VLDB 2026 Research / reviewers in the wild / expert
Jun Li 0001
dblp:l/JunLi1
· DBLP profile ↗
76ranked-venue papers
14as first author
14since 2021 · last 2025
0000-0002-5308-5672ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 9 first-author · 3 since 2021Security and privacy · 19 · 5 first-author · 9 since 2021Systems, architecture and hardware · 4 · 2 since 2021Artificial intelligence and machine learning · 3Databases, data management, data science and information retrieval · 3Software engineering, systems software and programming languages · 2Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Leakage-Resilient Easily Deployable and Efficiently Searchable Encryption (EDESE)abstractEasily Deployable and Efficiently Searchable Encryption (EDESE) is a cryptographic primitive designed for practical searchable applications, offering efficient search and easy deployment. However, it remains vulnerable to Leakage-Abuse attacks, allowing adversaries to exploit keyword-matching processes to extract sensitive information. To address these vulnerabilities, we introduce Leakage-Resilient EDESE (LR-EDESE) with k-indistinguishability and controlled leakage functions. We then propose Volume Leakage-Resilient EDESE (VLR-EDESE), a new scheme to protect against both query and document volume leakage. Our experimental results demonstrate that at k = 5000 (maximum security setting), VLR-EDESE incurs an overhead of 63× compared to the baseline EDESE without leakage protection, outperforming state-of-the-art methods with 320× and 97× overhead, respectively. For smaller k values (10, 20, 50, 100), storage and communication overhead remain within 2× and 2.5× of the baseline EDESE, highlighting VLR-EDESE's flexibility. Finally, we present CloudSec, an implementation of VLR-EDESE that seamlessly integrates with cloud storage platforms, using OneDrive as an example. Jiaming Yuan, Yingjiu Li, Jun Li 0001, Daoyuan Wu, Jianting Ning, Yangguang Tian, Robert H. Deng |
SACMAT | 3 |
| 2024 | On Explainable and Adaptable Detection of Distributed Denial-of-Service TrafficabstractLaunched from numerous end-hosts throughout the Internet, a distributed denial-of-service (DDoS) attack can exhaust the network bandwidth or other resources of a victim, cripple its service, and make it unavailable to legitimate clients. Recently many learning-based approaches attempt to detect DDoS attacks, but their results are often hardly explainable to users and their models are seldom adaptable to new environments. In this paper, we propose a new learning-based DDoS detection approach. It detects DDoS attacks via an enhanced k-nearest neighbors (KNN) algorithm, which utilizes a k-dimensional (KD) tree to speed up the detection process, and classifies DDoS sources at a fine granularity according to each IP's risk level. Compared to previous DDoS detection approaches, this approach outputs explanatory information that enables network administrators to easily inspect detection results and make necessary interventions. Moreover, this approach is adaptable in that users do not need to retrain the detection model to have it fit with a new network environment. We evaluated this approach in both simulated environments and the real world, achieving more than 95.6% accuracy in detecting DDoS attacks at line speed. In addition, we carried out a human subject study on its explainability, demonstrating that the outputs can help people better understand the attack and make interventions precisely and promptly. Yebo Feng, Jun Li 0001, Devkishen Sisodia, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Resilient Intermediary-Based Key Exchange Protocol for IoTabstractDue to the limited resources of Internet of Things (IoT) devices, Symmetric Key Cryptography (SKC) is typically favored over resource-intensive Public Key Cryptography (PKC) to secure communication between IoT devices. To utilize SKC, devices need to execute a key exchange protocol to establish a session key before initiating communication. However, existing SKC-based key exchange protocols assume that communication devices have a pre-shared secret or there are trusted intermediaries between them; neither is always realistic in IoT. We introduce a new SKC-based key exchange protocol for IoT devices. While also intermediary based, our protocol fundamentally departs from existing intermediary-based solutions in that intermediaries between two key exchange devices may be malicious, and moreover, our protocol can detect cheating behaviors and identify malicious intermediaries. We prove our protocol is secure under the universally composable model, and show that it can detect malicious intermediaries with probability 1.0. We implemented and evaluated our protocol on different IoT devices. We show that our protocol has significant improvements in computation time and energy cost. Compared to the PKC-based protocols ECDH, DH, and RSA, our protocol is 2.3 to 1,591 times faster on one of the two key exchange devices and 0.7 to 4.67 times faster on the other. Zhangxiang Hu, Jun Li 0001 |
ACM Trans. Internet Things | 2 |
| 2024 | A Two-Mode, Adaptive Security Framework for Smart Home Security ApplicationsabstractWith the growth of the Internet of Things (IoT), the number of cyber attacks on the Internet is on the rise. However, the resource-constrained nature of IoT devices and their networks makes many classical security systems ineffective or inapplicable. We introduce TWINKLE, a two-mode, adaptive security framework that allows an IoT network to be in regular mode for most of the time, which incurs a low resource consumption rate, and to switch to vigilant mode only when suspicious behavior is detected, which potentially incurs a higher overhead. Compared to the early version of this work, this article presents a more comprehensive design and architecture of TWINKLE, describes challenges and details in implementing TWINKLE, and reports evaluations of TWINKLE based on real-world IoT testbeds with more metrics. We show the efficacy of TWINKLE in two case studies where we examine two existing intrusion detection and prevention systems and transform both into new, improved systems using TWINKLE. Our evaluations show that TWINKLE is not only effective at securing resource-constrained IoT networks, but can also successfully detect and prevent attacks with a significantly lower overhead and detection latency than existing solutions. Devkishen Sisodia, Jun Li 0001, Samuel Mergendahl, Hasan Çam |
ACM Trans. Internet Things | 2 |
| 2023 | DDoS Mitigation Dilemma Exposed: A Two-Wave Attack with Collateral Damage of Millions
Lumin Shi, Jun Li 0001, Devkishen Sisodia, Mingwei Zhang 0004, Alberto Dainotti, Peter L. Reiher |
SecureComm (2) | 2 |
| 2023 | A Game Theoretical Analysis of Distributed Denial-of-Service Defense Incentive
Mingwei Zhang 0004, Jun Li 0001, Jiabin Wu, Peter L. Reiher |
SecureComm (2) | 2 |
| 2023 | On the Detection of Smart, Self-Propagating Internet WormsabstractSelf-propagating worms can infect millions of computers on the Internet in just several minutes. As witnessed by the recent Mirai and WannaCry worms, worm attacks are real, destructive, and continue to persist. Although many worm detectors exist, most that we studied suffer from three drawbacks: none systematically consider countermeasures from worm authors, potentially causing low effectiveness against evasive worms; all focus on outbound worms leaving a network, leaving their efficacy against inbound worms entering a network unanswered; and many require bi-directional traffic to detect worms, making their placement on the Internet inflexible. We therefore revisit worm detection in this paper, while avoiding the aforementioned drawbacks of existing work. We describe our design of SWORD, a new worm detector that focuses on the fundamental behavior of worms. It includes two complementary modules to monitor connections from and to a protected network, with one module monitoring burst durations and the other ensuring quiescent periods. Via extensive experiments using both simulated worm traffic and a real-world Mirai worm trace, we demonstrate that SWORD is superior to existing detectors at not only detecting both classic and evasive outbound worms, but also inbound worms, especially those that are superspreading or surreptitious. Jun Li 0001, Devkishen Sisodia, Shad Stafford |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Toward a Resilient Key Exchange Protocol for IoTabstractIn order for resource-constrained Internet of Things (IoT) devices to set up secure communication channels to exchange confidential messages, Symmetric Key Cryptography (SKC) is usually preferred to resource-intensive Public Key Cryptography (PKC). At the core of setting up a secure channel is secure key exchange, the process of two IoT devices securely agreeing on a common session key before they communicate. While compared to using PKC, key exchange using SKC is more resource-aware for IoT environments, it requires either a pre-shared secret or trusted intermediaries between the two devices; neither assumption is realistic in IoT. In this paper, we relax the above assumptions and introduce a new intermediary-based secure key exchange protocol for IoT devices that do not support PKC. With a design that is lightweight and deployable in IoT, our protocol fundamentally departs from existing intermediary-based solutions in that (1) it leverages intermediary parties that can be malicious and (2) it can detect malicious intermediary parties. We provide a formal proof that our protocol is secure and conduct a theoretical analysis to show the failure probability of our protocol is easily negligible with a reasonable setup and its malicious helper detection probability can be 1.0 even when a malicious helper only tampers a small number of messages. We implemented our protocol and our experimental results show that our protocol significantly improves the computation time and energy cost. Dependent on the IoT device type (Raspberry Pi, Arduino Due, or Sam D21) and the PKC algorithms to compare against (ECDH, DH, or RSA), our protocol is 2.3 to 1591 times faster on one of the two devices and 0.7 to 4.67 times faster on the other. Zhangxiang Hu, Jun Li 0001, Samuel Mergendahl |
CODASPY | 2 |
| 2022 | QCIR: Pattern Matching Based Universal Quantum Circuit Rewriting FrameworkabstractDue to multiple limitations of quantum computers in the NISQ era, quantum compilation efforts are required to efficiently execute quantum algorithms on NISQ devices Program rewriting based on pattern matching can improve the generalization ability of compiler optimization. However, it has rarely been explored for quantum circuit optimization, further considering physical features of target devices. Mingyu Chen 0009, Yu Zhang 0086, Yongshang Li, Zhen Wang 0075, Jun Li 0001, Xiang-Yang Li 0001 |
ICCAD | 5 |
| 2022 | CJ-Sniffer: Measurement and Content-Agnostic Detection of Cryptojacking TrafficabstractWith the continuous appreciation of cryptocurrency, cryptojacking, the act by which computing resources are stolen to mine cryptocurrencies, is becoming more rampant. In this paper, we conduct a measurement study on cryptojacking network traffic and propose CryptoJacking-Sniffer (CJ-Sniffer), an easily deployable, privacy-aware approach to protecting all devices within a network against cryptojacking. Compared with existing approaches that suffer from privacy concerns or high overhead, CJ-Sniffer only needs to access anonymized, content-agnostic metadata of network traffic from the gateway of the network to efficiently detect cryptojacking traffic. In particular, while cryptojacking traffic is also cryptocurrency mining traffic, CJ-Sniffer is the first approach to distinguishing cryptojacking traffic from user-initiated cryptocurrency mining traffic, making it possible to only filter cryptojacking traffic, rather than blindly filtering all cryptocurrency mining traffic as commonly practiced. After constructing a statistical model to identify all the cryptocurrency mining traffic, CJ-Sniffer extracts variation vectors from packet intervals and utilizes a long short-term memory (LSTM) network to further identify cryptojacking traffic. We evaluated CJ-Sniffer with a packet-level cryptomining dataset. Our evaluation results demonstrate that CJ-Sniffer achieves an accuracy of over 99% with reasonable delays. Yebo Feng, Jun Li 0001, Devkishen Sisodia |
RAID | 2 |
| 2022 | On Capturing DDoS Traffic Footprints on the InternetabstractWhile distributed denial-of-service (DDoS) attacks are easy to launch and are becoming more damaging, the defense against DDoS attacks often suffers from the lack of relevant knowledge of the DDoS traffic, including the paths the DDoS traffic has used, the source addresses (spoofed or not) that appear along each path, and the amount of traffic per path or per source. Though IP traceback and path inference approaches could be considered, they are either expensive and hard to deploy or inaccurate. We propose PathFinder, a service that a DDoS defense system can use to obtain the footprints of the DDoS traffic to the victim. PathFinder employs an architecture that is easy to implement and deploy on today's Internet, a PFTrie data structure that introduces multiple design features to log traffic at line rate, and streaming and zooming mechanisms that facilitates the storage and transmission of DDoS footprints more efficiently. Our evaluation shows that PathFinder can significantly improve the efficacy of a DDoS defense system, its PFTrie data structure is fast and has a manageable overhead, and its streaming and zooming mechanisms significantly reduce the delay and overhead in transmitting DDoS footprints. Lumin Shi, Jun Li 0001, Mingwei Zhang 0004, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Towards Learning-Based, Content-Agnostic Detection of Social Bot TrafficabstractWith the fast-growing popularity of online social networks (OSNs), the security and privacy of OSN ecosystems becomes essential for the public. Among threats OSNs face, malicious social bots have become the most common and detrimental. They are often employed to violate users’ privacy, distribute spam, and disturb the financial market, posing a compelling need for effective social bot detection solutions. Unlike traditional social bot detection approaches that have strict requirements on data sources (e.g., private payload information, social relationships, or activity histories), this article proposes a method called BotFlowMon that relies only on content-agnostic flow-level data as input to identify OSN bot traffic. BotFlowMon introduces several new algorithms and techniques to classify social bot traffic from real OSN user traffic, including aggregating network flow records to obtain OSN transaction data, fusing transaction data to extract features and visualize flows, and an innovative density-valley-based clustering algorithm to subdivide each transaction into individual actions. The evaluation shows BotFlowMon can identify the traffic from social bots with a 96.1 percent accuracy, which, based on the worst case study on a testing machine, only takes no more than 0.71 seconds on average after it sees the traffic. Yebo Feng, Jun Li 0001, Lei Jiao 0002, Xintao Wu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Service Placement for Collaborative Edge ApplicationsabstractEdge computing is emerging as a promising computing paradigm for supporting next-generation applications that rely on low-latency network connections in the Internet-of-Things (IoT) era. Many edge applications, such as multi-player augmented reality (AR) gaming and federated machine learning, require that distributed clients work collaboratively for a common goal through message exchanges. Given an edge network, it is an open problem how to deploy such collaborative edge applications to achieve the best overall system performance. This paper presents a formal study of this problem. We first provide a mix of cost models to capture the system. Based on a thorough formulation, we propose an iterative algorithm dubbed ITEM, where in each iteration, we construct a graph to encode all the costs and convert the cost optimization problem into a graph cut problem. By obtaining the minimum s-t cut via existing max-flow algorithms, we address the original problem via solving a series of graph cuts. We rigorously prove that ITEM has a parameterized constant approximation ratio. Inspired by the optimal stopping theory, we further design an online algorithm called OPTS, based on optimally alternating between partial and full placement updates. Our evaluations with real-world data traces demonstrate that ITEM performs close to the optimum (within 5%) and converges fast. OPTS achieves a bounded performance as expected while reducing full updates by more than 67% of the time. Lin Wang 0015, Lei Jiao 0002, Ting He 0001, Jun Li 0001, Henri E. Bal |
IEEE/ACM Trans. Netw. | 4 |
| 2021 | On the Effective Parallelization and Near-Optimal Deployment of Service Function ChainsabstractNetwork operators compose Service Function Chains (SFCs) by tying different network functions (e.g., packet inspection, flow shaping, network address translation) together and process traffic flows in the order the network functions are chained. Leveraging the technique of Network Function Virtualization (NFV), each network function can be “virtualized” and decoupled from its dedicated hardware, and therefore can be deployed flexibly for better performance at any appropriate location of the underlying network infrastructure. However, an SFC often incurs high latency as traffic goes through the virtual network functions one after another. In this article, we first design an algorithm that leverages virtual network function dependency to convert an original SFC into a parallelized SFC (p-SFC). Then, to deploy multiple p-SFCs over the network for serving a large number of users, we model the deployment problem as an Integer Linear Program and propose a heuristic, ParaSFC, based on the Viterbi dynamic programming algorithm to estimate each p-SFC's occupation of the bottleneck resources and adjust the processing order of the p-SFCs in order to approximate the optimal solution. Finally, we conduct extensive trace-driven evaluations and exhibit that, compared to the Greedy method and the state-of-the-art CoordVNF method, ParaSFC reduces the average service latency of all the deployed p-SFCs by about 15 percent through parallelization while accommodating more SFC deployment requests over resource-limited networks. Jian-Zhen Luo, Jun Li 0001, Lei Jiao 0002, Jun Cai 0002 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2020 | POSTER: Content-Agnostic Identification of Cryptojacking in Network TrafficabstractIn this paper, we propose a method that detects cryptojacking activities by analyzing content-agnostic network traffic flows. Our method first distinguishes crypto-mining activities by profiling the traffic with fast Fourier transform at each time window. It then generates the variation vectors between adjacent time windows and leverages a recurrent neural network to identify the cryptojacking patterns. Compared with the existing approaches, this method is privacy-preserving and can identify both browser-based and malware-based cryptojacking activities. Additionally, this method is easy to deploy. It can monitor all the devices within a network by accessing packet headers from the gateway router. Yebo Feng, Devkishen Sisodia, Jun Li 0001 |
AsiaCCS | 3 |
| 2020 | In-Network Filtering of Distributed Denial-of-Service Traffic with Near-Optimal Rule SelectionabstractA recent trend to mitigate large-scale distributed denial-of-service (DDoS) attacks is in-network filtering, where victims can deploy traffic-filtering rules in networks other than their own. However, given multiple constraints, such as the number of rules a victim can afford to deploy, the set of rules that DDoS defense entities allow a victim to deploy, and the amount of collateral damage to limit, the selection of rules has a large impact on the efficacy of an in-network filtering solution. Devkishen Sisodia, Jun Li 0001, Lei Jiao 0002 |
AsiaCCS | 2 |
| 2020 | Scheduling DDoS Cloud Scrubbing in ISP Networks via Randomized Online AuctionsabstractWhile both Internet Service Providers (ISPs) and third-party Security Service Providers (SSPs) offer Distributed Denial-of-Service (DDoS) mitigation services through cloud-based scrubbing centers, it is often beneficial for ISPs to outsource part of the traffic scrubbing to SSPs to achieve less economic cost and better network performance. To explore this potential, we design an online auction mechanism, featured by the challenge of the switching cost of using different winning bids over time. Formulating the social cost minimization as a nonconvex integer program, we firstly relax it and design an online algorithm that breaks it into a series of modified single-shot problems and solves each of them in polynomial time, without requiring knowledge of future inputs; then, we design a randomized rounding algorithm to convert the fractional decisions into integers without violating any constraints; and finally, we design the payment for each bid based on its winning probability. We rigorously prove that our mechanism achieves a parameterized-constant competitive ratio for the long-term social cost, with truthfulness and individual rationality in expectation. We also exhibit its superior practical performance via evaluations driven by real-world data traces. Wencong You, Lei Jiao 0002, Jun Li 0001, Ruiting Zhou |
INFOCOM | 3 |
| 2020 | Application-Layer DDoS Defense with Reinforcement LearningabstractApplication-layer distributed denial-of-service (L7 DDoS) attacks, by exploiting application-layer requests to overwhelm functions or components of victim servers, have become a rising major threat to today's Internet. However, because the traffic from an L7 DDoS attack appears legitimate in transport and network layers, it is difficult for traditional DDoS solutions to detect and defend against an L7 DDoS attack. In this paper, we propose a new, reinforcement-learning-based approach to L7 DDoS attack defense. We introduce a multiobjective reward function to guide a reinforcement learning agent to learn the most suitable action in mitigating L7 DDoS attacks. Consequently, while actively monitoring and analyzing the victim server, the agent can apply different strategies under different conditions to protect the victim: When an L7 DDoS attack is overwhelming, the agent will aggressively mitigate as many malicious requests as possible, thereby keeping the victim server functioning (even at the cost of sacrificing a small number of legitimate requests); otherwise, the agent will conservatively mitigate malicious requests instead, with a focus on minimizing collateral damage to legitimate requests. The evaluation shows that our approach can achieve minimal collateral damage when the L7 DDoS attack is tolerable and mitigate 98.73 % of the malicious application messages when the victim is brought to its knees. Yebo Feng, Jun Li 0001 |
IWQoS | 2 |
| 2020 | VeriTable: Fast equivalence verification of multiple large forwarding tables
Yaoqing Liu, Garegin Grigoryan, Jun Li 0001, Guchuan Sun, Tony Tauber |
Comput. Networks | 3 |
| 2019 | One-Class Adversarial Nets for Fraud DetectionabstractMany online applications, such as online social networks or knowledge bases, are often attacked by malicious users who commit different types of actions such as vandalism on Wikipedia or fraudulent reviews on eBay. Currently, most of the fraud detection approaches require a training dataset that contains records of both benign and malicious users. However, in practice, there are often no or very few records of malicious users. In this paper, we develop one-class adversarial nets (OCAN) for fraud detection with only benign users as training data. OCAN first uses LSTM-Autoencoder to learn the representations of benign users from their sequences of online activities. It then detects malicious users by training a discriminator of a complementary GAN model that is different from the regular GAN model. Experimental results show that our OCAN outperforms the state-of-the-art oneclass classification models and achieves comparable performance with the latest multi-source LSTM model that requires both benign and malicious users in the training phase. Panpan Zheng, Shuhan Yuan, Xintao Wu, Jun Li 0001, Aidong Lu |
AAAI | 4 |
| 2019 | On Multi-Point, In-Network Filtering of Distributed Denial-of-Service Traffic
Mingwei Zhang 0004, Lumin Shi, Devkishen Sisodia, Jun Li 0001, Peter L. Reiher |
IM | 4 |
| 2019 | MOERA: Mobility-Agnostic Online Resource Allocation for Edge ComputingabstractTo better support emerging interactive mobile applications such as those VR-/AR-based, cloud computing is quickly evolving into a new computing paradigm called edge computing. Edge computing has the promise of bringing cloud resources to the network edge to augment the capability of mobile devices in close proximity to the user. One big challenge in edge computing is the efficient allocation and adaptation of edge resources in the presence of high dynamics imposed by user mobility. This paper provides a formal study of this problem. By characterizing a variety of static and dynamic performance measures with a comprehensive cost model, we formulate the online edge resource allocation problem with a mixed nonlinear optimization problem. We propose MOERA, a mobility-agnostic online algorithm based on the “regularization” technique, which can be used to decompose the problem into separate subproblems with regularized objective functions and solve them using convex programming. Through rigorous analysis we are able to prove that MOERA can guarantee a parameterized competitive ratio, without requiring any a priori knowledge on input. We carry out extensive experiments with various real-world data and show that MOERA can achieve an empirical competitive ratio of less than 1.2, reduces the total cost by $4 \times$4× compared to static approaches, and outperforms the online greedy one-shot solution by 70 percent. Moreover, we verify that even being future-agnostic, MOERA can achieve comparable performance to approaches with perfect partial future knowledge. We also discuss practical issues with respect to the implementation of our algorithm in real edge computing systems. Lin Wang 0015, Lei Jiao 0002, Jun Li 0001, Julien Gedeon, Max Mühlhäuser |
IEEE Trans. Mob. Comput. | 3 |
| 2018 | Trojan Horses in Amazon's Castle: Understanding the Incentivized Online ReviewsabstractDuring the past few years, sellers have increasingly offered discounted or free products to selected reviewers of e-commerce platforms in exchange for their reviews. Such incentivized (and often very positive) reviews can improve the rating of a product which in turn sways other users' opinions about the product. Despite their importance, the prevalence, characteristics, and the influence of incentivized reviews in a major e-commerce platform have not been systematically and quantitatively studied. This paper examines the problem of detecting and characterizing incentivized reviews in two primary categories of Amazon products. We describe a new method to identify Explicitly Incentivized Reviews (EIRs) and then collect a few datasets to capture an extensive collection of EIRs along with their associated products and reviewers. We show that the key features of EIRs and normal reviews exhibit different characteristics. Furthermore, we illustrate how the prevalence of EIRs has evolved and been affected by Amazon's ban. Our examination of the temporal pattern of submitted reviews for sample products reveals promotional campaigns by the corresponding sellers and their effectiveness in attracting other users. Finally, we demonstrate that a classifier that is trained by EIRs (without explicit keywords) and normal reviews can accurately detect other EIRs as well as implicitly incentivized reviews. Overall, this analysis sheds an insightful light on the impact of EIRs on Amazon products and users. Soheil Jamshidi, Reza Rejaie, Jun Li 0001 |
ASONAM | 3 |
| 2018 | FR-WARD: Fast Retransmit as a Wary but Ample Response to Distributed Denial-of-Service Attacks from the Internet of ThingsabstractWhile the Internet of Things (IoT) becomes increasingly popular and ubiquitous, IoT devices often remain unprotected and can be exploited to launch large-scale distributed denial-of-service (DDoS) attacks. One could attempt to employ traditional DDoS defense solutions, but these solutions are hardly suitable in IoT environments since they seldom consider the resource constraints of IoT devices. We present FR-WARD, a system that defends against DDoS attacks launched from an IoT network. FR-WARD operates close to potential attack sources at the gateway of an IoT network and drops packets to throttle any DDoS traffic that attempts to leave the IoT network. However, in order to properly react to traffic too difficult to categorically label as good or bad, FR-WARD employs a novel response based on the fast retransmit and flow control mechanisms of the Transmission Control Protocol (TCP) which minimizes the energy consumption and network latency of benign IoT devices within the policed network. Based on our mathematical analysis, simulation, and experimental evaluation, FR-WARD not only effectively mitigates DDoS traffic, but also minimizes the number of retransmitted packets and the connection durations of benign IoT devices. In fact, FR-WARD can successfully mitigate both naive flood attacks and smarter DDoS attacks that follow TCP congestion control but still reduce overhead caused by retransmitted packets for benign IoT devices by a up to a factor of 150. Samuel Mergendahl, Devkishen Sisodia, Jun Li 0001, Hasan Çam |
ICCCN | 3 |
| 2018 | VeriTable: Fast Equivalence Verification of Multiple Large Forwarding TablesabstractDue to network practices such as traffic engineering and multi-homing, the number of routes-also known as IP prefixes-in the global forwarding tables has been increasing significantly in the last decade and continues growing in a super linear trend. One of the most promising solutions is to use smart Forwarding Information Base (FIB) aggregation algorithms to aggregate the prefixes and convert a large table into a small one. Doing so poses a research question, however, i.e., how can we quickly verify that the original table yields the same forwarding behaviors as the aggregated one? We answer this question in this paper, including addressing the challenges caused by the longest prefix matching (LPM) lookups. In particular, we propose the VeriTable algorithm that can employ a single tree/trie traversal to quickly check if multiple forwarding tables are forwarding equivalent, as well as if they could result in routing loops or black holes. The VeriTable algorithm significantly outperforms the state-of-the-art work for both IPv4 and IPv6 tables in every aspect, including the total running time, memory access times and memory consumption. Garegin Grigoryan, Yaoqing Liu, Michael Leczinsky, Jun Li 0001 |
INFOCOM | 4 |
| 2018 | Service Entity Placement for Social Virtual Reality Applications in Edge ComputingabstractWhile social Virtual Reality (VR) applications such as Facebook Spaces are becoming popular, they are not compatible with classic mobile-or cloud-based solutions due to their processing of tremendous data and exchange of delay-sensitive metadata. Edge computing may fulfill these demands better, but it is still an open problem to deploy social VR applications in an edge infrastructure while supporting economic operations of the edge clouds and satisfactory quality-of-service for the users. This paper presents the first formal study of this problem. We model and formulate a combinatorial optimization problem that captures all intertwined goals. We propose ITEM, an iterative algorithm with fast and big “moves” where in each iteration, we construct a graph to encode all the costs and convert the cost optimization into a graph cut problem. By obtaining the minimum s-t cut via existing max-flow algorithms, we can simultaneously determine the placement of multiple service entities, and thus, the original problem can be addressed by solving a series of graph cuts. Our evaluations with large-scale, real-world data traces demonstrate that ITEM converges fast and outperforms baseline approaches by more than 2 × in one-shot placement and around 1.3 × in dynamic, online scenarios where users move arbitrarily in the system. Lin Wang 0015, Lei Jiao 0002, Ting He 0001, Jun Li 0001, Max Mühlhäuser |
INFOCOM | 4 |
| 2018 | Online Control of Cloud and Edge Resources Using Inaccurate PredictionsabstractWe study cloud resource control in the global-local distributed cloud infrastructure. We firstly model and formulate the problem while capturing the multiple challenges such as the inter-dependency between resources and the uncertainty in the inputs. We then propose a novel online algorithm which, via the regularization technique, decouples the original problem into a series of subproblems for individual time slots and solves both the subproblems and the original problem over every prediction time window to jointly make resource allocation decisions. Compared against the offline optimum with accurate inputs, our approach maintains a provable parameterized worst-case performance gap with only inaccurate inputs under certain conditions. Finally, we conduct evaluations with large-scale, real-world data traces and show that our solution outperforms existing methods and works efficiently with near-optimal cost in practice. Lei Jiao 0002, Antonia M. Tulino, Jaime Llorca, Alessandra Sala, Jun Li 0001 |
IWQoS | 6 |
| 2018 | Multiple Granularity Online Control of Cloudlet Networks for Edge ComputingabstractOperating distributed cloudlets at optimal cost is nontrivial when facing not only the dynamic and unpredictable resource prices and user requests, but also the low efficiency of today's immature cloudlet infrastructures. We propose to control cloudlet networks at multiple granularities: fine-grained control of servers inside cloudlets and coarse-grained control of cloudlets themselves. We model this problem as a mixed-integer nonlinear program with the switching cost over time. To solve this problem online, we firstly linearize, "regularize", and decouple it into a series of one-shot subproblems that we solve at each corresponding time slot, and afterwards we design an iterative, dependent rounding framework using our proposed randomized pairwise rounding algorithm to convert the fractional control decisions into the integral ones at each time slot. Via rigorous theoretical analysis, we exhibit our approach's performance guarantee in terms of the competitive ratio and the multiplicative integrality gap towards the offline optimal integral decisions. Extensive evaluations with real-world data confirm the empirical superiority of our approach over the single granularity server control and the state-of-the-art algorithms. Lei Jiao 0002, Lingjun Pu, Lin Wang 0015, Xiaojun Lin 0001, Jun Li 0001 |
SECON | 5 |
| 2018 | Securing the Smart Home via a Two-Mode Security Framework
Devkishen Sisodia, Samuel Mergendahl, Jun Li 0001, Hasan Çam |
SecureComm (1) | 3 |
| 2018 | Fuzzing: a surveyabstractSecurity vulnerability is one of the root causes of cyber-security threats. To discover vulnerabilities and fix them in advance, researchers have proposed several techniques, among which fuzzing is the most widely used one. In recent years, fuzzing solutions, like AFL, have made great improvements in vulnerability discovery. This paper presents a summary of the recent advances, analyzes how they improve the fuzzing process, and sheds light on future work in fuzzing. Firstly, we discuss the reason why fuzzing is popular, by comparing different commonly used vulnerability discovery techniques. Then we present an overview of fuzzing solutions, and discuss in detail one of the most popular type of fuzzing, i.e., coverage-based fuzzing. Then we present other techniques that could make fuzzing process smarter and more efficient. Finally, we show some applications of fuzzing, and discuss new trends of fuzzing and potential future directions. Jun Li 0001, Bodong Zhao, Chao Zhang 0008 |
Cybersecur. | 1 |
| 2018 | SVDC: A Highly Scalable Isolation Architecture for Virtualized Layer-2 Data Center NetworksabstractWhile large layer-2 networks are widely accepted as the network fabric for modern data centers and network virtualization is required to support multi-tenant cloud computing, existing network virtualization solutions are not specifically designed for layer-2 networks. In this paper, we designSVDC, a highly-scalable and low-overhead virtualization architecture for large layer-2 data center networks. By leveraging the emerging software defined networking (SDN) framework, SVDC decouples the global identifier of a virtual network from the identifier carried in the packet header. Hence, SVDC can scale to a great number of virtual networks with a very short tag in the packet header, which is never achieved by previous network virtualization solutions. SVDC enhances MAC-in-MAC encapsulation in a way that packets with overlapped MAC addresses are correctly forwarded even without in-packet global identifiers to differentiate the virtual networks they belong to. Besides, scalable and efficient layer-2 multicast and broadcast within virtual networks are also supported in SVDC. With extensive simulations and experiments, we show that SVDC is better than existing solutions in many aspects, particularly isolating virtual networks with high scalability and higher network goodput due to minimal packet header overhead. Congjie Chen, Dan Li 0001, Jun Li 0001, Konglin Zhu |
IEEE Trans. Cloud Comput. | 3 |
| 2017 | Spectrum-based Deep Neural Networks for Fraud DetectionabstractIn this paper, we focus on fraud detection on a signed graph with only a small set of labeled training data. We propose a novel framework that combines deep neural networks and spectral graph analysis. In particular, we use the node projection (called as spectral coordinate) in the low dimensional spectral space of the graph's adjacency matrix as the input of deep neural networks. Spectral coordinates in the spectral space capture the most useful topology information of the network. Due to the small dimension of spectral coordinates (compared with the dimension of the adjacency matrix derived from a graph), training deep neural networks becomes feasible. We develop and evaluate two neural networks, deep autoencoder and convolutional neural network, in our fraud detection framework. Experimental results on a real signed graph show that our spectrum based deep neural networks are effective in fraud detection. Shuhan Yuan, Xintao Wu, Jun Li 0001, Aidong Lu |
CIKM | 3 |
| 2017 | Online Resource Allocation for Arbitrary User Mobility in Distributed Edge CloudsabstractAs clouds move to the network edge to facilitate mobile applications, edge cloud providers are facing new challenges on resource allocation. As users may move and resource prices may vary arbitrarily, %and service delays are heterogeneous, resources in edge clouds must be allocated and adapted continuously in order to accommodate such dynamics. In this paper, we first formulate this problem with a comprehensive model that captures the key challenges, then introduce a gap-preserving transformation of the problem, and propose a novel online algorithm that optimally solves a series of subproblems with a carefully designed logarithmic objective, finally producing feasible solutions for edge cloud resource allocation over time. We further prove via rigorous analysis that our online algorithm can provide a parameterized competitive ratio, without requiring any a priori knowledge on either the resource price or the user mobility. Through extensive experiments with both real-world and synthetic data, we further confirm the effectiveness of the proposed algorithm. We show that the proposed algorithm achieves near-optimal results with an empirical competitive ratio of about 1.1, reduces the total cost by up to 4x compared to static approaches, and outperforms the online greedy one-shot optimizations by up to 70%. Lin Wang 0015, Lei Jiao 0002, Jun Li 0001, Max Mühlhäuser |
ICDCS | 3 |
| 2017 | On the most representative summaries of network user activities
Joshua Stein, Han Hee Song, Mario Baldi, Jun Li 0001 |
Comput. Networks | 4 |
| 2017 | The Good Left Undone: Advances and Challenges in Decentralizing Online Social Networks
David Koll, Jun Li 0001, Xiaoming Fu 0001 |
Comput. Commun. | 2 |
| 2017 | I-Seismograph: Observing, Measuring, and Analyzing Internet EarthquakesabstractDisruptive events, such as large-scale power outages, undersea cable cuts, or security attacks, could have an impact on the Internet and cause the Internet to deviate from its normal state of operation, which we also refer to as an “Internet earthquake.” As the Internet is a large, complex moving target, unfortunately little research has been done to define, observe, quantify, and analyze such impact on the Internet, whether it is during a past event period or in real time. In this paper, we devise an Internet seismograph, orI-seismograph, to fill this gap. Since routing is the most basic function of the Internet and the Border Gateway Protocol (BGP) is thede factostandard inter-domain routing protocol, we focus on BGP to observe, measure, and analyze the Internet earthquakes. After defining what an impact to BGP entails, we describe how I-seismograph observes and measures the impact, exemplify its usage during both old and recent disruptive events, and further validate its accuracy and convergency. Finally, we show that I-seismograph can further be used to help analyze what happened to BGP while BGP experienced an impact, including which autonomous systems (AS) were affected most or which AS paths or path segments surged significantly in BGP updates during an Internet earthquake. Mingwei Zhang 0004, Jun Li 0001, Scott Brooks |
IEEE/ACM Trans. Netw. | 2 |
| 2017 | NCShield: Protecting Decentralized, Matrix Factorization-Based Network Coordinate SystemsabstractNetwork Coordinate (NC) systems provide a scalable means for Internet distance prediction and are useful for various Internet-based services, such as cloud or web-based services. Decentralized, matrix factorization-based NC (MFNC) systems have received particular attention recently. They can serve large-scale distributed services (as opposed to centralized NC systems) and do not need to satisfy the triangle inequality (as opposed to Euclidean-based NC systems). However, because of their decentralized nature, MFNC systems are vulnerable to various malicious attacks. In this paper, we provide the first study on attacks toward MFNC systems, and propose a trust and reputation-based approach calledNCShieldto counter such attacks. It is fully decentralized and can easily be customized. Different from previous approaches, NCShield is able to distinguish between legitimate distance variations and malicious distance alterations. Using four representative data sets from the Internet, we show that NCShield can defend against not only the typical disorder, repulsion and isolation attacks, but also more advanced attacks such as frog-boiling attacks. For example, when selecting node pairs with a shorter distance than a predefined threshold in an online game scenario, even if 30 percent of nodes are malicious, NCShield can reduce the false positive rate from 45.5 to 3.7 percent. Yang Chen 0001, Shining Wu, Jun Li 0001, Xiaoming Fu 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2016 | Compressing IP Forwarding Tables with Small Bounded Update Time
Yuanyuan Zhang 0006, Mingwei Xu 0001, Ning Wang 0001, Jun Li 0001, Penghan Chen |
Comput. Networks | 4 |
| 2016 | Optimizing Cost for Online Social Networks on Geo-Distributed CloudsabstractGeo-distributed clouds provide an intriguing platform to deploy online social network (OSN) services. To leverage the potential of clouds, a major concern of OSN providers is optimizing the monetary cost spent in using cloud resources while considering other important requirements, including providing satisfactory quality of service (QoS) and data availability to OSN users. In this paper, we study the problem of cost optimization for the dynamic OSN on multiple geo-distributed clouds over consecutive time periods while meeting predefined QoS and data availability requirements. We model the cost, the QoS, as well as the data availability of the OSN, formulate the problem, and design an algorithm named${\tt cosplay}$. We carry out extensive experiments with a large-scale real-world Twitter trace over 10 geo-distributed clouds all across the US. Our results show that, while always ensuring the QoS and the data availability as required,${\tt cosplay}$can reduce much more one-time cost than the state-of-the-art methods, and it can also significantly reduce the accumulative cost when continuously evaluated over 48 months, with OSN dynamics comparable to real-world cases. Lei Jiao 0002, Jun Li 0001, Tianyin Xu, Xiaoming Fu 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2015 | MDTC: An efficient approach to TCAM-based multidimensional table compressionabstractTernary Content Addressable Memory(TCAM)-based multidimensional tables are widely used to implement Access Control Lists (ACLs) for Internet packet classification and filtering, and have also become attractive for constructing the forwarding tables of Internet routers and the flow tables of Openflow switches, where multiple fields are generally used to match incoming packets. However, as such tables can grow quickly as the Internet develops fast, and sometimes even expand in size because of TCAMs limitation in storing rules with range fields, it becomes imperative to compress these tables. In this paper, we propose a fast and efficient approach to multidimensional table compression. We divide the multidimensional space iteratively to obtain a series of cells, and then combine those cells that are associated with the same action. Our approach applies to tables of any dimension, addresses the range expansion problem, and provides efficient compression for TCAM-based tables. The experiments show that our approach has low computing cost in time, which is significant for the online update of tables. On average, it reduces 23.0% entries of the real-life ACLs, 25.8% to 55.1% of the generated two-dimension tables, 55.1% of the generated ACLs, and 28.4% of the generated Openflow flow tables. Hanqing Zhu, Mingwei Xu 0001, Qing Li 0006, Jun Li 0001, Yuan Yang 0001, Suogang Li |
Networking | 4 |
| 2015 | Nexthop-Selectable FIB aggregation: An instant approach for internet routing scalability
Qing Li 0006, Mingwei Xu 0001, Dan Wang 0002, Jun Li 0001, Yong Jiang 0001, Jiahai Yang 0001 |
Comput. Commun. | 4 |
| 2015 | SF-DRDoS: The store-and-flood distributed reflective denial of service attack
Bingshuang Liu, Jun Li 0001, Tao Wei 0002, Skyler Berg, Jiayi Ye, Chao Zhang 0008, Xinhui Han |
Comput. Commun. | 2 |
| 2015 | Improving lookup reliability in Kad
Bingshuang Liu, Tao Wei 0002, Chao Zhang 0008, Jun Li 0001 |
Peer-to-Peer Netw. Appl. | 4 |
| 2014 | Splider: A split-based crawler of the BT-DHT network and its applicationsabstractCapturing accurate snapshots of peer-to-peer (P2P) networks, especially those with millions of users, is essential to many P2P-based applications, including those monitoring and analyzing P2P networks. The large scale and dynamic nature of P2P networks, however, make this task very challenging. Existent crawlers of P2P networks, for example, often miss a substantial portion of the ID space while unnecessarily crawling numerous nodes repeatedly. In this paper, we design and evaluate a new crawler called Splider. Unlike traditional crawling algorithms that adopt an iterative approach, Splider recursively splits the ID space of P2P nodes to crawl even tiny corners of the ID space, while avoiding crawling repeated nodes. We further implement a Splider prototype for BT-DHT, a Kademlia-based distributed hash table (DHT) P2P network, that exploits the structure of routing tables at BT-DHT nodes. Experiments show that Splider is able to gather more than 16 million nodes with a 100% recall ratio, whereas a traditional iterative crawler can at best capture only about 8 million nodes with a 66% recall ratio while its traffic-cost effectiveness is 50% less than Splider. Splider can further support distributed deployment; without any synchronization overhead, it reduces the time of capturing a full snapshot to be only about 3 minutes. We finally report and analyze the captured BT-DHT snapshots, including the spatial and temporal distribution of BT-DHT nodes and the existence of sybil and eclipse attacks in BT-DHT. Bingshuang Liu, Shidong Wu, Tao Wei 0002, Chao Zhang 0008, Jun Li 0001 |
CCNC | 5 |
| 2014 | The store-and-flood distributed reflective denial of service attackabstractDistributed reflective denial of service (DRDoS) attacks, especially those based on UDP reflection and amplification, can generate hundreds of gigabits per second of attack traffic, and have become a significant threat to Internet security. In this paper we show that an attacker can further make the DRDoS attack more dangerous. In particular, we describe a new DRDoS attack called store-and-flood DRDoS, or SF-DRDoS. By leveraging peer-to-peer (P2P) file-sharing networks, SF-DRDoS becomes more surreptitious and powerful than traditional DRDoS. An attacker can store carefully prepared data on reflector nodes before the flooding phase to greatly increase the amplification factor of an attack. We implemented a prototype of SF-DRDoS on Kad, a popular Kademlia-based P2P file-sharing network. With real-world experiments, this attack achieved an amplification factor of 2400 on average, with the upper bound of attack bandwidth at 670 Gbps in Kad. Finally, we discuss possible defenses to mitigate the threat of SF-DRDoS. Bingshuang Liu, Skyler Berg, Jun Li 0001, Tao Wei 0002, Chao Zhang 0008, Xinhui Han |
ICCCN | 3 |
| 2014 | Multi-objective data placement for multi-cloud socially aware servicesabstractSocially aware services often have a large user base and data of users have to be partitioned and replicated over multiple geographically distributed clouds. Choosing in which cloud to place data, however, is difficult. Effective data placements entail meeting multiple system objectives, including reducing the usage of cloud resources, providing good service quality to users, and even minimizing the carbon footprint, while facing critical challenges such as the interconnection of social data, the conflicting requirements of different objectives, and the customized multi-cloud data access policies. In this paper, we study multi-objective optimization for placing users' data over multiple clouds for socially aware services. We build a model framework that can accommodate a range of different objectives, and based on this model we formulate the optimization problem. Leveraging graph cuts, we propose an optimization approach that decomposes our original problem into two simpler subproblems and solves them alternately in multiple rounds. We carry out evaluations using a large group of real-world geographically distributed users with realistic interactions, and place users' data over 10 clouds all across the US. We demonstrate results that are significantly superior to standard and de facto methods in all objectives, and also show that our approach is capable of exploring trade-offs among objectives, converges fast and scales to a huge user base. Lei Jiao 0002, Jun Li 0001, Xiaoming Fu 0001 |
INFOCOM | 2 |
| 2014 | Toward the most representative summaries of network user activitiesabstractA summary of a user's Internet activities, such as web visits, can closely reflect their interests and preferences. However, automating the summarization process is not trivial as it should strike a good balance between generality and specificity, while there is no gold standard for doing so. In our approach to summarizing user information, we introduce two scoring mechanisms that cooperatively optimize for polarizing criteria. Having mapped user activity information onto a category tree, the scoring mechanisms highlight the most representative tree node; the node provides an aggregated view, i.e., a summary, of the activities most representative of the user. We evaluate our approach by summarizing web activity on the network of a large cellular service provider to devise interests of individual users as well as user groups. Joshua Stein, Han Hee Song, Mario Baldi, Jun Li 0001 |
IWQoS | 4 |
| 2014 | TED: Inter-domain traffic engineering via deflectionabstractAs inter-domain routing on today's Internet does not and basically cannot consider traffic load when determining best traffic forwarding paths, it is not always optimal for a router to forward packets along its default path, especially when the router's default output port incurs a long queuing delay. In this paper, we design a new approach called TED in which border routers of autonomous systems (AS) adaptively deflect outbound traffic from a congested default path to an alternative path to significantly improve inter-domain traffic engineering (TE) and end-to-end throughput. With TED, every router only needs to examine the queue length of its own outgoing ports to orchestrate its deflection operation and ensure traffic forwarding is at line speed. It does not need to communicate or coordinate with other TED-capable routers or modify packet content, making TED incrementally deployable. Our evaluation shows that TED significantly increases the average throughput of traffic flows, and the improvement is comparable to directly upgrading router hardware and capacity. Finally, a prototype of TED on NetFPGA is also implemented. Jun Li 0001, Ying Liu 0024, Dan Li 0001 |
IWQoS | 2 |
| 2014 | CCOF: Congestion control on the fly for Inter-Domain routingabstractWe design a new routing system called CCOF in which border routers of autonomous systems (AS) adaptively redirect outbound traffic from a congested default path to an alternative path in favor of Inter Domain traffic engineering (TE). We show how this can be done simply, by examining outgoing port's queuing size, and efficiently, that maintains line speed forwarding. In addition, CCOF-router is completely compatible with legacy routers since it neither requires cooperation nor modifies the packet content. Our evaluation shows that CCOF significantly increases the average throughput of traffic flows, and has similar improvement as directly upgrading device capacity. Finally, prototype implementation is achieved on NetFPGA. Ying Liu 0024, Jun Li 0001 |
LANMAN | 3 |
| 2014 | SOUP: an online social network by the people, for the peopleabstractConcomitant with the tremendous growth of online social networking (OSN) platforms are increasing concerns from users about their privacy and the protection of their data. As user data management is usually centralized, OSN providers nowadays have the unprecedented privilege to access every user's private data, which makes large-scale privacy leakage at a single site possible. One way to address this issue is to decentralize user data management and replicate user data at individual end-user machines across the OSN. David Koll, Jun Li 0001, Xiaoming Fu 0001 |
Middleware | 2 |
| 2014 | On the state of OSN-based Sybil defensesabstractA Sybil attack can inject many forged identities (called Sybils) to subvert a target system. Because of the severe damage that Sybil attacks can cause to a wide range of networking applications, there has been a proliferation of Sybil defense schemes. Of particular attention are those that explore the online social networks (OSNs) of users in a victim system in different ways. Unfortunately, while effective Sybil defense solutions are urgently needed, it is unclear how effective these OSN-based solutions are under different contexts. For example, all current approaches have focused on a common, classical scenario where it is difficult for an attacker to link Sybils with honest users and create attack edges; however, researchers have found recently that a modern scenario also becomes typical where an attacker can employ simple strategies to obtain many attack edges. In this work we analyze the state of OSN-based Sybil defenses. Our objective is not to design yet another solution, but rather to thoroughly analyze, measure, and compare how well or inadequate the well-known existing OSN-based approaches perform under both the classical scenario and the modern scenario. Although these approaches mostly perform well under the classical scenario, we find that under the modern scenario they are vulnerable to Sybil attacks. As shown in our quantitative analysis, very often a Sybil only needs a handful of attack edges to disguise itself as a benign node, and there is only a limited success in tolerating Sybils. Our study further points to capabilities a new solution must possess; in particular, in defense against Sybils under the modern scenario, we anticipate a new approach that enriches the structure of a social graph with more information about the relations between its users can work more effectively. David Koll, Jun Li 0001, Joshua Stein, Xiaoming Fu 0001 |
Networking | 2 |
| 2014 | SOUP: an online social network by the people, for the peopleabstractWith increasing frequency, users raise concerns about data privacy and protection in centralized Online Social Networks (OSNs), in which providers have the unprecedented privilege to access and exploit every user's private data at will. To mitigate these concerns, researchers have suggested to decentralize OSNs and thereby enable users to control and manage access to their data themselves. However, previously proposed decentralization approaches suffer from several drawbacks. To tackle their deficiencies, we introduce the Self-Organized Universe of People (SOUP). In this demonstration, we present a prototype of SOUP and share our experiences from a real-world deployment. David Koll, Jun Li 0001, Xiaoming Fu 0001 |
SIGCOMM | 2 |
| 2014 | Drawbridge: software-defined DDoS-resistant traffic engineeringabstractEnd hosts in today's Internet have the best knowledge of the type of traffic they should receive, but they play no active role in traffic engineering. Traffic engineering is conducted by ISPs, which unfortunately are blind to specific user needs. End hosts are therefore subject to unwanted traffic, particularly from Distributed Denial of Service (DDoS) attacks. This research proposes a new system called DrawBridge to address this traffic engineering dilemma. By realizing the potential of software-defined networking (SDN), in this research we investigate a solution that enables end hosts to use their knowledge of desired traffic to improve traffic engineering during DDoS attacks. Jun Li 0001, Skyler Berg, Mingwei Zhang 0004, Peter L. Reiher, Tao Wei 0002 |
SIGCOMM | 1 |
| 2014 | Tsunami: A parasitic, indestructible botnet on Kad
Ghulam Memon, Jun Li 0001, Reza Rejaie |
Peer-to-Peer Netw. Appl. | 2 |
| 2013 | On the effectiveness of sybil defenses based on online social networksabstractA Sybil attack can inject many forged identities (called Sybils) to subvert a target system. Among various defense approaches, of particular attention are those that explore the online social networks (OSNs) of users in a target system to detect or tolerate Sybil nodes. Albeit different in their working principle, all these approaches assume it is difficult for an attacker to create attack edges to connect Sybils with honest users. However, researchers have found that an attacker can employ simple strategies to obtain many attack edges. In this work we revisit the state-of-the-art, OSN-based Sybil defenses, and point out their strengths and weaknesses due to the impact of the new properties. We find these defense approaches are vulnerable to attackers under the new scenario, and in many cases a Sybil node only needs to obtain a handful of attack edges to disguise itself as a benign node. David Koll, Jun Li 0001, Joshua Stein, Xiaoming Fu 0001 |
ICNP | 2 |
| 2013 | Optimizing data center traffic of Online Social NetworksabstractWith a huge number of users and a very large scale of data, an Online Social Network (OSN) service has to partition its data among multiple servers inside a data center. As data are often partitioned randomly, the response time in accessing the data is however unpredictable. Researchers have proposed social locality to address this concern: if a server hosts the master replica of a user's data, it must also host a replica (either master or slave) of every friend of this user, thus enabling convenient access of all of them on the same server. However, doing so comes with two overheads: the replication storage and the traffic of maintaining replica consistency. Existing work focuses on the former, but overlooks the latter that can consume considerable network resources. In this paper, we study social-locality-aware partitioning of the OSN data while meeting diverse performance goals of data center networks. We formulate the traffic optimization problem and propose a new traffic-aware data partitioning algorithm. Through the evaluations with a large-scale, real-world Twitter trace, we further show that, compared with state-of-the-art algorithms, our algorithm significantly reduces traffic without deteriorating the load balance among servers and causing extra replication storage. Lei Jiao 0002, Jun Li 0001, Xiaoming Fu 0001 |
LANMAN | 2 |
| 2012 | Buddyguard: A buddy system for fast and reliable detection of IP prefix anomaliesabstractDue to operational malpractice or security attacks, an IP prefix (i.e., a block of IP addresses) can undergo many types of routing anomalies. Perhaps the most well-known of such anomalies is prefix hijacking, where an attacker hijacks traffic meant to reach the legitimate user of a prefix. Anomalies can also easily occur through route leaks, which can disrupt traffic for numerous prefixes at once. While various solutions have been proposed to detect such anomalies, these solutions are limited and susceptible to attacker countermeasures. In this paper we present Buddyguard, a new approach to detecting prefix anomalies including prefix hijacking and route leaks. Buddyguard compares the behavior of a monitored prefix with the behavior of a set of numerous buddy prefixes. The system detects anomalies when the behavior of the monitored prefix significantly diverges from that of its buddies. Our evaluation results show that Buddyguard provides fast, accurate and lightweight monitoring of IP prefix anomalies, and its introduction and use of buddy prefixes enables it to be resilient against resourceful attackers. Jun Li 0001, Toby Ehrenkranz, Paul Elliott |
ICNP | 1 |
| 2012 | Cost optimization for Online Social Networks on geo-distributed cloudsabstractGeo-distributed IaaS (Infrastructure-as-a-Service) clouds provide an intriguing platform to deploy Online Social Network (OSN) services. To leverage the potential of clouds, a major task of OSN providers is optimizing the monetary cost spent on cloud resource utilization while providing satisfactory Quality of Service (QoS) to OSN users. We thus study the problem of cost optimization for the dynamic OSN on multiple geo-distributed clouds over consecutive time periods, with its QoS meeting the pre-defined requirement. We model the QoS as well as the cost of an OSN, formulate the problem, and design a solution named cosplay. Our experiments with a large-scale Twitter trace show that, while always ensuring the QoS as required, cosplay can achieve superior one-time cost reduction compared with the state of the art, and can also reduce the accumulative cost significantly when continuously evaluated over 48 months with dynamics comparable to real-world OSNs. Lei Jiao 0002, Jun Li 0001, Tianyin Xu, Xiaoming Fu 0001 |
ICNP | 2 |
| 2012 | NCShield: Securing decentralized, matrix factorization-based network coordinate systemsabstractWhile network coordinate (NC) systems provide scalable Internet distance estimation service and are useful for various Internet applications, decentralized, matrix factorization-based NC (MFNC) systems have received particular attention recently. They can serve large-scale distributed applications (as opposed to centralized NC systems) and do not need to assume triangle inequality (as opposed to Euclidean-based NC systems). However, because of their decentralized nature, MFNC systems are vulnerable to various malicious attacks. In this paper, we provide the first study on attacks toward MFNC systems, and propose a decentralized trust and reputation approach, called NCShield, to counter such attacks. Different from previous approaches, our approach is able to distinguish between legitimate distance variations and malicious distance alterations. Using four representative data sets from the Internet, we show that NCShield can defend against attacks with high accuracy. For example, when selecting node pairs with a shorter distance than a predefined threshold in an online game scenario, even if 30% nodes are malicious, NCShield can reduce the false positive rate from 45.5% to 3.7%. Shining Wu, Yang Chen 0001, Xiaoming Fu 0001, Jun Li 0001 |
IWQoS | 4 |
| 2012 | Ghost Domain Names: Revoked Yet Still Resolvable
Jian Jiang 0002, Jinjin Liang, Kang Li 0001, Jun Li 0001, Hai-Xin Duan |
NDSS | 4 |
| 2012 | Revisiting why Kad lookup failsabstractKad is one of the most popular peer-to-peer (P2P) networks deployed on today's Internet. Its reliability is dependent on not only to the usability of the file-sharing service, but also to the capability to support other Internet services. However, Kad can only attain around a 91% lookup success ratio today. We build a measurement system called Anthill to analyze Kad's performance quantitatively, and find that Kad's failures can be classified into four types: packet loss, selective Denial of Service (sDoS) nodes, search sequence miss, and publish/search space miss. The first two are due to environment changes, the third is caused by the detachment of routing and content operations in Kad, and the last one shows the limitations of the Kademlia DHT algorithm under Kad's current configuration. Based on the analysis, we propose corresponding approaches for Kad, which achieve a success ratio of 99.8%, with only moderate communication overhead. Bingshuang Liu, Tao Wei 0002, Jun Li 0001 |
P2P | 4 |
| 2011 | I-seismograph: Observing and measuring Internet earthquakesabstractDisruptive events such as large-scale power outages, undersea cable cuts, or Internet worms could cause the Internet to deviate from its normal state of operation. This deviation from normalcy is what we refer to as the “impact” on the Internet, or an “Internet earthquake.” As the Internet is a large, complex moving target, to date there has been little successful research on how to observe and quantify the impact on the Internet, whether it is during specific event periods or in real time. In this paper, we devise an Internet seismograph, or I-seismograph, to provide a “Richter scale” for the Internet. Since routing is the most basic function of the Internet and the Border Gateway Protocol (BGP) is the de facto standard inter-domain routing protocol, we focus on BGP. After defining what “impact” means with respect to BGP, we describe how I-seismograph measures the impact, exemplify its usage with several disruptive events, and further validate its accuracy and consistency. We show that we can evaluate the impact on BGP during an arbitrary period, including doing so in real time. Jun Li 0001, Scott Brooks |
INFOCOM | 1 |
| 2011 | mSSL: A framework for trusted and incentivized peer-to-peer data sharing between distrusted and selfish clients
Jun Li 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2010 | Behavior-Based Worm Detectors Compared
Shad Stafford, Jun Li 0001 |
RAID | 2 |
| 2010 | Realizing a Source Authentic Internet
Toby Ehrenkranz, Jun Li 0001, Patrick D. McDaniel |
SecureComm | 2 |
| 2009 | On the state of IP spoofing defenseabstractIP source address spoofing has plagued the Internet for many years. Attackers spoof source addresses to mount attacks and redirect blame. Researchers have proposed many mechanisms to defend against spoofing, with varying levels of success. With the defense mechanisms available today, where do we stand? How do the various defense mechanisms compare? This article first looks into the current state of IP spoofing, then thoroughly surveys the current state of IP spoofing defense. It evaluates data from the Spoofer Project, and describes and analyzes host-based defense methods, router-based defense methods, and their combinations. It further analyzes what obstacles stand in the way of deploying those modern solutions and what areas require further research. Toby Ehrenkranz, Jun Li 0001 |
ACM Trans. Internet Techn. | 2 |
| 2008 | Learning the valid incoming direction of IP packets
Jun Li 0001, Jelena Mirkovic, Toby Ehrenkranz, Mengqiu Wang, Peter L. Reiher, Lixia Zhang 0001 |
Comput. Networks | 1 |
| 2007 | Is your IP address prefix well-served by internet routing?abstractIn today's Internet, users or network operators cannot easily find out how reachable their IP address prefixes are from the rest of the Internet, nor do they know what kind of packet delivery quality they receive from Internet routing. Instead of setting up probing sites from multiple locations on the Internet and probing every prefix, we leverage the fact that there are continuous collections of BGP updates concerning the reachability of every IP address prefix. We introduce a novel data mining method and cluster IP address prefixes according to their BGP attributes, and verify if each cluster corresponds to a different level of packet delivery performance. Users can classify their prefix to see to which cluster the prefix belongs to. Jun Li 0001 |
CoNEXT | 2 |
| 2007 | Understanding and Utilizing the Hierarchy of Abnormal BGP EventsabstractAbnormal events, such as security attacks, misconfigurations, or electricity failures, could have severe consequences toward the normal operation of the Border Gateway Protocol (BGP) that is in charge of the delivery of packets between different autonomous domains, a key operation for the Internet to function. Unfortunately, it has been a difficult task for network security researchers and engineers to classify and detect these events. In our previous work, we have shown that with classification (which relies on the labeling with domain knowledge from BGP experts), it is feasible to effectively detect and distinguish some worms and blackouts from normal BGP behaviors. In this paper, we move one important step forward—we show that we can automatically detect and classify between different abnormal BGP events based on a hierarchy discovered by clustering. As a systematic application of data mining, we devise a clustering method based on normalized BGP data that forms a tree-like hierarchy of abnormal BGP event classes. We then obtain a set of classification rules for each class (node) in the hierarchy, thus able to label unknown BGP data to a closest class. Our method works even as the BGP dynamics evolve over time, as shown in our experiments with seven different abnormal events during a four-year period. Our work, in a more general context, shows it is promising to conduct an interdisciplinary research between network security and data mining in solving real-world problems. Dejing Dou, Jun Li 0001, Han Qin, Shiwoong Kim, Sheng Zhong 0002 |
SDM | 2 |
| 2007 | Functional similarities between computer worms and biological pathogens
Jun Li 0001, Paul Knickerbocker |
Comput. Secur. | 1 |
| 2006 | Toward Understanding the Behavior of BGP During Large-Scale Power OutagesabstractWhile the Internet continues to thrive, the resiliency of its fundamental routing infrastructure is not fully understood. In this paper, we analyze the behavior of the de facto inter-domain routing protocol, BGP, during a large-scale power outage that affected the connectivity of 3,175 networks in dozens of cities in the eastern USA and Canada. By observing proper metrics of BGP, we study BGP behavior from both the global level and the prefix level. At the global level, our results show that many global BGP metrics remained stable during the blackout event; importantly, we do not find an increase in the number of BGP announcements, a metric that has been primarily used to indicate significant changes in routing. However, we observe an apparent increase in the number of withdrawals. At the prefix level, we introduce per-prefix AS-path graphs and study their evolution for affected prefixes during the blackout; we have found that in such graphs there is a sharp decrease in the number of edges and nodes as well as changes in node degrees. Jun Li 0001, Eric Purpus |
GLOBECOM | 1 |
| 2005 | mSSL: Extending SSL to Support Data Sharing Among Collaborative ClientsabstractClient-server applications often do not scale well when a large number of clients access a single server. To solve this, a new trend is to allow a client to download data from other peer clients, in addition to from the server directly. This paradigm, which we call the hybrid peer-to-peer paradigm, is friendly to the server's scalability, but also faces new security challenges. For example, how can the server authenticate its clients and support data confidentiality? How can a client trust the data downloaded from other clients? What if a client refuses to acknowledge the service it received or overstates the service it offered? In this paper, we present a protocol, called mSSL, that provides a set of security functions to enable secure sharing of the data of a server among its clients. In addition to access control and confidentiality support, mSSL provides an original design on supporting data integrity and proof of service in this new context. Our evaluation further shows that mSSL has a reasonable overhead Jun Li 0001, Xun Kang |
ACSAC | 1 |
| 2004 | Resilient self-organizing overlay networks for security update deliveryabstractRapid and widespread dissemination of security updates throughout the Internet will be invaluable for many purposes, including sending early-warning signals, updating certificate revocation lists, distributing new virus signatures, etc. Notifying a large number of machines securely, quickly, and reliably is challenging. Such a system must outpace the propagation of threats, handle complexities in a large-scale environment, deal with interruption attacks on dissemination, and also secure itself. Revere addresses these problems by building a large-scale, self-organizing, and resilient overlay network on top of the Internet. We discuss how to secure the dissemination procedure and the overlay network, considering possible attacks and countermeasures. We present experimental measurements of a prototype implementation of Revere gathered using a large-scale-oriented approach. These measurements suggest that Revere can deliver security updates at the required scale, speed and resiliency for a reasonable cost. Jun Li 0001, Peter L. Reiher, Gerald J. Popek |
IEEE J. Sel. Areas Commun. | 1 |
| 2002 | SAVE: Source Address Validity Enforcement ProtocolabstractForcing all IP packets to carry correct source addresses can greatly help network security, attack tracing, and network problem debugging. However, due to asymmetries in today's Internet routing, routers do not have readily available information to verify the correctness of the source address for each incoming packet. In this paper we describe a new protocol, named SAVE, that can provide routers with the information needed for source address validation. SAVE messages propagate valid source address information from the source location to all destinations, allowing each router along the way to build an incoming table that associates each incoming interface of the router with a set of valid source address blocks. This paper presents the protocol design and evaluates its correctness and performance by simulation experiments. The paper also discusses the issues of protocol security, the effectiveness of partial SAVE deployment, and the handling of unconventional forms of network routing, such as mobile IP and tunneling. Jun Li 0001, Jelena Mirkovic, Mengqiu Wang, Peter L. Reiher, Lixia Zhang 0001 |
INFOCOM | 1 |
| 2002 | Securing distributed adaptation
Jun Li 0001, Mark Yarvis, Peter L. Reiher |
Comput. Networks | 1 |
| 1999 | Securing information transmission by redundancyabstractMany approaches have been used or proposed for providing security Ior inlormation dissemination over networks, including encryption, authentication, and digital signafures.These mechanisms do not, however, necessarily help ensure that a message is delivered at all.Attacks that try to destroy or intercept security messal~es require other mechanisms.Authenticated acknowledgements are sometimes useful for this purpose, but do not scale well.This paper discusses the use of redundancy to combat attempts to prevent intbrmation dissemination.Redundancy has been widely used in other areas, such as high availability data storage, file replication, and some faulttolerant systems.The se_curity problem has different characteristics that require different approaches to redundancy.We present one example of using redundancy to increase assurance of security updates delivery. Jun Li 0001, Peter L. Reiher, Gerald J. Popek |
NSPW | 1 |