VLDB 2026 Research / reviewers in the wild / expert
Shyhtsun Felix Wu
dblp:w/ShFWu
· DBLP profile ↗
73ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0001-6033-5353ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 27Security and privacy · 18 · 1 first-authorHuman-computer interaction and ubiquitous computing · 13 · 3 since 2021Databases, data management, data science and information retrieval · 11 · 3 since 2021Artificial intelligence and machine learning · 10 · 3 since 2021Systems, architecture and hardware · 7 · 1 since 2021Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Online Social Community Neighborhood Formation
George A. Barnett, Norman S. Matloff, Shyhtsun Felix Wu |
ASONAM (1) | 4 |
| 2024 | Online Social Community City Classification
George A. Barnett, Norman S. Matloff, Shyhtsun Felix Wu |
ASONAM (4) | 4 |
| 2023 | Online Social Community Sub-Location ClassificationabstractFacebook public pages are a popular form of online social network (OSN) communities. The "like" connections between public pages create a graph of pages on Facebook. Geographic location is a crucial piece of metadata for pages, but it is often omitted by page managers. We propose a classification algorithm to restore the missing subdivision location of Facebook public pages. We propose neighborhood state distribution vectors as features for graph neural networks to classify the state of the pages. Then, we define intrastate and interstate Facebook public pages based on the high-probability state label outputted by the classification model. Finally, we profile states with different influences over the online communities by analyzing the classification confusion matrix, interstate page percentages, and interstate pages across state borders. Our method achieves better accuracy (87.52%) and F1 score (0.8756) than previous studies (66.2% and 73.08%). Xiaoyun Wang 0001, Chun-Ming Lai, Shyhtsun Felix Wu |
ASONAM | 4 |
| 2021 | The implementation of data storage and analytics platform for big data lake of electricity usage with spark
Chao-Tung Yang, Tzu-Yang Chen, Endah Kristiani, Shyhtsun Felix Wu |
J. Supercomput. | 4 |
| 2018 | Geo-Location Identification of Facebook PagesabstractOnline Social Network (OSN) communities serve as different platforms for multiple users' interaction - people behaving diversely among distinctive communities - such as entertainment, global and local discussion communities. However, attribute identification among online discussion communities remain largely unexplored. In this paper, we describe and analyze the geo-location property of large-scale Facebook public pages (15M pages). We propose a framework utilizing the connectivity of the page-like graph to predict the missing geo-location information based on Breadth-First Search (BFS). Our method achieves a satisfyingly high accuracy (89 %) on identifying the state location attribute of unknown United States (US) pages. Our empirical results offer a better understanding of regional social analysis and target audience broadcasting. Chun-Ming Lai, Jon William Chapman, Shyhtsun Felix Wu, George A. Barnett |
ASONAM | 4 |
| 2017 | Attacking strategies and temporal analysis involving Facebook discussion groupsabstractOnline social network (OSN) discussion groups are exerting significant effects on political dialogue. In the absence of access control mechanisms, any user can contribute to any OSN thread. Individuals can exploit this characteristic to execute targeted attacks, which increases the potential for subsequent malicious behaviors such as phishing and malware distribution. These kinds of actions will also disrupt bridges among the media, politicians, and their constituencies. For the concern of Security Management, blending malicious cyberattacks with online social interactions has introduced a brand new challenge. In this paper we describe our proposal for a novel approach to studying and understanding the strategies that attackers use to spread malicious URLs across Facebook discussion groups. We define and analyze problems tied to predicting the potential for attacks focused on threads created by news media organizations. We use a mix of macro static features and the micro dynamic evolution of posts and threads to identify likely targets with greater than 90% accuracy. One of our secondary goals is to make such predictions within a short (10 minute) time frame. It is our hope that the data and analyses presented in this paper will support a better understanding of attacker strategies and footprints, thereby developing new system management methodologies in handing cyber attacks on social networks. Chun-Ming Lai, Xiaoyun Wang 0001, Yunfeng Hong, Shyhtsun Felix Wu, Patrick D. McDaniel, Hasan Çam |
CNSM | 5 |
| 2017 | Defining and Detecting Environment Discrimination in Android Apps
Yunfeng Hong, Yongjian Hu, Chun-Ming Lai, Shyhtsun Felix Wu, Iulian Neamtiu, Patrick D. McDaniel, Paul L. Yu, Hasan Çam, Gail-Joon Ahn |
SecureComm | 4 |
| 2015 | Localizing Temporal Anomalies in Large Evolving GraphsabstractMining for anomalies in graph structured datasets is an important and challenging problem for many applications including security, health care, and social media. In this paper, we propose a novel framework to localize temporal anomalies in large evolving graphs with reduced false alarm rate. Specifically, we first introduce a node-centric model based on Vector Autoregression to analyze node behavior history in dynamic graphs. Then we develop two community-centric models to reduce the amount of false positive results by tracking the structural change and dynamics of graph communities. We analyze the performance of our proposed anomaly localization framework on several synthetic and real-world data sets including Enron email network data, an enterprise network traffic data, and CNN public Facebook page. All experimental results show the effectiveness and consistency of our framework in localizing temporal anomalies with reduced false alarm rate. Chunsheng Victor Fang, Derek Lin, Shyhtsun Felix Wu |
SDM | 4 |
| 2013 | The influence of feedback with different opinions on continued user participation in online newsgroupsabstractWith the popularity of social media in recent years, it has been a critical topic for social network designer to understand the factors that influence continued user participation in online newsgroups. Our study examines how feedback with different opinions is associated with participants' lifetime in online newsgroups. Firstly, we propose a new method of classifying different opinions among user interaction contents. Generally, we leverage user behavior information in online newsgroups to estimate their opinions and evaluate our classification results based on linguistic features. In addition, we also implement this opinion classification method into our SINCERE system as a real-time service. Based on this opinion classification tool, we use survival analysis to examine how others' feedback with different opinions influence continued participation. In our experiment, we analyze more than 88,770 interactions on the official Occupy LA Facebook page. Our final result shows that not only the feedback with the same opinions as the user, but also the feedback with different opinions can motivate continued user participation in online newsgroup. Furthermore, an interaction of feedback with both the same and different opinions can boost user continued participation to the greatest extent. This finding forms the basis of understanding how to improve online service in social media. Keith C. Wang, Fredrik Erlandsson, Shyhtsun Felix Wu, Robert Faris |
ASONAM | 4 |
| 2013 | SmartWiki: A reliable and conflict-refrained Wiki model based on reader differentiation and social context analysis
Haifeng Zhao 0004, William Kallander, Henric Johnson, Shyhtsun Felix Wu |
Knowl. Based Syst. | 4 |
| 2012 | On a Triadic Approach to Connect Microstructural Properties to Social Macrostructural PatternsabstractSocial macrostructures, such as structural balance, ranked clusters and transitivity, are of great importance on account of their abilities to reflect the underlying social psychological processes about the formation and evolution of relationships among people. Here we present a detailed study on examining the existence and evolution of social macrostructures in an empirical online social network, and exploring how they can be explained by network micro structural properties, i.e. nodal in degree and out degree and dyadic feature. We establish the micro-macro linkage by analyzing the network triadic patterns. Based on a novel clustering coefficient based network sampling approach, we show that the distribution of observed triad census in our data is low dimensional and can be greatly explained by network dyadic properties. In a time series analysis, we observe that our network exhibits strong tendencies towards balanced, transitive and clustered social macrostructure given the nodal and dyadic characteristics. Our findings supplement the studies on structural properties of online social network by providing more insights on the relation between network macrostructures and the micro-level social processes that result in them. And they form the basis to understand better how online social media systems change the information and communication fabric of our society. Yuxi Hu 0001, Mina Doroud, Shyhtsun Felix Wu |
ASONAM | 3 |
| 2012 | Collaborative assessment of functional reliability in wireless networksabstractNodes that are part of a multihop wireless network, typically deployed in mission critical settings, are expected to perform specific functions. Establishing a notion of reliability of the nodes with respect to each function (referred to as functional reliability or FR) is essential for efficient operations and management of the network. This is typically assessed based on evidence collected by nodes with regards to other nodes in the network. However, such evidence is often affected by factors such as channel induced effects and interference. In multihop contexts, unreliable intermediary relays may also influence evidence. We design a framework for collaborative assessment of the FR of nodes, with respect to different types of functions; our framework accounts for the above factors that influence evidence collection. Each node (say Chloe) in the network derives the FR of other nodes (say Jack) based on two types of evidence: (i) direct evidence, based on her direct transactions with each such node and (ii) indirect evidence, based on feedback received regarding Jack from others. Our framework is generic and is applicable in a variety of contexts. We also design a module that drastically reduces the overhead incurred in the propagation of indirect evidence at the expense of slightly increased uncertainty in the assessed FR values. We implement our framework on an indoor/outdoor wireless testbed. We show that with our framework, each node is able to determine the FR for every other node in the network with high accuracy. Our indirect evidence propagation module decreases the overhead by 37% compared to a simple flooding based evidence propagation, while the accuracy of the FR computations is decreased only by 8%. Finally, we examine the effect of different routing protocols on the accuracy of the assessed values. Zi Feng, Konstantinos Pelechrinis, Srikanth V. Krishnamurthy, Ananthram Swami, Shyhtsun Felix Wu, Munindar P. Singh |
MASS | 5 |
| 2011 | Social Network User LifetimeabstractOnline Social Network (OSN) operators are interested in promoting usage among their users, and try a variety of strategies to encourage use. Some recruit celebrities to their site, some allow third parties to develop applications that run on their sites, and all have features intended to encourage use. As important as usage is, we are unaware of any studies into what influences users to be active and to remain online. This paper is the first work studying the lifetime of OSN users, examining the factors that influence lifetime in one OSN, Buzz net. The major contributions of this work are the study of active lifetime, the features and behaviors that encourage activity, and the comparison of active lifetime to passive lifetime. Juan Lang, Shyhtsun Felix Wu |
ASONAM | 2 |
| 2011 | Design and Implementation of FAITH, An Experimental System to Intercept and Manipulate Online Social InformaticsabstractSocial informatics is the core of Facebook's business and is its most valuable asset which consists of the social graph and the private data of over 500 million users. However, without secure methods of managing this data, Face book has become vulnerable to privacy risks and devaluation. In Facebook's model, users are asked upon access to grant applications the required permissions without sufficient knowledge of the applications' intentions. As a result, if they are deceived, users risk the exposure of sensitive and personal data. This paper presents a system dubbed FAITH (Face book Applications: Identification, Transformation & Hyper visor) to mitigate or eliminate these issues by enhancing the management of social data. First, FAITH allows users to adjust the visibility of their social informatics for each individual application depending on how much they trust the application. Users can configure FAITH to let non-trusted applications run with the least privileges (least amount of social informatics) to minimize potential privacy leaks. Second, FAITH logs the activities of applications to assist users in making more secure decisions. Users can closely monitor each activity performed by applications to adjust their privacy settings more securely. Third, FAITH allows users to transform their social graph such that different applications see different social graphs preventing the formation of friendship inflation caused by applications. The implementation of FAITH only needs the resources and tools available to the public by Face book and requires no further cooperation from the social network. FAITH is a prototype system: the design and concept can be extended to secure other OSNs (Online Social Networks). Currently, FAITH contains thirteen Face book social applications and has been officially released for public usage with approximately two hundred monthly active users as of now. Ruaylong Lee, Roozbeh Nia, Jason Hsu, Karl N. Levitt, Jeff Rowe, Shyhtsun Felix Wu, Shaozhi Ye |
ASONAM | 6 |
| 2011 | Your best might not be good enough: Ranking in collaborative social search enginesabstract—A relevant feature of online social networks like Facebook is the scope for users to share external information from the web with their friends by sharing an URL. The phenomenon of sharing has bridged the web graph with the social network graph and the shared knowledge in ego networks Prantik Bhattacharyya, Jeff Rowe, Shyhtsun Felix Wu, Karen Zita Haigh, Niklas Lavesson, Henric Johnson |
CollaborateCom | 3 |
| 2011 | Inter-domain collaborative routing (IDCR): Server selection for optimal client performance
Martin O. Nicholes, Chen-Nee Chuah, Shyhtsun Felix Wu, Biswanath Mukherjee |
Comput. Commun. | 3 |
| 2010 | Crawling Online Social GraphsabstractExtensive research has been conducted on top of online social networks (OSNs), while little attention has been paid to the data collection process. Due to the large scale of OSNs and their privacy control policies, a partial data set is often used for analysis. The data set analyzed is decided by many factors including the choice of seeds, node selection algorithms, and the sample size. These factors may introduce biases and further contaminate or even skew the results. To evaluate the impact of different factors, this paper examines the OSN graph crawling problem, where the nodes are OSN users and the edges are the links (or relationship) among these users. More specifically, by looking at various factors in the crawling process, the following problems are addressed in this paper: 1) Efficiency: How fast different crawlers discover nodes/links; 2) Sensitivity: How different OSNs and the number of protected users affect crawlers; 3) Bias: How major graph properties are skewed. To the best of our knowledge, our simulations on four real world online social graphs provide the first in-depth empirical answers to these questions. Shaozhi Ye, Juan Lang, Shyhtsun Felix Wu |
APWeb | 3 |
| 2009 | Protecting Kernel Code and Data with a Virtualization-Aware Collaborative Operating SystemabstractThe traditional virtual machine usage model advocates placing security mechanisms in a trusted VM layer and letting the untrusted guest OS run unaware of the presence of virtualization. In this work we challenge this traditional model and propose a collaboration approach between a virtualization-aware operating system and a VM layer to prevent tampering against kernel code and data. Our integrity model is a relaxed version of Biba's and the main idea is to have all attempted writes into kernel code and data segments checked for validity at VM level. The OS-VM collaboration bridges the semantic gap between tracing low integrity objects at OS-level (files, processes, modules, allocated areas) and architecture-level (memory and registers). We have implemented this approach in a proof-of-concept prototype and have successfully tested it against 6 rootkits (including a non-control data attack) and 4 real-world benign LKM/drivers. All rootkits were prevented from corrupting kernel space and no false positive was triggered for benign modules. Performance measurements show that the average overhead to the VM for the OS-VM communication is low (7%, CPU benchmarks). The greatest overhead is caused by the memory monitoring module inside the VM: 1.38X alone and 1.46X when combined with the OS-VM communication. For OS microbenchmarks the slowdown for the OS-VM communication was 1.16X on average. Daniela Oliveira 0001, Shyhtsun Felix Wu |
ACSAC | 2 |
| 2009 | Social Network Model Based on Keyword CategorizationabstractA user profile on an online social network is characterized by its profile entries (keywords). In this paper, we study the relationship between semantic similarity of user keywords and the social network topology. First, we present a 'forest' model to categorize keywords and define the notion of distance between keywords across multiple categorization trees (i.e., a forest). Second, we use the keyword distance to define similarity functions between a pair of users and show how social network topology can be modeled accordingly. Third, we validate our social network topology model, using a simulated social graph, against a real life social graph dataset. Prantik Bhattacharyya, Ankush Garg, Shyhtsun Felix Wu |
ASONAM | 3 |
| 2009 | Design and Implementation of Davis Social Links OSN Kernel
Kelcey Chan, Shaozhi Ye, Prantik Bhattacharyya, Ankush Garg, Xiaoming Lu, Shyhtsun Felix Wu |
WASA | 7 |
| 2008 | Using Soft-Line Recursive Response to Improve Query Aggregation in Wireless Sensor NetworksabstractIn large wireless sensor networks (WSNs), each hop might incur varying delays due to medium access contention, transmission and computation delays. Fast and efficient query responses are essential to network performance and maintenance. To save energy in battery-powered sensors, it is desirable that data be aggregated or compressed along the way toward the base-station (BS). The common method to aggregate data from network edge to the BS uses a hard-line precomputed timer that requires sensors near the network edge to respond to a query earlier than sensors in the vicinity of the BS [1], [2]. Such rigid scheduling ignores the WSNs's topology and stability. Aggregation opportunities are wasted if the query response timer is set incorrectly. Estimating and allocating precise per- hop communication timers for each node in a large WSN is difficult because timing depends on the network dynamics. We develop a novel, generic and scalable method, which we call soft-line recursive response (SRR), that bases response-wait on actual response times to previous queries using a history buffer, and therefore, is tolerant of network faults or temporal delays. Our simulations show that SRR can improve aggregation opportunities up to 120% over the hard-line approach, while increasing delay less than 5%. SRR reduces query response traffic and data redundancy in both homogeneous and heterogeneous static and mobile WSNs with a maximum O(N) transmission overhead in large WSNs of N nodes and O(logb) update cost where b is the history buffer size. Xiaoming Lu, Matthew Spear, Karl N. Levitt, Norman S. Matloff, Shyhtsun Felix Wu |
ICC | 5 |
| 2008 | iBubble: Multi-Keyword Routing Protocol for Heterogeneous Wireless Sensor NetworksabstractMany tasks require multiple sensing capabilities; in wireless sensor networks (WSNs), it is expensive to deploy a homogeneous network wherein every sensor has the same functionality. Instead, it is economical to deploy a heterogeneous network wherein sensors differ in their capabilities; in such a network, efficient data querying is essential. We propose a multi-keyword routing protocol, iBubble, for heterogeneous wireless sensor networks (HWSNs) where keywords describe sensor functionalities. iBubble provides an efficient query interface for locating data; queries are routed only along paths with nodes matching the query. iBubble utilizes an intelligent bubbling mechanism to propagate keywords to the base-station (BS). The keywords are aggregated via a novel use of lattices to reduce network cost. We show that iBubble can emulate diffusion and generally produce less traffic by restricting the query dissemination based upon both application type and data value. Our study analytically compares iBubble and diffusion, and formally characterizes the conditions required for iBubble to outperform diffusion in both static (fixed) and dynamic (mobile) networks. We did extensive simulations, our results match our theory and show that iBubble can outperform diffusion in many heterogeneous deployments when keyword distributions are "clustered" enough to satisfy the fraction of the network involved in a query/update defined by our analytical bound. Additionally, iBubble handles mobility, fault-tolerance, and provides network diagnosis via keyword bubbling. By utilizing keywords, iBubble bridges many routing and energy problems prevalent in WSNs, and provides a simple, uniform solution. Xiaoming Lu, Matthew Spear, Karl N. Levitt, Shyhtsun Felix Wu |
INFOCOM | 4 |
| 2008 | Towards Automatically Generating Double-Free Vulnerability Signatures Using Petri Nets
Ryan Iwahashi, Daniela Oliveira 0001, Shyhtsun Felix Wu, Jedidiah R. Crandall, Young-Jun Heo, Jintae Oh, Jong-Soo Jang |
ISC | 3 |
| 2008 | Bezoar: Automated virtual machine-based full-system recovery from control-flow hijacking attacksabstractSystem availability is difficult for systems to maintain in the face of Internet worms. Large systems have vulnerabilities, and if a system attempts to continue operation after an attack, it may not behave properly. Traditional mechanisms for detecting attacks disrupt service and current recovery approaches are application-based and cannot guarantee recovery in the face of exploits that corrupt the kernel, involve multiple processes or target multithreaded network services. This paper presents Bezoar, an automated full-system virtual machine-based approach to recover from zero-day control-flow hijacking attacks. Bezoar tracks down the source of network bytes in the system and after an attack, replays the checkpointed run while ignoring inputs from the malicious source. We evaluated our proof-of-concept prototype on six notorious exploits for Linux and Windows. In all cases, it recovered the full system state and resumed execution. Bezoar incurs low overhead to the virtual machine: less than 1% for the recovery and log components and approximately 1.4X for the memory monitor component that tracks down network bytes, for five SPEC INT 2000 benchmarks. Daniela Oliveira 0001, Jedidiah R. Crandall, Gary Wassermann, Shaozhi Ye, Shyhtsun Felix Wu, Zhendong Su 0001, Fred Chong |
NOMS | 5 |
| 2008 | Optimal Cost, Collaborative, and Distributed Response to Zero-Day Worms - A Control Theoretic Approach
Senthilkumar G. Cheetancheri, John Mark Agosta, Karl N. Levitt, Shyhtsun Felix Wu, Jeff Rowe |
RAID | 4 |
| 2007 | CLID: A general approach to validate security policies in a dynamic networkabstractMany researchers have considered security policy management, including how to configure policies manually and even how to automatically generate security policies based on security requirements. Both can be error prone, especially when properties of the network topology change, because security requirements are usually not bound to any particular route path. Our DETER lab emulation results show that conflicts could be caused by these factors. Therefore, a systematic way to validate the correctness of the security policies is essential. This paper presents an approach, CLID (conflict and looping identification and detection), to verify whether a set of security policies (e.g. IPSec/VPN tunnels) satisfy the given security requirements, without causing any conflicts. This approach utilizes the definition of a security policy lo include network routing data as well as traffic selector information, thus it works for general network topologies. We also analyze and justify the correctness of the approach. The paper concludes with our simulation results and addresses future work. Chip Martel, Shyhtsun Felix Wu |
Integrated Network Management | 3 |
| 2007 | Interactive Informatics on Internet InfrastructureabstractWe present the design and evaluation of 14, a network infrastructure that enables information exchange and collaboration among different domains. 14 can help with network management in many scenarios, such as when eliminating the unwanted traffic to improve the network performance as well as diagnosing the network problems. We present the distributed denial-of-service (DDoS) attack as an example to demonstrate the advantages of 14. Simulation results show that 14 can significantly reduce the amount of DDoS attack packets and dramatically improve the quality of services received by legitimate users. Our design provides attractive properties, such as incremental deployment as well as incentives for such deployment etc. V. Rao Vemuri, Shyhtsun Felix Wu, S. J. Ben Yoo |
Integrated Network Management | 3 |
| 2007 | Filter-Based RFD: Can We Stabilize Network Without Sacrificing Reachability Too Much?
Ke Zhang 0026, Shyhtsun Felix Wu |
Networking | 2 |
| 2007 | Bounds on the Performance of P2P Networks Using Tit-for-Tat StrategiesabstractThe demand for cheap broadband Internet for nomadic users has created a market for Internet sharing. Wi- Fi communities which allow their users to share their wired Internet connections have emerged and become increasingly popular. Organizations like FON promise to provide free wireless Internet access in many places. However, user authentication is the Achilles heel of these systems. A user that allows other community members to use its access point must expect to be held responsible for other users' actions. Moreover, these Wi-Fi sharing systems are often insecure which allows eavesdroppers to gather sensitive information on the wireless link. This work provides efficient, scalable, and secure access control for large Wi-Fi sharing systems. The host identity protocol (HIP) is used as a building block for a solution which supports strong user authentication as well as mobility support for nomadic users. In our presentation, we show the feasibility and effectiveness of this approach by demonstrating the PISA authentication protocol in action. Dimitri do B. DeFigueiredo, Balaji Venkatachalam, Shyhtsun Felix Wu |
Peer-to-Peer Computing | 3 |
| 2006 | Temporal search: detecting hidden malware timebombs with virtual machinesabstractWorms, viruses, and other malware can be ticking bombs counting down to a specific time, when they might, for example, delete files or download new instructions from a public web server. We propose a novel virtual-machine-based analysis technique to automatically discover the timetable of a piece of malware, or when events will be triggered, so that other types of analysis can discern what those events are. This information can be invaluable for responding to rapid malware, and automating its discovery can provide more accurate information with less delay than careful human analysis.Developing an automated system that produces the timetable of a piece of malware is a challenging research problem. In this paper, we describe our implementation of a key component of such a system: the discovery of timers without making assumptions about the integrity of the infected system's kernel. Our technique runs a virtual machine at slightly different rates of perceived time (time as seen by the virtual machine), and identifies time counters by correlating memory write frequency to timer interrupt frequency.We also analyze real malware to assess the feasibility of using full-system, machine-level symbolic execution on these timers to discover predicates. Because of the intricacies of the Gregorian calendar (leap years, different number of days in each month, etc.) these predicates will not be direct expressions on the timer but instead an annotated trace; so we formalize the calculation of a timetable as a weakest precondition calculation. Our analysis of six real worms sheds light on two challenges for future work: 1) time-dependent malware behavior often does not follow a linear timetable; and 2) that an attacker with knowledge of the analysis technique can evade analysis. Our current results are promising in that with simple symbolic execution we are able to discover predicates on the day of the month for four real worms. Then through more traditional manual analysis we conclude that a more control-flow-sensitive symbolic execution implementation would discover all predicates for the malware we analyzed. Jedidiah R. Crandall, Gary Wassermann, Daniela Oliveira 0001, Zhendong Su 0001, Shyhtsun Felix Wu, Fred Chong |
ASPLOS | 5 |
| 2006 | An Integrated Solution to Protect Link State Routing against Faulty Intermediate RoutersabstractThe importance of the routers in the network and the vulnerability in the nature of the link state routing protocol highlight the necessity of effective routing protection against variant attacks. One of the severe attacks is from the faulty intermediate router (FIR) which intentionally compromises the LSA messages passing by and pollutes the routing tables of its downstream routers. Current security mechanisms are either too expensive or vulnerable to prevent this type of inside attack. To address the FIR attack, in this paper, we present a novel cost-reduced integrated solution which combines both fault-detection operations from routers and fault-tracing response from network management components. The significant properties of our system are the detectability of the abnormal behavior toward the LSAs and the traceability of the FIRs generating those bogus LSAs. The analysis of the memory requirement and the communication cost in our design demonstrate the feasibility and efficiency of our system Shyhtsun Felix Wu |
NOMS | 2 |
| 2006 | Minos: Architectural support for protecting control dataabstractWe present Minos, a microarchitecture that implements Biba's low water-mark integrity policy on individual words of data. Minos stops attacks that corrupt control data to hijack program control flow, but is orthogonal to the memory model. Control data is any data that is loaded into the program counter on control-flow transfer, or any data used to calculate such data. The key is that Minos tracks the integrity of all data, but protects control flow by checking this integrity when a program uses the data for control transfer. Existing policies, in contrast, need to differentiate between control and noncontrol data a priori , a task made impossible by coercions between pointers and other data types, such as integers in the C language. Our implementation of Minos for Red Hat Linux 6.2 on a Pentium-based emulator is a stable, usable Linux system on the network on which we are currently running a web server (http://minos.cs.ucdavis.edu). Our emulated Minos systems running Linux and Windows have stopped ten actual attacks. Extensive full-system testing and real-world attacks have given us a unique perspective on the policy tradeoffs that must be made in any system, such as Minos; this paper details and discusses these. We also present a microarchitectural implementation of Minos that achieves negligible impact on cycle time with a small investment in die area, as well as and minor changes to the Linux kernel to handle the tag bits and perform virtual memory swapping. Jedidiah R. Crandall, Shyhtsun Felix Wu, Fred Chong |
ACM Trans. Archit. Code Optim. | 2 |
| 2005 | On deriving unknown vulnerabilities from zero-day polymorphic and metamorphic worm exploitsabstractVulnerabilities that allow worms to hijack the control flow of each host that they spread to are typically discovered months before the worm outbreak, but are also typically discovered by third party researchers. A determined attacker could discover vulnerabilities as easily and create zero-day worms for vulnerabilities unknown to network defenses. It is important for an analysis tool to be able to generalize from a new exploit observed and derive protection for the vulnerability.Many researchers have observed that certain predicates of the exploit vector must be present for the exploit to work and that therefore these predicates place a limit on the amount of polymorphism and metamorphism available to the attacker. We formalize this idea and subject it to quantitative analysis with a symbolic execution tool called DACODA. Using DACODA we provide an empirical analysis of 14 exploits (seven of them actual worms or attacks from the Internet, caught by Minos with no prior knowledge of the vulnerabilities and no false positives observed over a period of six months) for four operating systems.Evaluation of our results in the light of these two models leads us to conclude that 1) single contiguous byte string signatures are not effective for content filtering, and token-based byte string signatures composed of smaller substrings are only semantically rich enough to be effective for content filtering if the vulnerability lies in a part of a protocol that is not commonly used, and that 2) practical exploit analysis must account for multiple processes, multithreading, and kernel processing of network data necessitating a focus on primitives instead of vulnerabilities. Jedidiah R. Crandall, Zhendong Su 0001, Shyhtsun Felix Wu, Fred Chong |
CCS | 3 |
| 2005 | Experiences Using Minos as a Tool for Capturing and Analyzing Novel Worms for Unknown Vulnerabilities
Jedidiah R. Crandall, Shyhtsun Felix Wu, Fred Chong |
DIMVA | 2 |
| 2005 | TCPtransform: Property-Oriented TCP Traffic Transformation
Seung-Sun Hong, Fiona Wong, Shyhtsun Felix Wu, Bjorn Lilja, Tony Y. Yohansson, Henric Johnson, Ame Nelsson |
DIMVA | 3 |
| 2005 | On Interactive Internet Traffic Replay
Seung-Sun Hong, Shyhtsun Felix Wu |
RAID | 2 |
| 2005 | Design, Implementation, and Evaluation of "FRiTrace"
Wayne Huang 0002, J. L. Cong, Chien-Long Wu, Shyhtsun Felix Wu |
SEC | 5 |
| 2004 | Threat Analysis on NEtwork MObility (NEMO)
Souhwan Jung, Shyhtsun Felix Wu, HyunGon Kim |
ICICS | 3 |
| 2004 | An analysis on selective dropping attack in BGPabstractPrevious studies show that current inter-domain routing protocol, border gateway protocol (BGP), is vulnerable to various attacks. Previously, the major concern about BGP security is that malicious BGP routers can arbitrarily falsify BGP routing messages and spread out incorrect routing information. However, one type of attack, which we term as the selective dropping attack, has been largely neglected in literatures. A selective dropping attack occurs when a malicious router intentionally drops incoming and outgoing UPDATE messages, which results in data traffic being blackholed or trapped in a loop. In this paper, we conduct a thorough analysis on this type of attack and advocate that new security countermeasures should be developed to detect and prevent such attack. Ke Zhang 0026, Xiaoliang Zhao, Shyhtsun Felix Wu |
IPCCC | 3 |
| 2004 | On Detection of Anomalous Routing Dynamics in BGP
Ke Zhang 0026, Amy Yen, Xiaoliang Zhao, Daniel Massey, Shyhtsun Felix Wu, Lixia Zhang 0001 |
NETWORKING | 5 |
| 2004 | Buttercup: on network-based detection of polymorphic buffer overflow vulnerabilitiesabstractAttack polymorphism is a powerful tool for the attackers in the Internet to evade signature-based intrusion detection/prevention systems. In addition, new and faster Internet worms can be coded and launched easily by even high school students anytime against our critical infrastructures, such as DNS or update servers. We believe that polymorphic Internet worms will be developed in the future such that many of our current solutions might have a very small chance to survive. In this paper, we propose a simple solution called "Buttercup" to counter against attacks based on buffer-overflow exploits (such as CodeRed, Nimda, Slammer, and Blaster). We have implemented our idea in SNORT, and included 19 return address ranges of buffer-overflow exploits. With a suite of tests against 55 TCPdump traces, the false positive rate for our best algorithm is as low as 0.01%. This indicates that, potentially, Buttercup can drop 100% worm attack packets on the wire while only 0.01% of the good packets will be sacrificed. Archana Pasupulati, Jason Coit, Karl N. Levitt, Shyhtsun Felix Wu, S. H. Li, J. C. Kuo, K. P. Fan |
NOMS (1) | 4 |
| 2004 | Panel three: Monitoring and controlling networks: Have we lost control of our networks?
Jürgen Schönwälder, Aiko Pras, Shyhtsun Felix Wu, Bert Wijnen, Loris Degioanni |
NOMS (1) | 3 |
| 2004 | On building the minimum number of tunnels: an ordered-split approach to manage IPSec/VPN policiesabstractMost of the current work in policy management for IPSec/VPN focuses on how to configure a single IPSec box or a pair of IPSec boxes. However, it has been shown (Fu et al. (2001)) that the local correctness of IPSec policies in every box individually does not necessarily guarantee global correctness. Therefore, it is critical to have a systematic way to analyze the security requirements globally and to generate, automatically and correctly, a set of IPSec policies to ensure the security for all the end-to-end connections. Previously (Fu et al. (2001)), two different algorithms (i.e. bundle and direct) were introduced to solve the policy generation problem in an "offline" fashion. While these two algorithms are efficient in producing globally correct policy rules, the number of output policy rules (i.e., the results themselves) is much greater than necessary. In other words, while the existing approaches can produce a solution quickly, the quality of the solution is far from optimal. In practice, this is undesirable for several reasons. For instance, "more IPSec policy rules" implies "more complicated virtual network topology". Therefore, in this paper, we focus on "how to produce a minimum set of IPSec/VPN tunnels". We formulate this problem as a special type of task-scheduling problem and develop a new method, the ordered-split approach, to produce a provably minimum set of globally correct policy rules. We have also compared the new approach with existing methods in simulation, and our results clearly demonstrate that the ordered-split approach performs significantly better. Chip Martel, Shyhtsun Felix Wu |
NOMS (1) | 3 |
| 2004 | Combining visual and automated data mining for near-real-time anomaly detection and analysis in BGPabstractThe security of Internet routing is a major concern because attacks and errors can result in data packets not reaching their intended destination and/or falling into the wrong hands. A key step in improving routing security is to analyze and understand it. In the past, we and other researchers have presented various visual-based, statistical-based, and signature-based methods of analyzing Internet routing data. Soon Tee Teoh, Ke Zhang 0026, Shih-Ming Tseng, Kwan-Liu Ma, Shyhtsun Felix Wu |
VizSEC | 5 |
| 2003 | A Study of Packet Delivery Performance during Routing ConvergenceabstractInternet measurements have shown that network failures happen frequently, and that existing routing protocols can take multiple seconds, or even minutes, to converge after a failure. During these routing convergence periods, some packets may already be en-route to their destinations and new packets may be sent. These in-ight packets can en-counter routing loops, delays, and losses. However, little is known about how many packets are delivered (or not de-livered) during routing convergence periods. In this paper, we study the impact of topological connec-tivity and routing protocol designs on the packet delivery during routing convergence. We examine three distributed routing protocols: RIP, Distributed Bellman Ford and BGP through protocol analysis and simulation experiments. Our study shows that the packet delivery ratio improves as the network connectivity becomes richer. However differences in routing protocol designs impact their ability to fully uti-lize the topological redundancy in face of component fail-ures. Two factors in routing protocol design, keeping al-ternate path information at each router and quickly prop-agating new reachability information, appear to have the most impact on the packet delivery behavior during con-vergence. 1 Dan Pei, Daniel Massey, Shyhtsun Felix Wu, Lixia Zhang 0001 |
DSN | 4 |
| 2003 | RBWA: an efficient random-bit window-based authentication protocolabstractGiven the wide and rapid deployment of "visitor networks" (Dory Leifer 2002), how to authenticate the user and account the usage on the per-packet basis securely and yet efficiently is still a challenging problem. In this paper, we explore the tradeoff between performance and security, and propose a per-data-packet authentication and access control protocol called RBWA (random-bit window-based authentication). Deployed in the IP layer, RBWA can work with various underlying linker layer specific mechanisms and network topologies. And compared with IPSec, it dramatically reduces the overhead and power consumption by adding only a few bits to each data packet. Furthermore, RBWA is strong against a suite of attacks such as replay attack, denial-of-service attack and spoofing etc. In particular, a robust antireplay window scheme is developed to counter the severe packet reordering. The performance of RBWA is evaluated via the simulation. Yongjoo Shin, Shyhtsun Felix Wu, Henric Johnson, Arne A. Nilsson |
GLOBECOM | 3 |
| 2003 | Analysis and improvement on IPSec anti-replay window protocolabstractThe anti-replay sliding window is used in IPSec to resist the replay attack. However, when experiencing the severe packet reordering, IPSec anti-replay sliding window can potentially drop a lot of good but late packets, thus the end-to-end performance is dramatically degraded. In this paper, we rigorously analyze the performance of IPSec anti-replay sliding window under the different reordering models and then come up with a set of robust anti-replay window protocols. The performance and efficiency of each protocol are compared through the simulation. Also we argue that by deploying our new proposal, it is possible to dramatically reduce the overhead of IPSec and save a lot of bandwidth. Shyhtsun Felix Wu |
ICCCN | 2 |
| 2003 | Protecting BGP Routes to Top Level DNS ServersabstractThe Domain Name System (DNS) is an essential part of the Internet infrastructure and provides fundamental services, such as translating host names into IP addresses for Internet communication. The DNS is vulnerable to a number of potential faults and attacks. In particular, false routing announcements can deny access to the DNS service or redirect DNS queries to a malicious impostor Due to the hierarchical DNS design, a single fault or attack against the routes to any of the top level DNS servers can disrupt Internet services to millions of users. In this paper we propose a path-filtering approach to protect the routes to the critical top level DNS servers. Our approach exploits the high degree of redundancy in top level DNS servers and also exploits the observation that popular destinations, including top level DNS servers, are well connected via stable routes. Our path-filter restricts the potential top level DNS server route changes to be within a set of established paths. Heuristics derived from routing operations are used to adjust the potential routes overtime. We tested our path-filtering design against BGP routing logs and the results show that the design can effectively ensure correct routes to top level DNS servers without impacting DNS service availability. Xiaoliang Zhao, Dan Pei, Randy Bush, Daniel Massey, Allison Mankin, Shyhtsun Felix Wu, Lixia Zhang 0001 |
ICDCS | 7 |
| 2003 | BANDS: An Inter-domain Internet Security Policy Management System for IPSec/VPN
Zhi (Judy) Fu, Shyhtsun Felix Wu |
Integrated Network Management | 3 |
| 2003 | A Visual Exploration Process for the Analysis of Internet Routing DataabstractThe Internet pervades many aspects of our lives and is becoming indispensable to critical functions in areas such as commerce, government, production and general information dissemination. To maintain the stability and efficiency of the Internet, every effort must be made to protect it against various forms of attacks, malicious users, and errors. A key component in the Internet security effort is the routine examination of Internet routing data, which unfortunately can be too large and complicated to browse directly. We have developed an interactive visualization process which proves to be very effective for the analysis of Internet routing data. In this application paper, we show how each step in the visualization process helps direct the analysis and glean insights from the data. These insights include the discovery of patterns, detection of faults and abnormal events, understanding of event correlations, formation of causation hypotheses, and classification of anomalies. We also discuss lessons learned in our visual analysis study. Soon Tee Teoh, Kwan-Liu Ma, Shyhtsun Felix Wu |
IEEE Visualization | 3 |
| 2002 | Detection of Invalid Routing Announcement in the InternetabstractNetwork measurement has shown that a specific IP address prefix may be announced by more than one autonomous system (AS), a phenomenon commonly referred to as Multiple Origin AS, or MOAS. MOAS can be due to either operational need to support multi-homing, or false route announcements due to configuration or implementation errors, or even by intentional attacks. Packets following such bogus routes will be either dropped or in the case of an intentional attack, delivered to a machine of the attacker's choosing. The paper presents a protocol enhancement to BGP which enables BGP to detect bogus route announcements from false origins. Rather than imposing cryptography-based authentication and encryption to secure routing message exchanges, our solution makes use of the rich connectivity among ASs that exists in the Internet. Simulation results show that this simple solution can effectively detect false routing announcements even in the presence of multiple compromised routers, become more robust in larger topologies, and can substantially reduce the impact of false routing announcements even with a partial deployment. Xiaoliang Zhao, Dan Pei, Daniel Massey, Allison Mankin, Shyhtsun Felix Wu, Lixia Zhang 0001 |
DSN | 6 |
| 2002 | Inter-Packet Delay Based Correlation for Tracing Encrypted Connections through Stepping Stones
Xinyuan Wang 0005, Douglas S. Reeves, Shyhtsun Felix Wu |
ESORICS | 3 |
| 2002 | SOLA: a one-bit identity authentication protocol for access control in IEEE 802.11abstractGiven the wide deployment of IPSec/VPN (virtual private networks) technology, there might be a redundancy in security protection in some configurations. Various commercial companies have replaced 802.11 security with IPSec/VPN to protect the wireless LAN (local area network). How to do it in an efficient and lightweight way is a challenging research problem. This paper introduces a new lightweight identity authentication protocol, SOLA (Statistical One-bit Lightweight Authentication), for access control well suited for IEEE 802.11 networks with IP connections. This protocol prevents unauthorized access on a per packet basis. Since SOLA only adds one identity bit to each packet it will have a low impact on the network bandwidth and power consumption. The performance and efficiency of the SOLA protocol together with IEEE 802.11 is analyzed and evaluated via simulation. Henric Johnson, Arne A. Nilsson, Zhi (Judy) Fu, Shyhtsun Felix Wu |
GLOBECOM | 4 |
| 2002 | Observation and analysis of BGP behavior under stressabstractDespite BGP's critical importance as the de-facto Internet inter-domain routing protocol, there is little understanding of how BGP actually performs under stressful conditions when dependable routing is most needed. In this paper, we examine BGP's behavior during one stressful period, the Code Red/Nimda attack on September 18, 2001. The attack was correlated with a 30-fold increase in the BGP update messages at a monitoring point which peers with a number of Internet service providers. Our examination of BGP's behavior during the event concludes that BGP exhibited no significant abnormality, and that over 40% of the observed updates can be attributed to the monitoring artifact in current BGP measurement settings. Our analysis, however, does reveal several weak points in both the protocol and its implementation, such as BGP's sensitivity to the transport session reliability, its inability to avoid the global propagation of small local changes, and its certain implementation features whose otherwise benign effects only get amplified under stressful conditions. We also identify areas for improvement in the current network measurement and monitoring effort. Xiaoliang Zhao, Dan Pei, Randy Bush, Daniel Massey, Allison Mankin, Shyhtsun Felix Wu, Lixia Zhang 0001 |
Internet Measurement Workshop | 7 |
| 2002 | Improving BGP Convergence Through Consistency AssertionsabstractThis paper presents a new mechanism for improving the convergence properties of path vector routing algorithms, such as BGP. Using a route's path information, we develop two consistency assertions for path vector routing algorithms that are used to compare similar routes and identify infeasible routes. To apply these assertions in BGP, mechanisms to signal failure/policy withdrawal, and traffic engineering are provided. Our approach was implemented and deployed in a BGP testbed and evaluated using simulation. By identifying and ignoring the infeasible routes, we achieved substantial reduction in both BGP convergence time and the total number of intermediate route changes. Dan Pei, Xiaoliang Zhao, Daniel Massey, Allison Mankin, Shyhtsun Felix Wu, Lixia Zhang 0001 |
INFOCOM | 6 |
| 2002 | Case Study: Interactive Visualization for Internet SecurityabstractInternet connectivity is defined by a set of routing protocols which let the routers that comprise the Internet backbone choose the best route for a packet to reach its destination. One way to improve the security and performance of Internet is to routinely examine the routing data. In this case study, we show how interactive visualization of Border Gateway Protocol (BGP) data helps characterize routing behavior, identify weaknesses in connectivity which could potentially cripple the Internet, as well as detect and explain actual anomalous events. Soon Tee Teoh, Kwan-Liu Ma, Shyhtsun Felix Wu, Xiaoliang Zhao |
IEEE Visualization | 3 |
| 2001 | On design and evaluation of "intention-driven" ICMP tracebackabstractSince late 1999, DDoS (distributed denial of service) attack has drawn many attentions from both research and industry communities. Many potential solutions (e.g., ingress filtering, packet marking or tracing, and aggregate-based congestion control or rate limiting) have been proposed to handle this network bandwidth consumption attack. Among them, "ICMP traceback (iTrace)" is currently being considered as an industry standard by the IETF (Internet Engineering Task Force). While the idea of iTrace is very clever, efficient, reasonably secure and practical, it suffers a serious statistic problem such that the chance for "useful" and "valuable" iTrace messages can be extremely small against various types of DDoS attacks. This implies that most of the network resources spent on generating and utilizing iTrace messages will be wasted. Therefore, we propose a simple enhancement called "intention-driven" iTrace, which conceptually introduces an extra bit in the routing and forwarding process. With the new "intention-bit", it is shown that, through our simulation study, the performance of iTrace improves dramatically. This work has been proposed to IETF's ICMP Trace-Back working group. Allison Mankin, Daniel Massey, Chien-Lung Wu, Shyhtsun Felix Wu, Lixia Zhang 0001 |
ICCCN | 4 |
| 2001 | IPSec/PHIL (packet header information list): design, implementation, and evaluationabstractFor most TCP/UDP/IP applications, when a packet or a message arrives, usually only the payload portion of the original packet can be obtained by the application. For instance, if a packet has been delivered through some IPSec (IP security) tunnels along the route path, then the application, in general, does not know exactly which tunnels have been used to deliver this particular packet. The IPSec/PHIL (packet header information list) interface has been designed and implemented such that an "authorized" application is able to know which set of IPSec tunnels has been used to deliver a particular incoming packet. Furthermore, IPSec/PHIL enables controllability over which set of IPSec tunnels is used to send a particular outgoing packet. IPSec/PHIL is a key component in the Deciduous decentralized source tracing system to correlate the IPSec information with intrusion detection results. Other IPSec/PHIL applications we have built include a SNMPv3 security module using IPSec as well as an IPSec tunnel switching router. Chien-Lung Wu, Shyhtsun Felix Wu, Ravindar Narayan |
ICCCN | 2 |
| 2001 | Sleepy Watermark Tracing: An Active Network-Based Intrusion Response Framework
Xinyuan Wang 0005, Douglas S. Reeves, Shyhtsun Felix Wu, Jim Yuill |
SEC | 3 |
| 2001 | Real-time protocol analysis for detecting link-state routing protocol attacksabstractA real-time knowledge-based network intrusion-detection model for a link-state routing protocol is presented for the OSPF protocol. This model includes three layers: a data process layer to parse packets and dispatch data; and event abstractor to abstract predefined real-time events for the link-state routing protocol; and an extended timed finite state machine to express the real-time behavior of the protocol engine and to detect intrusions by pattern matching. The timed FSM, called the JiNao Finite State Machine (JFSM) is extended from the conventional FSM with timed states, multiple timers, and time constraints on state transitions. The JFSM is implemented as a generator that can create and FSM by constructing the configuration file only. The results show that this approach is very effective for detecting real-time intrusions. Our approach can be extended for use in other network protocol intrusion-detection systems, especially for those with known attacks. Ho-Yen Chang, Shyhtsun Felix Wu, Y. Frank Jou |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2000 | A property oriented fault detection approach for link state routing protocolabstractThis paper proposes a new approach to fault detection for a link state routing system-property oriented analysis and detection (POD). A routing system is modeled as a set of distributed processes. A property is defined as state predicate(s) over system variables. For the link state routing protocol, the high-level overall converging property P is defined as the "synchronization" among routing information bases maintained by all processes. We decompose the routing protocol into different computation phases. For each phase, we use invariant state predicates (safety property) and the liveness property as our guide for observation and analysis. The goal of the detection algorithm is to construct a validation path based on the history to determine if the fault is natural or malicious once the stable property P is rendered invalid by faults. The contribution of this paper is twofold: first, a new detection approach is proposed that differs from traditional signature-based or profile-based intrusion detection paradigms in the sense that it utilizes the stable property as a starting point, and correlates the history and future to validate changes in the system; second, by exploring the primary concerned system properties, we show that detection effort can be conducted in a more focused and systematic fashion. Feiyi Wang, Fengmin Gong, Shyhtsun Felix Wu |
ICCCN | 3 |
| 2000 | Malicious Packet Dropping: How It Might Impact the TCP Performance and How We Can Detect ItabstractAmong various types of denial of service attacks, "dropping attack" is probably the most difficult one to handle. This paper explores the negative impacts of packet dropping attacks and a method to detect such attacks. First, three dropping patterns are classified and investigated. We demonstrate that attackers can choose different dropping patterns to degrade TCP service to different levels, and selectively dropping a very, small number of packets can result in severe damage to TCP performance. Second, we show that a hacker can utilize a DDoS attack tool to control a "uncompromised" router to emulate dropping attacks. This proves that dropping attacks are indeed practically very possible to happen in today's Internet environment. Third, we present a statistical analysis module for the detection of TCP packet dropping attacks. Three measures, session delay, the position and the number of packet reorderings, have been implemented in the statistical module. This paper has evaluated and compared their detection performance. Shyhtsun Felix Wu, Zhi Fu, Tsung-Li Wu |
ICNP | 2 |
| 2000 | ISCP: design and implementation of an inter-domain security management agent (SMA) coordination protocolabstractMany security mechanisms and protocols have been developed to handle security problems in various circumstances. This trend has created a heterogeneous security environment for today's global Internet. Although most security functions and modules can be managed "individually" through SNMP, very little has been researched in coordinating a set of distributed security modules to provide and manage an "end-to-end" security service. In order to support service management for network security, in this paper, we developed the ISCP protocol (inter-domain security management agent coordination protocol) to communicate security capability and policy information among the security management agents in each policy domain. ISCP is designed with good scalability, interoperability, extensibility and security. Performance evaluation using our ISCP prototype implementation is also presented. Zhi Fu, Tsung-Li Wu, Shyhtsun Felix Wu, Fengmin Gong, Ilya Baldin |
NOMS | 4 |
| 2000 | Intrusion-detection for incident-response, using a military battlefield-intelligence process
Jim Yuill, Shyhtsun Felix Wu, J. Settle, Fengmin Gong, R. Forno, Ming-Yuh Huang, J. Asbery |
Comput. Networks | 2 |
| 1999 | Intrusion detection for link state routing protocol through integrated network managementabstractThe JiNao IDS project focuses on detecting intrusions, especially insider attacks against link state routing protocols such as OSPF. One important feature of the JiNao system is its integrated network management (INM) capability. Through SNMP and distributed programming interface (DPI), we can manage and control distributed JiNao IDS remotely, interoperate with other JiNao systems to do correlation analysis, and utilize both private MIB and OSPF MIB as a complementary way of doing intrusion detection. This paper describes the design and implementation of JiNao's INM architecture. Three OSPF insider attacks (maxseq, maxage, and seq++) have been developed to evaluate its effectiveness and detection capability. Feiyi Wang, Fengmin Gong, Shyhtsun Felix Wu, Ravindar Narayan |
ICCCN | 3 |
| 1999 | DecIdUouS: Decentralized Source Identification for Network-Based IntrusionsabstractDECIDUOUS is a security management framework for identifying the sources of network-based intrusions. The first key concept in DECIDUOUS is dynamic security associations, which efficiently and collectively provide location information for attack sources. DECIDUOUS is built on top of the IETF's IPSEC/ISAKMP infrastructure, and it does not introduce any new network protocol for source identification in a single administrative domain. It defines a collaborative protocol for inter-domain attack source identification. The second key concept in DECIDUOUS is the management information integration of the intrusion detection system (IDS) and attack source identification system (ASIS) across different protocol layers. For example, in DECIDUOUS, it is possible for a network-layer security control protocol (e.g., IPSEC) to collaborate with an application-layer intrusion detection system module (e.g., IDS for the SNMP engine). In this paper, we present the motivations, design, and prototype implementation of the DECIDUOUS framework. Ho-Yen Chang, Ravindar Narayan, Shyhtsun Felix Wu, Brian Vetter, Xinyuan Wang 0005, Jim Yuill, Chandramouli Sargor, Y. Frank Jou, Fengmin Gong |
Integrated Network Management | 3 |
| 1999 | Intrusion Detection for an On-Going Attack
Jim Yuill, Shyhtsun Felix Wu, Fengmin Gong, Ming-Yuh Huang |
Recent Advances in Intrusion Detection | 2 |
| 1998 | On the Vulnerabilities and Protection of OSPF Routing ProtocolabstractThis paper analyzes both the strong points and weak points of the OSPF routing protocol from the security perspective. On its strong points, we abstract its features of information least dependency and information hiding, which make it very robust and fault resilient, even when facing certain malicious attacks. On its weak points, we take a pragmatic look at various problems centering round secure routing protocols. By carefully investigating a special re-routing attacking case, we show how a home-made malicious router can easily disrupt the service. It also provides a concrete example for routing protection and intrusion detection. Finally, we present the active protection idea and its architectural flexibility and compatibility advantages. Feiyi Wang, Shyhtsun Felix Wu |
ICCCN | 2 |
| 1998 | Statistical Anomaly Detection for Link-State Routing ProtocolsabstractThe JiNao project at MCNC/NCSU focuses on detecting intrusions, especially insider attacks, against the OSPF (open shortest path first) routing protocol. This paper presents the implementation and experiments of JiNao's statistical intrusion detection module. Our implementation is based upon the algorithm developed in SRI's NIDES (next-generation intrusion detection expert system) project. Some modifications and improvements to NIDES/STAT are made for a more effective implementation in our environment. Also, three OSPF insider attacks (e.g., maxseq, maxage, and seq++ attacks) have been developed for evaluating the efficacy of detecting capability. The experiments were conducted on two different network routing testbeds. The results indicate that the proposed statistical mechanism is very effective in detecting these routing protocol attacks. Diheng Qu, Brian Vetter, Feiyi Wang, Ravindar Narayan, Shyhtsun Felix Wu, Y. Frank Jou, Fengmin Gong, Chandramouli Sargor |
ICNP | 5 |
| 1997 | An experimental study of insider attacks for OSPF routing protocolabstractIt is critical to protect the network infrastructure (e.g., network routing and management protocols) against security intrusions, yet dealing with insider attacks are probably one of the most challenging research problems in network security. We study the security threats, especially internal/insider threats, for the standardized routing protocol OSPF. In OSPF, a group of routers collaborate, exchange routing information, and forward packets for each other. If one (and maybe more than one) router is evil or compromised, how can this router damage the whole network? In this paper, we analyze OSPF and identify its strengths and weakness under various insider attacks. Furthermore, to confirm our analysis, we have implemented and experimented one attack, the max sequence number attack, on our OSPF routing testbed. Our attack is very successful against two independently developed router products as it will block routing updates for 60 minutes by simply injecting one bad OSPF protocol data unit. Brian Vetter, Feiyi Wang, Shyhtsun Felix Wu |
ICNP | 3 |
| 1996 | Sleepy Network-Layer Authentication Service for IPSEC
Shyhtsun Felix Wu |
ESORICS | 1 |
| 1991 | An object-based approach to implementing distributed concurrency controlabstractDistributed concurrency control has been implemented by representing in-progress transactions as simulated objects, called transaction objects, that use normal message passing facilities. The implementation of an optimistic mechanism has been completed using transaction objects and a two-phase locking mechanism has been designed. The tradeoffs made and lessons learned, dealing with transactions both on objects and as objects, are discussed.> Steven S. Popovich, Shyhtsun Felix Wu, Gail E. Kaiser |
ICDCS | 2 |
| 1989 | MELDing Multiple Granularities of Parallelism
Gail E. Kaiser, Steven S. Popovich, Wenwey Hseush, Shyhtsun Felix Wu |
ECOOP | 4 |