Kang G. Shin

dblp:s/KangGShin · also Kang Geun Shin · DBLP profile ↗
← Back
681ranked-venue papers
58as first author
73since 2021 · last 2026
0000-0003-0086-8777ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 275 · 3 first-author · 34 since 2021Systems, architecture and hardware · 218 · 35 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 69 · 10 first-author · 6 since 2021Security and privacy · 60 · 1 first-author · 20 since 2021Software engineering, systems software and programming languages · 28 · 6 first-authorArtificial intelligence and machine learning · 20 · 4 first-author · 2 since 2021Databases, data management, data science and information retrieval · 15 · 6 since 2021Human-computer interaction and ubiquitous computing · 10 · 4 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 1 since 2021Theory of computation · 2
YearPublicationVenuePosition
2026 EchoScriptor: Automatic Lifelogging Narratives via Activity-Based Audio-Language Model
abstract
Automatic, camera-free lifelogging offers new opportunities for memory rehabilitation, personal informatics, and assistive technologies. However, most existing approaches limit daily activities to isolated event labels, offering little context and lacking the narrative coherence essential for effective lifelogging. Recent advances in audio–language models combine foundation audio processing with language-based reasoning, enabling open-ended sound understanding. We introduce EchoScriptor, an end-to-end system that transforms raw in-home audio into context-aware natural-language descriptions, generating coherent narrative lifelogs of activities and acoustic contexts. In moment-level evaluation, EchoScriptor achieved 94.15% activity recognition and 89.25% background recognition accuracy, and at the summary level, achieved an F1 score of 0.92, outperforming the classifier+LLM baseline. In our user study with 20 participants across 10 household activity videos, EchoScriptor summaries were consistently rated highly, approaching the perceived utility of human-written ones. By advancing from event detection to narrative understanding, EchoScriptor establishes a significant step toward automated, unobtrusive, context-aware lifelogging technologies.
Kaylee Yaxuan Li, Xinghao Zhou, Haizhong Zheng, Kang G. Shin, Alanson P. Sample
CHI4
2026 SpeechShield: Latency-Efficient and Robust Timbre-Aware Voice Protection Against Speech Synthesis Deepfake Attacks
Jianshuo Liu, Shiquan Dong, Hong Li 0004, Chenghua Gao, Kang G. Shin, Haining Wang 0001, Yimo Ren, Limin Sun 0001
DSN5
2026 Generative Covert Communication: Leveraging Signal Coupling for Secret Data Transmission
Zhao Li 0005, Linchuan Tan, Kang G. Shin, Hanqing Ding, Jia Liu 0009, Shen Qian, Zheng Yan 0002
INFOCOM4
2026 P2C-MUX: Multiplexing with Power and Polarity Coding for Communication Efficiency
Zhao Li 0005, Zhangbo Gao, Kang G. Shin, Hanqing Ding, Jia Liu 0009, Shen Qian, Zheng Yan 0002
INFOCOM4
2026 BBC: Enabling BLE to Support Bluetooth Classic
Hsun-Wei Cho, Kang G. Shin
NSDI2
2026 UWB-Based Localization of Smartphones inside a Vehicle to Prevent Distracted Driving
Kailai Cui, Ke Sun 0012, Kang G. Shin
SenSys3
2026 MagLens: Bringing Mobile, Fine-Grained Imaging to Ferrous Building Structures
abstract
Fine-grained inspection of ferrous structures, such as steel rebars and iron pipes, is essential for ensuring structural health/integrity. However, existing non-destructive imaging techniques often suffer from coarse spatial resolution, high operational costs, and limited mobility support, hence severely restricting their practical deployment. For example, ground-penetrating radar (GPR), constrained by its operating wavelength, cannot resolve sub-centimeter features or recover fine contours of embedded ferrous structures.
Jike Wang, Yasha Iravantchi, Mingke Wang, Alanson Sample, Kang G. Shin, Xinbing Wang, Dongyao Chen
SenSys5
2026 Design of Safer Control for Semi-Autonomous Vehicles
abstract
Component faults, bugs, and malicious attacks can all degrade in, or even prevent Semi-Autonomous Vehicles (SAVs) from, correctly capturing their operation context, which is essential to support critical safety features like emergency braking or wheel-steering. While safety features in contemporary SAVs usually rely on static assignment of control priority, such a design may lead to catastrophic accidents when accompanied with erroneous/compromised control and context estimation. To mitigate the grave consequence of using incorrect data, we propose CADCA , a novel control decision-maker for SAVs, that is designed to operate under sensor/data errors or falsifications as well as malicious/erroneous control inputs with the ultimate goal of resolving conflicting control inputs to ensure safety. Our evaluation of \( > \) 15,700 test-cases has shown CADCA to achieve a 98% success rate in preventing the execution of incorrect control decisions caused by component failures and/or malicious attacks in the most common (i.e., rear-end) collisions.
Chun-Yu (Daniel) Chen, Kang G. Shin
ACM Trans. Cyber Phys. Syst.2
2026 SecCSI: Securing Wireless Environment With RIS Against CSI-Forgery Attacks
abstract
Channel state information (CSI) is known to be crucial for both enhancing the transmission performance and ensuring physical-layer security (PLS) in wireless communication systems. To estimate a channel’s CSI, the transmitter (Tx) typically broadcasts a predetermined pilot signal, then the receiver (Rx) computes the channel coefficients based on the received pilot signal and returns the estimated CSI to the Tx. Most, if not all, of existing communication algorithms simply assume that the fed-back CSI is reliable/secure. However, in practice, a malicious terminal may send falsified CSI to the infrastructure, thus compromising the throughput and/or security of the communication over the channel. Although some researchers have already identified this vulnerability, demonstrated the feasibility of the CSI-forgery attacks, and designed countermeasures thereof, their methods either (i) are tailored to specific types of attacks, thus lacking generality, or (ii) require modifications to the pilot sequence and hence the protocol. To counter the CSI-forgery attacks and remove/mitigate the deficiencies of existing counter-measures, we first develop a comprehensive CSI-forgery model that can subsume the existing CSI-forgery attacks as special instances to facilitate the design of general countermeasures. Then, we propose a novel approach, called SecCSI, to detect potential CSI-forgery activities and identify their initiators using reconfigurable intelligent surface (RIS). SecCSI leverages the RIS to secretly and dynamically modify the wireless environment transparently to the receiver (Rx) in which the pilot signal is transmitted. The infrastructure can, therefore, detect any attempted manipulation of CSI by appropriately configuring the reflection coefficient matrix of the RIS, transmitting the pilot signal, and analyzing all CSI feedback. SecCSI can serve as a guard module for existing communication systems that simply accept the fed-back CSI without checking its trustworthiness. Our theoretical analysis, experimental and numerical evaluations have shown SecCSI to effectively detect the CSI-forgery attacks and identify the attacker.
Zhao Li 0005, Kang G. Shin, Zheng Yan 0002, Jia Liu 0009, Siwei Le
IEEE Trans. Inf. Forensics Secur.3
2026 ADA: Asynchronous Deterministic Access for Time-Sensitive Networking
abstract
Time-Sensitive Networking (TSN) enables deterministic transmission by requiring end systems to support 802.1Qbv and 802.1AS standards, which makes practical deployment challenging, especially for asynchronous end systems (AES) such as various legacy devices already deployed in industry. We present a new deterministic transmission scheme for asynchronous time-triggered flows from AES. First, we design an Asynchronous Deterministic Access (ADA) mechanism with two components: “Async to Sync” and “Latency Adaptation.” These components allow an AES flow to wait for its scheduled period, ensuring a theoretical end-to-end (E2E) deterministic delay. Second, we propose an ADA scheduling model to optimize the scheduling periods for AES flows. However, latency adaptation may cause AES flows to conflict with other flows at the final hop switch. To address this problem, we propose a conflict resolution mechanism that calculates safety distances between flows to reduce delay jitter. Finally, we implement ADA in our switches and evaluate its performance in terms of E2E delay and jitter. ADA is shown to achieve E2E delay and jitter reductions of 57.1–83.5% and 60.7–85.4%, respectively, over SOTA methods.
Wenlin Zhu, Zonghui Li, Kang G. Shin
IEEE Trans. Netw.6
2025 HW-Spy: Handwriting Inference by Tracing Pen-Tail Movements
abstract
While keyboard typing has been the most common way of inputting texts, handwriting still plays an important role in generating, inputting, or recording information like filling out essential/private forms. Considerable research has been done to identify and demonstrate the risk of keystroke-inference attacks. However, little has been done on handwriting inference despite its high risk of leaking sensitive information. To assess this under-explored risk of information leakage, we present a novel handwriting-inference attack, called HW-Spy, by tracing the victim's pen-tail movements when both the pen tip and the writing surface are outside the view of the attacker's camera, which usually happens when the victim is multitasking during an online meeting, when the victim's writing scene (in a public space) is recorded by a remote camera, or when the victim's writing behaviors are captured by the surveillance camera in a bank/dealership/realty office.
Long Huang 0001, Kang G. Shin
CCS2
2025 MichiCAN: Spoofing and Denial-of-Service Protection using Integrated CAN Controllers
abstract
The Controller Area Network (CAN) has been the de facto in-vehicle network protocol since the 1980s, despite lacking essential security principles like authenticity, confidentiality, integrity, and availability. CAN is especially vulnerable to Denial-of-Service (DoS) attacks, threatening the availability of safety-critical functions. Existing countermeasures have seen limited adoption due to challenges in real-time detection, prevention, and high overhead on Electronic Control Units (ECUs). To address these issues, we propose MichiCAN, a distributed, backward-compatible, real-time defense against DoS and spoofing attacks. MichiCAN leverages integrated/on-chip CAN controllers in modern MCUs, enabling bit-level access to CAN messages. This allows MichiCAN to detect DoS attacks during the arbitration phase and neutralize them by bussing off the attacker ECU swiftly. Experiments on a CAN bus prototype and a real vehicle demonstrate MichiCAN’s effectiveness in enhancing automotive network security.
Mert D. Pesé, Bulut Gözübüyük, Eric Andrechek, Habeeb Olufowobi, Mohammad Hamad, Kang G. Shin
DSN6
2025 Time-Triggered Flow Scheduling for Synchronization-Deviation-Tolerant TSN
abstract
Time-sensitive networking (TSN) has been widely used in industrial automation and automotive applications by precisely opening and closing the gates of packet queues. However, both clock drift and network congestion will likely result in timing misalignment when the clock synchronization protocol gPTP (802.1 AS) is used. This timing misalignment may, in turn, cause failure in forwarding packets at scheduled times and hence unexpected delay jitters, or even miss application deadlines. To address this acute problem, we propose a novel TSN scheduling algorithm, called SDT-TSN (Synchronization-Deviation-Tolerant TSN), to ensure that packets can still arrive on time and be transmitted deterministically even in the presence of inexact time synchronization. First, we formalize the linear constraint model of flow scheduling to maximize the tolerance of inexact time synchronization. Then, we propose an optimal algorithm based on SMT (Satisfiability Modulo Theories) and a fast heuristic algorithm to solve the packet scheduling problem under inexact network synchronization. SDT-TSN is the first to derive the maximum tolerable time-synchronization deviation. Finally, we evaluate SDT-TSN, demonstrating its capability of eliminating packet-forwarding failures due to the commonly-used/assumed constant time-synchronization deviation and increasing the tolerable synchronization deviation from 140µs to 480µs.
Jiamin Cui, Zonghui Li, Kang G. Shin
ICNP5
2025 Keypoints as Dynamic Centroids for Unified Human Pose and Segmentation
abstract
The dynamic movement of the human body presents a fundamental challenge for human pose estimation and body segmentation. State-of-the-art approaches primarily rely on combining keypoint heatmaps with segmentation masks, but often struggle in scenarios involving overlapping joints during pose estimation or rapidly changing poses for instance-level segmentation. To address these limitations, we leverage Keypoints as Dynamic Centroid (KDC), a new centroid-based representation for unified human pose estimation and instance-level segmentation. KDC adopts a bottom-up paradigm to generate keypoint heatmaps for easily distinguishable and complex keypoints, and improves keypoint detection and confidence scores by introducing KeyCentroids using a keypoint disk. It leverages high-confidence keypoints as dynamic centroids in the embedding space to generate MaskCentroids, allowing for the swift clustering of pixels to specific human instances during rapid changes in human body movements in a live environment. Our experimental evaluations focus on crowded and occluded cases using the CrowdPose, OCHuman, and COCO benchmarks, demonstrating KDC’s effectiveness and generalizability in challenging scenarios in terms of both accuracy and runtime performance. Our implementation is available at https://sites.google.com/view/niazahmad/projects/kdc.
Niaz Ahmad, Jawad Khan, Kang G. Shin, Youngmoon Lee
IJCAI3
2025 Scheduling Ev Battery Swap/Charge Operations
abstract
With the increasing popularity of electric vehicles (EVs), drivers want their vehicle batteries to be charged in a few minutes; at present, this is feasible only if battery service stations replace the EV battery pack with a fully charged battery pack. In this paper, we formulate the scheduling problem for battery swap stations, aiming to provide the drivers timing guarantees for different types of EVs, each with its own sporadic/periodic arrival pattern and deadline constraint. To solve this problem, we analyze its unique characteristics from a real-time scheduling perspective, with the main challenge being the circular timing dependency between two distinct scheduling processes: the swapping operation and the charging operation. We first derive a sufficient condition that decouples the dependency and then develop scheduling policies and timing guarantee techniques, designed for not only being specialized for the problem but also accommodating the sufficient condition in a time-predictable and resource-efficient manner. While the problem formulation and solution hold significance as the first attempt to establish real-time scheduling principles for battery swap stations, we also address how to accommodate real-world EV arrivals at a swapping station that do not necessarily follow a sporadic/periodic pattern. Finally, we evaluate the effectiveness of the proposed principles not only in addressing the formulated problem but also in accommodating real-world EV arrival patterns via simulation and a case study.
Jaeheon Kwak, Seongtae Lee, Kang G. Shin, Jinkyu Lee 0001
RTAS3
2025 Navigating Cookie Consent Violations Across the Globe
Brian Tang, Duc Bui, Kang G. Shin
USENIX Security Symposium3
2025 Cross-Modality and Equity-Aware Graph Pooling Fusion: A Bike Mobility Prediction Study
abstract
We propose an equity-awareGRAph-fusion differentiablePooling neural network to accurately predict the spatio-temporal urban mobility (e.g., station-level bike usage in terms of departures and arrivals) withEquity (GRAPE).GRAPEconsists of two independent hierarchical graph neural networks for two mobility systems—one as a target graph (i.e., a bike sharing system) and the other as an auxiliary graph (e.g., a taxi system). We have designed a convolutional fusion mechanism to jointly fuse the target and auxiliary graph embeddings and extract the shared spatial and temporal mobility patterns within the embeddings to enhance prediction accuracy. To further improve the equity of bike sharing systems for diverse communities, we focus on the bike resource allocation and model prediction performance, and propose to regularize the predicted bike resource as well as the accuracy across advantaged and disadvantaged communities, and thus mitigate the potential unfairness in the predicted bike sharing usage. Our evaluation of over 23 million bike rides and 100 million taxi trips in New York City and Chicago has demonstratedGRAPEto outperform all of the baseline approaches in terms of prediction accuracy (by 15.80% for NYC and 50.55% for Chicago on average) and social equity awareness (by 32.44% and 24.43% in terms of resource fairness for NYC and Chicago, and 13.36% and 16.52% in terms of performance fairness).
Suining He, Kang G. Shin, Mahan Tabatabaie
IEEE Trans. Big Data3
2025 Interference Recycling: Effective Utilization of Interference for Enhancing Data Transmission
abstract
With the rapid development of wireless communication technologies, Internet of Things (IoT) has emerged as one of the most important application scenarios. Due to the high density of IoT devices and the limited spectrum resources, along with the miniaturization and sustainability requirements of these devices, the development of low-cost interference management (IM) methods has become crucial for widespread use of IoT. Interference has long been known to harm network performance. Since a desired signal can be distorted by interference, and thus be incorrectly decoded at the destination, we argue that interference can also be transformed intentionally to extract the desired data from interfering signal(s). Based on this observation, we proposeInterference ReCycling(IRC) for the IoT. Under IRC, a recycling signal is generated using the interference a victim IoT device is subjected to, and then sent by the device’s associated gateway. Under the influence of the recycling signal, the desired data of the interfered/victim IoT transmission-pair can be recovered from the interference at the IoT device. We also show that the interfered user’s spectral efficiency (SE) with IRC can be optimized further by properly distributing the transmit power used for the desired signal’s transmission and the recycling signal. We validate the feasibility of IRC by implementing the method on the Universal Software Radio Peripheral (USRP) platform. Our theoretical analysis, experimental and numerical evaluation have shown that the proposed IRC can fully exploit interference, and hence can significantly improve the SE of the victim IoT device compared to other existing IM methods.
Zhao Li 0005, Chengyu Liu 0001, Siwei Le, Jie Chen 0056, Kang G. Shin, Zheng Yan 0002, Jia Liu 0009
IEEE Trans. Mob. Comput.6
2025 Distributed Modulation Exploiting IRS for Secure Communications
abstract
Due to the broadcast nature of wireless communications, users' data transmitted wirelessly is susceptible to security/privacy threats. The conventional modulation scheme “loads” all of the user's transmitted information onto a physical signal. Then, as long as an adversary overhears and processes the signal, s/he may access the user's information, hence breaching communication privacy. To counter this threat, we proposeIRS-DMSC, aDistributed Modulation based Secure Communication(DMSC) scheme by exploitingIntelligent Reflecting Surface(IRS). Under IRS-DMSC, two sub-signals are employed to realize legitimate data transmission. Of these two signals, one is directly generated by the legitimate transmitter (Tx), while the other is obtained by modulating the phase of the direct signal and then reflecting it at the IRS in an indirect way. Both the direct and indirect signal components superimpose on each other at the legitimate receiver (Rx) to produce a waveform identical to that obtained under traditional centralized modulation (CM), so that the legitimate Rx can employ the conventional demodulation method to recover the desired data from the received signal. IRS-DMSC incorporates the characteristics of wireless channels into the modulation process, and hence can fully exploit the randomness of wireless channels to enhance transmission secrecy. However, due to the distribution and randomization of legitimate transmission, it becomes difficult or even impossible for an eavesdropper to wiretap the legitimate user's information. Furthermore, in order to address the problem of decoding error incurred by the difference of two physical channels' fading, we developRelative Phase Calibration(RPC) andConstellation Point Calibration(CPC), to improve decoding correctness at the legitimate Rx. Our method design, experiment, and simulation have shown the proposed IRS-DMSC to cripple the eavesdropper while maintaining good performance of the legitimate transmission.
Zhao Li 0005, Siwei Le, Kang G. Shin, Jia Liu 0009, Zheng Yan 0002
IEEE Trans. Mob. Comput.4
2025 Parasitic Communication: Opportunistic Utilization of Interference Using Asymmetric Demodulation
abstract
With the rapid advancement of wireless communication technologies, interference has become a key impediment to the improvement of wireless data transmission performance. Traditional interference management (IM) suppresses or adjusts interference at the cost of additional communication resourceswithoutexploiting interference effectively. Especially when the interference is strong, simply eliminating it may be inefficient and costly. Moreover, wirelessly transmitted data is susceptible to threats such as eavesdropping, which also necessitates a thorough investigation. To address these issues cooperatively, we proposeOpportunistic Parasitic Communication with Asymmetric Demodulation(OPC-AD). In particular, we consider the interference experienced by the intended/target communication (i.e., parasitic) receiver (Rx) as the host signal. The target communication constructs a selection signal carrying parasitic indication information based on the data it intends to send and the data decoded by its Rx using asymmetric demodulation from the host signal, and then sends it to its Rx. This signal is used to instruct the parasitic Rx to extract the desired information from the host signal. OPC-AD allows for the exploitation of the interference (i.e., host signal) for data transmission to an interfered Rx. Using AD can also ensure the privacy of the host communication. Since the parasitic communication is concealed within the host signal, eavesdroppers cannot compromise the confidentiality of the parasitic transmission without precisely decoding the selection signal. Furthermore, considering more practical situations, such as non-zero delay/phase difference between the host signal and the selection signal, the implementation of the proposed method under various modulation schemes, and the enhancement of the probability of successful parasitism, we extend the OPC-AD design to cover a broader range of realistic scenarios. Our experimental results validate the applicability of OPC-AD, while our in-depth simulations demonstrate that parasitic communication can effectively thwart eavesdropping and achieve higher spectral efficiency (SE) than other existing IM methods, particularly in strong interference environments.
Zhao Li 0005, Kang G. Shin, Jia Liu 0009, Pintian Lyu, Zheng Yan 0002
IEEE Trans. Mob. Comput.3
2025 Paralfetch: Fast Application Launch on Personal Computing/Communication Devices
abstract
Paralfetchspeeds up application launches on personal computing/communication devices, by means of: 1) accurate collection of launch-related disk read requests, 2) pre-scheduling of these requests to improve I/O throughput during prefetching, and 3) overlapping application execution with disk prefetching for hiding disk access time from the execution of the application. We implementedParalfetchunder Linux kernels on a desktop/laptop PC, a Raspberry Pi 3 board, and an Android smartphone. Tests with popular applications show thatParalfetchsignificantly reduces application launch times on flash-based drives and hard disk drives, and it outperformsGSoC Prefetch[18] andFAST[21], which are representative application prefetchers available for Linux-based systems.
Junhee Ryu, Dongeun Lee 0001, Kang G. Shin, Kyungtae Kang
IEEE Trans. Parallel Distributed Syst.3
2024 DREW: Double-Throughput Emulated WiFi
abstract
Bidirectional communication between BLE/FSK devices and WiFi access points (APs) combines the benefits of long battery life, low device cost, and ubiquitous Internet access. However, prior cross-technology communication (CTC) solutions require transmission mixers inside FSK chips, thus not applicable to newer ultra-low-power (ULP) BLE chips, which removes these mixers to conserve power. Furthermore, throughputs of prior CTC solutions are limited to 1Mbps.
Hsun-Wei Cho, Kang G. Shin
MobiCom2
2024 Polaris: Accurate, Vision-free Fiducials for Mobile Robots with Magnetic Constellation
abstract
Fiducial marking is indispensable in mobile robots, including their pose calibration, contextual perception, and navigation. However, existing fiducial markers rely solely on vision-based perception which suffers such limitations as occlusion, energy overhead, and privacy leakage.
Jike Wang, Yasha Iravantchi, Alanson P. Sample, Kang G. Shin, Xinbing Wang, Dongyao Chen
MobiCom4
2024 Context-Aware Anomaly Detection Using Vehicle Dynamics
abstract
Replacing traditional vehicular components with electronic components brings numerous benefits but also introduces new vulnerabilities. To cope with this double-edged trend, we propose Context-Aware Detection of abnormal vehicle Dynamics (CADD) in general, or abnormal vehicle accelerations in particular. To account for the limited data availability common in production vehicles, we propose a new detection mechanism based on estimated vehicular contexts, instead of the commonly used “predict-input-then-compare.” That is, without relying on the unrealistically assumed availability of detailed measurements for accurate behavior modeling and prediction, CADD utilizes four sets of vehicle data to perform anomaly detection by cross-validating estimations of the underlying driving contexts, including road inclination, tire slippage, and total mass. Our extensive evaluation with > 87,000 test-cases has shown CADD to achieve > 96% recall and < 0.5% false positive rate. Furthermore, CADD can efficiently pinpoint the anomalous group of data with > 95% accuracy when the vehicle’s behavior deviates 0.07g (0.69 m/s2) from its normal pattern.
Chun-Yu (Daniel) Chen, Kang G. Shin, Soodeh Dadras
RAID2
2024 RT-BEV: Enhancing Real-Time BEV Perception for Autonomous Vehicles
abstract
Vision-centric Bird’s Eye View (BEV) perception has become popular for enhancing the situational awareness of autonomous vehicles (AVs). It uses multiple cameras to create a 360° view, capturing essential details for the vehicle’s navigation and decision-making. However, reducing the end-to-end (e2e) BEV perception latency without sacrificing accuracy is challenging due to the lack of co-optimization of message communication and object detection. Prior work either compresses the dense detection model to reduce computation which can hurt accuracy and assume images are well synchronized, or focuses on worstcase communication delay without considering the characteristics of object detection. To meet this challenge, we propose RT-BEV, the first frame-work designed to co-optimize message communication and object detection to improve real-time e2e BEV perception without sacrificing accuracy. The main insight of RT-BEV lies in generating traffic environment- and context-aware Regions of Interest (ROIs) for AV safety, combined with ROI-aware message communication. RT-BEV features an ROI-aware Camera Synchronizer that adaptively determines message groups and allowable delays based on ROIs’ coverage. We also develop a ROIs Generator to model context-aware ROIs and a Feature Split & Merge component to handle variable-sized ROIs effectively. Furthermore, a Time Predictor forecasts timelines for processing ROIs, and a Coordinator jointly optimizes latency and accuracy for the entire e2e pipeline. We have implemented RT-BEV in a ROS-based BEV perception pipeline and evaluated it with the nuScenes dataset. RT-BEV is shown to significantly enhances real-time BEV perception, reducing average e2e latency by $1.5 \times$, maintaining high mean Average Precision (mAP), doubling the number of processed frames, and improving the frame efficiency score (FES) by $2.9 \times$ compared to the existing approaches. Moreover, RT-BEV is shown to reduce the worst-case e2e latency by $19.3 \times$.
Liangkai Liu, Jinkyu Lee 0001, Kang G. Shin
RTSS3
2024 Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data Leakage
Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, Kang G. Shin
USENIX Security Symposium5
2024 PrivacyLens: On-Device PII Removal from RGB Images using Thermally-Enhanced Sensing
abstract
Internet-connected cameras support many useful home monitoring and health applications. However, these same cameras indiscriminately capture sensitive and Personally Identifiable Information (PII), limiting their acceptance in certain settings, such as the home. Prior works removed Region of Interest (ROI) to secure images and improve privacy. However, the methods that rely solely on RGB information to find persons are susceptible to environmental and lighting conditions, causing them to fail and leak PII. From our deployment study, nearly half of the images containing persons had a PII leakage when using RGB-only methods. Furthermore, ROI removal is often performed off-device, requiring the server performing these operations to be trustworthy. This work presents the PrivacyLens system, where with the addition of thermal sensing, our system has a significantly enhanced ability to find persons in RGB images and video and efficiently remove them on the device before any data is stored or transmitted, all while staying under typical IoT power constraints. From our aforementioned deployment study in an office-building atrium, family home, and outdoor park environment, the PrivacyLens prototype effectively removes PII with a sanitization rate of 99.1%. Additionally, PrivacyLens can use its embedded GPU to generate on-device features for downstream CV/ML tasks, as shown in three illustrative applications, further reducing the collection and storage of PII.
Yasha Iravantchi, Thomas Krolikowski, Kang G. Shin, Alanson P. Sample
Proc. Priv. Enhancing Technol.4
2024 Analysis and Prevention of MCAS-Induced Crashes
abstract
Semi-autonomous (SA) systems face the Challengeof determining which source to prioritize for control, whether it is from the human operator or the autonomous controller, especially when they conflict with each other. While one may design an SA system to default to accepting control from one or the other, such design choices can have catastrophic consequences in safety-critical settings. For instance, the sensors an autonomous controller relies upon may provide incorrect information about the environment due to tampering or natural fault. On the other hand, the human operator may also provide erroneous input. To better understand the consequences and resolution of this safety-critical design choice, we investigate a specific application of an SA system that failed due to a static assignment of control authority: the well-publicized Boeing 737-MAX maneuvering characteristics augmentation system (MCAS) that caused the crashes of Lion Air Flight 610 and Ethiopian Airlines Flight 302. First, using a representative simulation, we analyze and demonstrate the ease by which the original MCAS design could fail. Our analysis reveals the most robust public analysis of aircraft recoverability under MCAS faults, offering bounds for those scenarios beyond the original crashes. We also analyze Boeing’s updated MCAS and show how it falls short of its intended goals and continues to rely upon on a fault-prone static assignment of control priority. Using these insights, we present SA-MCAS, a new MCAS that both meets the intended goals of MCAS and avoids the failure cases that plague both MCAS designs. We demonstrate SA-MCAS’s ability to make safer and timely control decisions of the aircraft, even when the human and autonomous operators provide conflicting control inputs.
Noah T. Curran, Thomas Kennings, Kang G. Shin
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2024 iCoding: Countermeasure Against Interference and Eavesdropping in Wireless Communications
abstract
With the rapid development of wireless communication technologies, interference management (IM) and security/privacy in data transmission have become critically important. On one hand, due to the broadcast nature of wireless medium, the interference superimposed on the desired signal can destroy the integrity of data transmission. On the other hand, malicious receivers (Rxs) may eavesdrop a legitimate user’s transmission and thus breach the confidentiality of communication. To counter these threats, we propose a novel encoding method, called immunizing coding (iCoding), which handles both IM and physical-layer security simultaneously. By exploiting both channel state information (CSI) and data carried in the interference, an iCoded signal is generated and sent by the legitimate transmitter (Tx). The iCoded signal interacts with the interference at the desired/legitimate Rx, so that the intended data can be recovered without the influence of disturbance, i.e., immunity to interference. In addition, since the data carried in the iCoded signal which is obtained via encoding the desired data and interference cooperatively, is different from the original desired data, the eavesdropper cannot access unauthorized information by wiretapping the desired signal, thus achieving immunity to eavesdropping. Our theoretical analysis, experimental and numerical evaluation have shown iCoding to effectively manage interference while preventing potential eavesdropping, hence enhancing the legitimate user’s transmission and secrecy thereof.
Zhao Li 0005, Kang G. Shin, Zheng Yan 0002, Jia Liu 0009
IEEE Trans. Inf. Forensics Secur.3
2024 Decomposed and Distributed Modulation to Achieve Secure Transmission
abstract
With the rapid deployment and wide use of mobile services and applications, more and more sensitive user information is being transmitted wirelessly. Due to the broadcast nature of wireless transmissions, they are exposed to all surrounding entities and thus vulnerable to eavesdropping. To counter this vulnerability, we propose a new physical-layer secure transmission scheme, called DDM-Sec, based on decomposed and distributed modulation (DDM). We show that a high-order modulation can be decomposed into multiple quadrature phase shift keying (QPSK) modulations, each of which can be further represented by two mutually orthogonal binary phase shift keying (BPSK) modulations. Therefore, traditional modulation can be realized by two cooperative transmitters (Txs), each generating a BPSK signal, in a distributed manner. The legitimate receiver (Rx) can decode the desired/intended information from the mixed two received BPSK signals while preventing the eavesdropper from accessing the legitimate user's information. DDM-Sec can effectively exploit the randomness of wireless channels to secure data transmission, enrich the spatial signatures of the legitimate user's transmission by employing two cooperative Txs, and then distribute the user's information to two transmissions so that none of the decomposed signals alone carry the legitimate user's full information. Moreover, due to random deployment of the two Txs and Rx, delay difference of the two transmissions is introduced. This can be further utilized to make eavesdropping difficult. Our theoretical analysis and simulation have shown that DDM-Sec can effectively prevent the eavesdropping, and hence guarantee the secrecy of the legitimate user's data transmission.
Zhao Li 0005, Siwei Le, Jie Chen 0056, Kang G. Shin, Jia Liu 0009, Zheng Yan 0002, Riku Jäntti
IEEE Trans. Mob. Comput.4
2024 Exploiting Interference With an Intelligent Reflecting Surface to Enhance Data Transmission
abstract
With the increasing number of wireless devices connecting to networks and sharing spectrum resources, interference has become a major obstacle to improving network performance. Existing interference management (IM) methods treat interference as a negative factor and focus on suppressing or eliminating its impact on the transmission of intended signals. However, this often comes at the cost of consuming communication resources and degrading desired transmission performance. Therefore, the design of a cost-effective IM method that “exploits” interference is important. To achieve this goal, we proposeIntelligent Reflecting Surface Assisted Interference Exploitation(IRS-IE) to realize efficient desired data transmission. IRS-IE leverages the low-cost and adaptive deployment capabilities of IRS to gather and reflect interference towards the interfered receiver (Rx). By appropriately designing the reflection coefficient of IRS, a phase shift is introduced to the incident interference, allowing the reflected interference to interact with its direct counterpart at the interfered Rx. As a result, the interfered Rx can retrieve its desired data from the mixed interference. This way, IRS-IE can make use of the interference to facilitate the desired data transmission. Our theoretical analysis and simulation results show that IRS-IE significantly improves the spectral efficiency (SE) of the interfered communication pair over the other IM methods.
Zhao Li 0005, Chengyu Liu 0001, Kang G. Shin, Jia Liu 0009, Zheng Yan 0002, Riku Jäntti
IEEE Trans. Wirel. Commun.4
2023 T-TER: Defeating A2 Trojans with Targeted Tamper-Evident Routing
abstract
Since the inception of the Integrated Circuit (IC), the size of the transistors used to construct them has continually shrunk. While this advancement significantly improves computing capability, fabrication costs have skyrocketed. As a result, most IC designers must now outsource fabrication. Outsourcing, however, presents a security threat: comprehensive post-fabrication inspection is infeasible given the size of modern ICs, so it is nearly impossible to know if the foundry has altered the original design during fabrication (i.e., inserted a hardware Trojan). Defending against a foundry-side adversary is challenging because—even with as few as two gates—hardware Trojans can completely undermine software security. Researchers have attempted to both detect and prevent foundry-side attacks, but all existing defenses are ineffective against additive Trojans with footprints of a few gates or less.
Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks
AsiaCCS2
2023 Fast Application Launch on Personal Computing/Communication Devices
Junhee Ryu, Dongeun Lee 0001, Kang G. Shin, Kyungtae Kang
FAST3
2023 Decomposed and Distributed Modulation to Achieve Secure Transmission
abstract
Due to the broadcast nature of wireless transmissions, they are exposed to all surrounding entities and thus vulnerable to eavesdropping. To counter this vulnerability, we propose a new physical-layer secure transmission scheme, called DDM-Sec, based on decomposed and distributed modulation (DDM). DDM-Sec realizes traditional QPSK modulation by using two cooperative transmitters (Txs), each generating a BPSK signal, in a distributed manner. The legitimate receiver (Rx) can decode the desired/intended information from the mixed received signal while preventing the eavesdropper from accessing the legitimate user's information. DDM-Sec can effectively exploit the randomness of wireless channels to encrypt data transmission, enrich the spatial signatures of the legitimate transmission by employing two cooperative Txs. Moreover, DDM-Sec distributes user's information to two transmissions so that none of the decomposed signals alone carry the legitimate user's full information. Our theoretical analysis, hardware experiment, and simulation have shown that DDM-Sec can effectively prevent the eavesdropping, and hence guarantee the secrecy of the legitimate user's data transmission.
Zhao Li 0005, Siwei Le, Jie Chen 0056, Kang G. Shin, Riku Jäntti, Zheng Yan 0002, Jia Liu 0009
GLOBECOM4
2023 Interaction-Aware and Hierarchically-Explainable Heterogeneous Graph-based Imitation Learning for Autonomous Driving Simulation
abstract
Understanding and learning the actor-to-X inter-actions (AXIs), such as those between the focal vehicles (actor) and other traffic participants (e.g., other vehicles, pedestrians) as well as traffic environments (e.g., city/road map), is essential for the development of a decision-making model and simulation of autonomous driving (AD). Existing practices on imitation learning (IL) for AD simulation, despite the advances in the model learnability, have not accounted for fusing and differentiating the heterogeneous AXIs in complex road environments. Furthermore, how to further explain the hierarchical structures within the complex AXIs remains largely under-explored. To overcome these challenges, we propose HGIL, an interaction- aware and hierarchically-explainable Heterogeneous _Graph- based Imitation Learning approach for AD simulation. We have designed a novel heterogeneous interaction graph (HIG) to provide local and global representation as well as awareness of the AXIs. Integrating the HIG as the state embeddings, we have designed a hierarchically-explainable generative adversarial imitation learning approach, with local sub-graph and global cross-graph attention, to capture the interaction behaviors and driving decision-making processes. Our data-driven simulation and explanation studies have corroborated the accuracy and explainability of HGIL in learning and capturing the complex AXIs.
Mahan Tabatabaie, Suining He, Kang G. Shin
IROS3
2023 Unify: Turning BLE/FSK SoC into WiFi SoC
abstract
With the potential for connecting billions of WiFi devices to low-power Bluetooth/FSK devices, WiFi-Bluetooth cross-technology communication (CTC) has drawn significant interests from academia and industry. However, state-of-the-art CTC solutions either are limited to one-way communication, or require multiple chips with hardware modifications.
Hsun-Wei Cho, Kang G. Shin
MobiCom2
2023 METRO: Magnetic Road Markings for All-weather, Smart Roads
abstract
Road surface markings, like symbols and line markings, are vital traffic infrastructures for driving safety and efficiency. However, real-world conditions can impair the utility of existing road markings. For example, adverse weather conditions such as snow and rain can quickly obliterate visibility.
Jike Wang, Shanmu Wang, Yasha Iravantchi, Mingke Wang, Alanson P. Sample, Kang G. Shin, Xinbing Wang, Chenghu Zhou, Dongyao Chen
SenSys6
2023 Detection of Inconsistencies in Privacy Practices of Browser Extensions
abstract
All major web browsers support extensions to provide additional functionalities and enhance users’ browsing experience while the extensions can access and collect users’ data during their web browsing. Although the web extensions inform users of their data practices via multiple forms of notices, prior work has overlooked the critical gap between the actual data practices and the published privacy notices of browser extensions. To fill this gap, we propose ExtPrivA that automatically detects the inconsistencies between browser extensions’ data collection and their privacy disclosures. From the privacy policies and Dashboard disclosures, ExtPrivA extracts privacy statements to have a clear interpretation of the privacy practices of an extension. It emulates user interactions to trigger the extension’s functionalities and analyzes the initiators of network requests to accurately extract the users’ data transferred by the extension from the browser to external servers. Our end-to-end evaluation has shown ExtPrivA to detect inconsistencies between the privacy disclosures and data-collection behavior with an 85% precision. In a large-scale study of 47.2k extensions on the Chrome Web Store, we found 820 extensions with 1,290 flows that are inconsistent with their privacy statements. Even worse, we have found 525 pairs of contradictory privacy statements in the Dashboard disclosures and privacy policies of 360 extensions. These discrepancies between the privacy disclosures and the actual data-collection behavior are deemed as serious violations of the Store’s policies. Our findings highlight the critical issues in the privacy disclosures of browser extensions that potentially mislead, and even pose high privacy risks to, end-users.
Duc Bui, Brian Tang, Kang G. Shin
SP3
2023 Eye-Shield: Real-Time Protection of Mobile Device Screen Information from Shoulder Surfing
Brian Tang, Kang G. Shin
USENIX Security Symposium2
2023 Rethink Physical Security: Protecting Vehicles via Battery-Enabled Sensing and Control [Point of View]
abstract
Cyberization is the foundation of vehicle electrification and automation, requiring the deployment of ever-increasing on-board sensing, communication, and computing services. However, vehicle cyberization also introduces new cyber vulnerabilities. In this article, we discuss the opportunities and challenges of using the common 12/24V automotive batteries as sensors and actuators to provide vehicles with three-pronged physical security protection: driver authentication, vehicle access control, and vehicle intrusion detection.
Liang He 0002, Kang G. Shin
Proc. IEEE2
2023 In-Vehicle Phone Localization for Prevention of Distracted Driving
abstract
A new in-vehicle phone localization scheme, calledDAPL(Detection andAlarming of in-vehiclePhoneLocation), is proposed to determine the locations of smartphones inside a moving car, with the goal of preventing smartphone-distracted driving.DAPLoperates on commodity smartphones and cars, and does not require additional special/dedicated hardware to be installed inside the car, making its deployment easy and attractive to users and carmakers. Even when a phone is moved from one location to another inside a moving car,DAPLwill detect this movement, acquire the sensor data, and estimate the phone's destination location.DAPLcaptures the trajectory of each phone movement, the change of magnetic field, and the RSSI readings from the Bluetooth transceiver built in most cars, and then estimates the phone's destination location by matching the trajectory with the variation of magnetic field and the Bluetooth RSSI readings. Our extensive experimentation has shownDAPLto achieve an average of 91.71% accuracy of in-car phone localization at low energy overhead, i.e.,$<$2.5% reduction of actual usage (screen-on) time.
Chun-Yu (Daniel) Chen, Kang G. Shin
IEEE Trans. Mob. Comput.2
2023 Context-Aware Beam Tracking for 5G mmWave V2I Communications
abstract
Vehicles’ mobility causes frequent beam misalignments in millimeter wave (mmWave) vehicle-to-infrastructure (V2I) communications. In 5G systems, beam sweeping is done repeatedly to track a vehicle's mobility and maintain high-quality beam selection. Despite extensive studies on mmWave communications, there are still insufficient discussions on when to trigger beam sweeping for beam tracking. Triggering beam sweeping at an inappropriate time can either incur unnecessary overhead or degrade communication performance due to outdated beam selection. Based on this observation, we explore the problem of making beam-sweeping decisions for 5G mmWave vehicular communications. Considering the regularity in vehicle mobility, we propose aContext-aware standard-compatiBle beam update scheme (CarBeam) to help the base station determine when to trigger beam sweeping by exploiting the noisy and quantized beam-specific layer-1 reference signal received power feedback from the vehicle. Unlike prior work,CarBeamonly exploits the procedures and signaling supported in the current 5G beam management framework. Moreover, it can adapt its beam-sweeping decisions to vehicles's mobility for efficient beam tracking. The effectiveness ofCarBeamis evaluated and demonstrated using the vehicle traces from the TAPASCologne project.
Haichuan Ding, Kang G. Shin
IEEE Trans. Mob. Comput.2
2022 Are There Wireless Hidden Cameras Spying on Me?
abstract
The proliferation of IoT devices has created risks of their abuse for unauthorized sensing/monitoring of our daily activities. Especially, the leakage of images taken by wireless spy cameras in sensitive spaces, such as hotel rooms, Airbnb rentals, public restrooms, and shower rooms, has become a serious privacy concern/threat. To mitigate/address this pressing concern, we propose a Spy Camera Finder (SCamF) that uses ubiquitous smartphones to detect and locate wireless spy cameras by analyzing encrypted Wi-Fi network traffic. Not only by characterizing the network traffic patterns of wireless cameras but also by reconstructing encoded video frame sizes from encrypted traffic, SCamF effectively determines the existence of wireless cameras on the Wi-Fi networks, and accurately verifies whether the thus-detected cameras are indeed recording users’ activities. SCamF also accurately locates spy cameras by analyzing reconstructed video frame sizes. We have implemented SCamF on Android smartphones and evaluated its performance on a real testbed across 20 types of wireless cameras. Our experimental results show SCamF to: (1) classify wireless cameras with an accuracy of 0.98; (2) detect spy cameras among the classified wireless cameras with a true positive rate (TPR) of 0.97; (3) incur low false positive rates (FPRs) of 0 and 0.031 for non-camera devices and cameras not recording the users’ activities, respectively; (4) locate spy cameras with centimeter-level distance errors.
Jeongyoon Heo, Sangwon Gil, Youngman Jung, Jinmok Kim, Donguk Kim 0003, Yongdae Kim, Kang G. Shin, Choong-Hoon Lee
ACSAC8
2022 Do Opt-Outs Really Opt Me Out?
abstract
Online trackers, such as advertising and analytics services, have provided users with choices to opt out of their tracking and data collection to mitigate the users' concerns about increased privacy risks. While opt-out choices of online services for the cookies placed on their own websites have been examined before, the choices provided by trackers for their third-party tracking services on publisher websites have been largely overlooked. There is no guarantee that a tracker's opt-out options would faithfully follow the statements in its privacy policy. To address this concern, we develop an automated framework, called OptOutCheck, that analyzes (in)consistencies between trackers' data practices and the opt-out choice statements in their privacy policies. We create sentence-level classifiers, which achieve ≥ 84.6% precision on previously-unseen statements, to extract the opt-out policies that state neither tracking nor data collection for opted-out users from trackers' privacy-policy documents. tOptOutCheck analyzes both tracker and publisher websites to detect opt-out buttons, perform the opt-out, and extract the data flows to the tracker servers after the user opts out. Finally, we formalize the opt-out policies and data flows to derive logical conditions to detect the inconsistencies. In a large-scale study of 2.9k popular trackers, OptOutCheck detected opt-out choices on 165 trackers and found 11 trackers who exhibited data practices inconsistent with their stated opt-out policies. Since inconsistencies are violations of the trackers' privacy policies and demonstrate data collection without user consent, they are likely to lose users' trust in the online trackers and trigger the necessity of an automatic auditing process.
Duc Bui, Brian Tang, Kang G. Shin
CCS3
2022 Hydra : Resilient and Highly Available Remote Memory
Youngmoon Lee, Hasan Al Maruf, Mosharaf Chowdhury, Asaf Cidon, Kang G. Shin
FAST5
2022 FLEW: fully emulated wifi
abstract
WiFi is the de facto standard for providing wireless access to the Internet using the 2.4GHz ISM band. Tens of billions of WiFi devices were shipped worldwide and WiFi Access Points (APs) are ubiquitous in public, enterprise and personal environments. We have also witnessed the fast growth of IoT (Internet of Things) devices. With more stringent board-space and power requirements, many IoT devices use more power-efficient, lower-cost and smaller wireless chips, such as Bluetooth or proprietary wireless chips. Due to the mismatch of different wireless technologies, these devices access the Internet indirectly via far less ubiquitous IoT gateways. Bluetooth and most proprietary wireless chips are based on FSK (Frequency-Shift Keying) modulation since FSK can be implemented with extremely simple and low-power FM (Frequency Modulation) circuits.
Hsun-Wei Cho, Kang G. Shin
MobiCom2
2022 Automatic calibration of magnetic tracking
abstract
Magnetic sensing is emerging as an enabling technology for various engaging applications. Representative use cases include high-accuracy posture tracking, human-machine interaction, and haptic sensing. This technology uses multiple MEMS magnetometers to capture the changing magnetic field at a close distance. However, magnetometers are susceptible to real-world disturbances, such as hard- and soft-iron effects. As a result, users need to perform a cumbersome and lengthy calibration process frequently, severely limiting the usability of magnetic tracking.
Mingke Wang, Yasha Iravantchi, Alanson P. Sample, Kang G. Shin, Xiaohua Tian, Xinbing Wang, Dongyao Chen
MobiCom6
2022 Automatic calibration of magnetic tracking: demo
Mingke Wang, Yasha Iravantchi, Alanson P. Sample, Kang G. Shin, Xiaohua Tian, Xinbing Wang, Dongyao Chen
MobiCom6
2022 Battery-enabled anti-theft vehicle immobilizer
abstract
Auto thieves often exploit the cyber vulnerabilities of existing key/phone-based vehicle immobilizers. To prevent this exploitation of cyber vulnerabilities for auto thefts, we present Battery Sleuth (Bleuth), a novel "physical" vehicle immobilizer which is immune to the common cyber-attack vectors - avoiding the use of wireless communication between key/phone and vehicle as well as in-vehicle networks. Bleuth achieves this by using the common 12V vehicle batteries to authenticate the driver with encrypted power-line communication and then control the battery's output power based on the authentication results, hence (im)mobilizing the vehicle without requiring drivers to carry any additional token. Bleuth is also equipped with four alarms to detect, and respond to, illegitimate operations (i.e., theft attempts), including attempts of unauthorized cranking of the engine, removal/shorting of the authenticator from the battery, abuse of the PLC to drain the car battery, and removal of the dongle from the auxiliary power outlet. Bleuth recharges its power supply automatically to free drivers from the maintenance burden. We have prototyped Bleuth as an add-on module that can be installed on commodity vehicles and evaluated it via field tests on 8 vehicles. We have also demonstrated Bleuth's utility and effectiveness via a survey of 612 car owners.
Liang He 0002, Kang G. Shin
MobiSys2
2022 Battery-enabled vehicle immobilizer
abstract
To enhance anti-theft protection of vehicles, we present Battery Sleuth (Bleuth), a novel "physical" vehicle immobilizer that is immune to the common cyber-attack vectors of car keys/keyfobs. Bleuth uses the common 12V vehicle batteries to authenticate the driver with encrypted power-line communication and then control the vehicle's drivability by regulating the battery output power based on the authentication results, hence (im)mobilizing the vehicle without requiring drivers to carry any additional token.
Liang He 0002, Kang G. Shin
MobiSys2
2022 Protecting electric scooters from thefts using batteries
abstract
As the electric (e-) scooter market grows rapidly, e-scooter thefts are becoming a major issue. To mitigate this problem, we design, implement and evaluate BEAS, a Battery-Enabled Authentication System to provide e-scooters with an additional layer of anti-theft protection. Installed on commodity e-scooters as an add-on module, BEAS allows users to customize their passwords for activating e-scooters in the form of pre-defined on/off patterns of the scooter lamp, authenticates users by examining the password based on the thus-generated voltage, and immobilizes e-scooters based on the authentication results by controlling the battery output power. Compared to other existing/potential anti-theft solutions for e-scooters, BEAS has the advantages of being resistant to wireless hacking (i.e., a well-known cyber vulnerability of car keys/keyfobs) and convenient as users are not required to (un)install BEAS every time the e-scooter is parked or carry any additional tokens. We will demonstrate a proof-of-concept prototype of BEAS in this demo.
Samuel Wozinski, Liang He 0002, Kang G. Shin
MobiSys3
2022 DNN-SAM: Split-and-Merge DNN Execution for Real-Time Object Detection
abstract
As real-time object detection systems, such as autonomous cars, need to process input images acquired from multiple cameras, they face significant challenges in delivering accurate and timely inferences often based on machine learning (ML). To meet these challenges, we want to provide different levels of object detection accuracy and timeliness to different portions within each input image with different criticality levels. Specifically, we develop DNN-SAM, a dynamic Split-And-Merge Deep Neural Network (DNN) execution and scheduling framework, that enables seamless split-and-merge DNN execution for unmodified DNN models. Instead of processing an entire input image once in a full DNN model, DNN-SAM first splits a DNN inference task into two smaller sub-tasks-a mandatory sub-task dedicated for a safety-critical (cropped) portion of each image and an optional sub-task for processing a down-scaled image–then executes them independently, and finally merges their results into a complete inference. To achieve DNN-SAM’s timely and accurate detection of objects in each image, we also develop two scheduling algorithms that prioritize sub-tasks according to their criticality levels and adaptively adjust the scale of the input image to meet the timing constraints while minimizing the response time of mandatory sub-tasks or maximizing the accuracy of optional sub-tasks. We have implemented and evaluated DNN-SAM on a representative ML framework. Our evaluation shows DNN-SAM to improve detection accuracy in the safety-critical region by $2.0-3.7\times$ and lower average inference latency by $4.8-9.7\times$ over existing approaches without violating any timing constraints.
Woosung Kang 0002, Siwoo Chung, Jeremy Yuhyun Kim, Youngmoon Lee, Kilho Lee, Jinkyu Lee 0001, Kang G. Shin, Hoon Sung Chwa
RTAS7
2022 DETROIT: Data Collection, Translation and Sharing for Rapid Vehicular App Development
abstract
DETROIT is an open-source vehicle-agnostic end-to-end framework for vehicular data collection, translation and sharing that facilitates the rapid development of automotive apps. With vehicles becoming increasingly connected, unlocking sheer amounts of data from the in-vehicle network (IVN) can accelerate the development of many useful apps. Unlike existing commercial and academic solutions that can only access a restricted set of standardized emission-related sensor data and lack feasible data accessibility by third-party developers, DETROIT offers a convenient interface to develop apps which can access a broad range of powertrain-related sensors and car-body events thanks to crowd-sourcing vehicular translation tables by fully automated CAN bus reverse-engineering. DETROIT is developed with the objectives of simplicity, scalability, privacy and liability. To the best of our knowledge, this is the first end-to-end framework consisting of a frontend, backend and a developer portal to cover vehicular data collection, translation and sharing with app developers. Besides an extensive framework benchmark to show the light resource overhead and feasibility of DETROIT, we also have evaluated it by reimplementing two existing mobility apps from academia. Developers have reported that DETROIT offers high sensor fidelity, enhanced application flexibility, as well as low implementation complexity.
Mert D. Pesé, Dongyao Chen, C. Andrés Campos, Alice Ying, Troy Stacer, Kang G. Shin
SECON6
2022 SpecHammer: Combining Spectre and Rowhammer for New Speculative Attacks
abstract
The recent Spectre attacks have revealed how the performance gains from branch prediction come at the cost of weakened security. Spectre Variant 1 (v1) shows how an attacker-controlled variable passed to speculatively executed lines of code can leak secret information to an attacker. Numerous defenses have since been proposed to prevent Spectre attacks, each attempting to block all or some of the Spectre variants. In particular, defenses using taint-tracking are claimed to be the only way to protect against all forms of Spectre v1. However, we show that the defenses proposed thus far can be bypassed by combining Spectre with the well-known Rowhammer vulnerability. By using Rowhammer to modify victim values, we relax the requirement that the attacker needs to share a variable with the victim. Thus, defenses that rely on this requirement, such as taint-tracking, are no longer effective. Furthermore, without this crucial requirement, the number of gadgets that can potentially be used to launch a Spectre attack increases dramatically; those present in Linux kernel version 5.6 increases from about 100 to about 20,000 via Rowhammer bit-flips. Attackers can use these gadgets to steal sensitive information such as stack cookies or canaries, or use new triple gadgets to read any address in memory. We demonstrate two versions of the combined attack on example victims in both user and kernel spaces, showing the attack’s ability to leak sensitive data.
Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, Kang G. Shin
SP5
2022 Fuzzing Hardware Like Software
Timothy Trippel, Kang G. Shin, Alex Chernyakhovsky, Garret Kelly, Dominic Rizzo, Matthew Hicks
USENIX Security Symposium2
2022 Socially-Equitable Interactive Graph Information Fusion-based Prediction for Urban Dockless E-Scooter Sharing
abstract
Urban dockless e-scooter sharing (DES) has become a popular Web-of-Things (WoT) service and widely adopted globally. Despite its early commercial success, conventional mobility demand and supply prediction based on machine learning and subsequent redistribution may favor advantaged socio-economic communities and tourist regions, at the expense of reducing mobility accessibility and resource allocation for historically disadvantaged communities. To address this unfairness, we propose a socially-Equitable Interactive Graph information fusion-based mobility flow prediction system for Dockless E-scooter Sharing (EIGDES). By considering city regions as nodes connected by trips, EIGDES learns and captures the complex interactions across spatial and temporal graph features through a novel interactive graph information dissemination and fusion structure. We further design a novel model learning objective with metrics that capture both the mobility distributions and the socio-economic factors, ensuring spatial fairness in the communities’ resource accessibility and their experienced DES prediction accuracy. Through its integration with the optimization regularizer, EIGDES jointly learns the DES flow patterns and socio-economic factors, and returns socially-equitable flow predictions. Our in-depth experimental study upon more than 2,122,270 DES trips from three metropolitan cities in North America has demonstrated EIGDES’s effectiveness in accurate prediction of DES flow patterns with substantial reduction of mobility unfairness.
Suining He, Kang G. Shin
WWW2
2022 Framed Fidelity MAC: Losslessly packing multi-user transmissions in a virtual point-to-point framework
Zhao Li 0005, Bigui Zhang, Chengyu Liu 0001, Zhixian Chang, Kang G. Shin, Zheng Yan 0002
Comput. Networks5
2022 Pervasive Pose Estimation for Fall Detection
abstract
Falls are the second leading cause of accidental or unintentional injuries/deaths worldwide. Accurate pose estimation using commodity mobile devices will help early detection and injury assessment of falls, which are essential for the first aid of elderly falls. By following the definition of fall, we propose a P ervasive P ose Est imation scheme for fall detection ( P \( ^2 \) Est ), which measures changes in tilt angle and height of the human body. For the tilt measurement, P \( ^2 \) Est leverages the pointing of the mobile device, e.g., the smartphone, when unlocking to associate the Device coordinate system with the World coordinate system. For the height measurement, P \( ^2 \) Est exploits the fact that the person’s height remains unchanged while walking to calibrate the pressure difference between the device and the floor. We have prototyped and tested P \( ^2 \) Est in various situations and environments. Our extensive experimental results have demonstrated that P \( ^2 \) Est can track the body orientation irrespective of which pocket the phone is placed in. More importantly, it enables the phone’s barometer to detect falls in various environments with decimeter-level accuracy.
Jiaqing Luo, Ruiyu Bai, Suining He, Kang G. Shin
ACM Trans. Comput. Heal.4
2022 Information Fusion for (Re)Configuring Bike Station Networks With Crowdsourcing
abstract
Bike sharing service (BSS) networks have been proliferating all over the globe thanks to their success as the first/last-mile connectivity inside a smart city. Their (re)configuration — i.e., station (re)placement and dock resizing — has thus become increasingly important for BSS providers and smart city planners. Instead of using conventional labor-intensive manual surveys, we propose a novel information fusion framework calledCBikesthat (re)configures the BSS network by jointly fusing crowdsourced station suggestions from online websites and the usage history of bike stations. Using comprehensive real data analyses, we identify and exploit important global trip patterns to (re)configure the BSS network while mitigating the local biases of individual feedbacks. Specifically, crowdsourced feedbacks, station usage, cost and other constraints are fused into a joint optimization of BSS network configuration. We also model the spatial distributions of station usage to account for and estimate the unexplored regions without historical usage information. We further design a semidefinite programming transformation to solve the bike station (re)placement problem efficiently and effectively. Our extensive data analytics and evaluation have shownCBikes’ effectiveness and accuracy in (re)placing stations and resizing docks based on three large BSS systems (with$>$900 stations) in Chicago, Twin Cities (Minneapolis–Saint Paul), and Los Angeles.
Suining He, Kang G. Shin
IEEE Trans. Knowl. Data Eng.2
2022 Spatio-Temporal Capsule-Based Reinforcement Learning for Mobility-on-Demand Coordination
abstract
As an alternative means of convenient and smart transportation, mobility-on-demand (MOD), typified by online ride-sharing and connected taxicabs, has been rapidly growing and spreading worldwide. The large volume of complex traffic and the uncertainty of market supplies/demands have made it essential for many MOD service providers toproactivelydispatch vehicles towards ride-seekers. To meet this need effectively, we proposeSTRide, an MOD coordination learning mechanism reinforced spatio-temporally with capsules. We formalize the adaptive coordination of vehicles into a reinforcement learning framework.STRideincorporates spatial and temporal distributions of supplies (vehicles) and demands (ride requests), customers’ preferences and other external factors. A novel spatio-temporal capsule neural network is designed to predict the provider’s rewards based on MOD network states, vehicles and their dispatch actions. This way, the MOD platform adapts itself to the supply-demand dynamics with the best potential rewards. We have conducted extensive data analytics and experimental evaluation with five large-scale datasets ($\sim$27 million rides from Uber, NYC/Chicago Taxis, Didi and Car2Go).STRideis shown to outperform state-of-the-arts, substantially reducing request-rejection rate and passenger waiting time, and also increasing the service provider’s profits.
Suining He, Kang G. Shin
IEEE Trans. Knowl. Data Eng.2
2022 Distribution Prediction for Reconfiguring Urban Dockless E-Scooter Sharing Systems
abstract
Dockless E-scooter Sharing (DES) has become a popular means of last-mile commute for many smart cities. As e-scooters are getting deployed dynamically and flexibly across city regions that expand and/or shrink, accurate prediction of the e-scooter distribution given the reconfigured regions becomes essential for city planning. We presentGCScoot, a novel flow distribution prediction approach for reconfiguring urban DES systems. Based on real-world datasets with reconfiguration, we analyze e-scooter distribution features and flow dynamics for the data-driven designs. We propose a novel spatio-temporal graph capsule neural network withinGCScootto predict future dockless e-scooter flows given the reconfigured regions.GCScootpre-processes historical spatial e-scooter distributions into flow graph structures, where discretized city regions are considered as nodes and inter-region flows as edges. To facilitate initial training, we cluster the regions and generate virtual data for new deployment regions based on their peers in the same cluster. Given above designs, the region-to-region correlations embedded within the temporal flow graphs are captured via the multi-graph capsule convolutional neural network which accurately predicts the DES flows. Extensive studies upon four e-scooter datasets (total$>$3.4 million rides) in four populous US cities have corroborated accuracy and effectiveness ofGCScootin predicting the e-scooter distributions.
Suining He, Kang G. Shin
IEEE Trans. Knowl. Data Eng.2
2022 Accurate Angular Inference for 802.11ad Devices Using Beam-Specific Measurements
abstract
Due to their sparsity, 60GHz channels are characterized by a few dominant paths. Knowing the angular information of their dominant paths, we can develop various applications, such as the prediction of link performance and the tracking of 802.11ad devices. Although they are equipped with phased arrays, the angular inference for 802.11ad devices is still challenging due to their limited number of RF chains and limited phase control capabilities. Considering the beam sweeping operation and the high communication bandwidth of 802.11ad devices, we propose variation-based angle estimation (VAE), calledVAE-CIR, by utilizing beam-specific channel impulse responses (CIRs) measured under different beams and the directional gains of the corresponding beams to infer the angular information of dominant paths. Unlike state-of-the-arts,VAE-CIRexploits the variations between different beam-specific CIRs for angular inference and provides a performance guarantee in the high signal-to-noise-ratio regime. To evaluateVAE-CIR, we generate the beam-specific CIRs by simulating the beam sweeping of 802.11ad devices with the beam patterns measured on off-the-shelf 802.11ad devices. The 60GHz channel is generated via a ray-tracing-based simulator and the CIRs are extracted via channel estimation based on Golay sequences. Through extensive experiments,VAE-CIRis shown to achieve more accurate angle estimation than existing schemes.
Haichuan Ding, Kang G. Shin
IEEE Trans. Mob. Comput.2
2021 S2-CAN: Sufficiently Secure Controller Area Network
abstract
As automotive security concerns are rising, the Controller Area Network (CAN) — the de facto standard of in-vehicle communication protocol — has come under scrutiny due to its lack of encryption and authentication. Several vulnerabilities, such as eavesdropping, spoofing, and replay attacks, have shown that the current implementation needs to be extended. Both academic and commercial solutions for a Secure CAN (S-CAN) have been proposed, but OEMs have not yet integrated them into their products. The main reasons for this lack of adoption are their heavy use of limited computational resources in the vehicle, increased latency that can lead to missed deadlines for safety-critical messages, as well as insufficient space available in a CAN frame to include a Message Authentication Code (MAC).
Mert D. Pesé, Jay W. Schauer, Kang G. Shin
ACSAC4
2021 Consistency Analysis of Data-Usage Purposes in Mobile Apps
abstract
While privacy laws and regulations require apps and services to disclose the purposes of their data collection to the users (i.e., why do they collect my data?), the data usage in an app's actual behavior does not always comply with the purposes stated in its privacy policy. Automated techniques have been proposed to analyze apps' privacy policies and their execution behavior, but they often overlooked the purposes of the apps' data collection, use and sharing. To mitigate this oversight, we propose PurPliance, an automated system that detects the inconsistencies between the data-usage purposes stated in a natural language privacy policy and those of the actual execution behavior of an Android app. PurPliance analyzes the predicate-argument structure of policy sentences and classifies the extracted purpose clauses into a taxonomy of data purposes. Purposes of actual data usage are inferred from network data traffic. We propose a formal model to represent and verify the data usage purposes in the extracted privacy statements and data flows to detect policy contradictions in a privacy policy and flow-to-policy inconsistencies between network data flows and privacy statements. Our evaluation results of end-to-end contradiction detection have shown PurPliance to improve detection precision from 19% to 95% and recall from 10% to 50% compared to a state-of-the-art method. Our analysis of 23.1k Android apps has also shown PurPliance to detect contradictions in 18.14% of privacy policies and flow-to-policy inconsistencies in 69.66% of apps, indicating the prevalence of inconsistencies of data practices in mobile apps.
Duc Bui, Kang G. Shin, Jong-Min Choi, Jun-Bum Shin
CCS3
2021 iCoding: Countermeasure Against Interference and Eavesdropping in Wireless Communications
abstract
With the rapid development of wireless communication technologies, interference management (IM) and security/privacy in data transmission have become critically important. On one hand, due to the broadcast nature of wireless medium, the interference superimposed on the desired signal can destroy the integrity of data transmission. On the other hand, malicious receivers (Rxs) may eavesdrop a legitimate user's transmission and thus breach the confidentiality of communication. To counter these threats, we propose a novel encoding method, called immunizing coding (iCoding), which handles both IM and physical-layer security simultaneously. By exploiting both channel state information (CSI) and data carried in the interference, an iCoded signal is generated and sent by the legitimate transmitter (Tx). The iCoded signal interacts with the interference at the desired/legitimate Rx, so that the intended data can be recovered without the influence of disturbance, i.e., immunity to interference is achieved. In addition, since the data carried in the iCoded signal which is obtained via encoding the desired data and interference cooperatively, is different from the original desired data, the eavesdropper cannot access legitimate information by wiretapping the desired signal. Therefore, immunity to eavesdropping is achieved. Our theoretical analysis and in-depth simulation have shown iCoding to effectively manage interference while preventing potential eavesdropping, hence enhancing the legitimate user's data transmission and secrecy thereof.
Zhao Li 0005, Yanyan Zhu, Kang G. Shin
GLOBECOM3
2021 MagX: wearable, untethered hands tracking with passive magnets
abstract
Accurate tracking of the hands and fingers allows users to employ natural gestures in various interactive applications. Hand tracking also supports health applications, such as monitoring face-touching, a common vector for infectious disease. However, for both types of applications, the utility of hand tracking is often limited by the impracticality of bulky tethered systems (e.g., instrumented gloves) or inherent limitations (e.g., Line of Sight or privacy concerns with vision-based systems). These limitations have severely restricted the adoption of hand tracking in real-world applications. We present MagX, a fully untethered on-body hand tracking system utilizing passive magnets and a novel magnetic sensing platform. Since passive magnets require no maintenance, they can be worn on the hands indefinitely, and only the sensor board needs recharging, akin to a smartwatch.
Dongyao Chen, Mingke Wang, Chenxi He, Yasha Iravantchi, Alanson P. Sample, Kang G. Shin, Xinbing Wang
MobiCom7
2021 Wearable, untethered hands tracking with passive magnets
abstract
Accurate tracking of the hands and fingers allows users to employ natural gestures in various interactive applications, e.g., controller-free interaction in augmented reality. Hand tracking also supports health applications, such as monitoring face-touching, a common vector for infectious disease. However, for both types of applications, the utility of hand tracking is often limited by the impracticality of bulky tethered systems (e.g., instrumented gloves) or inherent limitations (e.g., Line of Sight or privacy concerns with vision-based systems). These limitations have severely restricted the adoption of hand tracking in real-world applications. We demonstrate MagX, a fully untethered on-body hand tracking system utilizing passive magnets and a novel magnetic sensing platform. Since passive magnets require no maintenance, they can be worn on the hands indefinitely, and only the sensor board needs recharging, akin to a smartwatch.
Dongyao Chen, Mingke Wang, Chenxi He, Yasha Iravantchi, Alanson P. Sample, Kang G. Shin, Xinbing Wang
MobiCom7
2021 ML for RT: Priority Assignment Using Machine Learning
abstract
As machine learning (ML) has been proven effective in solving various problems, researchers in the real-time systems (RT) community have recently paid increasing attention to ML. While most of them focused on timing issues for ML applications (i.e., RT for ML), only a little has been done on the use of ML for solving fundamental RT problems. In this paper, we aim at utilizing ML to solve a fundamental RT problem of priority assignment for global fixed-priority preemptive (gFP) scheduling on a multiprocessor platform. This problem is known to be challenging in the case of a large number (n) of tasks in a task set because exhaustive testing of all priority assignments (as many as n!) is intractable and existing heuristics cannot find a schedulable priority assignment, even if exists, for a number of task sets. We systematically incorporate RT domain knowledge into ML and develop an ML framework tailored to the problem, called PAL. First, raising and addressing technical issues including neural architecture selection and training sample regulation, we enable PAL to infer a schedulable priority assignment of a set of n tasks, by training PAL with same-size (i.e., with n tasks) samples each of whose schedulable priority assignment has already been identified. Second, considering the exhaustive testing of all priority assignments of each task set with large n makes it intractable to provide training samples to PAL, we derive inductive properties that can generate training samples with large n from those with small n, through empirical observation of PAL and mathematical analysis of the target gFP schedulability test. Finally, utilizing the inductive properties and additional techniques, we propose how to systematically implement PAL whose training sample generation process not only yields unbiased samples but also is tractable even for large n. Our experimental results demonstrate PAL covers a number of additional task sets, each of which has never been proven schedulable by any existing approaches for gFP.
Seunghoon Lee 0002, Hyeongboo Baek, Honguk Woo, Kang G. Shin, Jinkyu Lee 0001
RTAS4
2021 BlueFi: bluetooth over WiFi
abstract
Bluetooth and WiFi are the two dominant technologies enabling the communication of mobile and IoT devices. Built with specific design goals and principles, they are vastly different, each using its own hardware and software. Thus, they are not interoperable and require different hardware.
Hsun-Wei Cho, Kang G. Shin
SIGCOMM2
2021 Bomberman: Defining and Defeating Hardware Ticking Timebombs at Design-time
abstract
To cope with ever-increasing design complexities, integrated circuit designers increase both the size of their design teams and their reliance on third-party intellectual property (IP). Both come at the expense of trust: it is computationally infeasible to exhaustively verify that a design is free of all possible malicious modifications (i.e., hardware Trojans). Making matters worse, unlike software, hardware modifications are permanent: there is no "patching" mechanism for hardware; and powerful: they serve as a foothold for subverting software that sits above.To counter this threat, prior work uses both static and dynamic analysis techniques to verify hardware designs are Trojan-free. Unfortunately, researchers continue to reveal weaknesses in these "one-size-fits-all", heuristic-based approaches. Instead of attempting to detect all possible hardware Trojans, we take the first step in addressing the hardware Trojan threat in a divide-and-conquer fashion: defining and eliminating Ticking Timebomb Trojans (TTTs), forcing attackers to implement larger Trojan designs detectable via existing verification and side-channel defenses. Like many system-level software defenses (e.g., Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP)), our goal is to systematically constrict the hardware attacker’s design space.First, we construct a definition of TTTs derived from their functional behavior. Next, we translate this definition into fundamental components required to realize TTT behavior in hardware. Using these components, we expand the set of all known TTTs to a total of six variants—including unseen variants. Leveraging our definition, we design and implement a TTT-specific dynamic verification toolchain extension, called Bomber-man. Using four real-world hardware designs, we demonstrate Bomberman’s ability to detect all TTT variants, where previous defenses fail, with <1.2% false positives.
Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks
SP2
2021 Incentivizing Platform-User Interactions for Crowdsensing
abstract
For effective crowdsensing, it is essential to incentivize the interactions of participants and platforms. Existing approaches do not tailor users’ bidding to their preferences, i.e., personalized bidding (PB). To meet this need, we design an incentive mechanism, called Picasso, that achieves not only the expressiveness and description efficiency of PB for users, but also minimal social cost, computational efficiency, and strategy proof for platform owners. This design is, however, challenging due to the intrinsic conflicting goals of the platform owner and users. To handle these conflicts, Picasso represents bids in a novel 3-D expression space by orchestrating three logical operations to balance among expressiveness, computational complexity, and description efficiency. Moreover, we equivalently decompose and recombine the complex task dependencies of bids originated from the expressiveness of PB, thus achieving a constant-factor approximation of optimal task allocation with strategy proof in polynomial time. These properties of Picasso are proven theoretically. In addition to a detailed simulation study, our trace-driven evaluations show that, compared to existing approaches, Picasso can enable each user to bid$9.7\times $more tasks, on average, and decrease the description length by 74%, thus encouraging more users’ participation. Picasso also reduces the platform owner’s payment by more than 61%, hence yielding a win–win solution for incentivizing platform–user interactions.
Chaocan Xiang, Suining He, Kang G. Shin, Yuben Qu, Panlong Yang
IEEE Internet Things J.3
2021 Automated Extraction and Presentation of Data Practices in Privacy Policies
abstract
Abstract Privacy policies are documents required by law and regulations that notify users of the collection, use, and sharing of their personal information on services or applications. While the extraction of personal data objects and their usage thereon is one of the fundamental steps in their automated analysis, it remains challenging due to the complex policy statements written in legal (vague) language. Prior work is limited by small/generated datasets and manually created rules. We formulate the extraction of fine-grained personal data phrases and the corresponding data collection or sharing practices as a sequence-labeling problem that can be solved by an entity-recognition model. We create a large dataset with 4.1k sentences (97k tokens) and 2.6k annotated fine-grained data practices from 30 real-world privacy policies to train and evaluate neural networks. We present a fully automated system, called PI-Extract, which accurately extracts privacy practices by a neural model and outperforms, by a large margin, strong rule-based baselines. We conduct a user study on the effects of data practice annotation which highlights and describes the data practices extracted by PI-Extract to help users better understand privacy-policy documents. Our experimental evaluation results show that the annotation significantly improves the users’ reading comprehension of policy texts, as indicated by a 26.6% increase in the average total reading score.
Duc Bui, Kang G. Shin, Jong-Min Choi, Jun-Bum Shin
Proc. Priv. Enhancing Technol.2
2021 Exploiting Interactions of Multiple Interference for Cooperative Interference Alignment
abstract
Wireless networks are usually deployed to cover more overlapping areas, experiencing severe interferences and hence making interference management essential for their viability. Interference alignment (IA) is an effective way of interference management and has thus received significant attention. With IA, at least one degree-of-freedom (DoF) should be used to place the aligned interferences. However, when multiple interferences are from one identical transmitter and to a common destination, IA is not applicable under a one-DoF cost constraint. If these interfering signals are aligned in the same direction at the interfered receiver, they will also overlap with each other at their intended receiver, thus becoming indistinguishable. Moreover, IA is realized by adjusting the spatial feature of disturbance, hence incurring co-channel interference to the interfering transmission-pair’s own communication. To solve this problem, we proposecooperative IA. Instead of adjusting the spatial characteristics of all interferences, we aim to achieve IA by adjusting interferences’ strength along with one or none interference’s signature, based on the interactions among multiple wireless disturbances. We propose two cooperative IA schemes: cooperative IA with space-power adjustment and cooperative IA with power adjustment. With the first method, the overall effect of all interferences is aligned in the orthogonal direction with respect to the desired signal at the interfered receiver. This method modifies the direction of one interference with a properly designed precoding vector and the strength of all interferences via power allocation. Under the second scheme, the strength of all interfering signals is modified so that the overall effect of multiple interferences is orthogonal to the desired transmission while guaranteeing the orthogonality among the interfering signals at their intended receiver. Our theoretical analysis and in-depth simulation have shown that the proposed schemes can effectively manage multiple interferences from an identical source while achieving good performance of the interfering transmission-pair.
Zhao Li 0005, Jun Li 0095, Yinghou Liu, Xiujuan Liang, Kang G. Shin, Zheng Yan 0002, Hui Li 0006
IEEE Trans. Wirel. Commun.5
2020 Causes and fixes of unexpected phone shutoffs
abstract
Many users have reported that their smartphones shut off unexpectedly, even when they show >30% remaining battery capacity. After examining the problem from both the user and phone sides, we discovered the cause of these unexpected shutoffs to be a large and dynamic internal voltage drop of the phone battery, which is, in turn, caused by the dynamics of both battery's internal resistance and the phone's discharge current. To fix these unexpected shutoffs, we design a novel Battery-aware Power Management (BPM) middleware that accounts for these dual-dynamics in phone operation. Specifically, BPM profiles the battery's internal resistance --- which varies with battery state-of-charge (SoC), temperature, and aging --- using a novel duty-cycled charging method. BPM then regulates, at run-time, the phone's discharge current based on the constructed battery profile. We have implemented and evaluated BPM on 4 commodity smartphones from different OEMs with the latest battery firmware, demonstrating that BPM prevents unexpected phone shutoffs and extends their operation time by 1.16--2.03X. Our user study, which includes 121 mobile phone users, also corroborates BPM's usefulness/attractiveness.
Youngmoon Lee, Liang He 0002, Kang G. Shin
MobiSys3
2020 Optimal Priority Assignment for Multiple CAN/CAN-FD Buses with a Central Gateway
abstract
Automakers keep introducing new functions to vehicles to entice customers, thus increasing the size/number of in-vehicle buses. As a result, adopting multi-buses with a central gateway is becoming a norm in current and future vehicles. Since adding buses increases production cost, knowing whether or not to add a bus at design time to meet the given requirements is essential to design a cost-optimized in-vehicle network. However, due to the lack of an optimal priority-assignment algorithm for multi-bus systems, it is difficult to determine whether additional buses are needed. To address this difficulty, we propose an optimal priority-assignment algorithm, called OPMB, for multiple CAN/CAN-FD buses with a central gateway. OPMB builds on backtracking, and is thus of exponential time complexity. To reduce the execution time effectively for industry-size problems, we identify several theory-proven search-space reduction conditions. Our in-depth simulation has demonstrated that OPMB outperforms the state-of-art priority-assignment algorithms for multi-bus systems, and is suitable for high-speed systems which represent future automotive systems. Also, OPMB is shown to be feasible for most realistic automotive message sets.
Taeju Park, Jiarui Lyu, Kang G. Shin
RTSS3
2020 ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive Trojans
abstract
The transistors used to construct Integrated Circuits (ICs) continue to shrink. While this shrinkage improves performance and density, it also reduces trust: the price to build leading-edge fabrication facilities has skyrocketed, forcing even nation states to outsource the fabrication of high-performance ICs. Outsourcing fabrication presents a security threat because the black-box nature of a fabricated IC makes comprehensive inspection infeasible. Since prior work shows the feasibility of fabrication-time attackers' evasion of existing post-fabrication defenses, IC designers must be able to protect their physical designs before handing them off to an untrusted foundry. To this end, recent work suggests methods to harden IC layouts against attack. Unfortunately, no tool exists to assess the effectiveness of the proposed defenses, thus leaving defensive gaps.This paper presents an extensible IC layout security analysis tool called IC Attack Surface (ICAS) that quantifies defensive coverage. For researchers, ICAS identifies gaps for future defenses to target, and enables the quantitative comparison of existing and future defenses. For practitioners, ICAS enables the exploration of the impact of design decisions on an IC's resilience to fabrication-time attack. ICAS takes a set of metrics that encode the challenge of inserting a hardware Trojan into an IC layout, a set of attacks that the defender cares about, and a completed IC layout and reports the number of ways an attacker can add each attack to the design. While the ideal score is zero, practically, we find that lower scores correlate with increased attacker effort.To demonstrate ICAS' ability to reveal defensive gaps, we analyze over 60 layouts of three real-world hardware designs (a processor, AES and DSP accelerators), protected with existing defenses. We evaluate the effectiveness of each circuit-defense combination against three representative attacks from the literature. Results show that some defenses are ineffective and others, while effective at reducing the attack surface, leave 10's to 1000's of unique attack implementations that an attacker can exploit.
Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks
SP2
2020 SNB: Reduction of Consecutive Message Reception Failures in C-V2X Communications
abstract
Cellular vehicle-to-everything (C-V2X) features have been standardized in 3GPP Release 14. In particular, the standard introduces a fully-distributed resource-allocation algorithm for Mode 4 configuration, called sensing-based semi-persistent scheduling (SB-SPS). Although SB-SPS is effective for orthogonal radio resource allocation, it could easily suffer consecutive message losses caused by interference or half-duplex transmission since SB-SPS uses a selected resource consecutively (multiple times) for periodic transmissions. To mitigate this problem, we propose a novel Mode 4 resource-allocation algorithm, called SNB (Shake-and-Back). Instead of using a selected resource consecutively, SNB either randomly selects and uses a resource each time or uses a selected resource based on its decoding state to avoid consecutive message losses. We have conducted extensive simulations using NS-3 to evaluate SNB considering its coexistence with SB-SPS. Our evaluation results show that SNB improves the average message reception ratio (MRR) at three or more consecutive message losses significantly.
Taeju Park, Kang G. Shin
VTC Fall2
2020 Towards Fine-grained Flow Forecasting: A Graph Attention Approach for Bike Sharing Systems
abstract
As a healthy, efficient and green alternative to motorized urban travel, bike sharing has been increasingly popular, leading to wide deployment and use of bikes instead of cars. Accurate bike-flow prediction at the individual station level is essential for bike sharing service. Due to the spatial and temporal complexities of traffic networks and the lack of data-driven design for bike stations, existing methods cannot predict the fine-grained bike flows to/from each station.
Suining He, Kang G. Shin
WWW2
2020 Dynamic Flow Distribution Prediction for Urban Dockless E-Scooter Sharing Reconfiguration
abstract
Thanks to recent progresses in mobile payment, IoT, electric motors, batteries and location-based services, Dockless E-scooter Sharing (DES) has become a popular means of last-mile commute for a growing number of (smart) cities. As e-scooters are getting deployed dynamically and flexibly across city regions that expand and/or shrink, with subsequent social, commercial and environmental evaluation, accurate prediction of the distribution of e-scooters given reconfigured regions becomes essential for the city planners and service providers.
Suining He, Kang G. Shin
WWW2
2020 SPy: Car Steering Reveals Your Trip Route!
abstract
Abstract Vehicular data-collection platforms as part of Original Equipment Manufacturers’ (OEMs’) connected telematics services are on the rise in order to provide diverse connected services to the users. They also allow the collected data to be shared with third-parties upon users’ permission. Under the current suggested permission model, we find these platforms leaking users’ location information without explicitly obtaining users’ permission. We analyze the accuracy of inferring a vehicle’s location from seemingly benign steering wheel angle (SWA) traces, and show its impact on the driver’s location privacy. By collecting and processing real-life SWA traces, we can infer the users’ exact traveled routes with up to 71% accuracy, which is much higher than the state-of-the-art.
Mert D. Pesé, Xiaoying Pu, Kang G. Shin
Proc. Priv. Enhancing Technol.3
2020 Power saving with CoMP transmission for densely deployed small cell networks
Linjing Zhao, Kang G. Shin
J. Supercomput.4
2020 Coverage Performance in MIMO-ZFBF Dense HetNets with Multiplexing and LOS/NLOS Path-Loss Attenuation
abstract
The performance of multiple-input multiple-output (MIMO) multiplexing heterogenous cellular networks are often analyzed using a single-exponent path-loss model. Thus, the effect of the expected line-of-sight (LOS) propagation in densified settings is unaccounted for, leading to inaccurate performance evaluation and/or inefficient system design. This is due to the complexity of LOS/non-LOS models in the context of MIMO communications. We address this issue by developing an analytical framework based on stochastic geometry to evaluate the coverage performance. We focus on the zero-forcing beamforming where the maximum signal-to-interference ratio is used for cell association. We analytically derive the coverage. We then investigate the cross-stream interference correlation, and develop two approximations of the coverage: Alzer Approximation (A-A) and Gamma Approximation (G-A). The former is often used in the single antenna and single-stream MIMO. We extend A-A to a MIMO multiplexing system and evaluate its utility. We show that the inverse interference is well-fitted by a Gamma random variable, where its parameters are directly related to the system parameters. The accuracy and robustness of G-A is higher than that of A-A. We observe that depending on the multiplexing gain, it is possible to attain the best coverage probability by proper densification.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
IEEE Trans. Mob. Comput.3
2020 Power Guarantee for Electric Systems Using Real-Time Scheduling
abstract
Modern electric systems, such as electric vehicles, mobile robots, nano satellites, and drones, require to support various power-demand operations for user applications and system maintenance. This, in turn, calls for advanced power management that jointly considers power demand by the operations and power supply from various sources, such as batteries, solar panels, and supercapacitors. In this article, we develop a power scheduling framework for a reliable energy storage system with multiple power-supply sources and multiple power-demand operations. Specifically, we develop offline power-supply guarantee analysis and online power management. The former provides an offline power-supply guarantee such that every power-demand operation completes its execution in time while the sum of power required by individual operations does not exceed the total power supplied by the entire energy storage system at any time; to this end, we develop a plain power-supply analysis as well as its improved version using real-time scheduling techniques. On the other hand, the latter efficiently utilizes the surplus power available at runtime for improving system performance; we propose two approaches, depending on whether future scheduling information of power-demanding tasks is available or not. For evaluation, we perform simulations to evaluate both the plain and improved analyses for offline power guarantee under various synthetic power-demand operations. In addition, we have built a simulation model and demonstrated that the proposed framework with the offline analysis and online management not only guarantees the required power-supply, but also enhances system performance by up to 56.49 percent.
Youngmoon Lee, Liang He 0002, Kang G. Shin, Jinkyu Lee 0001
IEEE Trans. Parallel Distributed Syst.4
2019 LibreCAN: Automated CAN Message Translator
abstract
Modern Connected and Autonomous Vehicles (CAVs) are equipped with an increasing number of Electronic Control Units (ECUs), many of which produce large amounts of data. Data is exchanged between ECUs via an in-vehicle network, with the Controller Area Network (CAN) bus being the de facto standard in contemporary vehicles. Furthermore, CAVs have not only physical interfaces but also increased data connectivity to the Internet via their Telematic Control Units (TCUs), enabling remote access via mobile devices. It is also possible to tap into, and read/write data from/to the CAN bus, as data transmitted on the CAN bus is not encrypted. This naturally generates concerns about automotive cybersecurity. One commonality among most vehicular security attacks reported to date is that they ultimately require write access to the CAN bus. In order to cause targeted and intentional changes in vehicle behavior, malicious CAN injection attacks require knowledge of the CAN message format. However, since this format is proprietary to OEMs and can differ even among different models of a single make of vehicle, one must manually reverse-engineer the CAN message format of each vehicle they target --- a time-consuming and tedious process that does not scale. To mitigate this difficulty, we develop LibreCAN, which can translate most CAN messages with minimal effort. Our extensive evaluation on multiple vehicles demonstrates LibreCAN's efficiency in terms of accuracy, coverage, required manual effort and scalability to any vehicle.
Mert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry, Dongyao Chen, Kang G. Shin
CCS6
2019 Exploiting Sound Masking for Audio Privacy in Smartphones
abstract
Privacy leakage via malware's unauthorized audio recording has become an emerging threat to mobile users. To counter this threat, we propose SafeChat which prevents unauthorized recording without requiring new audio privacy settings in operating systems. SafeChat utilizes sound masking to differentiate audio information between authorized and unauthorized recording apps. Specifically, SafeChat enables authorized recording apps to recover more private/secret information than the unauthorized apps even though both of them record identical audio signals from the same microphone. We have implemented SafeChat as an Android chat app. Our experiments on several commodity phones have shown that SafeChat can make an up-to-26dB difference in signal strength between authorized and unauthorized recording apps. This difference reduces the accuracy of state-of-the-art speech recognition engines, like Google Speech API, to less than 0.1% in understanding the unauthorized recording while comprehending the authorized recording with high accuracy. Moreover, none of the 317 testing participants we recruited online could comprehend the masked speech. Our usability study shows that only 35% of the participants were aware of this threat of privacy leakage and 60% of them wanted to use SafeChat to protect their private/secret information from unauthorized recording.
Yu-Chih Tung, Kang G. Shin
AsiaCCS2
2019 Design Optimization of Frame Preemption in Real-Time Switched Ethernet
abstract
Switched Ethernet has been, and will also be increasingly common in current and future real-time and embedded systems. The IEEE 802.1 working group has recently developed standards and technologies, commonly referred to as Time-Sensitive Networking (TSN), to enhance switched Ethernet with timeliness and dependability. We address, for the first time, the synthesis problem for the TSN frame preemption standards IEEE 802.3br-2016 and 802.1Qbu-2016 by introducing two new configuration parameters: flow to queue and queue to Express/Preemptable MAC interface assignments. We present an optimization framework to determine these configuration parameters with reliability as the optimization goal. Our proposed framework is shown to outperform commonly used priority-assignment as well as intuitive approaches.
Taeju Park, Soheil Samii, Kang G. Shin
DATE3
2019 How Do Non-Ideal UAV Antennas Affect Air-to-Ground Communications?
abstract
Analysis of the performance of Unmanned Aerial Vehicle (UAV)-enabled communications systems often relies upon idealized antenna characteristic, where the side-lobe gain of UAVs' antenna is ignored. In practice, however, side-lobe cause inevitable interference to the ground users. We investigate the impact of UAVs' antenna side-lobe on the performance of UAV-enabled communication. Our analysis shows that even for a very small antenna's side-lobe gain, the ground receiver can experience substantial interference. We further show that a rather large exclusion zone is required to ensure a sufficient level of protection for the ground receiver. Nevertheless, in a multiple-antenna setting for the ground users, even when such a large exclusion zone was in place, UAVs' antenna side-lobe creates a high level of correlation among the interference signals received across receive antennas. Such a correlation limits the system ability to exploit channel diversity in a multiple-antenna setting for improving capacity. We then quantify the impact of UAVs' antenna side-lobes on the overall system performance by deriving the corresponding loss of the achieved capacity in various communications environments. We provide a new quantitative insight on the cost of adopting non-ideal UAV antenna on the overall capacity. Our analysis also shows that the capacity loss can be confined by careful selection of system parameters.
Mohammad G. Khoshkholgh, Keivan Navaie, Halim Yanikomeroglu, Victor C. M. Leung, Kang G. Shin
ICC5
2019 Crowd-Flow Graph Construction and Identification with Spatio-Temporal Signal Feature Fusion
abstract
To realize an efficient and flexible urban crowd-flow identification, we propose a new scheme called CFid by fusing fine-grained spatio-temporal smartphone signal features. Considering the abundance of ambient WiFi and geomagnetism, we design and validate several of their fine-grained features and similarity metrics to determine if two individuals belong to the same crowd-flow. We formalize a graph stream clustering problem, where co-flow user pairs are opportunistically identified and fed as a dynamic sequence of edges connecting each other. Given such a flexible form, a fast and accurate algorithm processes the edges and identifies the crowd-flows for further upper-level applications, including urban-flow monitoring and shopping-advertisement/recommendation. Using extensive data-driven analytics and 8-month experimental studies upon 50 users (over 2,500 walking traces at 7 different urban sites), we have validated the accuracy (usually >95%), efficiency (only <;5% extra energy-footprint on average than normal usage on mobiles) and flexibility of CFid in identifying large-scale crowd-flows.
Suining He, Kang G. Shin
INFOCOM2
2019 Interference Recycling: Exploiting Interfering Signals to Enhance Data Transmission
abstract
With the rapid development of wireless communication technologies, the demand for higher data rate and more concurrent transmissions has been continually increasing. Due to the widespread deployment of various wireless technologies, interference has become a key roadblock to the improvement of network performance. Interference has long been known to be harmful, leading to development of numerous interference management (IM) mechanisms based on resource segmentation or signal processing to mitigate or suppress interference. Since a desired signal can be distorted by interference, and thus be incorrectly decoded at the destination, we argue that interference can also be transformed intentionally to extract the desired data from interfering signal(s). Based on this observation, we propose Interference ReCycling (IRC). Under IRC, a recycling signal is generated with the interference a victim receiver (Rx) is subjected to, and then sent by the Rx's associated transmitter (Tx). Under the influence of the recycling signal, the desired data of the victim Tx-Rx pair can be recovered from the interference at the victim Rx. That is, by exploiting the interactions among multiple signals, i.e., recycling signal and interference, useful data information can be extracted from interference, or the unintended data carried in interference can be artificially converted to the desired one. Our theoretical analysis and numerical evaluation have shown that the proposed IRC can fully exploit interference, and hence can significantly improve the spectral efficiency (SE) of the victim Rx compared to the other existing IM methods.
Zhao Li 0005, Jie Chen 0056, Kang G. Shin, Jia Liu 0009
INFOCOM3
2019 Incrementally-deployable Indoor Navigation with Automatic Trace Generation
abstract
Despite years of research attention, localization-based indoor navigation has not found wide-spread practical use, largely due to the high burden on deployment and bootstrapping. Lightweight peer-to-peer navigation systems that use a leader-follower model have recently been proposed to alleviate these burdens. However, typical peer-to-peer navigation suffers from poor scalability and flexibility as navigation is only possible over pre-collected leader paths. In this paper, we present FollowUs, an easily-deployable (bootstrap-free) and scalable indoor navigation system. In addition to robust navigation through real-time trace-following, FollowUs integrates cloud services to process and combine traces at large scale. Optionally, it can also leverage floor plans to further enhance navigation efficiency. We design and implement FollowUs, including mobile app and cloud services. Experimental results from a company-internal beta release show that 91% of FollowUs' spatial errors on reaching destinations to be 3m or less, and 95% of navigation instructions are shown to users within a 4-step error margin during navigation.
Yuanchao Shu, Zhuqi Li, Börje Karlsson 0001, Yiyong Lin 0001, Thomas Moscibroda, Kang G. Shin
INFOCOM6
2019 Keep Others from Peeking at Your Mobile Device Screen!
abstract
People use their mobile devices anywhere and anytime to run various apps, and the information shown on their device screens can be seen by nearby (unauthorized) parties, called shoulder surfers. To mitigate this privacy threat, we have developed HideScreen by utilizing the human vision and optical system properties to hide the users' on-screen information from the shoulder surfers.
Chun-Yu (Daniel) Chen, Bo-Yao Lin, Junding Wang, Kang G. Shin
MobiCom4
2019 Keep Others from Peeking at Your Mobile Device Screen!
abstract
The information displayed on mobile device screens can be seen by nearby (unauthorized) parties, called shoulder surfers. To protect sensitive on-screen information, we have developed HideScreen by utilizing the human vision and optical system properties to hide the users' on-screen information from the shoulder surfers.
Chun-Yu (Daniel) Chen, Bo-Yao Lin, Junding Wang, Kang G. Shin
MobiCom4
2019 Detecting Misplaced RFID Tags on Static Shelved Items
abstract
A smart shelving system can visualize stock data in real time by leveraging item-level RFID tagging so that we can minimize out-of-stock and reduce warehousing and labor costs. The key issue of smart shelving is to locate RFID tags at any time, especially after misplacing tags. The detection of misplaced tags on stationary shelved items is very challenging due to position ambiguity, phase wrapping, device diversity, and phase ambiguity. Using a combination of theoretical analysis, simulation-based prediction and experimental verification, we propose an effective way of detecting misplaced tags, called FINDS, that integrates Particle Swarm Optimization (PSO), Synthetic Minority Over-sampling TEchnique (SMOTE) and Density-based Spatial Clustering of Applications with Noise (DBSCAN) algorithms to make theoretical and measured phases consistent with each other, and observe the phase shifts caused by misplaced tags. FINDS requires neither antenna movement nor external disturbances. We have implemented a prototype of FINDS with 20 tags and evaluated its performance, demonstrating FINDS's accuracy to be higher than 0.92 in the case of 2 stationary antennas.
Jiaqing Luo, Kang G. Shin
MobiSys2
2019 Detection of Misplaced Stationary RFID Tags
abstract
A smart shelving system can visualize stock data in real time by leveraging item-level RFID tagging. The detection of misplaced tags on stationary shelved items is very challenging due to position ambiguity, phase wrapping, device diversity, and phase ambiguity. We propose an effective way of detecting misplaced tags, called FINDS, that requires neither antenna movement nor external disturbances.
Jiaqing Luo, Kang G. Shin
MobiSys2
2019 Tiresias: A GPU Cluster Manager for Distributed Deep Learning
Juncheng Gu, Mosharaf Chowdhury, Kang G. Shin, Yibo Zhu 0001, Myeongjae Jeon, Junjie Qian, Hongqiang Harry Liu, Chuanxiong Guo
NSDI3
2019 Optimal Priority Assignment for Scheduling Mixed CAN and CAN-FD Frames
abstract
Controller Area Network with Flexible Data-rate (CAN-FD) has been drawing considerable attention as the most promising substitute of Controller Area Network (CAN), thanks to its higher bandwidth, larger payload size, and physical-layer compatibility with CAN. In particular, the physical-layer compatibility allows legacy CAN-based Electronic Control Units (ECUs) to share the same communication bus with CAN-FD-based ECUs. However, CAN-based ECUs always treat a CAN-FD frame as an erroneous frame due to the difference in frame format. This, in turn, makes CAN-FD-based ECUs unable to communicate with each other via CAN-FD frames. A straightforward solution to this problem is to utilize the silent mode of the current CAN controller, in which a CAN node does not transmit any frame including error frames, but can receive CAN frames. However, a non-negligible time overhead is incurred by each mode transition, thus degrading the schedulability of mixed CAN and CAN-FD frame sets significantly. We propose a new algorithm, called Priority Assignment with Mode Transition (PAMT), that minimizes the required number of mode transitions by clustering frame instances based on their frame type. Our evaluation results show that PAMT can schedule about 17% more mixed CAN and CAN-FD frame sets than existing optimal priority assignment algorithms for CAN.
Taeju Park, Kang G. Shin
RTAS2
2019 Coverage Performance of Aerial-Terrestrial HetNets
abstract
Providing seamless coverage in current cellular network technologies is surmountable only through gross overengineering. Alternatively, as an economically effective solution, the use of unmanned aerial vehicles (UAVs), augmented with the functionalities of terrestrial base stations (BSs), is recently advocated. In this paper we investigate the effect that the incorporation of UAV-mounted BSs (U-BS) poses on the coverage probability of cellular networks. To this end, we focus on the evaluation of the coverage probability of a large-scale aerialterrestrial heterogenous cellular network (AT-HetNet), in which BSs of each technology/tier can be either ground (G-BS) or UBS. Our analysis incorporates the impact of Line-of-Sight (LOS) and non-LOS (NLOS) path-loss attenuations of both ground-toground (G2G) and Air-to-Ground (A2G) links. Adopting tools of stochastic geometry we then obtain the coverage probability as a function of main system parameters and percentage of BSs in each tier that are aerial. Using simulations we also confirm the accuracy of our analysis. We further observe that for several common communication environments, e.g., high-rise and dense urban environments, the inclusion of U-BSs can be detrimental to the coverage probability. Nevertheless, it is still possible to minimize the coverage cost by turning off a percentage of G-BSs. Interestingly, for urban and sub-urban areas one can adjust the altitude of U-BSs in order to adjust the coverage probability.
Mohammad G. Khoshkholgh, Keivan Navaie, Halim Yanikomeroglu, Victor C. M. Leung, Kang G. Shin
VTC Spring5
2019 Caching or No Caching in Dense HetNets?
abstract
Caching the content closer to the user equipments (UEs) in heterogenous cellular networks (HetNets) improves user-perceived Quality-of-Service (QoS) while lowering the operators backhaul usage/costs. Nevertheless, under the current networking strategy that promotes aggressive densification, it is unclear whether cache-enabled HetNets preserve the claimed cost-effectiveness and the potential benefits. This is due to 1) the collective cost of caching which may inevitably exceed the expensive cost of backhaul in a dense HetNet, and 2) the excessive interference which affects the signal reception irrespective of content placement. We analyze these significant, yet overlooked, issues, showing that while densification reduces backhaul load and increases spectral efficiency in cache-enabled dense networks, it simultaneously reduces cache-hit probability and increases the network cost. We then introduce a caching efficiency metric, area spectral efficiency per unit spent cost, and find it enough to cache only about 3% of the content library size in the cache of small-cell base stations. We further show that range expansion, known to be of substantial value in wireless networks, is almost impotent to curb the caching inefficiency. Surprisingly, unlike the conventional wisdom recommending traffic offloading from macro cells to small cells, in cache-enabled HetNets, it is more beneficial to exclude offloading altogether or to do the opposite.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung, Halim Yanikomeroglu
WCNC3
2019 Randomized Caching in Cooperative UAV-Enabled Fog-RAN
abstract
We consider an unmanned aerial vehicle enabled (UAV-enabled) fog-radio access network (F-RAN) in which UAVs are considered as flying remote radio heads (RRH) equipped with caching and cooperative communications capabilities. We are mainly focus on probabilistic/randomized content placement strategy, and accordingly formulate the content placement as an optimization problem. We then study the efficiency of the proposed content placement by evaluating the average system capacity and its energy-efficiency. Our results indicate that cooperative communication plays an essential role in UAV-enabled edge communications as it effectively curbs the impact of dominant Line-of-Sight (LOS) received interference. It is also seen that cooperative cache-enabled UAV F-RAN performs better in high-rise environments than dense urban and sub-urban environments. This is due to a significant reduction of the received LOS interference because of blockage by the high-rise buildings, and the performance gain of cooperative communication on the attending signal. Comparing the performances of the developed content placement strategy and conventional caching techniques shows that our proposed probabilistic/randomized caching outperforms the others in most of the practical cases.
Mohammad G. Khoshkholgh, Keivan Navaie, Halim Yanikomeroglu, Victor C. M. Leung, Kang G. Shin
WCNC5
2019 Spatio-Temporal Capsule-based Reinforcement Learning for Mobility-on-Demand Network Coordination
abstract
As an alternative means of convenient and smart transportation, mobility-on-demand (MOD), typified by online ride-sharing and connected taxicabs, has been rapidly growing and spreading worldwide. The large volume of complex traffic and the uncertainty of market supplies/demands have made it essential for many MOD service providers to proactively dispatch vehicles towards ride-seekers.
Suining He, Kang G. Shin
WWW2
2019 Exploiting interactions among signals to decode interfering transmissions with fewer receiving antennas
Zhao Li 0005, Jiamin Ding, Xiaoqin Dai, Kang G. Shin, Jia Liu 0009
Comput. Commun.4
2019 Interference Steering to Manage Interference in IoT
abstract
Internet of Things (IoT) is a new paradigm that involves the interconnection of thousands of devices and home appliances. Due to the scarcity of the spectrum suitable for wireless electromagnetic transmission, many communication systems and devices are close to each other, or even overlapping in spectrum, thus incurring complicated interference situations. Therefore, interference in IoT is worthy of thorough investigation and should be well addressed. There have been numerous interference management (IM) proposals at the interfering transmitter or the interfered transmitter/receiver separately or cooperatively. Moreover, the existing IM schemes rely mainly on the use of channel state information (CSI). However, in some communication scenarios, the option to adjust the interferer is not available, and, in the case of downlink transmission, it is always difficult or even impossible for the interfered receiver to acquire necessary information for IM. Based on the above observations, we first propose a novel IM technique, called interference steering (IS). By making use of both CSI with respect to and data carried in the interfering signal, IS generates a signal to modify the spatial feature of the original interference, so that the steered interference at the interfered receiver is orthogonal to its intended signal. We then apply IS to a wireless local area network (WLAN)-based IoT in which the same frequency band is reused by adjacent basic service sets (BSSs) with overlapping areas. With IS, multiple nearby access points (APs) could simultaneously transmit data on the same channel to their mobile stations (STAs), thus enhancing spectrum reuse. Our in-depth simulation results show that IS significantly improves network SE over existing IM schemes.
Zhao Li 0005, Yinghou Liu, Kang G. Shin, Jia Liu 0009, Zheng Yan 0002
IEEE Internet Things J.3
2019 Thermal-Aware Scheduling for Integrated CPUs-GPU Platforms
abstract
As modern embedded systems like cars need high-power integrated CPUs--GPU SoCs for various real-time applications such as lane or pedestrian detection, they face greater thermal problems than before, which may, in turn, incur higher failure rate and cooling cost. We demonstrate, via experimentation on a representative CPUs--GPU platform, the importance of accounting for two distinct thermal characteristics—the platform’s temperature imbalance and different power dissipations of different tasks —in real-time scheduling to avoid any burst of power dissipations while guaranteeing all timing constraints. To achieve this goal, we propose a new Real-Time Thermal-Aware Scheduling (RT-TAS) framework. We first capture different CPU cores’ temperatures caused by different GPU power dissipations (i.e., CPUs--GPU thermal coupling ) with core-specific thermal coupling coefficients. We then develop thermally-balanced task-to-core assignment and CPUs--GPU co-scheduling . The former addresses the platform’s temperature imbalance by efficiently distributing the thermal load across cores while preserving scheduling feasibility. Building on the thermally-balanced task assignment, the latter cooperatively schedules CPU and GPU computations to avoid simultaneous peak power dissipations on both CPUs and GPU, thus mitigating excessive temperature rises while meeting task deadlines. We have implemented and evaluated RT-TAS on an automotive embedded platform to demonstrate its effectiveness in reducing the maximum temperature by 6−12.2° C over existing approaches without violating any task deadline.
Youngmoon Lee, Kang G. Shin, Hoon Sung Chwa
ACM Trans. Embed. Comput. Syst.2
2019 EACAN: Reliable and Resource-Efficient CAN Communications
abstract
Worst-case-based timing verification for the controller area network (CAN) has been the bottleneck to efficient use of its bandwidth. Especially, this inefficiency comes from the worst-case transmission error rate (WCTER) when transmission errors are accounted for. To alleviate this inefficiency, we propose a runtime adaptation scheme, error-adaptive CAN (EACAN). EACAN observes the behavior of transmission errors at runtime, and reconfigures the message period based on the observation to meet the timing-failure requirement. We experimentally evaluate the bandwidth utilization of both EACAN- and WCTER-based verification, showing that the former improves the bandwidth utilization by 14% over the latter.
Taeju Park, Kang G. Shin
ACM Trans. Embed. Comput. Syst.2
2019 Spatio-temporal Adaptive Pricing for Balancing Mobility-on-Demand Networks
abstract
Pricing in mobility-on-demand (MOD) networks, such as Uber, Lyft, and connected taxicabs, is done adaptively by leveraging the price responsiveness of drivers (supplies) and passengers (demands) to achieve such goals as maximizing drivers’ incomes, improving riders’ experience, and sustaining platform operation. Existing pricing policies only respond to short-term demand fluctuations without accurate trip forecast and spatial demand-supply balancing, thus mismatching drivers to riders and resulting in loss of profit. We propose CAPrice, a novel adaptive pricing scheme for urban MOD networks. It uses a new spatio-temporal deep capsule network (STCapsNet) that accurately predicts ride demands and driver supplies with vectorized neuron capsules while accounting for comprehensive spatio-temporal and external factors. Given accurate perception of zone-to-zone traffic flows in a city, CAPrice formulates a joint optimization problem by considering spatial equilibrium to balance the platform, providing drivers and riders/passengers with proactive pricing “signals.” We have conducted an extensive experimental evaluation upon over 4.0× 10 8 MOD trips (Uber, Didi Chuxing, and connected taxicabs) in New York City, Beijing, and Chengdu, validating the accuracy, effectiveness, and profitability (often 20% ride prediction accuracy and 30% profit improvements over the state-of-the-arts) of CAPrice in managing urban MOD networks.
Suining He, Kang G. Shin
ACM Trans. Intell. Syst. Technol.2
2019 On the Granularity of Trie-Based Data Structures for Name Lookups and Updates
abstract
Name lookup is an essential function but a performance bottleneck in both today's and future network architectures. Trie is an excellent candidate data structure and has been widely used for looking up and updating names. However, the granularity of trie-at bit, byte (character), or component level-can dramatically affect the network performance in terms of memory usage and packet-processing speed, which has not yet been studied adequately. To fill this gap, we first show that the choice of trie's granularity for name lookups and updates (i.e., insertions and removals) is not a trivial problem due to the complex performance tradeoffs involved. We also introduce a new tool, called NameGen, which uses a Markov-based name learning model and generates pseudo-real datasets with different tunable name characteristics. We compare different trie granularities based on a collection of datasets and performance metrics, highlight the strengths and weaknesses of each granularity, and draw a conclusion on the choice of granularity. Surprisingly, our experimental evaluation finds that there are only two key rules to choose the proper trie's granularity for any kind of dataset: 1) bit-level trie is the choice when the memory requirement is a real concern and 2) character- and component-level tries are preferred for faster lookups and updates when dealing with names composed of short and long components, respectively.
Chavoosh Ghasemi, Hamed Yousefi 0001, Kang G. Shin, Beichuan Zhang 0001
IEEE/ACM Trans. Netw.3
2019 Extending Battery System Operation via Adaptive Reconfiguration
abstract
Large-scale battery packs are commonly used in applications such as electric vehicles (EVs) and smart grids. Traditionally, to provide stable voltage to the loads, voltage regulators are used to convert battery packs’ output voltage to those of the loads’ required levels, causing power loss especially when the difference between the supplied and required voltages is large or when the load is light. In this article, we address this issue via a reconfiguration framework for the battery system. By abstracting the battery system as a cell graph, we develop an adaptive reconfiguration algorithm to identify the desired system configurations based on real-time load requirements. Our design is evaluated via both prototype-based experiments, EV driving trace-based emulations, and large-scale simulations. The results demonstrate an extended system operation time of up to 5×, especially when facing severe cell imbalance.
Liang He 0002, Linghe Kong, Yu Gu 0001, Cong Liu 0005, Tian He 0001, Kang G. Shin
ACM Trans. Sens. Networks6
2019 Coordinated Multi-Point Transmissions Based on Interference Alignment and Neutralization
abstract
Both interference alignment (IA) and interference neutralization (IN) are exploited for coordinated multi-point (CoMP) communications. With the cooperation of the base station (BS), a transmit precoder and a receive filter are jointly designed, and concurrent transmissions of multiple data streams are then enabled. In the design of a precoder, the IN is applied to the interferences carrying the same data so as to align the interfering signals in the opposite direction in a subspace. On the other hand, for interferences carrying different information, IA is employed to align them in the same direction in a subspace, thus reducing the interference signal observed at the receiver side. Based on different precoding schemes at the transmitter's side, receivers adopt zero forcing (ZF) so as to recover the desired data. The proposed IA- and IN-based CoMP (IAN-CoMP) mechanism can achieve effective interference cancellation and suppression by exploiting limited and flexible collaboration at the BS side. It can also make a flexible tradeoff between the cooperation overhead and the system's achievable degrees of freedom (DoFs). We extend the mechanism to general cases where the antenna configurations at both the transmitter and receiver sides, the number of transmitters participating in CoMP, and that of simultaneously served users are variable. Moreover, we discuss both single-location and multi-location-based realizations of the IAN-CoMP. Finally, by defining the average transmit and receive cooperation order, we analyze the upper bound for IAN-CoMP. Our in-depth simulation shows that the IAN-CoMP can significantly improve the spectral efficiency (SE) for cell-edge users.
Zhao Li 0005, Jie Chen 0056, Lu Zhen, Sha Cui, Kang G. Shin, Jia Liu 0009
IEEE Trans. Wirel. Commun.5
2019 Design and Adaptation of Multi-Interference Steering
abstract
With the rapid development in wireless communication technologies, interference has become a main impediment to network performance, making interference management (IM) a critical issue. Interference steering (IS) is emerging as a novel way of IM, which can steer the spatial feature of interference to a target subspace by exploiting the interactions of multiple signals over the air to avoid the disturbance to the interfered receiver. In reality, there always exists multiple interferences from single or multiple sources. We propose three ways to realize IS. The first two of them are categorized as individual interference steering (IIS), in which multiple interfering signals are separately adjusted to either an identical direction (a single-target IS, STIS) or different directions (multi-target IS, MTIS), incurring single or multiple degrees of freedom (DoFs) overheads, respectively. Furthermore, by recognizing that the goal of IM is to limit the effect of interference-i.e., the effective portion of interference imposed on the intended transmission- we propose aggregated interference steering (AIS) that exploits the constructive or destructive effects of multiple interfering signals. By considering the overall effect of multiple interferences, the DoF cost of AIS is reduced to one regardless of the number of interference to be managed. Finally, the proposed three IS realizations are adapted to minimize the power cost of steering interference. Our theoretical analysis and in-depth simulation results have shown that the proposed IS schemes can effectively manage multiple interference via better utilizing the DoF and transmit power. The AIS is shown to be advantageous in both power cost and DoF consumption.
Zhao Li 0005, Yinghou Liu, Kang G. Shin, Jun Li 0095, Fengjuan Guo, Jia Liu 0009
IEEE Trans. Wirel. Commun.3
2018 Wireless CSI-based head tracking in the driver seat
abstract
In recent years, augmented reality (AR) has drawn significant attention in the automotive industry and shown great potential for a variety of driver-assistance applications. Tracking the driver's head is vital to seamlessly merge the AR content in the driver's view but still remains an open problem. Specifically, most existing in-vehicle AR solutions rely on cameras for head tracking, which suffer from low sampling rate, weak performance at night, and even high computation costs. Wearing a dedicated headset, on the other hand, is intrusive and inconvenient for daily driving.
Xiufeng Xie, Kang G. Shin, Hamed Yousefi 0001, Suining He
CoNEXT2
2018 An Optimization Method for Multi-Operator and Mixed-Traffic LTE Deployments in the Unlicensed Bands
abstract
The proliferation of multimedia applications and services increased the demand on data and the requirement by operators to improve the experience of their users. This has motivated the extension of cellular technologies, such as Long Term Evolution (LTE) toward using the unlicensed bands. However, the nature of these bands poses a challenge since there is uncontrolled interference from other coexisting transmissions. We discuss in this paper the issue of efficient coexistence of LTE operators in the unlicensed bands through an optimization framework that is based on performance metrics obtained using stochastic geometry. The proposed optimization framework allows for obtaining optimized network topologies that maximize the benefit of LTE operators looking to deploy their networks in the unlicensed bands.
Abdel-Karim Ajami, Hassan Artail, Kang G. Shin
GLOBECOM3
2018 A Fast and Memory-Efficient Trie Structure for Name-Based Packet Forwarding
abstract
Name lookup is an essential function, but a performance bottleneck in both today's and future network architectures. Variable-length and unbounded names rather than fixed-length addresses, as well as much larger and more dynamic forwarding tables call for a careful re-engineering of lookup structures for fast, memory-efficient, and scalable packet forwarding. We propose a novel data structure, called NameTrie, to store and index forwarding table entries efficiently and to support fast name lookups and updates. Its novelty lies in the optimized design and implementation of a character-trie structure. The nodes of NameTrie are stored compactly, improving cache efficiency and speeding up packet processing. Its edges are implemented using a hash table, facilitating fast name lookups and updates. A new scheme is used to encode control information without consuming additional memory. Running on conventional commodity hardware and using large-scale real-world name datasets, our implementation of NameTrie in software achieves 2.82~3.56, 3.48~3.72, and 2.73~3.25 million name insertions, lookups, and removals per second, respectively, for various datasets while requiring a small memory footprint. We have conducted a comprehensive performance evaluation against the state-of-the-art of named data networking (NDN) as a typical use-case. It is shown to require at least 35% less memory and runs at least 3x faster for name table lookups and updates than two well-known trie-based schemes in NDN.
Chavoosh Ghasemi, Hamed Yousefi 0001, Kang G. Shin, Beichuan Zhang 0001
ICNP3
2018 Steering Crowdsourced Signal Map Construction via Bayesian Compressive Sensing
abstract
Mobile crowdsensing with increasing pervasiveness of smartphones has enabled a myriad of applications, including urban-scale signal map monitoring and revision. Despite the importance of its quality, due to the large size of a site to cover, dense crowdsourcing is neither cost-effective nor convenient for crowdsourcing participants, making it critical and challenging to balance between signal quality and crowdsourcing cost. To address this problem, we propose a novel incentive mechanism, BCCS, based on Bayesian Compressive Crowdsensing (BCS). BCCS iteratively determines the spatial grids for crowd-sourcing quality and predicts the remaining unexplored grids for deployment efficiency. BCS returns not only the predicted signal values, but also the confidence intervals for convergence and incentive control. A probabilistic user participation and measurement model is applied for incentive design, which is flexible for crowdsensing deployment. Our extensive evaluation based on two different data sets shows that BCCS achieves much higher prediction accuracy (often by more than 20%) with lower payments to the participants and fewer iterations (often by 30%) than existing solutions.
Suining He, Kang G. Shin
INFOCOM2
2018 (Re)Configuring Bike Station Network via Crowdsourced Information Fusion and Joint Optimization
abstract
Thanks to their great success as a green urban transportation means of first/last-mile connectivity, bike sharing service (BSS) networks has been proliferating all over the globe. Their station (re)placement and dock resizing has thus become an increasingly important problem for bike sharing service providers.
Suining He, Kang G. Shin
MobiHoc2
2018 Cross-Platform Support for Rapid Development of Mobile Acoustic Sensing Applications
abstract
LibAS is a cross-platform framework to facilitate the rapid development of mobile acoustic sensing apps. It helps developers quickly realize their ideas by using a high-level Matlab script, and test them on various OS platforms, such as Android, iOS, Tizen, and Linux/Win. LibAS simplifies the development of acoustic sensing apps by hiding the platform-dependent details. For example, developers need not learn Objective-C/SWIFT or the audio buffer management in the CoreAudio framework when they want to implement acoustic sensing algorithms on an iPhone. Instead, developers only need to decide on the sensing signals and the callback function to handle each repetition of sensing signals. We have implemented apps covering three major acoustic sensing categories to demonstrate the benefits and simplicity of developing apps with LibAS. Our evaluation results show the adaptability of LibAS in supporting various acoustic sensing apps and tuning/improving their performance efficiently. Developers have reported that LibAS saves them a significant amount of time/effort and can reduce up to 90% lines of code in their acoustic sensing apps.
Yu-Chih Tung, Duc Bui, Kang G. Shin
MobiSys3
2018 Physical-State-Aware Dynamic Slack Management for Mixed-Criticality Systems
abstract
Safety-critical cyber-physical systems like autonomous cars require not only different levels of assurance, but also close interactions with dynamically-changing physical environments. While the former has been studied extensively by exploiting the notion of mixed-criticality (MC) systems, the latter has not, especially in conjunction with MC systems. To fill this important gap, we conduct an in-depth case study, demonstrating the importance of capturing current physical states, and introduce the problem of achieving efficient utilization of computing resources under varying physical states in MC systems. To solve this problem, we first develop a physical-state-aware MC task model, which is a generalization of the existing basic MC task model. We then propose new slack concepts tailored to the new task model, which enable efficient utilization of computing resources for MC systems. Finally, we develop a physical-state-aware dynamic slack management framework and demonstrate how to utilize the new MC task model and slack concepts towards efficient system utilization. We show, via a case study and in-depth evaluation, that the proposed framework makes 20x less low-criticality jobs dropped over a popular MC scheduling algorithm without compromising the MC-schedulability requirements.
Hoon Sung Chwa, Kang G. Shin, Hyeongboo Baek, Jinkyu Lee 0001
RTAS2
2018 Closing the Gap Between Stability and Schedulability: A New Task Model for Cyber-Physical Systems
abstract
A cyber-physical system (CPS) usually contains multiple control loops, each responsible for controlling different physical subprocesses, that run simultaneously upon a shared platform. The foremost design goal for CPSes is to guarantee system stability and control quality with limited cyber resources. We show, via an in-depth case study, that two inter-related design parameters - sampling period and consecutive control update misses - play a key role in determining stability and control performance. However, most CPS designs, such as control-schedule co-design and fault-tolerant scheduling, focus on either sampling period or control update misses alone, but not both. To remedy this problem, we propose a new CPS task model that captures both system stability and control performance in terms of sampling period and maximum allowable number of consecutive control update misses. To demonstrate the utility and power of this model, we develop two new scheduling mechanisms, offline parameter assignment and online state-aware scheduling. The former determines the sampling period and the maximum allowable number of consecutive job deadline misses for each task while preserving system stability. The latter then generates a schedule by exploiting the state of each physical subprocess to manage job deadline misses so as to improve the overall system performance without compromising system stability. Our in-depth evaluation results demonstrate that the proposed task model and the corresponding scheduling algorithm not only enable the efficient use of computing resource, but also significantly improve control performance without compromising system stability.
Hoon Sung Chwa, Kang G. Shin, Jinkyu Lee 0001
RTAS2
2018 Maximizing Quality of Aggregation in WSNs under Deadline and Interference Constraints
abstract
Maximizing quality of aggregation (QoA) is an essential requirement for real-time wireless sensor networks (WSNs) where the participation of all sensor nodes in data aggregation is hampered by the underlying sink deadline and interference constraints. This problem, however, remains unsolved under the physical interference model that captures the reality more accurately than the widely used graph-based models. In this paper, we formulate an optimization problem of maximizing QoA under deadline and interference constraints in commonly seen tree- based WSNs. We prove the problem to be NP- complete, and then propose a suboptimal scheduling algorithm which relies on a Markov approximation framework and modifies the matching graphs in order to handle the globally-imposed interference constraints. The problem and its solution are then coupled with successive interference cancellation (SIC) to improve QoA by increasing the number of concurrent transmissions. Our evaluation has shown the proposed solution to be effective under the physical interference model, both with and without SIC.
Hamed Yousefi 0001, Masoud Mehrabi Koushki, Bahram Alinia, Kang G. Shin
SECON4
2018 Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep Learning
Hamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub, Kang G. Shin, Karl Aberer
USENIX Security Symposium5
2018 ClusterFetch: A Lightweight Prefetcher for Intensive Disk Reads
abstract
By overlapping disk accesses with computation-intensive operations, prefetching can reduce delays in launching an application and in loading significant amounts of data while the application is running. The key to effective prefetching is making the tradeoff between the mining accuracy of selecting relevant blocks, and the time to decide those blocks. To address this problem, we propose a new prefetcher called ClusterFetch. In its learning mode, ClusterFetch detects periods of intensive disk accesses by monitoring the speed at which read requests are queued; it re-organizes these reads and locates the file opened by the application just before each such period. During subsequent runs of the same application, ClusterFetch prefetches the data associated with the opening of a “trigger” file. Our experimental results show that ClusterFetch implemented in Linux can reduce the application launch time by up to 41.3 percent and the loading time by up to 38.2 percent, while taking up less than 200 KB of main memory.
Junhee Ryu, Dongeun Lee 0001, Kang G. Shin, Kyungtae Kang
IEEE Trans. Computers3
2018 Thermal-Aware Resource Management for Embedded Real-Time Systems
abstract
With an increasing demand for complex and powerful system-on-chips, modern real-time automotive systems face significant challenges in managing on-chip-temperature. We demonstrate, via real experiments, the importance of accounting for dynamic ambient temperature and task-level power dissipation in resource management so as to meet both thermal and timing constraints. To address this problem, we propose RT-TRM, a real-time thermal-aware resource management framework. We first introduce a task-level dynamic power model that can capture different power dissipations with a simple task-level parameter called the activity factor. We then develop two new mechanisms, adaptive parameter assignment and online idle-time scheduling. The former adjusts voltage/frequency levels and task periods according to the varying ambient temperature while preserving feasibility. The latter generates a schedule by allocating idle times efficiently without missing any task/job deadline. By tightly integrating the solutions of these two mechanisms, we can guarantee both thermal and timing constraints in the presence of dynamic ambient temperature variations. We have implemented RT-TRM on an automotive microcontroller to demonstrate its effectiveness, achieving better resource utilization by 18.2% over other runtime approaches while meeting both thermal and timing constraints.
Youngmoon Lee, Hoon Sung Chwa, Kang G. Shin, Shige Wang
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2018 Post-CCA and Reinforcement Learning Based Bandwidth Adaptation in 802.11ac Networks
abstract
The new 802.11ac standard aims at achieving Gbps data throughput for individual users by exploiting enhanced physical-layer features, such as higher modulation levels, Multiple Input Multiple Output (MIMO), and wider bandwidths. However, the heterogeneity of bandwidth in a network can cause asymmetric interferences in which certain transmissions cannot be sensed by some other nodes. As a result, the conventional Carrier Sense Multiple Access with Collision Avoidance (CSMA/CA) may not work well in 802.11ac networks. We call this the Hidden Channel (HC) problem, which is shown to be real via experiments with USRP and WARP boards. To solve this problem, we propose bandwidth adaptation based on post-CCA, which is a clear channel assessment (CCA) procedure performed aftercompleting a transmission. Post-CCA in wireless networks helps mimic the CSMA with Collision Detection (CSMA/CD) mechanism in the wired Ethernet, thus enhancing channel assessment capability. Using post-CCA, we propose Post-CCA based Bandwidth Adaptation (PoBA) that alters bandwidth and channel configuration dynamically by applying a reinforcement learning mechanism. Post-CCA and PoBA do not require any hardware modification and are also compliant with the 802.11 standards. PoBA is shown via simulation to increase network-wide throughput, channel utilization and fairness, and also lower packet error probability.
Seowoo Jang, Kang G. Shin, Saewoong Bahk
IEEE Trans. Mob. Comput.2
2018 Cell Association in Dense Heterogeneous Cellular Networks
abstract
Coverage evaluation of heterogeneous multi-tier cellular networks (HetNets) is often based on simplifying assumptions on cell association (CA): the resource required by, and practical limitations of pilot measurements are overlooked. Also, the base station (BS) providing the strongest signal-to-interference ratio among all BSs is always the serving BS (an ideal CA (iCA)). Consequently, the resultant analysis falls short of characterizing HetNets' coverage in practical settings. We therefore propose an analytical framework for modeling a practical CA (pCA) by considering pilot measurement, pilot sensitivity at the users, and the number of pilot measurements, KP. Using tools from stochastic geometry, we obtain the coverage with pCA in both Rayleigh and Nakagami environments. We propose an algorithm to obtain the optimal KP and its partitioning among the BSs in different tiers that maximizes the coverage. Our analysis provides key insights in designing dense HetNets. For dense networks, scale invariance achievable under iCA is shown unsustained with pCA. Also, dense HetNets are pilot-neutral, and hence their performance is not affected by pilot sensitivity. Our extensive simulations confirm the accuracy of our analysis and the proposed algorithm, and demonstrate the effect of pCA in comparison with iCA.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
IEEE Trans. Mob. Comput.3
2018 Automatic Identification of Driver's Smartphone Exploiting Common Vehicle-Riding Actions
abstract
Texting or browsing the web on a smartphone while driving, called distracted driving, significantly increases the risk of car accidents. There have been a number of proposals for the prevention of distracted driving, but none of them has addressed its important challenges completely and effectively. To remedy this deficiency, we present an event-driven solution, called Automatic Identification of Driver's Smartphone (AIDS), which identifies a driver's smartphone by analyzing and fusing the phone's sensory information related to common vehicle-riding activities, such as walking toward the vehicle, standing near the vehicle while opening a vehicle door, entering the vehicle, closing the door, and starting the engine. AIDS extracts features useful for identification of the driver's phone from diverse sensors available in commodity smartphones. It identifies the driver's phone before the vehicle leaves its parked spot, and differentiates seated (front or rear) rows in a vehicle by analyzing the subtle electromagnetic field spikes caused by the starting of the engine. To evaluate the feasibility and adaptability of AIDS, we have conducted extensive experiments: a prototype of AIDS was distributed to 12 participants, both males and females in their 20 and 30s, who have driven seven different vehicles for three days in real-world environments. Our evaluation results show that AIDS identified the driver's phone with an 83.3-93.3 percent true positive rate while achieving a 90.1-91.2 percent true negative rate at a marginal increase of the phone's energy consumption.
Homin Park, DaeHan Ahn, Taejoon Park, Kang G. Shin
IEEE Trans. Mob. Comput.4
2018 Use of Phone Sensors to Enhance Distracted Pedestrians' Safety
abstract
Studies have shown that using smartphones while walking-called distracted walking-significantly increases the risk of pedestrians colliding with dangerous objects. In this paper, we explore how to mitigate this problem by exploiting the phone's built-in sensors only and developing an application called BumpAlert. BumpAlert provides a generic solution without requiring any prior knowledge of the user's surroundings by estimating distances to nearby objects using the phone's speakers and microphones. This process is enhanced further by using the images acquired from the phone's rear camera, when necessary. We have evaluated BumpAlert under a variety of settings ranging from aisle to outdoor environments with walls, pillars, signboards, dustbins, and people, etc., that are common in our daily surroundings. Our evaluation has shown an average accuracy of BumpAlert to be higher than 95 percent with a less than 2 percent false-positive rate to detect frontal objects 2-4m away, which suffices for the user to react and avoid collision. Even though BumpAlert is unable to detect all dangerous situations, most participants of our user study feel safer when they walk with BumpAlert enabled. Integrating our current design of BumpAlert with other safety systems can provide a practical solution for protecting distracted pedestrians.
Yu-Chih Tung, Kang G. Shin
IEEE Trans. Mob. Comput.2
2018 Distributed Packet Forwarding and Caching Based on Stochastic Network Utility Maximization
Yitu Wang, Wei Wang 0021, Ying Cui 0001, Kang G. Shin, Zhaoyang Zhang 0001
IEEE/ACM Trans. Netw.4
2017 Viden: Attacker Identification on In-Vehicle Networks
abstract
Various defense schemes --- which determine the presence of an attack on the in-vehicle network --- have recently been proposed. However, they fail to identify which Electronic Control Unit (ECU) actually mounted the attack. Clearly, pinpointing the attacker ECU is essential for fast/efficient forensic, isolation, security patch, etc. To meet this need, we propose a novel scheme, called Viden (Voltage-based attacker identification), which can identify the attacker ECU by measuring and utilizing voltages on the in-vehicle network. The first phase of Viden, called ACK learning, determines whether or not the measured voltage signals really originate from the genuine message transmitter. Viden then exploits the voltage measurements to construct and update the transmitter ECUs' voltage profiles as their fingerprints. It finally uses the voltage profiles to identify the attacker ECU. Since Viden adapts its profiles to changes inside/outside of the vehicle, it can pinpoint the attacker ECU under various conditions. Moreover, its efficiency and design-compliance with modern in-vehicle network implementations make Viden practical and easily deployable. Our extensive experimental evaluations on both a CAN bus prototype and two real vehicles have shown that Viden can accurately fingerprint ECUs based solely on voltage measurements and thus identify the attacker ECU with a low false identification rate of 0.2%.
Kyong-Tak Cho, Kang G. Shin
CCS2
2017 Research Issues and Approaches for Connected and Automated Vehicles
abstract
Driverless and/or environment-friendly cars have recently received a great deal of attention from media and almost all industry and government sectors due mainly to their great potential impacts on safety, economy, and environments. In particular, enabling vehicles to communicate with one another via wireless devices holds the potential to automate vehicles while dramatically improving safety, reducing congestion, and conserving energy. To move toward realization of this potential, we have been conducting research into various issues, including: Automation of vehicle sensing and control; Vehicle safety and passenger comfort; Securing information communication and computation; Developing environment-friendly solutions.
Kang G. Shin
CODASPY1
2017 Locating and Tracking BLE Beacons with Smartphones
abstract
We present a smartphone-based application, called LocBLE, for enabling users to estimate the location of nearby Bluetooth low energy (BLE) beacons. In contrast to existing BLE beacon-based proximity applications that can only show coarse-grained (immediate, near, and far) distance estimation, LocBLE's fine-grained estimation can enhance human-environment interactions.
Dongyao Chen, Kang G. Shin, Yurong Jiang, Kyu-Han Kim
CoNEXT2
2017 Enhancing wireless performance using reflectors
abstract
Signal decay is the fundamental problem of wireless communications, especially in an indoor environment where line-of-sight (LOS) paths for signal propagation are often blocked and various indoor objects exacerbate signal fading. There are three reasons for signal decay: long transmission distance, signal penetration, and reflection. In this paper, we propose OptRe which optimally places metallic reflectors - providing a highly reflective surface that can reflect impinging signals almost 100% - in indoor environments to reduce the reflection loss and enhance wireless transmissions. It enhances both WiFi signal and low-power IoT devices without changing their configurations or network protocols. To enable OptRe, we first develop an empirical signal propagation model that can accurately estimate the signal strength and adapt itself to the reflectors' location. Using micro-benchmarks, our empirical signal propagation model is shown to be more accurate than the other existing path loss models. We also optimally place reflectors to maximize the worst-case signal coverage within the target indoor areas. Our extensive experimental evaluation results have shown OptRe to enhance signal strength for different types of wireless signals by almost 2x.
Sihui Han, Kang G. Shin
INFOCOM2
2017 When and how much to neutralize interference?
abstract
Interference management (IM) is essential to wireless communication networks, but interference suppression, a key component of IM, is known to degrade users' achievable spectral efficiency (SE). It is thus important to select an appropriate IM method with optimal operating parameters according to diverse network deployments, transmit power differences of various communication equipments, and dynamically changing channel conditions so as to balance the benefits brought by and the cost of IM. Interference neutralization (IN) has recently been receiving considerable attention, with which a duplicate of interference of the same strength and opposite phase w.r.t. the original interfering signal is generated to neutralize the disturbance at the intended receiver. However, to the best of our knowledge, all existing IN schemes assume that interference is completely neutralized without accounting for their power consumption. To remedy this deficiency, we propose a novel scheme, called dynamic interference neutralization (DIN). By intelligently determining the appropriate portion of interference to be neutralized, we balance the transmitter's power used for IN and the desired signal's transmission. We then present a new way to adaptively select one of DIN and other IM methods by taking into account the cost of multiple IM methods and their benefits. Our analysis has shown that DIN can include complete IN and non-interference management (non-IM) as special cases. The proposed strategy is shown via simulation to be able to make better use of the transmit power than existing IM methods, hence enhancing users' SE.
Zhao Li 0006, Kang G. Shin, Lu Zhen
INFOCOM2
2017 Efficient thermoelectric cooling for mobile devices
abstract
Mobile apps suffer large performance degradation when the underlying processors are throttled to cool down the devices. Fans or heat sinks are not a viable option for mobile devices, thus calling for a new portable cooling solution. Thermoelectric coolers are scalable and controllable cooling devices that can be embedded into mobile devices on the chip surface. This paper presents a thermoelectric cooling solution that enables efficient processor thermal management in mobile devices. Our goal is to minimize performance loss from thermal throttling by efficiently using thermoelectric cooling. Since mobile devices experience large variations in workloads and ambient temperature, our solution adaptively controls cooling power at runtime. Our evaluation on a smartphone using mobile benchmarks demonstrated that the performance loss from the maximum speed is only 1.8% with the TEC compared to 19.2% without the TEC.
Youngmoon Lee, Kang G. Shin
ISLPED3
2017 Continuous Authentication for Voice Assistants
abstract
Voice has become an increasingly popular User Interaction (UI) channel, mainly contributing to the current trend of wearables, smart vehicles, and home automation systems. Voice assistants such as Alexa, Siri, and Google Now, have become our everyday fixtures, especially when/where touch interfaces are inconvenient or even dangerous to use, such as driving or exercising. The open nature of the voice channel makes voice assistants difficult to secure, and hence exposed to various threats as demonstrated by security researchers. To defend against these threats, we present VAuth, the first system that provides continuous authentication for voice assistants. VAuth is designed to fit in widely-adopted wearable devices, such as eyeglasses, earphones/buds and necklaces, where it collects the body-surface vibrations of the user and matches it with the speech signal received by the voice assistant's microphone. VAuth guarantees the voice assistant to execute only the commands that originate from the voice of the owner. We have evaluated VAuth with 18 users and 30 voice commands and find it to achieve 97% detection accuracy and less than 0.1% false positive rate, regardless of VAuth's position on the body and the user's language, accent or mobility. VAuth successfully thwarts various practical attacks, such as replay attacks, mangled voice attacks, or impersonation attacks. It also incurs low energy and latency overheads and is compatible with most voice assistants.
Huan Feng, Kassem Fawaz, Kang G. Shin
MobiCom3
2017 Poster: Charge My Phone As I Instruct
abstract
Charging mobile devices fast alleviates users' impatience in waiting for their devices to be charged. So, fast charging has been the focus of both industry and academia, developing and deploying various technologies, such as Quick Charge by Qualcomm, TurboPower by Motorola, Flash Charge by OPPO, etc. Fast charging, unfortunately, accelerates the capacity fading of device battery because it follows the Constant Current, Constant Voltage (CCCV) charge principle without considering the behavior of how users charge their devices. CCCV charging principle is a two-phase charging process consisting of (i) Constant-Current Charge (CC-Chg) and (ii) Constant-Voltage Charge (CV-Chg) [2] where CV-Chg is usually triggered at the end of charging (e.g., 80-100%) to stabilize the battery condition. However, fast charging technologies are agnostic of users' available charging time, resulting in premature termination of the planned charging if users only have limited time. This, in turn, leads to an incomplete CV-Chg phase or even skipping it completely. From our empirical measurements, we discovered that CV-Chg relaxes the batteries and slows down their capacity fading by up to 80% [1] incomplete CV-Chg shortens the battery life significantly over time!
Liang He 0002, Yu-Chih Tung, Kang G. Shin
MobiSys3
2017 iCharge: User-Interactive Charging of Mobile Devices
abstract
Charging mobile devices "fast" has been the focus of both industry and academia, leading to the deployment of various fast charging technologies. However, existing fast charging solutions are agnostic of users' available time for charging their devices, causing early termination of the intended/planned charging. This, in turn, accelerates the capacity fading of device battery and thus shortens the device operation. In this paper, we propose a novel user-interactive charging paradigm, called iCharge, that tailors the device charging to the user's real-time availability and need. The core of iCharge is a relaxation-aware (R-Aware) charging algorithm that maximizes the charged capacity within the user's available time and slows down the battery's capacity fading. iCharge also integrates R-Aware with existing fast charging algorithms via a user-interactive interface, allowing users to choose a charging method based on their availability and need. We evaluate iCharge via extensive laboratory experiments and field-tests on Android phones, as well as user studies. R-Aware is shown to slow down the battery fading by more than 36% on average, and up to 60% in extreme cases, when compared to existing fast charging algorithms. This slowdown of capacity fading translates to, for instance, an up to 2-hour extension of the LTE time for a Nexus 5X phone after its use for 2 years, according to our trace-driven analysis of 976 device charging cases of 7 users over 3 months.
Liang He 0002, Yu-Chih Tung, Kang G. Shin
MobiSys3
2017 Efficient Memory Disaggregation with Infiniswap
Juncheng Gu, Youngmoon Lee, Yiwen Zhang 0008, Mosharaf Chowdhury, Kang G. Shin
NSDI5
2017 Adaptive transmission in heterogeneous networks
abstract
An A daptive tran S mission mechanism exploiting both interference lo C ality and the relationship between d E sired sig N al and in T erference ( ASCENT ) is proposed for uplink transmission in heterogeneous networks. The authors adopt both X channel and Z channel models according to which spatial signal processing is designed. In the X channel, the picocell base station (PBS) exploits information the macrocell base station (MBS) shares to cancel local interference, and cooperatively decodes the data carried by strong interference from a macro‐user (MU), which is then fed to the MBS. As a result, a pico‐user (PU) can transmit simultaneously with an MU on the same channel. In addition, adaptive reception is employed to achieve good tradeoff between interference suppression and the desired level of signal distortion. For the Z channel, the PU and the PBS adopt signal processing suitable for their own channel state. At a PBS, interference cancellation is adopted to eliminate disturbance from an MU via inter‐base station collaboration. ASCENT is also extended to the case of multiple picocells. The authors’ simulation results show that in X channel mode, the achievable uplink rate of an MU can be significantly enhanced. In the case of Z channel, the PU's rate is improved while guaranteeing the MU's data rate.
Zhao Li 0006, Lu Zhen, Xiaoqin Dai, Biao Shen, Yujiao Bai, Xiaohui Ren, Kang G. Shin
IET Commun.7
2017 Development and use of a new task model for cyber-physical systems: A real-time scheduling perspective
Jinkyu Lee 0001, Kang G. Shin
J. Syst. Softw.2
2017 A Case Study on Improving Capacity Delivery of Battery Packs via Reconfiguration
abstract
Cell imbalance in large battery packs degrades their capacity delivery, especially for cells connected in series where the weakest cell dominates their overall capacity. In this article, we present a case study of exploiting system reconfigurations to mitigate the cell imbalance in battery packs. Specifically, instead of using all the cells in a battery pack to support the load, selectively skipping cells to be discharged may actually enhance the pack’s capacity delivery. Based on this observation, we propose CSR, a Cell Skipping-assisted Reconfiguration algorithm that identifies the system configuration with (near)-optimal capacity delivery. We evaluate CSR using large-scale emulation based on empirically collected discharge traces of 40 lithium-ion cells. CSR achieves close-to-optimal capacity delivery when the cell imbalance in the battery pack is low and improves the capacity delivery by about 20% and up to 1x in the case of a high imbalance.
Liang He 0002, Kang G. Shin
ACM Trans. Cyber Phys. Syst.3
2017 Joint Energy Replenishment and Operation Scheduling in Wireless Rechargeable Sensor Networks
abstract
Wireless charging is a promising way to solve the energy constraint problem in sensor networks. While extensive efforts have been made to improve the performance of charging and communication in wireless rechargeable sensor networks (WRSNs), little has been done to address the operation scheduling problem. To fill this void, we propose a joint energy replenishment and scheduling mechanism so as to maximize the network lifetime while making strict sensing guarantees in the WRSN. We first formulate the problem in a general 2-D space and prove its NP-completeness. We then devise an f-approximate scheduling mechanism by transforming the classical minimum set cover problem and develop an optimal energy-replenish strategy based on the energy consumption of nodes returned by the scheduling mechanism. Large-scale simulation results validate our design and show a 39.2% improvement of network lifetime over a baseline method.
Yuanchao Shu, Kang G. Shin, Jiming Chen 0001, Youxian Sun
IEEE Trans. Ind. Informatics2
2017 Battery-Aware Mobile Data Service
abstract
Significant research has been devoted to reduce the energy consumption of mobile devices, but how to increase their energy supply has received far less attention. Moreover, reducing the energy consumption alone does not always extend the device operation time due to a unique battery property - the capacity it delivers hinges critically upon how it is discharged. In this paper, we propose B-MODS, a novel design of battery-aware mobile data service on mobile devices. B-MODS constructs battery-friendly discharge patterns utilizing the recovery effect so as to increase the capacity delivered from batteries while meeting data service requirements. We implement B-MODS as an application layer library on the Android platform. Our experiments with diverse mobile devices under various application scenarios have shown that B-MODS increases the capacity delivery from the battery by up to 49.5 percent, with which an increase in the user-perceived data service utilities of up to 28.6 percent is observed.
Liang He 0002, Guozhu Meng, Yu Gu 0001, Cong Liu 0005, Jun Sun 0001, Ting Zhu 0001, Yang Liu 0003, Kang G. Shin
IEEE Trans. Mob. Comput.8
2017 Coverage Analysis of Multi-Stream MIMO HetNets With MRC Receivers
abstract
Most of the current research on the coverage performance of multi-stream MIMO heterogeneous networks (HetNets) has focused on a single data-stream. This does not always provide accurate results as our analysis show the cross-stream correlation due to interference can greatly affect the coverage performance. This paper analyzes the coverage probability in such systems, and studies the impact of cross-stream correlation. Specifically, we focus on the max-SIR cell association policy and leverage stochastic geometry to study scenarios, whereby a receiver is considered in the coverage, if all of its data-streams are successfully decodeable. Assuming open-loop maximum ratio combining (MRC) at receivers, we consider the cases where partial channel state information is available at the receiver. We then obtain an upper-bound on the coverage and formulate cross-stream SIR correlation. We further show that approximating such systems based on fully-correlated (non-correlated) data-streams results in a slight underestimation (substantial overestimation) of the coverage performance. Our results provide insights on the multiplexing regimes where densification improves the coverage performance and spectral efficiency. We also compare MRC with more complex zero-forcing receiver and provide quantitative insights on the design tradeoffs. Our analysis is validated via extensive simulations.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
IEEE Trans. Wirel. Commun.3
2016 Understanding and defending the binder attack surface in Android
Huan Feng, Kang G. Shin
ACSAC2
2016 Error Handling of In-vehicle Networks Makes Them Vulnerable
abstract
Contemporary vehicles are getting equipped with an increasing number of Electronic Control Units (ECUs) and wireless connectivities. Although these have enhanced vehicle safety and efficiency, they are accompanied with new vulnerabilities. In this paper, we unveil a new important vulnerability applicable to several in-vehicle networks including Control Area Network (CAN), the de facto standard in-vehicle network protocol. Specifically, we propose a new type of Denial-of-Service (DoS), called the bus-off attack, which exploits the error-handling scheme of in-vehicle networks to disconnect or shut down good/uncompromised ECUs. This is an important attack that must be thwarted, since the attack, once an ECU is compromised, is easy to be mounted on safety-critical ECUs while its prevention is very difficult. In addition to the discovery of this new vulnerability, we analyze its feasibility using actual in-vehicle network traffic, and demonstrate the attack on a CAN bus prototype as well as on two real vehicles. Based on our analysis and experimental results, we also propose and evaluate a mechanism to detect and prevent the bus-off attack.
Kyong-Tak Cho, Kang G. Shin
CCS2
2016 RT-OPEX: Flexible Scheduling for Cloud-RAN Processing
abstract
It is cost-effective to process wireless frames on general purpose processors (GPPs) in place of dedicated hardware. Wireless operators are decoupling signal processing from basestations and implementing it in a cloud of compute resources, also known as a cloud-RAN (C-RAN). A C-RAN must meet the deadlines of processing wireless frames; for example, 3ms to transport, decode and respond to an LTE uplink frame. The design of baseband processing on these platforms is thus a major challenge for which various processing and real-time scheduling techniques have been proposed. In this paper, we implement a medium-scale C-RAN-type platform and conduct an in-depth analysis of its real-time performance. We find that the commonly used (e.g., partitioned) scheduling techniques for wireless frame processing are inefficient as they either over-provision resources or suffer from deadline misses. This inefficiency stems from the large variations in processing times due to fluctuations in wireless traffic. We present a new framework called RTOPEX, that leverages these variations and proposes a flexible approach for scheduling. RT-OPEX dynamically migrates parallelizable tasks to idle compute resources at runtime, reducing processing times and hence deadline misses at no additional cost. We implement and evaluate RT-OPEX on a commodity GPP platform using realistic cellular workload traces. Our results show that RT-OPEX achieves an order-of-magnitude improvement over existing C-RAN schedulers in meeting frame processing deadlines.
Krishna C. Garikipati, Kassem Fawaz, Kang G. Shin
CoNEXT3
2016 Exploiting Quantization Uncertainty for Enhancing Capacity of Limited-Feedback MISO Ad Hoc Networks
abstract
In this paper we investigate the capacity of random wireless networks in which transmitters are equipped with multiantennas. A quantized version of channel direction information (CDI) is also available, provided by the associated single antenna receivers. We adopt tools of stochastic geometry and random vector quantization to incorporate the impacts of interference and quantization errors, respectively. We first study the capacity of Aloha, and channel quality information (CQI)-based scheduling, whereby the transmissions decision in each transceiver pair depends on the strength of the CQI against a prescribed threshold. We then propose a new scheduling scheme, namely modified CQI (MCQI), by which the quantization error is effectively incorporated in the scheduling. Further we obtain the capacity of MCQI-based scheduling. Simulation results confirm our analysis and show that the proposed MCQI-based scheduling improves the capacity compared to the CQI-based scheduling and Aloha. It is also seen that the performance boost is more significant where the feedback capacity is low and the network is dense. In comparison with the case of high feedback capacity, the network capacity is not reduced by low feedback capacity in the MCQI-based scheduling. This is of practical importance since the network designer can save the feedback resources by employing MCQI-based scheduling without compromising the capacity and increasing the receivers' complexity.
Mohammad G. Khoshkholgh, Ali A. Haghighi, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
GLOBECOM4
2016 Provisioning Statistical QoS for Coordinated Communications with Limited Feedback
abstract
The capacity performance of ICIC has been extensively studied in coordinated multi-point transmissions (CoMP). In practice however, due to limited feedback, the acquired channel direction information (CDI), which is crucial for ICIC, is often partially available. Hence one may question whether the ICIC is able to meet the Quality-of- Service (QoS) requirements. This paper considers the optimal partitioning of the feedback bits in CoMP while accounting for the inter-cell interference cancellation (ICIC). In this paper, we adopt a statistical model of QoS in CoMP by using the notion of effective capacity (EC). Utilizing EC we then formulate the system function as an optimization problem with the objective of maximizing the total EC subject to the limited feedback available to the cluster of base stations (BSs). Analytical approximations are then obtained on the EC performance which are then utilized as the base for algorithms that assign feedback bits among the user equipments (UEs) and BSs. Using simulations we then investigate the accuracy of the obtained approximations and highlight practical system designs for dealing with stringent delay requirements. Of crucial practical importance, the findings of this paper also indicates that in CoMP there is an optimal cluster size for a given feedback capacity that maximizes the corresponding EC.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
GLOBECOM3
2016 Coordinated multi-point transmissions based on interference alignment and neutralization
abstract
Both interference alignment (IA) and interference neutralization (IN) are exploited for Coordinated Multi-Point (CoMP) transmissions. With the base station's cooperation, transmit precoder and receive filter are designed jointly, and then concurrent transmissions of multiple data streams are achieved. In the design of preprocessing, IN is applied to the interferences carrying same data so as to align the interfering signals with opposite directions in a subspace. On the other hand, for interferences carrying different information, IA is employed to align them with the same direction in a subspace, thus reducing the interference signal dimension observed at the user side. Based on different precoding schemes at the transmitter's side, receivers adopt zero-forcing (ZF) so as to recover the desired data. The proposed interference alignment and neutralization based CoMP (IAN-CoMP) mechanism can achieve effective interference cancellation and suppression by exploiting limited and flexible collaboration only at the base station (BS) side. We also extend the mechanism to general cases where the antenna configurations at both transmitter and receiver side, the number of transmitters participating in CoMP and simultaneously served users are variable. In addition, the proposed scheme can also achieve a flexible tradeoff between cooperation overhead and the system's achievable degrees of freedom (DoFs). Our in-depth simulation results show that IAN-CoMP can significantly improve the spectral efficiency (SE) for cell-edge users.
Zhao Li 0006, Sha Cui, Kang G. Shin
INFOCOM3
2016 Decoding interfering signals with fewer receiving antennas
abstract
Due to the hierarchical structure and heterogeneity of most deployed wireless networks, multiple data transmissions using the same communication resource, such as frequency band and time slot, are likely to occur in the same area. Hence, interference becomes critical to the decoding of interfered signals. There have already been numerous techniques dealing with interferences that can be implemented either at the transmitter, the receiver or both, to support simultaneous multi-user transmissions. This paper focuses on the reception design in multiple access channels (MACs) where multiple transmitters send data to a common receiver simultaneously. By exploiting the constructive/destructive interactions among interfering signals, we propose a receiver structure based on interference combination (ICom) incorporating zero-forcing (ZF) and successive interference cancellation (SIC). The proposed receiver structure does not require coordination at the transmitter side and can significantly reduce the number of receiving antennas at a moderate processing cost. The ICom-based reception is shown to be able to not only achieve a significant improvement of system spectral efficiency (SE) under stringent latency constraints, but also make a flexible tradeoff between the requirement of receiving antennas and signal processing complexity, thus facilitating its implementation and deployment.
Zhao Li 0006, Xiaoqin Dai, Kang G. Shin
INFOCOM3
2016 Analog man-in-the-middle attack against link-based packet source identification
abstract
A novel attack model is proposed against the existing wireless link-based source identification, which classifies packet sources according to the physical-layer link signatures. A link signature is believed to be a more reliable indicator than an IP or MAC address for identifying packet source, as it is generally harder to modify/forge. It is therefore expected to be a future authentication against impersonation and DoS attacks. However, if an attacker is equipped with the same capability/hardware as the authenticator to process physical-layer signals, a link signature can be easily manipulated by any nearby wireless device during the training phase. Based on this finding, we propose an attack model, called the analog man-in-the-middle (AMITM) attack, which utilizes the latest full-duplex relay technology to inject semi-controlled link signatures into authorized packets and reproduce the injected signature in the fabricated packets. Our experimental evaluation shows that with a proper parameter setting, 90% of fabricated packets are classified as those sent from an authorized transmitter. A countermeasure against this new attack is also proposed for the authenticator to inject link-signature noise by the same attack methodology.
Yu-Chih Tung, Kang G. Shin, Kyu-Han Kim
MobiHoc2
2016 Expansion of Human-Phone Interface By Sensing Structure-Borne Sound Propagation
abstract
ForcePhone is a novel system that enables commodity phones to recognize the force applied to their touch screen and body. Researchers have shown the usefulness and importance of this expressive input interface (especially for the one-hand operation), but this advanced function has not yet been realized and deployed in most state-of-the-art smartphones. Instead of employing or augmenting specialized/proprietary sensors, ForcePhone uses only the phone's built-in sensors to measure the applied force via a physical property called structure-borne sound propagation. ForcePhone has been implemented and evaluated on both iOS and Android phones. Multiple demo applications, such as getting the option menu by hard-pressing a button or surfing the previous webpage by squeezing the phone, have been implemented and tested successfully. The estimated force is shown highly correlated to the real applied force and the estimation error is less than 54g when the phone is stationary. Users can easily control the applied force at two different levels with a 97% accuracy. Moreover, ForcePhone can detect the squeeze of the phone body with a higher than 90% accuracy. Most participants in our usability study were able to master the ForcePhone-based apps and find them very useful.
Yu-Chih Tung, Kang G. Shin
MobiSys2
2016 Masquerade of mobile applications: Introducing unlinkability in a practical way
abstract
Smartphone apps are becoming a popular vehicle to collect users' personal interests, demographics and other private information. Due to lack of regulation, a curious party can covertly link and aggregate sensitive information from independent sources (sessions or apps) over time to conduct unwanted user profiling, targeted advertising or surveillance. Such unregulated aggregation is rooted at the non-existence of unlinkability in the mobile ecosystem. On one hand, the mobile ecosystem is over-populated with various persistent identifiers and fueled by the abundance of user information; on the other hand, users only expect app usages that are functionally-dependent to be linkable. To bridge this gap, we propose a practical solution, called Mask, that allows users to negotiate to what extent his behavior can be linked and aggregated. Specifically, Mask introduces a set of private execution modes which enable different levels of unlinkability. Mask is a user-level solution and does not require any change in the existing ecosystem, thus allowing for easy deployment. We present the technical details and challenges of our user-level implementation and evaluate its runtime performance as well as applicability.
Huan Feng, Kang G. Shin
PST2
2016 Prevention of information mis-translation by a malicious gateway in connected vehicles
abstract
As connectivity is becoming a norm for modern vehicles, data exchange between in-vehicle components and external entities is becoming common. However, car makers is concerned about a third-party's extraction of their proprietary vehicle data. To address this concern, an intermediate ECU (or a gateway) is introduced in between internal and external networks to translate proprietary in-vehicle data to rich type data, thus preventing the exposure of raw in-vehicle data. However, the translation relies solely on the gateway which can be a direct target of cyber attacks, making it difficult to trust the data passed through the gateway. This, in turn, requires authentication of the translated data. We present a new, effective protocol that provides secure communications between the vehicle's internal components and external entities against a compromised gateway.
Kyusuk Han, Kang G. Shin
PST2
2016 Offline Guarantee and Online Management of Power Demand and Supply in Cyber-Physical Systems
abstract
Since modern electric systems require to support various power-demand operations for user applications and system maintenance, they need advanced power management that jointly considers power demand by the operations and power supply from various sources, such as batteries, solar panels, and supercapacitors. In this paper, we develop a power scheduling framework for a reliable energy storage system with multiple power-supply sources and multiple power-demand operations. First, we provide an offline power-supply guarantee such that every power-demand operation completes its execution in time while the sum of power required by individual operations does not exceed the total power supplied by the entire energy storage system at any time. We find similarities between this and a real-time scheduling problem, and make a power-supply guarantee using real-time scheduling techniques. Second, we propose online power management that efficiently utilizes the surplus power (available at run-time) for system performance improvement. Our experimental results on a prototype demonstrate that the proposed framework not only guarantees the required power supply, but also enhances system performance by up to 33.1%.
Jinkyu Lee 0001, Liang He 0002, Youngmoon Lee, Kang G. Shin
RTSS5
2016 Reducing Journaling Harm on Virtualized I/O Systems
abstract
This paper analyzes the host cache effectiveness in full virtualization, particularly associated with journaling of guests. We observe that the journal access of guests degrades cache performance largely due to the write-once access pattern and the frequent sync operations. To remedy this problem, we design and implement a novel caching policy, called PDC (Pollution Defensive Caching), that detects the journal accesses and prevents them from entering the host cache. The proposed PDC is implemented in QEMU-KVM 2.1 on Linux 4.14 and provides 3-32% performance improvement for various file and I/O benchmarks.
Hyokyung Bahn, Minseong Jeong, Jesung Yeon, Seunghoon Yoo, Sam H. Noh, Kang G. Shin
SYSTOR8
2016 Version Traveler: Fast and Memory-Efficient Version Switching in Graph Processing Systems
Xiaoen Ju, Dan Williams 0001, Hani Jamjoom, Kang G. Shin
USENIX ATC4
2016 Fingerprinting Electronic Control Units for Vehicle Intrusion Detection
Kyong-Tak Cho, Kang G. Shin
USENIX Security Symposium2
2016 Protecting Privacy of BLE Device Users
Kassem Fawaz, Kyu-Han Kim, Kang G. Shin
USENIX Security Symposium3
2016 Coverage Performance of MIMO-MRC in Heterogeneous Networks: A Stochastic Geometry Perspective
abstract
We study the coverage performance of multi-antenna (MIMO) communications with maximum ratio combining (MRC) at the receiver in heterogeneous networks (HetNets). Our main interest in on multi-stream communications when BSs do not have access to channel state information. Adopting stochastic geometry we evaluate the network-wise coverage performance of MIMO-MRC assuming maximum signal- to-interference ratio (SIR) cell association rule. Coverage analysis in MIMO-MRC HetNets is challenging due to inter-stream interference and statistical dependencies among streams' SIR values in each communication link. Using the results of stochastic geometry we then investigate this problem and obtain tractable analytical approximations for the coverage performance. We then show that our results are adequately accurate and easily computable. Our analysis sheds light on the impacts of important system parameters on the coverage performance, and provides quantitative insight on the densification in conjunction with high multiplexing gains in MIMO HetNets. We further observe that increasing multiplexing gain in high- power tier can cost a huge coverage reduction unless it is practiced with densification in femto-cell tier.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
VTC Fall3
2016 Performance Evaluation of MISO-SDMA in Heterogeneous Networks with Practical Cell Association
abstract
In this paper adopting stochastic geometry we investigate the system performance in heterogeneous networks including multiple tiers of BSs with multiple-input single output spatial division multiple access (MISO-SDMA) technique. In the related literature on heterogeneous systems, ideal cell association (CA) rules are often considered for simplicity, where each user equipment (UE) examines a very large number of pilots across the tiers before choosing its associated base station (BS). Here we consider practical cases where UEs are restricted to examine KH≥ 1 pilots across all tiers before choosing their associated BS. We then obtain closed-form expressions for the system performance measured by the coverage probability and UE's data rate. Our analytical results provide quantitative insights on the impact of different factors on the system performance including the BS's spatial density, their transmission powers, number of transmit antennas, SIR thresholds, number of UEs served by each BS, and KH. Interestingly, we observe that increasing KHalways improves the coverage probability however, it only improves data rate up to a certain point. The data rate is then reduced by further increasing of KH. Given KHpilots in practical cases, the issue is how to allocate the pilots among different tiers. We address this issue by developing an algorithm and show that by careful allocation of available pilots, the network performance is significantly improved even in cases with small KH. Our results also indicate a fundamental tradeoff, as sharing strategies providing the best coverage performance yield very poor capacity and vice versa. Such trade-off provides a new degree of freedom in heterogeneous networks design.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Victor C. M. Leung
VTC Fall3
2016 Generalizing fixed-priority scheduling for better schedulability in mixed-criticality systems
Yao Chen 0005, Kang G. Shin, Huagang Xiong
Inf. Process. Lett.2
2016 Privacy vs. Reward in Indoor Location-Based Services
abstract
Abstract With the advance of indoor localization technology, indoor location-based services (ILBS) are gaining popularity. They, however, accompany privacy concerns. ILBS providers track the users’ mobility to learn more about their behavior, and then provide them with improved and personalized services. Our survey of 200 individuals highlighted their concerns about this tracking for potential leakage of their personal/private traits, but also showed their willingness to accept reduced tracking for improved service. In this paper, we propose PR-LBS (Privacy vs. Reward for Location-Based Service), a system that addresses these seemingly conflicting requirements by balancing the users’ privacy concerns and the benefits of sharing location information in indoor location tracking environments. PR-LBS relies on a novel location-privacy criterion to quantify the privacy risks pertaining to sharing indoor location information. It also employs a repeated play model to ensure that the received service is proportionate to the privacy risk. We implement and evaluate PR-LBS extensively with various real-world user mobility traces. Results show that PR-LBS has low overhead, protects the users’ privacy, and makes a good tradeoff between the quality of service for the users and the utility of shared location data for service providers.
Kassem Fawaz, Kyu-Han Kim, Kang G. Shin
Proc. Priv. Enhancing Technol.3
2016 Eliminating Periodic Flush Overhead of File I/O with Non-Volatile Buffer Cache
abstract
File I/O buffer caching plays an important role to narrow the wide speed gap between main memory and secondary storage. However, data loss or inconsistency may occur if the system crashes before updated data in the buffer cache is flushed to storage. Thus, most operating systems adopt a daemon that periodically flushes dirty data to secondary storage. This periodic flush degrades the caching efficiency seriously because most write requests lead to direct storage accesses. We show that periodic flush accounts for 30-70 percent of the total write traffic to storage. To remove this inefficiency, this paper presents a new buffer cache architecture that adopts a small amount of non-volatile memory to maintain modified data. This novel buffer cache architecture removes almost all storage accesses due to periodic flush operations without any loss of reliability. It also improves the buffer cache performance through space-efficient management techniques, such as delta-write and fragment-grouping. Our experimental results show that the proposed buffer cache reduces the storage write traffic by 44.3 percent and also improves the throughput by 23.6 percent on average.
Hyojung Kang, Hyokyung Bahn, Kang G. Shin
IEEE Trans. Computers4
2016 Fair and Efficient Coexistence of Heterogeneous Channel Widths in Next-Generation Wireless LANs
abstract
To meet the diverse traffic demands of different applications, emerging WLAN standards have been incorporating a variety of channel widths ranging from 5 to 160 MHz. The coexistence of variable-width channels imposes a new challenge to the 802.11 protocols, since the 802.11 MAC is agnostic of, and thus incapable of, adapting to the PHY-layer spectrum heterogeneity. To address this challenge, we uncover the cause and effect of variable-width channel coexistence, and develop a MAC-layer scheme, called Fine-grained Spectrum Sharing (FSS), that solves the general problem of fair and efficient spectrum sharing among users with heterogeneous channel-widths. Instead of deeming its spectrum band as an atomic block, an FSS user divides the spectrum into chunks, and adapts its chunk usage on a per-packet basis. FSS's spectrum adaptation is driven by a decentralized optimization framework. It preserves the 802.11 CSMA/CA primitives while allowing users to contend for each spectrum chunk, and can opportunistically split a wide-band channel or bond multiple (discontiguous) chunks to ensure fair and efficient access to available spectrum. In making such adaptation decisions, it balances the benefit from discontiguous chunks and the cost of guardband - a unique tradeoff in WLANs with heterogeneous channel-widths. Our in-depth evaluation demonstrates that FSS can improve throughput by multiple folds, while maintaining fairness of spectrum sharing for heterogeneous WLANs.
Sihui Han, Xinyu Zhang 0003, Kang G. Shin
IEEE Trans. Mob. Comput.3
2016 Near-Optimal Velocity Control for Mobile Charging in Wireless Rechargeable Sensor Networks
abstract
Limited energy in each node is the major design constraint in wireless sensor networks (WSNs). To overcome this limit, wireless rechargeable sensor networks (WRSNs) have been proposed and studied extensively over the last few years. In a typical WRSN, batteries in sensor nodes can be replenished by a mobile charger that periodically travels along a certain trajectory in the sensing area. To maximize the charged energy in sensor nodes, one fundamental question is how to control the traveling velocity of the charger. In this paper, we first identify the optimal velocity control as a key design objective of mobile wireless charging in WRSNs. We then formulate the optimal charger velocity control problem on arbitrarily-shaped irregular trajectories in a 2D space. The problem is proved to be NP-hard, and hence a heuristic solution with a provable upper bound is developed using novel spatial and temporal discretization. We also derive the optimal velocity control for moving the charger along a linear (1D) trajectory commonly seen in many WSN applications. Extensive simulations show that the network lifetime can be extended by 2.5× with the proposed velocity control mechanisms.
Yuanchao Shu, Hamed Yousefi 0001, Peng Cheng 0001, Jiming Chen 0001, Yu Gu 0001, Tian He 0001, Kang G. Shin
IEEE Trans. Mob. Comput.7
2016 POEM: Minimizing Energy Consumption for WiFi Tethering Service
abstract
Despite the rapidly increasing number of public WiFi hotspots, their coverage is still limited to indoor and office/business environments. WiFi tethering is thus a useful and economic means of providing on-the-go mobile users' Internet connection. One of the main problems of WiFi tethering is the excessive power consumption of mobile access points (APs), or tethered smartphones. Since the power-saving mechanism, defined and deployed in the IEEE 802.11 standard, is intended for clients only, the WiFi interface of a mobile AP never enters the sleep mode. In this paper, we propose a simple but effective system, called power-efficient mobile (POEM), which reduces energy consumption of a mobile AP by allowing its WiFi interface to sleep even during data transfer. The POEM exploits the inherent bandwidth asymmetry between the WiFi and the WWAN interfaces of a mobile AP by buffering the data packets received via the WWAN interface at the mobile AP, thereby allowing the WiFi interface to enter the sleep mode. Compared with the other power-saving solutions for WiFi tethering, the POEM is able to handle various types of applications, such as video steaming and file download, designed to support legacy clients (i.e., clients without POEM), and is also efficient in reducing the clients' energy consumption. We have implemented and conducted an extensive evaluation of the POEM's effectiveness in an android/linux-based test bed. Our experimental results show that the POEM can allow the WiFi interface of a mobile AP to sleep for up to 90% of the total transfer time without significantly affecting system throughput or end-to-end delay.
Wan-Seon Lim, Kang G. Shin
IEEE/ACM Trans. Netw.2
2015 Application-assisted live migration of virtual machines with Java applications
abstract
Live migration of virtual machines (VMs) can consume excessive time and resources, and may affect application performance significantly if VM memory pages get dirtied faster than their content can be transferred to the destination. Existing approaches to this problem transfer memory content faster with high-speed networks, slow down the dirtying of memory pages by throttling the execution of applications, or reduce the amount of memory content to be transferred, for example, using compression. However, these approaches incur high resource costs or application performance penalties. In this paper, we propose to skip the transfer of VM memory pages that need not be migrated for the execution of running applications at the destination, by exploiting applications' assistance. We have designed a generic framework for application-assisted live migration and then used it to build and evaluate JAVMM, which migrates VMs running various types of Java applications skipping the transfer of garbage in Java memory. Our experimental results show that JAVMM can reduce the completion time, the network traffic of transferring memory pages, and the application downtime of Java VM migration, all by up to over 90%, compared to the vanilla Xen VM migration, without incurring noticeable performance penalty to applications.
Kai-Yuan Hou, Kang G. Shin, Jan-Lung Sung
EuroSys2
2015 On the impact of delay constraint on the multicast outage in wireless fading environment
abstract
In this paper we investigate single-hop multicast transmission in which randomly located multiple transmitters multicast packets to a cluster of receivers. Packet retransmission is known as a promising mechanism for improving the transmission reliability. Our focus is on evaluating (i) the minimum required delay (retransmission attempts), τ*, for establishing an outage-free multicast, where a transmitted packet is successfully decoded by entire nodes in the cluster, and (ii) Multicast Progress Radius (MPR) for a given delay constraint. MPR indicates how far, on average, a packet can successfully progress in a cluster without outage while the retransmission delay is restricted. Assuming general fading distribution, we derive closed-form expressions for the cumulative distribution function of τ*, and MPR. By simulations we confirmed our analysis and studied the impact of several system parameters on the MPR. Based on results of this paper we conclude that outage-free multicast requires a very large number of retransmission attempts, thus not practically achievable only based on retransmission.
Mohammad G. Khoshkholgh, Keivan Navaie, Kang G. Shin, Chun-Hung Liu, Yongguang Zhang, Victor C. M. Leung, Stein Gjessing
ICC3
2015 EMS: Efficient Multicast Streaming Scheme for Multicasting within Wi-Fi Hotspot
abstract
We have discovered two main problems when a multicast sender and multicast receivers are associated with the same AP. First, the multicast sender cannot determine a proper sending rate with the traditional end-to-end rate-adaptation schemes. Second, the multicast sender wastes its power due to the unique characteristics of power saving mode of the IEEE 802.11 standard. We propose efficient multicast streaming (EMS) to solve these problems without modifying the AP and the multicast receivers. With EMS, the multicast sender adapts its sending rate at the application layer and adjusts the sleep cycle at the MAC layer by monitoring multicast packets sent from the AP. Our experimentation and simulation results show that EMS can improve video quality at the receivers and reduce power consumption of the multicast sender significantly.
Wan-Seon Lim, Kang G. Shin
ICNP2
2015 SPIRO: Turning elephants into mice with efficient RF transport
abstract
Cloud-RANs (Radio Access Networks) assume the existence of a high-capacity, low-delay/latency fronthaul to support cooperative transmission schemes such as CoMP (Coordinated Multi-Point) and coordinated beamforming. However, building such hierarchical wired fronthauls is challenging as the typical I/Q data stream is non-elastic - I/Q data over the wired fronthaul has little tolerance for delay jitters and zero tolerance for losses. Any distortion to the I/Q data stream will make the resulting wireless transmission completely unintelligible. We propose Spiro, a mechanism that efficiently transports RF signals over a wired fronthaul network. The primary goal of Spiro is to make I/Q data streams elastic and resilient to unexpected network condition changes. This is accomplished through a novel combination of compression and data prioritization of I/Q data on the wired fronthaul. For a given wireless throughput, Spiro can reduce the bandwidth demand of the fronthaul data stream by up to 50% without any noticeable degradation in the wireless reception quality. Further bandwidth reduction via compression and frame losses only have a limited impact on the wireless throughput.
Eugene Chai, Kang G. Shin, Sung-Ju Lee 0001, Jeongkeun Lee, Raúl H. Etkin
INFOCOM2
2015 Differentially private and strategy-proof spectrum auction with approximate revenue maximization
abstract
The rapid growth of wireless mobile users and applications has led to high demand of spectrum. Auction is a powerful tool to improve the utilization of spectrum resource, and many auction mechanisms have been proposed thus far. However, none of them has considered both the privacy of bidders and the revenue gain of the auctioneer together. In this paper, we study the design of privacy-preserving auction mechanisms. We first propose a differentially private auction mechanism which can achieve strategy-proofness and a near optimal expected revenue based on the concept of virtual valuation. Assuming the knowledge of the bidders' valuation distributions, the near optimal differentially private and strategy-proof auction mechanism uses the generalized Vickrey-Clarke-Groves auction payment scheme to achieve high revenue with a high probability. To tackle its high computational complexity, we also propose an approximate differentially PrivAte, Strategy-proof, and polynomially tractable Spectrum (PASS) auction mechanism that can achieve a suboptimal revenue. PASS uses a monotone allocation algorithm and the critical payment scheme to achieve strategy-proofness. We also evaluate PASS extensively via simulation, showing that it can generate more revenue than existing mechanisms in the spectrum auction markets.
Ruihao Zhu, Kang G. Shin
INFOCOM2
2015 Last-Mile Navigation Using Smartphones
abstract
Although GPS has become a standard component of smartphones, providing accurate navigation during the last portion of a trip remains an important but unsolved problem. Despite extensive research on localization, the limited resolution of a map imposes restrictions on the navigation engine in both indoor and outdoor environments. To bridge the gap between the end position obtained from legacy navigation services and the real destination, we propose FollowMe, a "last-mile" navigation system to enable plug-and-play navigation in indoor and semi-outdoor environments. FollowMe exploits the ubiquitous, stable geomagnetic field and natural walking patterns to navigate the users to the same destination taken by an earlier traveler. Unlike existing localization and navigation systems, FollowMe is infrastructure-free, energy-efficient and cost-saving. We implemented FollowMe on smartphones, and evaluated it in a four-story campus building with a testing area of 2000m2. Our experimental results with 5 users show that 95% of spatial errors during navigation were 2m or less with at least 50% energy savings over a benchmark system.
Yuanchao Shu, Kang G. Shin, Tian He 0001, Jiming Chen 0001
MobiCom2
2015 EchoTag: Accurate Infrastructure-Free Indoor Location Tagging with Smartphones
abstract
We propose a novel mobile system, called EchoTag, that enables phones to tag and remember indoor locations without requiring any additional sensors or pre-installed infrastructure. The main idea behind EchoTag is to actively generate acoustic signatures by transmitting a sound signal with a phone's speakers and sensing its reflections with the phone's microphones. This active sensing provides finer-grained control of the collected signatures than the widely-used passive sensing. For example, because the sensing signal is controlled by EchoTag, it can be intentionally chosen to enrich the sensed signatures and remove noises from useless reflections. Extensive experiments show that EchoTag distinguishes 11 tags at 1cm resolution with 98% accuracy and maintains 90% accuracy even a week after its training. With this accurate location tagging, one can realize many interesting applications, such as automatically turning on the silent mode of a phone when it is placed at a pre-defined location/area near the bed or streaming favorite songs to speakers if it is placed near a home entertainment system. Most participants of our usability study agree on the usefulness of EchoTag's potential applications and the adequacy of its sensing accuracy for supporting these applications.
Yu-Chih Tung, Kang G. Shin
MobiCom2
2015 Invisible Sensing of Vehicle Steering with Smartphones
abstract
Detecting how a vehicle is steered and then alarming drivers in real time is of utmost importance to the vehicle and the driver's safety, since fatal accidents are often caused by dan- gerous steering. Existing solutions for detecting dangerous maneuvers are implemented either in only high-end vehicles or on smartphones as mobile applications. However, most of them rely on the use of cameras, the performance of which is seriously constrained by their high visibility requirement. Moreover, such an over/sole-reliance on the use of cameras can be a distraction to the driver.
Dongyao Chen, Kyong-Tak Cho, Sihui Han, Zhizhuo Jin, Kang G. Shin
MobiSys5
2015 Modeling and Real-Time Scheduling of Large-Scale Batteries for Maximizing Performance
abstract
Modern electric vehicles are equipped with an advanced battery management system, responsible for providing the necessary power efficiently from batteries to electric motors while maintaining the batteries within an operational condition. Because discharge-rate and temperature of batteries affect their health and efficiency significantly, batteries are managed to mitigate their discharge and thermal stresses. In this paper, we develop a real-time, efficient integrated management system for discharge-rate and temperature of batteries. To achieve this objective, we first construct a prognosis system predicting the likely states of batteries' capacity and capability. Based on prognostic estimates of the impact of temperature and discharge-rate on the performance, we solve an optimization problem to search for efficient discharging and cooling scheduling. Our experimentation and simulation demonstrate that the proposed management enhances system performance up to 85.3%.
Jinkyu Lee 0001, Kang G. Shin
RTSS3
2015 Anatomization and Protection of Mobile Apps' Location Privacy Threats
Kassem Fawaz, Huan Feng, Kang G. Shin
USENIX Security Symposium3
2015 LinkDroid: Reducing Unregulated Aggregation of App Usage Behaviors
Huan Feng, Kassem Fawaz, Kang G. Shin
USENIX Security Symposium3
2015 Fast and accurate cardinality estimation in cellular-based wireless communications
abstract
Cardinality estimation is of fundamental importance in various wireless communication applications. The performance of any adaptive medium access control in the uplink channel is in fact affected by its accuracy. This paper provides a fresh look at this fundamental problem, and proposes a novel scheme for fast and accurate cardinality estimation. This scheme utilizes the experienced outage probability in detecting IDs of the devices in the uplink. It is observed that for practically relevant values of Signal-to-Interference-plus-Noise Ratio (SINR) threshold, e.g., β ≤ 10 dB, and spreading sequence length, e.g., Nc≥ 7, the base station is able to estimate the true cardinality with vanishing error in only one shot, even if the network is so populated, e.g., the number of active devices N ≥ 100. Otherwise, one may apply the proposed method in couple of consecutive shots such that in each of which portion of the cardinality is estimated.
Mohammad G. Khoshkholgh, Victor C. M. Leung, Kang G. Shin
WCNC3
2015 Modeling and characterization of transmission energy consumption in Machine-to-Machine networks
abstract
In future, a massive number of devices are expected to communicate for pervasive monitoring and measurement, industrial automation, and home/building energy management. Nevertheless, such Machine-to-Machine (M2M) communications are prone to failure due to depletion of machines energy if the communication system is not designed properly. A key step in building energy-efficient protocols for large-scale M2M communications is to assess, model or characterize a network energy consumption profile. To meet this need, we develop a theoretical and numerical framework to evaluate the cumulative distribution function (CDF) of the total energy consumption by fully exploiting the properties of stochastic geometry. Unlike the other existing approaches, we model the transmission energy as a function of transmission power, packet size, and link affordable capacity that is a logarithmic function of experienced Signal to Interference plus Noise Ratio (SINR). Since it is very difficult, if not impossible, to derive a closed-form expression for the CDF, we derive numerically computable first- and second-order moments of energy consumption. Applying these moments we then propose Log-normal and Log-logistic distributions to approximate the CDF. Our simulation results show that Log-logistic almost precisely approximates the exact CDF.
Mohammad G. Khoshkholgh, Yan Zhang 0002, Kang G. Shin, Victor C. M. Leung, Stein Gjessing
WCNC3
2015 Radio Resource Allocation for OFDM-Based Dynamic Spectrum Sharing: Duality Gap and Time Averaging
abstract
This paper considers radio resource allocation (RRA) in the downlink of an orthogonal frequency division multiple access (OFDM)-based spectrum-sharing network. The objective of RRA is to maximize the average achievable throughput subject to the primary service interference threshold and the secondary service transmit power constraint. RRA is usually implemented based on a time window T over which system parameters are averaged and checked against resource constraints. We use short-term ( T=1 time slot) and long-term ( T ≫ 1 slots) averaging as approximations to instantaneous and average constraints, respectively. RRA is also investigated for this system with long-term interference threshold and short-term interference threshold constraints. RRA optimization is a nonconvex optimization problem in which the duality principle is adopted to obtain approximate solutions. The duality gap indicates the degree of approximation in the thus-obtained solution. We prove that the duality gap corresponding to each resource allocation asymptotically decays at least with an exponential rate of T. We further show that OFDMA is, asymptotically, the optimal subcarrier assignment. We also propose a practically implementable online power and subcarrier allocation with on-the-fly channel state information measurement. An extensive simulation study has been conducted to verify the theoretically predicted duality gap behavior and to investigate the impact of different system parameters on the secondary service performance. The developed algorithms are also validated to be robust in practical settings and converge fast to theoretical bounds, and thus practically implementable.
Mohammad G. Khoshkholgh, Nader Mokari, Keivan Navaie, Halim Yanikomeroglu, Victor C. M. Leung, Kang G. Shin
IEEE J. Sel. Areas Commun.6
2015 Connectivity of Cognitive Device-to-Device Communications Underlying Cellular Networks
abstract
Providing direct communications among a rapidly growing number of wireless devices within the coverage area of a cellular system is an attractive way of exploiting the proximity among them to enhance coverage and spectral and energy efficiency. However, such device-to-device (D2D) communications create a new type of interference in cellular systems, calling for rigorous system analysis and design to both protect mobile users (MUs) and guarantee the connectivity of devices. Motivated by the potential advantages of cognitive radio (CR) technology in detecting and exploiting underutilized spectrum, we investigate CR-assisted D2D communications in a cellular network as a viable solution for D2D communications, in which devices access the network with mixed overlay-underlay spectrum sharing. Our comprehensive analysis reveals several engineering insights useful to system design. We first derive bounds of pivotal performance metrics. For a given collision probability constraint, as the prime spectrum-sharing criterion, we also derive the maximum allowable density of devices. This captures the density of MUs and that of active macro base stations. Limited in spatial density, devices may not have connectivity among them. Nevertheless, it is shown that for the derived maximum allowable density, one should judiciously push a portion of devices into receiving mode in order to preserve the connectivity and to keep the isolation probability low. Furthermore, upper bounds on the cellular coverage probability are obtained incorporating load-based power allocation for both path-loss and fading-based cell association mechanisms, which are fairly accurate and consistent with our in-depth simulation results. Finally, implementation issues are discussed.
Mohammad G. Khoshkholgh, Yan Zhang 0002, Kwang-Cheng Chen, Kang G. Shin, Stein Gjessing
IEEE J. Sel. Areas Commun.4
2015 Distributed Coordination of Co-Channel Femtocells via Inter-Cell Signaling With Arbitrary Delay
abstract
To achieve high spatial reuse of spectrum resources with limited inter-layer/cell interference, co-channel femtocells must be coordinated with the underlying macro- and other femto-cells in using radio resources. While inter-cell signaling can coordinate femtocells by providing the status information of neighbor cells explicitly, signaling delay-which may result from a limited signaling rate to reduce the resulting overhead, network latency, etc.-and its impact on the behavior of distributed coordination has not been explored before. In this paper, we propose a new architecture for the distributed coordination of co-channel femtocells based on asynchronous inter-cell signaling, called asynchronous coordination of co-channel femtocells (ACoF). ACoF improves solutions iteratively; femtocells update radio resource usage based on the received information, which usually gets outdated due to delayed signaling and asynchronous update behavior. ACoF allows each femtocell to adjust its signaling rate depending on its local conditions for fine-grained cost minimization, but at the expense of higher degree of inconsistency of femtocells' knowledge. Despite such asynchrony and inconsistency, the solution yielded by ACoF is guaranteed to converge to a global optimum under a certain condition of configuration parameters, which we prove theoretically. We design the optimization method of per-cell signaling rate for both wired and over-the-air signaling. Finally, we present a joint muting and transmit power adjustment scheme designed for ACoF and evaluate its convergence behavior and performance gain.
Ji-Hoon Yun, Kang G. Shin
IEEE J. Sel. Areas Commun.2
2015 Composition of Schedulability Analyses for Real-Time Multiprocessor Systems
abstract
With increasing popularity and deployment of multi-core chips in embedded systems, a number of real-time multiprocessor scheduling algorithms have been proposed along with their schedulability analyses (or tests), which verify temporal correctness under a specific algorithm. Each of these algorithms often comes with several different schedulability tests, especially when it is difficult to find exact schedulability tests for the algorithm. Such tests usually find different task sets deemed schedulable even under the same scheduling algorithm. While these different tests have been compared with each other in terms of schedulability performance, little has been done on how to combine such different tests to improve the overall schedulability of a given scheduling algorithm beyond a simple union of their individual schedulability. Motivated by this, we propose a composition theory for schedulability tests with two new methods. The first method composes task-level timing guarantees derived from different schedulability tests, and the second one derives system-level schedulability results from a single schedulability test. The unified composition theory with these two methods then utilizes existing schedulability tests effectively so as to cover additional schedulable task sets. The proposed composition theory is shown to be applicable to most existing preemptive/non-preemptive scheduling algorithms. We also present three case-studies, demonstrating how and by how much the theory can improve schedulability by composing existing schedulability tests. Our evaluation results also show that the composition theory makes it possible to cover up to 181.7 percent additional schedulable task sets for preemptive fpEDF, preemptive EDF and non-preemptive EDF scheduling algorithms beyond their existing tests.
Jinkyu Lee 0001, Kang G. Shin, Insik Shin, Arvind Easwaran
IEEE Trans. Computers2
2015 Low-Overhead Control Channels in Wireless Networks
abstract
Low-latency, low-overhead and reliable control channels are essential to the efficient operation of wireless networks. However, control channels that utilize current in-band and out-of-band designs do not fully meet this requirement. In this paper, we design and implement Aileron, a novel control channel based on automatic modulation recognition that carries control frames over an OFDM(A) PHY by varying the modulation rate of the OFDM subcarriers. With Aileron, the control information is embedded into the modulation type, not as the actual symbol value. The thus-transmitted information can be received with little to no frame synchronization. We have evaluated Aileron using both extensive simulations and real-world measurements, and discovered that control frames can be transmitted with more than 80 percent accuracy using only 10 OFDM blocks on a channel with SNR of merely 10 dB. In order to demonstrate its applicability and efficiency in realistic networking scenarios, we also show how Aileron can be used in conjunction with a fine-grained channel access protocol to increase throughput under heterogeneous link conditions.
Eugene Chai, Kang G. Shin
IEEE Trans. Mob. Comput.2
2015 Thwarting Intelligent Malicious Behaviors in Cooperative Spectrum Sensing
abstract
Sensing falsification is a key security threat in cooperative spectrum sensing in cognitive radio networks. Intelligent malicious users (IMUs) adjust their malicious behaviors according to their objectives and the network's defense schemes. Without long-term collection of information on users' reputation, the existing schemes fail to thwart such malicious behaviors. In this paper, we construct a joint spectrum sensing and access framework to thwart the malicious behaviors of both rational and irrational IMUs. Lack of reputation information makes the malicious behavior resistance degrade performance since the honest users may be misjudged as IMUs. Based on the moral hazard principal-agent model, we design an incentive compatible mechanism to provide a moderate punishment to IMUs. Our findings show that neither spectrum sensing nor spectrum access alone can prevent malicious behaviors without any information on users' reputation. According to the different properties of malicious behavior resistance by spectrum sensing and spectrum access, we employ joint spectrum sensing and access to optimally prevent the IMUs sensing falsification. The proposed malicious behavior resistance mechanism is shown to achieve almost the same performance as the ideal case with truthful sensing.
Wei Wang 0021, Lin Chen 0002, Kang G. Shin, Lingjie Duan
IEEE Trans. Mob. Comput.3
2015 Cooperation without Synchronization: Practical Cooperative Relaying for Wireless Networks
abstract
Cooperative relay aims to realize the capacity of multi-antenna arrays in a distributed manner. However, the symbol-level synchronization requirement among distributed relays limits its use in practice. We propose to circumvent this barrier with a cross-layer protocol called Distributed Asynchronous Cooperation (DAC). With DAC, multiple relays can schedule concurrent transmissions with packet-level (hence coarse) synchronization. The receiver then extracts multiple versions of each relayed packet via a collision-resolution algorithm, thus realizing the diversity gain of cooperative communication. We demonstrate the feasibility of DAC by prototyping and testing it on the GNURadio/USRP software radio platform. To explore its relevance at the network level, we introduce a DAC-based medium access control (MAC) protocol, and a generic approach to integration of the DAC MAC/PHY layer into a typical routing algorithm. Considering the use of DAC for multiple network flows, we analyze the fundamental tradeoff between the improvement in diversity gain and the reduction in multiplexing opportunities. DAC is shown to improve the throughput and delay performance of lossy networks with intermediate link quality. Our analytical results have also been confirmed via network-level simulation with ns-2.
Xinyu Zhang 0003, Kang G. Shin
IEEE Trans. Mob. Comput.2
2014 Location Privacy Protection for Smartphone Users
abstract
As smartphones are increasingly used to run apps that provide users with location-based services, the users' location privacy has become a major concern. Existing solutions to this concern are deficient in terms of practicality, efficiency, and effectiveness. To address this problem, we design, implement, and evaluate LP-Guardian, a novel and comprehensive framework for location privacy protection for Android smartphone users. LP-Guardian's overcomes the shortcomings of existing approaches by addressing the tracking, profiling, and identification threats while maintaining app functionality. We have implemented and evaluated LP-Guardian's on Android 4.3.1. Our evaluation results show that LP-Guardian's effectively thwarts the privacy threats, without deteriorating the user's experience (less than 10% overhead in delay and energy). Also, LP-Guardian's privacy protection is shown to be achieved at a tolerable loss in app functionality.
Kassem Fawaz, Kang G. Shin
CCS2
2014 POSTER: Positioning Attack on Proximity-Based People Discovery
abstract
Over the past few years, Proximity-based People Discovery (PBPD) services, typically known as Nearby Friends,have been increasingly popular among geosocial apps. Unlike many unsuccessful predecessors which directly pinpoint users' exact locations on the map, PBPD services provide coarse-grained (discretized) proximity information, such as "Jennifer is within 2 miles," striking a useful balance between privacy and functionality. Considering PBPD's business potential, many companies including Facebook have been trying to promote this feature and instill the perception in mobile users that coarse-grained proximity information is innocuous to share. Here, we propose a novel positioning attack which can locate end-users of PBPD services with high precision using only coarse-grained (discretized) proximity information. This attack requires neither specialized hardware nor server-side collusion and can be easily automated. Based on this attack, we design and implement Geosocial Positioning System (GsPS) and show that GsPS can effectively locate users with high precision (10m) in a matter of a few minutes under real-world settings, and is capable of performing effective city-scale scanning and long-term profiling at low costs. The public and the social network industry should therefore be aware of the potential risk introduced by this attack and consider use of PBPD services with caution.
Huan Feng, Kang G. Shin
CCS2
2014 Vulnerability and Protection of Channel State Information in Multiuser MIMO Networks
abstract
Multiple-In-Multiple-Out (MIMO) offers great potential for increasing network capacity by exploiting spatial diversity with multiple antennas. Multiuser MIMO (MU-MIMO) further enables Access Points (APs) with multiple antennas to transmit multiple data streams concurrently to several clients. In MU-MIMO, clients need to estimate Channel State Information (CSI) and report it to APs in order to eliminate interference between them. We explore the vulnerability in clients' plaintext feedback of estimated CSI to the APs and propose two advanced attacks that malicious clients can mount by reporting forged CSI: (1) sniffing attack that enables concurrently transmitting malicious clients to eavesdrop other ongoing transmissions; (2) power attack that enables malicious clients to enhance their own capacity at the expense of others?. We have implemented and evaluated these two attacks in a WARP testbed. Based on our experimental results, we suggest a revision of the current CSI feedback scheme and propose a novel CSI feedback system, called the CSIsec, to prevent CSI forging without requiring any modification at the client side, thus facilitating its deployment.
Yu-Chih Tung, Sihui Han, Dongyao Chen, Kang G. Shin
CCS4
2014 Secure cooperative spectrum sensing and access against intelligent malicious behaviors
abstract
Sensing falsification is a key security problem in cooperative spectrum sensing for cognitive radio networks. Most previous approaches assume that malicious users only cheat in their sensing reports following a predefined rule. However, some malicious users usually act intelligently to strategically adjust their malicious behavior according to their objectives and the network's defense schemes. The existing schemes cannot resist the malicious behaviors of intelligent malicious users (IMUs) without long-term collection of information on their reputation. In this paper, we construct a moral hazard principal-agent framework and design an incentive compatible mechanism to thwart the malicious behaviors of rational and irrational IMUs. We find that neither spectrum sensing nor spectrum access alone can prevent the malicious behavior without any information on users' reputation. According to the analysis of malicious behavior resistance methods, we propose a joint spectrum sensing and access mechanism to optimally prevent the IMUs from sensing falsification. Our evaluation results show that the proposed mechanism achieves almost the same performance as the ideal case with perfect sensing.
Wei Wang 0021, Lin Chen 0002, Kang G. Shin, Lingjie Duan
INFOCOM3
2014 Reliable video multicast over Wi-Fi networks with coordinated multiple APs
abstract
Forward Error Correction (FEC) can be exploited to realize reliable video multicast over Wi-Fi with high video quality. We propose reliable video multicast over Wi-Fi networks with coordinated multiple Access Points (APs) to enhance video quality. By coordinating multiple APs, each AP can transmit entirely or partially different FEC-encoded packets so that a multicast receiver can benefit from both spatial and time diversities. The proposed schemes can enlarge the satisfactory video multicast region by exploiting the AP diversity, thus serving more multicast receivers located at cell edge with satisfactory video quality. We propose a resource-allocation algorithm for FEC-code rate adaptation, utilizing the limited wireless resource more efficiently while enhancing video quality. We also introduce the method for estimating the video packet delivery ratio after FEC decoding. The effectiveness of the proposed schemes is comparatively evaluated via extensive simulation and experimentation. The proposed schemes are observed to enhance the ratio of satisfied users by up to 37.1% compared to the conventional single AP multicast scheme.
Munhwan Choi, Jonghoe Koo, Sunghyun Choi 0001, Kang G. Shin
INFOCOM5
2014 Rendezvous for heterogeneous spectrum-agile devices
abstract
Cognitive radio (CR) is intended to meet the exponentially growing demand for spectrum by allowing for opportunistic utilization of idle legacy channels. Rendezvous, where two radios complete handshaking in an idle channel, is a key step for “stranger” (unknown to each other) CRs to start communication. However, none of existing algorithms guarantee rendezvous for heterogeneous or stranger CRs with different spectrum-sensing capabilities, in spite of the fact that (i) a wide variety of mobile devices are equipped with heterogeneous radios and (ii) there are numerous applications requiring efficient rendezvous for heterogeneous radios/CRs. In this paper, we propose a new channel hopping algorithm, called Heterogeneous Hopping (HH), that guarantees rendezvous without assuming existence of a universal channel set that can be sensed by all radios. HH is realized with a two-layer design that harmonizes the fixed-short-cycle and parity-alignment techniques we propose here, in order to guide CRs to rendezvous in two complementary situations resulting from the different capabilities of mobile wireless devices. To best of our knowledge, HH is the first channel-hopping scheme that guarantees rendezvous between heterogeneous radios. Our in-depth evaluation has shown HH to be significantly faster than simple extensions of existing schemes. Moreover, the latter cannot guarantee successful rendezvous, either.
Shan-Hung Wu, Ching-Chan Wu, Wing-Kai Hon, Kang G. Shin
INFOCOM4
2014 Measurement-based transmission schemes for network MIMO
abstract
The scaling of network MIMO (netMIMO) comes with the challenges of interference that arise from the aging of the Channel State Information (CSI). Particularly, in scenarios of high channel mobility---where netMIMO is expected to be used---the performance degradation from interference can be severe. In this paper, we design transmission schemes to address the two sources of CSI aging: delay in acquiring CSI feedback, and transmission period over which CSI remains unchanged. We introduce a two-phase training and feedback protocol that balances CSI aging across users by allowing users with high interference to have a shorter feedback delay. We also introduce an adaptive adjustment to the transmission length to reduce the decoding errors caused from interference. The proposed protocols adapt to the measurements collected from the users and hence applicable to various mobility scenarios. Our evaluation in a real and synchronized netMIMO setup shows significant gains (5--10dB) in user performance, especially in mobile channels.
Krishna C. Garikipati, Kang G. Shin
MobiHoc2
2014 Differentially private spectrum auction with approximate revenue maximization
abstract
Dynamic spectrum redistribution---under which spectrum owners lease out under-utilized spectrum to users for financial gain---is an effective way to improve spectrum utilization. Auction is a natural way to incentivize spectrum owners to share their idle resources. In recent years, a number of strategy-proof auction mechanisms have been proposed to stimulate bidders to truthfully reveal their valuations. However, it has been shown that truthfulness is not a necessary condition for revenue maximization. Furthermore, in most existing spectrum auction mechanisms, bidders may infer the valuations---which are private information---of the other bidders from the auction outcome. In this paper, we propose a Differentially privatE spectrum auction mechanism with Approximate Revenue maximization (DEAR). We theoretically prove that DEAR achieves approximate truthfulness, privacy preservation, and approximate revenue maximization. Our extensive evaluations show that DEAR achieves good performance in terms of both revenue and privacy preservation.
Ruihao Zhu, Zhijing Li 0001, Fan Wu 0006, Kang G. Shin, Guihai Chen
MobiHoc4
2014 MU-MIMO downlink scheduling based on users' correlation and fairness
abstract
A scheduling algorithm based on weighted users' correlation and fairness (WUCFS) is proposed for MU-MIMO downlink broadcast channels (BC), to address the problem that traditional fairness scheduling algorithms cannot handle, i.e., they cannot accurately compute the achievable rate for each user in their iterative user selection process, thus creating an undesirable tradeoff between user fairness and system sum-rate. The proposed WUCFS is used to activate mobile subscribers by evaluating the correlation between the candidate and the selected users as well as those who may be scheduled for data transmission. Weighted inverse-correlation maximization is then employed to determine which users to be scheduled for data transmission. By estimating potential co-channel interference (CCI) a priori, our algorithm can accurately estimate the actual transmission rate of each mobile user, and fairly activate a set of users with small mutual interference. Compared to existing schemes, the proposed algorithm is shown to improve fairness among users while ensuring high system sum-rate.
Zhao Li 0006, Kang G. Shin
PIMRC3
2014 Real-Time Discharge/Charge Rate Management for Hybrid Energy Storage in Electric Vehicles
abstract
Electric vehicles (EVs) are equipped with a large number of expensive battery cells, necessitating an effective battery management system (BMS) which protects the battery cells from harsh conditions while providing the required power efficiently. The discharge/charge rate affects battery health significantly, and existing BMSes employ simple discharge/charge rate scheduling so as to prevent weak cells from excessive discharge/charge. In this paper, we design and evaluate the real-time management of battery discharge/charge rate to extend battery life for EVs based on the physical dynamics and operation history of batteries. We first explore a modern energy storage system for EVs to capture physical dynamics and their impact on the battery discharge/charge rate, for example, a regenerative braking system for reusing the dissipated energy leads to current surges into the batteries, which shortens battery life. Based on understanding of the effects of discharge/charge rate in an energy storage system, we devise control knobs for manipulating the rate. Then, we design an adaptive discharge/charge rate management algorithm that determines the control knobs with a reconfigurable energy storage architecture. Our in-depth evaluation results demonstrate that the proposed discharge/charge rate management improves battery life up to 37.7% at little additional cost over the existing energy storage systems.
Kang G. Shin, Jinkyu Lee 0001
RTSS2
2014 Rapid Prototyping and Evaluation of Intelligence Functions of Active Storage Devices
abstract
Active storage devices further improve their performance by executing “intelligence functions,” such as prefetching and data deduplication, in addition to handling the usual I/O requests they receive. Significant research has been carried out to develop effective intelligence functions for the active storage devices. However, laborious and time-consuming efforts are usually required to set up a suitable experimental platform to evaluate each new intelligence function. Moreover, it is difficult to make such prototypes available to other researchers and users to gain valuable experience and feedback. To overcome these difficulties, we propose$\tt {IOLab}$, a virtual machine (VM)-based platform for evaluating intelligence functions of active storage devices. The VM-based structure of$\tt {IOLab}$enables the evaluation of new (and existing) intelligence functions for different types of OSes and active storage devices with little additional effort.$\tt {IOLab}$also supports real-time execution of intelligence functions, providing users opportunities to experience latest intelligence functions without waiting for their deployment in commercial products. Using a set of interesting case studies, we demonstrate the utility of$\tt {IOLab}$with negligible performance overhead except for the VM’s virtualization overhead.
Yongsoo Joo, Junhee Ryu, Sangsoo Park, Heonshik Shin, Kang G. Shin
IEEE Trans. Computers5
2014 Preempt a Job or Not in EDF Scheduling of Uniprocessor Systems
abstract
The earliest-deadline-first (EDF) policy has been widely studied for the scheduling of real-time jobs for its effectiveness and simplicity. However, since each preemption incurs an additional delay to the execution of jobs, the effectiveness of EDF is affected greatly by the underlying preemption policy that determines if and when a higher-priority job is allowed to preempt a currently executing lower-priority job. To address this problem, we propose a new and better (in meeting job deadlines) preemption policy of EDF, given a non-zero preemption delay. Specifically, we propose a controlled preemption (CP) policy that controls the condition of preempting jobs, whereas existing approaches focus on that of preempted jobs. We define cp-EDF in which the CP policy is applied to EDF, and analyze its schedulability. This schedulability analysis is then utilized to develop an algorithm that assigns the optimal control parameters of cp-EDF. Our in-depth evaluation has demonstrated that cp-EDF with the optimal parameter assignment improves EDF schedulability over existing preemption policies by up to 7.4%.
Jinkyu Lee 0001, Kang G. Shin
IEEE Trans. Computers2
2014 Fast Spectrum Shaping for Next-Generation Wireless Networks
abstract
Spectrum management and device coordination for dynamic spectrum access (DSA) networks have received significant research attention. However, current wireless devices have yet to fully embrace DSA networks due to the difficulties in realizing spectrum-agile communications. We address the practical hurdles and present solutions toward implementing DSA devices, answering an important question “what is a simple practical extension to current wireless devices that makes them spectrum-agile?” To this end, we propose RODIN, a general per-frame spectrum-shaping protocol that has the following features to support DSA in commercial off-the-shelf (COTS) wireless devices: direct manipulation of passband signals from COTS devices, fast FPGA-based spectrum shaping, and a novel preamble design for spectrum agreement. RODIN uses an FPGA-based spectrum shaper together with a preamble I-FOP to achieve per-frame spectrum shaping with a delay of under 10 μs.
Eugene Chai, Kang G. Shin, Jeongkeun Lee, Sung-Ju Lee 0001, Raúl H. Etkin
IEEE Trans. Mob. Comput.2
2014 Improvement of Real-Time Multi-CoreSchedulability with Forced Non-Preemption
abstract
While tasks may be preemptive or non-preemptive (due to their transactional operations), deadline guarantees in multi-core systems have been made only for those task sets in each of which all tasks are preemptive or non-preemptive, not a mixture thereof,i.e., fully preemptive or fully non-preemptive. In this paper, we first develop a schedulability analysis framework that guarantees the timing requirements of a given task set in which a task can be either preemptive or non-preemptive in multi-core systems. We then apply this framework to the prioritization polices of EDF (earliest deadline first) and FP (fixed priority), yielding schedulability tests of mpn-EDF (Mixed Preemptive/Non-preemptive EDF) and mpn-FP, which are generalizations of corresponding fully-preemptive and non-preemptive algorithms, i.e., fp-EDF and np-EDF, and fp-FP and np-FP. In addition to their timing guarantees for any task set that consists of a mixture of preemptive and non-preemptive tasks, the tests outperform the existing schedulability tests of np-EDF andnp-FP (i.e., special cases of mpn-EDF and mpn-FP). Using these tests, we also improve schedulability by developing an algorithm that optimally disallows preemption of a preemptive task under a certain assumption. We demonstrate via simulation that the algorithm finds up to 47.6 percent additional task sets that are schedulable with mpn-FP (likewise mpn-EDF), but not with fp-FP and np-FP (likewisefp-EDF and np-EDF).
Jinkyu Lee 0001, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.2
2014 Reducing Peak Power Consumption inMulti-Core Systems without ViolatingReal-Time Constraints
abstract
The potential of multi-core chips for high performance and reliability at low cost has made them ideal computing platforms for embedded real-time systems. As a result, power management of a multi-core chip has become an important issue in the design of embedded real-time systems. Most existing approaches have been designed to regulate the behavior of average power consumption, such as minimizing the total energy consumption or the chip temperature. However, little attention has been paid to the worst-case behavior of instantaneous power consumption on a chip, called chip-level peak power consumption, an important design parameter that determines the cost and/or size of chip design/packaging and the underlying power supply. We address this problem by reducing the chip-level peak power consumption at design time without violating any real-time constraints. We achieve this by carefully scheduling real-time tasks, without relying on any additional hardware implementation for power management, such as dynamic voltage and frequency scaling. Specifically, we propose a new scheduling algorithm FPΘthat restricts the concurrent execution of tasks assigned on different cores, and perform its schedulability analysis. Using this analysis, we develop a method that finds a set of concurrent executable tasks, such that the design-time chip-level peak power consumption is minimized and all timing requirements are met. We demonstrate via simulation that the proposed method not only keeps the design-time chip-level peak power consumption as low as the theoretical lower bound for trivial cases, but also reduces the peak power consumption for non-trivial cases by up to 12.9 percent compared to the case of no restriction on concurrent task execution.
Jinkyu Lee 0001, Buyoung Yun, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.3
2013 DUET: integration of dynamic and static analyses for malware clustering with cluster ensembles
abstract
Automatic malware clustering plays a vital role in combating the rapidly growing number of malware variants. Most existing malware clustering algorithms operate on either static instruction features or dynamic behavior features to partition malware into families. However, these two distinct approaches have their own strengths and weaknesses in handling different types of malware. Moreover, different clustering algorithms and even multiple runs of the same algorithms may produce inconsistent or even contradictory results. To remedy this heterogeneity and lack of robustness of a single clustering algorithm, we propose a novel system called DUET by exploiting the complementary nature of static and dynamic clustering algorithms and optimally integrating their results. By using the concept of clustering ensemble, DUET combines partitions from individual clustering algorithms into a single consensus partition with better quality and robustness. DUET improves existing ensemble algorithms by incorporating cluster-quality measures to effectively reconcile differences and/or contradictions between base malware clusterings. Using real-world malware samples, we compare the performance of DUET (in terms of clustering precision, recall and coverage) with individual state-of-the-art static and dynamic clustering component. The comprehensive experiments demonstrate DUET's capability of improving the coverage of malware samples by 20--40% while keeping the precision near the optimum achievable by any individual clustering algorithm.
Xin Hu 0001, Kang G. Shin
ACSAC2
2013 On fault resilience of OpenStack
abstract
Cloud-management stacks have become an increasingly important element in cloud computing, serving as the resource manager of cloud platforms. While the functionality of this emerging layer has been constantly expanding, its fault resilience remains under-studied. This paper presents a systematic study of the fault resilience of OpenStack---a popular open source cloud-management stack. We have built a prototype fault-injection framework targeting service communications during the processing of external requests, both among OpenStack services and between OpenStack and external services, and have thus far uncovered 23 bugs in two versions of OpenStack. Our findings shed light on defects in the design and implementation of state-of-the-art cloud-management stacks from a fault-resilience perspective.
Xiaoen Ju, Livio B. Soares, Kang G. Shin, Kyung Dong Ryu, Dilma Da Silva
SoCC3
2013 CogWnet: A Resource Management Architecture for Cognitive Wireless Networks
abstract
With the increasing adoption of wireless communication technologies, there is a need to improve management of existing radio resources. Cognitive radio is a promising technology to improve the utilization of wireless spectrum. Its operating principle is based on building an integrated hardware and software architecture that configures the radio to meet application requirements within the constraints of spectrum policy regulations. However, such an architecture must be able to cope with radio environment heterogeneity. In this paper, we propose a cognitive resource management architecture, called CogWnet, that allocates channels, re-configures radio transmission parameters to meet QoS requirements, ensures reliability, and mitigates interference. The architecture consists of three main layers: Communication Layer, which includes generic interfaces to facilitate the communication between the cognitive architecture and TCP/IP stack layers; Decision-Making Layer, which classifies the stack layers input parameters and runs decision-making optimization algorithms to output optimal transmission parameters; and Policy Layer to enforce policy regulations on the selected part of the spectrum. The efficiency of CogWnet is demonstrated through a testbed implementation and evaluation.
Ismail AlQerm, Basem Shihada, Kang G. Shin
ICCCN3
2013 Defeating heterogeneity in wireless multicast networks
abstract
The growing demand for real-time streaming video on portable devices has increased the importance of multimedia multicast in mobile wireless networks. A defining characteristic of such multicast networks is its heterogeneity in both the channel states and the MIMO capabilities of its clients. However, current wireless multicast schemes adapt poorly to such heterogeneity. We introduce Procrustes, a multimedia multicast scheme that is built upon a novel PHY-layer rateless code. Unlike bit-level rateless codes (such as Raptor [14] codes), Procrustes clients automatically adjust the PSNR of the received multicast video stream to match both the instantaneous channel state and the number of active receive antennas. We demonstrate the performance of Procrustes in a simulated environment.
Eugene Chai, Kang G. Shin, Sung-Ju Lee 0001, Jeongkeun Lee, Raúl H. Etkin
INFOCOM2
2013 Gap Sense: Lightweight coordination of heterogeneous wireless devices
abstract
Coordination of co-located wireless devices is a fundamental function/requirement for reducing interference. However, different devices cannot directly coordinate with one another as they often use incompatible modulation schemes. Even for the same type (e.g., WiFi) of devices, their coordination is infeasible when neighboring transmitters adopt different spectrum widths. Such an incompatibility between heterogeneous devices may severely degrade the network performance. In this paper, we introduce Gap Sense (GSense), a novel mechanism that can coordinate heterogeneous devices without modifying their PHYlayer modulation schemes or spectrum widths. GSense prepends legacy packets with a customized preamble, which piggy-backs information to enhance inter-device coordination. The preamble leverages the quiet period between signal pulses to convey such information, and can be detected by neighboring nodes even when they have incompatible PHY layers. We have implemented and evaluated GSense on a software radio platform, demonstrating its significance and utility in three popular protocols. GSense is shown to deliver coordination information with close to 100% accuracy within practical SNR regions. It can also reduce the energy consumption by around 44%, and the collision rate by more than 88% in networks of heterogeneous transmitters and receivers.
Xinyu Zhang 0003, Kang G. Shin
INFOCOM2
2013 NEMOx: scalable network MIMO for wireless networks
abstract
Network MIMO (netMIMO) has potential for significantly enhancing the capacity of wireless networks with tight coordination of access points (APs) to serve multiple users concurrently. Existing schemes realize netMIMO by integrating distributed APs into one ``giant'' MIMO but do not scale well owing to their global synchronization requirement and overhead in sharing data between APs. To remedy this limitation, we propose a novel system, NEMOx, that realizes netMIMO downlink transmission for large-scale wireless networks. NEMOx organizes a network into practical-size clusters, each containing multiple distributed APs (dAPs) that opportunistically synchronize with each other for netMIMO downlink transmission. Inter-cluster interference is managed with a decentralized channel-access algorithm, which is designed to balance between the dAPs' cooperation gain and spatial reuse---a unique tradeoff in netMIMO. Within each cluster, NEMOx optimizes the power budgeting among dAPs and the set of users to serve, ensuring fairness and effective cancellation of cross-talk interference. We have implemented and evaluated a prototype of NEMOx in a software radio testbed, demonstrating its throughput scalability and multiple folds of performance gain over current wireless LAN architecture and alternative netMIMO schemes.
Xinyu Zhang 0003, Karthikeyan Sundaresan, Mohammad Ali Amir Khojastepour, Sampath Rangarajan, Kang G. Shin
MobiCom5
2013 Predicting thermal behavior for temperature management in time-critical multicore systems
abstract
Multi-core System-on-Chip (SoC) has become a popular execution platform for many embedded real-time systems that require high performance and low power-consumption. High temperature is known to accelerate the failure of deep submicron chips. To prevent such accelerated failures due to chip overheating, various thermal-aware scheduling (TAS) algorithms and dynamic thermal management (DTM) have been proposed and applied to mission/safety-critical applications. To control on-chip temperature more effectively, it is necessary to predict the thermal dynamics of a multi-core chip in real time and trigger appropriate power/temperature management before overheating the chip. However, due to dynamically-changing runtime environments, it is very difficult to estimate the chip temperature on-the-fly. In this paper, we propose models of efficiently estimating multi-core chip temperature while accounting for the system dynamics in real time. Based on these models, we design a proactive peak temperature manager (PTM) which periodically estimates future core temperature and triggers proper DTMs on the estimated-to-be-overheated cores for their cooling without violating applications timing constraints. Our in-depth evaluation based on the HotSpot thermal simulator has shown that the proposed method can predict the occurrence of peak temperature in a core with 90-98% accuracy, and using the estimated thermal model of a multi-core chip, PTM can effectively keep core temperature below a given threshold without violating any timing constraint.
Buyoung Yun, Kang G. Shin, Shige Wang
IEEE Real-Time and Embedded Technology and Applications Symposium2
2013 Design and Management of Satellite Power Systems
abstract
Satellites are indispensable for broadcast, weather forecast, navigation, and many other applications, but their design entails a number of stringent requirements, such as limited space and weight, impossible/costly online repairs, severe radiation, and a wide range of temperature they have to withstand. These requirements can only be met by an effective, robust co-design of physical and computing (control) parts of each satellite, making them prototypical cyber-physical systems (CPSes). Of the various CPS issues related to satellites, this paper focuses on offline design and online management of satellite power systems. Specifically, we analyze and model unique characteristics of power supply and demand of a satellite, which are dictated by the periodicity of power generation from solar panels and the nonlinear behavior of rechargeable battery cells. Based on the understanding of these characteristics, we first propose how to find the best configuration (e.g., the number, the arrangement, and the type) of solar panels and battery cells at design time, such that all tasks can be executed without power shortage throughout the satellite's mission lifetime. Second, we propose how to manage power online so as to execute the highest QoS versions of tasks (thus yielding the most power-effective performance) without compromising the power-sufficiency guarantee under a given configuration. As a case study, we study cubic-shaped nanosatellites, which have been launched multiple times since 2004. We borrow their architecture, configuration and parameters, and demonstrate the effectiveness of our design and management of satellite power systems.
Jinkyu Lee 0001, Kang G. Shin
RTSS3
2013 Schedulability Analysis for a Mode Transition in Real-Time Multi-core Systems
abstract
To enable real-time systems to adapt to dynamically changing environments, update functionalities and/or accommodate those tasks migrated from other failed sub-systems, there have been a number of studies on making timing guarantees while accounting for change of parameters and addition/deletion of tasks. While most of them have dealt with "transition" protocols that delay next task releases or discard the unfinished tasks released before the transition, such protocols are not suitable for many control systems in which missing/delaying control updates (by completing periodic tasks) even during a transition or mode-change may cause system instability or incur a significant incremental operational cost. In this paper, we focus on a transition protocol that does not miss/delay control updates during a system transition, and develop a new schedulability analysis for the transition in a real-time multi-core system, which provides sufficient timing guarantees without requiring any online information, such as the release and execution patterns of tasks and the start time of a transition. To achieve this, we extend an existing popular schedulability analysis framework for nontransitional tasks, and identify the scenarios that maximize the duration of a task's interference to another task in the case of a transition. Since the analysis works for any arbitrary transition order of tasks, we can improve the schedulability performance by enforcing a specific order. We formulate the problem of assigning an optimal transition order, and develop a solution by deriving some properties of optimality. Our evaluation results demonstrate that the proposed solution finds more schedulable task sets, which are not covered by naive approaches.
Jinkyu Lee 0001, Kang G. Shin
RTSS2
2013 Distributed association control in shared wireless networks
abstract
In modern wireless networks, fairness of user throughputs is often important to efficiently utilize the available network bandwidth. Association control-control of user associations to reduce overloading of access points (APs)-has been the standard approach to address this problem. However, in the recent paradigm of shared wireless networks in both, community and commercial space, access points are increasingly managed without any central coordination. As a result, achieving user level fairness in these settings remains a challenging task. In this paper, we consider the global utility of proportional fairness. Specifically, we propose a distributed approach to association control, in which each user makes association decisions based on the information gathered from probe responses from its nearby APs. Two solutions are presented: (i) a randomized approach, in which users update their associations probabilistically, and (ii) a deterministic association rule that converges quickly. We provide theoretical guarantees on the performance of both approaches. Our simulation results show that the proposed solutions can significantly improve fairness and overall throughput compared to other association heuristics.
Krishna C. Garikipati, Kang G. Shin
SECON2
2013 MutantX-S: Scalable Malware Clustering Based on Static Features
Xin Hu 0001, Kang G. Shin, Sandeep Bhatkar, Kent Griffin
USENIX ATC2
2013 An Enhanced Spectrum Resource Allocation Algorithm for Femtocells
abstract
Efficient spectrum resource allocation in wireless networks is important for improving the system throughput and guaranteeing the user-percieved Quality-of-Service (QoS). In this paper, we propose an enhanced algorithm for spectrum resource allocation in femtocells. First, the bandwidth of each user is determined by the user's demand and the channel state. Second, graph theory is enhanced and used to improve spectrum efficiency. Our simulation results show that the proposed algorithm improves the system throughput significantly and also guarantees the fairness toward the users.
Linjing Zhao, Guangrui Huo, Kang G. Shin
VTC Fall3
2013 Enhanced cognitive Radio Resource Management for LTE systems
abstract
The explosive growth in mobile Internet and related services has increased the need for more bandwidth in cellular networks. The Long-Term Evolution (LTE) technology is an attractive solution for operators and subscribers to meet such need since it provides high data rates and scalable bandwidth. Radio Resource Management (RRM) is essential for LTE to provide better communication quality and meet the application QoS requirements. Cognitive resource management is a promising solution for LTE RRM as it improves network efficiency by exploiting radio environment information, intelligent optimization algorithms to configure transmission parameters, and mitigate interference. In this paper, we propose a cognitive resource management scheme to adapt LTE network parameters to the environment conditions. The scheme optimizes resource blocks assignment, modulation selection and bandwidth selection to maximize throughput and minimize interference. The scheme uses constrained optimization for throughput maximization and interference control. It is also enhanced by learning mechanism to reduce the optimization complexity and improve the decision-making quality. Our evaluation results show that our scheme achieved significant improvements in throughput and LTE system capacity. Results also show the improvement in the user satisfaction over other techniques in LTE RRM.
Ismail AlQerm, Basem Shihada, Kang G. Shin
WiMob3
2013 Ergodic Sum Capacity of Spectrum-Sharing Multiple Access with Collision Metric
abstract
This paper investigates the ergodic sum capacity of a spectrum-shared Multiple Access Channel (MAC). We assume that the secondary service (SS) only knows the channel distribution information (CDI) between its transmitters and the primary receivers. Availability of CDI results in collision incidences at the primary receivers because of conflicting levels of intolerable interference. We introduce the concept of collision probability constraint to manage the unexpected QoS degradation of primary service in the secondary resource allocation (RA). This RA problem is inherently difficult to solve and its objective function is not necessarily convex. Two well-known approaches, called Iterative Approach (IA) and Analytical Approach (AA), each with several cases/categories, are then used to find solutions. IA solves the problem iteratively by reconstructing convex optimization problems from the original (non-convex) one in a number of iterative loops until the collision probability constraints are satisfied. IA is shown to converge quickly to a suitable solution. Furthermore, by using a control parameter, the system designer can make a tradeoff between the speed of convergence and the ergodic sum capacity. AA, on the other hand, solves the RA problem by suggesting tractable versions of collision probability constraints. Unlike IA, AA does not require extra signaling between transmitters and the base station to tune parameters, thus facilitating the implementation of SS. Our in-depth simulations have shown the proposed approach to yield lower spectral efficiency than IA.
Mohammad G. Khoshkholgh, Nader Mokari, Kang G. Shin
IEEE J. Sel. Areas Commun.3
2013 Hierarchical Market Competition in a Duopoly Super Wi-Fi Spectrum Market
abstract
Super Wi-Fi refers to Wi-Fi-like Internet access via spectrum white spaces (WS), which is expected to enhance today's Wi-Fi thanks to the superior propagation characteristics of the WS compared to ISM/UNII bands. A Super Wi-Fi wireless service provider (WSP) dynamically leases and opportunistically utilizes a licensed band while it is temporarily unoccupied by its (licensed) primary users (PUs). The PUs' spectrum usage pattern presents time-varying spectrum availability, thus necessitating eviction of in-service customers upon return of PUs where the evicted customers are compensated with partial reimbursement of their service charge. This paper investigates the dynamics of a duopoly Super Wi-Fi market where two co-located WSPs compete for leasing better quality channels and for setting competitive service price to entice more customers. The channel quality is measured by the PUs' utilization factor (smaller the better). Since higher quality channels possess more WS incurring larger channel leasing cost, a WSP should strike a balance between channel quality and service tariff in maximizing its profit. The market competition is modeled as hierarchical noncooperative price- and quality-games, and their Nash Equilibria (NE) are derived. In addition, we investigate the impact of differentiated reimbursement rates and limited channel availability. Finally, we demonstrate the tradeoffs among leasing cost, customer arrival rate, and channel characteristics via numerical analyses.
Hyoil Kim, Jaehyuk Choi 0002, Kang G. Shin
IEEE J. Sel. Areas Commun.3
2013 What Should Secondary Users Do Upon Incumbents' Return?
abstract
In a cognitive radio network (CRN), secondary users (SUs) opportunistically utilize idle licensed spectrum bands. We address the natural questions that arise when the incumbents or primary users (PUs) return to the channel the SUs are using opportunistically. Instead of immediately switching to another idle channel as proposed in almost all existing approaches, the SUs may opt to wait silently in their current channel until the PUs depart. This option would be beneficial to the SUs if the returned PUs stay at the channel only for a short period of time and the SUs' channel-switching incurs a non-negligible overhead. We determine how long the SUs should wait in their current channel before switching to a new idle channel. The SUs should also occasionally sense those (called em out-of-band) channels currently not in use for sensing the availability of spectrum opportunities. We propose an efficient, adaptive spectrum-sensing technique to detect when a busy out-of-band channel becomes idle. We also present a spectrum-management architecture that integrates the SUs' strategies and facilitates fast discovery of spectrum opportunities.
Caoxie Zhang, Kang G. Shin
IEEE J. Sel. Areas Commun.2
2013 Agent-based modeling of malware dynamics in heterogeneous environments
abstract
ABSTRACT The increasing convergence of power‐law networks such as social networking and peer‐to‐peer applications, web‐delivered applications, and mobile platforms makes today's users highly vulnerable to entirely new generations of malware that exploit vulnerabilities in web applications and mobile platforms for new infections, while using the power‐law connectivity for finding new victims. The traditional epidemic models based on assumptions of homogeneity, average‐degree distributions, and perfect‐mixing are inadequate to model this type of malware propagation. In this paper, we study four aspects crucial to modeling malware propagation:application‐level interactions among users of such networks,local network structure,user mobility, andnetwork coordination of malware such as botnets. Since closed‐form solutions of malware propagation considering these aspects are difficult to obtain, we describe an open‐source, flexible agent‐based emulation framework that can be used by malware researchers for studying today's complex malware. The framework, called Agent‐Based Malware Modeling (AMM), allows different applications, network structure, network coordination, and user mobility in either a geographic or a logical domain to study various infection and propagation scenarios. In addition to traditional worms and viruses, the framework also allows modeling network coordination of malware such as botnets. The majority of the parameters used in the framework can be derived from real‐life network traces collected from a network, and therefore, represent realistic malware propagation and infection scenarios. As representative examples, we examine two well‐known malware spreading mechanisms: (i) a malicious virus such as Cabir spreading among the subscribers of a cellular network using Bluetooth and (ii) a hybrid worm that exploit email and file‐sharing to infect users of a social network. In both cases, we identify the parameters most important to the spread of the epidemic based upon our extensive simulation results. Copyright © 2011 John Wiley & Sons, Ltd.
Abhijit Bose, Kang G. Shin
Secur. Commun. Networks2
2013 Optimal Online Sensing Sequence in Multichannel Cognitive Radio Networks
abstract
We address the problem of rapidly discovering spectrum opportunities for seamless service provisioning in cognitive radio networks (CRNs). In particular, we focus on multichannel communications via channel-bonding with heterogeneous channel characteristics of ON/OFF patterns, sensing time, and channel capacity. Using dynamic programming (DP), we derive an optimal online sensing sequence incurring a minimal opportunity-discovery delay, and propose a suboptimal sequence that presents a near-optimal performance while incurring significantly less computational overhead than the DP algorithm. To facilitate fast opportunity discovery, we also propose a channel-management strategy that maintains a list of backup channels to be used at building the optimal sequence. A hybrid of maximum likelihood (ML) and Bayesian inference is introduced as well for flexible estimation of ON/OFF channel-usage patterns, which selectively chooses the better between the two according to the frequency of sensing and ON/OFF durations. The performance of the proposed schemes, in terms of the opportunity-discovery delay, is evaluated via in-depth simulation, and for the scenarios we considered, the proposed suboptimal sequence achieves a near-optimal performance with only an average of 0.5 percent difference from the optimal delay, and outperforms the previously proposed probabilistic scheme by up to 50.1 percent. In addition, the backup channel update scheme outperforms the no-update case by up to 49.9 percent.
Hyoil Kim, Kang G. Shin
IEEE Trans. Mob. Comput.2
2013 Mobile Autonomous Router System for Dynamic (Re)formation of Wireless Relay Networks
abstract
Multihop wireless relays can extend the area of network connectivity instantly and efficiently. However, due to the spatial dependence of wireless link-quality, the deployment of relay nodes requires extensive, expensive measurement, and management efforts. This paper presents a mobile autonomous router system, (MARS) through which a relay router autonomously seeks and adjusts the best "receptionâ position for itself and cooperatively forms a string-type relay network with other neighboring routers. Specifically, MARS 1) accurately characterizes spatial link-quality through a new measurement technique, 2) effectively probes/optimizes node positioning via a spatial probing algorithm, and 3) maintains error-tolerant position information via an inexpensive positioning algorithm. MARS has been prototyped with both a commodity mobile robot and a wireless router with IEEE 802.11 cards. Our experimental evaluation of both the MARS prototype and ns-2-based simulation show that MARS achieves an average of 95 percent accuracy in link-quality measurements, and reduces the measurement effort necessary for the optimization of a node's location by two-thirds, compared to exhaustive spatial probing.
Kyu-Han Kim, Kang G. Shin, Dragos Niculescu
IEEE Trans. Mob. Comput.2
2013 Maximizing Transmission Opportunities in Wireless Multihop Networks
abstract
Being readily available in most of 802.11 radios, multirate capability appears to be useful as WiFi networks are getting more prevalent and crowded. More specifically, it would be helpful in high-density scenarios because internode distance is short enough to employ high data rates. However, communication at high data rates mandates a large number of hops for a given node pair in a multihop network and thus, can easily be depreciated as per-hop overhead at several layers of network protocol is aggregated over the increased number of hops. This paper presents a novel multihop, multirate adaptation mechanism, called multihop transmission opportunity (MTOP), that allows a frame to be forwarded a number of hops consecutively to minimize the MAC-layer overhead between hops. This seemingly collision-prone nonstop forwarding is proved to be safe via analysis and USRP/GNU Radio-based experiment in this paper. The idea of MTOP is in clear contrast to the conventional opportunistic transmission mechanism, known as TXOP, where a node transmits multiple frames back-to-back when it gets an opportunity in a single-hop WLAN. We conducted an extensive simulation study via OPNET, demonstrating the performance advantage of MTOP under a wide range of network scenarios.
Jeong-Yoon Lee, Chansu Yu, Kang G. Shin, Young-Joo Suh
IEEE Trans. Mob. Comput.3
2013 Joint Optimal Sensor Selection and Scheduling in Dynamic Spectrum Access Networks
abstract
Spectrum sensing is key to the realization of dynamic spectrum access. To protect primary users' communications from the interference caused by secondary users, spectrum sensing must meet the strict detectability requirements set by regulatory bodies, such as the FCC. Such strict detection requirements, however, can hardly be achieved using PHY-layer sensing techniques alone with one-time sensing by only a single sensor. In this paper, we jointly exploit two MAC-layer sensing methods-cooperative sensing and sensing scheduling- to improve spectrum sensing performance, while incurring minimum sensing overhead. While these sensing methods have been studied individually, little has been done on their combinations and the resulting benefits. Specifically, we propose to construct a profile of the primary signal's RSSs and design a simple, yet near-optimal, incumbent detection rule. Based on this constructed RSS profile, we develop an algorithm to find 1) an optimal set of sensors; 2) an optimal point at which to stop scheduling additional sensing; and 3) an optimal sensing duration for one-time sensing, so as to make a tradeoff between detection performance and sensing overhead. Our evaluation results show that the proposed sensing algorithms reduce the sensing overhead by up to 65 percent, while meeting the requirements of both false-alarm and misdetection probabilities of less than 0.01.
Alexander W. Min, Kang G. Shin
IEEE Trans. Mob. Comput.2
2013 Delay-Optimal Broadcast for Multihop Wireless Networks Using Self-Interference Cancellation
abstract
Conventional wireless broadcast protocols rely heavily on the 802.11-based CSMA/CA model, which avoids interference and collision by conservative scheduling of transmissions. While CSMA/CA is amenable to multiple concurrent unicasts, it tends to degrade broadcast performance significantly, especially in lossy and large-scale networks. In this paper, we propose a new protocol called Chorus that improves the efficiency and scalability of broadcast service with a MAC/PHY layer that allows packet collisions. Chorus is built upon the observation that packets carrying the same data can be effectively detected and decoded, even when they overlap with each other and have comparable signal strengths. It resolves collision using symbol-level interference cancellation, and then combines the resolved symbols to restore the packet. Such a collision-tolerant mechanism significantly improves the transmission diversity and spatial reuse in wireless broadcast. Chorus' MAC-layer cognitive sensing and scheduling scheme further facilitates the realization of such an advantage, resulting in an asymptotic broadcast delay that is proportional to the network radius. We evaluate Chorus' PHY-layer collision resolution mechanism with symbol-level simulation, and validate its network-level performance via ns-2, in comparison with a typical CSMA/CA-based broadcast protocol. Our evaluation validates Chorus's superior performance with respect to scalability, reliability, delay, etc., under a broad range of network scenarios (e.g., single/multiple broadcast sessions, static/mobile topologies).
Xinyu Zhang 0003, Kang G. Shin
IEEE Trans. Mob. Comput.2
2013 Cooperative Carrier Signaling: Harmonizing Coexisting WPAN and WLAN Devices
abstract
The unlicensed ISM spectrum is getting crowded by wireless local area network (WLAN) and wireless personal area network (WPAN) users and devices. Spectrum sharing within the same network of devices can be arbitrated by existing MAC protocols, but the coexistence between WPAN and WLAN (e.g., ZigBee and WiFi) remains a challenging problem. The traditional MAC protocols are ineffective in dealing with the disparate transmit-power levels, asynchronous time-slots, and incompatible PHY layers of such heterogeneous networks. Recent measurement studies have shown moderate-to-high WiFi traffic to severely impair the performance of coexisting ZigBee. We propose a novel mechanism, called cooperative carrier signaling (CCS), that exploits the inherent cooperation among ZigBee nodes to harmonize their coexistence with WiFi WLANs. CCS employs a separate ZigBee node to emit a carrier signal (busy tone) concurrently with the desired ZigBee's data transmission, thereby enhancing the ZigBee's visibility to WiFi. It employs an innovative way to concurrently schedule a busy tone and a data transmission without causing interference between them. We have implemented and evaluated CCS on the TinyOS/MICAz and GNURadio/USRP platforms. Our extensive experimental evaluation has shown that CCS reduces collision between ZigBee and WiFi by 50% for most cases, and by up to 90% in the presence of a high-level interference, all at negligible WiFi performance loss.
Xinyu Zhang 0003, Kang G. Shin
IEEE/ACM Trans. Netw.2
2013 Robust Tracking of Small-Scale Mobile Primary User in Cognitive Radio Networks
abstract
In cognitive radio networks (CRNs), secondary users must be able to accurately and reliably track the location of small-scale mobile primary users/devices (e.g., wireless microphones) in order to efficiently utilize spatial spectrum opportunities, while protecting primary communications. However, accurate tracking of the location of mobile primary users is difficult due mainly to the CR-unique constraint, i.e., localization must rely solely on reported sensing results (i.e., measured primary signal strengths), which can easily be compromised by malicious sensors (or attackers). To cope with this challenge, we propose a new framework, called Sequential mOnte carLo combIned with shadow-faDing estimation (SOLID), for accurate, attack/fault-tolerant tracking of small-scale mobile primary users. The key idea underlying SOLID is to exploit the temporal shadow fading correlation in sensing results induced by the primary user's mobility. Specifically, SOLID augments conventional Sequential Monte Carlo (SMC)-based target tracking with shadow-fading estimation. By examining the shadow-fading gain between the primary transmitter and CRs/sensors, SOLID 1) significantly improves the accuracy of primary tracking regardless of the presence/absence of attack, and 2) successfully masks the abnormal sensing reports due to sensor faults or attacks, preserving localization accuracy and improving spatial spectrum efficiency. Our extensive evaluation in realistic wireless fading environments shows that SOLID lowers localization error by up to 88 percent in the absence of attacks, and 89 percent in the presence of the challenging "slow-poisoning” attack, compared to the conventional SMC-based tracking.
Alexander W. Min, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.2
2013 Joint collision resolution and transmit-power adjustment for Aloha-type random access
abstract
ABSTRACT We consider uplink random access for which slotted Aloha has usually been employed with unknown channel conditions. Upon failure of a transmission attempt, a user cannot tell whether the failure was caused by collision with other simultaneously transmitting users or by his use of insufficient transmit power. If a transmission attempt failed due to collision which could have been resolved by retransmission, increasing transmit power would just waste power and, moreover, reduce the other users' chance of successful access. To handle this lack of information on the cause of failure, we propose a novel Cause‐of‐Failure resolution, where the transmit power is increased after a given number of consecutive unsuccessful access attempts when the probability that a given failure is caused by collision becomes sufficiently low. To exploit the thus‐obtained transmit power for the next random access attempt, we also determine the Cause‐of‐Success based on the number of consecutive successful attempts, i.e., whether to (probabilistically) decrease or maintain the current transmit power. This way, users can adjust their transmit power for random access, which we call Auto Power Fallback (APF), considered as an advanced version of the power ramping algorithm. We evaluate APF by modeling analysis and numerical computation based on the slotted Aloha, showing that APF determines a suitable transmit power for uplink random accesses while achieving good performance. Copyright © 2011 John Wiley & Sons, Ltd.
Young-June Choi, Kang G. Shin
Wirel. Commun. Mob. Comput.2
2012 Exploiting interference locality in coordinated multi-point transmission systems
abstract
Coordinated Multi-Point (CoMP) transmission is emerging as a concept that can substantially suppress interference, thus improving the capacity of multi-cell wireless networks. However, existing CoMP techniques either require sharing of data and channel state information (CSI) for all links in the network, or have limited capability of interference suppression. In this paper, we propose distributed interference alignment and cancellation (DIAC) to overcome these limitations. DIAC builds on a key intuition of interference locality — since each link is interfered with a limited number of neighboring links, it is sufficient to coordinate with those strong interferers and ignore others, in order to bound the overhead in CoMP. DIAC realizes the localized coordination by integrating interference cancellation and distributed interference alignment, and can be applied to both the uplink and downlink of multi-cell wireless networks. We validate DIAC using both model-driven and trace-based simulation where the traces are collected by implementing a MIMO-OFDM channel estimator on a software radio platform. Our experiments show that DIAC can substantially improve the degrees of freedom in multi-cell wireless networks.
Xinyu Zhang 0003, Mohammad Ali Amir Khojastepour, Karthikeyan Sundaresan, Sampath Rangarajan, Kang G. Shin
ICC5
2012 Open WiFi networks: Lethal weapons for botnets?
abstract
This paper assesses the potential for highly mobile botnets to communicate and perform nefarious actions using only open WiFi networks, which we term mobile WiFi botnets. We design and evaluate a proof-of-concept mobile WiFi botnet using real-world mobility traces and actual open WiFi network locations for the urban environment of San Francisco. Our extensive simulation results demonstrate that mobile WiFi botnets can support rapid command propagation, with commands typically reaching over 75% of the botnet only 2 hours after injection-sometimes, within as little as 30 minutes. Moreover, those bots able to receive commands usually have ≈40-50% probability of being able to do so within a minute of the command being issued. Our evaluation results also indicate that even a small mobile WiFi botnet of only 536 bots can launch an effective DDoS attack against poorly protected systems. Furthermore, mobile WiFi botnet traffic is sufficiently distributed across multiple open WiFi networks-with no single network being over-utilized at any given moment-to make detection difficult.
Matthew Knysz, Xin Hu 0001, Kang G. Shin
INFOCOM4
2012 Building efficient spectrum-agile devices for dummies
abstract
Spectrum management and device coordination for Dynamic Spectrum Access (DSA) networks have received significant research attention. However, current wireless devices have yet to fully embrace DSA networks due to the difficulties in realizing spectrum-agile communications. We address the practical hurdles and present solutions towards implementing DSA devices, answering an important question "what is a simple practical extension to current wireless devices that makes them spectrum-agile?" To this end, we propose RODIN, a general per-frame spectrum-shaping protocol that has the following features to support DSA in commercial off-the-shelf (COTS) wireless devices: (a) direct manipulation of passband signals from COTS devices, (b) fast FPGA-based spectrum shaping, and (c) a novel preamble design for spectrum agreement. RODIN uses an FPGA-based spectrum shaper together with a preamble I-FOP to achieve per-frame spectrum shaping with a delay of under 10 μ s.
Eugene Chai, Jeongkeun Lee, Sung-Ju Lee 0001, Raúl H. Etkin, Kang G. Shin
MobiCom5
2012 Controlling Preemption for Better Schedulability in Multi-Core Systems
abstract
Interest in real-time multiprocessor scheduling has been rekindled as multi-core chips are increasingly used for embedded real-time systems. While tasks may be preemptive or non-preemptive (due to their transactional operations), deadline guarantees are usually made only for those task sets in each of which all tasks are preemptive or non-preemptive, not a mixture thereof, i.e., all or nothing. In this paper, we develop a schedulability analysis framework that guarantees the timing requirements of a given task set in which a task can be either preemptive or non-preemptive. As an example, we apply this framework to the prioritization policy of EDF (Earliest Deadline First), yielding schedulability tests of mpn-EDF (Mixed Preemptive/Non-preemptive EDF), which is a generalization of both fp-EDF (fully-preemptive EDF) and np-EDF (non-preemptive EDF). In addition to their deadline guarantees for any task set that is composed of a mixture of preemptive and non-preemptive tasks, the tests outperform the existing schedulability tests of np-EDF (a special case of mpn-EDF) by up to 109.1%. Using these tests, we also improve schedulability by disallowing preemptions of some preemptive tasks. For this, we develop an algorithm that optimally disallows preemption of a preemptive task under a certain assumption, and demonstrate via simulation that the algorithm discovers up to 30.9% additional task sets that are schedulable with the proposed scheduling scheme, but not with fp-EDF or np-EDF.
Jinkyu Lee 0001, Kang G. Shin
RTSS2
2012 Generalized geometry-based optimal power control in wireless networks
abstract
Geometry-based optimal power control was proposed in [14] to transform the power-control problem to a new geometrical problem on the position relationship between a line and some points. This scheme provides a novel visual perspective and lowers the complexity of optimization. We generalize this scheme to a larger class of power-control optimization problems so as to maximize the network utility with multiple average and peak power constraints in wireless networks. To facilitate the handling of the geometrical model, we define a subset of geometrical models with specified characteristics, called a regular geometrical model, and derive the type of power-control problems eligible for the regular geometrical model. For such a type of problems, two strategies are proposed for the construction of the regular geometrical model. Utilizing geometrical properties, we propose a novel geometry-based optimization scheme for the general power-control problem. Its computational complexity is significantly lower than the conventional algorithms. We also provide a further discussion on irregular geometrical model cases. Finally, we provide two examples of deploying the proposed geometry-based power-control scheme.
Wei Wang 0021, Kang G. Shin, Zhaoyang Zhang 0001, Wenbo Wang 0007, Tao Peng 0001
SECON2
2012 ARCHoN: Adaptive range control of hotzone cells in heterogeneous cellular networks
abstract
Heterogeneous networks (HetNets) are typified by cellular deployments with multiple types of cells of different sizes and overlapping coverage areas using a common frequency band. Especially, hotzone cells overlaid on a macrocell to cover hotspot areas are expected to prevail in HetNets, thus cost-effectively enhancing cellular capacity via spatial reuse of spectrum resource and offloading macrocells. In order to fully achieve such benefits, users need to be properly distributed/assigned to the overlaid hotzone cells such that the radio resources therein are fully utilized. To this end, we propose a new architecture called Adaptive Range Control of Hotzone Cells for Heterogeneous Networks (ARCHoN) that jointly controls the radio resource allocations and ranges of OFDMA-based hotzone cells. The use of cell ranges for distributing users in ARCHoN is advantageous in that it can be implemented within a conventional cell-selection framework without modifying user devices or an air interface. In ARCHoN, each cell allocates users radio (frequency, time and power) resources in a non-cooperative manner, deriving a sequence of allocations monotonically decreasing the entire load. For range control, two algorithms are proposed: per-cell and universal, which have a tradeoff between performance and computational complexity. The solution yielded by the combination of these radio resource and range control algorithms is analytically proven to converge to a unique fixed point. Our in-depth evaluation has shown ARCHoN to significantly improve the service quality of users; in an example simulation scenario, ARCHoN is shown to improve the signal-to-interference and noise ratios (SINRs) of users, on average, by up to 3.5 dB in downlink and 18.8 dB in uplink, over the case of the conventional handover framework.
Ji-Hoon Yun, Kang G. Shin
SECON2
2012 Design of SMS commanded-and-controlled and P2P-structured mobile botnets
abstract
Botnets are one of the most serious security threats to the Internet and personal computer (PC) users. Although botnets have not yet caused major outbreaks in the mobile world, with the rapidly-growing popularity of smartphones such as Apple's iPhone and Android-based phones that store more personal data and gain more capabilities than earlier generation handsets, botnets are expected to become a severe threat to smartphones soon. In this paper, we propose the design of a mobile botnet that makes the most of mobile services and is resilient to disruption. The mobile botnet utilizes SMS messages for C&C and a P2P structure as its topology. Our simulation results demonstrate that a modified Kademlia---a structured architecture---is a better choice for the mobile botnet's topology. In addition, we discuss potential countermeasures to defend against this mobile botnet threat.
Kang G. Shin, Xin Hu 0001
WISEC2
2012 QoS provisioning for large-scale multi-ap WLANs
Jaehyuk Choi 0002, Kang G. Shin
Ad Hoc Networks2
2012 Improving Application Launch Performance on Solid State Drives
Yongsoo Joo, Junhee Ryu, Sangsoo Park, Kang G. Shin
J. Comput. Sci. Technol.4
2012 Attack Prevention for Collaborative Spectrum Sensing in Cognitive Radio Networks
abstract
Collaborative spectrum sensing is vulnerable to data falsification attacks, where malicious secondary users (attackers) submit manipulated sensing reports to mislead the fusion center's decision on spectrum occupancy. This paper considers a challenging attack scenario, where multiple attackers cooperatively maximize their aggregate spectrum utilization. Without attack-prevention mechanisms, we show that honest secondary users (SUs) are unable to opportunistically transmit over the licensed spectrum and may even get penalized for collisions caused by attackers. To prevent such attacks, we propose two attack-prevention mechanisms with direct and indirect punishments. Our key idea is to identify collisions with the primary user (PU) that should not happen if all SUs follow the fusion center's decision. Unlike prior work, the proposed simple mechanisms do not require the fusion center to identify and exclude attackers. The direct punishment can effectively prevent all attackers from behaving maliciously. The indirect punishment is easier to implement and can prevent attacks when the attackers care enough about their long-term reward.
Lingjie Duan, Alexander W. Min, Jianwei Huang 0001, Kang G. Shin
IEEE J. Sel. Areas Commun.4
2012 DESA: Dependable, Efficient, Scalable Architecture for Management of Large-Scale Batteries
abstract
Conventional battery management systems (BMSs) for electric vehicles (EVs) are designed in an ad hoc way, causing the supply of EVs to fall behind the market demand. A well-designed and combined hardware-software architecture is essential for the efficient management of a large-scale battery pack that may consists of thousands of battery cells as in Tesla Motors and GM Chevy Volt. We propose a Dependable, Efficient, Scalable Architecture (DESA) that effectively monitors a large number of battery cells, efficiently controls, and reconfigures, if needed, their connection arrangement. DESA supports hierarchical, autonomous management of battery cells, where a global BMS orchestrates a group of local BMSs. A local controller on each local BMS autonomously manages an array of battery cells, and the global controller reconfigures the connectivity of such battery-cell arrays in coordination with the local controllers. Also, DESA allows individual arrays and local BMSs to be selectively powered-off for energy savings. The performance of this energy-saving capability is modeled and evaluated using a Markov chain. Our evaluation results show that DESA effectively tolerates battery-cell failures by an order-of-magnitude—while achieving$7.4\times$service cost savings—better than a conventional BMS. This superior performance not only extends the battery life significantly, but also provides the flexibility in supporting diverse electric power demands from a growing number of on-board applications.
Hahnsang Kim, Kang G. Shin
IEEE Trans. Ind. Informatics2
2012 Admission and Eviction Control of Cognitive Radio Users at Wi-Fi 2.0 Hotspots
abstract
Cognitive radio (CR)-based Wi-Fi 2.0 hotspots are introduced as an attractive application of dynamic spectrum access (DSA), at which a wireless service provider (WSP) leases licensed channels via secondary market and offers Internet access to CR-enabled customers by opportunistically utilizing the leased spectrum. The CR users access the channels only when they are temporarily unoccupied by their legacy users, and pay a usage charge according to the WSP's pricing policy. In this paper, we study the profit maximization problem of a WSP by deriving the (sub)optimal control of admission (at CR user arrivals) and eviction (upon return of the legacy users) of CR users. We formulate the problem as a semi-Markov decision process (SMDP) with two quality-of-service (QoS) constraints on arrival-blocking and service-dropping probabilities, which is solved by the linear programming techniques. Using an extensive numerical analysis, we show that the derived policy achieves up to 22.5-44 percent more profit than simple complete-sharing algorithms in the tested scenarios. In addition, we evaluate the impact of the number of leased channels and pricing on the achieved profit, and study the tradeoffs between the two QoS constraints.
Hyoil Kim, Kang G. Shin
IEEE Trans. Mob. Comput.2
2012 Exploiting Spectrum Heterogeneity in Dynamic Spectrum Market
abstract
The dynamic spectrum market (DSM) is a key economic vehicle for realizing the opportunistic spectrum access that will mitigate the anticipated spectrum-scarcity problem. DSM allows legacy spectrum owners to lease their channels to unlicensed spectrum consumers (or secondary users) in order to increase their revenue and improve spectrum utilization. In DSM, determining the optimal spectrum leasing price is an important yet challenging problem that requires a comprehensive understanding of market participants' interests and interactions. In this paper, we study spectrum pricing competition in a duopoly DSM, where two wireless service providers (WSPs) lease spectrum access rights, and secondary users (SUs) purchase the spectrum use to maximize their utility. We identify two essential, but previously overlooked, properties of DSM: 1) heterogeneous spectrum resources at WSPs and 2) spectrum sharing among SUs. We demonstrate the impact of spectrum heterogeneity via an in-depth measurement study using a software-defined radio (SDR) testbed. We then study the impacts of spectrum heterogeneity on WSPs' optimal pricing and SUs' WSP selection strategies using a systematic three-step approach. First, we study how spectrum sharing among SUs subscribed to the same WSP affects the SUs' achievable utility. Then, we derive the SUs' optimal WSP selection strategy that maximizes their payoff, given the heterogeneous spectrum propagation characteristics and prices. We analyze how individual SU preferences affect market evolution and prove the market convergence to a mean-field limit, even though SUs make local decisions. Finally, given the market evolution, we formulate the WSPs' pricing strategies in a duopoly DSM as a noncooperative game and identify its Nash equilibrium points. We find that the equilibrium price and its uniqueness depend on the SUs' geographical density and spectrum propagation characteristics. Our analytical framework reveals the impact of spectrum heterogeneity in a real-world DSM, and can be used as a guideline for the WSPs' pricing strategies.
Alexander W. Min, Xinyu Zhang 0003, Jaehyuk Choi 0002, Kang G. Shin
IEEE Trans. Mob. Comput.4
2012 E-MiLi: Energy-Minimizing Idle Listening in Wireless Networks
abstract
WiFi interface is known to be a primary energy consumer in mobile devices, and idle listening (IL) is the dominant source of energy consumption in WiFi. Most existing protocols, such as the 802.11 power-saving mode (PSM), attempt to reduce the time spent in IL by sleep scheduling. However, through an extensive analysis of real-world traffic, we found more than 60 percent of energy is consumed in IL, even with PSM enabled. To remedy this problem, we propose Energy-Minimizing idle Listening (E-MiLi) that reduces the power consumption in IL, given that the time spent in IL has already been optimized by sleep scheduling. Observing that radio power consumption decreases proportionally to its clock rate, E-MiLi adaptively downclocks the radio during IL, and reverts to full clock rate when an incoming packet is detected or a packet has to be transmitted. E-MiLi incorporates sampling rate invariant detection, ensuring accurate packet detection and address filtering even when the receiver's sampling clock rate is much lower than the signal bandwidth. Further, it employs an opportunistic downclocking mechanism to optimize the efficiency of switching clock rate, based on a simple interface to existing MAC-layer scheduling protocols. We have implemented E-MiLi on the USRP software radio platform. Our experimental evaluation shows that E-MiLi can detect packets with close to 100 percent accuracy even with downclocking by a factor of 16. When integrated with 802.11, E-MiLi can reduce energy consumption by around 44 percent for 92 percent of users in real-world wireless networks.
Xinyu Zhang 0003, Kang G. Shin
IEEE Trans. Mob. Comput.2
2012 Distributed Resource Allocation Based on Queue Balancing in Multihop Cognitive Radio Networks
abstract
Cognitive radio (CR) allows unlicensed users to access the licensed spectrum opportunistically (i.e., when the spectrum is left unused by the licensed users) to enhance the spectrum utilization efficiency. In this paper, the problem of allocating resources (channels and transmission power) in multihop CR networks is modeled as a multicommodity flow problem with the dynamic link capacity resulting from dynamic resource allocation, which is in sharp contrast with existing flow-control approaches that assume fixed link capacity. Based on queue-balancing network flow control that is ideally suited for handling dynamically changing spectrum availability in CR networks, we propose a distributed scheme (installed and operational in each node) for optimal resource allocation without exchanging spectrum dynamics information between remote nodes. Considering the power masks, each node makes resource-allocation decisions based on current or past local information from neighboring nodes to satisfy the throughput requirement of each flow. Parameters of these proposed schemes are configured to maintain the network stability. The performance of the proposed scheme for both asynchronous and synchronous scenarios is analyzed comparatively. Both cases of sufficient and insufficient network capacity are considered.
Wei Wang 0021, Kang G. Shin, Wenbo Wang 0007
IEEE/ACM Trans. Netw.2
2012 DSASync: Managing End-to-End Connections in Dynamic Spectrum Access Wireless LANs
abstract
Wireless LANs (WLANs) have been widely deployed as edge access networks that provide the important service of Internet access to wireless devices. Therefore, performance of end-to-end connections to/from such WLANs is of great importance. The advent of Dynamic Spectrum Access (DSA) technology is expected to play a key role in improving wireless communication. With DSA capability, WLANs opportunistically access licensed channels in order to improve spectrum-usage efficiency and provide better network performance. In this paper, we identify the key issues that impact end-to-end connection performance when a DSA-enabled WLAN is integrated with the wired cloud. We propose a new network management framework, called DSASync, to mitigate the identified performance issues. DSASync achieves this objective by managing the connections at the transport layer as a third-party supervisor and targets both TCP streams and UDP flows. DSASync requires no modifications to the network infrastructure or the existing network stack and protocols while ensuring transport protocol (TCP or UDP) semantics to be obeyed. It mainly consists of a combination of buffering and traffic-shaping algorithms to minimize the adverse side-effects of DSA on active connections. DSASync is evaluated using a prototype implementation and deployment in a testbed. The results show significant improvement in end-to-end connection performance, with substantial gains on QoS metrics like goodput, delay, and jitter. Thus, DSASync is a promising step toward applying DSA technology in consumer WLANs.
Kang G. Shin
IEEE/ACM Trans. Netw.2
2012 Application-aware dynamic spectrum access
Kang G. Shin
Wirel. Networks2
2011 FAST: Quick Application Launch on Solid-State Drives
Yongsoo Joo, Junhee Ryu, Sangsoo Park, Kang G. Shin
FAST4
2011 Sidekick: AP aggregation over partially overlapping channels
abstract
The uncoordinated deployment of many high-bandwidth 802.11a/g/n access points (APs) in urban areas offers the potential for WLANs to be a strong complement to cellular networks in providing ubiquitous connectivity. However, given that the bandwidth of the backhaul links connected to these APs is often an order-of-magnitude lower than that of the WLAN channel, aggregating the throughput from multiple APs is often necessary in order for the client to achieve an acceptable level of network performance. In this paper, we present Sidekick - a simple and novel AP aggregation protocol that exploits effective communication between 802.11a/g/n nodes on partially overlapping channels to attain high aggregate throughput in the face of dynamic WLAN and backhaul link conditions. Sidekick is built upon Aileron, which provides an extremely reliable and low-overhead control channel over which the APs and clients can coordinate the aggregation process. The use of such a control channel over partially overlapping channels enables Sidekick to quickly respond to varying bandwidth availability and probe for new transmission opportunities with little overhead. Our evaluation results indicate that Sidekick can make more than 30% improvement in throughput over FatVAP in a variety of situations.
Eugene Chai, Kang G. Shin
ICNP2
2011 Out-of-band sensing with ZigBee for dynamic channel assignment in on-the-move hotspots
abstract
Mobile WiFi hotspots have become increasingly popular as a new innovative wireless Internet access technology. Although it has received little attention, adaptive, dynamic (re)assignment of channels in a mobile hotspot router - typically, a smartphone or a laptop or a tablet equipped with heterogeneous network interfaces like 3G/4G, WiFi, Bluetooth or ZigBee - is key to mobile hotspot performance. To fill this important gap, we present a novel scheme, called Ex2R, that finds the best WiFi service-channel by harnessing secondary low-power ZigBee radios accompanied in mobile hotspot systems, enabling intelligent and seamless dynamic channel reconfiguration. Ex2R exploits the RSSI values and clear channel assessment (CCA) outputs from the ZigBee radio sampling interface to measure idle-time fractions on candidate WiFi channels, and determines the channel that can provide the highest hotspot capacity. Ex2R thus provides a mobile hotspot router accurate information necessary for the selection of the best channel. We have implemented and evaluated Ex2R, demonstrating its effectiveness; Ex2R accurately ranks WiFi channels for a mobile hotspot router to dynamically select and switch to the best channel available, thus improving hotspot performance significantly.
Jaehyuk Choi 0002, Kang G. Shin
ICNP2
2011 Adaptive Subcarrier Nulling: Enabling partial spectrum sharing in wireless LANs
abstract
Emerging WLAN standards have been incorporating a variety of channel widths ranging from 5MHz to 160MHz, in order to match the diverse traffic demands on different networks. Unfortunately, the current 802.11 MAC/PHY is not designed for the coexistence of variable-width channels. Overlapping narrowband channels may block an entire wide-band channel, resulting in severe spectrum underutilization and even starvation of WLANs on the wide-band. A similar peril exists when a WLAN partially overlaps its channel with multiple orthogonal WLANs. In this paper, we propose to solve the problem of partial spectrum sharing using Adaptive Subcarrier Nulling (ASN). ASN builds on the 802.11 OFDM PHY, but allows the radios to sense, transmit, detect, and decode packets through spectrum fragments, or subbands. An ASN transmitter can adapt its spectrum usage on a per-packet basis, by nulling the subbands used by neighboring WLANs, and sending packets through the remaining idle subbands. ASN preserves the 802.11 CSMA/CA primitives while allowing users to contend for access to each subband, and can opportunistically exploit the merits of wide-band channels via spectrum aggregation. We have implemented and evaluated ASN on the GNURadio/USRP platform. Our experimental results have shown ASN to achieve detection and decoding performance comparable to the legacy 802.11. Our detailed simulation in ns-2 further shows that ASN substantially improves the efficiency and fairness of spectrum sharing for multi-cell WLANs.
Xinyu Zhang 0003, Kang G. Shin
ICNP2
2011 Measurement and analysis of global IP-usage patterns of fast-flux botnets
abstract
This paper considers the global IP-usage patterns exhibited by different types of malicious and benign domains, with a focus on single and double fast-flux domains. We have developed and deployed a lightweight DNS probing engine, called DIGGER, on 240 PlanetLab nodes spanning 4 continents. Collecting DNS data for over 3.5 months on a plethora of domains, our global vantage points enabled us to identify distinguishing behavioral features between them based on their DNS-query results. To help us analyze the enormous amount of data, we have quantified these features and designed an effective classifier capable of accurately discriminating between different types of domains. Applying the classifier on the 3.5-month DNS data allows us to reveal the relative prevalence of different fast-flux domains and conduct detailed studies on them separately. These results provide insight into the current global state of fast-flux botnets and their range in implementation, revealing potential trends for botnet-based services. We also uncover previously-unseen domains whose name servers alone demonstrate fast-flux behavior and a new, cautious IP management strategy currently employed by criminals to evade detection.
Xin Hu 0001, Matthew Knysz, Kang G. Shin
INFOCOM3
2011 Wi-Fi 2.0: Price and quality competitions of duopoly cognitive radio wireless service providers with time-varying spectrum availability
abstract
The whitespaces (WS) in the legacy spectrum provide new opportunities for the future Wi-Fi-like Internet access, often called Wi-Fi 2.0, since service quality can be greatly enhanced thanks to the better propagation characteristics of the WS than the ISM bands. In the Wi-Fi 2.0 networks, each wireless service provider (WSP) temporarily leases a licensed spectrum band from the licensees and opportunistically utilizes it during the absence of the legacy users. The WSPs in Wi-Fi 2.0 thus face unique challenges since spectrum availability of the leased channel is time-varying due to the ON/OFF spectrum usage patterns of the legacy users, which necessitates the eviction control of in-service customers at the return of legacy users. As a result, to maximize its profit, a WSP should consider both channel leasing and eviction costs to optimally determine a spectrum band to lease and a service tariff. In this paper, we consider a duopoly Wi-Fi 2.0 market where two co-located WSPs compete for the spectrum and customers. The competition between the WSPs is analyzed using game theory to derive the Nash Equilibria (NE) of the price (of the service tariffs) and the quality (of the leased channel, in terms of channel utilization) competitions. The NE existence condition and market entry barriers are also derived. Via an extensive numerical analysis, we show the tradeoffs between leasing/eviction cost, customer arrivals, and channel usage patterns by the legacy users.
Hyoil Kim, Jaehyuk Choi 0002, Kang G. Shin
INFOCOM3
2011 Good guys vs. Bot Guise: Mimicry attacks against fast-flux detection systems
abstract
In this paper, we explore the escalating “arms race” between fast-flux (FF) botnet detectors and the botmasters' effort to subvert them, and investigate several novel mimicry-attack techniques that allow botmasters to avoid detection. We first analyze the state-of-art FF detectors and their effectiveness against the current botnet threat, demonstrating how botmasters can - with their current resources - thwart detection strategies. Based on the realistic assumptions inferred from empirically observed trends, we create formal models for bot decay, online availability, DNS-advertisement strategies and performance, allowing us to demonstrate the effectiveness of different mimicry attacks and evaluate their effects on the overall online availability and capacity of botnets.
Matthew Knysz, Xin Hu 0001, Kang G. Shin
INFOCOM3
2011 Opportunistic spectrum access for mobile cognitive radios
abstract
Cognitive radios (CRs) can mitigate the impending spectrum scarcity problem by utilizing their capability of accessing licensed spectrum bands opportunistically. While most existing work focuses on enabling such opportunistic spectrum access for stationary CRs, mobility is an important concern to secondary users (SUs) because future mobile devices are expected to incorporate CR functionality. In this paper, we identify and address three fundamental challenges encountered specifically by mobile SUs. First, we model channel availability experienced by a mobile SU as a two-state continuous-time Markov chain (CTMC) and verify its accuracy via in-depth simulation. Then, to protect primary/incumbent communications from SU interference, we introduce guard distance in the space domain and derive the optimal guard distance that maximizes the spatio-temporal spectrum opportunities available to mobile CRs. To facilitate efficient spectrum sharing, we formulate the problem of maximizing secondary network throughput within a convex optimization framework, and derive an optimal, distributed channel selection strategy. Our simulation results show that the proposed spectrum sensing and distributed channel access schemes improve network throughput and fairness significantly, and reduce SU energy consumption for spectrum sensing by up to 74%.
Alexander W. Min, Kyu-Han Kim, Jatinder Pal Singh, Kang G. Shin
INFOCOM4
2011 Measuring the effectiveness of infrastructure-level detection of large-scale botnets
abstract
Botnets are one of the most serious security threats to the Internet and its end users. In recent years, utilizing P2P as a Command and Control (C&C) protocol has become popular due to its decentralized nature that can help hide the botmaster's identity. Most bot detection approaches targeting P2P botnets either rely on behavior monitoring or traffic flow and packet analysis, requiring fine-grained information collected locally. This requirement limits the scale of detection. In this paper, we consider detection of P2P botnets at a high-level - the infrastructure level-by exploiting their structural properties from a graph analysis perspective. Using three different P2P overlay structures, we measure the effectiveness of detecting each structure at various locations (the Autonomous System (AS), the Point of Presence (PoP), and the router rendezvous) in the Internet infrastructure.
Guanhua Yan, Stephan J. Eidenbenz, Kang G. Shin
IWQoS4
2011 E-MiLi: energy-minimizing idle listening in wireless networks
abstract
WiFi interface is known to be a primary energy consumer in mobile devices, and idle listening (IL) is the dominant source of energy consumption in WiFi. Most existing protocols, such as the 802.11 power-saving mode (PSM), attempt to reduce the time spent in IL by sleep scheduling. However, through an extensive analysis of real-world traffic, we found more than 60% of energy is consumed in IL, even with PSM enabled. To remedy this problem, we propose E-MiLi (Energy-Minimizing idle Listening) that reduces the power consumption in IL, given that the time spent in IL has already been optimized by sleep scheduling. Observing that radio power consumption decreases proportionally to its clock-rate, E-MiLi adaptively downclocks the radio during IL, and reverts to full clock-rate when an incoming packet is detected or a packet has to be transmitted. E-MiLi incorporates sampling rate invariant detection, ensuring accurate packet detection and address filtering even when the receiver's sampling clock-rate is much lower than the signal bandwidth. Further, it employs an opportunistic downclocking mechanism to optimize the efficiency of switching clock-rate, based on a simple interface to existing MAC-layer scheduling protocols. We have implemented E-MiLi on the USRP software radio platform. Our experimental evaluation shows that E-MiLi can detect packets with close to 100% accuracy even with downclocking by a factor of 16. When integrated with 802.11, E-MiLi can reduce energy consumption by around 44% for 92% of users in real-world wireless networks.
Xinyu Zhang 0003, Kang G. Shin
MobiCom2
2011 Enabling coexistence of heterogeneous wireless systems: case for ZigBee and WiFi
abstract
The ISM spectrum is becoming increasingly populated by emerging wireless networks. Spectrum sharing among the same network of devices can be arbitrated by MAC protocols (e.g., CSMA), but the coexistence between heterogeneous networks remains a challenge. The disparate power levels, asynchronous time slots, and incompatible PHY layers of heterogeneous networks severely degrade the effectiveness of traditional MAC. In this paper, we propose a new mechanism, called the Cooperative Busy Tone (CBT), that enables the reliable coexistence between two such networks, ZigBee and WiFi. CBT allows a separate ZigBee node to schedule a busy tone concurrently with the desired transmission, thereby improving the visibility of ZigBee devices to WiFi. Its core components include a frequency flip scheme that prevents the mutual interference between cooperative ZigBee nodes, and a busy tone scheduler that minimizes the interference to WiFi, for both CSMA and TDMA packets. To optimize CBT, we establish an analytical framework that relates its key design parameters to performance and cost. Both the analytical and detailed simulation results demonstrate CBT's significant throughput improvement over the legacy ZigBee protocol, with negligible performance loss to WiFi. The results are validated further by implementing CBT on sensor motes and software radios.
Xinyu Zhang 0003, Kang G. Shin
MobiHoc2
2011 Thermal-Aware Scheduling of Critical Applications Using Job Migration and Power-Gating on Multi-core Chips
abstract
Multi-core System-on-Chip (SoC) has become a popular execution platform for many embedded real-time systems. As CMOS transistors continue to shrink down to the nanoscale regime, it becomes more susceptible to various reliability threats mainly due to thermal hotspots. To improve the reliability of embedded real-time systems, dynamic thermal management (DTM) is required for mission/safety- critical applications running on a multi-core chip to avoid possible thermal hazards while meeting the applications' timing constraints. In this paper, we propose an efficient runtime thermal- aware scheduler (TAS) using job-migration and power-gating techniques to avoid the thermal hotspots on a multi-core chip. Before runtime, the TAS distributes the periodic real-time tasks to cores using the tasks' execution profiles to balance the utilization of functional units on the chip. At runtime, the TAS periodically monitors the core temperatures and triggers one of the following pre-defined thermal management schemes depending on the level of the measured core temperature: (i) migrating jobs running on hot cores to other cooler cores to reduce the workloads on the hot cores, or (ii) turning off hot cores for a certain period of time to cool them down. All tasks' timing constraints are guaranteed during the job migrations and powering cores on/off. Our in-depth evaluation has shown that the proposed TAS can effectively minimize the thermal hotspots on a multi-core chip without violating any application timing constraint.
Buyoung Yun, Kang G. Shin, Shige Wang
TrustCom2
2011 Detection of Small-Scale Primary Users in Cognitive Radio Networks
abstract
In cognitive radio networks (CRNs), detecting small-scale primary devices, such as wireless microphones, is a challenging, but very important, problem that has not yet been addressed well. Recently, cooperative sensing and sensing scheduling have been advocated as an effective MAC (medium access control) layer approach to detecting large-scale primary signals. However, it is unclear whether and how they can improve the detection of a small-scale primary signal because of (i) its small signal footprint due to the use of weak transmit-power, and (ii) the unpredictability of its spatial and temporal spectrum-usage patterns. Based on extensive analysis and simulation, we identify the data-fusion range as a key factor that enables effective cooperative sensing for detection of small-scale primary signals. In particular, we derive a closed-form expression for the optimal data-fusion range that minimizes the average detection delay. We also observe that the sensing performance is sensitive to the accuracy in estimating the primary's location and transmit-power. Based on these observations, we propose an efficient sensing framework that jointly performs \underline{De}tection, \underline{LOC}ation estimation, and transmit-power estimation ({t DeLOC}) for small-scale primary users. Our extensive evaluation results in a realistic CRN environment show that {t DeLOC} achieves near-optimal detection performance, while meeting the detection requirements specified in the IEEE 802.22 standard draft. These findings provide useful insights and guidelines in designing a sensing scheme for detection of small-scale primaries in CRNs.
Alexander W. Min, Xinyu Zhang 0003, Kang G. Shin
IEEE J. Sel. Areas Commun.3
2011 Adaptive Interference Management of OFDMA Femtocells for Co-Channel Deployment
abstract
Femtocell technology has been drawing considerable attention as a cost-effective means of extending cellular coverage and enhancing capacity as well as realizing its potential, when combined with orthogonal frequency-division multiple access (OFDMA), for improved indoor broadband wireless services. However, under the expected co-channel deployment of femto- and macro-cells, femtocells may incur high uplink interference to macrocells, and vice versa. To mitigate this interference, we propose a distributed and self-organizing femtocell management architecture, called the Complementary TRi-control Loops (CTRL), that consists of three control loops to determine (1) maximum transmit power of femtocell users based on the fed-back macrocell load margin for protection of the macrocell uplink communications; (2) target signal to interference plus noise ratios (SINRs) of femtocell users to reach a Nash equilibrium; and (3) instantaneous transmit power of femtocell users to achieve the target SINRs against bursty interference from other nearby users. CTRL requires neither special hardware nor change to the radio resource management (RRM) of existing macrocells, thus facilitating non-disruptive (hence seamless) penetration of femtocells. Also, CTRL guarantees convergence in the presence of environmental changes and delayed feedback. Our evaluation has shown CTRL to successfully preserve the macrocell users' service quality under highly dynamic user transmission conditions and be able to make a tradeoff between macrocell and femtocell capacities.
Ji-Hoon Yun, Kang G. Shin
IEEE J. Sel. Areas Commun.2
2011 A Lightweight Passive Online Detection Method for Pinpointing Misbehavior in WLANs
abstract
Detecting misbehaving users in wireless networks is an important problem that has been drawing considerable attention. Even though there is a plethora of work on 802.11 wireless local area networks (WLANs), most existing schemes employ behavior-based anomaly detection, assuming that the backoff-time information of each transmitting node is available to the monitoring node. Unfortunately, it is practically infeasible to obtain the accurate backoff value chosen by other transmitting nodes because this MAC-layer information is not readily available. In this paper, we propose a practical way of pinpointing the misbehaving nodes without requiring access of hardware-level (e.g., backoff time) information in 802.11 WLANs. In contrast to most prior work, our scheme exploits the sequence of successfully received packets, which are readily observable at the access point. The distinct features of our scheme are that it 1) promptly detects a misbehaving node using a sequential hypothesis test, 2) performs well in realistic erroneous channel conditions due to its ability to accurately capture link heterogeneity, and 3) incurs negligible memory and computation overheads as it makes detection decisions based on runtime observations. The effectiveness of the proposed scheme is evaluated via extensive simulation as well as implementation, demonstrating its capability of accurately detecting nodess' selfish behavior in realistic 802.11 WLAN environments.
Jaehyuk Choi 0002, Alexander W. Min, Kang G. Shin
IEEE Trans. Mob. Comput.3
2011 MODELZ: Monitoring, Detection, and Analysis of Energy-Greedy Anomalies in Mobile Handsets
abstract
It is of great importance to protect rapidly-spreading and widely-used small mobile devices like smartphones and PocketPCs from energy-depletion attacks by monitoring software (processes) and hardware (especially, battery) resources. The ability to use these devices for on- and/or off-job functions, and even for medical emergencies or disaster recovery is often dictated by their limited battery capacity. However, traditional malware detection systems and antivirus solutions based on matching signatures are limited to detection of only known malware, and hence, cannot deal with battery-depletion attacks. To meet this challenge, we propose to develop, implement, and evaluate a comprehensive framework, called MODELZ, that MOnitors, DEtects, and anaLyZes energy-greedy anomalies on small mobile devices. MODELZ comprises 1) a charge flow meter that allows infrequent sampling of energy consumption without losing accuracy, 2) a power monitor, in coordination with the charge flow meter, that samples and builds a power-consumption history, and 3) a data analyzer that generates a power signature from the power-consumption history. To generate a power signature, we devise and apply light-weighted, effective noise filtering and data compression, reducing the detection overhead significantly. The similarities between power signatures are measured by the χ2-distance and used to lower both false-positive and false-negative detection rates. Our experimental results on an HP iPAQ running the Windows Mobile OS have shown that MODELZ achieves significant (up to 95 percent) storage-savings without losing detection accuracy, and a 99 percent true-positive rate in differentiating legitimate programs from suspicious ones while the monitoring consumes 50 percent less energy than the case of keeping the Bluetooth radio turned on.
Hahnsang Kim, Kang G. Shin, Padmanabhan Pillai
IEEE Trans. Mob. Comput.2
2011 Secure Cooperative Sensing in IEEE 802.22 WRANs Using Shadow Fading Correlation
abstract
Cooperative (or distributed) sensing has been recognized as a viable means to enhance the incumbent signal detection by exploiting the diversity of sensors. However, it is challenging to secure such distributed sensing due mainly to the unique features of dynamic spectrum access networks-openness of low-layer protocol stacks in software-defined radio devices and the absence of interactions/coordination between primary and secondary devices. To meet this challenge, we propose an attack-tolerant distributed sensing protocol (ADSP) for DTV signal detection in IEEE 802.22 WRANs, under which sensors in close proximity are grouped as a cluster, and sensors within a cluster cooperate to safeguard the integrity of sensing. The heart of ADSP is a novel filter based on shadow-fading correlation, by which the fusion center cross-validates reports from the sensors to identify and penalize abnormal sensing reports. By realizing this correlation filter, ADSP significantly reduces the impact of an attack on the performance of distributed sensing, while incurring minimal processing and communication overheads. ADSP also guarantees the detectability requirements of 802.22 to be met even with the presence of sensing report manipulation attacks by scheduling sensing within the framework of sequential hypothesis testing. The efficacy of ADSP is validated on a realistic 2D shadow-fading field. Our extensive simulation-based study shows that ADSP reduces the false-alarm rate by 99.2 percent while achieving 97.4 percent of maximum achievable detection rate, and meets the detection requirements of IEEE 802.22 in various attack scenarios.
Alexander W. Min, Kang G. Shin, Xin Hu 0001
IEEE Trans. Mob. Comput.2
2011 Joint Spectrum Allocation and Power Control for Multihop Cognitive Radio Networks
abstract
We propose a new framework of joint spectrum allocation and power control to utilize open spectrum bands in cognitive radio networks (CRNs) by considering both interference temperature constraints and spectrum dynamics. We first address a simpler problem for the case of a single flow. A TDM-based power-control strategy is adopted to achieve maximum end-to-end throughput by choosing an appropriate multihop route and spectrum combination for each single flow. Then, the simpler solution is extended to the multiflow case in which interflow interference and cumulative interference temperature must be considered. Considering the overhead of switching route and spectrum, the optimal waiting time before making a switch is derived. Our in-depth simulation study has shown that the proposed algorithms utilize spectrum more efficiently than other existing algorithms.
Wei Wang 0021, Kang G. Shin, Wenbo Wang 0007
IEEE Trans. Mob. Comput.2
2011 Self-reconfigurable wireless mesh networks
abstract
During their lifetime, multihop wireless mesh networks (WMNs) experience frequent link failures caused by channel interference, dynamic obstacles, and/or applications' bandwidth demands. These failures cause severe performance degradation in WMNs or require expensive manual network management for their real-time recovery. This paper presents an autonomous network reconfiguration system (ARS) that enables a multiradio WMN to autonomously recover from local link failures to preserve network performance. By using channel and radio diversities in WMNs, ARS generates necessary changes in local radio and channel assignments in order to recover from failures. Next, based on the thus-generated configuration changes, the system cooperatively reconfigures network settings among local mesh routers. ARS has been implemented and evaluated extensively on our IEEE 802.11-based WMN test-bed as well as through ns2-based simulation. Our evaluation results show that ARS outperforms existing failure-recovery schemes in improving channel-efficiency by more than 90% and in the ability of meeting the applications' bandwidth demands by an average of 200%.
Kyu-Han Kim, Kang G. Shin
IEEE/ACM Trans. Netw.2
2010 Detection of botnets using combined host- and network-level information
abstract
Bots are coordinated by a command and control (C&C) infrastructure to launch attacks that seriously threaten the Internet services and users. Most botnet-detection approaches function at the network level and require the analysis of packets' payloads, raising privacy concerns and incurring large computational overheads. Moreover, network traffic analysis alone can seldom provide a complete picture of botnets' behavior. By contrast, in-host detection approaches are useful to identify each bot's host-wide behavior, but are susceptible to the host-resident malware if used alone. To address these limitations, we consider both the coordination within a botnet and the malicious behavior each bot exhibits at the host level, and propose a C&C protocol-independent detection framework that combines host- and network-level information for making detection decisions. The framework is shown to be effective in detecting various types of botnets with low false-alarm rates.
Xin Hu 0001, Kang G. Shin
DSN3
2010 M-Polar: Channel Allocation for Throughput Maximization in SDR Mesh Networks
abstract
In traditional wireless networks, nodes use only a single channel per radio interface, thus limiting the overall channel diversity of the network. This restriction is due to the inherent limitations of commercially-available RF devices. With the advent of high bandwidth software-defined radios (SDRs), we now have the option of assigning multiple contiguous, independent channels to a single wireless interface. This new-found opportunity raises an important question: how do we assign contiguous channels to nodes in order to maximize overall network throughput? This question lies at the often-ignored intersection of single-radio-multi-channel and multi-radio-multi-channel assignment schemes. In this paper, we develop a protocol that assigns contiguous channels with the goal of evenly spreading the load across the multiple channels. Neighboring nodes greedily adjust their channel ranges according to channel conditions to achieve an overall pattern of partially-overlapping bandwidths that maximizes the network throughput. The end-result is a network that can dynamically adapt its bandwidth usage to the network load and the conditions of the different channels. The proposed protocol is evaluated with a prototype built upon the USRP as well as with detailed simulation.
Eugene Chai, Kang G. Shin
INFOCOM2
2010 Asymmetry-Aware Real-Time Distributed Joint Resource Allocation in IEEE 802.22 WRANs
abstract
In IEEE 802.22 Wireless Regional Area Networks (WRANs), each Base Station (BS) solves a complex resource allocation problem of simultaneously determining the channel to reuse, power for adaptive coverage, and Consumer Premise Equipments (CPEs) to associate with, while maximizing the total downstream capacity of CPEs. Although joint power and channel allocation is a classical problem, resource allocation in WRANs faces two unique challenges that has not yet been addressed: (1) the presence of small-scale incumbents such as wireless microphones (WMs), and (2) asymmetric interference patterns between BSs using omnidirectional antennas and CPEs using directional antennas. In this paper, we capture this asymmetry in upstream/downstream communications to propose an accurate and realistic WRAN-WM coexistence model that increases spatial reuse of TV spectrum while protecting small-scale incumbents. Based on the proposed model, we formulate the resource allocation problem as a mixed-integer nonlinear programming (MINLP) which is NP-hard. To solve the problem in real-time, we propose a suboptimal algorithm based on the Genetic Algorithm (GA), and extend the basic GA algorithm to a fully-distributed GA algorithm (dGA) that distributes computational cost over the network and achieves scalability via local cooperation between neighboring BSs. Using extensive simulation, the proposed dGA is shown to perform as good as 99.4-99.8% of the optimal solution, while reducing the computational cost significantly.
Hyoil Kim, Kang G. Shin
INFOCOM2
2010 Spatio-Temporal Fusion for Small-scale Primary Detection in Cognitive Radio Networks
abstract
In cognitive radio networks (CRNs), detecting small-scale primary devices---such as wireless microphones (WMs)---is a challenging, but very important, problem that has not yet been addressed well. We identify the data-fusion range as a key factor that enables effective cooperative sensing for detection of small-scale primary devices. In particular, we derive a closed-form expression for the optimal data-fusion range that minimizes the average detection delay. We also observe that the sensing performance is sensitive to the accuracy in estimating the primary's location and transmit-power. Based on these observations, we propose an efficient sensing framework, called DeLOC, that iteratively performs location/transmit-power estimation and dynamic sensor selection for cooperative sensing. Our extensive simulation results in a realistic CRN environment show that DeLOC achieves near-optimal detection performance, while meeting the detection requirements specified in the IEEE 802.22 standard draft.
Alexander W. Min, Xinyu Zhang 0003, Kang G. Shin
INFOCOM3
2010 Multihop Transmission Opportunity in Wireless Multihop Networks
abstract
Wireless multihop communication is becoming more important due to the increasing popularity of wireless sensor networks, wireless mesh networks, and mobile social networks. They are distinguished from conventional multihop networks in terms of scale, traffic intensity and/or node density. Being readily-available in most of 802.11 radios, multirate facility appears to be useful to address some of these issues and is particularly helpful in high-density scenarios where inter-node distance is short, demanding a prudent multirate adaptation algorithm. However, communication at high bit rates mandates a large number of hops for a given node pair and thus, can easily be depreciated as per-hop overhead at several layers of network protocol is aggregated over the increased number of hops. This paper presents a novel multihop, multirate adaptation mechanism, called Multihop Transmission OPportunity (MTOP), that allows a frame to be forwarded a number of hops consecutively but reduces the MAC-layer overhead between hops. This seemingly collision-prone multihop forwarding is proven to be safe via analysis and USRP/GNU Radio-based experiment. The idea of MTOP is in clear contrast to, but not mutually exclusive with, the conventional opportunistic transmission mechanism, referred to as TXOP, where a node transmits multiple frames back-to-back when it gets an opportunity. We conducted an extensive simulation study via ns-2, demonstrating the performance advantage of MTOP under a wide range of network scenarios.
Chansu Yu, Tianning Shen, Kang G. Shin, Jeong-Yoon Lee, Young-Joo Suh
INFOCOM3
2010 DAC: Distributed Asynchronous Cooperation for Wireless Relay Networks
abstract
Cooperative relay is a communication paradigm that aims to realize the capacity of multi-antenna arrays in a distributed manner. However, the symbol-level synchronization requirement among distributed relays limits its use in practice. We propose to circumvent this barrier with a cross-layer protocol called Distributed Asynchronous Cooperation (DAC). With DAC, multiple relays can schedule concurrent transmissions with packet-level (hence coarse) synchronization. The receiver then extracts multiple versions of each relayed packet via a collision-resolution algorithm, thus realizing the diversity gain of cooperative communication. We demonstrate the feasibility of DAC by prototyping and testing it on the GNURadio/USRP software radio platform. To explore its relevance at the network level, we introduce a DAC-based MAC, and a generic approach to integrate the DAC MAC/PHY layer into a typical routing algorithm. Considering the use of DAC for multiple network flows, we analyze the fundamental tradeoff between the improvement in diversity gain and the reduction in multiplexing opportunities. DAC is shown to improve the throughput and delay performance of lossy networks with medium-level link quality. Our analytical results are also confirmed by network-level simulation in ns-2.
Xinyu Zhang 0003, Kang G. Shin
INFOCOM2
2010 Chorus: Collision Resolution for Efficient Wireless Broadcast
abstract
Traditional wireless broadcast protocols rely heavily on the 802.11-based CSMA/CA model, which avoids interference and collision by conservatively scheduling transmissions. While CSMA/CA is amenable to multiple concurrent unicasts, it tends to degrade broadcast performance, especially when there are a large number of nodes and links are lossy. In this paper, we propose a new, drastically different protocol called Chorus that improves the efficiency and scalability of broadcast service with a MAC layer that allows packet collisions. Chorus is built upon the observation that packets carrying the same data can be effectively detected and decoded, even when they overlap in time and have comparable signal strength. It performs collision resolution using symbol-level iterative decoding, and then combines the resolved symbols to reconstruct the packet. This collision-tolerant mechanism significantly improves the transmission diversity and spatial reuse in wireless broadcast, providing an asymptotic broadcast delay that is proportional to the network radius. This advantage is exploited further by Chorus's MAC-layer cognitive sensing and scheduling scheme. We evaluate Chorus with symbol-level simulation, and validate its network-level performance via ns-2, in comparison with a typical CSMA/CA broadcast protocol.
Xinyu Zhang 0003, Kang G. Shin
INFOCOM2
2010 Sybot: an adaptive and mobile spectrum survey system for wifi networks
abstract
Information on site-specific spectrum characteristics is essential to evaluate and improve the performance of wireless networks. However, it is usually very costly to obtain accurate spectrum-condition information in heterogeneous wireless environments. This paper presents a novel spectrum-survey system, called Sybot (Spectrum survey robot), that guides network engineers to efficiently monitor the spectrum condition (e.g., RSS) of WiFi networks. Sybot effectively controls mobility and employs three disparate monitoring techniques - complete, selective, and diagnostic - that help produce and maintain an accurate spectrum-condition map for challenging indoor WiFi networks. By adaptively triggering the most suitable of the three techniques, Sybot captures spatio-temporal changes in spectrum condition. Moreover, based on the monitoring results, Sybot automatically determines several key survey parameters, such as site-specific measurement time and space granularities. Sybot has been prototyped with a commodity IEEE 802.11 router and Linux OS, and experimentally evaluated, demonstrating its ability to generate accurate spectrum-condition maps while reducing the measurement effort (space, time) by more than 56%.
Kyu-Han Kim, Alexander W. Min, Kang G. Shin
MobiCom3
2010 CTRL: a self-organizing femtocell management architecture for co-channel deployment
abstract
Femtocell technology has been drawing considerable attention as a cost-effective means of improving cellular coverage and capacity. However, under co-channel deployment, femtocells may incur high uplink interference to existing macrocells, and vice versa. To alleviate this interference, we propose a distributed and self-organizing femtocell management architecture, called CTRL Complementary TRi-control Loops), that consists of three control loops. First, for protection of macrocell users' uplink communications, CTRL controls the maximum TX power of femtocell users based on the fedback macrocell's load margin so as to keep, on average, the macrocell load below a certain threshold. Second, CTRL determines the target SINRs of femtocell users, conditioned on the maximum TX power, to reach a Nash equilibrium based on their utility functions, thus achieving efficient coordination of uplink usage among femtocells. Third, for protection of femtocell users' uplink communications, the instantaneous TX power of each femtocell user is controlled to achieve the target SINR against bursty interference from nearby macrocell or femtocell users.
Ji-Hoon Yun, Kang G. Shin
MobiCom2
2010 Managing TCP Connections in Dynamic Spectrum Access Based Wireless LANs
abstract
Wireless LANs have been widely deployed as edge access networks in home/office/commercial buildings, providing connection to the Internet. Therefore, performance of end-to-end connections to/from such WLANs is of great importance to network applications and end-users. The advent of Dynamic Spectrum Access (DSA) technology is expected to play a major role in improving wireless communication. With DSA enabled, WLANs opportunistically access licensed channels in order to enhance spectrum-usage efficiency, and provide better network performance. In this paper, we explore issues and solutions in realizing this potential of DSA. We first identify the key issues that impact end-to-end TCP performance when a DSA-enabled WLAN is integrated with the wired cloud. Then, we propose a new network management framework, called DSASync, to eliminate or mitigate the performance issues we identified. DSASync requires no modifications to the fixed wired network or existing network stack, while ensuring traditional TCP semantics to be obeyed. DSASync uses a combination of buffering and traffic-shaping algorithms to minimize the adverse side-effects of DSA on the TCP flows. Finally, we evaluate DSASync through a prototype implementation and deployment in a testbed. The results show significant improvements in TCP performance, e.g., a 74 increase in downlink goodput, making it a promising step forward towards applying DSA technology in consumer WLANs.
Kang G. Shin
SECON2
2010 LiteGreen: Saving Energy in Networked Desktops Using Virtualization
Tathagata Das, Pradeep Padala, Venkat N. Padmanabhan, Ramachandran Ramjee, Kang G. Shin
USENIX ATC5
2010 Integration of Collaborative Analyses for Development of Embedded Control Software
abstract
Model-based methodologies have been widely used to handle the increasing demand for rapid development of high-quality, real-time embedded control software. A key challenge in such model-based design is integration of various “collaborative” analysis methods to support the automation of the design process. Traditional analysis methods developed for analyzing specific system properties, however, are not designed for such integration, and thus cannot ensure that the information for the analysis will be provided at the design stage where the information is needed. Moreover, many traditional analysis methods depend heavily on complete and accurate design models which can only be applied to post-design verification and are unavailable for automation of the design process involving an early design stage, where implementation details are unknown. This challenge can be met by integrating analysis methods with the design process. We have developed such a framework combined with software modeling, execution platform configuration, and run-time monitoring mechanisms to enable accurate assessment of embedded software quality at early design stages. We have implemented and demonstrated the framework with a toolkit, called AIRES, that integrates software models, a virtual execution platform, and timing and schedulability analysis methods.
Sangsoo Park, Kang G. Shin, Shige Wang
Proc. IEEE2
2010 On predictive routing of security contexts in an all-IP network
abstract
Abstract While mobile nodes (MNs) undergo handovers across inter‐wireless access networks, their security contexts must be propagated for secure re‐establishment of on‐going application sessions, such as those in secure mobile internet protocol (IP), authentication, authorization, and accounting (AAA) services. Routing security contextsviaan IP network either on‐demand or based on MNs' mobility prediction, imposes new challenging requirements of securecross‐handoverservices and security context management. In this paper, we present acontext router(CXR) that manages security contexts in an all‐IP network, providing seamless and secure handover services for the mobile users that carry multimedia‐access devices. A CXR is responsible for (1) monitoring of MNs' cross‐handover, (2) analysis of MNs' movement patterns, and (3) routing of security contexts ahead of MNs' arrival at relevant access points. The predictive routing reduces the delay in the underlying security association that would otherwise fetch an involved security context from a remote server. The predictive routing of security contexts is performed based on statistical learning of MNs' movement pattern, gauging (dis)similarities between the patterns obtainedviadistance measurements. The CXR has been evaluated with a prototypical implementation based on an MN mobility model on a grid. Our evaluation results support the predictive routing mechanism's improvement in seamless and secure cross‐handover services by a factor of 2.5. Also, the prediction mechanism is shown to outperform the Kalman filter‐based method [13] as a Kalman Fiter‐based mechanism up to 1.5 and 3.6 times regarding prediction accuracy and computation performance, respectively. Copyright © 2009 John Wiley & Sons, Ltd.
Hahnsang Kim, Kang G. Shin
Secur. Commun. Networks2
2010 Maximum Achievable Throughput in Multiband Multiantenna Wireless Mesh Networks
abstract
We have recently witnessed a rapidly increasing demand for, and hence, a shortage of, wireless network bandwidth due to rapidly growing wireless services and applications. It is, therefore, important to develop an efficient way of utilizing this limited bandwidth resource. Fortunately, recent technological advances have enabled software-defined radios (SDRs) to switch from one frequency band to another at minimum cost, thereby making dynamic multiband access and sharing possible. On the other hand, recent advances in signal processing combined with those in antenna technology provide multiple-input multiple-output (MIMO) capabilities, thereby creating opportunities for enhancing the throughput of wireless networks. Both SDRs and MIMO together enable next-generation wireless networks, such as mesh networks, to support dynamic and adaptive bandwidth sharing along time, frequency, and space. In this paper, we develop a new framework that 1) identifies the limits and potential of SDRs and MIMO in terms of achievable network throughput and 2) provides guidelines for designers to determine the optimal parameters of wireless mesh networks equipped with multiband and multiantenna capabilities.
Bechir Hamdaoui, Kang G. Shin
IEEE Trans. Mob. Comput.2
2010 In-Band Spectrum Sensing in IEEE 802.22 WRANs for Incumbent Protection
abstract
In cognitive radios, in-band spectrum sensing is essential for the protection of legacy spectrum users, enabling secondary users to vacate channels immediately upon detection of primary users. For in-band sensing, it is important to meet detectability requirements, such as the maximum allowed detection latency and the probability of misdetection and false alarm. In this paper, we propose key techniques for efficient in-band sensing. We first advocate the use of clustered sensor networks, and propose a periodic in-band sensing algorithm that optimizes sensing period and sensing time to meet the detectability requirements while minimizing sensing overhead. The scheme also determines the better of energy or feature detection incurring less sensing overhead at each SNR level, and derives the threshold aRSSthresholdon the average received signal strength of a primary signal above which energy detection is preferred to feature detection. We consider two key factors affecting aRSSthresholdnoise uncertainty and inter-CRN interference. aRSSthresholdappears to lie between -114.6 dBm and -109.9 dBm with noise uncertainty ranging from 0.5 dB to 2 dB, and between -112.9 dBm and -110.5 dBm with 1-6 interfering CRNs. We also investigate how strict the detection requirement must be for efficient reuse of idle channels without incurring unnecessary channel switches due to false detection of primaries.
Hyoil Kim, Kang G. Shin
IEEE Trans. Mob. Comput.2
2010 Geometry-based optimal power control of fading multiple access channels for maximum sum-rate in cognitive radio networks
abstract
In this letter, a power-control scheme for maximum sum-rate is proposed for the fading multiple access channels by considering the presence of primary users. Both the average transmit-power constraints and the peak interference-temperature constraints are considered. The interference caused by cognitive users must be under a pre-specified threshold for protecting primary users. The power-control optimization is considered as a novel geometrical problem which investigates the relationship of positions of a line and a few points. At most two users transmit simultaneously for optimality and the corresponding conditions are provided for both cases. Based on the analysis, the optimal power control is given for each specific fading state. For lowering computational complexity, the power-control optimization problem is divided into two categories according to different tight constraints. Simulation results are provided for the optimal power-control performance.
Wei Wang 0021, Wenbo Wang 0007, Qianxi Lu, Kang G. Shin, Tao Peng 0001
IEEE Trans. Wirel. Commun.4
2009 Large-scale malware indexing using function-call graphs
abstract
A major challenge of the anti-virus (AV) industry is how to effectively process the huge influx of malware samples they receive every day. One possible solution to this problem is to quickly determine if a new malware sample is similar to any previously-seen malware program. In this paper, we design, implement and evaluate a malware database management system called SMIT (Symantec Malware Indexing Tree) that can efficiently make such determination based on malware's function-call graphs, which is a structural representation known to be less susceptible to instruction-level obfuscations commonly employed by malware writers to evade detection of AV software. Because each malware program is represented as a graph, the problem of searching for the most similar malware program in a database to a given malware sample is cast into a nearest-neighbor search problem in a graph database. To speed up this search, we have developed an efficient method to compute graph similarity that exploits structural and instruction-level information in the underlying malware programs, and a multi-resolution indexing scheme that uses a computationally economical feature vector for early pruning and resorts to a more accurate but computationally more expensive graph similarity function only when it needs to pinpoint the most similar neighbors. Results of a comprehensive performance study of the SMIT prototype using a database of more than 100,000 malware demonstrate the effective pruning power and scalability of its nearest neighbor search mechanisms.
Xin Hu 0001, Tzi-cker Chiueh, Kang G. Shin
CCS3
2009 Automated control of multiple virtualized resources
abstract
Virtualized data centers enable sharing of resources among hosted applications. However, it is difficult to satisfy service-level objectives(SLOs) of applications on shared infrastructure, as application workloads and resource consumption patterns change over time. In this paper, we present AutoControl, a resource control system that automatically adapts to dynamic workload changes to achieve application SLOs. AutoControl is a combination of an online model estimator and a novel multi-input, multi-output (MIMO) resource controller. The model estimator captures the complex relationship between application performance and resource allocations, while the MIMO controller allocates the right amount of multiple virtualized resources to achieve application SLOs. Our experimental evaluation with RUBiS and TPC-W benchmarks along with production-trace-driven workloads indicates that AutoControl can detect and mitigate CPU and disk I/O bottlenecks that occur over time and across multiple nodes by allocating each resource accordingly. We also show that AutoControl can be used to provide service differentiation according to the application priorities during resource contention.
Pradeep Padala, Kai-Yuan Hou, Kang G. Shin, Xiaoyun Zhu, Mustafa Uysal, Zhikui Wang, Sharad Singhal, Arif Merchant
EuroSys3
2009 A Case Study of QoS Provisioning in TV-Band Cognitive Radio Networks
abstract
Dynamic Spectrum Access (DSA) MAC protocols allow a Cognitive Radio (CR) device to opportunistically access unused or less crowded spectrum while ensuring protection for the incumbents. Though DSA shows great potential to enhance spectrum efficiency, the associated constraints on QoS may limit its usefulness. QoS support in a DSA-based network is not trivial due to the fact that in addition to unfavorable characteristics of the wireless medium, the secondary devices are subject to additional interference and interruption from incumbents. In this paper, we present a case-study of key QoS provisioning techniques in DSA protocol design that facilitate the required application QoS. Specifically, we consider a CR system that supports high quality multimedia (including HDTV) streaming over UHF frequency bands. We model and evaluate the QoS- oriented CR system together with the underlying QoS-Provisioned DSA Protocol (referred as QPDP) through extensive simulations. The results show the effectiveness of DSA coupled with QoS provisioning, in supporting QoS-demanding consumer- oriented network applications in TV bands. This outcome is significant as FCC has recently approved UHF bands for unlicensed operations in the second Report and Order in the USA, and various DSA-based personal/portable CR systems are being actively considered by the consumer wireless industry.
Kang G. Shin, Kiran S. Challapali
ICCCN2
2009 Attack-Tolerant Distributed Sensing for Dynamic Spectrum Access Networks
abstract
Accurate sensing of the spectrum condition is of crucial importance to the mitigation of the spectrum scarcity problem in dynamic spectrum access (DSA) networks. Specifically, distributed sensing has been recognized as a viable means to enhance the incumbent signal detection by exploiting the diversity of sensors. However, it is challenging to make such distributed sensing secure due mainly to the unique features of DSA networks - openness of a low-layer protocol stack in SDR devices and non-existence of communications between primary and secondary devices. To address this challenge, we propose attack-tolerant distributed sensing protocol (ADSP), under which sensors in close proximity are grouped into a cluster, and sensors in a cluster cooperatively safeguard distributed sensing. The heart of ADSP is a novel shadow fading correlation-based filter tailored to anomaly detection, by which the fusion center prefilters abnormal sensor reports via cross-validation. By realizing this correlation filter, ADSP minimizes the impact of an attack on the performance of distributed sensing, while incurring minimal processing and communications overheads. The efficacy of our scheme is validated on a realistic two-dimensional shadow-fading field, which accurately approximates real-world shadowing environments. Our extensive simulation-based evaluation shows that ADSP significantly reduces the impact of attacks on incumbent detection performance.
Alexander W. Min, Kang G. Shin, Xin Hu 0001
ICNP2
2009 Predictive routing of contexts in an overlay network
abstract
While mobile nodes (MNs) undergo handovers across inter-wireless access networks, their contexts must be propagated for seamless re-establishment of on-going application sessions, including IP header compression, secure Mobile IP, authentication, authorization, and accounting services, to name a few. Routing contexts via an overlay network either on-demand or based on prediction of an MNs' mobility, introduces a new challenging requirement of context management. This paper proposes a context router (CXR) that manages contexts in an overlay network. A CXR is responsible for (1) monitoring of MNs' cross-handover, (2) analysis of MNs' movement patterns, and (3) context routing ahead of each MN's arrival at an AP or a network. The predictive routing of contexts is performed based on statistical learning of (dis)similarities between the patterns obtained from vector distance measurements. The proposed CXR has been evaluated on a prototypical implementation based on an MN mobility model in an emulated access network. Our evaluation results show that the prediction mechanisms applied on the CXR outperform a Kalman-filter-based method [34] with respect to both prediction accuracy and computation performance.
Hahnsang Kim, Kang G. Shin
Integrated Network Management2
2009 RB-Seeker: Auto-detection of Redirection Botnets
Xin Hu 0001, Matthew Knysz, Kang G. Shin
NDSS3
2009 On Dynamic Reconfiguration of a Large-Scale Battery System
abstract
Electric vehicles powered with large-scale battery packs are gaining popularity as gasoline price soars. Large-scale battery packs usually consist of an estimated 12,000 battery cells connected in series and parallel, which are susceptible to battery-cell failures. Unfortunately, current battery-management systems are unable to handle the inevitable battery-cell failures very well. To address this problem, we propose a dynamic reconfiguration framework that monitors, reconfigures, and controls large-scale battery packs online. The framework is built upon a syntactic bypassing mechanism that provides a set of rules for changing the battery-pack configuration, and a semantic bypassing mechanism by which the battery-cell connectivity is reconfigured to recover from a battery-cell failure. In particular, the semantic bypassing mechanism is dictated by constant-voltage-keeping and dynamic-voltage-allowing policies. The former policy is effective in preventing unavoidable voltage drops during the battery discharge, while the latter policy is effective in supplying different amounts of power to meet a wide-range of application requirements. Our experimental evaluation has shown the proposed framework to enable the battery packs to be 9 times as fault-tolerant as a legacy scheme.
Hahnsang Kim, Kang G. Shin
IEEE Real-Time and Embedded Technology and Applications Symposium2
2009 Post-Deployment Performance Debugging in Wireless Sensor Networks
abstract
When an application on a wireless sensor network (WSN) exhibits poor post-deployment performance, users (programmers and administrators) usually do not know which nodes in the network, nor which pieces of debugging information are relevant to the determination of causes of the performance problem. Blind logging and collection of information on all nodes and/or links for the purpose of debugging, however, are energy expensive and sometimes ineffective. To address this problem, we need algorithms and tools that help users pinpoint the causes of application performance problems, and then provide useful hints for fixing them or further examination. To meet this need, we propose a data-centric approach called post-deployment performance debugging (PD2). PD2 focuses on the data flows that an application generates, and relates poor application performance to significant data losses or latencies of some data flows (problematic data flows) as they go through the software modules on individual nodes and through the network. PD2 derives a few inference rules based on the data dependencies between different software modules, as well as between different nodes, and use them to trace back in each problematic flow. Then, PD2 turns on the performance monitoring of, and collects debugging information from, only those modules and nodes that the problematic flows go through. Finally, PD2 provides the debugging information to help users isolate the causes of poor performance. We have implemented PD2 on TinyOS and evaluated it on a real WSN testbed. Our experimental results show that PD2 helps users quickly locate the possible sources of problems, such as code bugs, weak links, and radio interference. Depending on the hop-count between the source of the problem and the data sink, PD2's energy consumption (communication overhead) is shown to be only 5-10% of that of collecting debugging information from all nodes.
Zhigang Chen 0004, Kang G. Shin
RTSS2
2009 Scheduling of Battery Charge, Discharge, and Rest
abstract
Electric vehicles operate inefficiently with a naive battery management system that charges or discharges battery cells in a pack based solely on application load demands. The battery pack's operation-time and lifetime can be extended significantly by effectively scheduling (the cyber part) battery charge, discharge, and rest activities, based on the battery characteristics (the physical part). We propose a set of policies for scheduling battery-cell activities, called the weighted-k round-robin (kRR) scheduling framework. This framework dynamically adapts battery-cell activities to load demands and the condition of individual cells, thereby extending the battery pack's operation-time and making them robust to anomalous voltage-imbalances. The framework comprises two key components. First, an adaptive filter estimates the upcoming load demand. Then, based on the estimated load demand, the kRR scheduler determines the number of parallel-connected cells to be discharged simultaneously. The scheduler also effectively partitions the cells in the pack, allowing the cells to be simultaneously charged and discharged in coordination with the battery reconfiguration system we developed earlier [17]. Besides the kRR scheduling framework, we characterize the discharge and recovery efficiency of a Lithium-ion battery cell. The kRR scheduling framework is shown to outperform three alternative scheduling mechanisms with respect to the operation-time by 7-56%, and improve the tolerance of voltage-imbalance by up to 50%.
Hahnsang Kim, Kang G. Shin
RTSS2
2009 Optimal Admission and Eviction Control of Secondary Users at Cognitive Radio HotSpots
abstract
Cognitive radio (CR) HotSpot is a typical example of commercialized dynamic spectrum access (DSA) in which a wireless service provider (WSP) provides CR end-users access to its local-area network. A WSP temporarily leases licensed channels from the primary licensees via spectrum auction, and subleases them to CR end-users or customers, each demanding a different amount of spectrum, according to its own advertised pricing policy. The CR customers use the subleased channels opportunistically when the channels are not being used by primary/legacy users, and hence, the amount of available spectrum resource varies with time. A WSP should, therefore, maximize its average profit by 'optimally' (in some sense) (1) controlling the admission/rejection of arriving CR end-users, and (2) determining a policy of evicting in-service opportunistic users at the channel to which primary users return. To our best knowledge, this is the first attempt to jointly optimize admission and eviction controls for the dynamic spectrum market. The WSP's profit maximization problem is formulated with a semi-Markov decision process (SMDP) and its corresponding linear programming (LP) setup. This problem is found to become nonlinear programming (NLP) subject to two quality-of-service (QoS) constraints on request-blocking and user-dropping probabilities, which can fortunately be converted to LP via some manipulation. Using an extensive numerical analysis, we discovered that the derived optimal policy achieves up to 81% more profit than a complete-sharing (CS) algorithm in the tested scenario. We also investigate tradeoffs between the two QoS constraints, and consider other important factors affecting WSP's profit maximization such as the number of leased channels, the end-user pricing, and the cost for reimbursing evicted customers.
Hyoil Kim, Kang G. Shin
SECON2
2009 An Optimal Sensing Framework Based on Spatial RSS-profile in Cognitive Radio Networks
abstract
In cognitive radio networks (CRNs), regulatory bodies, such as the FCC, enforce an extremely demanding detectability requirement to protect primary users' communications, which can hardly be achieved with one-time sensing using only a single sensor. Most of the previous work focused on either cooperative sensing or sensing scheduling as a viable means to improve the detection performance without studying their interactions. In this paper, we propose an optimal spectrum sensing framework in CRNs that jointly exploits sensors' cooperation and sensing scheduling to meet the desired detection performance with minimum sensing overhead. Specifically, we propose an optimal sensing framework for the IEEE 802.22 wireless regional area networks (WRANs) that directs the base station (BS) to manage spectrum sensing by (i) constructing each primary signal's spatial profile of received signal strengths (RSSs) as a detection criterion, (ii) selecting an optimal set of sensors for cooperative sensing, and (iii) finding an optimal time to stop sensing. This framework will ensure the desired sensing performance of 802.22 with minimum sensing overhead. Our evaluation results show that the proposed sensing algorithms reduce the sensing overhead significantly and lower the feasible operation region of energy detector by 13 dB for practical scenarios.
Alexander W. Min, Kang G. Shin
SECON2
2009 Throughput Behavior in Multihop Multiantenna Wireless Networks
abstract
Multiantenna or MIMO systems offer great potential for increasing the throughput of multihop wireless networks via spatial reuse and/or spatial multiplexing. This paper characterizes and analyzes the maximum achievable throughput in multihop, MIMO-equipped, wireless networks under three MIMO protocols, spatial reuse only (SRP), spatial multiplexing only (SMP), and spatial reuse and multiplexing (SRMP), each of which enhances the throughput, but via a different way of exploiting MIMO's capabilities. We show via extensive simulation that as the number of antennas increases, the maximum achievable throughput first rises and then flattens out asymptotically under SRP, while it increases "almost" linearly under SMP or SRMP. We also evaluate the effects of several network parameters on this achievable throughput, and show how throughput behaves under these effects.
Bechir Hamdaoui, Kang G. Shin
IEEE Trans. Mob. Comput.2
2009 On accurate and asymmetry-aware measurement of link quality in wireless mesh networks
Kyu-Han Kim, Kang G. Shin
IEEE/ACM Trans. Netw.2
2008 On the Achievable Throughput of Multi-Band Multi-Antenna Wireless Mesh Networks
abstract
Recent technological advances have enabled SDRs to switch from one frequency to another at low cost, thus making dynamic multi-band access possible. On the other hand, recent advances in signal processing combined with those in antenna technology provide MIMO capabilities, thereby creating opportunities for enhancing the throughput of wireless networks. Both SDRs and MIMO together enable next-generation wireless networks, such as wireless mesh networks, to support dynamic and adaptive bandwidth sharing along time, frequency, and space. In this paper, we develop a new framework that identifies the limits and potentials of SDRs and MIMO. We characterize and analyze the maximum throughput that wireless networks can achieve when they are SDR-capable and MIMO-equipped.
Bechir Hamdaoui, Kang G. Shin
GLOBECOM2
2008 Power-Adjusted Random Access to a Wireless Channel
abstract
The operation of widely-deployed random access to wireless networks is based on limited information on the result of each access attempt. When making a random access attempt, users usually do not know the exact amount of transmit power to make it successful. Also, upon failure of a transmission attempt, a user cannot tell whether the failure was caused by collision with other simultaneously-transmitting users or by his use of insufficient transmit power. To handle lack of information on the cause of failure, we propose an innovative Cause-of-Failure (CoF) resolution which increases the transmit power after a given number of consecutive unsuccessful access attempts when the probability that a given failure is caused by collision becomes sufficiently low. To exploit the thus-achieved transmit power for the next random access attempt, we also determine the Cause-of-Success (CoS) based on the number of consecutive successful attempts, i.e., whether to decrease or maintain the present transmit power probabilistically. This way, users can adjust their transmit power for random access, which we call Auto Power Fallback (APF). We evaluate APF by modeling analysis and numerical computation based on the slotted Aloha, showing that APF makes significant energy-savings for uplink random accesses while achieving good performance.
Young-June Choi, Kang G. Shin
INFOCOM2
2008 Attack-Tolerant Time-Synchronization in Wireless Sensor Networks
abstract
Achieving secure time-synchronization in wireless sensor networks (WSNs) is a challenging, but very important problem that has not yet been addressed effectively. This paper proposes an attack-tolerant time-synchronization protocol (ATSP) in which sensor nodes cooperate to safeguard the time- synchronization service against malicious attacks. ATSP exploits the high temporal correlation existing among adjacent nodes in a WSN to achieve (1) adaptive management of the profile of each sensor's normal behavior, (2) distributed, cooperative detection of falsified clock values advertised by attackers or compromised nodes, and (3) significant improvement of synchronization accuracy and stability by effectively compensating the clock drifts with the calibrated clock. To reduce the risk of losing time-synchronization due to attacks on the reference node, ATSP utilizes distributed, mutual synchronization and confines the impact of attacks to a local area (where attacks took place). Furthermore, by maintaining an accurate profile of sensors' normal synchronization behaviors, ATSP detects various critical attacks while incurring only reasonable communication and computation overheads, making ATSP attack-tolerant and ideal for resource-constrained WSNs.
Xin Hu 0001, Taejoon Park, Kang G. Shin
INFOCOM3
2008 Exploiting Multi-Channel Diversity in Spectrum-Agile Networks
abstract
Recently, spectrum-agile (SA) networks have been recognized as a viable solution to the spectrum-scarcity problem in spectrum-scarcity problem. In SA networks, secondary (unlicensed) users are allowed to opportunistically utilize idle licensed spectrum bands, thus improving spectrum utilization efficiency and accommodating more users and applications. We take a two- step approach to the problem of maximizing the throughput of an SA network. The first step is to determine a subset of "candidate" channels that a secondary device will consider for its channel-switching. The candidate channels are selected based on their estimated utilization. We then propose channel-aware switching to determine when and where to switch to, among the candidate channels. Wireless channels are assumed to experience independent Rayleigh fading, and modeled with a finite-state Markov channel (FSMC) model. Our evaluation results show that the proposed channel-aware switching scheme significantly outperforms the traditional forced-switching scheme in terms of average throughput.
Alexander W. Min, Kang G. Shin
INFOCOM2
2008 In-band spectrum sensing in cognitive radio networks: energy detection or feature detection?
abstract
In a cognitive radio network (CRN), in-band spectrum sensing is essential for the protection of legacy spectrum users, with which the presence of primary users (PUs) can be detected promptly, allowing secondary users (SUs) to vacate the channels immediately. For in-band sensing, it is important to meet the detectability requirements, such as the maximum allowed latency of detection (e.g., 2 seconds in IEEE 802.22) and the probability of mis-detection and false-alarm. In this paper, we propose an effcient periodic in-band sensing algorithm that optimizes sensing-frequency and sensing-time by minimizing sensing overhead while meeting the detectability requirements. The proposed scheme determines the better of energy or feature detection that incurs less sensing overhead at each SNR level, and derives the threshold aRSSthreshold on the average received signal strength (RSS) of a primary signal below which feature detection is preferred. We showed that energy detection under lognormal shadowing could still perform well at the average SNR < SNRwall [1] when collaborative sensing is used for its location diversity. Two key factors affecting detection performance are also considered: noise uncertainty and inter-CRN interference. aRSSthreshold appears to lie between -114.6 dBm and -109.9 dBm with the noise uncertainty ranging from 0.5 dB to 2 dB, and between -112.9 dBm and -110.5 dBm with 1~6 interfering CRNs.
Hyoil Kim, Kang G. Shin
MobiCom2
2008 Behavioral detection of malware on mobile handsets
abstract
A novel behavioral detection framework is proposed to detect mobile worms, viruses and Trojans, instead of the signature-based solutions currently available for use in mobile devices. First, we propose an efficient representation of malware behaviors based on a key observation that the logical ordering of an application's actions over time often reveals the malicious intent even when each action alone may appear harmless. Then, we generate a database of malicious behavior signatures by studying more than 25 distinct families of mobile viruses and worms targeting the Symbian OS - the most widely-deployed handset OS - and their variants. Next, we propose a two-stage mapping technique that constructs these signatures at run-time from the monitored system events and API calls in Symbian OS. We discriminate the malicious behavior of malware from the normal behavior of applications by training a classifier based on Support Vector Machines (SVMs). Our evaluation on both simulated and real-world malware samples indicates that behavioral detection can identify current mobile viruses and worms with more than 96% accuracy. We also find that the time and resource overheads of constructing the behavior signatures from low-level API calls are acceptably low for their deployment in mobile devices.
Abhijit Bose, Xin Hu 0001, Kang G. Shin, Taejoon Park
MobiSys3
2008 Detecting energy-greedy anomalies and mobile malware variants
abstract
Mobile users of computation and communication services have been rapidly adopting battery-powered mobile handhelds, such as PocketPCs and SmartPhones, for their work. However, the limited battery-lifetime of these devices restricts their portability and applicability, and this weakness can be exacerbated by mobile malware targeting depletion of battery energy. Such malware are usually difficult to detect and prevent, and frequent outbreaks of new malware variants also reduce the effectiveness of commonly-seen signature-based detection. To alleviate these problems, we propose a power-aware malware-detection framework that monitors, detects, and analyzes previously unknown energy-depletion threats. The framework is composed of (1) a power monitor which collects power samples and builds a power consumption history from the collected samples, and (2) a data analyzer which generates a power signature from the constructed history. To generate a power signature, simple and effective noise-filtering and data-compression are applied, thus reducing the detection overhead. Similarities between power signatures are measured by the χ2-distance, reducing both false-positive and false-negative detection rates. According to our experimental results on an HP iPAQ running a Windows Mobile OS, the proposed framework achieves significant (up to 95%) storage-savings without losing the detection accuracy, and a 99% true-positive rate in classifying mobile malware.
Hahnsang Kim, Kang G. Shin
MobiSys3
2008 OPAG: Opportunistic Data Aggregation in Wireless Sensor Networks
abstract
We proposeOpportunisticDataAggregation(OPAG) that incurs no computation error and tolerates moderate message losses in wireless sensor networks (WSNs). OPAG performs in-network data aggregation in two layers: (1) at the data-aggregation layer, aggregation results are computed accurately; and (2) at the data-routing layer,a WSN node may send intermediate/partial results to its aggregation node using multi-path routing in order to tolerate message losses.By space-multiplexing messages (i.e., padding multiple partial results or sensor readings in a single message), OPAG opportunistically exploits a multi-path routing scheme, which is more energy-efficient than retransmission. This is based on a key observation that, when sending a message, the radio may consume much more energy in idle listening during the backoff period and the time to wait for its acknowledgment than transmitting the data bits.We implemented OPAG on TinyOS 2.x and TMote Sky Mote, and evaluated its performance on the Motelab Testbed at Harvard University.When a network is relatively well connected, OPAG can reduce the energy consumption by 33% at the expense of slightly higher relative errors, compared to TAG with reliable transmission.Compared to synopsis diffusion, OPAG can reduce the aggregation errors by 50% while consuming roughly the same amount of energy.
Zhigang Chen 0004, Kang G. Shin
RTSS2
2008 An Optimal Transmission Strategy for IEEE 802.11 Wireless LANs: Stochastic Control Approach
abstract
The family of IEEE 802.11 Wireless Local Area Network (WLAN) standards supports multiple transmission rates in the physical layer (PHY). This multi-rate capability offers a viable means of coping with dynamically-fluctuating wireless channel conditions. We propose a cross-layer approach for the optimal PHY mode control to maximize the system goodput. Our key idea is to exploit the underlying channel fading characteristics and the history of PHY mode control and observations to infer the current channel condition, so that the optimal PHY mode may be selected. Assuming Rayleigh fading, we describe the receiver-side signal-to-noise ratio (SNR) fluctuations as a finite-state Markov channel (FSMC) model. Since the channel condition (i.e., fading level) is not directly observable by the transmitter, we formulate the PHY rate adaptation problem as a partially-observable Markov decision process (POMDP) to find the optimal transmission policy. We use the belief state vector to represent the channel state probabilistically. The belief state is updated solely based on the channel state-transition matrix and acknowledgement (ACK) information. Our evaluation results show that the POMDP-based rate adaptation outperforms two most well-known rate adaptation schemes, Auto Rate Fallback (ARF) and Adaptive ARF (AARF), in terms of average goodput under various fading conditions, and achieves up to 92% of the ideal performance.
Alexander W. Min, Kang G. Shin
SECON2
2008 On capturing malware dynamics in mobile power-law networks
abstract
The increasing convergence of power-law networks such as social networking and peer-to-peer sites, web applications and mobile platforms makes today's users highly vulnerable to entirely new generations of malware that exploit vulnerabilities in web applications and mobile platforms for new infections, while using the power-law connectivity for finding new victims. The traditional epidemic models based on assumptions of homogeneity, averagedegree distributions, and perfect-mixing are inadequate to model this type of malware propagation. In this paper, we study three aspects crucial to modeling malware propagation in such environments: application-level interactions among users of such networks, local network structure, and user mobility.Since closed-form solutions of malware propagation in such environments are difficult to obtain, we describe an open-source, flexible agent-based emulation framework that can be used by malware researchers for studying today's complex malware. The framework, called Agent-Based Malware Modeling (AMM), allows different applications, network structure and user mobility in either a geographic or a logical domain to study various infection and propagation scenarios. The majority of the parameters used in the framework can be derived from real-life network traces collected from these networks, and therefore, represent realistic malware propagation and infection scenarios. As representative examples, we examine two well-known malware spreading mechanisms: (i) a malicious virus such as Cabir spreading among the subscribers of a cellular network using Bluetooth, and (ii) a hybrid worm that exploit email and file-sharing to infect users of a social network. In both cases, we identify the parameters most important to the spread of the epidemic based upon our extensive simulation results.
Abhijit Bose, Kang G. Shin
SecureComm2
2008 ARCMA: attack-resilient collaborative message authentication in wireless sensor networks
abstract
Data Centric Storage (DCS) is a well-known data storage and query processing mechanism for Wireless Sensor Networks (WSNs), storing sensed data or their metadata at pre-specified locations. Queries issued by mobile users are sent to, and processed at, such storage nodes. However, securing DCS is very difficult because WSNs usually operate in an unattended environment and hence are subject to node-capture attacks. Even after capturing a single node, an attacker may be able to subvert the entire system by using the keying material extracted from the captured node.
Min Gyu Cho, Kang G. Shin
SecureComm2
2008 Containment of network worms via per-process rate-limiting
abstract
Network worms pose a serious threat to the Internet infrastructure as well as end-users. Various techniques have been proposed for detection of, and response against worms. A frequently-used and automated response mechanism is to rate-limit outbound worm traffic while maintaining the operation of legitimate applications, offering a gentler alternative to the usual detect-and-block approach. However, most rate-limiting schemes to date only focus on host-level network activities and impose a single threshold on the entire host, failing to (i) accommodate network-intensive applications and (ii) effectively contain network worms at the same time. To alleviate these limitations, we propose a per-process-based containment framework in each host that monitors the fine-grained runtime behavior of each process and accordingly assigns the process a suspicion level generated by a machine-learning algorithm. We have also developed a heuristic to optimally map each suspicion level to the rate-limiting threshold. The framework is shown to be effective in containing network worms and allowing the traffic of legitimate programs, achieving lower false-alarm rates.
Xin Hu 0001, Haixiong Wang, Kang G. Shin, Abhijit Bose
SecureComm4
2008 Using hypervisor to provide data secrecy for user applications on a per-page basis
abstract
Hypervisors are increasingly utilized in modern computer systems, ranging from PCs to web servers and data centers. Aside from server applications, hypervisors are also becoming a popular target for implementing many security systems, since they provide a small and easy-to-secure trusted computing base. This paper presents a novel way of using hypervisors to protect application data privacy even when the underlying operating system is not trustable. Each page in virtual address space is rendered to user applications according to the security context the application is running in. The hypervisor encrypts and decrypts each memory page requested depending on the application's access permission to the page. The main result of this system is the complete removal of the operating system from the trust base for user applications' data privacy. To reduce the runtime overhead of the system, two optimization techniques are employed. We use page-frame replication to reduce the number ofcryptographic operations by keeping decrypted versions of a page frame. We also employ lazy synchronization to minimize overhead due to an update to one of the replicated page frame. Our system is implemented and evaluated by modifying the Xen hypervisor, showing that it increases the application execution time only by 3% for CPU and memory-intensive workloads.
Jisoo Yang, Kang G. Shin
VEE2
2008 Energy-conservation in 802.11 WLANs via transmission-strategy-aware airtime allocation
Daji Qiao, Kang G. Shin, Zakhia G. Abichar
Comput. Networks2
2008 Secure routing based on distributed key sharing in large-scale sensor networks
abstract
Sensor networks, usually built with a large number of small, low-cost sensor nodes, are characterized by their large-scale and unattended deployment, necessitating “secur ” communications between nearby, as well as remote, sensor nodes for their intended applications and services. Key setup/sharing is crucial to the protection of such applications/services from attacks, but existing (public-key, cluster-based, or pairwise) solutions become too expensive (hence, inefficient) when the underlying applications/services require communications between distant sensor nodes. To remedy this inefficiency, we propose a novel distributed key-sharing scheme, in which each participating sensor node shares unique keys with a small number of other sensor nodes—called distributed key servers (DKSs)—chosen according to their geographic distance and communication direction. Using DKSs, we develop two secure routing protocols: (1) secure geographic forwarding that delivers packets by using a chain of DKS lookups, each secured with its own key and forwarded geographically; and (2) key establishment that creates a secure session between two distant sensor nodes based solely on symmetric-ciphers. These protocols enable low-cost, low-power sensors to provide high-level security at a very low cost.
Taejoon Park, Kang G. Shin
ACM Trans. Embed. Comput. Syst.2
2008 Attack-tolerant localization via iterative verification of locations in sensor networks
abstract
In sensor networks, secure localization—determining sensors' locations in a hostile, untrusted environment—is a challenging, but very important, problem that has not yet been addressed effectively. This paper presents an attack-tolerant localization protocol, called Verification for Iterative Localization (VeIL), under which sensors cooperatively safeguard the localization service. By exploiting the high spatiotemporal correlation existing between adjacent nodes, VeIL realizes (a) adaptive management of a profile for normal localization behavior, and (b) distributed detection of false locations advertised by attackers by comparing them against the profile of normal behavior. Our analysis and simulation results show that VeIL achieves high-level tolerance to many critical attacks, and is computationally feasible on resource-limited sensors.
Taejoon Park, Kang G. Shin
ACM Trans. Embed. Comput. Syst.2
2008 Distributed Authentication of Program Integrity Verification in Wireless Sensor Networks
abstract
Security in wireless sensor networks has become important as they are being developed and deployed for an increasing number of applications. The severe resource constraints in each sensor make it very challenging to secure sensor networks. Moreover, sensors are usually deployed in hostile and unattended environments and hence are susceptible to various attacks, including node capture, physical tampering, and manipulation of the sensor program. Park and Shin [2005] proposed a soft tamper-proofing scheme that verifies the integrity of the program in each sensor device, called the program integrity verification (PIV), in which sensors authenticate PIV servers (PIVSs) using centralized and trusted third-party entities, such as authentication servers (ASs). This article presents a distributed authentication protocol of PIVSs (DAPP) without requiring the commonly used ASs. DAPP uses the Blundo scheme [Blundo et al. 1992] for sensors and PIVSs to establish pairwise keys and for PIVSs to authenticate one another. We also present a protocol for PIVSs to cooperatively detect and revoke malicious PIVSs in the network. We implement and evaluate both DAPP and PIV on Mica2 Motes and laptops, showing that DAPP reduces the sensors' communication traffic in the network by more than 90% and the energy consumption on each sensor by up to 85%, as compared to the case of using a centralized AS for authenticating PIVSs. We also analyze the security of DAPP under various attack models, demonstrating its capability in dealing with diverse types of attacks.
Katharine Chang, Kang G. Shin
ACM Trans. Inf. Syst. Secur.2
2008 OS-MAC: An Efficient MAC Protocol for Spectrum-Agile Wireless Networks
abstract
Wireless networks and devices have been rapidly gaining popularity over their wired counterparts. This popularity, in turn, has been generating an explosive and ever-increasing demand for, and hence creating a shortage of, the radio spectrum. Existing studies indicate that this foreseen spectrum shortage is not so much due to the scarcity of the radio spectrum, but due to the inefficiency of current spectrum access methods, thus leaving spectrum opportunities along both the time and the frequency dimensions that wireless devices can exploit. Fortunately, recent technological advances have made it possible to build software-defined radios (SDRs) which, unlike traditional radios, can switch from one frequency band to another at little or no cost. We propose a MAC protocol, called Opportunistic Spectrum MAC (OS-MAC), for wireless networks equipped with cognitive radios like SDRs. OS-MAC (1) adaptively and dynamically seeks and exploits opportunities in both licensed and unlicensed spectra and along both the time and the frequency dimensions; (2) accesses and shares spectrum among different unlicensed and licensed users; and (3) coordinates with other unlicensed users for better spectrum utilization. Using extensive simulation, OS-MAC is shown to be far more effective than current access protocols from both the network's and the user's perspectives. By comparing its performance with an Ideal-MAC protocol, OS-MAC is also shown to not only outperform current access protocols, but also achieve performance very close to that obtainable under the Ideal-MAC protocol.
Bechir Hamdaoui, Kang G. Shin
IEEE Trans. Mob. Comput.2
2008 Efficient Discovery of Spectrum Opportunities with MAC-Layer Sensing in Cognitive Radio Networks
abstract
Sensing/monitoring of spectrum-availability has been identified as a key requirement for dynamic spectrum allocation in cognitive radio networks (CRNs). An important issue associated with MAC-layer sensing in CRNs is how often to sense the availability of licensed channels and in which order to sense those channels. To resolve this issue, we address (1) how to maximize the discovery of spectrum opportunities by sensing-period adaptation and (2) how to minimize the delay in finding an available channel. Specifically, we develop a sensing-period optimization mechanism and an optimal channel-sequencing algorithm, as well as an environment- adaptive channel-usage pattern estimation method. Our simulation results demonstrate the efficacy of the proposed schemes and its significant performance improvement over nonoptimal schemes. The sensing-period optimization discovers more than 98 percent of the analytical maximum of discoverable spectrum-opportunities, regardless of the number of channels sensed. For the scenarios tested, the proposed scheme is shown to discover up to 22 percent more opportunities than nonoptimal schemes, which may become even greater with a proper choice of initial sensing periods. The idle-channel discovery delay with the optimal channel-sequencing technique ranges from 0.08 to 0.35 seconds under the tested scenarios, which is much faster than nonoptimal schemes. Moreover, our estimation method is shown to track time-varying channel-parameters accurately.
Hyoil Kim, Kang G. Shin
IEEE Trans. Mob. Comput.2
2007 Content-Sharing for Dummies: A Secure and Usable Mechanism in Wi-Fi Infrastructure Home Networks
Sehee Han, Kang G. Shin
CCNC3
2007 An Experimental Approach to Spectrum Sensing in Cognitive Radio Networks with Off-the-Shelf IEEE 802.11 Devices
abstract
Spectrum sensing is essential to the realization of spectrum agility in cognitive radio (CR) networks. Although fundamental tradeoffs and theoretical limits associated with spectrum sensing have been studied extensively, there have been very few experimental studies focused on building a spectrum "sensor" with commercial off-the-shelf devices. We have therefore built a prototype of CR-based sensor implementation with off-the-shelf IEEE 802.11 devices. 1 In particular, we have explored issues in implementing a spectrum sensor, mostly at the MAC layer, as well as the difficulty in implanting sensing functions into industrial network interfaces. Our experimental results demonstrate the feasibility of building a spectrum sensor and the construction of an incumbent-detection mechanism with off-the-shelf devices. We have also identified technical difficulties, such as device-dependency in determining the detection threshold, in-band signal jamming between secondary devices, and adjacent channel interference due to out-of-band signal emission. This experimental experience has led us to suggest a sensor design guideline for commercial wireless interfaces which can also facilitate other CR-related research.
Kang G. Shin, Hyoil Kim, Carlos Cordeiro 0001, Kiran S. Challapali
CCNC1
2007 Internet routing resilience to failures: analysis and implications
abstract
Internet interdomain routing is policy-driven, and thus physical connectivity does not imply reachability. On average, routing on today's Internet works quite well, ensuring reachability for most networks and achieving reasonable performance across most paths. However, there is a serious lack of understanding of Internet routing resilience to significant but realistic failures such as those caused by the 911 event, the 2003 Northeast blackout, and the recent Taiwan earthquake in December 2006. In this paper, we systematically analyze how the current Internet routing system reacts to various types of failures by developing a realistic failure model, and then pinpoint reliability bottlenecks of the Internet. For validity of our simulation results, we generate topology graphs by addressing concerns over the incompleteness of topology and the inaccuracy of inferred AS relationships. By focusing on the impact of structural and policy properties, our analysis provides guidelines for future Internet design. The simulation tool we provide for analyzing routing resilience is also efficient to scale to Internet-size topologies.
Jian Wu 0028, Ying Zhang 0022, Z. Morley Mao, Kang G. Shin
CoNEXT4
2007 Adaptive control of virtualized resources in utility computing environments
abstract
Data centers are often under-utilized due to over-provisioning as well as time-varying resource demands of typical enterprise applications. One approach to increase resource utilization is to consolidate applications in a shared infrastructure using virtualization. Meeting application-level quality of service (QoS) goals becomes a challenge in a consolidated environment as application resource needs differ. Furthermore, for multi-tier applications, the amount of resources needed to achieve their QoS goals might be different at each tier and may also depend on availability of resources in other tiers. In this paper, we develop an adaptive resource control system that dynamically adjusts the resource shares to individual tiers in order to meet application-level QoS goals while achieving high resource utilization in the data center. Our control system is developed using classical control theory, and we used a black-box system modeling approach to overcome the absence of first principle models for complex enterprise applications and systems. To evaluate our controllers, we built a testbed simulating a virtual data center using Xen virtual machines. We experimented with two multi-tier applications in this virtual data center: a two-tier implementation of RUBiS, an online auction site, and a two-tier Java implementation of TPC-W. Our results indicate that the proposed control system is able to maintain high resource utilization and meets QoS goals in spite of varying resource demands from the applications.
Pradeep Padala, Kang G. Shin, Xiaoyun Zhu, Mustafa Uysal, Zhikui Wang, Sharad Singhal, Arif Merchant, Kenneth Salem
EuroSys2
2007 Self-healing multi-radio wireless mesh networks
abstract
We present novel Localized sElf-reconfiGuration algOrithms (LEGO) for a multi-radio wireless mesh network to autonomously and effectively recover from wireless link failures. First, LEGO locally detects link failures by accurately monitoring the network condition and, upon detection of a failure, triggers network reconfiguration. Second, it dynamically forms/deforms a local group for cooperative network reconfiguration among local mesh routers in a fully-distributed manner. Next, LEGO intelligently generates a local network reconfiguration plan through which a thus-formed group recovers from local failures, while keeping network changes to minimum. Finally, by figuring local channel utilization and reconfiguration cost in its planning, LEGO maximizes the network's ability to meet diverse links' QoS demands. LEGO has been implemented on a Linux-based system and experimented on a reallife testbed, demonstrating its effectiveness in recovering from link failures and its improvement of channel efficiency by up to 92%.
Kyu-Han Kim, Kang G. Shin
MobiCom2
2007 Towards context-aware wireless spectrum agility
abstract
Spectrum agility (SA) is a novel way of improving spectrum utilization efficiency and making greater bandwidth available to network applications. Despite its advantages, the fundamental operations (e.g., periodic spectrum sensing) involved in realizing SA can also adversely affect application performance. We propose Context-Aware Spectrum Agility (CASA), which uses application hints together with the current channel condition to adapt key SA parameters. Our preliminary evaluation shows that CASA improves throughput by 35%, and is also more effective in meeting application demands than conventional SA.
Kang G. Shin
MobiCom2
2007 Characterization and analysis of multi-hop wireless MIMO network throughput
abstract
Use of multiple antennas or MIMO has great potential for enhancing the throughput of multi-hop wireless networks via spatial reuse and/or spatial division multiplexing. In this paper, we characterize and analyze the maximum achievable throughput in multi-hop wireless MIMO networks under three MIMO protocols, spatial reuse only (SRP), spatial multiplexing only (SMP), and spatial reuse & multiplexing (SRMP), each of which enhances throughput via a different way of exploiting the MIMO's potential. We show via extensive simulation that as the number of antennas increases, the maximum achievable throughput first rises and then flattens out asymptotically under SRP, while it increases almost linearly under SMP or SRMP. We evaluate the effects of several network parameters on this achievable throughput. We also demonstrate how these results can be used by designers to determine the optimal parameters of multi-hop wireless MIMO networks.
Bechir Hamdaoui, Kang G. Shin
MobiHoc2
2007 Partial Disk Failures: Using Software to Analyze Physical Damage
Hai Huang 0002, Kang G. Shin
MSST2
2007 Energy-efficient airtime allocation in multi-rate multi-power-level wireless LANs
abstract
This paper considers the energy-conservation problem in multi-rate multi-power-level wireless local area networks (WLANs). This problem is addressed from a unique angle — the system-level fair-ness which is significantly different from most of current research that focuses on improving the performance of each individual wire-less station. To emphasize fair energy-consumption among con-tending stations, we introduce a new fairness notion, called energy-conservation fairness, in contrast to the conventional throughput fairness and airtime fairness. Another contribution of the paper is an energy-efficient airtime allocation scheme, which allocates air-time shares to contending stations in such a way that the combined airtime and energy-conservation fairness is achieved. Our simu-lation results show that, when the energy-conservation fairness is considered, both aggregate system throughput and overall system energy-efficiency can be improved significantly with all contend-ing stations consuming a similar amount of energy.
Daji Qiao, Kang G. Shin
QSHINE2
2007 Integrating Virtual Execution Platform for Accurate Analysis in Distributed Real-Time Control System Development
abstract
A distributed real-time control system is modeled by au- tomatically generating a virtual execution platform and in- tegrating it with an abstract run-time model. This allows us to capture the dynamic effects of non-deterministic behavior of the underlying hardware and real-time operating system (RTOS), which cannot be accurately evaluated by existing static approaches. Our framework has been implemented and integrated with the existing AIRES toolkit. The con- struction of a virtual execution platform for a control appli- cation is observed to take 422ms. The integrated platform and control application consists of 56 software components connected by 1280 links for data exchanges and precedence relations, and the constructed platform executes the appli- cation at a normalized speed--defined as the ratio of simu- lation time to real time -- 10.6. Our preliminary evaluation has demonstrated the virtual execution platform's capabil- ity of providing accurate run-time information at a reason- able time-cost.
Sangsoo Park, Walter Olds, Kang G. Shin, Shige Wang
RTSS3
2007 What and how much to gain by spectrum agility?
abstract
Static spectrum allocation prohibits radio devices from using spectral bands designated for others. As a result, some bands are under-utilized while other bands are over-populated with radio devices. To remedy this problem, the concept of spectrum agility has been considered so as to enable devices to opportunistically utilize others' spectral bands. In order to help realize this concept, we establish an analytical model to derive performance metrics, including spectrum utilization and spectrum-access blocking time in spectral-agile communication systems. We then propose three basic building blocks for spectral-agile systems, namely spectrum opportunity discovery, spectrum opportunity management, and spectrum usage coordination, and develop protocols for each blocks. These protocols are integrated with the IEEE 802.11 protocol, and simulated using ns-2 to evaluate the protocol overhead. The simulation results show that our proposed protocols can improve the throughput of an IEEE 802.11 wireless LAN by 90% for the simulated scenarios, and the improvements matched well our analytical model. These results demonstrate the great potential of using spectrum agility for improving spectral utilization in an efficient, distributed, and autonomous manner
Chun-Ting Chou, Sai Shankar Nandagopalan, Hyoil Kim, Kang G. Shin
IEEE J. Sel. Areas Commun.4
2007 PRISM: Improving the Performance of Inverse-Multiplexed TCP in Wireless Networks
abstract
Multi-homed mobile hosts in physical proximity may spontaneously team up to form a community and run high-bandwidth applications by pooling their low wireless widearea network (WWAN) bandwidths together for communication with a remote application server. Utilizing their high-bandwidth wireless local-area network (WLAN), the thus-teamed mobile hosts can aggregate and distribute the application content among themselves. This paper first justifies the need for such a mobile collaborative community (MC2), or a community, to improve user-perceived network bandwidth and utilization. Then, existing one-to-one communication protocols like TCP are shown to suffer significant performance degradation due to frequent out-of-order packet deliveries. To address this TCP problem, we propose a proxy-based inverse multiplexer, called PRISM, that enables TCP to efficiently utilize the community members' WWAN connections while avoiding the performance degradation. PRISM runs at the proxy's network layer as a routing component and stripes each TCP flow over multiple WWAN links by exploiting the transport-layer feedback information. Moreover, it masks a variety of adverse effects specific to each WWAN link via an intelligent ACK-control mechanism. Finally, PRISM enables TCP to respond correctly to dynamically-changing network states through a sender-side enhancement of congestion control. PRISM has been evaluated with experimentation on a testbed as well ns-2-based simulation. Our experimental evaluation has shown PRISM to improve TCP's performance by up to 310% even with two collaborative mobile hosts. Our in-depth simulation study has also shown that PRISM delivers a near-optimal aggregated bandwidth in the community, and improves network utilization significantly
Kyu-Han Kim, Kang G. Shin
IEEE Trans. Mob. Comput.2
2007 Aggregating Bandwidth for Multihomed Mobile Collaborative Communities
abstract
Multihomed, mobile wireless computing and communication devices can spontaneously form communities to logically combine and share the bandwidth of each other's wide-area communication links using inverse multiplexing. But, membership in such a community can be highly dynamic, as devices and their associated WWAN links randomly join and leave the community. We identify the issues and trade-offs faced in designing a decentralized inverse multiplexing system in this challenging setting and determine precisely how heterogeneous WWAN links should be characterized and when they should be added to, or deleted from, the shared pool. We then propose methods of choosing the appropriate channels on which to assign newly arriving application flows. Using video traffic as a motivating example, we demonstrate how significant performance gains can be realized by adapting allocation of the shared WWAN channels to specific application requirements. Our simulation and experimentation results show that collaborative bandwidth aggregation systems are, indeed, a practical and compelling means of achieving high-speed Internet access for groups of wireless computing devices beyond the reach of public or private access points
Puneet Sharma 0001, Sung-Ju Lee 0001, Jack Brassil, Kang G. Shin
IEEE Trans. Mob. Comput.4
2007 Maximizing Communication Concurrency via Link-Layer Packet Salvaging in Mobile Ad Hoc Networks
abstract
Carrier-sense medium access control (MAC) protocols such as the IEEE 802.11 distributed coordination function (DCF) avoid collisions by holding up pending packet transmission requests when a carrier signal is observed above a certain threshold. However, this often results in unnecessarily conservative communication, thus making it difficult to maximize the utilization of the spatial spectral resource. This paper shows that a higher aggregate throughput can be achieved by allowing more concurrent communications and adjusting the communication distance on the fly, which needs provisions for the following two areas. On the one hand, carrier sense-based MAC protocols do not allow aggressive communication attempts when they are within the carrier senseable area. On the other hand, the communication distance is generally neither short nor adjustable because multihop routing protocols strive for providing minimum hop paths. This paper proposes a new MAC algorithm, called multiple access with salvation army (MASA), which adopts less sensitive carrier sensing to promote more concurrent communications and adjusts the communication distance adaptively via "packet salvaging" at the MAC layer. Extensive simulation based on the ns-2 has shown MASA to outperform the DCF, particularly in terms of packet delay. We also discuss the implementation of MASA based on the DCF specification
Chansu Yu, Kang G. Shin, Lubo Song
IEEE Trans. Mob. Comput.2
2007 Interference analysis and transmit power control in IEEE 802.11a/h wireless LANs
Daji Qiao, Sunghyun Choi 0001, Kang G. Shin
IEEE/ACM Trans. Netw.3
2007 Defense against spoofed IP traffic using hop-count filtering
Haining Wang 0001, Kang G. Shin
IEEE/ACM Trans. Netw.3
2007 Online Web Cluster Capacity Estimation and Its Application to Energy Conservation
abstract
Designers of data centers and Web servers aim to make on-demand allocation of resources to clients in order to lower the deployment cost of hosted services. Moreover, they must also minimize operating costs, such as energy consumption, by matching service-capacity demand with resource supply. However, since the term "capacity" is typically defined vaguely or inadequately, it is difficult to assess resource needs and, hence, servers, which are several times larger than needed at runtime, are usually deployed. The time-varying nature of the workload model further complicates the problem and necessitates an online capacity-estimation solution. To address this overprovisioning problem, we first define the capacity of a server cluster as the sustainable throughput subject to a request retransmission ratio constraint and then analyze different approaches to capacity estimation in a running system. Various capacity-estimation mechanisms, such as offline benchmarking and CPU-utilization evaluation, are discussed and compared with our queue-monitoring method. We employ several different data-collection methods (application instrumentation, user-space tools, simple network management protocol (SNMP), and kernel modules) to compare their effects on estimation accuracy. Of these, queue monitoring is found to provide a good and stable estimate of server capacity. To validate this finding, we propose a simple cluster- resizing mechanism and evaluate the energy-conservation performance. A good combination of data collection and online capacity estimation is found to make significantly more energy savings than traditional approaches (that is, static estimation and scheduled capacity). Our experimental results show that more than 40 percent of energy can be saved for regular daily usage patterns without any prior knowledge of the workload and that long start-up and shutdown delays affect energy savings considerably.
Chang-Hao Tsai, Kang G. Shin, John Reumann, Sharad Singhal
IEEE Trans. Parallel Distributed Syst.2
2007 Smooth handoff with enhanced packet buffering-and-forwarding in wireless/mobile networks
Chun-Ting Chou, Kang G. Shin
Wirel. Networks2
2006 On Securing Networked Real-Time Embedded Systems
Kang G. Shin
EUC1
2006 Gvu: A View-Oriented Framework for Data Management in Grid Environments
Pradeep Padala, Kang G. Shin
HiPC2
2006 Differentiated BGP Update Processing for Improved Routing Convergence
abstract
Internet routers today can be overwhelmed by a large number of BGP updates triggered by events such as session resets, link failures, and policy changes. Such excessive updates can delay routing convergence, which, in turn, degrades the performance of delay- and jitter-sensitive applications. This paper proposes a simple and novel idea of differentiated processing of BGP updates to reduce routers' load and improve routing convergence without changing the protocol semantics. Based on a set of criteria, BGP updates are grouped into different priority classes. Higher-priority updates are processed and propagated sooner, while lower-priority ones, not affecting routing decisions, can be delayed to both reduce routers' load and improve routing convergence. We first present a general methodology for update classification, update processing, and priority-state inference. By analyzing real BGP data obtained from Route Views, we show that our update classification is feasible and beneficial. We further propose two differentiated update processing (DUP) algorithms and evaluate them using the SSFNet BGP simulator on several realistic network topologies. The algorithms are shown to be very effective for large networks, yielding 30% fewer updates and reducing convergence time by 80%. Our scheme is simple and light-weight with little added processing overhead. It can be deployed incrementally, since BGP messages are not modified and every BGP router makes routing decisions independently.
Z. Morley Mao, Kang G. Shin
ICNP3
2006 On accurate measurement of link quality in multi-hop wireless mesh networks
abstract
This paper presents a highly efficient and accurate link-quality measurement framework, called EAR (Efficient and Accurate link-quality monitoR), for multi-hop wireless mesh networks, that has several salient features. First, it exploits three complementary measurement schemes: passive, cooperative, and active monitoring. EAR maximizes the measurement accuracy by (i) dynamically and adaptively adopting one of these schemes and (ii) opportunistically exploiting the nicast application traffic present in the network, while minimizing the measurement overhead. Second, EAR effectively identifies the existence of wireless link asymmetry by measuring the quality of each link in both directions of the link, thus improving the utilization of network capacity by up to 114%. Finally, its reliance on both the network layer and the IEEE 802.11-based device driver solutions makes EAR easily deployable in existing multi-hop wireless mesh networks without system recompilation or MAC firmware modification. EAR has been evaluated extensively via both ns-2-based simulation and experimentation on our Linux-based implementation. Both simulation and experimentation results have shown EAR to provide highly accurate link-quality measurements with minimum overhead.
Kyu-Han Kim, Kang G. Shin
MobiCom2
2006 System Support for Management of Networked Low-Power Sensors
abstract
This paper addresses the problem of managing a wireless sensor network with mobile managers. The mobile managers should be able to create their connectivity to the nodes they manage, and advertise their interests in the management data to be collected. Also, the network nodes should self-manage their connectivity to the managers in order to forward the management data. To meet these requirements, we propose (1) an algorithm for creating and maintaining encounter-associated management connectivity and (2) both management data exchange protocols and programming abstractions for network management applications. Both our simulation-based evaluation and experimentation of the proposed algorithm and architectural elements on real sensors demonstrated their effectiveness in meeting the requirements.
Jai-Jin Lim, Daniel L. Kiskis, Kang G. Shin
NOMS3
2006 Design of Location Service for a Hybrid Network of Mobile Actors and Static Sensors
abstract
Location services are essential to many applications running on a hybrid of wirelessly-networked mobile actors and static sensors, such as surveillance systems and the pursuer and evader game (PEG). To our best knowledge, there has been no previous location service protocol for wireless sensor networks. A number of location service protocols have been proposed for mobile ad hoc networks, but they are not applicable to sensor networks due to the usually large per-hop latency between sensors. This paper presents a distributed location service protocol (DLSP) for wireless sensor networks. Using a rigorous analysis of DLSP, we derive the condition for achieving a high packet-delivery ratio, and show how to configure the protocol parameters to ensure the scalability of DLSP. We find that DLSP is scalable if the mobile's speed is below a certain fraction of the packet-transmission speed, which depends on a movement threshold. For example, if the movement threshold for the location servers at the lowest level equals the radio range, the speed limit is one-tenth of the packet-transmission speed. The mobile's theoretical speed limit is one-fifth of the packet-transmission speed, beyond which DLSP cannot scale regardless of the movement threshold. Because of the high location-update overhead of DLSP, we propose an optimization, DLSP-SN, which can reduce the overhead by over 70%, while achieving high packet-delivery ratios. However, due to the griding effect, the packet's path length of DLSP-SN may be longer than that of DLSP, incurring higher data-delivery cost
Zhigang Chen 0004, Min Gyu Cho, Kang G. Shin
RTSS3
2006 Improving aggregated channel performance through decentralized channel monitoring
Puneet Sharma 0001, Jack Brassil, Sung-Ju Lee 0001, Kang G. Shin
Comput. Networks4
2006 Contention-based airtime usage control in multirate IEEE 802.11 wireless LANs
Chun-Ting Chou, Kang G. Shin, Sai Shankar Nandagopalan
IEEE/ACM Trans. Netw.2
2006 On the role and controllability of persistent clients in traffic aggregates
Hani Jamjoom, Kang G. Shin
IEEE/ACM Trans. Netw.2
2006 Sapphire: Statistical Characterization and Model-Based Adaptation of Networked Applications
abstract
Many modern networked applications require specific levels of service quality from the underlying network. Moreover, next-generation networked applications are expected to adapt to changes in the underlying network, services, and user interactions. While some applications have built-in adaptivity, the adaptation itself requires specification of a system model. This paper presents Sapphire, an experimental approach for systematic model generation for application adaptation within a target network. It employs a nearly-automated, statistical design of experiments to characterize the relationships of both application and network-level parameters. First, it applies the Analysis of Variance (ANOVA) method to identify the most significant parameters and their interactions that affect performance. Next, it generates a model of application performance with respect to these parameters within the ranges of measurements. The key benefit of the framework is the integration of several well-established concepts of statistical modeling and distributed systems in the form of simple APIs so that existing applications can take advantage of it. We demonstrate the usefulness and flexibility of Sapphire by generating a performance model of an audio streaming application. We show that many existing multimedia and QoS-sensitive applications can exploit a statistical modeling approach such as Sapphire to incorporate application adaptivity. The approach can also be used for feedback control of distributed applications, tuning network and application parameters to achieve service levels in a target network.
Abhijit Bose, Mohamed A. El-Gendy, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.3
2006 Task Construction for Model-Based Design of Embedded Control Software
abstract
Constructing runtime tasks, or operating system-level processes/threads, from the components of software design models is crucial to the model-based development of embedded control software. A better method should explore more design choices and reduce the overheads of the runtime system to meet the timing and resource constraints of embedded control software. This paper presents a novel, two-step method for systematic and automatic construction of runtime tasks from software design models. It uses graph transformation to construct a task set meeting system-level end-to-end (e2e) timing constraints. Its first step decomposes the system-level e2e timing constraints into the components' timing constraints, which form a necessary condition for any valid and feasible schedule. The second step iteratively merges the components into tasks and sequences their executions. A thus-constructed task set is proven to meet both intercomponent precedence and system-level e2e timing constraints and to minimize runtime overheads by minimizing the total number of resultant tasks. Our evaluation results based on randomly generated software models have shown that the proposed method outperforms commonly used methods and is also scalable.
Shige Wang, Kang G. Shin
IEEE Trans. Software Eng.2
2005 SMRP: Fast Restoration of Multicast Sessions from Persistent Failures
abstract
The growing reliance of networked applications on timely and reliable data transfer requires the underlying networking infrastructure to provide adequate services even in the presence of "persistent" failures (e.g., broken links/routers). It is much more difficult to meet this requirement for multicast sessions than for unicast communications because any on-tree component failure may often cause simultaneous service disruptions to multiple receivers. This paper presents a new multicast routing protocol, called the survivable multicast routing protocol (SMRP), which facilitates fast recovery of multicast sessions in face of persistent failures via local detour paths. Our evaluation results show that SMRP trades end-to-end delay and resource usage for short, and hence fast, recovery paths. For example, under a certain set of parameter values, SMRP shortens the recovery path by 20% with only a 5% increase of end-to-end delay and resource usage. Moreover, several design enhancements have made SMRP efficient, robust, flexible and scalable.
Jian Wu 0028, Kang G. Shin
DSN2
2005 CONNET: Self-Controlled Access Links for Delay and Jitter Requirements
abstract
Access links are typically the bottleneck between a high bandwidth LAN and a high bandwidth IP network. Without a priori resource provisioning or reservation, this tends to have a serious effect on premium traffic from delay- and jitter-sensitive applications. This paper develops a new reservation-less mechanism for delay and jitter guarantees across "single FIFO queue" access links by controlling interfering non-premium traffic. The mechanism, called CONNET (CONtrolled NETwork), uses feedback regulation to create self-controlled network services capable of tracking delay and jitter references. We use a control-theoretic approach in designing the feedback loop based on a "black-box" model of the access link in both cases of single and multiple nodes. For robust control, we employ optimal Linear Quadratic Gaussian (LQG) regulator. We evaluate the performance of CONNET using a real testbed implementation showing its superiority to other rate-based schemes (such as CBQ and WFQ) in terms of simplicity, deployability, and accuracy.
Mohamed A. El-Gendy, Kang G. Shin, Hosam K. Fathy
ICNP2
2005 Achieving per-stream QoS with distributed airtime allocation and admission control in IEEE 802.11e wireless LANs
abstract
To support the transmission of (high-rate and oftenbursty) multimedia data with performance guarantees in an IEEE 802.11e wireless local area network (LAN), it is crucial to design judicious algorithms for admission control and resource allocation. The traffic specification element (TSPEC) of the new IEEE 802.11e standard is used to facilitate the design of the admission control. Based on the traffic profile given in the TSPEC and the dual-token bucket regulation, a guaranteed rate is derived for our airtime-based admission control. The admission control is integrated with the contention-based enhanced distributed channel access (EDCA), which together can provide so-called "parameterized QoS" - as in the polling-based HCF controlled channel access (HCCA) - via a new distributed, quantitative control of stations' airtime usage. We also extend the current QoS signaling of HCCA defined in IEEE 802.11e to perform admission control for this enhanced EDCA. Furthermore, we extend the integrated scheme for QoS provisioning in ad hoc wireless LANs and design appropriate signaling procedures. We evaluate via simulation the effectiveness of this parameterized QoS-capable EDCA scheme, and demonstrate its advantages over the centralized, polling-based HCCA scheme.
Chun-Ting Chou, S. N. Shankar, Kang G. Shin
INFOCOM3
2005 Smart power-saving mode for IEEE 802.11 wireless LANs
abstract
Static PSM (power-saving mode) schemes employed in the current IEEE 802.11 implementations could not provide any delay-performance guarantee because of their fixed wakeup intervals. In this paper, we propose a smart PSM (SPSM) scheme, which directs a wireless station to sleep/wake up according to an "optimal" sequence, such that the desired delay performance is guaranteed with minimum energy consumption. Instead of constructing the sequence directly, SPSM takes a unique two-step approach. First, it translates an arbitrary user-desired delay performance into a generic penalty function. Second, it provides a generic algorithm that takes the penalty function as the input and produces the optimal station action sequence automatically. This way, the potentially-complicated energy-consumption-minimization problem subject to delay-performance constraints is simplified and solved systematically. Our simulation results show that, with a two-stair penalty function, SPSM achieves delay performance similar to the BSD (bounded slowdown) protocol under various scenarios, but always with less energy consumption, thanks to its capability to adapt to changes in the response-time distribution. Moreover, because of SPSM's two-step design feature, it is more flexible than BSD in the sense of being able to meet arbitrary user-desired delay requirement, e.g., providing soft delay-bound guarantees with power penalty functions.
Daji Qiao, Kang G. Shin
INFOCOM2
2005 Improving energy efficiency by making DRAM less randomly accessed
abstract
Existing techniques manage power for the main memory by passively monitoring the memory traffic, and based on which, predict when to power down and into which low-power state to transition. However, passively monitoring the memory traffic can be far from being effective as idle periods between consecutive memory accesses are often too short for existing power-management techniques to take full advantage of the deeper power-saving state implemented in modern DRAM architectures. In this paper, we propose a new technique that will actively reshape the memory traffic to coalesce short idle periods --- which were previously unusable for power management --- into longer ones, thus enabling existing techniques to effectively exploit idleness in the memory
Hai Huang 0002, Kang G. Shin, Charles Lefurgy, Tom W. Keller
ISLPED2
2005 Model-Checking of Component-Based Event-Driven Real-Time Embedded Software
abstract
As complexity of real-time embedded software grows, it is desirable to use formal verification techniques to achieve a high level of assurance. We discuss application of model-checking to verify system-level concurrency properties of component-based real-time embedded software based on CORBA event service, using avionics mission computing software as an application example. We use the process algebra FSP to formalize specification of software components and system architecture, previously only available in the form of natural language and prone to misinterpretation and misunderstanding, and use model-checking to verify system-level concurrency properties. We also discuss effective techniques for coping with the state-space explosion problem by exploiting application domain semantics. We have applied our analysis techniques to realistic application scenarios provided by our industry partner to demonstrate their utility and power.
Zonghua Gu 0001, Kang G. Shin
ISORC2
2005 Energy-efficient self-adapting online linear forecasting for wireless sensor network applications
abstract
New energy-efficient linear forecasting methods are proposed for various sensor network applications, including in-network data aggregation and mining. The proposed methods are designed to minimize the number of trend changes for a given application-specified forecast quality metric. They also self-adjust the model parameters, the slope and the intercept, based on the forecast errors observed via measurements. As a result, they incur O(1) space and time overheads, a critical advantage for resource-limited wireless sensors. An extensive simulation study based on real-world and synthetic time-series data shows that the proposed methods reduce the number of trend changes by 20%/spl sim/50% over the existing well-known methods for a given forecast quality metric. That is, they are more predictive than the others with the same forecast quality metric.
Jai-Jin Lim, Kang G. Shin
MASS2
2005 Link-layer salvaging for making routing progress in mobile ad hoc networks
abstract
IEEE 802.11 MAC, called the Distributed Coordination Function (DCF), employs carrier sensing to effectively avoid collisions, but this makes it difficult to maximally reuse the spatial spectral resource available for exposed terminals. This paper proposes a new MAC algorithm, called Multiple Access with Salvation Army (MASA), which adopts less sensitive carrier sensing to promote more spatial reuse of the channel. However, this may result in a higher collision probability. MASA alleviates this problem by adaptively adjusting the communication distance via "packet salvaging" at the MAC layer. Extensive simulation based on the ns-2 has shown MASA to offer as much as 25% higher packet delivery rate and 27% higher throughput than the DCF with the CBR (constant bit rate) and TCP traffic, respectively. In particular, a significant reduction in packet delay, 86% and 70% lower packet delay with the CBR and TCP traffic, makes MASA suitable for delay-sensitive applications. For practicality, we discuss the implementation of MASA based on the DCF specification.
Chansu Yu, Kang G. Shin, Lubo Song
MobiHoc2
2005 Improving TCP performance over wireless networks with collaborative multi-homed mobile hosts
abstract
Multi-homed mobile hosts situated in physical proximity may spontaneously team up to run high-bandwidth applications by pooling their low wireless wide-area network (WWAN) bandwidths together for communication with a remote application server and utilizing their high-bandwidth wireless local-area network (WLAN) in ad-hoc mode for aggregation and distribution of application contents among the participating mobile hosts. In this paper, we first describe the need for such a mobile collaborative community, or a community, in which multi-homed mobile hosts exploit the diversity of WWAN connections to improve a user-perceived bandwidth and network utilization. Then, we show that existing one-to-one communication protocols like TCP suffer significant performance degradation due to frequent packet reordering and heterogeneity of WWAN links in the community.To address the above TCP problem, we propose a proxy-based inverse multiplexer, called PRISM, that enables TCP to efficiently utilize the community members' WWAN connections. PRISM runs at a proxy's network layer as a routing component and stripes each TCP flow over multiple WWAN links by exploiting the transport-layer feedback information. Moreover, it masks variety of adverse effects specific to each WWAN link via intelligent ACK-control mechanism. Finally, PRISM includes a sender-side enhancement of congestion control, enabling TCP to respond correctly to dynamically-changing network states.We have evaluated the PRISM protocol using both experimentation and ns-2-based simulation. Our experimental evaluation has shown PRISM to improve TCP's performance by up to 310% even with two collaborative mobile hosts. Our in-depth simulation study also shows that PRISM delivers a near-optimal aggregated bandwidth in the community formed by heterogeneous mobile hosts, and improves network utilization significantly.
Kyu-Han Kim, Kang G. Shin
MobiSys2
2005 Context-aware metadata creation in a heterogeneous mobile environment
abstract
With an exponentially-growing amount of digital information, data management is becoming increasingly burdensome for an average user. We propose an enhancement to the existing media-management techniques which utilizes the context available in the surrounding environment around the time a media file is created. This context information is associated with the file to provide enhanced data categorization and searching capabilities. A typical scenario considered in our design involves a heterogeneous environment where users capture digital images using camera-enabled mobile devices, such as iPAQs. Concurrently, these mobile agents also collect environmental data from a variety of sensors and other surrounding wirelessly-enabled devices. At the time of image capture, mobile devices collect and process environmental information, which is then associated with the digital image in the form of metadata. Association of the context with the image makes it possible to build user applications with context-based image classification and query facilities. Our system includes such a GUI application, which provides an image query mechanism based on metadata attributes collected at the time of a picture. Our preliminary evaluation of the system validates successful metadata creation and association with the media files and demonstrates the enhanced searching and classification capabilities using a GUI application.
Olga Volgin, Wanda Hung, Chris Vakili, Jason Flinn, Kang G. Shin
NOSSDAV5
2005 Smooth Handoff with Enhanced Packet Buffering-and-Forwarding in Wireless/Mobile Networks
abstract
Packet buffering-and-forwarding is a simple but essential mechanism and has been widely used with other mechanisms to provide seamless handoffs in many wireless/mobile networks. However, some undesirable side effects of this mechanism, if not managed appropriately, can easily diminish its effectiveness in providing seamless inter-cell transitions during a handoff. We first examine these side effects and show how inappropriate buffer management by a mobility agent could affect the TCP performance. The throughput of TCP is then studied with special emphasis on the effects of a handoff. We enhance the conventional buffering-and-forwarding by proposing the last-come-first-drop (LCFD) buffer management policy (to be employed by mobility agents) and post-handoff acknowledgement suppression (to be used by mobile nodes). Our enhancements are backward compatible and suitable for the gradual/incremental deployment. By deriving an analytical model and conducting numerical analysis, we show that our scheme can improve the TCP throughput up to 30%. Finally, we conduct the ns-2 based simulation to confirm these numerical results, and demonstrate the applicability of the analytic model for predicting TCP throughput in other handoff schemes.
Chun-Ting Chou, Kang G. Shin
QSHINE2
2005 Priority Refinement for Dependent Tasks in Large Embedded Real-Time Software
abstract
In a large embedded real-time system, priority assignment can greatly affect the timing behavior - which can consequently affect the overall behavior - of the system. Thus, it is crucial for model-based design of a large embedded real-time system to be able to intelligently assign priorities such that tasks can meet their deadlines. In this paper, we propose a priority-refinement method for dependent tasks distributed throughout a heterogeneous multiprocessor environment. In this method, we refine an initial priority assignment iteratively using the simulated annealing technique with tasks' latest completion times (LCT). Our evaluations, based on randomly-generated models, have shown that the refinement method outperforms other priority-assignment schemes and scales well for large, complex, real-time systems. This method has been implemented in the Automatic Integration of Reusable Embedded Software (AIRES) toolkit and has been successfully applied to a vehicle system control application.
Jeffrey R. Merrick, Shige Wang, Kang G. Shin, William Milam
IEEE Real-Time and Embedded Technology and Applications Symposium3
2005 Synthesis of Real-Time Implementations from Component-Based Software Models
abstract
Component-based software development is an effective technique for tackling the increasing complexity of large-scale embedded software systems. After building a logical software model, the designer must make design decisions, including choosing a multi-threading strategy and assigning priorities to threads, to ensure that the final implementation on the target execution platform satisfies non-functional requirements. Code generators for software design tools produce functional code, but typically ignore concurrency and timing issues. In this paper, we describe techniques for real-time scheduling and design-space exploration and optimization, with the goal of helping the designer synthesize efficient real-time implementations from component-based software models. Experimental evaluation shows that our techniques yield high-quality implementations with reasonable running time of the optimization algorithm.
Zonghua Gu 0001, Kang G. Shin
RTSS2
2005 Gradient-Ascending Routing via Footprints in Wireless Sensor Networks
abstract
A novel gradient-ascending stateless routing protocol, called GRASP (gradient ascending stateless protocol), is proposed for stationary wireless sensor networks. GRASP is built with a novel packet forwarding method called FBF (footprint-based forwarding), in which each node maintains a Bloom filter that holds a dejavu image for the nodes whose packets were relayed through the filter. Forwarding a packet through networked sensors is then just running a membership test of the packet's destination against the networked Bloom filters, either dropping the packet before it reaches the destination or eventually delivering it to the destination. An extensive simulation study with various routing scenarios has shown the proposed method to achieve about 99% packet delivery while incurring only a small amount of overhead. It also achieves more than 86% packet delivery even for a lossy channel with up to 30% loss rate. Furthermore, our comparative evaluation against AODV or simple flooding shows that GRASP achieves a comparable, or even better, performance in terms of the packet delivery ratio and overhead under the simulation settings investigated. GRASP is shown to reduce the delivery overhead by a factor of 2.37 over AODV or 3.11 over the simple flooding, while providing more robustness to packet losses - this is a significant improvement for low-power sensors in a lossy wireless environment. Manipulating Bloom filters incurs a small space overhead and does not create any protocol conflict with the underlying gradient-descending protocols, thanks to its stateless routing.
Jai-Jin Lim, Kang G. Shin
RTSS2
2005 Improving Cross-domain Authentication overWireless Local Area Networks
abstract
As mobile users cross the border of two adjacent domains with on-going sessions, their re-authentication causes a significant impact on inter-domain handoff latency as it requires remote contact with the authentication server across domains, making it difficult to employ current authentication protocols. This paper focuses on the cross-domain authentication over wireless local area networks (WLANs) that minimizes the need for remote access. We analyze the security requirements suggested by the IEEE 802.11i authentication standard, and consider additional requirements to help reduce the authentication latency without compromising the level of security. We propose an enhanced protocol called the Mobility-adjusted Authentication Protocol (MAP) that performs mutual authentication and hierarchical key derivation with minimal handshakes, relying on symmetric cryptographic functions. We also present security context nodes (SCNs) that handle security contexts in conjunction with MAP, which allows for avoiding continuous remote contact with the home authentication server. In contrast to Kerberos which favors inter-realm authentication, MAP achieves a 26% reduction of authentication latency without degrading the level of security.
Hahnsang Kim, Kang G. Shin, Walid Dabbous
SecureComm2
2005 FS2: dynamic data replication in free disk space for improving disk performance and energy consumption
abstract
Disk performance is increasingly limited by its head positioning latencies, i.e., seek time and rotational delay. To reduce the head positioning latencies, we propose a novel technique that dynamically places copies of data in file system's free blocks according to the disk access patterns observed at runtime. As one or more replicas can now be accessed in addition to their original data block, choosing the "nearest" replica that provides fastest access can significantly improve performance for disk I/O operations.We implemented and evaluated a prototype based on the popular Ext2 file system. In our prototype, since the file system layout is modified only by using the free/unused disk space (hence the name Free Space File System, or FS2), users are completely oblivious to how the file system layout is modified in the background; they will only notice performance improvements over time. For a wide range of workloads running under Linux, FS2 is shown to reduce disk access time by 41--68% (as a result of a 37--78% shorter seek time and a 31--68% shorter rotational delay) making a 16--34% overall user-perceived performance improvement. The reduced disk access time also leads to a 40--71% energy savings per access.
Hai Huang 0002, Wanda Hung, Kang G. Shin
SOSP3
2005 Best-Effort Patching for Multicast True VoD Service
Huadong Ma, Kang G. Shin, Wei Biao Wu
Multim. Tools Appl.2
2005 An Enhanced Inter-Access Point Protocol for Uniform Intra and Intersubnet Handoffs
abstract
An enhanced IEEE 802.11 inter-access point protocol (IAPP) is proposed to provide a unified solution for both intra and intersubnet handoff processes. The proposed enhancement relies on the access point's (AP's) interoperability with other APs, provided by the IP-based IAPP, so as to enable the intra and intersubnet link-layer frame buffering-and-forwarding. This enhancement not only eliminates frame losses during an intrasubnet handoff but, more importantly, realizes loss-free, fast intersubnet handoffs without modifying the IP-mobility protocols such as mobile IP. Our ns-2-based simulation results show that the intersubnet handoff process is transparent to the mobile host's TCP session. Moreover, the enhanced IAPP supports higher user mobility and achieves a higher TCP throughput - up to 50 percent improvement over the original IAPP.
Chun-Ting Chou, Kang G. Shin
IEEE Trans. Mob. Comput.2
2005 Soft Tamper-Proofing via Program Integrity Verification in Wireless Sensor Networks
abstract
Small low-cost sensor devices, each equipped with limited resources, are networked and used for various critical applications, especially those related to homeland security. Making such a sensor network secure is challenging mainly because it usually has to operate in a harsh, sometimes hostile, and unattended environment, where it is subject to capture, reverse-engineering, and manipulation. To address this challenge, we present a program-integrity verification (PIV) protocol that verifies the integrity of the program residing in each sensor device whenever the device joins the network or has experienced a long service blockage. The heart of PIV is the novel randomized hash function tailored to low-cost CPUs, by which the algorithm for hash computation on the program can be randomly generated whenever the program needs to be verified. By realizing this randomized hash function, the PlV protocol 1) prevents manipulation/reverse-engineering/reprogramming of sensors unless the attacker modifies the sensor hardware (e.g., attaching more memory), 2) provides purely software-based protection, and 3) triggers the verification infrequently, thus incurring minimal intrusiveness into normal sensor functions. Our performance evaluation shows that the PIV protocol is computationally efficient and incurs only a small communication overhead, hence making it ideal for use in low-cost sensor networks.
Taejoon Park, Kang G. Shin
IEEE Trans. Mob. Comput.2
2005 Optimal tradeoffs for location-based routing in large-scale ad hoc networks
abstract
Existing location-based routing protocols are not versatile enough for a large-scale ad hoc environment to simultaneously meet all of the requirements of scalability, bandwidth efficiency, energy efficiency, and quality-of-service routing. To remedy this deficiency, we propose an optimal tradeoff approach that: 1) constructs a hybrid routing protocol by combining well-known location-update schemes (i.e., proactive location updates within nodes' local regions and a distributed location service), and 2) derives its optimal configuration, in terms of location-update thresholds (both distance and time-based), to minimize the overall routing overhead. We also build a route-discovery scheme based on an Internet-like architecture, i.e., first querying the location of a destination, then applying a series of local-region routing until finding a complete route by aggregating the thus-found partial routes. To find the optimal thresholds for the hybrid protocol, we derive the costs associated with both location updates and route discovery as a function of location-update thresholds, assuming a random mobility model and a general distribution for route request arrivals. The problem of minimizing the total cost is then cast into a distributed optimization problem. We first prove that the total cost is a convex function of the thresholds, and then derive the optimal thresholds. Finally, we show, via simulation, that our analysis results indeed capture the real behavior.
Taejoon Park, Kang G. Shin
IEEE/ACM Trans. Netw.2
2005 End-to-end delay bounds for traffic aggregates under guaranteed-rate scheduling algorithms
abstract
This paper evaluates, via both analysis and simulation, the end-to-end (e2e) delay performance of aggregate scheduling with guaranteed-rate (GR) algorithms. Deterministic e2e delay bounds for a single aggregation are derived under the assumption that all incoming flows at an aggregator conform to the token bucket model. An aggregator can use any of three types of GR scheduling algorithms: stand-alone GR, two-level hierarchical GR, and rate-controlled two-level hierarchical GR. E2e delay bounds are also derived for the case of multiple aggregations within an aggregation region when aggregators use the rate-controlled two-level hierarchical GR. By using the GR scheduling algorithms for traffic aggregates, we show not only the existence of delay bounds for each flow, but also the fact that, under certain conditions (e.g., when the aggregate traverses a long path after the aggregation point), the bounds are smaller than that of per-flow scheduling. We then compare the analytic delay bounds numerically and conduct in-depth simulation to: 1) confirm the analytic results and 2) compare the e2e delays of aggregate and per-flow scheduling. The simulation results have shown that aggregate scheduling is very robust and can exploit statistical multiplexing gains. It performs better than per-flow scheduling in most of the simulation scenarios we considered. Overall, aggregate scheduling is shown theoretically to provide bounded e2e delays and practically to provide excellent e2e delay performance. Moreover, it incurs lower scheduling and state-maintenance overheads at routers than per-flow scheduling. All of these salient features make aggregate scheduling very attractive for use in Internet core networks.
Kang G. Shin
IEEE/ACM Trans. Netw.2
2005 IP Easy-pass: a light-weight network-edge resource access control
abstract
Providing real-time communication services to multimedia applications and subscription-based Internet access often requires that sufficient network resources be reserved for real-time traffic. However, the reserved network resource is susceptible to resource theft and abuse. Without a resource access control mechanism that can efficiently differentiate legitimate real-time traffic from attacking packets, the traffic conditioning and policing enforced at Internet Service Provider (ISP) edge routers cannot protect the reserved network resource from embezzlement. On the contrary to the usual expectation, the traffic policing at edge routers aggravates their vulnerability to flooding attacks by blindly dropping packets. In this paper, we propose a fast and lightweight IP network-edge resource access control mechanism, called IP Easy-pass, to prevent unauthorized access to reserved network resources at edge devices. We attach a unique pass to each legitimate real-time packet so that an ISP edge router can validate the legitimacy of the incoming IP packet very quickly and simply by checking its pass. We present the generation of Easy-pass, its embedding, and verification procedures. We implement the IP Easy-pass mechanism in the Linux kernel, and measure its overhead on our testbed. Finally, we demonstrate its effectiveness against packet forgery and resource embezzlement attempts by conducting a series of experiments.
Haining Wang 0001, Abhijit Bose, Mohamed A. El-Gendy, Kang G. Shin
IEEE/ACM Trans. Netw.4
2004 Handheld Routers: Intelligent Bandwidth Aggregation for Mobile Collaborative Communities
abstract
Multi-homed, mobile wireless computing and communication devices can spontaneously form communities to logically combine and share the bandwidth of each other's wide-area communication links using inverse multiplexing. But membership in such a community can be highly dynamic, as devices and their associated WAN links randomly join and leave the community. We identify the issues and tradeoffs faced in designing a decentralized inverse multiplexing system in this challenging setting, and determine precisely how heterogeneous WAN links should be characterized, and when they should be added to, or deleted from, the shared pool. We then propose methods of choosing the appropriate channels on which to assign newly-arriving application flows. Using video traffic as a motivating example, we demonstrate how significant performance gains can be realized by adapting allocation of the shared WAN channels to specific application requirements. Our simulation and experimentation results show that collaborative bandwidth aggregation systems are, indeed, a practical and compelling means of achieving high-speed Internet access for groups of wireless computing devices beyond the reach of public or private access points.
Puneet Sharma 0001, Sung-Ju Lee 0001, Jack Brassil, Kang G. Shin
BROADNETS4
2004 TCP performance under aggregate fair queueing
abstract
In this paper, we studied TCP performance under aggregate fair queueing (FQ). We first showed the livelock problem of FQ under the DropFront scheme, and proposed a simple solution to the problem. Then, to improve the fairness of aggregate FQ, we proposed a new active buffer-management scheme called ALQD+ (approximated longest queue drop), which is fairer than ALQD. Based on these two enhancements, via simulation, we showed that aggregate FQ provides not only excellent scalability (small scheduling and state-maintenance overheads) but also good performance, especially throughput. In addition to the simulation-based evaluation, we provided a simple performance analysis.
Kang G. Shin
GLOBECOM2
2004 The Impact of Concurrency Gains on the Analysis and Control of Multi-threaded Internet Services
abstract
With the proliferation of Internet services, many solutions have emerged to provide quality-of-service (QoS) guarantees when the demands for the hosted services exceed the server's capacity. We take an analytical approach to answering key questions in the design and performance of application-level QoS techniques, especially those that are based on the multi-threading or multi-processing abstraction. Key to our analysis is the integration of the effects of concurrency into the interactions between multi-threaded services. To this end, we extend traditional time-sharing models to develop the multi-threaded round-robin (MTRR) servers, a more accurate model of operation of typical multi-threaded Internet services. For this model, we first develop powerful, yet computationally-efficient, mathematical relationships that describe the performance (in terms of throughput and response time) of multi-threaded services. We then apply optimization techniques to derive the optimal allocation of threads given specific QoS objective functions. Using realistic workloads on a typical Web server, we show the efficacy and accuracy of the proposed new methodology.
Hani Jamjoom, Chun-Ting Chou, Kang G. Shin
INFOCOM3
2004 IP Easy-pass: Edge Resource Access Control
abstract
Providing real-time communication services to multimedia applications and subscription-based Internet access often requires sufficient network resources to be reserved for real-time traffic. However, the reserved network resource is susceptible to resource theft and abuse. Without a resource access control mechanism that can efficiently differentiate legitimate real-time traffic from attacking packets, the traffic conditioning and policing enforced at ISP (Internet service provider) edge routers cannot protect the reserved network resource from embezzlement. On the contrary, the traffic policing at edge routers aggravates their vulnerability to flooding attacks by blindly dropping packets. We propose a fast and light-weighted IP network-edge resource access control mechanism, called IP easy-pass to prevent unauthorized access to reserved network resources at edge devices. We attach a unique pass to each legitimate real-time packet so that an ISP edge router can validate the legitimacy of an incoming IP packet very quickly and simply by checking its pass. We present the generation of easy-pass, its embedding, and verification procedures. We implement the IP easy-pass mechanism in the Linux kernel, analyze its effectiveness against packet forgery and resource embezzlement attempts. Finally, we measure the overhead incurred by easy-pass.
Haining Wang 0001, Abhijit Bose, Mohamed A. El-Gendy, Kang G. Shin
INFOCOM4
2004 On the Modeling and Optimization of Discontinuous Network Congestion Control Systems
abstract
AIMD is a widely-used network congestion control scheme. Despite its discontinuous control behavior, the majority of contemporary literature employed a statistically-averaged continuous model to approximate AIMD without considering its discontinuity. The design of a discontinuous control system must be based on rules that are entirely different from that of continuous control systems. Ignoring discontinuity issues results in great discrepancy between analytical models and the practice. In this paper we use the sliding mode control (SMC) theory to investigate congestion control without ignoring its discontinuity. Based on the SMC theory, the design of discontinuous (congestion) control systems must consider the relative degree and zero dynamics of the system, in order to guarantee asymptotic stability. This framework can precisely reflect the behavior of the control rules and the controlled objective of a congestion control system. We show that the relative degree of the control system of rate-based, AIMD flow-control algorithms is two. That is, to apply sound control principles to the design of AIMD algorithms, one should use both the queue length error and its first order time derivative to construct the switching function of the control model of an active queue management scheme. Based on the SMC model, one can quantify the tradeoffs among the convergence speed, the amount of throttling adjustments, and the degree of oscillations. We show quantitatively that one can guarantee stability conditions, drastically reduce oscillation of AIMD without significant loss of fairness and stability, and quantitative understanding of the tradeoffs among oscillation, delay and fairness.
Yong Xiong, Jyh-Charn Liu, Kang G. Shin, Wei Zhao 0001
INFOCOM3
2004 Paving the first mile for QoS-dependent applications and appliances
abstract
Paving the first mile of quality-of-service (QoS) support has become essential for full deployment and utilization of QoS proposals in the Internet. Most of existing efforts have been made to provide network services and control without paying much attention to how applications can use these services. In this paper, we design and implement a two-tier architecture, called QoS Gateway (QoSGW), that acts as an interface between application QoS requirements and network-provided QoS capabilities. The QoSGW is to support small embedded network devices that rely on network-provided QoS. Our architecture, in its full version, is composed of two key components: (i) an agent that resides on the end-host and provides an adequate interface for QoS-dependent applications, and (ii) a QoS manager that provides an interface to network services for the agents. Using these two components enhances generality and scalability in providing QoS support for Internet applications and end-devices. The QoSGW is intended to promote QoS deployment and facilitate construction of QoS-aware access networks.
Mohamed A. El-Gendy, Abhijit Bose, Seong-Taek Park, Kang G. Shin
IWQoS4
2004 Coordinated aggregate scheduling for improving end-to-end delay performance
abstract
This paper proposes a novel coordinated aggregate scheduling (CAS) algorithm that combines both EOF (earliest-deadline-first) scheduling and rate-based fair queueing. CAS uses guaranteed rate (GR) scheduling (Goyal, P et al., 1995) for traffic aggregates at the inter-aggregate level, but employs EDF-like scheduling at the intra-aggregate level. Computation of the deadline D/sub N/ of a packet at an intermediate node N is coordinated between the node N and its upstream nodes, and D/sub N/ is related to the packet's guaranteed rate clock (GRC) value at the flow-aggregation node. CAS provides tighter end-to-end (e2e) delay bounds than the "vanilla" GR aggregate scheduling that relies on FIFO queueing within an aggregate. Our in-depth simulation results demonstrate CAS's superior performance. Moreover, as an aggregate-based work-conserving scheduling algorithm, CAS incurs lower scheduling and state-maintenance overheads at routers than per-flow scheduling. These salient features make CAS very attractive for use in Internet core networks.
Kang G. Shin
IWQoS2
2004 Distributed Channel Monitoring for Wireless Bandwidth Aggregation
Puneet Sharma 0001, Sung-Ju Lee 0001, Jack Brassil, Kang G. Shin
NETWORKING4
2004 Component Allocation with Multiple Resource Constraints for Large Embedded Real-Time Software Design
abstract
Allocating software components while meeting multiple platform resource constraints is crucial for model-based design of large embedded real-time software and automatic design model transformation. In this paper, we propose a new method for component allocation using an informed branch-and-bound and forward checking mechanism subject to a combination of resource constraints. We have implemented this method in the automatic integration of reusable embedded software (AIRES) toolkit - which has been developed under the DARPA MoBIES Program - and applied it to an automotive electronic throttle control (ETC) system. Our evaluation based on randomly-generated design models has shown that the proposed method scales well for large and complex embedded real-time software.
Shige Wang, Jeffrey R. Merrick, Kang G. Shin
IEEE Real-Time and Embedded Technology and Applications Symposium3
2004 On-Line Dynamic Voltage Scaling for Hard Real-Time Systems Using the EDF Algorithm
abstract
Recently, there has been a rapid and wide spread of non-traditional computing platforms, especially mobile and portable computing devices. As applications become sophisticated and computation power increases, the most serious limitation on these devices is the available battery life. Dynamic voltage scaling (DVS) has been a key technique to exploit the hardware characteristics of processors to reduce energy dissipation by lowering the supply voltage and operating frequency. This paper presents a novel on-line DVS algorithm called OLDVS that, when coupled with the underlying OS task management mechanism and real-time scheduler, can make significant energy savings, while preserving timeliness guarantees made by the underlying real-time scheduling algorithm. While most existing DVS algorithms are confined to periodic tasks only, OLDVS does not assume task periodicity, nor does it require any a priori information on the task set to be scheduled. OLDVS requires only O(1) computation on each task context switch, thus making it fairly easy to be incorporated into a real-time operating system. The OLDVS algorithm considers a general task model which is very difficult, if not impossible, for the existing DVS algorithms to handle. Our simulation results show that OLDVS achieves great energy savings and outperforms the existing DVS algorithms when the ratio of the computation requirement of aperiodic tasks to the total computation requirement is higher than 40%. The performance advantage becomes much larger as the ratio increases.
Cheol-Hoon Lee, Kang G. Shin
RTSS2
2004 Power-stepped protocol: enhancing spatial utilization in a clustered mobile ad hoc network
abstract
While most previous studies on mobile ad hoc networks (MANETs) rely on the assumption that nodes are randomly distributed in the network coverage area, this assumption is unlikely to hold, as nodes tend to be cluttered around hot spots like the site of an accident or disaster. We refer to this as a clustered layout. Intuitively, a MANET with the clustered layout may suffer from serious performance degradation due to the excessive collisions in congested hot spots and space underutilization of sparse areas. In this paper, we propose a power-controlled network protocol, called the power-stepped protocol (PSP), that maximizes the spatial utilization of limited channel bandwidth. Using a number of discrete power levels available for the underlying wireless network hardware, PSP finds the appropriate power level for each node in a distributed and a coordinated manner without causing any serious problem at the medium access control and network routing layers. A unique feature of this approach is the use the chosen radio power for both data and control packets, and thus, it requires neither any special mechanism (e.g., a separate control channel) nor frequent power adjustments. Our extensive ns-2-based simulation results have shown the proposed PSP provides excellent performance in terms of packet delivery ratio and delay, as well as the network capacity.
Chansu Yu, Kang G. Shin, Ben Lee
IEEE J. Sel. Areas Commun.2
2004 Change-Point Monitoring for the Detection of DoS Attacks
abstract
This work presents a simple and robust mechanism, called change-point monitoring (CPM), to detect denial of service (DoS) attacks. The core of CPM is based on the inherent network protocol behavior and is an instance of the sequential change point detection. To make the detection mechanism insensitive to sites and traffic patterns, a nonparametric cumulative sum (CUSUM) method is applied, thus making the detection mechanism robust, more generally applicable, and its deployment much easier. CPM does not require per-flow state information and only introduces a few variables to record the protocol behaviors. The statelessness and low computation overhead of CPM make itself immune to any flooding attacks. As a case study, the efficacy of CPM is evaluated by detecting a SYN flooding attack - the most common DoS attack. The evaluation results show that CPM has short detection latency and high detection accuracy.
Haining Wang 0001, Danlu Zhang, Kang G. Shin
IEEE Trans. Dependable Secur. Comput.3
2004 LiSP: A lightweight security protocol for wireless sensor networks
abstract
Small low-cost sensor devices with limited resources are being used widely to build a self-organizing wireless network for various applications, such as situation monitoring and asset surveillance. Making such a sensor network secure is crucial to their intended applications, yet challenging due to the severe resource constraints in each sensor device. We present a lightweight security protocol (LiSP) that makes a tradeoff between security and resource consumption via efficient rekeying. The heart of the protocol is the novel rekeying mechanism that offers (1) efficient key broadcast without requiring retransmission/ACKs, (2) authentication for each key-disclosure without incurring additional overhead, (3) the ability of detecting/recovering lost keys, (4) seamless key refreshment without disrupting ongoing data encryption/decryption, and (5) robustness to inter-node clock skews. Furthermore, these benefits are preserved in conventional contention-based medium access control protocols that do not support reliable broadcast. Our performance evaluation shows that LiSP reduces resource consumption significantly, while requiring only three hash computations, on average, and a storage space for eight keys.
Taejoon Park, Kang G. Shin
ACM Trans. Embed. Comput. Syst.2
2004 Analysis of Adaptive Bandwidth Allocation in Wireless Networks with Multilevel Degradable Quality of Service
abstract
A wireless/mobile network supporting multilevel quality of service (QoS) is considered. In such a network, users or applications can tolerate a certain degree of QoS degradation. Bandwidth allocation to users can, therefore, be adjusted dynamically according to the underlying network condition so as to increase bandwidth utilization and service provider's revenue. However, arbitrary QoS degradation may be unsatisfactory or unacceptable to the users, hence resulting in their subsequent defection. Instead of only focusing on bandwidth utilization or blocking/dropping probability, two new user-perceived QoS metrics, degradation ratio and upgrade/degrade frequency, are proposed. A Markov model is then provided to derive these QoS metrics. Using this model, we evaluate the effects of adaptive bandwidth allocation on user-perceived QoS and show the existence of trade offs between system performance and user-perceived QoS. We also show how to exploit adaptive bandwidth allocation to increase system utilization (for the system administrator) with controlled QoS degradation (for the users). By considering various mobility patterns, the simulation results are shown to match our analytical results, demonstrating the applicability of our analytical model to more general cases.
Chun-Ting Chou, Kang G. Shin
IEEE Trans. Mob. Comput.2
2004 Checking consistency in multimedia synchronization constraints
abstract
Constraint-based design is often used to correctly author a multimedia scenario due to its flexibility and efficiency. However, such a system must provide a mechanism with which users can easily manipulate the underlying structures to meet the application requirements. This paper proposes a novel method for analyzing multimedia synchronization constraints based on the constraint graph and classification, which is essential in developing efficient system support tools for constraint-based authoring systems. We specify temporal and spatial relations between multimedia objects, and use a directed graph to represent the constraints among the objects in a multimedia scenario. Moreover, we develop a method for analyzing temporal and spatial synchronization constraints based on graph theory, solving the problems of completeness checking, consistency checking, constraints relaxation and automatic spatio-temporal layout generation in a unified theoretical framework. We also discuss the effects of user interactive authoring. Compared with other methods, the proposed approach is simpler, more efficient, and easier to implement.
Huadong Ma, Kang G. Shin
IEEE Trans. Multim.2
2004 Stateful distributed interposition
abstract
Interposition-based system enhancements for multitiered servers are difficult to build because important system context is typically lost at application and machine boundaries. For example, resource quotas and user identities do not propagate easily between cooperating services that execute on different hosts or that communicate with each other via intermediary services. Application-transparent system enhancement is difficult to achieve when such context information is obscured by complex service interaction patterns. We propose a basic mechanism for sharing contextual information across the tiers of multitier computations to support system enhancement for multitier servers and applications.This article introduces generic, cluster-wide context as a new, configurable abstraction for the OS. System administrator- or application-specified context tracking rules determine how context is associated with system processes, sockets, messages, how it is relayed along the interapplication communication channels, and how it is to be interpreted by system interpositions, thus realizing Stateful Distributed Interposition.
John Reumann, Kang G. Shin
ACM Trans. Comput. Syst.2
2004 Resynchronization and controllability of bursty service requests
abstract
There is an increasing prevalence of interactive Web sessions in the Internet. These are mostly short-lived TCP connections that are delay-sensitive and have transfer times dominated by TCP backoffs, if any, during connection establishment. Unfortunately, arrivals of such connections at a server tend to be bursty, and can trigger multiple retransmissions, resulting in long average client-perceived delays. Traditional traffic control mechanisms, such as token bucket filters, are designed to complement admission control mechanisms, by regulating throughput, bounding service times, and protecting systems from overload. However, they cannot control connection-establishment delays, and thus, do not provide effective control of client-perceived delays. We first present the surprising discovery of a resynchronization property of retransmitted requests that exacerbates client-perceived delays when traditional control mechanisms are used. Then, we introduce a novel, multistage filtering scheme called Abacus Filters (AFs) that limits the client-perceived delay while maximizing server throughput even in the case of bursty connection arrivals. Analysis of delay-control properties of various filtering mechanisms is presented, along with a detailed performance evaluation. AFs are shown to provide tight delay control and better complement traditional admission control policies.
Hani Jamjoom, Padmanabhan Pillai, Kang G. Shin
IEEE/ACM Trans. Netw.3
2004 Markov-chain modeling for multicast signaling delay analysis
abstract
Feedback signaling plays a key role in flow control because the traffic source relies on the signaling information to make correct and timely flow-control decisions. However, it is difficult to design an efficient signaling algorithm since a signaling message can tolerate neither error nor latency. Multicast flow-control signaling imposes two additional challenges: scalability and feedback synchronization. Previous research on multicast signaling has mainly focused on the development of algorithms without analyzing their delay performance. To remedy this deficiency, we have previously developed a binary-tree model and an independent-marking statistical model for multicast-signaling delay analysis. This paper considers a general scenario where the congestion markings at different links are dependent - a more accurate but complex case. Specifically, we develop a Markov-chain model defined by the link-marking state on each path in the multicast tree. The Markov chain can not only capture link-marking dependencies, but also yield a tractable analytical model. We also develop a Markov-chain dependency-degree model to evaluate all possible Markov-chain dependency degrees without any prior knowledge of them. Using the above two models, we derive the general probability distributions of each path becoming the multicast-tree bottleneck. Also derived are the first and second moments of multicast signaling delays. The proposed Markov chain is also shown to asymptotically reach an equilibrium, and its limiting distribution converges to the marginal link-marking probabilities when the Markov chain is irreducible. Applying the two models, we analyze and contrast the delay scalability of two representative multicast signaling protocols: Soft-Synchronization Protocol (SSP) and Hop-By-Hop (HBH) algorithms.
Xi Zhang 0005, Kang G. Shin
IEEE/ACM Trans. Netw.2
2004 Soft Real-Time Communication over Ethernet with Adaptive Traffic Smoothing
abstract
Due to the low price and robustness resulting from its wide acceptance and deployment, Ethernet has become an attractive candidate for real-time control networks. However, it is difficult to build a real-time control network using the standard Ethernet because the Ethernet MAC protocol-1-persistent CSMA/CD protocol-may cause unpredictable access delay. When both real-time and nonreal-time packets are concurrently transported over an ordinary Ethernet, real-time (RT) packets from a node may experience a large delay due to 1) contention with nonRT packets in the local node where they originate and 2) collision with RT and nonRT packets from the other nodes. To resolve this problem, we design, implement, and evaluate an adaptive traffic smoother. Specifically, we design two adaptive traffic smoothers, one at the kernel level and the other at the user level. The kernel-level traffic smoother is installed between the IP layer and the Ethernet MAC layer for better performance, and the user-level traffic smoother is installed on top of the transport layer for better portability. The kernel-level traffic smoother first gives RT packets priority over nonRT packets in order to eliminate contention within the local node. Second, it smoothes nonRT traffic so as to reduce collision with RT packets from the other nodes. This traffic smoothing can dramatically decrease the packet-collision probability on the network. The traffic smoother, installed at each node, regulates the node's outgoing nonRT traffic to maintain a certain rate. In order to provide a reasonable nonRT throughput while providing probabilistic delay guarantees for RT traffic, the nonRT traffic-generation rate is allowed to adapt itself to the underlying network load condition. Our implementation of the traffic smoother requires only a minimal change in the OS kernel without any modification to the current standard of Ethernet MAC protocol or the TCP or UDP/IP stack. The traffic smoother has been implemented on the Linux OS and is shown to reduce the RT message deadline-miss ratio up to two orders of magnitude under a heavily loaded condition, while the nonRT throughput drops only by half. For better portability, we also implemented and evaluated a user-level traffic smoother on top of the transport layer. Moreover, we emulate a switch using a kernel-level traffic smoother to evaluate the performance of traffic smoother in a switched Ethernet environment that can scale to a large control network.
Seok-Kyu Kweon, Min Gyu Cho, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.3
2003 Hop-count filtering: an effective defense against spoofed DDoS traffic
abstract
IP spoofing has been exploited by Distributed Denial of Service (DDoS) attacks to (1) conceal flooding sources and localities in flooding traffic, and (2) coax legitimate hosts into becoming reflectors, redirecting and amplifying flooding traffic. Thus, the ability to filter spoofed IP packets near victims is essential to their own protection as well as to their avoidance of becoming involuntary DoS reflectors. Although an attacker can forge any field in the IP header, he or she cannot falsify the number of hops an IP packet takes to reach its destination. This hop-count information can be inferred from the Time-to-Live (TTL) value in the IP header. Using a mapping between IP addresses and their hop-counts to an Internet server, the server can distinguish spoofed IP packets from legitimate ones. Base on this observation, we present a novel filtering technique that is immediately deployable to weed out spoofed IP packets. Through analysis using network measurement data, we show that Hop-Count Filtering (HCF) can identify close to 90% of spoofed IP packets, and then discard them with little collateral damage. We implement and evaluate HCF in the Linux kernel, demonstrating its benefits using experimental measurements.
Haining Wang 0001, Kang G. Shin
CCS3
2003 Transforming Structural Model to Runtime Model of Embedded Software with Real-Time Constraints
abstract
The model-based methodology has proven to be effective for fast and low-cost development of embedded software. In the model-based development process, transforming a software structural model that describes the underlying application, to an implementable runtime model is a critical issue. Since the designed software will finally run on the target platform, non-functional issues like schedulability timing constraints and resource requirements have to be considered during the transformation. In this paper we propose a generic runtime model architecture that can best satisfy the non-functional requirements of the system, and a generic transformation method to convert a structural model to a runtime model in such an architecture. The transformation approach is based on the notion of end-to-end computations performed by the system in response to external stimuli. We demonstrate the advantages and effectiveness of the proposed method by constructing a software runtime model for a combined electronic throttle and air-fuel ratio control system.
Sharath Kodase, Shige Wang, Kang G. Shin
DATE3
2003 An Integrated Approach to Modeling and Analysis of Embedded Real-Time Systems Based on Timed Petri Net
abstract
In computer-based control systems, embedded software is taking over what mechanical and dedicated electronic systems used to do, that is, to engage and control the physical world, interacting directly with sensors and actuators. Therefore, software running on a digital processor is tightly-coupled with its surrounding physical environment. We propose an integrated approach based on Timed Petri-Nets for modeling and analysis of embedded real-time systems where real-time scheduling behavior of the controller software is explicitly represented at the model-level, together with the physical environment that it interacts with. This enables the designer to have an integrated view of the entire system while analyzing the system and making design decisions. We also describe a syntax-directed, automated translation procedure from Timed Petri-Nets to Timed Automata, thus enabling the use of model checkers such as UPPAAL for analysis purposes. We consider the railroad crossing problem as an application example, and evaluate alternatives for controller implementation on either single-processor or distributed multi-processor platforms based on the integrated approach.
Zonghua Gu 0001, Kang G. Shin
ICDCS2
2003 Algorithms for effective variable bit rate traffic smoothing
abstract
The transfer of prerecorded, compressed variable-bit-rate video requires multimedia services to support large fluctuations in bandwidth requirements on multiple time scales. Bandwidth smoothing techniques can reduce the burstiness of a VBR (variable bit rate) stream by transmitting data at a series of fixed rates, simplifying the allocation of resources in video servers and the communication network. The RCBR (renegotiated constant bit rate) service model seems ideally suited for smoothed VBR traffic which is piece-wise CBR. Zhimei Jiang (see Proc. IEEE Infocomm 98, p.676, 1998) proposed a dynamic programming algorithm to compute the optimal renegotiation schedule given the relative cost of renegotiation and client buffer size. We show that the schedule produced by his algorithm has high peak rates and frequent renegotiations. We propose another algorithm that computes a renegotiation schedule that has a slightly higher cost than the optimal schedule, but has other desirable properties, such as lower peak rate and lower frequency of renegotiations. We also consider proxy-based online smoothing, and propose an adaptive heuristic algorithm to generate renegotiation schedules at runtime without knowledge of future frame size information. We compare the schedule computed by the algorithm to the optimal schedule computed with full knowledge of future frame sizes.
Zonghua Gu 0001, Kang G. Shin
IPCCC2
2003 Statistical Characterization for Per-hop QoS
Mohamed A. El-Gendy, Abhijit Bose, Haining Wang 0001, Kang G. Shin
IWQoS4
2003 Improving Dependability of Real-Time Communication with Preplanned Backup Routes and Spare Resource Pool
Songkuk Kim, Kang G. Shin
IWQoS2
2003 MiSer: an optimal low-energy transmission strategy for IEEE 802.11a/h
abstract
Reducing the energy consumption by wireless communication devices is perhaps the most important issue in the widely-deployed and exponentially-growing IEEE 802.11 Wireless LANs (WLANs). TPC (Transmit Power Control) and PHY (physical layer) rate adaptation have been recognized as two most effective ways to achieve this goal. The emerging 802.11h standard, which is an extension to the current 802.11 MAC and the high-speed 802.11a PHY, will provide a structured means to support intelligent TPC.In this paper, we propose a novel scheme, called MiSer, that minimizes the communication energy consumption in 802.11a/h systems by combining TPC with PHY rate adaptation. The key idea is to compute offline an optimal rate-power combination table, and then at runtime, a wireless station determines the most energy-efficient transmission strategy for each data frame by a simple table lookup. Another key contribution of this paper is to provide a rigorous analysis of the relation among different radio ranges and TPC's effect on the interference in 802.11a/h systems, which justifies MiSer's approach to ameliorating the TPC-caused interference by transmitting the CTS frames at a stronger power level. Our simulation results show that MiSer delivers about 20% more data per unit of energy consumption than the PHY rate adaptation scheme without TPC, while outperforming single-rate TPC schemes significantly thanks to the excellent energy-saving capability of PHY rate adaptation.
Daji Qiao, Sunghyun Choi 0001, Kang G. Shin
MobiCom4
2003 RT-WLAN: a soft real-time extension to ORiNOCO Linux device driver
abstract
The current IEEE 802.11 wireless LAN (WLAN) systems are unable to support real-time applications because the underlying contention-based MAC (medium access control) protocol causes unpredictable delays. In this paper, we present the implementation details of a new RT-WLAN device driver module, which extends the original Linux device driver for the popular Agere ORiNOCO cards to support soft real-time communications. To our best knowledge, this is the first effort in providing real-time support in the WLAN environment at the device driver level. By shifting the design focus from the MAC layer, which is normally hard-coded in the NIC (network interface card), to the device driver level, which is between the system kernel and the MAC layer, our scheme has a clear advantage. Users can simply replace the original ORiNOCO driver with RT-WLAN, and then enjoy the benefits of real-time communications without having to change the NIC firmware or re-compile the Linux kernel. RT-WLAN uses two separate queues for real-time and non-real-time traffic. The real-time queue is served according to the EDF (earliest-deadline-first) policy, while the non-real-time queue is served in a FIFO (first-in-first-out) manner. Besides, an adaptive traffic smoother is implemented in RT-WLAN to regulate bursty non-real-time traffic before they are injected into the network, thus giving higher priority to in-progress real-time transmissions. Experimental results show that the desired real-time support and service differentiation among multiple real-time sessions are achieved by using RT-WLAN.
Daji Qiao, Kang G. Shin
PIMRC3
2003 On Soft Real-Time Guarantees on Ethernet
Min Gyu Cho, Kang G. Shin
RTCSA2
2003 An End-to-End Tool Chain for Multi-View Modeling and Analysis of Avionics Mission Computing Software
abstract
We present an end-to-end tool-chain for model-based design and analysis of component-based embedded real-time software, with avionics mission computing as an application domain. The tool-chain covers the entire system development lifecycle including modeling, analysis, code generation, and run-time instrumentation. Emphasis is placed on integration of tools developed by multiple institutions via standardized interface format definitions in XML. By capturing all relevant information explicitly in models at the design level, and performing analysis that provides insight into non-functional aspects of the system, we can raise the level of abstraction for the designer, and facilitate rapid system prototyping.
Zonghua Gu 0001, Shige Wang, Sharath Kodase, Kang G. Shin
RTSS4
2003 Persistent dropping: an efficient control of traffic aggregates
abstract
Flash crowd events (FCEs) present a real threat to the stability of routers and end-servers. Such events are characterized by a large and sustained spike in client arrival rates, usually to the point of service failure. Traditional rate-based drop policies, such as Random Early Drop (RED), become ineffective in such situations since clients tend to be persistent, in the sense that they make multiple retransmission attempts before aborting their connection. As it is built into TCP's congestion control, this persistence is very widespread, making it a major stumbling block to providing responsive aggregate traffic controls. This paper focuses on analyzing and building a coherent model of the effects of client persistence on the controllability of aggregate traffic. Based on this model, we propose a new drop strategy called persistent dropping to regulate the arrival of SYN packets and achieves three important goals: (1) it allows routers and end-servers to quickly converge to their control targets without sacrificing fairness, (2) it minimizes the portion of client delay that is attributed to the applied controls, and (3) it is both easily implementable and computationally tractable. Using a real implementation of this controller in the Linux kernel, we demonstrate its efficacy, up to 60% delay reduction for drop probabilities less than 0.5.
Hani Jamjoom, Kang G. Shin
SIGCOMM2
2003 Design and Implementation of Power-Aware Virtual Memory
Hai Huang 0002, Padmanabhan Pillai, Kang G. Shin
USENIX ATC, General Track3
2003 Assured forwarding fairness using equation-based packet marking and packet separation
Mohamed A. El-Gendy, Kang G. Shin
Comput. Networks2
2003 Energy-efficient PCF operation of IEEE 802.11a WLANs via transmit power control
Daji Qiao, Sunghyun Choi 0001, Amjad Soomro, Kang G. Shin
Comput. Networks4
2003 Evolution of the Internet QoS and support for soft real-time applications
abstract
The past few years have witnessed the emergence of many real-time networked applications on the Internet. These types of applications require special support from the underlying network such as reliability, timeliness, and guaranteed delivery, as well as different levels of service quality. Unfortunately, this support is not available within the current "best-effort" Internet architecture. In this paper, we review several mechanisms and frameworks proposed to provide network- and application-level quality of service (QoS) in the next-generation Internet. We first discuss the QoS requirements of many of the above-mentioned real-time applications, and then we categorize them according to the required service levels. We also describe the various building blocks often used in QoS approaches. We briefly present asynchronous transfer mode (ATM) and Internet Protocol precedence. Then, we present and compare two service architectures recently adopted by the Internet Engineering Task Force, called integrated services (IntServ) and differentiated services (DiffServ), for providing per-flow and aggregated-flow service guarantees, respectively. We focus on DiffServ because it is a candidate QoS framework to be used in next-generation Internet along with multiprotocol label switching and traffic engineering. We also examine several operational and research issues that need to be resolved before such frameworks can be put in practice.
Mohamed A. El-Gendy, Abhijit Bose, Kang G. Shin
Proc. IEEE3
2003 User-Level QoS-Adaptive Resource Management in Server End-Systems
abstract
Proliferation of QoS-sensitive client-server Internet applications such as high-quality audio, video-on-demand, e-commerce, and commercial Web hosting has generated an impetus to provide performance guarantees. These applications require a guaranteed minimum amount of resources to operate acceptably to the users, thus calling for QoS-provisioning mechanisms. One good place to locate such mechanisms is in server communication subsystems. Server-side communication subsystems manage an increasing number of connection end-points, thus readily controlling important bottleneck resources. We propose, implement, and evaluate a novel communication server architecture that maximizes the aggregate utility of QoS-sensitive connections for a community of clients even in the case of overload. A contribution of this architecture is that it manages QoS from the user space and is transparent to the application. It does not require modifications to the OS kernel, which improves portability and reduces development cost. Results from an experimental evaluation on a microkernel indicate that it achieves end-system overload protection and traffic prioritization, improves insulation between independent clients, adapts to offered load, and enhances aggregate service utility.
Tarek F. Abdelzaher, Kang G. Shin, Nina T. Bhatti
IEEE Trans. Computers2
2003 A Fault-Tolerant Scheduling Algorithm for Real-Time Periodic Tasks with Possible Software Faults
abstract
A hard real-time system is usually subject to stringent reliability and timing constraints. One way to avoid missing deadlines is to trade the quality of computation results for timeliness, and software fault tolerance is often achieved with the use of redundant programs. A deadline mechanism which combines these two methods is proposed to provide software fault tolerance in hard real-time periodic task systems. We consider the problem of scheduling a set of real-time periodic tasks each of which has two versions: primary and alternate. The primary version contains more functions and produces good quality results, but its correctness is more difficult to verify. The alternate version contains only the minimum required functions and produces less precise results and its correctness is easy to verify. We propose a scheduling algorithm which 1) guarantees either the primary or alternate version of each critical task to be completed in time and 2) attempts to complete as many primaries as possible. Our basic algorithm uses a fixed priority-driven preemptive scheduling scheme to preallocate time intervals to the alternates and, at runtime, attempts to execute primaries first. An alternate will be executed only if necessary because of time or bugs.
Ching-Chih Han, Kang G. Shin, Jian Wu 0028
IEEE Trans. Computers2
2003 Delay analysis of feedback-synchronization signaling for multicast flow control
abstract
Feedback signaling plays a key role in flow control because the traffic source relies on the signaling information to make correct and timely flow-control decisions. Design of an efficient signaling algorithm is a challenging task since the signaling messages can tolerate neither error nor latency. Multicast flow-control signaling imposes two additional challenges: scalability and feedback synchronization. Previous research on multicast feedback-synchronization signaling has mainly focused on algorithm design and implementation. However, the delay properties of these algorithms are, despite their vital importance, neither well understood nor thoroughly studied. We develop both deterministic and statistical binary-tree models to study the delay performance of the multicast signaling algorithms. The deterministic model is used to derive the expressions of each path's feedback roundtrip time in a multicast tree, while the statistical model is employed to derive the general probability distributions of each path becoming the multicast-tree bottleneck. Using these models, we analyze and contrast the signaling delay scalability of two representative multicast signaling protocols - the soft-synchronization protocol (SSP) and the hop-by-hop (HBH) scheme - by deriving the first and second moments of multicast signaling delays. Also derived is the optimal flow-control update interval for SSP to minimize the multicast signaling delay.
Xi Zhang 0005, Kang G. Shin
IEEE/ACM Trans. Netw.2
2003 Statistical Real-Time Communication over Ethernet
abstract
In order to realize real-time communication over Ethernet or fast Ethernet, one must be able to bound the medium access time within an acceptable limit. The multiple access nature of Ethernet makes it impossible to guarantee a deterministic medium access time (hence, packet-delivery deadlines) to individual stations. However, one can bound the medium access time statistically by limiting the packet-arrival rate at the medium access control (MAC) layer. While considering automated manufacturing systems as the main target application, this paper addresses the connection admission control (CAC) problem for statistically bounding the medium access time of Ethernet. Specifically, a packet is guaranteed to have a medium access time smaller than a predefined bound with a certain probability if the instantaneous packet-arrival rate is kept below a certain threshold. Through a mathematical analysis, we first derived such a threshold. In order to keep the packet-arrival rate under the given threshold, we developed and installed middleware which 1) resides between the transport layer and the Ethernet datalink layer, and 2) smooths packet streams between them. The implementation of this middleware requires only a minimal change in the OS kernel without modification to the current standard of Ethernet MAC protocol or TCP or UDP/IP stack. In order to solve the CAC problem, we derived the probability of transmitting a packet successfully upon each trial by modeling the MAC protocol, 1-persistent CSMA/CD, and the collision resolution protocol inary exponential backoff - of Ethernet. Our in-depth simulation results have shown this analytic model to provide a reasonably accurate estimate of packet-loss (or deadline-miss) ratio over fast Ethernet. Finally, we implemented the middleware on the Linux OS, experimentally demonstrating the effectiveness of our approach in providing real-time communication over Ethernet.
Seok-Kyu Kweon, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.2
2003 Transport-Aware IP Routers: A Built-In Protection Mechanism to Counter DDoS Attacks
abstract
The lack-of service differentiation and resource isolation by current IP routers exposes their vulnerability to Distributed Denial of Service (DDoS) attacks (Garber, 2000), causing a serious threat to the availability of Internet services. Based on the concept of layer-4 service differentiation and resource isolation, where the transport-layer information is inferred from the IP headers and used for packet classification and resource management, we present a transport-aware IP (tIP) router architecture that provides fine-grained service differentiation and resource isolation among different classes of traffic aggregates. The tIP router architecture consists of a fine-grained Quality-of-Service (QoS) classifier and an adaptive weight-based resource manager. A two-stage packet-classification mechanism is devised to decouple the fine-grained QoS lookup from the usual routing lookup at core routers. The fine-grained service differentiation and resource isolation provided inside the tIP router is a powerful built-in protection mechanism to counter DDoS attacks, reducing the vulnerability of Internet to DDoS attacks. Moreover, the tIP architecture is stateless and compatible with the Differentiated Service (DiffServ) infrastructure. Thanks to its scalable QoS support for TCP control segments, the tIP router supports bidirectional differentiated services for TCP sessions.
Haining Wang 0001, Kang G. Shin
IEEE Trans. Parallel Distributed Syst.2