Ing-Ray Chen

dblp:c/IngRayChen · DBLP profile ↗
← Back
150ranked-venue papers
52as first author
10since 2021 · last 2026
0000-0003-1657-6728ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 49 · 11 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 30 · 17 first-author · 2 since 2021Systems, architecture and hardware · 21 · 7 first-author · 1 since 2021Software engineering, systems software and programming languages · 21 · 8 first-authorDatabases, data management, data science and information retrieval · 13 · 5 first-author · 2 since 2021Security and privacy · 8 · 3 first-authorTheory of computation · 5 · 2 first-authorArtificial intelligence and machine learning · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 since 2021
YearPublicationVenuePosition
2026 On effectiveness of AI-based misbehavior detection in medical IoT
Hamid Al-Hamadi, Ing-Ray Chen, Ding-Chau Wang, Abdullah Almutairi
Future Gener. Comput. Syst.2
2024 eMTD: Energy-Aware Moving Target Defense for Sustainable Solar-powered Sensor-based Smart Farms
abstract
Smart farms, as a way for better productivity and efficiency, have yet to be thoroughly studied for their service quality amid cyber threats. This work introduces a proactive security approach, Moving Target Defense (MTD), to the smart farm system to proactively address diverse cyber threats. Specifically, we develop an energy-aware MTD, termed eMTD, using port hopping for a sustainable smart farm network. Leveraging deep reinforcement learning (DRL), we identify the optimal MTD strategy capable of ensuring high monitoring quality of animal conditions and sufficient energy levels for solar-powered sensors on the farm. Our experiments demonstrate a significant improvement by approximately 15% in monitoring quality and remaining energy compared to other schemes.
Dian Chen 0007, Ing-Ray Chen, Dong Sam Ha, Jin-Hee Cho
NOMS2
2024 Energy-Adaptive and Robust Monitoring for Smart Farms Based on Solar-Powered Wireless Sensors
abstract
While smart farm technologies significantly aid in reducing costs and boosting productivity for farmers, they often lack the necessary robustness against cyberattacks and adaptability to dynamic environmental changes. We propose a solar-powered sensor-based smart farm system to provide high monitoring quality while preserving sensor energy in the presence of adversarial attacks. In a smart farm system, solar-powered sensors are attached to animals (e.g., cows) to monitor their health under varying weather conditions to provide energy-adaptive and high-quality monitoring services. Further, a smart farm system should be robust against adversarial attacks aiming to disrupt monitoring quality. We use deep reinforcement learning (DRL) to identify the optimal policy for maximizing monitoring quality and prolonging the system’s lifetime while maintaining sufficient energy. We introduce transfer learning (TL) into the DRL process to achieve fast learning without experiencing a cold start problem in DRL. In addition, we develop an uncertainty-aware anomaly data detection method to filter out deceptive data caused by adversarial attacks. Via extensive comparative performance analysis conducted based on real datasets, we demonstrate the superior performance of the proposed TL-based DRL strategies over existing competitive counterparts in the system lifetime, the monitoring quality, the learning convergence time, and the energy consumption.
Dian Chen 0007, Qisheng Zhang, Ing-Ray Chen, Dong Sam Ha, Jin-Hee Cho
IEEE Internet Things J.3
2024 Privacy-Preserving and Diversity-Aware Trust-based Team Formation in Online Social Networks
abstract
As online social networks (OSNs) become more prevalent, a new paradigm for problem-solving through crowd-sourcing has emerged. By leveraging the OSN platforms, users can post a problem to be solved and then form a team to collaborate and solve the problem. A common concern in OSNs is how to form effective collaborative teams, as various tasks are completed through online collaborative networks. A team’s diversity in expertise has received high attention to producing high team performance in developing team formation (TF) algorithms. However, the effect of team diversity on performance under different types of tasks has not been extensively studied. Another important issue is how to balance the need to preserve individuals’ privacy with the need to maximize performance through active collaboration, as these two goals may conflict with each other. This research has not been actively studied in the literature. In this work, we develop a TF algorithm in the context of OSNs that can maximize team performance and preserve team members’ privacy under different types of tasks. Our proposed PRivAcy-Diversity-Aware TF framework, called PRADA-TF , is based on trust relationships between users in OSNs where trust is measured based on a user’s expertise and privacy preference levels. The PRADA-TF algorithm considers the team members’ domain expertise, privacy preferences, and the team’s expertise diversity in the process of TF. Our approach employs game-theoretic principles Mechanism Design to motivate self-interested individuals within a TF context, positioning the mechanism designer as the pivotal team leader responsible for assembling the team. We use two real-world datasets (i.e., Netscience and IMDb) to generate different semi-synthetic datasets for constructing trust networks using a belief model (i.e., Subjective Logic) and identifying trustworthy users as candidate team members. We evaluate the effectiveness of our proposed PRADA-TF scheme in four variants against three baseline methods in the literature. Our analysis focuses on three performance metrics for studying OSNs: social welfare, privacy loss, and team diversity.
Yash Mahajan, Jin-Hee Cho, Ing-Ray Chen
ACM Trans. Intell. Syst. Technol.3
2023 Attack-Resistant, Energy-Adaptive Monitoring for Smart Farms: Uncertainty-Aware Deep Reinforcement Learning Approach
abstract
This work proposes an energy-adaptive monitoring system for a smart farm using solar sensors attached to cows. The proposed system aims to achieve a high monitoring quality in the smart farm under fluctuating energy and cyber attacks disrupting the collection of sensed data from solar sensors, such as protocol noncompliance, false data injection, denial-of-service, and state manipulation. We adopt Subjective Logic, a belief model, to consider multidimensional uncertainty in sensed data. We employ deep reinforcement learning (DRL) for agents on gateways to collect high-quality sensed data from the solar sensors. The DRL agents aim to collect high-quality sensed data with low uncertainty and high freshness under fluctuating energy levels in solar sensors. We analyze the performance of the proposed energy-adaptive smart farm system in accumulated reward, monitoring error rate, and system overload. We conduct a comparative performance analysis of the uncertainty-aware DRL algorithms against their counterparts in choosing the number of sensed data to be updated to collect high-quality sensed data to achieve high resilience against attacks. Our results prove that multiagent proximal policy optimization (MAPPO) using the uncertainty maximization technique outperforms other counterparts, showing about 4% lower monitoring error rate and the system overload.
Qisheng Zhang, Dian Chen 0007, Yash Mahajan, Ing-Ray Chen, Dong Sam Ha, Jin-Hee Cho
IEEE Internet Things J.4
2022 An Attack-Resilient and Energy-Adaptive Monitoring System for Smart Farms
abstract
In this work, we propose an energy-adaptive moni-toring system for a solar sensor-based smart animal farm (e.g., cattle). The proposed smart farm system aims to maintain high-quality monitoring services by solar sensors with limited and fluctuating energy against a full set of cyberattack behaviors including false data injection, message dropping, or protocol non-compliance. We leverage Subjective Logic (SL) as the belief model to consider different types of uncertainties in opinions about sensed data. We develop two Deep Reinforcement Learning (D RL) schemes leveraging the design concept of uncertainty maximization in SL for DRL agents running on gateways to collect high-quality sensed data with low uncertainty and high freshness. We assess the performance of the proposed energy-adaptive smart farm system in terms of accumulated reward, monitoring error, system overload, and battery maintenance level. We compare the performance of the two DRL schemes developed (i.e., multi-agent deep Q-Iearning, MADQN, and multi-agent proximal policy optimization, MAPPO) with greedy and random baseline schemes in choosing the set of sensed data to be updated to collect high-quality sensed data to achieve resilience against attacks. Our experiments demonstrate that MAPPO with the uncertainty maximization technique outperforms its counterparts.
Qisheng Zhang, Yash Mahajan, Ing-Ray Chen, Dong Sam Ha, Jin-Hee Cho
GLOBECOM3
2022 SAFER: Social Capital-Based Friend Recommendation to Defend against Phishing Attacks
Zhen Guo 0002, Jin-Hee Cho, Ing-Ray Chen, Srijan Sengupta, Michin Hong, Tanushree Mitra
ICWSM3
2022 Proactive Defense for Internet-of-things: Moving Target Defense With Cyberdeception
abstract
Resource constrained Internet-of-Things (IoT) devices are highly likely to be compromised by attackers, because strong security protections may not be suitable to be deployed. This requires an alternative approach to protect vulnerable components in IoT networks. In this article, we propose an integrated defense technique to achieve intrusion prevention by leveraging cyberdeception (i.e., a decoy system) and moving target defense (i.e., network topology shuffling). We evaluate the effectiveness and efficiency of our proposed technique analytically based on a graphical security model in a software-defined networking (SDN)-based IoT network. We develop four strategies (i.e., fixed/random and adaptive/hybrid) to address “when” to perform network topology shuffling and three strategies (i.e., genetic algorithm/decoy attack path-based optimization/random) to address “how” to perform network topology shuffling on a decoy-populated IoT network, and we analyze which strategy can best achieve a system goal, such as prolonging the system lifetime, maximizing deception effectiveness, maximizing service availability, or minimizing defense cost. We demonstrated that a software-defined IoT network running our intrusion prevention technique at the optimal parameter setting prolongs system lifetime, increases attack complexity of compromising critical nodes, and maintains superior service availability compared with a counterpart IoT network without running our intrusion prevention technique. Further, when given a single goal or a multi-objective goal (e.g., maximizing the system lifetime and service availability while minimizing the defense cost) as input, the best combination of “when” and “how” strategies is identified for executing our proposed technique under which the specified goal can be best achieved.
Mengmeng Ge 0001, Jin-Hee Cho, Dong Seong Kim 0001, Ing-Ray Chen
ACM Trans. Internet Techn.5
2021 Vulnerability-Aware Resilient Networks: Software Diversity-Based Network Adaptation
abstract
By leveraging the principle of software polyculture to ensure security in a network, we propose a vulnerability-based software diversity metric to determine how a network topology can be adapted to minimize security vulnerability while maintaining maximum network connectivity. Our proposed metric estimates the software diversity of the node using the vulnerabilities of software packages installed on nearby nodes on attack paths reachable to the node. Our software diversity-based adaptation (SDA) scheme employs the diversity of each node for edge adaptations. These adaptations include the removal of edges that expose high security vulnerability as well as the potential addition of edges between certain nodes with low vulnerabilities associated with them. To validate the proposed SDA scheme, we conduct extensive experiments comparing our approach with counterpart baseline schemes in real networks. Our simulation results demonstrate that SDA outperforms these existing counterparts. We discuss insights into these findings in terms of the effectiveness and efficiency of the proposed SDA scheme under three real network topologies with vastly different network densities.
Qisheng Zhang, Jin-Hee Cho, Terrence J. Moore, Ing-Ray Chen
IEEE Trans. Netw. Serv. Manag.4
2021 Reliability of Autonomous Internet of Things Systems With Intrusion Detection Attack-Defense Game Design
abstract
In this article we develop an intrusion detection attack-defense game for Internet of Things (IoT) systems for which autonomous IoT devices collaboratively solve a problem. We develop an analytical model to determine the conditions under which malicious nodes have no incentives to perform attack in the intrusion detection attack-defense game. We also develop a stochastic Petri net model to analyze the effect of attack-defense behaviors on system reliability, given a definition of system failure conditions as input. The performance evaluation results demonstrate that our intrusion detection system (IDS) attack-defense game design greatly improves system reliability over existing autonomous IoT systems without gaming design consideration when attacks are reckless and intensive.
Ding-Chau Wang, Ing-Ray Chen, Hamid Al-Hamadi
IEEE Trans. Reliab.2
2020 Bayesian-Based Spectrum Sensing and Optimal Channel Estimation for MAC Layer Protocol in Cognitive Radio Sensor Networks
abstract
Abstract Cognitive radio (CR) is an intelligent and adaptive radio technology that automatically detects the available channels in the wireless spectrum and sometimes changes the transmission parameters to enable effective communication. Spectrum sensing in CR prevents harmful interference with the licensed users and maximizes the spectrum utilization. Thus, this paper proposes a technique for optimal channel estimation and spectrum sensing for MAC layer protocol in CR networks such that the scheduling issues are addressed. Initially, in the CR networks, spectrum sensing is done using the proposed optimal naive Bayes classifier (ONBC) based on the signal statistics, such as energy and likelihood ratio. The ONBC is developed by integrating the bat–bird swarm algorithm (BBSA) with the naive Bayes classifier, which works based on the Bayesian concept. The BBSA is newly developed by integrating the bird swarm algorithm (BSA) and bat algorithm. Finally, the channel estimation is done using the pilot-based sequential procedure and least square estimation (LSE). The analysis of the proposed method is done in the Rayleigh and Rician environments using 256 and 512 sub-carriers. From the results, it is exposed that the proposed BBSA + LSE pilot-based sequential method obtains the bit error rate, normalized energy and Probability detection (PD) of is 0.0126, 0.8446 and 0.9355, respectively.
Jemish V. Maisuria, Saurabh N. Mehta, Ing-Ray Chen
Comput. J.3
2020 Lightweight Misbehavior Detection Management of Embedded IoT Devices in Medical Cyber Physical Systems
abstract
We propose a lightweight specification-based misbehavior detection management technique to efficiently and effectively detect misbehavior of an IoT device embedded in a medical cyber physical system through automatic model checking and formal verification. We verify our specification-based misbehavior detection technique with a patient-controlled analgesia (PCA) device embedded in a medical health monitoring system. Through extensive ns3 simulation, we verify its superior performance over popular machine learning anomaly detection methods based on support vector machine (SVM) and k-nearest neighbors (KNN) techniques in both effectiveness and efficiency performance metrics.
Gaurav Choudhary, Philip Virgil Astillo, Ilsun You, Kangbin Yim, Ing-Ray Chen, Jin-Hee Cho
IEEE Trans. Netw. Serv. Manag.5
2019 Analysis of Attack-Defense Strategies in Autonomous Distributed IoT Systems
abstract
We develop an analytical model to capture the interplay of attack-defense strategies of an autonomous distributed Internet of Things system (ADIoTS). Every node participates in intrusion detection of a target node of the same type, thus necessitating that every good node plays a set of defense strategies and every bad node plays a set of attack strategies for achieving their own goals. The end product is a methodology for identifying the best defense strategies to maximize the system lifetime.
Hamid Al-Hamadi, Ing-Ray Chen, Ding-Chau Wang
ISADS2
2019 Trust-Based Service Management for Mobile Cloud IoT Systems
abstract
We propose and analyze a 3-tier cloud-cloudlet-device hierarchical trust-based service management protocol called IoT-HiTrust for large-scale mobile cloud Internet of Things (IoT) systems. Our mobile cloud hierarchical service management protocol allows an IoT customer to report its service experiences and query its subjective service trust score toward an IoT service provider following a scalable report-and-query design. We conduct a formal scalability analysis along with an ns-3 simulation performance analysis demonstrating that IoT-HiTrust not only achieves scalability without compromising accuracy, convergence, and resiliency properties against malicious attacks but also outperforms contemporary distributed and centralized IoT trust management protocols. We test the feasibility by applying IoT-HiTrust to two case studies: 1) a smart city travel service composition and binding application and 2) an air pollution detection and response application. The results demonstrate that IoT-HiTrust outperforms contemporary distributed and centralized trust-based IoT service management protocols in selecting trustworthy nodes to maximize application performance, while achieving scalability.
Ing-Ray Chen, Ding-Chau Wang, Jeffrey J. P. Tsai, Hamid Al-Hamadi, Ilsun You
IEEE Trans. Netw. Serv. Manag.1
2019 Network Adaptations Under Cascading Failures for Mission-Oriented Networks
abstract
In the network science domain, a larger size of the giant component (i.e., the largest cluster of nodes) represents higher network resilience in terms of maximizing network availability in the presence of attacks. However, this does not necessarily represent how well the network provides promised services under attacks and/or failures. We aim to improve network resilience by introducing network adaptability (i.e., reconfiguration of a network topology), in addition to fault-tolerance. We develop a suite of strategies adopting processes from percolation theory, describing the process to percolate into a medium, for a tactical, mission-oriented network. This network is service-oriented, characterized by a number of task teams where each resource-restricted node aims to maximize resource utilization while completing multiple tasks without failure. We investigate how node failures can trigger overloads, leading to cascading failures. We consider various attack behaviors (infectious, non-infectious, random, or targeted) and analyze their effects. Through extensive simulations, we show the outperformance of the proposed adaptation strategy compared with the performance of the existing counterparts in terms of the size of the giant component, the utilization of resources, the number of alive task teams (or mission success ratio), and the adaptation cost for a large-scale, mission-oriented network under attack.
Terrence J. Moore, Jin-Hee Cho, Ing-Ray Chen
IEEE Trans. Netw. Serv. Manag.3
2018 Intrusion Detection Systems for Networked Unmanned Aerial Vehicles: A Survey
abstract
Unmanned Aerial Vehicles (UAV)-based civilian or military applications become more critical to serving civilian and/or military missions. The significantly increased attention on UAV applications also has led to security concerns particularly in the context of networked UAVs. Networked UAVs are vulnerable to malicious attacks over open-air radio space and accordingly intrusion detection systems (IDSs) have been naturally derived to deal with the vulnerabilities and/or attacks. In this paper, we briefly survey the state-of-the-art IDS mechanisms that deal with vulnerabilities and attacks under networked UAV environments. In particular, we classify the existing IDS mechanisms according to information gathering sources, deployment strategies, detection methods, detection states, IDS acknowledgment, and intrusion types. We conclude this paper with research challenges, insights, and future research directions to propose a networked UAVIDS system which meets required standards of effectiveness and efficiency in terms of the goals of both security and performance.
Gaurav Choudhary, Vishal Sharma 0001, Ilsun You, Kangbin Yim, Ing-Ray Chen, Jin-Hee Cho
IWCMC5
2018 On IoT Misbehavior Detection in Cyber Physical Systems
abstract
This article discusses a lightweight behavior rule specification-based monitoring solution for identifying misbehavior of an embedded IoT device. These unusual activities are exhibited because of attacks exploiting the vulnerability exposed through automatic model checking and formal verification. It is conclusive in the presented research that rule specification-based misbehavior detection technique outperforms contemporary anomaly-based misbehavior detection techniques for an unmanned aerial vehicle (UAV) cyber-physical system.
Ilsun You, Kangbin Yim, Vishal Sharma 0001, Gaurav Choudhary, Ing-Ray Chen, Jin-Hee Cho
PRDC5
2018 Trust-based mechanism design for cooperative spectrum sensing in cognitive radio networks
Ing-Ray Chen, Jeffrey J. P. Tsai, Ding-Chau Wang
Comput. Commun.2
2018 PROVEST: Provenance-Based Trust Model for Delay Tolerant Networks
abstract
Delay tolerant networks (DTNs) are often encountered in military network environments where end-to-end connectivity is not guaranteed due to frequent disconnection or delay. This work proposes a provenance-based trust framework, namely PROVEST (PROVEnance-baSed Trust model) that aims to achieve accurate peer-to-peer trust assessment and maximize the delivery of correct messages received by destination nodes while minimizing message delay and communication cost under resource-constrained network environments. Provenance refers to the history of ownership of a valued object or information. We leverage the interdependency between trustworthiness of information source and information itself in PROVEST. PROVEST takes a data-driven approach to reduce resource consumption in the presence of selfish or malicious nodes while estimating a node's trust dynamically in response to changes in the environmental and node conditions. This work adopts a model-based method to evaluate the performance of PROVEST (i.e., trust accuracy and routing performance) using Stochastic Petri Nets. We conduct a comparative performance analysis of PROVEST against existing trust-based and non-trust-based DTN routing protocols to analyze the benefits of PROVEST. We validate PROVEST using a real dataset of DTN mobility traces.
Jin-Hee Cho, Ing-Ray Chen
IEEE Trans. Dependable Secur. Comput.2
2018 Editorial
abstract
I am very happy to report that TSC has gained an Impact Factor (IF) of 3.520 and the 5-year IF of 4.245, both of which represent significant increases from the previous years. This further speaks to the global reputation of the journal and the amazing work done by the past EICs, all the current and past EB members, and reviewers - all of whom have volunteered their precious time despite their very busy schedule to support and contribute to the growth of this journal. I hope to count on your continued engagement for the future growth of this journal. Over this past year, several esteemed EB members have completed their terms of service to TSC after serving for several years. On behalf of the Services Computing community and the TSC EAB, I would like to thank the following Associate Editors who retired from TSC EB in 2017 for their invaluable service and contributions to the journal. Overall, I am very proud of the success that TSC has achieved in 2017. This would not have been possible without the continued support of the authors, readers, reviewers, TSC EAB, TSC EB, and the staff of IEEE and IEEE Computer Society. I look forward to exploring ways to further enhance the reputation and impact of our journal. I would love to hear your suggestions and comments, and I hope to have your continued support.
Paramvir Bahl, Barbara Carminati, James Caverlee, Ing-Ray Chen, Wynne Hsu, Toru Ishida 0001, Valérie Issarny, Surya Nepal, Indrakshi Ray, Kui Ren 0001, Shamik Sural, Mei-Ling Shyu
IEEE Trans. Serv. Comput.4
2018 CATrust: Context-Aware Trust Management for Service-Oriented Ad Hoc Networks
abstract
We propose a context-aware trust management model called CATrust for service-oriented ad hoc networks such as peer-to-peer and Internet of Things networks wherein a node can be a service requester or a service provider. The novelty of our design lies in the use of logistic regression to dynamically estimate trustworthiness of a service provider based on its service behavior patterns in response to context environment changes. We develop a recommendation filtering mechanism to effectively screen out dishonest recommendations even in extremely hostile environments in which the majority recommenders are dishonest. We demonstrate desirable convergence, accuracy, and resiliency properties of CATrust. We also demonstrate that CATrust outperforms contemporary peer-to-peer and Internet of Things trust models in terms of service trust prediction accuracy against collusion recommendation attacks.
Ing-Ray Chen, Jin-Hee Cho, Ananthram Swami, Yen-Cheng Lu, Chang-Tien Lu, Jeffrey J. P. Tsai
IEEE Trans. Serv. Comput.2
2017 PDGM: Percolation-based directed graph matching in social networks
abstract
Linking multiple accounts owned by the same user across different online social networks (OSNs) is an important issue in social networks, known as identity reconciliation. Graph matching is one of popular techniques to solve this problem by identifying a map that matches a set of vertices across different OSNs. Among them, percolation-based graph matching (PGM) has been explored to identify entities belonging to a same user across two different networks based on a set of initial pre-matched seed nodes and graph structural information. However, existing PGM algorithms have been applied in only undirected networks while many OSNs are represented by directional relationships (e.g., followers or followees in Twitter or Facebook). For PGM to be applicable in real world OSNs represented by directed networks with a small set of overlapping vertices, we propose a percolation-based directed graph matching algorithm, namely PDGM, by considering the following two key features: (1) similarity of two nodes based on directional relationships (i.e., outgoing edges vs. incoming edges); and (2) celebrity penalty such as penalty given for nodes with a high in-degree. Through the extensive simulation experiments, our results show that the proposed PDGM outperforms the baseline PGM counterpart that does not consider either directional relationships or celebrity penalty.
Lijing Wang 0001, Jin-Hee Cho, Ing-Ray Chen, Jiangzhuo Chen
ICC3
2017 A survey of trust computation models for service management in internet of things systems
Ing-Ray Chen, Jeffrey J. P. Tsai
Comput. Commun.2
2017 Trust-Based Decision Making for Health IoT Systems
abstract
With the onset of the Internet of Things (IoT) era, the number of IoT devices and sensors is increasing tremendously. This paper is concerned with a health IoT system consisting of various IoT devices carried by members of an environmental health community. We propose a novel trust-based decision making protocol that uses trust-based information sharing among the health IoT devices, so that a collective knowledge base can be built to rate the environment at a particular location and time. This knowledge would enable an IoT device acting on behalf of its user to decide whether or not it should visit this place/environment for health reasons. Unlike existing trust management protocols, our trust-based health IoT protocol considers risk classification, reliability trust, and loss of health probability as three design dimensions for decision making, resulting in a protocol suitable for decision making in health IoT systems. Our protocol is resilient to noisy sensing data provided by IoT devices either unintentionally or intentionally. We present performance data of our trust-based health IoT protocol and conduct a comparative performance analysis of our protocol with two baseline protocols to demonstrate the feasibility.
Hamid Al-Hamadi, Ing-Ray Chen
IEEE Internet Things J.2
2017 Trust-Based Task Assignment With Multiobjective Optimization in Service-Oriented Ad Hoc Networks
abstract
We propose and analyze a trust management protocol in service-oriented mobile ad hoc networks (MANETs) populated with service providers and service requesters, and demonstrate the resiliency and convergence properties against bad-mouthing, ballot-stuffing, opportunistic service, and self-promotion attacks. To demonstrate the applicability, we consider a mission-driven service-oriented MANET that must handle dynamically arriving tasks to achieve multiple conflicting objectives. We devise a trust-based heuristic algorithm based on auctioning with local knowledge of node status to solve this node-to-task assignment problem with multiobjective optimization (MOO) requirements. Our trust-based heuristic algorithm has a polynomial runtime complexity, rather than an exponential runtime complexity as in existing work, thus allowing dynamic node-to-task assignment to be performed at runtime. It outperforms a nontrust-based counterpart using blacklisting techniques while performing close to the ideal solution quality with perfect knowledge of node status over a wide range of environmental conditions. We conduct extensive sensitivity analysis of the results with respect to key design parameters and alternative trust protocol designs. We also develop a table-lookup method to apply the best trust protocol parameter settings upon detection of dynamically changing environmental conditions to maximize MOO performance.
Ing-Ray Chen, Jin-Hee Cho, Jeffrey J. P. Tsai
IEEE Trans. Netw. Serv. Manag.2
2017 Trust-Based Service Composition and Binding with Multiple Objective Optimization in Service-Oriented Mobile Ad Hoc Networks
abstract
With the proliferation of fairly powerful mobile devices and ubiquitous wireless technology, we see a transformation from traditional mobile ad hoc networks (MANETs) into a new era of service-oriented MANETs wherein a node can provide and receive services. Requested services must be decomposed into more abstract services and then bound; we formulate this as a multi-objective optimization (MOO) problem to minimize the service cost, while maximizing the quality of service and quality of information in the service a user receives. The MOO problem is an SP-to-service assignment problem. We propose a multidimensional trust based algorithm to solve the problem. We carry out an extensive suite of simulations to test the relative performance of the proposed trust-based algorithm against a non-trust-based counterpart and an existing single-trust-based beta reputation scheme. Our proposed algorithm effectively filters out malicious nodes exhibiting various attack behaviors by penalizing them with loss of reputation, which ultimately leads to high user satisfaction. Further, our proposed algorithm is efficient with linear runtime complexity while achieving a close-to-optimal solution.
Ing-Ray Chen, Jin-Hee Cho, Ananthram Swami, Kevin S. Chan
IEEE Trans. Serv. Comput.2
2016 Trust-based decision making for environmental health community of interest IoT systems
abstract
With the onset of the Internet of Things (IoT) era, the number of devices and sensors is increasing tremendously. This paper is concerned with Health IoT consisting of various devices carried by members of an environmental health community of interest (CoI). We propose trust based information sharing among the CoI users of these IoT devices, so that a collective knowledge base can be built to rate the environment at a particular location and at a given time. This rated knowledge of various environments would enable a user's mobile device to automatically decide whether or not the user should visit this place/environment. Our trust-based decision making framework considers risk classification, reliability trust, and loss of health probability as three design dimensions for decision making. Performance data are shown to demonstrate the feasibility of our approach.
Hamid Al-Hamadi, Ing-Ray Chen
WiMob2
2016 Trust threshold based public key management in mobile ad hoc networks
Jin-Hee Cho, Ing-Ray Chen, Kevin S. Chan
Ad Hoc Networks2
2016 A topic-focused trust model for Twitter
Liang Zhao 0002, Ting Hua, Chang-Tien Lu, Ing-Ray Chen
Comput. Commun.4
2016 Trust-Based Service Management for Social Internet of Things Systems
abstract
A social internet of things (IoT) system can be viewed as a mix of traditional peer-to-peer networks and social networks, where “things” autonomously establish social relationships according to the owners' social networks, and seek trusted “things” that can provide services needed when they come into contact with each other opportunistically. We propose and analyze the design notion of adaptive trust management for social IoT systems in which social relationships evolve dynamically among the owners of IoT devices. We reveal the design tradeoff between trust convergence versus trust fluctuation in our adaptive trust management protocol design. With our adaptive trust management protocol, a social IoT application can adaptively choose the best trust parameter settings in response to changing IoT social conditions such that not only trust assessment is accurate but also the application performance is maximized. We propose a table-lookup method to apply the analysis results dynamically and demonstrate the feasibility of our proposed adaptive trust management scheme with two real-world social IoT service composition applications.
Ing-Ray Chen, Fenye Bao
IEEE Trans. Dependable Secur. Comput.1
2016 Modeling and Analysis of Attacks and Counter Defense Mechanisms for Cyber Physical Systems
abstract
In this paper, we develop an analytical model based on stochastic Petri nets to capture the dynamics between adversary behavior and defense for cyber physical systems. We consider several types of failures including attrition failure, pervasion failure, and exfiltration failure which can happen to a cyber physical system. Using a modernized electrical grid as an example, we illustrate the parameterization process. Our results reveal optimal design conditions, including the intrusion detection interval, and the redundancy level, under which the modernized electrical grid's mean time to failure is maximized. Further, there exists a design tradeoff between exfiltration failure, attrition failure, and pervasion failure when using redundancy to improve the overall system reliability.
Robert Mitchell 0001, Ing-Ray Chen
IEEE Trans. Reliab.2
2016 Trust Management for SOA-Based IoT and Its Application to Service Composition
abstract
A future Internet of Things (IoT) system will connect the physical world into cyberspace everywhere and everything via billions of smart objects. On the one hand, IoT devices are physically connected via communication networks. The service oriented architecture (SOA) can provide interoperability among heterogeneous IoT devices in physical networks. On the other hand, IoT devices are virtually connected via social networks. In this paper we propose adaptive and scalable trust management to support service composition applications in SOA-based IoT systems. We develop a technique based on distributed collaborative filtering to select feedback using similarity rating of friendship, social contact, and community of interest relationships as the filter. Further we develop a novel adaptive filtering technique to determine the best way to combine direct trust and indirect trust dynamically to minimize convergence time and trust estimation bias in the presence of malicious nodes performing opportunistic service and collusion attacks. For scalability, we consider a design by which a capacity-limited node only keeps trust information of a subset of nodes of interest and performs minimum computation to update trust. We demonstrate the effectiveness of our proposed trust management through service composition application scenarios with a comparative performance analysis against EigenTrust and PeerTrust.
Ing-Ray Chen, Fenye Bao
IEEE Trans. Serv. Comput.1
2015 Trust-Based Task Assignment in Autonomous Service-Oriented Ad Hoc Networks
abstract
We propose and analyze a trust management protocol for autonomous service-oriented mobile ad hoc networks (MANETs) populated with service providers (SPs) and service requesters (SRs). We demonstrate the resiliency and convergence properties of our trust protocol design for service-oriented MANETs in the presence of malicious nodes performing opportunistic service attacks and slandering attacks. Further, we consider a situation in which a mission comprising dynamically arriving tasks must achieve multiple conflicting objectives, including maximizing the mission reliability, minimizing the utilization variance, and minimizing the delay to task completion. We devise a trust-based heuristic algorithm to solve this multi-objective optimization problem with a linear runtime complexity, thus allowing dynamic node-to-task assignment to be performed at runtime. Through extensive simulation, we demonstrate that our trust-based node-to-task assignment algorithm outperforms a non-trust-based counterpart using blacklisting techniques while performing close to the ideal solution quality with perfect knowledge of node reliability over a wide range of environmental conditions.
Ing-Ray Chen, Jin-Hee Cho
ISADS2
2015 Hierarchical trust management of community of interest groups in mobile ad hoc networks
Ing-Ray Chen
Ad Hoc Networks1
2015 Behavior Rule Specification-Based Intrusion Detection for Safety Critical Medical Cyber Physical Systems
abstract
We propose and analyze a behavior-rule specification-based technique for intrusion detection of medical devices embedded in a medical cyber physical system (MCPS) in which the patient's safety is of the utmost importance. We propose a methodology to transform behavior rules to a state machine, so that a device that is being monitored for its behavior can easily be checked against the transformed state machine for deviation from its behavior specification. Using vital sign monitor medical devices as an example, we demonstrate that our intrusion detection technique can effectively trade false positives off for a high detection probability to cope with more sophisticated and hidden attackers to support ultra safe and secure MCPS applications. Moreover, through a comparative analysis, we demonstrate that our behavior-rule specification-based IDS technique outperforms two existing anomaly-based techniques for detecting abnormal patient behaviors in pervasive healthcare applications.
Robert Mitchell 0001, Ing-Ray Chen
IEEE Trans. Dependable Secur. Comput.2
2015 Adaptive Network Defense Management for Countering Smart Attack and Selective Capture in Wireless Sensor Networks
abstract
We propose and analyze adaptive network defense management for countering smart attack and selective capture which aim to cripple the basic data delivery functionality of a base station based wireless sensor network. With selective capture, the adversaries strategically capture sensors and turn them into inside attackers. With smart attack, an inside attacker is capable of performing random, opportunistic, and insidious attacks to evade detection and maximize their chance of success. We develop a model-based analysis methodology with simulation validation to identify the best defense protocol settings under which the sensor network lifetime is maximized against selective capture and smart attack.
Hamid Al-Hamadi, Ing-Ray Chen
IEEE Trans. Netw. Serv. Manag.2
2015 Integrated Intrusion Detection and Tolerance in Homogeneous Clustered Sensor Networks
abstract
In this article, we propose and analyze dynamic redundancy management of integrated intrusion detection and tolerance for lifetime maximization of homogeneous clustered wireless sensor networks (WSNs). We take a holistic approach of integrating multisource and multipath routing for intrusion tolerance with majority voting for intrusion detection in our redundancy management protocol design. By dynamically controlling the redundancy level for both multisource multipath routing and voting-based intrusion detection with energy consideration, we identify the optimal redundancy level to be applied to maximize the WSN lifetime in response to changing environment conditions including node density, radio range, and node capture rate. We demonstrate the effectiveness of our integrated redundancy management protocol by a comparative analysis with a multisource multipath routing algorithm called AFTQC that considers only fault/intrusion tolerance.
Hamid Al-Hamadi, Ing-Ray Chen
ACM Trans. Sens. Networks2
2014 Dynamic Hierarchical Trust Management of Mobile Groups and Its Application to Misbehaving Node Detection
abstract
In military operation or emergency response situations, very frequently a commander will need to assemble and dynamically manage Community of Interest (COI) mobile groups to achieve a critical mission assigned despite failure, disconnection or compromise of COI members. We combine the designs of COI hierarchical management for scalability and reconfigurability with COI dynamic trust management for survivability and intrusion tolerance to compose a scalable, reconfigurable, and survivable COI management protocol for managing COI mission-oriented mobile groups in heterogeneous mobile environments. A COI mobile group in this environment would consist of heterogeneous mobile entities such as communication-device-carried personnel/robots and aerial or ground vehicles operated by humans exhibiting not only quality of service (QoS) characters, e.g., competence and cooperativeness, but also social behaviors, e.g., connectivity, intimacy and honesty. A COI commander or a subtask leader must measure trust with both social and QoS cognition depending on mission task characteristics and/or trustee properties to ensure successful mission execution. In this paper, we present a dynamic hierarchical trust management protocol that can learn from past experiences and adapt to changing environment conditions, e.g., increasing misbehaving node population, evolving hostility and node density, etc. to enhance agility and maximize application performance. With trust-based misbehaving node detection as an application, we demonstrate how our proposed COI trust management protocol is resilient to node failure, disconnection and capture events, and can help maximize application performance in terms of minimizing false negatives and positives in the presence of mobile nodes exhibiting vastly distinct QoS and social behaviors.
Ing-Ray Chen
AINA1
2014 Trust management for service composition in SOA-based IoT systems
abstract
An Internet of Things (IoT) system connects a large amount of tags, sensors, and smart devices often with mobility to facilitate information sharing, enabling a variety of attractive applications. On the one hand, the service oriented architecture (SOA) can provide connectivity and interoperability among heterogeneous IoT devices in the physical network. On the other hand, IoT devices are virtually connected via social networks. In this paper, we analyze the notion of adaptive trust management to support reliable service composition applications in SOA-based IoT systems. Each device records user satisfaction experiences toward devices with which it has interacted, and collects trust feedbacks from other devices sharing social interests. We consider friendship, social contact, and community of interest social relationships to select trust feedbacks. Further we develop a novel adaptive filtering technique to determine the best way to combine direct trust and indirect trust feedbacks dynamically to minimize both convergence time and trust bias. We demonstrate the effectiveness of the proposed trust management through a service composition application in SOA-based IoT systems.
Ing-Ray Chen, Fenye Bao
WCNC1
2014 Trust management in mobile ad hoc networks for bias minimization and application performance maximization
Ing-Ray Chen, Fenye Bao, Jin-Hee Cho
Ad Hoc Networks1
2014 Scalable and efficient dual-region based mobility management for ad hoc networks
Ing-Ray Chen, Yinan Li 0002, Robert Mitchell 0001, Ding-Chau Wang
Ad Hoc Networks1
2014 A survey of intrusion detection in wireless network applications
Robert Mitchell 0001, Ing-Ray Chen
Comput. Commun.2
2014 Dynamic Trust Management for Delay Tolerant Networks and Its Application to Secure Routing
abstract
Delay tolerant networks (DTNs) are characterized by high end-to-end latency, frequent disconnection, and opportunistic communication over unreliable wireless links. In this paper, we design and validate a dynamic trust management protocol for secure routing optimization in DTN environments in the presence of well-behaved, selfish and malicious nodes. We develop a novel model-based methodology for the analysis of our trust protocol and validate it via extensive simulation. Moreover, we address dynamic trust management, i.e., determining and applying the best operational settings at runtime in response to dynamically changing network conditions to minimize trust bias and to maximize the routing application performance. We perform a comparative analysis of our proposed routing protocol against Bayesian trust-based and non-trust based (PROPHET and epidemic) routing protocols. The results demonstrate that our protocol is able to deal with selfish behaviors and is resilient against trust-related attacks. Furthermore, our trust-based routing protocol can effectively trade off message overhead and message delay for a significant gain in delivery ratio. Our trust-based routing protocol operating under identified best settings outperforms Bayesian trust-based routing and PROPHET, and approaches the ideal performance of epidemic routing in delivery ratio and message delay without incurring high message or protocol maintenance overhead.
Ing-Ray Chen, Fenye Bao, Moonjeong Chang, Jin-Hee Cho
IEEE Trans. Parallel Distributed Syst.1
2014 Adaptive Intrusion Detection of Malicious Unmanned Air Vehicles Using Behavior Rule Specifications
abstract
In this paper, we propose an adaptive specification-based intrusion detection system (IDS) for detecting malicious unmanned air vehicles (UAVs) in an airborne system in which continuity of operation is of the utmost importance. An IDS audits UAVs in a distributed system to determine if the UAVs are functioning normally or are operating under malicious attacks. We investigate the impact of reckless, random, and opportunistic attacker behaviors (modes which many historical cyber attacks have used) on the effectiveness of our behavior rule-based UAV IDS (BRUIDS) which bases its audit on behavior rules to quickly assess the survivability of the UAV facing malicious attacks. Through a comparative analysis with the multiagent system/ant-colony clustering model, we demonstrate a high detection accuracy of BRUIDS for compliant performance. By adjusting the detection strength, BRUIDS can effectively trade higher false positives for lower false negatives to cope with more sophisticated random and opportunistic attackers to support ultrasafe and secure UAV applications.
Robert Mitchell 0001, Ing-Ray Chen
IEEE Trans. Syst. Man Cybern. Syst.2
2013 Access Protocols in Data Partitioning Based Cloud Storage
abstract
Existing share access protocols require the client to retrieve all shares even for read accesses in order to achieve atomic semantics. In cloud storage with widely distributed servers, this implies significant communication latency (from client to the farthest server) and additional network traffic. In this paper, we consider a nearby share retrieval approach to improve read performance. We first analyze the impact of this approach on the consistency semantics. Then we present the nearby share retrieval (NSR) protocol that satisfies regular semantics and guarantees wait-free reads. Experimental results show that our protocol yields significantly better read performance than existing protocols. To further optimize the performance of read accesses, we setup experiments to analyze the performance impacts of the number of shares to be retrieved in one round. Experimental results show that for most of the data, using the least required number (the threshold number in (n, k) data partitioning schemes) yields the best performance. But for hot data (with high access rates), access more servers in one round can achieve better performance.
Yunqi Ye, Liangliang Xiao, Yinzi Chen, I-Ling Yen, Farokh B. Bastani, Ing-Ray Chen
IEEE CLOUD6
2013 Adaptive network management for countering selective capture in wireless sensor networks
abstract
We propose and analyze adaptive network management for countering selective capture which aims to compromise critical sensor nodes close to the base station in a wireless sensor network (WSN) to block data delivery. We consider 3 countermeasures in the protocol design: (1) dynamic radio range adjustment; (2) multisource multipath routing for intrusion tolerance; and (3) voting-based intrusion detection. We identify the best protocol settings in terms of the best redundancy level used for multisource multipath routing, and the best number of voters and the intrusion invocation interval used for intrusion detection under which the lifetime of a WSN is maximized in the presence of selective capture which turns nodes into malicious nodes capable of performing packet dropping attacks and bad-mouthing attacks.
Hamid Al-Hamadi, Ing-Ray Chen
CNSM2
2013 Trust-Based Multi-objective Optimization for Node-to-Task Assignment in Coalition Networks
abstract
A temporary coalition is often formed to pursue a common goal based on the collaboration of multiple partners who may have their own objectives. The coalition network must attain multiple objectives, under resource constraints and time deadlines. We propose a task assignment algorithm for a scenario where tasks are dynamic, with different arrival times and deadlines. We propose a heuristic coalition formation technique that uses multiple dimensions of trust (i.e., integrity, competence, social connectedness, and reciprocity) to assess trust of each entity. The proposed scheme enables task leaders to make critical assignment decisions based on assessed trustworthiness of entities. We consider three different objectives, namely, maximizing resilience and resource utilization while minimizing delay to task completion. We devise a ranking-based heuristic with linear runtime complexity to select members based on risk derived from trust assessment of nodes. We validate the performance of our proposed scheme by comparing our scheme with a non-trust-based baseline scheme as well as a global optimal solution implemented with the Integer Linear Programming technique.
Jin-Hee Cho, Ing-Ray Chen, Kevin S. Chan
ICPADS2
2013 Dual-Region Location Management for Mobile Ad Hoc Networks
abstract
We propose and analyze a novel location management scheme for mobile ad hoc networks (MANETs) called Dual-region Mobility Management (DrMoM). The basic design concept of DrMoM is to use local regions to complement existing location services in MANETs that assign home regions to mobile nodes and have mobile nodes in the home region of a mobile node serve as location servers for that node. DrMoM is based on the design notion of integrated mobility and service management for network cost minimization. Specifically, unlike existing location services that define the home region size statically at design time for all mobile users, DrMoM dynamically determines the optimal home region size and local region size per mobile user based on mobility and service characteristics of individual mobile nodes to minimize the overall network cost incurred by location management and data packet delivery. We develop a performance model to derive the optimal values of these two key design parameters under which the overall network cost incurred by DrMoM is minimized. Through a comparative performance study, we show that DrMoM outperforms a well-known scheme called SLURP based on static home regions as well as a region-based location management scheme called RUDLS which claims to outperform contemporary region-based location management schemes.
Yinan Li 0002, Ing-Ray Chen, Ding-Chau Wang
ICPADS2
2013 Dynamic multisource multipath routing for intrusion tolerance and lifetime maximization of autonomous wireless sensor networks
abstract
Multisource multipath data routing to a remote sink node is an effective way to cope with unreliable and malicious nodes in autonomous wireless sensor networks (WSNs). In this paper we analyze the optimal amount of redundancy in terms of the number of source sensors sensing the same physical phenomena and the number of paths through which data are routed to a remote sink node in the presence of unreliable and malicious nodes so that the query success probability is maximized while maximizing the sensor network lifetime. Our dynamic multisource multipath routing algorithm design integrates with a voting-based distributed intrusion detection algorithm to remove malicious nodes from the sensor network. By controlling the redundancy level for multisource multipath and intrusion detection settings dynamically with energy considerations as prescribed by our algorithm, we demonstrate that the lifetime of a query-based autonomous WSN is maximized in response to changing environment conditions including node density, radio range, and node capture rate.
Hamid Al-Hamadi, Ing-Ray Chen
ISADS2
2013 Scalable, adaptive and survivable trust management for community of interest based Internet of Things systems
abstract
An Internet of Things (IoT) system connects a large amount of tags, sensors, and mobile devices to facilitate information sharing, enabling a variety of attractive applications. It challenges the design and evaluation of IoT systems to meet the scalability, compatibility, extendibility, dynamic adaptability and resiliency requirements. In this paper, we design and evaluate a scalable, adaptive and survivable trust management protocol in dynamic IoT environments. Recognizing that entities in an IoT system are connected through social networks of entity owners, we consider a community of interest (CoI) based social IoT where nodes form into communities of interest. Given inter-CoI vs. intra-CoI social connections among entity owners as input, we identify best trust protocol settings for achieving convergence, accuracy, dynamic adaptability and resiliency properties in the presence of dynamically changing conditions and malicious nodes performing trust-related attacks. For scalability, we consider a design by which a node only keeps trust information of a subset of nodes meeting its interest and performs minimum computation to update trust. We validate our design by extensive simulation considering both limited and ideal (unlimited) storage space. The results demonstrate that our trust management protocol using limited storage space achieves a similar performance level compared with the one under ideal storage space, and a newly joining node can quickly build up trust towards other nodes with desirable accuracy and convergence behavior.
Fenye Bao, Ing-Ray Chen
ISADS2
2013 On the tradeoff between altruism and selfishness in MANET trust management
Jin-Hee Cho, Ing-Ray Chen
Ad Hoc Networks2
2013 Dynamic agent-based hierarchical multicast for wireless mesh networks
Yinan Li 0002, Ing-Ray Chen
Ad Hoc Networks2
2013 Hierarchical agent-based secure and reliable multicast in wireless mesh networks
Yinan Li 0002, Ing-Ray Chen
Comput. Commun.2
2013 Redundancy Management of Multipath Routing for Intrusion Tolerance in Heterogeneous Wireless Sensor Networks
abstract
In this paper we propose redundancy management of heterogeneous wireless sensor networks (HWSNs), utilizing multipath routing to answer user queries in the presence of unreliable and malicious nodes. The key concept of our redundancy management is to exploit the tradeoff between energy consumption vs. the gain in reliability, timeliness, and security to maximize the system useful lifetime. We formulate the tradeoff as an optimization problem for dynamically determining the best redundancy level to apply to multipath routing for intrusion tolerance so that the query response success probability is maximized while prolonging the useful lifetime. Furthermore, we consider this optimization problem for the case in which a voting-based distributed intrusion detection algorithm is applied to detect and evict malicious nodes in a HWSN. We develop a novel probability model to analyze the best redundancy level in terms of path redundancy and source redundancy, as well as the best intrusion detection settings in terms of the number of voters and the intrusion invocation interval under which the lifetime of a HWSN is maximized. We then apply the analysis results obtained to the design of a dynamic redundancy management algorithm to identify and apply the best design parameter settings at runtime in response to environment changes, to maximize the HWSN lifetime.
Hamid Al-Hamadi, Ing-Ray Chen
IEEE Trans. Netw. Serv. Manag.2
2013 Effect of Intrusion Detection and Response on Reliability of Cyber Physical Systems
abstract
In this paper we analyze the effect of intrusion detection and response on the reliability of a cyber physical system (CPS) comprising sensors, actuators, control units, and physical objects for controlling and protecting a physical infrastructure. We develop a probability model based on stochastic Petri nets to describe the behavior of the CPS in the presence of both malicious nodes exhibiting a range of attacker behaviors, and an intrusion detection and response system (IDRS) for detecting and responding to malicious events at runtime. Our results indicate that adjusting detection and response strength in response to attacker strength and behavior detected can significantly improve the reliability of the CPS. We report numerical data for a CPS subject to persistent, random and insidious attacks with physical interpretations given.
Robert Mitchell 0001, Ing-Ray Chen
IEEE Trans. Reliab.2
2012 An integrated framework for spatio-temporal-textual search and mining
abstract
This paper presents an integrated framework for Spatio-Temporal-Textual (STT) information retrieval and knowledge discovery system. The proposed ensemble framework contains an efficient STT search engine with multiple indexing, ranking and scoring schemes, an effective STT pattern miner with Spatio-Temporal (ST) analytics, and novel STT topic modeling. Specifically, we design an effective prediction prototype with a third-order linear regression model, and present an innovative STT topic modeling relevance ranker to score documents based on inherent STT features under topical space. We demonstrate the framework with a crime dataset from the Washington, DC area from 2006 to 2010 and a global terrorism dataset from 2004 to 2010.
Bingsheng Wang, Haili Dong, Arnold P. Boedihardjo, Chang-Tien Lu, Harland Yu, Ing-Ray Chen
SIGSPATIAL/GIS6
2012 Behavior Rule Based Intrusion Detection for Supporting Secure Medical Cyber Physical Systems
abstract
In this paper we propose a behavior-rule specification-based intrusion detection (BSID) technique of medical devices (sensors or actuators) embedded in a medical cyber physical system (MCPS) in which the patient's safety is of the utmost importance. We investigate the impact of attacker behaviors on the effectiveness of our malware detection technique. Using vital sign monitor medical devices as an example, we demonstrate that our intrusion detection technique can effectively trade false positives for a high detection probability to cope with more sophisticated and hidden attackers to support ultra safe and secure MCPS applications.
Robert Mitchell 0001, Ing-Ray Chen
ICCCN2
2012 Energy vs. QoS Tradeoff Analysis of Multipath Routing Protocols for Intrusion Tolerance in Heterogeneous Wireless Sensor Networks
abstract
In this paper we analyze the tradeoff between energy consumption vs. Quality of Service (QoS) gain in reliability, timeliness, and security in heterogeneous wireless sensor networks (HWSNs) utilizing multipath routing to answer user queries in the presence of unreliable and malicious nodes. We formulate the tradeoff as an optimization problem for determining the best redundancy level to apply to multipath routing so that the query response success probability is maximized while prolonging the sensor network lifetime. We consider the optimization problem for the case in which a voting-based distributed intrusion detection algorithm is applied to detect and evict malicious nodes of various types in a HWSN. We identify the optimal redundancy level and intrusion detection setting under which the HWSN lifetime is maximized while satisfying the QoS requirements of query responses in reliability, timeliness and security.
Hamid Al-Hamadi, Ing-Ray Chen
ISPA2
2012 Trust management for the internet of things and its application to service composition
abstract
The Internet of Things (IoT) integrates a large amount of everyday life devices from heterogeneous network environments, bringing a great challenge into security and reliability management. Recognizing that the smart objects in IoT are most likely human-carried or human-operated devices, we propose a scalable trust management protocol for IoT, with the emphasis on social relationships. We consider multiple trust properties including honesty, cooperativeness, and community-interest to account for social interaction. Each node performs trust evaluation towards a limited set of devices of its interest only. The trust management protocol is event-driven upon the occurrence of a social encounter or interaction event, and trust is aggregated using both direct observations and indirect recommendations. We analyze the effect of trust parameters on trust assessment accuracy and trust convergence time. Our results show that there exists a trade-off between trust assessment accuracy vs. trust convergence time in the presence of false recommendations attacks performed by malicious nodes. We demonstrate the effectiveness of the proposed trust management protocol with a trust-based service composition application. Our results indicate that trust-based service composition significantly outperforms non-trust-based (random) service composition and its performance approaches the maximum achievable performance with global knowledge.
Fenye Bao, Ing-Ray Chen
WOWMOM2
2012 Modeling and analysis of trust management with trust chain optimization in mobile ad hoc networks
Jin-Hee Cho, Ananthram Swami, Ing-Ray Chen
J. Netw. Comput. Appl.3
2012 Hierarchical Trust Management for Wireless Sensor Networks and its Applications to Trust-Based Routing and Intrusion Detection
abstract
We propose a highly scalable cluster-based hierarchical trust management protocol for wireless sensor networks (WSNs) to effectively deal with selfish or malicious nodes. Unlike prior work, we consider multidimensional trust attributes derived from communication and social networks to evaluate the overall trust of a sensor node. By means of a novel probability model, we describe a heterogeneous WSN comprising a large number of sensor nodes with vastly different social and quality of service (QoS) behaviors with the objective to yield "ground truth" node status. This serves as a basis for validating our protocol design by comparing subjective trust generated as a result of protocol execution at runtime against objective trust obtained from actual node status. To demonstrate the utility of our hierarchical trust management protocol, we apply it to trust-based geographic routing and trust-based intrusion detection. For each application, we identify the best trust composition and formation to maximize application performance. Our results indicate that trust-based geographic routing approaches the ideal performance level achievable by flooding-based routing in message delivery ratio and message delay without incurring substantial message overhead. For trust-based intrusion detection, we discover that there exists an optimal trust threshold for minimizing false positives and false negatives. Furthermore, trust-based intrusion detection outperforms traditional anomaly-based intrusion detection approaches in both the detection probability and the false positive probability.
Fenye Bao, Ing-Ray Chen, Moonjeong Chang, Jin-Hee Cho
IEEE Trans. Netw. Serv. Manag.2
2012 Mobility Management in Wireless Mesh Networks Utilizing Location Routing and Pointer Forwarding
abstract
We propose and analyze LMMesh: a routing-based location management scheme with pointer forwarding for wireless mesh networks. LMMesh integrates routing-based location update and pointer forwarding by exploiting the advantages of both methods, while avoiding their drawbacks. It considers the effect of the integration on the overall network cost incurred by location management and packet delivery. By exploring the tradeoff between the service cost for packet delivery and the signaling cost for location management, LMMesh identifies the optimal protocol setting that minimizes the overall network cost on a per-user basis for each individual mesh client, when given a set of parameter values characterizing the specific mobility and service characteristics of the mesh client. We develop an analytical model based on stochastic Petri net techniques for analyzing the performance of LMMesh and a computational procedure for calculating the overall network cost. Through a comparative performance study, we show that LMMesh outperforms both pure routing-based location management schemes and pure pointer forwarding schemes, as well as traditional tunnel-based location management schemes.
Yinan Li 0002, Ing-Ray Chen
IEEE Trans. Netw. Serv. Manag.2
2011 CROWDSAFE: crowd sourcing of crime incidents and safe routing on mobile devices
abstract
Crowd sourcing is based on a simple but powerful concept: Virtually anyone has the potential to plug in valuable information. The concept revolves around large groups of people or community handling tasks that have traditionally been associated with a specialist or small group of experts. With the advent of the smart devices, many mobile applications are already tapping into crowd sourcing to report community issues and traffic problems, but more can be done. While most of these applications work well for the average user, it neglects the information needs of particular user communities. We present CROWDSAFE, a novel convergence of Internet crowd sourcing and portable smart devices to enable real time, location based crime incident searching and reporting. It is targeted to users who are interested in crime information. The system leverages crowd sourced data to provide novel features such as a Safety Router and value added crime analytics. We demonstrate the system by using crime data in the metropolitan Washington DC area to show the effectiveness of our approach. Also highlighted is its ability to facilitate greater collaboration between citizens and civic authorities. Such collaboration shall foster greater innovation to turn crime data analysis into smarter and safe decisions for the public.
Sumit Shah, Fenye Bao, Chang-Tien Lu, Ing-Ray Chen
GIS4
2011 Trust-Based Intrusion Detection in Wireless Sensor Networks
abstract
We propose a trust-based intrusion detection scheme utilizing a highly scalable hierarchical trust management protocol for clustered wireless sensor networks. Unlike existing work, we consider a trust metric considering both quality of service (QoS) trust and social trust for detecting malicious nodes. By statistically analyzing peer-to-peer trust evaluation results collected from sensor nodes, each cluster head applies trust-based intrusion detection to assess the trustworthiness and maliciousness of sensor nodes in its cluster. Cluster heads themselves are evaluated by the base station. We develop an analytical model based on stochastic Petri nets for performance evaluation of the proposed trust-based intrusion detection scheme, as well as a statistical method for calculating the false alarm probability. We analyze the sensitivity of false alarms with respect to the minimum trust threshold below which a node is considered malicious. Our results show that there exists an optimal trust threshold for minimizing false positives and false negatives. Further, the optimal trust threshold differs depending on the anticipated wireless sensor network lifetime.
Fenye Bao, Ing-Ray Chen, Moonjeong Chang, Jin-Hee Cho
ICC2
2011 Hierarchical Agent-Based Secure Multicast for Wireless Mesh Networks
abstract
We propose and analyze a hierarchical agent-based secure multicast (HASM) algorithm for efficiently supporting secure mobile multicast in wireless mesh networks, with design considerations given to minimize the overall network cost incurred by multicast packet delivery, mobility management, security key management, and group membership maintenance. HASM dynamically maintains a group of multicast agents running on mesh routers for integrated mobility and multicast service management and leverages a hierarchical multicast structure for efficient multicast packet delivery. The regional service size of each multicast agent is a key design parameter. We demonstrate via model-based analysis that their exists an optimal regional service size that minimizes the overall communication cost. Through a comparative performance study, we demonstrate that HASM under optimal settings significantly outperforms traditional algorithms based on shortest-path trees and static agent-based multicasting extended with mobility management and security support.
Yinan Li 0002, Ing-Ray Chen
ICC2
2011 Survivability analysis of mobile cyber physical systems with voting-based intrusion detection
abstract
In this paper we address the survivability issue of a mobile cyber physical system (MCPS) comprising sensor-carried human actors, vehicles, or robots assembled together for executing a specific mission in battlefield or emergency response situations. We develop a mathematical model to assess the survivability property of a MCPS subject to energy exhaustion and security failure. Our model-based analysis reveals the optimal design setting for invoking intrusion detection to best balance energy conservation vs. intrusion tolerance for achieving high survivability. We test the effectiveness of our approach with a dynamic voting-based intrusion detection technique leveraging sensing and ranging capabilities of mobile nodes in the MCPS and demonstrate its validity with numerical data.
Robert Mitchell 0001, Ing-Ray Chen
IWCMC2
2011 A hierarchical performance model for intrusion detection in cyber-physical systems
abstract
In this paper we develop a generic hierarchical model for performance analysis of intrusion detection techniques as applied to a cyber-physical system (CPS) consisting of mobile nodes with navigation, manipulation, sensing and actuating capability. We develop two intrusion detection techniques, namely, positional discontinuity and enviroconsistency, for intrusion detection of malicious attackers in a CPS. We utilize the hierarchical model developed to analyze the performance characteristics of these two techniques and identify optimal design settings under which the reliability of the CPS may be maximized. The analysis reveals design tradeoffs in security assurance and energy consumption, and suggests that enviroconsistency be used over positional discontinuity for reliability maximization. Numerical results with physical interpretations are given to demonstrate the effectiveness of our approach.
Robert Mitchell 0001, Ing-Ray Chen
WCNC2
2011 Adaptive per-user per-object cache consistency management for mobile data access in wireless mesh networks
Yinan Li 0002, Ing-Ray Chen
J. Parallel Distributed Comput.2
2011 Performance analysis of hierarchical group key management integrated with adaptive intrusion detection in mobile ad hoc networks
Jin-Hee Cho, Ing-Ray Chen
Perform. Evaluation2
2011 Adaptive Fault-Tolerant QoS Control Algorithms for Maximizing System Lifetime of Query-Based Wireless Sensor Networks
abstract
Data sensing and retrieval in wireless sensor systems have a widespread application in areas such as security and surveillance monitoring, and command and control in battlefields. In query-based wireless sensor systems, a user would issue a query and expect a response to be returned within the deadline. While the use of fault tolerance mechanisms through redundancy improves query reliability in the presence of unreliable wireless communication and sensor faults, it could cause the energy of the system to be quickly depleted. Therefore, there is an inherent trade-off between query reliability versus energy consumption in query-based wireless sensor systems. In this paper, we develop adaptive fault-tolerant quality of service (QoS) control algorithms based on hop-by-hop data delivery utilizing “source” and “path” redundancy, with the goal to satisfy application QoS requirements while prolonging the lifetime of the sensor system. We develop a mathematical model for the lifetime of the sensor system as a function of system parameters including the “source” and “path” redundancy levels utilized. We discover that there exists optimal “source” and “path” redundancy under which the lifetime of the system is maximized while satisfying application QoS requirements. Numerical data are presented and validated through extensive simulation, with physical interpretations given, to demonstrate the feasibility of our algorithm design.
Ing-Ray Chen, Anh Phan Speer, Mohamed Eltoweissy
IEEE Trans. Dependable Secur. Comput.1
2011 Design and Performance Analysis of Mobility Management Schemes Based on Pointer Forwarding for Wireless Mesh Networks
abstract
We propose efficient mobility management schemes based on pointer forwarding for wireless mesh networks (WMNs) with the objective to reduce the overall network traffic incurred by mobility management and packet delivery. The proposed schemes are per-user-based, i.e., the optimal threshold of the forwarding chain length that minimizes the overall network traffic is dynamically determined for each individual mobile user, based on the user's specific mobility and service patterns. We develop analytical models based on stochastic Petri nets to evaluate the performance of the proposed schemes. We demonstrate that there exists an optimal threshold of the forwarding chain length, given a set of parameters characterizing the specific mobility and service patterns of a mobile user. We also demonstrate that our schemes yield significantly better performance than schemes that apply a static threshold to all mobile users. A comparative analysis shows that our pointer forwarding schemes outperform routing-based mobility management protocols for WMNs, especially for mobile Internet applications characterized by large traffic asymmetry for which the downlink packet arrival rate is much higher than the uplink packet arrival rate.
Yinan Li 0002, Ing-Ray Chen
IEEE Trans. Mob. Comput.2
2010 Trust Management for Encounter-Based Routing in Delay Tolerant Networks
abstract
We propose and analyze a class of trust management protocols for encounter-based routing in delay tolerant networks (DTNs). The underlying idea is to incorporate trust evaluation in the routing protocol, considering not only quality-of-service (QoS) trust properties (connectivity) but also social trust properties (honesty and unselfishness) to evaluate other nodes encountered. Two versions of trust management protocols are considered: an equal-weight QoS and social trust management protocol (called trust-based routing) and a QoS only trust management protocol (called connectivity-based routing). By utilizing a stochastic Petri net model describing a DTN behavior, we analyze the performance characteristics of these two routing protocols in terms of message delivery ratio, latency, and message overhead. We also perform a comparative performance analysis with epidemic routing for a DTN consisting of heterogeneous mobile nodes with vastly different social and networking behaviors. The results indicate that trust-based routing approaches the ideal performance of epidemic routing in delivery ratio, while connectivity-based routing approaches the ideal performance in message delay of epidemic routing, especially as the percentage of selfish and malicious nodes present in the DTN system increases. By properly selecting weights associated with QoS and social trust metrics for trust evaluation, our trust management protocols can approximate the ideal performance obtainable by epidemic routing in delivery ratio and message delay without incurring high message overhead.
Ing-Ray Chen, Fenye Bao, Moonjeong Chang, Jin-Hee Cho
GLOBECOM1
2010 APPCCM: Adaptive per-user per-object cache consistency management for mobile client-server applications in wireless mesh networks
abstract
In this paper, we propose and analyze APPCCM: an adaptive per-user per-object cache consistency management scheme for mobile Internet client-server applications in wireless mesh networks (WMNs). The objective of the proposed scheme is two-fold: to speedup data access and to mitigate the performance bottleneck at WMN gateways. In our proposed adaptive scheme, a data object can be cached at the mesh client (MC) directly or at a mesh router (MR) dynamically selected by APPCCM, such that the overall network cost incurred for the WMN to process the MC's mobility and data access/update events is minimized. APPCCM is adaptive, per-user and per-object as the decision of where to cache a data object accessed by an MC depends on the MC's mobility and object access/update characteristics, and the WMN conditions. We demonstrate via model-based analysis that APPCCM outperforms non-adaptive schemes that always cache a data object at the MC, or at the MC's current serving MR for cache consistency management in WMNs.
Yinan Li 0002, Ing-Ray Chen
LCN2
2010 Cross-layer integrated mobility and service management utilizing smart routers in mobile IPv6 systems
abstract
In this paper we model and analyze a cross-layer integrated mobility and service management scheme called DMAPwSR in Mobile IPv6 environments with the goal to minimize the overall mobility and service management cost for serving mobile users with diverse mobility and service characteristics. The basic idea of DMAPwSR is that each mobile node (MN) can utilize its application-layer knowledge to choose smart routers to be its dynamic mobility anchor points (DMAPs) to balance the cost associated with mobility services vs. packet delivery services. These smart routers are just access routers for MIPv6 systems except that they are capable of processing binding messages from the MN and storing the current location of the MN in the routing table for forwarding service packets destined to the MN. The MN's DMAP changes dynamically as the MN roams across the MIPv6 network. Furthermore the DMAP service area also changes dynamically reflecting the MN's mobility and service behaviors dynamically. Unlike previous mobility management protocols such as HMIPv6 that focus only on mobility management, DMAPwSR considers integrated mobility and service management. We develop an analytical model based on stochastic Petri nets to analyze DMAPwSR and compare its performance against MIPv6 and HMIPv6. We validate analytical solutions obtained through extensive simulation including sensitivity analysis of simulation results with respect to the network coverage model, the MN's residence time distribution and the DMAP service area definition.
Weiping He, Ing-Ray Chen, Ding-Chau Wang
MoMM2
2010 Reliability of wireless sensors with code attestation for intrusion detection
Ing-Ray Chen, Ding-Chau Wang
Inf. Process. Lett.1
2010 Effect of Intrusion Detection on Reliability of Mission-Oriented Mobile Group Systems in Mobile Ad Hoc Networks
abstract
For mission-oriented mobile group systems designed to continue mission execution in hostile environments in the presence of security attacks, it is critical to properly deploy intrusion detection techniques to cope with insider attacks to enhance the system reliability. In this paper, we analyze the effect of intrusion detection system (IDS) techniques on the reliability of a mission-oriented group communication system consisting of mobile groups set out for mission execution in mobile ad hoc networks. Unlike the common belief that IDS should be executed as often as possible to cope with insider attacks to prolong the system lifetime, we discover that IDS should be executed at an optimal rate to maximize the mean time to failure of the system. Further, the optimal rate at which IDS is executed depends on the operational conditions, system failure definitions, attacker behaviors, and IDS techniques used. We develop mathematical models based on Stochastic Petri nets to identify the optimal rate for IDS execution to maximize the mean time to failure of the system, when given a set of parameter values characterizing the operational conditions, and attacker behaviors.
Jin-Hee Cho, Ing-Ray Chen, Phu-Gui Feng
IEEE Trans. Reliab.2
2010 Modeling and analysis of intrusion detection integrated with batch rekeying for dynamic group communication systems in mobile ad hoc networks
Jin-Hee Cho, Ing-Ray Chen
Wirel. Networks2
2009 Comparative Performance Analysis of CAC Reward Optimization Algorithms in Wireless Networks
abstract
In this paper, we perform a comparative analysis of a set of call admission control (CAC) algorithms designed for servicing multiple priority classes in wireless networks with quality of service (QoS) guarantees. We evaluate the performance of partitioning, threshold-based, spillover, and elastic-threshold CAC algorithms in terms of the maximum number of mobile users the system is able to support with QoS satisfaction while maximizing the "reward" obtainable from servicing multiple priority classes with distinct QoS requirements. We compare these algorithms thoroughly with test cases generated through a combination of user workload, mobility, location, and population. We verify analytical results via simulation validation using real mobility trace data to model user mobility. We also analyze the tradeoff between solution optimality vs. solution efficiency in designing CAC algorithms for reward optimization and QoS satisfaction when servicing multiple service classes with distinct QoS requirements in wireless networks.
Okan Yilmaz, Ing-Ray Chen
AINA2
2009 Dynamic adaptive redundancy for quality-of-service control in wireless sensor networks
abstract
In this paper, we develop and evaluate a new concept of adaptive optimal redundancy to efficiently provide wireless sensor network (WSN) users with QoS-aware information services. Our approach to satisfying application QoS requirements while maximizing the system lifetime is to determine dynamically the optimal level of redundancy at the ldquosourcerdquo and ldquopathrdquo levels in response to network dynamics and query QoS requirements on a query by query basis. We develop a mathematical model to analyze the performance characteristics of our proposed solution. The obtained results show that dynamically and adaptively identifying and managing optimal redundancy for per-hop data delivery lead to satisfying query QoS requirements in terms of reliability and timeliness, while maximizing the useful lifetime of WSNs. We validate the analytical results with extensive simulation.
Ing-Ray Chen, Anh Ngoc Speer, Mohamed Eltoweissy
IPDPS1
2009 Performance analysis of distributed intrusion detection protocols for mobile group communication systems
abstract
Under highly security vulnerable, resource restricted, and dynamically changing mobile ad hoc environments, it is critical to be able to maximize the system lifetime while bounding the communication response time for mission-oriented mobile groups. In this paper, we analyze the tradeoff of security versus performance for distributed intrusion detection protocols employed in mobile group communication systems (GCSs). We investigate a distributed voting-based intrusion detection protocol for GCSs in multi-hop mobile ad hoc networks and examine the effect of intrusion detection on system survivability measured by the mean time to security failure (MTTSF) metric and efficiency measured by the communication cost metric. We identify optimal design settings under which the MTTSF metric can be best traded off for the communication cost metric or vice versa.
Jin-Hee Cho, Ing-Ray Chen
IPDPS2
2009 Utilizing call admission control for pricing optimization of multiple service classes in wireless cellular networks
Okan Yilmaz, Ing-Ray Chen
Comput. Commun.2
2009 Elastic threshold-based admission control for QoS satisfaction with reward optimization for servicing multiple priority classes in wireless networks
Okan Yilmaz, Ing-Ray Chen
Inf. Process. Lett.2
2009 A proxy-based integrated cache consistency and mobility management scheme for client-server applications in Mobile IP systems
Weiping He, Ing-Ray Chen
J. Parallel Distributed Comput.2
2008 On QoS Guarantees with Reward Optimization for Servicing Multiple Priority Classes in Wireless Networks
abstract
We report performance characteristics of a class of call admission control (CAC) algorithms designed for servicing multiple priority classes in wireless networks with the goal of quality of service (QoS) satisfaction and reward optimization. By reward, we mean some sort of "value" obtained by the system as a result of servicing multiple priority classes. In this paper we design and evaluate the performance of anew algorithm, elastic threshold-based CAC, in terms of the maximum reward obtainable with QoS satisfaction from servicing multiple priority classes with distinct QoS requirements, and compare it with existing partitioning, threshold, and spillover CAC algorithms. We also develop a heuristic-based search method to determine the best threshold-value sets used for multiple service classes by sequentially adjusting these thresholds based on the total reward and rejection rate vs. QoS constraints of each service class. We demonstrate through test cases and simulation that elastic threshold-based CAC outperforms existing CAC algorithms for QoS satisfaction and reward optimization in solution optimality for serving multiple QoS service classes in wireless networks.
Okan Yilmaz, Ing-Ray Chen
ICCCN2
2008 Effect of intrusion detection on secure group communications in hierarchically structured group architectures
abstract
We develop a class of adaptive security protocols with designs to allow group communication systems (GCSs) in mobile ad hoc networks (MANETs) to dynamically adjust operational settings to best satisfy application-imposed performance and security requirements, leveraging the inherent tradeoff between security and performance properties of the system. These adaptive security protocols include an intrusion detection protocol for dealing with insider attacks and a scalable region-based hierarchical group key management protocol for dealing with outsider attacks. Our design settings include the time interval over which intrusion detection should be performed, and the regional area size for the region-based hierarchical group key management protocol for group key management. When given a set of parameter values characterizing operational and environmental conditions of a GCS, we identify optimal design settings to be used by the system dynamically to maximize the mean time to security failure of the system while minimizing the total group communication cost incurred for GCSs in MANET environments.
Jin-Hee Cho, Ing-Ray Chen
LCN2
2008 Effect of Intrusion Detection on Failure Time of Mission-Oriented Mobile Group Systems in Mobile Ad Hoc Networks
abstract
In this paper, we analyze the effect of intrusion detection system (IDS) techniques on failure time of a mission-oriented group communication system consisting of mobile groups set out for mission execution in mobile ad hoc networks. Unlike the common belief that IDS should be executed as often as possible to cope with insider attacks to prolong the system lifetime, we discover that IDS should be executed at an optimal rate in order to maximize the system lifetime. Further, the optimal rate at which IDS is executed depends on the operational conditions, system failure definitions, attacker behaviors, and IDS techniques used. We develop mathematical models based on stochastic petri nets to identify the optimal rate for IDS execution to maximize the mean time to security failure of the system, when given a set of parameter values characterizing the operational conditions and attacker behaviors.
Jin-Hee Cho, Ing-Ray Chen, Phu-Gui Feng
PRDC2
2008 Availability Analysis of Robotic Swarm Systems
abstract
Availability analysis is an important issue in robotic swarm systems. It can help the designer to construct a cost-effective system with high availability and fewer resources. For the model and analysis to be fully specified and practical, this paper systematically investigates the major issues that need to be addressed in the analysis of various robotic swarm applications. Four models are established to consider systems with dependent and independent robots, homogenous and non-homogenous systems, and the effect of various types of motions on the overall system failure pattern. Detailed analysis of each of these models is performed based on renewal theory and continuous Markov Chain techniques. Numerical availability evaluations for two applications are also presented.
Yansheng Zhang, Farokh B. Bastani, I-Ling Yen, Jicheng Fu, Ing-Ray Chen
PRDC5
2008 Movement-based checkpointing and logging for failure recovery of database applications in mobile environments
Sapna E. George, Ing-Ray Chen
Distributed Parallel Databases2
2008 Proxy-based hybrid cache management in Mobile IP systems
Weiping He, Ing-Ray Chen
Inf. Process. Lett.2
2008 Performance optimization of region-based group key management in mobile ad hoc networks
Jin-Hee Cho, Ing-Ray Chen, Ding-Chau Wang
Perform. Evaluation2
2008 On optimal batch rekeying for secure group communications in wireless networks
Jin-Hee Cho, Ing-Ray Chen, Mohamed Eltoweissy
Wirel. Networks2
2007 A Proxy-Based Integrated Cache Consistency and Mobility Management Scheme for Mobile IP Systems
abstract
In this paper, we investigate a proxy-based integrated cache consistency and mobility management scheme in mobile IP systems. Our scheme is based on a stateful strategy by which cache invalidation messages are asynchronously sent by the server to a mobile host (MH) whenever data objects cached at the MH have been updated. We use a per-user proxy to buffer invalidation messages to allow the MH to disconnect arbitrarily and to reduce the number of uplink requests when the MH is reconnected. Moreover, the MH's proxy serves as a gateway foreign agent (GFA) as in the MIP Regional Registration protocol to keep track of the address of the MH in a region. The proxy migrates with the MH when the MH crosses a regional area. We identify the optimal regional area size under which the overall network traffic cost, due to cache consistency management, mobility management, and query requests/replies, is minimized. We demonstrate that the integrated cache consistency and mobility management scheme outperforms both no-proxy and/or no-cache schemes in Mobile IPv6 environments.
Weiping He, Ing-Ray Chen, Baoshan Gu
AINA2
2007 Modeling and analysis of regional registration based mobile multicast service management
abstract
We propose and analyze a regional registration based mobile multicast service management scheme which we call URRMoM for efficiently supporting mobile multicast in Mobile IP networks. URRMoM extends the design concept of Remote Subscription (RS) by using mobile multicast agents (MMAs), each covering a number of MHs in its service area through tunneling multicast packets received from the multicast source to them. URRMoM adopts a user-central design allowing each mobile host to determine its optimal MMA service area dynamically depending on its service and mobility characteristics. We develop an analytical model to describe the behavior of a MH operating under URRMoM and derive the optimal service area of the MMA based on the MH’s service and mobility characteristics to minimize the total network traffic generated due to multicast packet delivery and multicast tree maintenance. We demonstrate the benefit of our proposed regional registration based mobile multicast service management scheme over existing schemes including RS and RBMoM.
Ing-Ray Chen, Ding-Chau Wang
ICPADS1
2007 Proxy-based Regional Registration for Integrated Mobility and Service Management in Mobile IP Systems
abstract
We propose and analyse a proxy-based regional registration scheme for integrated mobility and service management with the goal to minimize the network signaling and packet delivery cost in Mobile Internet Protocol (MIP) systems. Under the proposed proxy-based regional registration scheme, a client-side proxy is created on a per-user basis to serve as a gateway between a mobile node (MN) and all services engaged by the MN. From the perspective of these services, the proxy behaves as if it were the MN. From the perspective of the MN, the proxy behaves as if it were the services. Leveraging MIP with route optimization, the proxy runs on a foreign agent node and cooperates with the home agent and foreign agents of the MN in the MIP network to maintain the location information of the MN in order to facilitate data delivery by services engaged by the MN. Further the proxy can optimally determine when to move with the MN so as to minimize the network cost associated with the user's mobility and service management. We investigate the notion of ‘service areas’ for the proxy to perform ‘service handoffs’ in our scheme. We show that, when given a set of parameters characterizing the operational and workload conditions of an MN, there exists an optimal service area size for the MN such that the network communication cost is minimized for serving mobility and service management operations of the MN. We demonstrate via Petri net modeling and analysis that our proposed scheme outperforms both basic MIP and MIP regional registration that do not consider integrated mobility and service management.
Ing-Ray Chen, Weiping He, Baoshan Gu
Comput. J.1
2007 Effect of redundancy on the mean time to failure of wireless sensor networks
abstract
Abstract In data‐driven wireless sensor networks (WSNs), the system must perform data sensing and retrieval and possibly aggregate data as a response at runtime. As a WSN is often deployed unattended in areas where replacements of failed sensors are difficult, energy conservation is of primary concern. While the use of redundancy is desirable in terms of satisfying user queries to cope with sensor and transmission faults, it may adversely shorten the lifetime of the WSN, as more sensor nodes will have to be used to answer queries, causing the energy of the system to drain quickly. In this paper, we analyze the effect of redundancy on the mean time to failure (MTTF) of a WSN in terms of the number of queries the system is able to answer correctly before it fails due to either sensor/transmission faults or energy depletion. In particular, we analyze the effect of redundancy on the MTTF of cluster‐structured WSNs for energy conservations. We show that a tradeoff exists between redundancy and MTTF. Furthermore, an optimal redundancy level exists such that the MTTF of the system is maximized. Copyright © 2007 John Wiley & Sons, Ltd.
Anh Phan Speer, Ing-Ray Chen
Concurr. Comput. Pract. Exp.2
2006 Effect of Redundancy on Mean Time to Failure of Wireless Sensor Networks
abstract
In query-based wireless sensor networks (WSNs), the system must perform data sensing and retrieval and possibly aggregate data as a response at runtime. Since a WSN is often deployed unattended in areas where replacements of failed sensors are difficult, energy conservation is of primary concern. While the use of redundancy is desirable in terms of satisfying user queries to cope with sensor faults, it may adversely shorten the lifetime of the WSN, as more sensor nodes will have to be used to answer queries, causing the energy of the system to drain quickly. In this paper, we analyze the effect of redundancy on the mean time to failure (MTTF) of a WSN in terms of the number of queries the system is able to answer correctly before it fails due to either sensor faults or energy depletion. In particular, we analyze their effect of redundancy on the MTTF of cluster-structured WSN for energy conservations. We show that a tradeoff exists between redundancy and MTTF. Furthermore, an optimal redundancy level exists such that the MTTF of the system is maximized.
Anh Phan Speer, Ing-Ray Chen
AINA (2)2
2006 DMAP: A Scalable and Efficient Integrated Mobility and Service Management Scheme for Mobile IPv6 Systems
abstract
We investigate an integrated mobility and service management scheme based on MIPv6 with the goal to minimize the overall network signaling cost in MIPv6 systems for serving mobility and service management related operations. Our design extends hierarchical mobile IPv6 (HMIPv6) with the notion of dynamic mobility anchor points (DMAPs) for each mobile node (MN) instead of static ones for all MNs. These DMAPs are access routers (ARs) chosen by individual MNs to act as a regional router to reduce the signaling overhead for intra-regional movements. The DMAP domain size, i.e., the number of subnets covered by a DMAP, is based on the MN's mobility and service characteristics. Under our DMAP protocol, a MN optimally determines when and where to launch a DMAP to minimize the network cost in serving the user's mobility and service management operations. We demonstrate that our DMAP protocol for integrated mobility and service management yields significantly improved performance over basic MIPv6 and HMIPv6
Ing-Ray Chen, Weiping He, Baoshan Gu
LCN1
2006 On Optimal Path and Source Redundancy for Achieving QoS and Maximizing Lifetime of Query-Based Wireless Sensor Networks
abstract
Data sensing and retrieval in wireless sensor systems have a widespread application in areas such as security and surveillance monitoring, as well as command and control in battlefield situations. In query-based sensor systems, a user would issue a query with quality of service (QoS) requirements in terms of reliability and timeliness, and expect a response to be returned within the deadline. Satisfying these QoS requirements implies that fault tolerance mechanisms through redundancy will be used, which may cause the energy of the system to be quickly depleted. We develop a hop-by-hop data delivery mechanism in which we utilize "source" and "path" redundancy with the goal to satisfy application QoS requirements while maximizing the lifetime of the sensor system. When given QoS requirements of a query, we identify optimal "source" and "path" redundancy such that not only QoS requirements are satisfied, but also the lifetime of the system is prolonged. Numerical data are presented with physical interpretations given to demonstrate the feasibility of our approach.
Anh Phan Speer, Ing-Ray Chen
MASCOTS2
2006 High Assurance Software Systems
abstract
The last few decades are marked by an unprecedented increase in the complexity and consequence of information technology systems. High assurance software systems must satisfy basic functional service properties that the system intends to deliver, as well as guarantee desirable system properties such as security, safety, timeliness and reliability. Examples of high assurance software systems include command and control systems, nuclear power plants, electronic banking, aerospace systems, automated manufacturing and medical systems. One of the major challenges in high assurance software engineering is to develop well-founded methods for system construction, verification and validation, so they provide critical services with a high degree of confidence in their correctness and quality. The goal of the special issue is to bring together innovative research ideas and advances in the field of high assurance software systems to address these challenges. To this end, the guest editors invited six papers published in the 29th IEEE Annual International Computer Software and Applications Conference (COMPSAC 2005) in the conference theme of High Assurance Software Systems to submit to this special issue, from which four papers after a rigorous review process have been selected to appear in the special issue.
Ing-Ray Chen, Bojan Cukic
Comput. J.1
2006 On Integrated Location and Service Management for Minimizing Network Cost in Personal Communication Systems
abstract
We investigate the notion of per-user integrated location and service management in personal communication service (PCS) networks by which a per-user service proxy is created to serve as a gateway between the mobile user and all client-server applications engaged by the mobile user. The service proxy is always colocated with the mobile user's location database such that whenever the MU's location database moves during a location handoff, a service handoff also ensues to colocate the service proxy with the location database. This allows the proxy to know the location of the mobile user all the time to reduce the network communication cost for service delivery. We investigate four integrated location and service management schemes. Our results show that the centralized scheme performs the best when the mobile user's SMR (service to mobility ratio) is low and CMR (call to mobility ratio) is high, while the fully distributed scheme performs the best when both SMR and CMR are high. In all other conditions, the dynamic anchor scheme is the best except when the service context transfer cost is high, under which the static anchor scheme performs the best. Through analytical and simulation results, we demonstrate that different users with vastly different mobility and service patterns should adopt different integrated location and service management methods to optimize system performance. Further, the best integrated scheme always performs better than the best decoupled scheme that considers location and service managements separately and management schemes that do not use any service proxy.
Ing-Ray Chen, Baoshan Gu, Sheng-Tzong Cheng
IEEE Trans. Mob. Comput.1
2006 Filtering strategies for TFC selection schemes in 3GPP W-CDMA systems
abstract
The selection of a suitable transport format combination (TFC) according to the system load condition is one important issue of the radio resource management (RRM) in 3GPP W-CDMA systems. Different TFCs specify different ways of transmitting user data input from logical channels. It is observed that data transmission with a higher data rate will suffer a higher bit error rate (BER). This paper investigates the impact of BER on the selection of optimal TFC for transmitting the user data. Two filtering strategies are proposed to filter out infeasible TFCs so that the optimal TFC can be selected to achieve high performance. Moreover, an imbedded Markov chain is developed to evaluate the proposed strategies. From the simulation results, the feasibility and the effectiveness of the proposed strategies are demonstrated as well. We are suggesting that, for the design of an optimal TFC selection algorithm, the proposed TFC filtering strategy shall be taken into consideration.
Sheng-Tzong Cheng, Chun-Yen Wang, Ing-Ray Chen
IEEE Trans. Wirel. Commun.3
2006 Extending Proxy Caching Capability: Issues and Performance
Wei Hao 0001, Jicheng Fu, I-Ling Yen, Farokh B. Bastani, Ing-Ray Chen
World Wide Web6
2005 Performance Analysis of Location-Aware Mobile Service Proxies for Reducing Network Cost in Personal Communication Systems
Baoshan Gu, Ing-Ray Chen
Mob. Networks Appl.2
2005 Adaptive QoS Control Based on Benefit Optimization for Video Servers Providing Differentiated Services
Ing-Ray Chen, Sheng-Tun Li, I-Ling Yen
Multim. Tools Appl.1
2005 On failure recoverability of client-server applications in mobile wireless environments
abstract
Analytical results for the Cdf of the failure recovery time for client-server applications in mobile wireless environments characterized by logging, and mobility handoff strategies for facilitating failure recovery are reported in the paper. The results can be applied to determine if a mobile application can satisfy its recoverability requirement upon a mobile host failure when operating under a set of parameter values characterizing the mobile application, the underlying client-server environment, and the logging & mobility handoff strategies adopted by the mobile application. Model parameters which affect the shape of the failure recovery time Cdf for two mobility handoff strategies, namely, Eager and Lazy, are identified, and their effects are analyzed, with numerical data and result interpretations given. A tradeoff analysis between the cost invested by these two mobility handoff strategies for maintaining the logging and checkpoint information before failure versus the return of investment in terms of improved failure recoverability is given, and the best checkpoint interval period that would yield the best return of investment for the eager mobility handoff strategy over the lazy strategy is identified.
Ing-Ray Chen, Baoshan Gu, Sapna E. George, Sheng-Tzong Cheng
IEEE Trans. Reliab.1
2004 Performance Analysis of Location-Based Data Consistency Algorithms in Mobile Ad Hoc Networks
Ing-Ray Chen, Jeffery W. Wilson, Frank Driscoll, Karen Rigopoulos
ICPADS1
2004 Admission Control Algorithms Integrated with Pricing for Revenue Optimization with QoS Guarantees in Mobile Wireless Networks
Naresh Verma, Ing-Ray Chen
ICPADS2
2004 Survivable Systems Based on an Adaptive NMR Algorithm
abstract
Summary form only given. Due to the extensive use of computers and networks in critical systems, survivability is no longer a luxury but an essential requirement. We consider survivability assurance for critical applications where the system may incur accidental failures as well as intentional attacks. A successful attack can penetrate and compromise a pan of the system and, consequently, make the system behave like incurring a malicious failure. We model successful attacks as Byzantine failures and use the replication scheme to uniformly cope with failures and attacks. Instead of using conventional replication protocols that generally have a high overhead, we develop a novel coordination protocol, namely, adaptive NMR (ANMR) algorithm, to provide efficient coordination among replicated sites. Also, a special data partitioning technique is used with ANMR to assure confidentiality of the system even if it is partially compromised. Due to the adaptive nature, our ANMR algorithm reduces the communication overhead incurred in conventional NMR schemes. When there is no failure, the system operates at a very good performance. When failures occur, the system adapts to the NMR scheme gracefully.
Qingkai Ma, I-Ling Yen, Farokh B. Bastani, Ing-Ray Chen
IPDPS5
2004 Editorial: Mobile and Pervasive Computing
abstract
Ing-Ray Chen, Luiz DaSilva, Scott Midkiff; Editorial: Mobile and Pervasive Computing, The Computer Journal, Volume 47, Issue 4, 1 January 2004, Pages 404, https
Ing-Ray Chen, Luiz A. DaSilva, Scott F. Midkiff
Comput. J.1
2004 Analyzing reconfigurable algorithms for managing replicated data
Ing-Ray Chen, Ding-Chau Wang, Chih-Ping Chu
J. Syst. Softw.1
2004 Systematic Reliability Analysis of a Class of Application-Specific Embedded Software Frameworks
abstract
Dramatic advances in computer and communication technologies have made it economically feasible to extend the use of embedded computer systems to more and more critical applications. At the same time, these embedded computer systems are becoming more complex and distributed. As the bulk of the complex application-specific logic of these systems is realized by software, the need for certifying software systems has grown substantially. While relatively mature techniques exist for certifying hardware systems, methods of rigorously certifying software systems are still being actively researched. Possible certification methods for embedded software systems range from formal verification to statistical testing. These methods have different strengths and weaknesses and can be used to complement each other. One potentially useful approach is to decompose the specification into distinct aspects that can be independently certified using the method that is most effective for it. Even though substantial-research has been carried out to reduce the complexity of the software system through decomposition, one major hurdle is the need to certify the overall system on the basis of the aspect properties. One way to address this issue is to focus on architectures in which the aspects are relatively independent of each other. However, complex embedded systems are typically comprised of multiple architectures. We present an alternative approach based on the use of application-oriented-frameworks for implementing embedded systems. We show that it is possible to design such frameworks for embedded applications and derive expressions for determining the system reliability from the reliabilities of the framework and the aspects. The method is illustrated using a distributed multimedia collaboration system.
Farokh B. Bastani, I-Ling Yen, Ing-Ray Chen
IEEE Trans. Software Eng.4
2003 High-Assurance Synthesis of Security Services from Basic Microservices
abstract
Computer systems are vulnerable to many different types of threats ranging from harmless mistakes in data entries to malicious attacks by computer hackers. Furthermore, the explosive growth of the Internet has introduced very sophisticated ways of compromising any computer system. Consequently, a great deal of time and effort has been spent on achieving computer network security. Most of the efforts to deal with computer security have emphasized the network security aspect (i.e., the focus so far has been on intruders from outside the system). However, there also exists a significant threat from "enemies within", e.g. attacks due to malicious code embedded in the software. Whether it is intentional or not, there are many software bugs that can potentially be the source of the information misusages. One approach for dealing with this issue is to certify component security and deduce system security from its components. The advantage of this method is that it is much simpler to validate a small component as compared with a large monolithic software system. In this paper, we define a general process that allows the system security to be decomposed into orthogonal aspects so that it is possible to rigorously certify the security of a system. The approach is illustrated for the security service for an e-mail application.
Farokh B. Bastani, I-Ling Yen, Ing-Ray Chen
ISSRE4
2003 A Cost-Based Admission Control Algorithm for Digital Library Multimedia Systems Storing Heterogeneous Objects
abstract
We present and analyze a cost-based admission control algorithm for handling mixed workloads in modern multimedia systems such as a digital library multimedia system that must provide access services to heterogeneous objects stored in the library. The cost-based scheme considered in the paper is based on the concept of ‘rewards’ and ‘penalties’ associated with requests of various media object types. Instead of admitting object requests until resources are exhausted as a condition for admission control, resources are reserved to requests of different media types dynamically based on the cost-based scheme so that the system is capable of maximizing the total reward received by the system in response to workload changes in the environment. We analyze the maximum queue sizes for admitting discrete media requests to meet the imposed response-time constraints and for improving the total reward received by the system by exploiting leftover resources from servicing continuous media requests. A solution for the total reward obtainable is derived and validated via simulation.
Ing-Ray Chen, Naresh Verma
Comput. J.1
2003 Analyzing User-Perceived Dependability and Performance Characteristics of Voting Algorithms for Managing Replicated Data
Ing-Ray Chen, Ding-Chau Wang, Chih-Ping Chu
Distributed Parallel Databases1
2003 Performance evaluation of an admission control algorithm: dynamic threshold with negotiation
Sheng-Tzong Cheng, Chi-Ming Chen, Ing-Ray Chen
Perform. Evaluation3
2003 Quantitative Analysis of a Hybrid Replication with Forwarding Strategy for Efficient and Uniform Location Management in Mobile Wireless Networks
abstract
A location management scheme in wireless networks must effectively handle both user location update and search operations. Replication and forwarding are two well-known techniques to reduce user search and update costs, respectively, with replication being most effective when the call to mobility ratio (CMR) of the user is high, while forwarding is most effective when the CMR value is low. Thus, based on the user's CMR, the system can adopt a CMR threshold-based scheme such that if the user's CMR is lower than a threshold, then the system applies the forwarding scheme; otherwise, it applies the replication scheme. Applying different location management schemes based on per-user CMR values introduces undesirable high complexity in managing and maintaining location- related information stored in the system as different system support mechanisms must be applied to different users. In this paper, we quantitatively analyze a hybrid replication with forwarding scheme that can be uniformly applied to all users. The most striking feature of the hybrid scheme is that it can determine and apply the optimal number of replicas and forwarding chain length on a per-user basis to minimize the communication cost due to location management operations while still being able to use the same data structure and algorithm to execute location management operations in a uniform way for all users. We develop a stochastic Petri net model to help gather this information and show how the information obtained statically can be used efficiently by the system at runtime to determine the optimal number of replicas and forwarding chain length when given a use user's profile. We show that the proposed hybrid scheme outperforms both pure replication and forwarding schemes, as well as the CMR threshold-based scheme under all CMR values.
Ing-Ray Chen, Baoshan Gu
IEEE Trans. Mob. Comput.1
2002 Reliability Assessment of Framework-Based Distributed Embedded Software Systems
abstract
Distributed embedded software systems, such as sensor networks and command and control systems, are complex systems with stringent performance, reliability, security, and safety constraints. These are also long-lived systems that must be continually upgraded and evolved to incorporate enhanced functionality. One approach for achieving high quality and evolvability for these systems is to organize them in the form of application-oriented frameworks that allow the system to be composed from orthogonal aspects that can be independently developed, evolved, and certified. In this paper, we define a general framework that allows a distributed embedded system to have relatively independent aspects, including "plug-and-play" capability. We present conditions under which the reliability of the system can be inferred from the reliability of the individual aspects. The approach is illustrated for a framework-based distributed sensor network.
Farokh B. Bastani, I-Ling Yen, Ing-Ray Chen
ISSRE4
2002 A Comparative Cost Analysis of Degradable Location Management Algorithms in Wireless Networks
abstract
In this paper, we develop a uniform framework to provide a cost analysis of location update and search operations for a class of degradable location management algorithms in personal communication service (PCS) networks for tracking mobile users in the two-tier HLR (Home Location Register)–VLR (Visitor Location Register) structure. Depending on the algorithm employed, the PCS may be in a degraded state in maintaining the location of a mobile user. We classify existing location management algorithms based on how well the location information is maintained in terms of the costs associated with location updates and develop a two-level hierarchical modeling framework to analyze the performance characteristics of these algorithms. Specifically, the high-level model calculates the total cost incurred to the PCS network as a result of location-update and call-delivery operations during the period between two consecutive calls. The low-level model is a stochastic model that estimates the values of high-level model parameters. We show that by utilizing simple Markov models at the low level, we can assess and compare the performance characteristics of degradable location management algorithms easily. The basic scheme used in the standard IS-41 and GSM protocols, the paging and location updating algorithm (PLA), the forwarding and resetting algorithm (FRA) and the local anchoring algorithm (LAA) are used as examples to demonstrate the applicability of our approach. We also show how the modeling approach developed can be extended to the analysis of algorithms for handling service handoffs in the two-tier HLR–VLR architecture.
Ing-Ray Chen, Baoshan Gu
Comput. J.1
2002 A self-adjusting quality of service control scheme
Sheng-Tzong Cheng, Ing-Ray Chen
Inf. Process. Lett.2
2002 Algorithms for Supporting Disconnected Write Operations for Wireless Web Access in Mobile Client-Server Environments
abstract
In a wireless mobile client-server environment, a mobile user may voluntarily disconnect itself from the Web server to save its battery life and avoid high communication prices. To allow Web pages to be updated while the mobile user is disconnected from the Web server, updates can be staged in the mobile host and propagated back to the Web server upon reconnection. In this paper, we analyze algorithms for supporting disconnected write operations for wireless Web access and develop a performance model to identify the optimal length of the disconnection period under which the cost of update propagation is minimized. The analysis result is particularly applicable to Web applications which allow wireless mobile users to modify Web contents while on the move. We show how the result can be applied to real-time Web applications such that the mobile user can determine the longest disconnection period such that it can still propagate updates to the server before the deadline so that a minimum communication cost is incurred.
Ing-Ray Chen, Ngoc Anh Phan, I-Ling Yen
IEEE Trans. Mob. Comput.1
2001 A Cost-Based Admission Control Algorithm for Handling Mixed Workloads in Multimedia Server Systems
abstract
We propose and analyze a cost-based, resource-reservation admission control algorithm for handling mixed workloads in modern multimedia systems such as a digital library multimedia system that must provide access services to heterogeneous objects stored in the library. The cost-based scheme considered is based on the concept of "rewards" and "penalties" associated with requests of various object types. Instead of admitting object requests until resources are exhausted as a condition for admission control, resources are reserved to requests of different types dynamically based on the cost-based scheme so that the system is capable of maximizing the total reward received by the system in response to workload changes in the environment.
Ing-Ray Chen, Sheng-Tun Li
ICPADS1
2001 Analysis of Algorithms for Supporting Disconnected Write Operations in Mobile Client-Server Environments
abstract
A mobile user may voluntarily disconnect itself from the Web server to save its battery life and avoid high communication prices. To allow Web pages to be updated while the mobile user is disconnected from the Web server, updates can be staged in the mobile unit and propagated back to the Web server upon reconnection. We analyze algorithms for supporting disconnected write operations and develop a performance model which helps identify the optimal length of the disconnection period under which the cost of update propagation is minimized. The analysis result is particularly applicable to Web applications which allow wireless mobile users to modify Web contents while on the move. We also show how the result can be applied to real-time Web applications such that the mobile user can determine the longest disconnection period such that it can still propagate updates to the server before the deadline with a minimum communication cost.
Ing-Ray Chen, Ngoc Anh Phan, I-Ling Yen
ISADS1
2001 Special Issue Editorial: High Assurance Systems
abstract
1 Department of Computer Science, Northern Virginia Graduate Center, Virginia Tech (VPI&SU), Falls Church, VA 22043, USA Email: [email protected]
Ing-Ray Chen
Comput. J.1
2001 Agent-Based Forwarding Strategies for Reducing Location Management Cost in Mobile Networks
Ing-Ray Chen, Tsong-Min Chen, Chiang Lee
Mob. Networks Appl.1
2000 Analyzing Reconfigurable Algorithms for Managing Replicated Data with Strict Consistency Requirements: A Case Study
abstract
We address reconfigurable algorithms for managing replicated data with strict consistency requirements, that is, whenever the user performs an update operation, the update is applied to all reachable copies as part of the update protocol. A key issue of designing such algorithms is to determine how often one should detect and react to failure conditions so that reorganization operations can be performed at the appropriate time to improve the availability of replicated data. We use dynamic voting as a case study to illustrate how often such failure detection and reconfiguration activities should be performed so as to maximize the data availability. We show that there exists an optimal period at which the failure detection and reconfiguration activities should be performed to optimize the system availability. Stochastic Petri nets (SPNs) are used as a tool to facilitate our analysis.
Ding-Chau Wang, Chih-Ping Chu, Ing-Ray Chen
COMPSAC3
2000 Response time behavior of distributed voting algorithms for managing replicated data
Ing-Ray Chen, Ding-Chau Wang, Chih-Ping Chu
Inf. Process. Lett.1
2000 Dynamic Quota-Based Admission Control with Sub-Rating in Multimedia Servers
Sheng-Tzong Cheng, Chi-Ming Chen, Ing-Ray Chen
Multim. Syst.3
1999 Response Time Behavior of Voting Schemes for Managing Replicated Data
abstract
Voting is a simple and yet effective way of managing replicated data in distributed systems. In this paper we analyze its response time behavior. We investigate a technique for obtaining the access time distribution for requests that access replicated data maintained by the distributed system. The technique is based on Petri net modeling and can be used to estimate the reliability of real-time applications which must access replicate data with a deadline requirement.
Ing-Ray Chen, Ding-Chau Wang, Chih-Ping Chu
COMPSAC1
1999 Performance and Stability Analysis of Multilevel Data Structures with Deferred Reorganization
abstract
We develop a methodology for analyzing the performance and stability of a server that maintains a multilevel data structure to service a set of access operations for (key, value) records. A subset of the operations executed by the server (e.g., insert and delete) require the multilevel data structure be reorganized so that the sewer can execute all subsequent requests efficiently. We study how often the server should carry out data reorganization (i.e., maintenance) to maximize its performance. If the server is frequently idle then there is no need to impose the reorganization overhead on the operation requests. The reorganization overhead may be completely eliminated by utilizing server-idling periods. If the server is frequently busy, then the reorganization overhead can be minimized by performing a complete reorganization only after the server has served a sufficient number of insert/delete operations so that the amortized cost per operation is small. Therefore, the issue of how often one should perform data reorganization to minimize the average service time depends not only on the multilevel data structure maintained by the server but also on the type and intensity of the system workload. The proposed methodology is exemplified with a two-level sorted file with deferred maintenance. The performance and stability results are compared with those of a single-level binary tree data structure with on-the-fly maintenance. It is shown that deferred maintenance of the two-level sorted file outperforms on-the-fly maintenance of the single-level binary tree in both open and closed systems. Furthermore, deferred maintenance can sustain higher workload intensities without risking system stability.
Ing-Ray Chen, Sayed Atef Banawan
IEEE Trans. Software Eng.1
1998 Agent-Based Forwarding Strategies for Reducing Location Management Cost in Mobile Networks
abstract
A major issue with location management in mobile wireless networks is the high cost associated with location updates and searches. A search occurs when a caller needs to connect to a mobile user whose location is unknown to the caller and the network must locate the callee. An update occurs when a mobile user moves into a new registration area and the network is informed of the location change. We propose and analyze a class of new agent-based forwarding strategies with the objective to reduce the location management cost in mobile wireless networks. We develop analytical Markov models to compare the performance of the proposed strategies with existing location management schemes to demonstrate their feasibility and also to reveal conditions under which the proposed schemes are superior to existing ones.
Ing-Ray Chen, Tsong-Min Chen, Chiang Lee
ICPADS1
1998 Performance Evaluation of Forwarding Strategies for Location Management in Mobile Networks
abstract
This paper presents a methodology for evaluating the performance of forwarding strategies for location management in a personal communication services (PCS) mobile network. A forwarding strategy in the PCS network can be implemented by two mechanisms: a forwarding operation which follows a chain of databases to locate a mobile user and a resetting operation which updates the databases in the chain so that the current location of a mobile user can be known directly without having to follow a chain of databases. In this paper, we consider the PCS network as a server whose function is to provide services to the mobile user for ‘updating the location of the user as the user moves across a database boundary’ and ‘locating the mobile user’. We use a Markov chain to describe the behavior of the mobile user and analyze the best time when forwarding and resetting should be performed in order to optimize the service rate of the PCS network. We demonstrate the applicability of our approach with hexagonal and mesh coverage models for the PCS network and provide a physical interpretation of the result.
Ing-Ray Chen, Tsong-Min Chen, Chiang Lee
Comput. J.1
1998 Performance Analysis of Admission Control Algorithms Based on Reward Optimization for Real-Time Multimedia Servers
Ing-Ray Chen, Tao-Hung Hsi
Perform. Evaluation1
1997 Performance characterization of forwarding strategies in personal communication networks
abstract
The paper presents a framework for modeling and evaluating the performance of forwarding strategies in a personal communication services (PCS) mobile network. A forwarding strategy in the PCS network can be implemented by two mechanisms: a forwarding operation which follows a chain of databases to locate a mobile user, and a resetting operation which updates the databases in the chain so that the current location of a mobile user can be known directly without having to follow a chain of databases. We consider the PCS network as a server whose function is to provide services to the mobile user for "updating the location of the user as the user moves across a database boundary" and "locating the mobile user". We use a Markov chain to describe the behavior of the mobile user and analyze the best time when forwarding and resetting should be performed in order to optimize the service rate of the PCS network. We demonstrate the applicability of our approach with hexagonal coverage models for the PCS network and provide a physical interpretation of the result.
Ing-Ray Chen, Tsong-Min Chen, Chiang Lee
COMPSAC1
1996 Analyzing Dynamic Voting Using Petri Nets
abstract
Dynamic voting is considered a promising technique for achieving high availability in distributed systems with data replication. To date, stochastic analysis of dynamic voting algorithms is restricted to either site or link Markov models, but not both, possibly because of the difficulty in specifying the state-space which grows exponentially as the number of sites increases. Furthermore, to reduce the state-space, the assumption of "frequent updates" was normally made, which results in an overestimation of the availability. In this paper, we develop a Petri net model that considers both site and link failures and also relaxes the modeling assumption of frequent updates. We test our Petri net model on ring and star network topologies to analyze if availability under dynamic voting can be seriously degraded if updates are not frequent under various site and link failure/repair situations. Finally, We use the Petri net developed in the paper to determine the maximum achievable improvement in availability when null updates are introduced to augment regular updates to keep the status of availability up-to-date.
Ing-Ray Chen, Ding-Chau Wang
SRDS1
1996 Threshold-Based Admission Control Policies for Multimedia Servers
abstract
Traditional admission control algorithms for on-demand multimedia servers concern the acceptance decisions for new clients' requests so as to guarantee that continuous services to all clients are executed. These algorithms determine whether a new client can be accepted, based on the consideration whether the underlying hardware can satisfy the quality of service (QoS) requirements of admitted client requests. In this paper, we consider a richer class of admission control algorithms that make acceptance/rejection decisions not only to satisfy the hardware requirements of client requests but also to optimize the reward of the system based on a performance criterion as it services clients of different priority classes. We divide the server capacity into a number of ‘priority threshold values’ based on which the system decides whether to accept clients of different priority classes dynamically in order to maximize the system value. The resulting threshold-based admission control algorithm is developed based on the idea that admission control can be driven not only by hardware requirements, but also by knowledge regarding the workload characteristics of client requests, thus allowing the system to adjust dynamically the threshold values in response to changes in client workload characteristics. We derive a close-form expression for the value which the system can obtain when operating under the threshold-based algorithm as a function of model parameters, and discuss how the server can utilize the analytical solution at run time so as to maximize the system value dynamically without violating clients' continuity requirements.
Ing-Ray Chen, Chi-Ming Chen
Comput. J.1
1996 Analysis of Replicated Data with Repair Dependency
abstract
Pessimistic control algorithms for replicated data permit only one partition to perform update operations at any time so as to ensure mutual exclusion of the replicated data object. Existing availability modelling and analyses of pessimistic control algorithms for replicated data management are constrained to either site-failure-only or link-failure-only models, but not both, because of the large state space which needs to be considered. Moreover, the assumption of having an independent repairman for each link and each site has been made to reduce the complexity of analysis. In this paper, we remove these restrictions with the help of stochastic Petric nets. In addition to including both site and link failures/repairs events in our analysis, we investigate the effect of repair dependency which occurs when many sites and links may have to share the same repairman due to repair constraints. Four repairman models are examined in the paper: (a) independent repairman with one repairman assigned to each link and each node; (b) dependent repairman with FIFO servicing discipline; (c) dependent repairman with linear-order servicing discipline; and (d) dependent repairman with best-first servicing discipline. Using dynamic voting as a case study, we compare and contrast the resulting availabilities due to the use of these four different repairman models and give a physical interpretation of the differences. We show that ignoring concurrent site and link failures/repairs events or repair dependency can very unrealistically overestimate the availability of replicated data.
Ing-Ray Chen, Ding-Chau Wang
Comput. J.1
1995 Quality Assessment for Multiple Server Cooperating Systems
abstract
Multiple agent systems are being used increasingly in various applications, including real time applications and safety critical systems. Many of these applications have a soft real time constraints and fuzzy rather than binary correctness criteria for the output value. Also, a principal characteristic of such systems is the trade off between using an efficient but less accurate strategy or a sophisticated but more time consuming strategy. We develop methods for assessing the quality of these systems in terms of the timeliness and accuracy of the output to aid decision making. We consider two commonly used coordination structures, parallel and pipeline structures. We also propose some adaptive schemes for increasing the quality of the system.
I-Ling Yen, Ing-Ray Chen
COMPSAC2
1995 A Degradable Blink-Tree with Periodic Data Reorganization
abstract
This paper develops a periodic data reorganization algorithm for the B link -tree data structure in concurrent environments, and identifies conditions under which the data reorganization should be performed in order to minimize the response time per access operation
Ing-Ray Chen
Comput. J.1
1995 On Applying Imprecise Computation to Real-Time AI Systems
abstract
Imprecise computation is known as a technique for real-time systems where precise outputs are traded off for timely responses to system events. This paper discusses how the technique can be applied to a class of real-time AI systems designed for solving combinatorial problems and proposes an evaluation method for assessing if imprecise computation can satisfy both the timing and functional requirements of these systems.
Ing-Ray Chen
Comput. J.1
1995 Stochastic Petri Net Analysis of Deadlock Detection Algorithms in Transaction Database Systems with Dynamic Locking
abstract
We develop stochastic Petri net (SPN) models to analyze the best time interval between two consecutive executions of periodic deadlock detection algorithms for two-phase locking database systems with dynamic locking. Our models can accurately estimate ‘wait time per lock conflict’ automatically and allow the best time interval to be determined as a function of workload intensities and database characteristics. A system designer can apply the SPN tools developed in the paper to choose the best deadlock detection strategy, continuous or periodic, to optimize system performance, when given a set of system characteristics.
Ing-Ray Chen
Comput. J.1
1995 Analysis of Probabilistic Error Checking Procedures on Storage Systems
abstract
Conventionally, error checking on storage systems is performed on-the-fly (with probability 1) as the storage system is being accessed in order to improve the reliability of the storage system. However, such a procedure may needlessly cause degraded performance due to the extra processing time needed for executing the error checking code. In this paper, we consider fault-tolerance storage systems designed to provide continuous services to customers over a mission period and the design goal is (1) to maximize the cumulative number of requests that the storage system can service without failure over the mission period or (2) to be able to service at least a given number of requests without failure over the mission period with its system reliability maximized. We develop a Markov reward model to identify the design conditions under which probabilistic error checking procedures can better satisfy this design goal than conventional on-to-fly error checking procedures. The result helps determine the best time interval between successive executions of the error checking procedure to meet such design goal and is useful for designing adaptive systems that can temporarily tradeoff reliability for performance to meet design goal (2) in response to dynamic workload changes in the environment.
Ing-Ray Chen, I-Ling Yen
Comput. J.1
1995 On the Reliability of AI Planning Software in Real-Time Applications
abstract
We define the reliability of a real-time system incorporating AI planning programs as the probability that, for each problem-solving request issued from the environment, the embedded system can successfully plan and execute a response within a specified real-time deadline. A methodology is developed for evaluating the reliability of such systems taking into consideration the fact that, other than program bugs, the intrinsic characteristics of AI planning programs may also cause the embedded system to fail even after all software bugs are removed from the program. The utility of the methodology is demonstrated by applying it to the reliability evaluation of two AI planning algorithms embedded in a real-time multicriteria route finding system.>
Ing-Ray Chen, Farokh B. Bastani, Ta-Wei Tsao
IEEE Trans. Knowl. Data Eng.1
1994 Performance Evaluation of Rule Grouping on a Real-Time Expert System Architecture
abstract
Uses a Markov process to model a real-time expert system architecture characterized by message passing and event-driven scheduling. The model is applied to the performance evaluation of rule grouping for real-time expert systems running on this architecture. An optimizing algorithm based on Kernighan-Lin heuristic graph partitioning for the real-time architecture is developed and a demonstration system based on the model and algorithm has been developed and tested on a portion of the advanced GPS receiver (AGR) and manned manoeuvring unit (MMU) knowledge bases.>
Ing-Ray Chen, Bryant L. Poole
IEEE Trans. Knowl. Data Eng.1
1994 Warm Standby in Hierarchically Structured Process-Control Programs
abstract
We classify standby redundancy design space in process-control programs into the following three categories: cold standby, warm standby, and hot standby. Design parameters of warm standby are identified and the reliability of a system using warm standby is evaluated and compared with that of hot standby. Our analysis indicates that the warm standby scheme is particularly suitable for long-lived unmaintainable systems, especially those operating in harsh environments where burst hardware failures are possible. The feasibility of warm standby is demonstrated with a simulated chemical batch reactor system.>
Ing-Ray Chen, Farokh B. Bastani
IEEE Trans. Software Eng.1
1993 Reliability of uniprocessor and multiprocessor real-time artificial intelligence planning systems
abstract
By real-time artificial intelligence (AI) planning systems, we mean those systems embedded in process-control systems that must plan and execute control strategies in response to external events within a real-time constraint. We propose a methodology for estimating the reliability of uniprocessor and multiprocessor real-time AI planning systems. We first discuss why there are intrinsic faults in AI planning programs that must be considered in the reliability modeling of real-time AI planning systems. Then, we show that for uniprocessor systems, no single planning algorithm can avoid all types of intrinsic faults. Finally, we investigate a multiprocessor architecture with parallel planning with the objective of reducing intrinsic faults of real-time AI planning systems and improving the reliability of embedded systems. A robot path-planning system in static domains is used as an example to illustrate our methodology.
Ing-Ray Chen, Ta-Wei Tsao, Farokh B. Bastani
ISSRE1
1993 A Software Reliability Model for Artificial Intelligence Programs
abstract
In this paper we develop a software reliability model for Artificial Intelligence (AI) programs. We show that conventional software reliability models must be modified to incorporate certain special characteristics of AI programs, such as (1) failures due to intrinsic faults, e.g., limitations due to heuristics and other basic AI techniques, (2) fuzzy correctness criterion, i.e., difficulty in accurately classifying the output of some AI programs as correct or incorrect, (3) planning-time versus execution-time tradeoffs, and (4) reliability growth due to an evolving knowledge base. We illustrate the approach by modifying the Musa-Okumoto software reliability growth model to incorporate failures due to intrinsic faults and to accept fuzzy failure data. The utility of the model is exemplified with a robot path-planning problem.
Farokh B. Bastani, Ing-Ray Chen, Ta-Wei Tsao
Int. J. Softw. Eng. Knowl. Eng.2
1993 Modeling and Analysis of Concurrent Maintenance Policies for Data Structures Using Pointers
abstract
We present a state reduction method that effectively reduces a two-dimensional Markov model to a one-dimensional Markov model for the performance analysis of a class of concurrent data structure maintenance policies. The reduced model allows the derivation of a closed form expression for the average service time per operation and facilitates the identification of priority allocation functions under which: the system is stable; and the service time per operation is minimized. The applicability of the model is exemplified with a binary tree data structure and the conditions under which concurrent maintenance strategies are better than a conventional incremental maintenance strategy are determined.>
Ing-Ray Chen, Sayed Atef Banawan
IEEE Trans. Software Eng.1
1992 A Reduced Markov Model for the Performance Analysis of Data Structure Servers with Periodic Maintenance
Ing-Ray Chen, Sayed Atef Banawan
Comput. J.1
1991 A Model for the Stability Analysis of Maintenance Stragies for Linear List
abstract
In this paper, we present a fluid approximation model to analyse the stability of two frequeently used data structure maintenance strategies in client-server distributed environments, namely, concurrent and periodic maintenance strategies. We give a detailed analysis for a linear list data structure and derive the maximum allowable value of the input arrival rate under which a stable system can be obtained when these maintenance strategies are used. Conditions under which one strategy may be more preferable than the other in terms of the system throughput and the variance of the service time distribution are identified. The stability behaviour of these two maintenance strategies under high traffic situation is also investigated.
Farokh B. Bastani, Ing-Ray Chen, Wael Hilal Bahaa-El-Din
Comput. J.2
1988 A Class of Inherently Fault Tolerant Distributed Programs
abstract
Software for industrial process-control systems, such as nuclear power plant safety control systems and robots, can be very complex because of the large number of cases that must be considered. A design approach is proposed that uses decentralized control concepts, and is based on E.W. Dijkstra's concept of self-stabilizing systems (1974). This method greatly simplifies the software, so that its correctness can be verified more easily. A simple control system is described for a simulated robot that is tolerant of partial failure of controllers and mechanisms, and permits online repair and enhancement of the control functions.>
Farokh B. Bastani, I-Ling Yen, Ing-Ray Chen
IEEE Trans. Software Eng.3