymization algorithms in terms of efficiency and data utility. Naixuan Guo, Ming Yang 0001, Qiyuan Gong, Zhouguo Chen, Junzhou Luo |
CSCWD | 2 |
| 2019 | Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous NetworksabstractDiverse anonymous communication systems are widely deployed as they can provide the online privacy protection and Internet anti-censorship service. However, these systems are severely abused and a large amount of anonymous traffic is malicious. To mitigate this issue, we propose a novel and practical traceback technique to confirm the communication relationship between the suspicious server and the user. We leverage the software-defined network (SDN) switch at a destination server side to intercept target traffic towards the server and alter the advertised TCP window sizes so as to stealthily vary the traffic rate at the server. By carefully varying the traffic rate, we can successfully modulate a secret signal into the traffic. The traffic carrying the signal passes through the anonymous communication system and reaches the SDN switch at the user side. Then we can detect the modulated signal from the traffic so as to confirm the communication relationship between the server and the user. To validate the feasibility and effectiveness of our technique, extensive real-world experiments are performed using three popular anonymous communication systems, i.e., SSH tunnel, OpenVPN tunnel, and Tor. The results demonstrate that the detection rates approach 100% for SSH and Open VPN and 95% for Tor while the false positive rates are significantly low, approaching 0% for these three systems. Zhen Ling 0001, Junzhou Luo, Danni Xu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 4 |
| 2019 | ACAC: An Airtime-Aware Centralized Association Control System in 802.11ac WLANsabstractIn recent years, 802.11ac wireless local area networks (WLANs) have been popular in campus and enterprise environments, and a large number of access points (APs) are densely deployed to meet the rapidly increasing clients' demand. In such networks, it is challenging to promote the performance of AP-client association since numerous clients need to find their respective optimal APs under the conditions of multiple capability-limited APs and a small number of available channels. Thus, the conventional association mechanism that only utilizes local information on the client side, such as received signal strength indicator (RSSI), may lead to poor network performance. In this context, we propose and implement an airtime-aware centralized association control system that deals with client requests in a centralized manner and makes AP-client association decisions according to the global information, that is, AP airtime utilization and client requests' RSSI. In particular, we design an AP airtime measurement method to obtain AP airtime utilization from the ath10k driver, and present an airtime-aware AP selection algorithm to implement AP selection policy. Furthermore, we develop an experimental testbed, and conduct the experiments to evaluate the performance of our system. The results demonstrate that our system can significantly improve network throughput and effectively guarantee clients' fairness. Jiazhi Yao, Wenjia Wu, Ming Yang 0001, Junzhou Luo |
MSN | 3 |
| 2019 | Locally differentially private item-based collaborative filtering
Taolin Guo, Junzhou Luo, Kai Dong 0001, Ming Yang 0001 |
Inf. Sci. | 4 |
| 2019 | Your clicks reveal your secrets: a novel user-device linking method through network and visual data
Naixuan Guo, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Wenjia Wu, Xinwen Fu |
Multim. Tools Appl. | 4 |
| 2018 | Estimating the Number of Posts in Microblogging ServicesabstractAnalyzing the popularity of microblogging services is of great significance in various applications. The number of posts provides novel insights into the popularity of microblogging services, and is critical to learn about the frequency of use. Existing approaches analyze this parameter by observing posts published by a large number of users, which may lead to underestimate the value since the sampled user may stop to use the service during the observing process. In this paper, we propose a novel method to estimate the number of posts in microblogging services. The basic idea behind this method is to make use of a common API provided by microblogging services, i.e., the public_timeline API. Posts sampled by this API may duplicate among multiple invocations, so the capture-recapture model can be used to estimate the total number of posts. Based on the traditional capture-recapture model, we propose an improved model to address challenges on low sampling probability and unequal sampling probability. We validate the proposed method using a real life Sina Weibo dataset, and the experimental results demonstrate the effectiveness and accuracy of our proposed method. Taolin Guo, Junzhou Luo, Kai Dong 0001, Zhouguo Chen, Yubin Guo, Ming Yang 0001 |
CSCWD | 6 |
| 2018 | SecTap: Secure Back of Device Input System for Mobile DevicesabstractSmart mobile devices have become an integral part of people's life and users often input sensitive information on these devices. However, various side channel attacks against mobile devices pose a plethora of serious threats against user security and privacy. To mitigate these attacks, we present a novel secure Back-of-Device (BoD) input system, SecTap, for mobile devices. To use SecTap, a user tilts her mobile device to move a cursor on the keyboard and tap the back of the device to secretly input data. We design a tap detection method by processing the stream of accelerometer readings to identify the user's taps in real time. The orientation sensor of the mobile device is used to control the direction and the speed of cursor movement. We also propose an obfuscation technique to randomly and effectively accelerate the cursor movement. This technique not only preserves the input performance but also keeps the adversary from inferring the tapped keys. Extensive empirical experiments were conducted on different smart phones to demonstrate the usability and security on both Android and iOS platforms. Zhen Ling 0001, Junzhou Luo, Yaowen Liu, Ming Yang 0001, Kui Wu 0001, Xinwen Fu |
INFOCOM | 4 |
| 2018 | Differentially private graph-link analysis based social recommendation
Taolin Guo, Junzhou Luo, Kai Dong 0001, Ming Yang 0001 |
Inf. Sci. | 4 |
| 2018 | Fingerprinting Network Entities Based on Traffic Analysis in High-Speed Network EnvironmentabstractFor intrusion detection, it is increasingly important to detect the suspicious entities and potential threats. In this paper, we introduce the identification technologies of network entities to detect the potential intruders. However, traditional entities identification technologies based on the MAC address, IP address, or other explicit identifiers can be deactivated if the identifier is hidden or tampered. Meanwhile, the existing fingerprinting technology is also restricted by its limited performance and excessive time lapse. In order to realize entities identification in high-speed network environment, PFQ kernel module and Storm are used for high-speed packet capture and online traffic analysis, respectively. On this basis, a novel device fingerprinting technology based on runtime environment analysis is proposed, which employs logistic regression to implement online identification with a sliding window mechanism, reaching a recognition accuracy of 77.03% over a 60-minute period. In order to realize cross-device user identification, Web access records, domain names in DNS responses, and HTTP User-Agent information are extracted to constitute user behavioral fingerprints for online identification with Multinomial Naive Bayes model. When the minimum effective feature dimension is set to 9, it takes only 5 minutes to reach an accuracy of 79.51%. Performance test results show that the proposed methods can support over 10Gbps traffic capture and online analysis, and the system architecture is justified in practice because of its practicability and extensibility. Xiaodan Gu, Ming Yang 0001, Peilong Pan, Zhen Ling 0001 |
Secur. Commun. Networks | 2 |
| 2018 | Energy-Efficient User Association with Congestion Avoidance and Migration Constraint in Green WLANsabstractGreen wireless local area networks (WLANs) have captured the interests of academia and industry recently, because they save energy by scheduling an access point (AP) on/off according to traffic demands. However, it is very challenging to determine user association in a green WLAN while simultaneously considering several other factors, such as avoiding AP congestion and user migration constraints. Here, we study the energy‐efficient user association with congestion avoidance and migration constraint (EACM). First, we formulate the EACM problem as an integer linear programming (ILP) model, to minimize APs’ overall energy consumption within a time interval while satisfying the following constraints: traffic demand, AP utilization threshold, and maximum number of demand node (DN) migrations allowed. Then, we propose an efficient migration‐constrained user reassociation algorithm, consisting of two steps. The first step removeskAP‐DN associations to eliminate AP congestion and turn off as many idle APs as possible. The second step reassociates thesekDNs according to an energy efficiency strategy. Finally, we perform simulation experiments that validate our algorithm’s effectiveness and efficiency. Wenjia Wu, Junzhou Luo, Kai Dong 0001, Ming Yang 0001, Zhen Ling 0001 |
Wirel. Commun. Mob. Comput. | 4 |
| 2017 | Joint AP coverage adjustment and user association optimization for load balancing in multi-rate WLANsabstractWe investigate the problem of joint AP coverage adjustment and user association optimization for load balancing in multi-rate WLANs in this paper. We first divide the problem into two sub-problems and then formulate them as mixed integer linear programming models, which aim to minimize the AP utilization of the most congested AP while satisfying users' traffic demands. Then we design two corresponding heuristic algorithms that are performed in sequence to address the problem. Finally, we conduct extensive simulations to evaluate the performance of the proposed algorithms. The results not only show that the algorithms can balance the loads among APs effectively and efficiently, but also demonstrate that the solutions of joint AP coverage adjustment and user association optimization outperform that of AP coverage adjustment with low overhead. Junzhou Luo, Wenjia Wu, Ming Yang 0001 |
CSCWD | 4 |
| 2017 | Implicit authentication for mobile device based on 3D magnetic finger motion patternabstractTouch pattern based implicit authentication has been proposed to defend against diverse attacks against mobile devices that aim to obtain credentials, e.g., passwords, in the process of user authentication. However, this defense technique cannot obtain a complete user operation pattern by merely deriving user operation data via a touch-enabled screen, since user operations, including on-screen and in-air finger movements, are performed in a three-dimensional space. In this paper, we propose a novel three-dimensional magnetic finger motion pattern based implicit authentication technique, referred to as FingerAuth. To use FingerAuth, a user first wears a magnetic ring on her finger and uses this finger to operate her mobile device, e.g., typing messages and surfing websites. By using a built-in three-axis magnetometer on the mobile device, we can derive the three-dimension (3D) magnetic finger motion pattern that is used as a human behavioral feature to implicitly authenticate the user. We construct robust 3D magnetic finger motion pattern detection model using machine learning techniques. Real-world experiments were conducted to demonstrate that our approach achieves high accuracy of 96.38% as well as low false acceptance rate of 4.06% and low false rejection rate of 3.18%. Yaowen Liu, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
CSCWD | 2 |
| 2017 | A novel attack to track users based on the behavior patternsabstractSummary Currently, people around the world daily use the Internet to access various services, such as e‐mail and online shopping. However, the behavior‐based tracking attacks have posed a considerable threat to users' privacy. Relying on characteristic patterns within the Internet activities, this attack can link a user's multiple sessions. In this paper, we investigate the behavior‐based tracking attack and propose some countermeasures to mitigate the threat. We preprocess the raw traffic data and then extract features ranging from lower layer network packets to high‐level application‐related traffic. Specifically, we focus on four types of application‐level traffic to infer users' habits, including HTTP, IM, e‐mail, and P2P. In addition, we extract the web queries entered into shopping websites and classify them to infer users' preferences. Then, we construct the preference models and propose an improved method. For evaluation, we collect traffic in the real‐world environment to construct a large‐scale dataset. Five hundred and nine users are selected in terms of the user's active degree. When the term frequency–inverse document frequency transformation is used, the improved method can identify an average of 93.79% instances correctly. Our extensive empirical experiments demonstrate the effectiveness and efficiency of our approaches. Finally, we discuss and evaluate several countermeasures. Copyright © 2016 John Wiley & Sons, Ltd. Xiaodan Gu, Ming Yang 0001, Congcong Shi, Zhen Ling 0001, Junzhou Luo |
Concurr. Comput. Pract. Exp. | 2 |
| 2017 | Detection of malicious behavior in android apps through API calls and permission uses analysisabstractSummary In recent years, with the prevalence of smartphones, the number of Android malware shows explosive growth. As malicious apps may steal users' sensitive data and even money from mobile and bank accounts, it is important to detect potential malicious behaviors so as to block them. To achieve this goal, we propose a dynamic behavior inspection and analysis framework for malicious behavior detection. A customized Android system is built to record apps' API calls, permission uses, and some other runtime features. We also develop an automated app behavior inspection platform to install and inspect massive samples so as to collect apps' dynamic behavior records. Then these records are exploited to train a string subsequence kernel–based Support Vector Machine (SVM) model, which can be used to classify benign and malicious behaviors offline. To realize online detection, we further extract apps' runtime features including sensitive permission combination uses, sensitive behavior sequences, and user interactions for behavior classification. The classification results can reach an accuracy of 84.9% in offline phase and 99.0% in online phase. Besides, we verify our scheme for identifying malicious apps, and the results show that 71.8% instances of malware samples are identified by running each app for only 18 minutes. Ming Yang 0001, Shan Wang 0008, Zhen Ling 0001, Yaowen Liu, Zhenyu Ni |
Concurr. Comput. Pract. Exp. | 1 |
| 2017 | Anonymizing 1: M microdata with high utility
Qiyuan Gong, Junzhou Luo, Ming Yang 0001, Weiwei Ni |
Knowl. Based Syst. | 3 |
| 2017 | Dealing with Insufficient Location Fingerprints in Wi-Fi Based Indoor Location FingerprintingabstractThe development of the Internet of Things has accelerated research in the indoor location fingerprinting technique, which provides value-added localization services for existing WLAN infrastructures without the need for any specialized hardware. The deployment of a fingerprinting based localization system requires an extremely large amount of measurements on received signal strength information to generate a location fingerprint database. Nonetheless, this requirement can rarely be satisfied in most indoor environments. In this paper, we target one but common situation when the collected measurements on received signal strength information are insufficient, and show limitations of existing location fingerprinting methods in dealing with inadequate location fingerprints. We also introduce a novel method to reduce noise in measuring the received signal strength based on the maximum likelihood estimation, and compute locations from inadequate location fingerprints by using the stochastic gradient descent algorithm. Our experiment results show that our proposed method can achieve better localization performance even when only a small quantity of RSS measurements is available. Especially when the number of observations at each location is small, our proposed method has evident superiority in localization accuracy. Kai Dong 0001, Zhen Ling 0001, Xiangyu Xia, Haibo Ye, Wenjia Wu, Ming Yang 0001 |
Wirel. Commun. Mob. Comput. | 6 |
| 2016 | Utility enhanced anonymization for incomplete microdataabstractAlthough a variety of anonymization approaches have been proposed to achieve anonymity during data sharing, few of them can handle incomplete microdata, i.e. microdata with missing values. Directly applying existing approaches to incomplete microdata will incur extensive information loss, due to the existence of missing values. In this paper, we formulate this problem as missing value pollution, and analysis its influences on generalization based algorithms. Then we propose two top-down algorithms named Enhanced Mondrian and Semi-Partition, which achieve high data utility on incomplete microdata. Extensive experiments on real-world data show the effectiveness of our approach. Qiyuan Gong, Ming Yang 0001, Zhouguo Chen, Junzhou Luo |
CSCWD | 2 |
| 2016 | Secure fingertip mouse for mobile devicesabstractVarious attacks may disclose sensitive information such as passwords of mobile devices. Residue-based attacks exploit oily or heat residues on the touch screen, computer vision based attacks analyze the hand movement on a keyboard, and sensor based attacks measure a device's motion difference via motion sensors as different keys are tapped. A randomized soft keyboard may defeat these attacks. However, a randomized key layout is counter-intuitive and users may be reluctant to adopt it. In this paper, we introduce a novel and intuitive input system, secure finger mouse, which uses a mobile device's camera sensing the fingertip movement, moves an on-screen cursor and performs clicks by sensing click gestures. We design a randomized mouse acceleration algorithm so that the adversary cannot infer keys clicked on the soft keyboard by observing the finger movement. The secure finger mouse can defeat attacks including residue, computer vision and motion based attacks too. We perform both theoretical analysis and real-world experiments to demonstrate the security and usability of the secure fingertip mouse. Zhen Ling 0001, Junzhou Luo, Qinggang Yue, Ming Yang 0001, Wei Yu 0002, Xinwen Fu |
INFOCOM | 5 |
| 2016 | A fine-grained permission control mechanism for external storage of AndroidabstractAndroid lacks fine-grained permission control for the external storage. Under the current coarse-grained mechanism, any application is able to access all the data on the external storage very easily. At the same time, many applications store sensitive data into the external storage, and some of these data are highly concerned with user privacy, which could bring severe security problems. In this paper, we propose a fine-grained permission control mechanism for external storage of Android. The mechanism is based on Filesystem in Userspace (FUSE) and offers the following features: protecting user private media files such as photos and videos; isolating the data of each application; providing access control settings for user. We implement this mechanism on the latest Android version, by introducing a new type of GID (ESDS-GID), extending the functionality of the emulated filesystem as well as the system services. The results of functional verification and performance benchmark show that with a reasonable performance overhead, this mechanism brings considerable enhancement for Android system security. Feiqiao Huang, Wenjia Wu, Ming Yang 0001, Junzhou Luo |
SMC | 3 |
| 2015 | A novel Website Fingerprinting attack against multi-tab browsing behaviorabstractWebsite Fingerprinting (WF) attacks have posed a serious threat to users' privacy, which allow an adversary to infer the anonymous communication content by using traffic analysis. Recent studies have demonstrated the effectiveness of WF attacks through a large number of experiments. However, some researchers believe that the assumptions of WF attacks vastly simplify the problem and are critical in the practical scenarios. In this paper, we assess the threat model of WF and relax the assumptions about browsing behavior to improve the practical feasibility. To deal with the multi-tab browsing scenario, we propose a novel WF attack and identify webpages respectively. The main idea resides in the fact that the user visits the second page with a short delay after opening the first page due to the think time. We analyze the anonymous traffic transmitted in the delay and select fine-grained features to identify the first page. Furthermore, we exclude the first page's traffic and utilize coarse features to identify the second page. We deploy our attack in real word environment and the experiment lasts for two months. The Naive Bayes classifier is then applied on the collected datasets to classify the visited websites among 50 top ranked websites in Alexa. When the delay is set to 2 seconds, our attack can classify the first page with 75.9% accuracy, and the second page is 40.5%. The results show that the WF attack is still effective in the practical scenarios and we can't dismiss WF as a threat. Xiaodan Gu, Ming Yang 0001, Junzhou Luo |
CSCWD | 2 |
| 2015 | Joint Node Scheduling and Radio Switching for Energy Efficiency in Multi-radio WLAN Mesh NetworksabstractMulti-radio WLAN mesh networks (WMNs) are intended to provide a wireless access infrastructure with high throughput and reliable transmission. With the increasing demand for ubiquitous Internet access, access networks tend to be large-scale, complex and dense, and energy consumption has become a critical concern. Since the networks are designed to support peak traffic demand but does not serve peak traffic demand all the time, which leads to significant energy wastage in off-peak conditions. This means that energy consumption can be effectively reduced through scheduling nodes on/off according to the current traffic demand. In multi-radio WMNs, each node is equipped with multiple radios, and radios can also be switched on/off for further energy saving. Therefore, we investigate the problem of joint node scheduling and radio switching for energy efficiency in this paper, which is proven to be NP-hard. We first formulate the problem as an integer linear programming model, which aims to minimize the power consumption of the network while satisfying node-radio-link, traffic demand and routing constraints. Then, we propose an efficient heuristic algorithm, which iteratively finds routing paths for all mesh access points (MAPs) while satisfying their traffic demand. In each iteration, exact one MAP is selected, and the nodes on its routing path are scheduled on and the corresponding radios are switched on. Finally, extensive simulations are conducted to evaluate the performance of the proposed algorithm in terms of the number of active nodes and radios. The results not only show that the algorithm can achieve energy saving efficiently and effectively, but also demonstrate that the joint optimization of node scheduling and radio switching can obtain better performance on energy efficiency. Wenjia Wu, Junzhou Luo, Ming Yang 0001, Xiaolin Fang 0001 |
MSN | 3 |
| 2015 | Energy Efficient Channel Assignment with Switching Optimization in Multi-radio Wireless NetworksabstractIn multi-radio wireless networks, it is vital to efficiently utilize the resource of non-overlapping channels, and thus the problem of channel assignment has been widely studied. Most proposed channel assignment approaches focus on reducing interference or maximizing throughput, assuming that all the radios on each node are keeping active. However, it is a significant waste of energy when network traffic is low, since the network is designed for peak traffic demands but does not serve peak traffic demands all the time. Even if the number of active radios is dynamically adaptive to time-varying network traffic, some radios will inevitably switch their channels, which significantly increase network delay. Therefore, we investigate the energy efficient channel assignment problem with switching optimization in this paper. To address this problem, we first define the optimization objective to minimize the number of active radios and channel switchings, and then propose several constraints, such as channel switching, radio amount, transmission existence, link rate, link interference, traffic demand and routing constraints. On this basis, we present an MILP model called EECA-SO, and evaluate its performance through numerical analysis. The results show that the proposed EECA-SO model can not only achieve energy saving effectively, but also obtain the trade off between energy efficiency and switching optimization. Wenjia Wu, Junzhou Luo, Ming Yang 0001 |
SMC | 3 |
| 2015 | A novel application classification attack against TorabstractSummary Tor is a famous anonymous communication system for preserving users' online privacy. It supports TCP applications and packs upper‐layer application data into encrypted equal‐sized cells with onion routing to hide private information of users. However, we note that the current Tor design cannot conceal certain application behaviors. For example, P2P applications usually upload and download files simultaneously, and this behavioral feature is also kept in Tor traffic. Motivated by this observation, we investigate a new attack against Tor, application classification attack, which can recognize application types from Tor traffic. An attacker first carefully selects some flow features such asburst volumesanddirectionsto represent the application behaviors and takes advantage of some efficient machine‐learning algorithm (e.g., Profile Hidden Markov Model) to model different types of applications. Then he or she can use these established models to classify target's Tor traffic and infer its application type. We have implemented the application classification attack on Tor using parallel computing, and our experiments validate the feasibility and effectiveness of the attack. We argue that the disclosure of application type information is a serious threat to Tor users' anonymity because it can be used to reduce the anonymity set and facilitate other attacks. We also present guidelines to defend against application classification attack. Copyright © 2015 John Wiley & Sons, Ltd. Gaofeng He, Ming Yang 0001, Junzhou Luo, Xiaodan Gu |
Concurr. Comput. Pract. Exp. | 2 |
| 2015 | Tor Bridge Discovery: Extensive Analysis and Large-scale Empirical EvaluationabstractTor is a well-known low-latency anonymous communication system that is able to bypass the Internet censorship. However, publicly announced Tor routers are being blocked by various parties. To counter the censorship blocking, Tor introduced non-public bridges as the first-hop relay into its core network. In this paper, we investigated the effectiveness of two categories of bridge-discovery approaches: 1) enumerating bridges from bridge HTTPS and email servers, and 2) inferring bridges by malicious Tor middle routers. Large-scale real-world experiments were conducted and validated our theoretic findings. We discovered 2365 Tor bridges through the two enumeration approaches and 2369 bridges by only one Tor middle router in 14 days. Our study shows that the bridge discovery based on malicious middle routers is simple, efficient, and effective to discover bridges with little overhead. We also discussed issues related to bridge discovery and mechanisms to counter the malicious bridge discovery. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Ming Yang 0001, Xinwen Fu |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2014 | A novel active website fingerprinting attack against Tor anonymous systemabstractTor is a popular anonymizing network and the existing work shows that it can preserve users' privacy from website fingerprinting attacks well. However, based on our extensive analysis, we find it is the overlap of web objects in returned web pages that make the traffic features obfuscated, thus degrading the attack detection rate. In this paper, we propose a novel active website fingerprinting attack under Tor's local adversary model. The main idea resides in the fact that the attacker can delay HTTP requests originated from users for a certain period to isolate responding traffic segments containing different web objects. We deployed our attack in PlanetLab and the experiment lasted for one month. The SVM multi-classification algorithm was then applied on the collected datasets with the introduced features to identify the visited website among 100 top ranked websites in Alexa. Compared to the stat-of-the-art work, the classification result is improved from 48.5% to 65% by delaying at most 10 requests. We also analyzed the timing characteristics of Tor traffic to prove the stealth of our attack. The research results show that anonymity in Tor is not as strong as expected and should be enhanced in the future. Gaofeng He, Ming Yang 0001, Xiaodan Gu, Junzhou Luo |
CSCWD | 2 |
| 2013 | Max-Cut based overlapping channel assignment for 802.11 multi-radio wireless mesh networksabstractDue to the limited number of orthogonal channels in a multi-radio multi-channel wireless mesh network (MR-WMN), overlapping channel assignment (CA) is one of the main factors that greatly affect the network capacity. In this paper, we first propose a model for measuring achieved network capacity in MR-WMNs. Then we prove that finding an optimal overlapping CA in a given MR-WMN with odd number of channels, is equivalent to finding an optimal assignment by only using its orthogonal channels. This theory allows us to use fewer channels to solve complicated CA problems. Third, we prove that in 802.11b/g-based MR-WMN, the simplified optimization problem is a Max-3-Cut problem. Although this problem is NP-hard, it has an efficient approximation algorithm that achieves approximation ratio of 1.19616 probabilistically by using the algorithm for Max-Cut whose approximation ratio is 1.1383 probabilistically. Based on the algorithm for Max-Cut, this paper proposes Max-Cut-based channel assignment (MCCA) which uses a heuristic method to adjust the result produced by the Max-Cut algorithm to achieve an even better result. Finally, we perform extensive simulations to compare the MCCA with a state-of-the-art Tabu-Search based algorithm. The results show that the Max-Cut-based overlapping CA algorithm effectively improves on the network capacity. Wei Wang 0089, Bo Liu 0004, Ming Yang 0001, Junzhou Luo, Xiaojun Shen 0002 |
CSCWD | 3 |
| 2013 | A novel sequential watermark detection model for efficient traceback of secret network attack flows
Xiaogang Wang 0012, Ming Yang 0001, Junzhou Luo |
J. Netw. Comput. Appl. | 2 |
| 2013 | How to block Tor's hidden bridges: detecting methods and countermeasures
Ming Yang 0001, Junzhou Luo, Lu Zhang 0030, Xiaogang Wang 0012, Xinwen Fu |
J. Supercomput. | 1 |
| 2012 | An efficient sequential watermark detection model for tracing network attack flowsabstractWatermarking schemes for tracing network attack flows have been proposed to detect stepping-stone intrusion and fight against the abuse of anonymity. However, most existing network flow watermark detection techniques focus on fixed sample size of network data, thus resulting in not only unguaranteed rates of detection errors but also low efficiency of watermark detection. We herein propose an efficient sequential watermark detection (ESWD) model for tracing network attack flows. Based on the ESWD model, a statistical analysis of sequential detectors, with no assumptions or limitations concerning the distribution of the timing of packets, proves their effectiveness despite traffic timing perturbations. The experiments using a large number of synthetically-generated SSH traffic flows demonstrate that there is a significant advantage in using the ESWD model over the existing fixed sample size (FSS) detector, where the optimal sequential watermark detector (OSWD) based on the ESWD model results in almost 28% savings in the average number of packets compared to the FSS watermark detector. Furthermore, the nonparametric sequential sign watermark detector (SSWD) can also reduce the average packet number, given the required probability of detection errors. Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001 |
CSCWD | 3 |
| 2012 | Extensive analysis and large-scale empirical evaluation of tor bridge discoveryabstractTor is a well-known low-latency anonymous communication system that is able to bypass Internet censorship. However, publicly announced Tor routers are being blocked by various parties. To counter the censorship blocking, Tor introduced nonpublic bridges as the first-hop relay into its core network. In this paper, we analyzed the effectiveness of two categories of bridge-discovery approaches: (i) enumerating bridges from bridge https and email servers, and (ii) inferring bridges by malicious Tor middle routers. Large-scale experiments were conducted and validated our theoretic findings. We discovered 2365 Tor bridges through the two enumeration approaches and 2369 bridges by only one Tor middle router in 14 days. Our study shows that the bridge discovery based on malicious middle routers is simple, efficient and effective to discover bridges with little overhead. We also discussed the mechanisms to counter the malicious bridge discovery. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Ming Yang 0001, Xinwen Fu |
INFOCOM | 4 |
| 2012 | A novel network delay based side-channel attack: Modeling and defenseabstractInformation leakage via side channels has become a primary security threat to encrypted web traffic. Existing side channel attacks and corresponding countermeasures focus primarily on packet length, packet timing, web object size and web flow size. However, we found that encrypted web traffic can also leak information via network delay between a user and the web sites that she visits. Motivated by this observation, we investigate a novel network-delay based side-channel attack to infer web sites visited by a user. The adversary can utilize pattern recognition techniques to differentiate web sites by measuring sample mean and sample variance of the round-trip time (RTT) between a victim user and web sites. We theoretically analyzed the damage caused by such an adversary and derived closed-form formulae for detection rate, the probability that the adversary correctly recognizes a web site. To defeat this side-channel attack, we proposed several countermeasures. The basic idea is to shape traffic from different web sites so that they have similar RTT statistics. We proposed the strategies based on the k-means clustering and K-Anonymity to ensure that traffic shaping will not cause excessive delay while providing a predictable degree of anonymity. We conducted extensive experiments and our empirical results match our theory very well. Zhen Ling 0001, Junzhou Luo, Yang Zhang 0072, Ming Yang 0001, Xinwen Fu, Wei Yu 0002 |
INFOCOM | 4 |
| 2012 | Joint Interface Placement and Channel Assignment in Multi-channel Wireless Mesh NetworksabstractIn multi-channel wireless mesh networks (WMNs), it is significantly important to achieve efficient channel utilization. The channel assignment problem, which investigates how to seek a proper mapping between available channels and network interface cards (NICs) on mesh routers (MRs), is attracting more and more attention from the research community. However, most proposed channel assignment approaches assume that NICs are evenly placed on the MRs, and its amount is also pre-determined. Due to the non-uniform distribution of WMN traffic, the equal interface placement will inevitably cause that the bottleneck MRs suffer from NIC shortage, and MRs with less load only have a low utilization of NICs. Hence, in order to improve network performance and reduce network cost, interface placement should be considered carefully in the process of planning a WMN. In this paper, we investigate the joint interface placement and channel assignment problem, i.e., how to appropriately place NICs on MRs and assign channels to them. We first formulate the problem as a mixed integer linear programming (MILP) model, which aims to minimize the total number of NICs while satisfying logical link, link bandwidth, link interference and traffic demand constraints. Then, we propose an MILP-based heuristic algorithm, using iterated local search to obtain sub-optimal solutions efficiently. Finally, we conduct simulation experiments to compare the heuristic solutions with the optimal solutions, and the results show that our proposed heuristic algorithm can achieve good sub-optimal solutions. Moreover, the simulation results also demonstrate that the algorithm can be well applied in large-scale WMNs where the optimal solutions cannot be obtained, and can perform well under different traffic demands. Wenjia Wu, Junzhou Luo, Ming Yang 0001, Laurence T. Yang |
ISPA | 3 |
| 2012 | An interval centroid based spread spectrum watermarking scheme for multi-flow traceback
Junzhou Luo, Xiaogang Wang 0012, Ming Yang 0001 |
J. Netw. Comput. Appl. | 3 |
| 2011 | A potential HTTP-based application-level attack against Tor
Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001, Zhen Ling 0001 |
Future Gener. Comput. Syst. | 3 |
| 2010 | A Double Interval Centroid-Based Watermark for network flow tracebackabstractNetwork flow watermarks exploiting active traffic analysis approaches have been proposed for tracing attacks implemented through stepping stones or anonymized channels. Existing watermarking schemes either require longer observation duration leading to low efficiency of traceback or introduce large delays to the target flows, making themselves vulnerable to attacks. Especially, they are unsuitable for tracing multiple flows simultaneously due to their interference with each other. We herein propose a novel efficient and secret Double Interval Centroid-Based Watermark (DICBW) for network flow traceback by modulating the packet timing within each pair of adjacent intervals collaboratively and efficiently. By combining DICBW with spread spectrum (SS) coding techniques, we further present a general hybrid watermarking framework for efficient multi-flow traceback. Comparing with existing Interval Centroid-Based Watermark (ICBW), both statistical analysis of DICBW and the experiments using a series of synthetically generated SSH traffic flows demonstrate that DICBW can trace network flows more efficiently and the DICBW based hybrid watermarking framework can trace multiple flows simultaneously by exploiting the low cross-correlation of SS coding techniques. Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001 |
CSCWD | 3 |
| 2010 | Interference-aware gateway placement for wireless mesh networks with fault tolerance assuranceabstractWireless mesh networks (WMNs), as a promising technology to provide broadband Internet access, is attracting more and more attention from research community. In the research on WMN design, gateway placement is one of the most important and challenging aspects, that is, finding the optimal number and locations of gateways. Although several gateway placement approaches have been proposed, few of them consider the effect of link interference and gateway failure on network performance. In this paper, we address this issue to further optimize network performance. First of all, a tri-state interference model is defined, and on that basis, a new metric for gateway interference is proposed. Next, the gateway placement problem, which involves reducing link interference and assuring fault tolerance, is formulated as a multi-objective integer linear program issue. Then, an interference-aware and K-coverage gateway placement algorithm (IKGPA) is proposed, and a distributed fault tolerance routing mechanism is presented. Finally, the performance of our algorithm IKGPA is evaluated. Simulation results not only show the effectiveness of our algorithm, but also demonstrate that our algorithm achieves fault tolerance assurance with placing only a few additional gateways. Junzhou Luo, Wenjia Wu, Ming Yang 0001 |
SMC | 3 |
| 2009 | A novel flow multiplication attack against TorabstractTor has become one of the most popular overlay networks for anonymizing TCP traffic. A novel and effective flow multiplication attack against Tor is proposed in this paper, which exploits the fundamental vulnerability of anonymous web browsing by using a man-in-the-middle attack on client's HTTP flow. In the flow multiplication attack, whenever a malicious exit onion router detects a web request to a target server, it responds with a malicious page embedded with specified number of image tags, which will cause the browser to initiate deterministic number of web connections on the same circuit to fetch those images. The entry onion router on the circuit can then find such traffic pattern and the communication relationship between the client and the web server will be discovered. Even if all active content systems such as JavaScript in the browser are disabled, our attack can still compromise the anonymity of Tor while achieving invisibility by keeping client's communication running continuously. The experiment results on Tor validate the feasibility and effectiveness of our attack. Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001, Zhen Ling 0001 |
CSCWD | 3 |
| 2009 | Gateway placement optimization for load balancing in wireless mesh networksabstractWireless mesh networks (WMNs) have recently evoked much research attention as a novel technology for last-mile broadband Internet access. When designing a WMN, gateway placement is significant for it determines the total network throughput. To address this problem, a novel gateway placement approach is proposed in this paper, in which three objectives are optimized, i.e. the number of gateways, the average MR (mesh router)-GW (gateway) hop count and the variance of gateway load. The gateway placement problem is modeled as a multiple objective linear program first, and then a two-stage load balanced gateway placement algorithm is proposed. The first stage is weight-based greedy gateway selection, and the second stage is load balanced MR attachment. Simulation results show that the algorithm behaves similarly compared with existing approaches in both number of gateways and average MR-GW hop count, while achieving better load balance. Wenjia Wu, Junzhou Luo, Ming Yang 0001 |
CSCWD | 3 |
| 2009 | An Interval Centroid Based Spread Spectrum Watermark for Tracing Multiple Network FlowsabstractNetwork flow watermarking schemes have been proposed to trace attackers in the presence of stepping stones or anonymized channels. Most existing interval-based watermarking schemes are ineffective at tracing multiple network flows in parallel due to their interference with each other, while recently proposed direct sequence spread spectrum (DSSS) watermarking technique is unsuitable for tracing low data rate traffic. By combining interval centroid based watermarking (ICBW) modulation approaches with spread spectrum (SS) based watermarking coding techniques, we herein propose an interval centroid based spread spectrum watermarking scheme (ICBSSW) for efficiently tracing multiple network flows in parallel. Based on our proposed theoretical model, a statistical analysis of ICBSSW, with no assumptions or limitations concerning the distribution of packet times, proves its effectiveness despite traffic timing perturbation and robustness against multi-flow attacks. The experiments using a large number of synthetically generated SSH traffic flows demonstrate that ICBSSW can efficiently trace multiple flows simultaneously and achieve high secrecy by utilizing multiple PN codes as random seeds for randomizing the location of the embedded watermark across multiple flows. Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001 |
SMC | 3 |
| 2007 | Analysis of security protocols based on challenge-response
Junzhou Luo, Ming Yang 0001 |
Sci. China Ser. F Inf. Sci. | 2 |