EDBT 2026 Demo / reviewers in the wild / expert
Hongxin Hu
dblp:02/2870
· DBLP profile ↗
147ranked-venue papers
12as first author
53since 2021 · last 2026
0000-0001-8710-247XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 61 · 8 first-author · 20 since 2021Computer networks · 35 · 1 first-author · 9 since 2021Artificial intelligence and machine learning · 18 · 16 since 2021Human-computer interaction and ubiquitous computing · 15 · 2 first-author · 2 since 2021Systems, architecture and hardware · 7 · 6 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021Software engineering, systems software and programming languages · 4Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Age-Based Restrictions: Rethinking Children's Online Safety Through Comparing Parent-Child Perspectives of Risks in User-Generated Content Games
Ruchi Panchanadikar, Keyan Guo, Amelia L. Hall, Hongxin Hu, Nishant Vishwamitra, Guo Freeman |
CHI | 5 |
| 2026 | Few-shot transfer learning for laser welding prediction
Luchen Wu, Hongxin Hu |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | SLeak: Multi-Target Privacy Stealing Attack Against Split LearningabstractSplit Learning (SL) is a distributed learning framework that has gained popularity for its privacy-preserving nature and low computational demands. However, recent studies have the potential that a server adversary to carry out inference attacks, compromising the privacy of victim clients. Nevertheless, upon re-evaluating prior studies, we found that existing methods rely on overly strong assumptions to enhance their performance, resulting in a significant decline in effectiveness under more realistic scenarios. In this work, we provide new insights into the inherent vulnerabilities of SL. Specifically, we discover that both the smashed data and the server model contain the client's representation preference, which the server adversary can exploit to build a substitute client that approximates the target client's unique feature extraction behavior. With a well-trained substitute client, the server can perfectly steal the target client's functionality, training data, and labels. Building on this observation, we introduce Split Leakage (SLeak), a new threat that targets multiple privacy stealing objectives against SL. Notably, SLeak does not depend on strong privacy priors and only requires partial same-domain auxiliary public data to conduct the attacks. Experimental results on diverse datasets and target models show that SLeak surpasses the state-of-the-art method across multiple metrics. Moreover, ablation studies further confirm its robustness and applicability under various scenarios and assumptions. Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Mengda Yang, Yong Zhuang, Mang Ye |
IEEE Trans. Pattern Anal. Mach. Intell. | 4 |
| 2026 | Palladium: Guarding Neural Network Training With Confidential ComputingabstractIn the era of deep learning, protecting the training data and model parameters of high-performance Deep Neural Networks (DNNs) is critical. Data holders often want to use private data to train dedicated DNNs while leveraging AI accelerators hosted on remote servers, such as GPUs or TPUs. However, cloud systems are vulnerable to adversaries who may compromise both computational integrity and user data privacy. Performing verifiable and private training without losing access to untrusted accelerators remains a significant challenge. While previous works rely on Trusted Execution Environments (TEEs) to safeguard privacy during inference, they primarily address forward propagation and are not suitable for backward propagation in training. To address this limitation, this paper proposesPalladium, the first system to achieve confidentiality, integrity, and low latency for both model parameters and training data.Palladiumleverages TEE-empowered confidential computing to protect privacy and verify integrity, while securely outsourcing most linear layer computations to untrusted GPUs to optimize performance. Specifically,Palladiumpreserves the confidentiality of outsourced parameters by transforming the weights of linear operators and generating input masks through a carefully designedCloakstrategy. It then fully recovers the execution results inside the TEE using the correspondingUnCloakstrategy. To further ensure computational integrity,Palladiumincorporates a stochastic operator verification mechanism that detects breaches outside the TEE with 99% confidence. We implement a prototype ofPalladiumbased on Libtorch and Occlum and conduct a comprehensive evaluation on four network architectures and four datasets. Evaluation results show thatPalladiumprovides strong security guarantees with reasonable performance overhead, preserves high training accuracy, and protects model privacy. Wenzhe Yi, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Learning to Defend: Auto-Augmentation Search Against Model Inversion AttacksabstractModel Inversion Attacks (MIAs) can recover private training data by accessing model weights or outputs, posing significant threats to user privacy. Existing defenses cannot provide comprehensive protection against attackers with varying levels of knowledge and often lack evaluation against the most advanced attacks. Moreover, current defenses primarily focus on regularizing latent representations or labels. While prior work has explored input-level defenses (e.g., Random Erasing), these approaches are typically limited to simple transformations, and more complex or systematically combined input-level defenses remain underexplored. As the most common input-level perturbation technique, data augmentation applies transformations like cropping directly to input images. However, finding augmentations or their combinations that achieve a good privacy-utility trade-off is challenging, as it is impossible to evaluate every augmentation exhaustively through attacks. To address this, we design privacy and utility assessments for efficient evaluation and propose a Defense via Auto-Augmentation Search (DAAS). DAAS can automatically assess and identify candidates with strong privacy-utility trade-offs from a large augmentation pool. The final search results can then be leveraged for privacy-preserving training against MIAs. We evaluate DAAS across various models, datasets, and attacks, demonstrating superior defense performance compared to existing methods. Extensive ablation studies further demonstrate the effectiveness of DAAS. Wenzhe Yi, Xiaoyang Xu 0001, Yong Zhuang, Juan Wang 0006, Hongxin Hu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed LearningabstractModel Inversion Attacks (MIAs) aim to reconstruct private training data from models, leading to privacy leakage, particularly in facial recognition systems. Although many studies have enhanced the effectiveness of white-box MIAs, less attention has been paid to improving efficiency and utility under limited attacker capabilities. Existing black-box MIAs necessitate an impractical number of queries, incurring significant overhead. Therefore, we analyze the limitations of existing MIAs and introduce Surrogate Model-based Inversion with Long-tailed Enhancement (SMILE), a high-resolution oriented and query-efficient MIA for the black-box setting. We begin by analyzing the initialization of MIAs from a data distribution perspective and propose a long-tailed surrogate training method to obtain high-quality initial points. We then enhance the attack’s effectiveness by employing the gradient-free black-box optimization algorithm selected by NGOpt. Our experiments show that SMILE outperforms existing state-of-the-art black-box MIAs while requiring only about 5% of the query overhead. Our code is available at https://github.com/L1ziang/SMILE. Juan Wang 0006, Meihui Chen, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001, Mengda Yang, Chenjun Ma |
CVPR | 5 |
| 2025 | HVGuard: Utilizing Multimodal Large Language Models for Hateful Video DetectionabstractThe rapid growth of video platforms has transformed information dissemination and led to an explosion of multimedia content. However, this widespread reach also introduces risks, as some users exploit these platforms to spread hate speech, which is often concealed through complex rhetoric, making hateful video detection a critical challenge. Existing detection methods rely heavily on unimodal analysis or simple feature fusion, struggling to capture cross-modal interactions and reason through implicit hate in sarcasm and metaphor. To address these limitations, we propose HVGuard, the first reasoning-based hateful video detection framework with multimodal large language models (MLLMs). Our approach integrates Chain-of-Thought (CoT) reasoning to enhance multimodal interaction modeling and implicit hate interpretation. Additionally, we design a Mixture-of-Experts (MoE) network for efficient multimodal fusion and final decision-making. The framework is modular and extensible, allowing flexible integration of different MLLMs and encoders. Experimental results demonstrate that HVGuard outperforms all existing advanced detection tools, achieving an improvement of 6.88% to 13.13% in accuracy and 9.21% to 34.37% in M-F1 on two public datasets covering both English and Chinese. Yiheng Jing, Mingming Zhang 0009, Yong Zhuang, Jiacheng Guo, Juan Wang 0006, Xiaoyang Xu 0001, Wenzhe Yi, Keyan Guo, Hongxin Hu |
EMNLP | 9 |
| 2025 | Toward Unified Moderation of Cyberbullying Across Social Media and Video GamesabstractThe growing integration of social media and video games in adolescents’ daily lives has heightened the risk of cyberbullying, contributing to severe mental health challenges such as depression and suicidal ideation. Traditional moderation techniques, including manual review and rule-based filters, often fail to capture contextual nuances. Existing machine learning models also face limitations due to their reliance on large labeled datasets and lack of cross-platform adaptability. Our experiments further reveal that models trained on social media content perform poorly on video game data and vice versa, leading to inefficient moderation. To address these challenges, we propose a novel approach that leverages Large Language Models (LLMs) with Chain-of-Thought (CoT) reasoning for cyberbullying detection across both domains. This method eliminates the need for extensive training data while significantly improving accuracy. It achieves 90.3% and 91.1% accuracy on social media and video game datasets, respectively, offering a scalable and resource-efficient solution for cyberbullying moderation. David Cong, Keyan Guo, Hongxin Hu |
ICMLA | 3 |
| 2025 | I know what you MEME! Understanding and Detecting Harmful Memes with Multimodal Large Language Models
Yong Zhuang, Keyan Guo, Juan Wang 0006, Yiheng Jing, Xiaoyang Xu 0001, Wenzhe Yi, Mengda Yang, Bo Zhao 0023, Hongxin Hu |
NDSS | 9 |
| 2025 | APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
Yu Nong, Haoran Yang 0002, Long Cheng 0005, Hongxin Hu, Haipeng Cai |
USENIX Security Symposium | 4 |
| 2025 | JBShield: Defending Large Language Models from Jailbreak Attacks through Activated Concept Analysis and Manipulation
Shenyi Zhang, Yuchen Zhai, Keyan Guo, Hongxin Hu, Zheng Fang 0014, Lingchen Zhao, Chao Shen 0001, Cong Wang 0001, Qian Wang 0002 |
USENIX Security Symposium | 4 |
| 2025 | Microft: Exploring and Mitigating Cross-State Control-Flow Hijacking Attacks on ARM Cortex-M TrustZone
Zheyuan Ma, Xi Tan 0002, Lukasz Ziarek, Ning Zhang 0017, Shambhu J. Upadhyaya, Hongxin Hu, Ziming Zhao 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Command Hijacking on Voice-Controlled IoT in Amazon Alexa PlatformabstractVoice Personal Assistants (VPA) are becoming popular entry points to control connected devices in an IoT environment, e.g., by invoking Amazon Alexa voice-apps (called skills) to turn on/off lights through voice commands. Amazon Alexa platform allows third-party developers to build skills and publish them to marketplaces, which greatly extends the functionalities of VPA. Despite the many convenient features, there are increasing security and safety concerns about VPA-controlled IoT systems. Previous research demonstrated the prevalence of potentially malicious or problematic skills in the marketplace. However, existing works mainly focus on non-IoT skills (e.g., skills under the Kids and Health categories). The security and safety risks of IoT skills are largely under-explored. Wenbo Ding 0003, Song Liao, Long Cheng 0005, Xianghang Mi, Ziming Zhao 0001, Hongxin Hu |
AsiaCCS | 6 |
| 2024 | Is Difficulty Calibration All We Need? Towards More Practical Membership Inference AttacksabstractThe vulnerability of machine learning models to Membership Inference Attacks (MIAs) has garnered considerable attention in recent years. These attacks determine whether a data sample belongs to the model's training set or not. Recent research has focused on reference-based attacks, which leverage difficulty calibration with independently trained reference models. While empirical studies have demonstrated its effectiveness, there is a notable gap in our understanding of the circumstances under which it succeeds or fails. In this paper, we take a further step towards a deeper understanding of the role of difficulty calibration. Our observations reveal inherent limitations in calibration methods, leading to the misclassification of non-members and suboptimal performance, particularly on high-loss samples. We further identify that these errors stem from an imperfect sampling of the potential distribution and a strong dependence of membership scores on the model parameters. By shedding light on these issues, we propose RAPID: a query-efficient and computation-efficient MIA that directly Re-leverAges the original membershiP scores to mItigate the errors in Difficulty calibration. Our experimental results, spanning 9 datasets and 5 model architectures, demonstrate that RAPID outperforms previous state-of-the-art attacks (e.g., LiRA and Canary offline) across different metrics while remaining computationally efficient. Our observations and analysis challenge the current de facto paradigm of difficulty calibration in high-precision inference, encouraging greater attention to the persistent risks posed by MIAs in more practical scenarios. Yu He 0009, Boheng Li, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xingyu Zhao 0001 |
CCS | 6 |
| 2024 | A First Look at Security and Privacy Risks in the RapidAPI EcosystemabstractWith the emergence of the open API ecosystem, third-party developers can publish their APIs on the API marketplace, significantly facilitating the development of cutting-edge features and services. The RapidAPI platform is currently the largest API marketplace and it provides over 40,000 APIs, which have been used by more than 4 million developers. However, such open API also raises security and privacy concerns associated with APIs hosted on the platform. In this work, we perform the first large-scale analysis of 32,089 APIs on the RapidAPI platform. By searching in the GitHub code and Android apps, we find that 3,533 RapidAPI keys, which are important and used in API request authorization, have been leaked in the wild. These keys can be exploited to launch various attacks, such as Resource Exhaustion Running, Theft of Service, Data Manipulation, and User Data Breach attacks. We also explore risks in API metadata that can be abused by adversaries. Due to the lack of a strict certification system, adversaries can manipulate the API metadata to perform typosquatting attacks on API URLs, impersonate other developers or renowned companies, and publish spamming APIs on the platform. Lastly, we analyze the privacy non-compliance of APIs and applications, e.g., Android apps, that call these APIs with data collection. We find that 1,709 APIs collect sensitive data and 94% of them dont provide a complete privacy policy. For the Android apps that call these APIs, 50% of them in our study have privacy non-compliance issues. Song Liao, Long Cheng 0005, Xiapu Luo, Zheng Song 0001, Haipeng Cai, Danfeng Yao, Hongxin Hu |
CCS | 7 |
| 2024 | A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningabstractSplit Learning (SL) is a distributed learning framework renowned for its privacy-preserving features and minimal computational requirements. Previous research consistently highlights the potential privacy breaches in SL systems by server adversaries reconstructing training data. However, these studies often rely on strong assumptions or compromise system utility to enhance attack performance. This paper introduces a new semi-honest Data Reconstruction Attack on SL, named Feature-Oriented Reconstruction Attack (FORA). In contrast to prior works, FORA relies on limited prior knowledge, specifically that the server utilizes auxiliary samples from the public without knowing any client's private information. This allows FORA to conduct the attack stealthily and achieve robust performance. The key vulnerability exploited by FORA is the revelation of the model representation preference in the smashed data output by victim client. FORA constructs a substitute client through feature-level transfer learning, aiming to closely mimic the victim client's representation preference. Leveraging this substitute client, the server trains the attack model to effectively reconstruct private data. Extensive experiments showcase FORA's superior performance compared to state-of-the-art methods. Furthermore, the paper systematically evaluates the proposed method's applicability across diverse settings and advanced defense strategies. Xiaoyang Xu 0001, Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Yong Zhuang |
CVPR | 6 |
| 2024 | Detecting Cyberbullying in Visual Content: A Large Vision-Language Model ApproachabstractCyberbullying has rapidly evolved with the evolution of online platforms, transcending traditional text-based forms to include images and other multimedia content. Two major challenges are identified in detecting cyberbullying images: recognizing cyberbullying-related visual factors and addressing the context-dependent nature of such images. In this paper, we conduct a comprehensive investigation of the ability of Large Vision-Language Models (LVLMs) to evaluate visual factors related to cyberbullying, and to interpret the context-dependent nature of such images. Furthermore, by proposing a diverse set of prompting strategies, we optimize LVLMs for cyberbullying image detection. In particular, through our carefully crafted Chain-of-Thought (CoT) methodology, we guide the model through structured reasoning pathways to interpret complex visual factors and account for their context. Our results show that the structured reasoning pathways significantly enhance model performance, achieving state-of-the-art accuracy and precision while remaining efficient by eliminating the need for any extensive training process. Jaden Mu, David Cong, Helen Qin, Ishan Ajay, Keyan Guo, Nishant Vishwamitra, Hongxin Hu |
ICMLA | 7 |
| 2024 | Hairpin: Rethinking Packet Loss Recovery in Edge-based Interactive Video Streaming
Zili Meng, Bo Wang 0066, Mingwei Xu 0001, Venkat Arun, Hongxin Hu |
NSDI | 9 |
| 2024 | Moderating New Waves of Online Hate with Chain-of-Thought Reasoning in Large Language ModelsabstractOnline hate is an escalating problem that negatively impacts the lives of Internet users, and is also subject to rapid changes due to evolving events, resulting in new waves of online hate that pose a critical threat. Detecting and mitigating these new waves present two key challenges: it demands reasoning-based complex decision-making to determine the presence of hateful content, and the limited availability of training samples hinders updating the detection model. To address this critical issue, we present a novel framework called HateGuard for effectively moderating new waves of online hate. HateGuard employs a reasoning-based approach that leverages the recently introduced chain-of-thought (CoT) prompting technique, harnessing the capabilities of large language models (LLMs). HateGuard further achieves prompt-based zero-shot detection by automatically generating and updating detection prompts with new derogatory terms and targets in new wave samples to effectively address new waves of online hate. To demonstrate the effectiveness of our approach, we compile a new dataset consisting of tweets related to three recently witnessed new waves: the 2022 Russian invasion of Ukraine, the 2021 insurrection of the US Capitol, and the COVID-19 pandemic. Our studies reveal crucial longitudinal patterns in these new waves concerning the evolution of events and the pressing need for techniques to rapidly update existing moderation tools to counteract them. Comparative evaluations against state-of-the-art approaches illustrate the superiority of our framework, showcasing a substantial 10.59% to 88% improvement in detecting the three new waves of online hate. Our work highlights the severe threat posed by the emergence of new waves of online hate and represents a paradigm shift in addressing this threat practically. Nishant Vishwamitra, Keyan Guo, Farhan Tajwar Romit, Isabelle Ondracek, Long Cheng 0005, Ziming Zhao 0001, Hongxin Hu |
SP | 7 |
| 2024 | Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models
Keyan Guo, Ayush Utkarsh, Wenbo Ding 0003, Isabelle Ondracek, Ziming Zhao 0001, Guo Freeman, Nishant Vishwamitra, Hongxin Hu |
USENIX Security Symposium | 8 |
| 2024 | Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesabstractAmazon Alexa is one of the largest Voice Personal Assistant (VPA) platforms and it allows third-party developers to publish their voice apps, named skills, to the Alexa skill store. To satisfy the needs of European users, Amazon Alexa has established multiple skill marketplaces in Europe and allows developers to publish skills in their native languages. Skills in European marketplaces are required to comply with GDPR (General Data Protection Regulation), which imposes strict obligations on data collection and processing. Skills that involve data collection should provide a privacy policy to disclose the data practice to users and meet GDPR requirements. Song Liao, Mohammed Aldeen, Long Cheng 0005, Xiapu Luo, Haipeng Cai, Hongxin Hu |
WWW | 7 |
| 2024 | Penetralium: Privacy-preserving and memory-efficient neural network inference at the edge
Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001 |
Future Gener. Comput. Syst. | 4 |
| 2024 | IMap: Toward a Fast, Scalable and Reconfigurable In-Network Scanner With Programmable SwitchesabstractNetwork scanning has been a standard measurement technique to understand a network’s security situations, e.g., revealing security vulnerabilities, monitoring service deployments. However, probing a large-scale scanning space with existing network scanners is both difficult and slow, since they are all implemented on commodity servers and deployed at the network edge. To address this, we introduce IMap, a fast, scalable and reconfigurable in-network scanner based on programmable switches. In designing IMap, we overcome key restrictions posed by computation models and memory resources of programmable switches, and devise numerous techniques and optimizations, including an address-random and rate-adaptive probe packet generation mechanism, and a correct and efficient response packet processing scheme, to turn a switch into a practical runtime-reconfigurable high-speed network scanner. We implement an open-source prototype of IMap, and evaluate it with extensive testbed experiments and real-world deployments in our campus network. Evaluation results show that even with one switch port enabled, IMap can survey all ports of our campus network (i.e., a total of up to 25 billion scanning space) in 8 minutes. This demonstrates a nearly 4 times faster scanning speed and 1.5 times higher scanning accuracy than the state of the art, which shows that IMap has great potentials to be the next-generation terabit network scanner with all switch ports enabled. Besides, our experiments also show that IMap supports the reconfiguration of scanning tasks at runtime, without incurring switch downtime. Leveraging IMap, we also discover several potential security threats in our campus network, and report them to our network administrators responsibly. Menghao Zhang 0001, Cheng Guo 0007, Han Bao 0011, Mingwei Xu 0001, Hongxin Hu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Dual-Level Knowledge Distillation via Knowledge Alignment and CorrelationabstractKnowledge distillation (KD) has become a widely used technique for model compression and knowledge transfer. We find that the standard KD method performs the knowledge alignment on an individual sample indirectly via class prototypes and neglects the structural knowledge between different samples, namely, knowledge correlation. Although recent contrastive learning-based distillation methods can be decomposed into knowledge alignment and correlation, their correlation objectives undesirably push apart representations of samples from the same class, leading to inferior distillation results. To improve the distillation performance, in this work, we propose a novel knowledge correlation objective and introduce the dual-level knowledge distillation (DLKD), which explicitly combines knowledge alignment and correlation together instead of using one single contrastive objective. We show that both knowledge alignment and correlation are necessary to improve the distillation performance. In particular, knowledge correlation can serve as an effective regularization to learn generalized representations. The proposed DLKD is task-agnostic and model-agnostic, and enables effective knowledge transfer from supervised or self-supervised pretrained teachers to students. Experiments show that DLKD outperforms other state-of-the-art methods on a large number of experimental settings including: 1) pretraining strategies; 2) network architectures; 3) datasets; and 4) tasks. Yin Yang 0002, Hongxin Hu, Venkat N. Krovi, Feng Luo 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2023 | Understanding and Analyzing COVID-19-related Online Hate Propagation Through Hateful Memes Shared on TwitterabstractRecent studies regarding the COVID-19 pandemic have revealed the widespread propagation of hateful content during this period. While significant research has focused on COVID-19-related online hate in text (e.g., text-based tweets), the role of memes in propagating online hate during the pandemic has been largely overlooked. Memes are a popular mechanism used by Internet users to convey their thoughts and opinions on a variety of topics. However, memes have emerged as an important mechanism through which ideologically potent and hateful content spreads on social media platforms. In this work, we focus on investigating the role of memes in the propagation of online hate during the COVID-19 pandemic. We first collect a novel dataset of 4,001 COVID-19-related hateful memes and their replies over a 3-year period from Twitter. Then, we carry out the first large-scale investigation into the impact of these memes on Twitter users, by studying the psychological reactions of Twitter users to these memes using various text analysis methods. We find that COVID-19-related hateful memes have a significantly greater negative impact on Twitter users in comparison to text-based hateful tweets, and increasing negativity towards such memes over the 3-year period. Our new dataset of COVID-19-related hateful memes and findings from our work pave the way for studying the dissemination and moderation of COVID-19-related online hate through the medium of memes. Nishant Vishwamitra, Keyan Guo, Song Liao, Jaden Mu, Zheyuan Ma, Long Cheng 0005, Ziming Zhao 0001, Hongxin Hu |
ASONAM | 8 |
| 2023 | SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseabstractThe Amazon Alexa marketplace is the largest Voice Personal Assistant (VPA) platform with over 100,000 voice applications (i.e., skills) published to the skills store. In an effort to maintain the quality and trustworthiness of voice-apps, Amazon Alexa has implemented a set of policy requirements to be adhered to by third-party skill developers. However, recent works reveal the prevalence of policy-violating skills in the current skills store. To understand the causes of policy violations in skills, we first conduct a user study with 34 third-party skill developers focusing on whether they are aware of the various policy requirements defined by the Amazon Alexa platform. Our user study results show that there is a notable gap between VPA's policy requirements and skill developers' practices. As a result, it is inevitable that policy-violating skills will be published. Song Liao, Long Cheng 0005, Haipeng Cai, Linke Guo, Hongxin Hu |
CCS | 5 |
| 2023 | Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and DefenseabstractARM Cortex-M is one of the most popular microcontroller architectures designed for embedded and Internet of Things (IoT) applications. To facilitate efficient execution, it has some unique hardware optimization. In particular, Cortex-M TrustZone has a fast state switch mechanism that allows direct control-flow transfer from the secure state program to the non-secure state userspace program. In this paper, we demonstrate how this fast state switch mechanism can be exploited for arbitrary code execution with escalated privilege in the non-secure state by introducing a new exploitation technique, namely return-to-non-secure (ret2ns). We experimentally confirmed the feasibility of four variants of ret2ns attacks on two Cortex-M hardware systems. To defend against ret2ns attacks, we design two address sanitizing mechanisms that have negligible performance overhead. Zheyuan Ma, Xi Tan 0002, Lukasz Ziarek, Ning Zhang 0017, Hongxin Hu, Ziming Zhao 0001 |
DAC | 5 |
| 2023 | An Investigation of Large Language Models for Real-World Hate Speech DetectionabstractHate speech has emerged as a major problem plaguing our social spaces today. While there have been significant efforts to address this problem, existing methods are still significantly limited in effectively detecting hate speech online. A major limitation of existing methods is that hate speech detection is a highly contextual problem, and these methods cannot fully capture the context of hate speech to make accurate predictions. Recently, large language models (LLMs) have demonstrated state-of-the-art performance in several natural language tasks. LLMs have undergone extensive training using vast amounts of natural language data, enabling them to grasp intricate contextual details. Hence, they could be used as knowledge bases for context-aware hate speech detection. However, a fundamental problem with using LLMs to detect hate speech is that there are no studies on effectively prompting LLMs for context-aware hate speech detection. In this study, we conduct a large-scale study of hate speech detection, employing five established hate speech datasets. We discover that LLMs not only match but often surpass the performance of current benchmark machine learning models in identifying hate speech. By proposing four diverse prompting strategies that optimize the use of LLMs in detecting hate speech. Our study reveals that a meticulously crafted reasoning prompt can effectively capture the context of hate speech by fully utilizing the knowledge base in LLMs, significantly outperforming existing techniques. Furthermore, although LLMs can provide a rich knowledge base for the contextual detection of hate speech, suitable prompting strategies play a crucial role in effectively leveraging this knowledge base for efficient detection. Keyan Guo, Alexander Hu, Jaden Mu, Ziheng Shi, Ziming Zhao 0001, Nishant Vishwamitra, Hongxin Hu |
ICMLA | 7 |
| 2023 | Analysis of COVID-19 Offensive Tweets and Their TargetsabstractDuring the global COVID-19 pandemic, people utilized social media platforms, especially Twitter, to spread and express opinions about the pandemic. Such discussions also drove the rise in COVID-related offensive speech. In this work, focusing on Twitter, we present a comprehensive analysis of COVID-related offensive tweets and their targets. We collected a COVID-19 dataset with over 747 million tweets for 30 months and fine-tuned a BERT classifier to detect offensive tweets. Our offensive tweets analysis shows that the ebb and flow of COVID-related offensive tweets potentially reflect events in the physical world. We then studied the targets of these offensive tweets. There was a large number of offensive tweets with abusive words, which could negatively affect the targeted groups or individuals. We also conducted a user network analysis, and found that offensive users interact more with other offensive users and that the pandemic had a lasting impact on some offensive users. Our study offers novel insights into the persistence and evolution of COVID-related offensive tweets during the pandemic Song Liao, Ebuka Okpala, Long Cheng 0005, Nishant Vishwamitra, Hongxin Hu, Feng Luo 0001, Matthew Costello |
KDD | 6 |
| 2023 | GAN You See Me? Enhanced Data Reconstruction Attacks against Split InferenceabstractSplit Inference (SI) is an emerging deep learning paradigm that addresses computational constraints on edge devices and preserves data privacy through collaborative edge-cloud approaches. However, SI is vulnerable to Data Reconstruction Attacks (DRA), which aim to reconstruct users' private prediction instances. Existing attack methods suffer from various limitations. Optimization-based DRAs do not leverage public data effectively, while Learning-based DRAs depend heavily on auxiliary data quantity and distribution similarity. Consequently, these approaches yield unsatisfactory attack results and are sensitive to defense mechanisms. To overcome these challenges, we propose a GAN-based LAtent Space Search attack (GLASS) that harnesses abundant prior knowledge from public data using advanced StyleGAN technologies. Additionally, we introduce GLASS++ to enhance reconstruction stability. Our approach represents the first GAN-based DRA against SI, and extensive evaluation across different split points and adversary setups demonstrates its state-of-the-art performance. Moreover, we thoroughly examine seven defense mechanisms, highlighting our method's capability to reveal private information even in the presence of these defenses. Mengda Yang, Juan Wang 0006, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001 |
NeurIPS | 5 |
| 2023 | Enabling High Quality Real-Time Communications with Adaptive Frame-Rate
Zili Meng, Tingfeng Wang, Yixin Shen 0002, Bo Wang 0066, Mingwei Xu 0001, Venkat Arun, Hongxin Hu |
NSDI | 9 |
| 2023 | xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
Hongda Li 0002, Ziming Zhao 0001, Hongxin Hu |
USENIX Security Symposium | 4 |
| 2023 | SvTPM: SGX-Based Virtual Trusted Platform Modules for Cloud ComputingabstractVirtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is$1700\times$faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX. Juan Wang 0006, Jie Wang 0006, Chengyang Fan, Fei Yan 0008, Yueqiang Cheng, Yinqian Zhang, Mengda Yang, Hongxin Hu |
IEEE Trans. Cloud Comput. | 9 |
| 2023 | SysFlow: Toward a Programmable Zero Trust Framework for System SecurityabstractZero Trust, as an emerging trend of cybersecurity paradigms in modern infrastructure (e.g., enterprise, cloud, edge, IoT, and 5G), is moving security defenses from static and perimeter-based control systems to focus on users and resources with no assumption of implicit trust. However, the current Zero Trust Architecture (ZTA) mainly focuses on the network security and lacks in-depth considerations on system-level security policies and abstractions, which leaves the realization of the principle incomplete. To bridge the gap, we propose an innovativeprogrammablesystem security framework called SYSFLOW to enable unified, dynamic, and fine-grained Zero Trust security control for system resources. SYSFLOW introduces a novelsystem flowabstraction to modelsystem activitiesacross the entire infrastructure, and provides a system-level data plane and control plane separation and abstraction. The new logically centralized controller accommodates a unifiedprogrammablePolicy Decision Point (PDP) that acquires a holistic view of system behaviors for controlling system resource accesses by translated programmable security policies into system flow rules. The SYSFLOW data plane, acting as Policy Enforcement Point (PEP), enforces translated system flow rules, which can be updated dynamically and facilitate fine-grained responsive actions. Our extensive evaluations demonstrate the effectiveness and scalability of SYSFLOW, which addresses the security issues in various scenarios with a minor performance overhead. Sungmin Hong, Lei Xu 0024, Hongda Li 0002, Hongxin Hu, Guofei Gu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Understanding and Detecting Remote Infection on Linux-based IoT DevicesabstractThe rocketed population, poor security, and 24/7 online properties make Linux-based Internet of Things (IoT) devices ideal targets for attackers. However, due to the budget constraints and an enormous number of vulnerabilities on such devices, protecting them against attacks is very challenging. Therefore, understanding and detecting IoT malware remote infection, which is before the compromised IoT devices are monetized by adversaries, is crucial to mitigate damages and financial loss caused by IoT malware. In this paper, we conduct an empirical study on a large-scale dataset covering 403,464 samples collected from VirusShare and a large group of IoT honeypots to gain a deep insight into the characteristics of IoT malware remote infection. We share detailed statistics of shell commands found in our dataset, highlight malicious behaviors performed through those commands, investigate current states of fingerprinting methods of those commands, and offer a taxonomy of shell commands by introducing the notion of infection capability. To demonstrate the usefulness of the knowledge gained from our study, we develop an approach to detect ongoing remote infection activities based on infection capabilities. Our evaluation shows that our detection approach can achieve a 99.22% detection rate for remote infections in the wild and introduce small performance overhead. Hongda Li 0002, Qiqing Huang, Hongxin Hu, Long Cheng 0005, Guofei Gu, Ziming Zhao 0001 |
AsiaCCS | 4 |
| 2022 | Towards Automated Content-based Photo Privacy Control in User-Centered Social NetworksabstractA large number of photos shared online often contain private user information, which can cause serious privacy breaches when viewed by unauthorized users. Thus, there is a need for more efficient privacy control that requires automatic detection of users' private photos. However, the automatic detection of users' private photos is a challenging task, since different users may have different privacy concerns and a generalized one-size-fits-all approach for private photo detection would not be suitable for most users. User-specific detection of private photos should, therefore, be investigated. Furthermore, for effective privacy control, the exact sensitive regions in private photos need to be pinpointed, so that sensitive content can be protected via different privacy control methods. In this paper, we propose a novel system, AutoPri, to enable automatic and user-specific content-based photo privacy control in online social networks. We collect a large dataset of 31, 566 private and public photos from real-world users and present important observations on photo privacy concerns. Our system can automatically detect private photos in a user-specific manner using a detection model based on a multimodal variational autoencoder and pinpoint sensitive regions in private photos with an explainable deep learning-based approach. Our evaluations show that AutoPri can effectively determine user-specific private photos with high accuracy (94.32%) and pinpoint exact sensitive regions in them to enable effective privacy control in user-centered online social networks. Nishant Vishwamitra, Yifang Li, Hongxin Hu, Kelly Caine, Long Cheng 0005, Ziming Zhao 0001, Gail-Joon Ahn |
CODASPY | 3 |
| 2022 | Multi-level Distillation of Semantic Knowledge for Pre-training Multilingual Language ModelabstractPre-trained multilingual language models play an important role in cross-lingual natural language understanding tasks.However, existing methods did not focus on learning the semantic structure of representation, and thus could not optimize their performance.In this paper, we propose Multi-level Multilingual Knowledge Distillation (MMKD), a novel method for improving multilingual language models.Specifically, we employ a teacher-student framework to adopt rich semantic representation knowledge in English BERT.We propose token-, word-, sentence-, and structure-level alignment objectives to encourage multiple levels of consistency between source-target pairs and correlation similarity between teacher and student models.We conduct experiments on crosslingual evaluation benchmarks including XNLI, PAWS-X, and XQuAD.Experimental results show that MMKD outperforms other baseline models of similar size on XNLI and XQuAD and obtains comparable performance on PAWS-X.Especially, MMKD obtains significant performance gains on low-resource languages. Long Cheng 0005, Hongxin Hu, Feng Luo 0001 |
EMNLP | 5 |
| 2022 | BYOZ: Protecting BYOD Through Zero Trust Network SecurityabstractAs the COVID-19 pandemic scattered businesses and their workforces into new scales of remote work, vital security concerns arose surrounding remote access. Bring Your Own Device (BYOD) also plays a growing role in the ability of companies to support remote workforces. As more enterprises embrace concepts of zero trust in their network security posture, access control policy management problems become a more significant concern as it relates to BYOD security enforcement. This BYOD security policy must enable work from home, but enterprises have a vested interest in maintaining the security of their assets. Therefore, the BYOD security policy must strike a balance between access, security, and privacy, given the personal device use. This paper explores the challenges and opportunities of enabling zero trust in BYOD use cases. We present a BYOD policy specification to enable the zero trust access control known as BYOZ. Accompanying this policy specification, we have designed a network architecture to support enterprise zero trust BYOD use cases through the novel incorporation of continuous authentication & authorization enforcement. We evaluate our architecture through a demo implementation of BYOZ and demonstrate how it can meet the needs of existing enterprise networks using BYOD. Qiqing Huang, Long Cheng 0005, Hongxin Hu |
NAS | 4 |
| 2022 | Measuring Data Reconstruction Defenses in Collaborative Inference SystemsabstractThe collaborative inference systems are designed to speed up the prediction processes in edge-cloud scenarios, where the local devices and the cloud system work together to run a complex deep-learning model. However, those edge-cloud collaborative inference systems are vulnerable to emerging reconstruction attacks, where malicious cloud service providers are able to recover the edge-side users’ private data. To defend against such attacks, several defense countermeasures have been recently introduced. Unfortunately, little is known about the robustness of those defense countermeasures. In this paper, we take the first step towards measuring the robustness of those state-of-the-art defenses with respect to reconstruction attacks. Specifically, we show that the latent privacy features are still retained in the obfuscated representations. Motivated by such an observation, we design a technology called Sensitive Feature Distillation (SFD) to restore sensitive information from the protected feature representations. Our experiments show that SFD can break through defense mechanisms in model partitioning scenarios, demonstrating the inadequacy of existing defense mechanisms as a privacy-preserving technique against reconstruction attacks. We hope our findings inspire further work in improving the robustness of defense mechanisms against reconstruction attacks for collaborative inference systems. Mengda Yang, Juan Wang 0006, Hongxin Hu, Ao Ren, Xiaoyang Xu 0001, Wenzhe Yi |
NeurIPS | 4 |
| 2022 | IMap: Fast and Scalable In-Network Scanning with Programmable Switches
Menghao Zhang 0001, Cheng Guo 0007, Han Bao 0011, Mingwei Xu 0001, Hongxin Hu |
NSDI | 6 |
| 2022 | SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the Wild
Song Liao, Long Cheng 0005, Hongxin Hu, Huixing Deng |
USENIX Security Symposium | 4 |
| 2022 | S-Blocks: Lightweight and Trusted Virtual Security Function With SGXabstractDespite the advantages of scalability and flexibility, Security Function Virtualization (SFV) raises concerns about its own security. To enhance the security of SFV, a promising approach is to run critical components of off-the-shelf security software inside Software Guard Extensions (SGX) enclaves. This idea, however, is hardly practical due to the difficulty of detaching components from the monolithic security function and the unacceptable cost of executing them inside enclaves. In this article, we propose S-Blocks, an architecture to modularize virtual security functions (VSFs) and protect crucial modules with SGX in an efficient manner. S-Blocks decomposes VSFs into trusted and untrusted modules and provides dedicated APIs systematically. Only crucial VSF modules are hardened with enclaves. Furthermore, aiming at addressing state consistency and secure migration issues of security function scaling, we design a fine-grained state synchronization and migration mechanism to ensure loss-free, order-preserving, and state security for VSFs. To demonstrate the effectiveness of our approach, we prototype S-Blocks using Fast-Click on a real Skylake platform and implement three critical types of virtual security functions based on the S-Blocks architecture. Our evaluation results show that S-Blocks only imposes a manageable performance overhead, and low latency and resource consumption when protecting VSFs. Juan Wang 0006, Shirong Hao, Hongxin Hu, Bo Zhao 0023, Hongda Li 0002, Jun Xu 0024, Peng Liu 0005 |
IEEE Trans. Cloud Comput. | 3 |
| 2021 | Switches are Scanners Too!: A Fast and Scalable In-Network Scanner with Programmable SwitchesabstractNetwork scanning has been a standard measurement technique to understand the network's security situations, however, probing a large-scale scanning space with existing network scanners is both difficult and slow. To address this issue, we introduce IMap, a fast and scalable in-network scanner based on programmable switches. In designing IMap, we overcome key restrictions posed by computation models and memory resources of programmable switches, and devise numerous techniques and optimizations to turn a switch into a practical high-speed network scanner. We conduct preliminary experiments on the open-source prototype of IMap and evaluation results show that IMap can survey all addresses (i.e., 6 Class B Addresses) and all ports of our campus network in 8 minutes, nearly 4 times faster than state-of-the-art network scanners. As an ongoing work, we plan to continuously improve the design and implementation of IMap, and hope IMap can serve as a foundation for designing next-generation terabit network scanners. Menghao Zhang 0001, Cheng Guo 0007, Han Bao 0011, Mingwe Xu, Hongxin Hu |
HotNets | 6 |
| 2021 | CARTL: Cooperative Adversarially-Robust Transfer LearningabstractTransfer learning eases the burden of training a well-performed model from scratch, especially when training data is scarce and computation power is limited. In deep learning, a typical strategy for transfer learning is to freeze the early layers of a pre-trained model and fine-tune the rest of its layers on the target domain. Previous work focuses on the accuracy of the transferred model but neglects the transfer of adversarial robustness. In this work, we first show that transfer learning improves the accuracy on the target domain but degrades the inherited robustness of the target model. To address such a problem, we propose a novel cooperative adversarially-robust transfer learning (CARTL) by pre-training the model via feature distance minimization and fine-tuning the pre-trained model with non-expansive fine-tuning for target domain tasks. Empirical results show that CARTL improves the inherited robustness by about 28% at most compared with the baseline with the same degree of accuracy. Furthermore, we study the relationship between the batch normalization (BN) layers and the robustness in the context of transfer learning, and we reveal that freezing BN layers can further boost the robustness transfer. Dian Chen 0004, Hongxin Hu, Qian Wang 0002, Yinli Li, Cong Wang 0001, Chao Shen 0001, Qi Li 0002 |
ICML | 2 |
| 2021 | COVID-HateBERT: a Pre-trained Language Model for COVID-19 related Hate Speech DetectionabstractWith the dramatic growth of hate speech on social media during the COVID-19 pandemic, there is an urgent need to detect various hate speech effectively. Existing methods only achieve high performance when the training and testing data come from the same data distribution. The models trained on the traditional hateful dataset cannot fit well on COVID-19 related dataset. Meanwhile, manually annotating the hate speech dataset for supervised learning is time-consuming. Here, we propose COVID-HateBERT, a pre-trained language model to detect hate speech on English Tweets to address this problem. We collect 200M English tweets based on COVID-19 related hateful keywords and hashtags. Then, we use a classifier to extract the 1.27M potential hateful tweets to re-train BERT-base. We evaluate our COVID-HateBERT on four benchmark datasets. The COVID-HateBERT achieves a 14.8%-23.8% higher macro average F1 score on traditional hate speech detection comparing to baseline methods and a 2.6%-6.73% higher macro average F1 score on COVID-19 related hate speech detection comparing to classifiers using BERT and BERTweet, which shows that COVID-HateBERT can generalize well on different datasets. Song Liao, Ebuka Okpala, Max Tong, Matthew Costello, Long Cheng 0005, Hongxin Hu, Feng Luo 0001 |
ICMLA | 7 |
| 2021 | HierTopo: Towards High-Performance and Efficient Topology Optimization for Dynamic NetworksabstractDynamic networks have enabled dynamically adapting the network topology to meet the need of real-time traffic demands. However, due to the complexity of topology optimization, existing solutions suffer from a trade-off between performance and efficiency, which either have large optimality gaps or excessive optimization overhead. To break through this trade-off, our key observation is that we could offload the optimization procedure to every network node to handle the complexity. Thus, we propose HierTopo, a hierarchical topology optimization method for dynamic networks that achieves both high performance and efficiency. HierTopo firstly runs a local policy on each network node to aggregate network information into low-dimension features, then uses these features to make global topology decisions. Evaluation on real-world network traces shows that HierTopo outperforms the state-of-the-art solutions by 11.52-38.91% with only milliseconds of decision latency, and is also superior in generalization ability. Zili Meng, Yaning Guo, Mingwei Xu 0001, Hongxin Hu |
IWQoS | 5 |
| 2021 | IoTSafe: Enforcing Safety and Security Policy with Real IoT Physical Interaction Discovery
Wenbo Ding 0003, Hongxin Hu, Long Cheng 0005 |
NDSS | 2 |
| 2021 | Towards Understanding and Detecting Cyberbullying in Real-world Images
Nishant Vishwamitra, Hongxin Hu, Feng Luo 0001, Long Cheng 0005 |
NDSS | 2 |
| 2021 | Context-Rich Privacy Leakage Analysis Through Inferring Apps in Smart Home IoTabstractEmerging Internet of Things (IoT) systems leverage connected devices to enable intelligent and automated functionalities. Despite the benefits, there exist privacy risks of network traffic, which have been studied by the previous research. However, with the current privacy inference remaining at the event-level, potential privacy risks are underestimated, which, as our study shows, can be much higher than previously reported through app-level traffic analysis. A key observation of our research is that IoT event-triggered traffic is generated by apps, which often adopt an if-trigger-then-action (trigger-action) programming paradigm. We utilize this feature to develop fingerprints to differentiate running apps and learn context-rich privacy-sensitive information from apps. In this article, we present a privacy leakage analysis called ALTA to infer running apps in smart home IoT environments. First, ALTA identifies app fingerprints through static analysis and extracts sensitive information from app descriptions and input prompts. Then, through dynamic traffic profiling, it learns traffic fingerprints of apps. Finally, ALTA matches the fingerprints of app and traffic, and thus is able to pinpoint which app is running from IoT traffic at runtime. To demonstrate the feasibility of our approach, we analyze 254 SmartThings applications via program and natural language processing (NLP) analysis. We also perform the app inference evaluation on 31 apps executed in a simulated smart home. The results suggest that ALTA can effectively infer running apps from IoT traffic and learn context-rich information (e.g., health conditions, daily routines, and user activities) from apps with high accuracy. Long Cheng 0005, Hongxin Hu, Guojun Peng, Danfeng Yao |
IEEE Internet Things J. | 3 |
| 2021 | IoT-Praetor: Undesired Behaviors Detection for IoT DevicesabstractDue to insecure design and configuration, the Internet-of-Things (IoT) devices are vulnerable to various security issues. In most attacks against IoT, e.g., Mirai, attackers control devices to perform malicious behaviors that are not expected by owners and administrators. Therefore, how to effectively detect malicious behaviors is crucial to protect the security of IoT devices. Different from powerful PCs and servers, resource-constrained IoT devices are generally used to execute the specific function and their behaviors are limited. Based on this observation, we propose IoT-Praetor, an undesired behavior security detection system for IoT devices. In IoT-Praetor, a new device usage description (DUD) model is proposed to construct an IoT device behavior specification, including communication and interaction behaviors. Furthermore, automatic behavior extraction approaches are presented. We also design a behavior rule engine to detect device behaviors in real time. To evaluate the effectiveness of IoT-Praetor, we implemented our methods on Samsung SmartThings and performed a security test. The evaluation results show that the successful detection rate of malicious interaction behavior is 94.5% on average, and the detection rate of malicious communication behavior is above 98%, and system running time delay is only in millisecond level. Juan Wang 0006, Shirong Hao, Ru Wen, Boxian Zhang, Hongxin Hu, Rongxing Lu |
IEEE Internet Things J. | 6 |
| 2021 | Enabling Performant, Flexible and Cost-Efficient DDoS Defense With Programmable SwitchesabstractDistributed Denial-of-Service (DDoS) attacks have become a critical threat to the Internet. Due to the increasing number of vulnerable Internet of Things (IoT) devices, attackers can easily compromise a large set of nodes and launch high-volume DDoS attacks from the botnets. State-of-the-art DDoS defenses, however, have not caught up with the fast development of the attacks. Middlebox-based defenses can achieve high performance with specialized hardware; however, these defenses incur a high cost, and deploying new defenses typically requires a device upgrade. On the other hand, software-based defenses are highly flexible, but software-based packet processing leads to high performance overheads. In this article, we propose Poseidon, a system that addresses these limitations in today's DDoS defenses. It leverages emerging programmable switches, which can be reconfigured in the field without additional hardware upgrades. Users of Poseidon can specify their defense strategies in a modular fashion in the form of a set of defense primitives; this can be further customized easily for each network and extended to include new defenses. Poseidon then maps the defense primitives to run on programmable switches-and when necessary, on server software-for effective defense. When attacks change, Poseidon can reconfigure the underlying defense primitives to respond to the new attack patterns. Evaluations using our prototype demonstrate that Poseidon can effectively defend against high-volume attacks, easily support customization of defense strategies, and adapt to dynamic attacks with low overheads. Menghao Zhang 0001, Chang Liu 0021, Mingwei Xu 0001, Ang Chen 0001, Hongxin Hu, Guofei Gu, Qi Li 0002 |
IEEE/ACM Trans. Netw. | 7 |
| 2021 | Practically Deploying Heavyweight Adaptive Bitrate Algorithms With Teacher-Student LearningabstractMajor commercial client-side video players employ adaptive bitrate (ABR) algorithms to improve the user quality of experience (QoE). With the evolvement of ABR algorithms, increasingly complex methods such as neural networks have been adopted to pursue better performance. However, these complex methods are too heavyweight to be directly deployed in client devices with limited resources, such as mobile phones. Existing solutions suffer from a trade-off between algorithm performance and deployment overhead. To make the deployment of sophisticated ABR algorithms practical, we propose PiTree, a general, high-performance, and scalable framework that can faithfully convert sophisticated ABR algorithms into decision trees with teacher-student learning. In this way, network operators can train complex models offline and deploy converted lightweight decision trees online. We also present theoretical analysis on the conversion and provide two upper bounds of the prediction error during the conversion and the generalization loss after conversion. Evaluation on three representative ABR algorithms with both trace-driven emulation and real-world experiments demonstrates that PiTree could convert ABR algorithms into decision trees with <; 3% average performance degradation. Moreover, compared to original deployment solutions, PiTree could save considerable operating expenses for content providers. Zili Meng, Yaning Guo, Yixin Shen 0002, Chao Zhou 0003, Minhu Wang, Jia Zhang 0010, Mingwei Xu 0001, Chen Sun 0005, Hongxin Hu |
IEEE/ACM Trans. Netw. | 10 |
| 2021 | Octans: Optimal Placement of Service Function Chains in Many-Core SystemsabstractNetwork Function Virtualization (NFV) offers service delivery flexibility and reduces overall costs by running service function chains (SFCs) on commodity servers with many cores. Existing solutions for placing SFCs in one server treat all CPU cores as equal and allocate isolated CPU cores to network functions (NFs). However, advanced servers often adopt Non-Uniform Memory Access (NUMA) architecture to improve the scalability of many-core systems. CPU cores are grouped into nodes, incurring performance degradation due to cross-node memory access and intra-node resource contention. Our evaluation shows that randomly selecting cores to place NFs in an SFC could suffer from 39.2 percent lower throughput comparing to an optimal placement solution. In this article, we propose Octans, an NFV orchestrator to achieve maximum aggregate throughput of all SFCs in many-core systems. Octans first formulates the optimization problem as a Non-Linear Integer Programming (NLIP) Model. Then we identify the key factor for problem solving as evaluating the throughput drop of an NF caused by other NFs in the same SFC or different SFCs, i.e., performance drop index, and propose a formal and accurate prediction model based on system level performance metrics. Finally, we propose two online algorithms to quickly find near-optimal placement solutions for one-time and incremental deployment. Extensive evaluation on a prototype implementation shows that Octans significantly improves the aggregate throughput comparing to two state-of-the-art placement solutions by 27.1 ~ 45.2 percent for one-time deployment and by 20.9 ~ 38.1 percent for incremental deployment, with very low prediction errors. Moreover, Octans could quickly find a near-optimal placement solution with tiny optimality gap. Heng Yu 0005, Zhilong Zheng, Junxian Shen, Congcong Miao, Chen Sun 0005, Hongxin Hu, Jun Bi, Jilong Wang 0001 |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2020 | Measuring the Effectiveness of Privacy Policies for Voice Assistant ApplicationsabstractVoice Assistants (VA) such as Amazon Alexa and Google Assistant are quickly and seamlessly integrating into people’s daily lives. The increased reliance on VA services raises privacy concerns such as the leakage of private conversations and sensitive information. Privacy policies play an important role in addressing users’ privacy concerns and informing them about the data collection, storage, and sharing practices. VA platforms (both Amazon Alexa and Google Assistant) allow third-party developers to build new voice-apps and publish them to app stores. Voice-app developers are required to provide privacy policies to disclose their apps’ data practices. However, little is known whether these privacy policies are informative and trustworthy or not on emerging VA platforms. On the other hand, many users invoke voice-apps through voice and thus there exists a usability challenge for users to access these privacy policies. Song Liao, Christin Wilson, Long Cheng 0005, Hongxin Hu, Huixing Deng |
ACSAC | 4 |
| 2020 | Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant PlatformsabstractWith the emergence of the voice personal assistant (VPA) ecosystem, third-party developers are allowed to build new voice-apps are called skills in the Amazon Alexa platform and actions in the Google Assistant platform, respectively. For the sake of brevity, we use the term skills to describe voice-apps including Amazon skills and Google actions, unless we need to distinguish them for different VPA platforms. and publish them to the skills store, which greatly extends the functionalities of VPAs. Before a new skill becomes publicly available, that skill must pass a certification process, which verifies that it meets the necessary content and privacy policies. The trustworthiness of skill certification is of significant importance to platform providers, developers, and end users. Yet, little is known about how difficult it is for a policy-violating skill to get certified and published in VPA platforms. In this work, we study the trustworthiness of the skill certification in Amazon Alexa and Google Assistant platforms to answer three key questions: 1) Whether the skill certification process is trustworthy in terms of catching policy violations in third-party skills. 2) Whether there exist policy-violating skills published in their skills stores. 3) What are VPA users' perspectives on the skill certification and their vulnerable usage behavior when interacting with VPA devices? Over a span of 15 months, we crafted and submitted for certification 234 Amazon Alexa skills and 381 Google Assistant actions that intentionally violate content and privacy policies specified by VPA platforms. Surprisingly, we successfully got 234 (100%) policy-violating Alexa skills certified and 148 (39%) policy-violating Google actions certified. Our analysis demonstrates that policy-violating skills exist in the current skills stores, and thus users (children, in particular) are at risk when using VPA services. We conducted a user study with 203 participants to understand users' misplaced trust on VPA platforms. Unfortunately, user expectations are not being met by the skill certification in leading VPA platforms. Long Cheng 0005, Christin Wilson, Song Liao, Daniel Dong, Hongxin Hu |
CCS | 6 |
| 2020 | DeepPower: Non-intrusive and Deep Learning-based Detection of IoT Malware Using Power Side ChannelsabstractThe vulnerability of Internet of Things (IoT) devices to malware attacks poses huge challenges to current Internet security. The IoT malware attacks are usually composed of three stages: intrusion, infection and monetization. Existing approaches for IoT malware detection cannot effectively identify the executed malicious activities at intrusion and infection stages, and thus cannot help stop potential attacks timely. In this paper, we present DeepPower, a non-intrusive approach to infer malicious activities of IoT malware via analyzing power side-channel signals using deep learning. DeepPower first filters raw power signals of IoT devices to obtain suspicious signals, and then performs a fine-grained analysis on these signals to infer corresponding executed activities inside the devices. DeepPower determines whether there exists an ongoing malware infection by conducting a correlation analysis on these identified activities. We implement a prototype of DeepPower leveraging low-cost sensors and devices and evaluate the effectiveness of DeepPower against real-world IoT malware using commodity IoT devices. Our experimental results demonstrate that DeepPower is able to detect infection activities of different IoT malware with a high accuracy without any changes to the monitored devices. Hongda Li 0002, Feng Luo 0001, Hongxin Hu, Long Cheng 0005, Hai Xiao, Rong Ge 0002 |
AsiaCCS | 4 |
| 2020 | Towards A Taxonomy of Content Sensitivity and Sharing Preferences for PhotosabstractDetermining which photos are sensitive is difficult. Although emerging computer vision systems can label content items, previous attempts to distinguish private or sensitive content fall short. There is no human-centered taxonomy that describes what content is sensitive or how sharing preferences for content differs across recipients. To fill this gap, we introduce a new sensitive content elicitation method which surmounts limitations of previous approaches, and, using this new method, collected sensitive content from 116 participants. We also recorded participants' sharing preferences with 20 recipient groups. Next, we conducted a card sort to surface user-defined categories of sensitive content. Using data from these studies, we generated a taxonomy that identifies 28 categories of sensitive content. We also establish how sharing preferences for content differs across groups of recipients. This taxonomy can serve as a framework for understanding photo privacy, which can, in turn, inform new photo privacy protection mechanisms. Yifang Li, Nishant Vishwamitra, Hongxin Hu, Kelly Caine |
CHI | 3 |
| 2020 | SmartChain: Enabling High-Performance Service Chain Partition between SmartNIC and CPUabstractSmart Network Interface Cards (SmartNICs) have been widely used to accelerate software-based network functions (NFs). However, from the scope of a service chain, a careless selection of NFs to offload onto SmartNIC could severely degrade the performance due to frequent communications between CPU and SmartNIC. In this paper, we present SmartChain, a high performance and efficient framework that achieves optimal partition of service chains between SmartNIC and CPU. SmartChain consists of two logical steps. First, SmartChain analyzes the suitability of elements in a chain to run on SmartNIC to exploit its high performance. Besides, SmartChain also ensures the dependencies between elements. Second, as our key novelty, SmartChain models the service chain latency and resource constraints, and solves the partition problem with 0-1 integer linear programming. We implement a SmartChain prototype based on Netronome SmartNIC. Evaluation results show that when used in real world cases, SmartChain could reduce the service chain latency by up to 87% with throughput maintained compared with strawman solutions. Shuhe Wang, Zili Meng, Chen Sun 0005, Minhu Wang, Mingwei Xu 0001, Jun Bi, Tong Yang 0003, Qun Huang 0001, Hongxin Hu |
ICC | 9 |
| 2020 | Martini: Bridging the Gap between Network Measurement and Control Using Switching ASICsabstractAdvanced network management systems, including network measurement and traffic control, rely on a remote controller to make control decisions. However, this approach incurs a long control loop of a few seconds to minutes. Even if we switch to switch-local controller, the latency is still tens of milliseconds and is unacceptable for many latency-sensitive tasks. In this paper, we propose Martini, a general framework that supports measurement-based timely control. The key idea is to perform measurement, control decision, and control entirely in the switch data plane. This could shorten the control loop of management tasks that require timely control based on only locally measured statistics in the switch. First, Martini introduces a set of primitives to describe management tasks. Next, Martini provides an innovative network-wide task placement mechanism to exploit resources of all switches to accommodate massive management tasks. Finally, Martini provides a code library and a compiler to support measurement and control on a state-of-the-art switching ASIC. Evaluation results show that Martini can effectively support a wide range of fine-timescale management tasks such as microburst detection and fast load balancing by reducing the control loop from seconds to nanoseconds. Shuhe Wang, Chen Sun 0005, Zili Meng, Minhu Wang, Jiamin Cao, Mingwei Xu 0001, Jun Bi, Qun Huang 0001, Masoud Moshref, Tong Yang 0003, Hongxin Hu, Gong Zhang 0001 |
ICNP | 11 |
| 2020 | Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches
Menghao Zhang 0001, Chang Liu 0021, Ang Chen 0001, Hongxin Hu, Guofei Gu, Qi Li 0002, Mingwei Xu 0001 |
NDSS | 6 |
| 2020 | Interpreting Deep Learning-Based Networking SystemsabstractWhile many deep learning (DL)-based networking systems have demonstrated superior performance, the underlying Deep Neural Networks (DNNs) remain blackboxes and stay uninterpretable for network operators. The lack of interpretability makes DL-based networking systems prohibitive to deploy in practice. In this paper, we propose Metis, a framework that provides interpretability for two general categories of networking problems spanning local and global control. Accordingly, Metis introduces two different interpretation methods based on decision tree and hypergraph, where it converts DNN policies to interpretable rule-based controllers and highlight critical components based on analysis over hypergraph. We evaluate Metis over two categories of state-of-the-art DL-based networking systems and show that Metis provides human-readable interpretations while preserving nearly no degradation in performance. We further present four concrete use cases of Metis, showcasing how Metis helps network operators to design, debug, deploy, and ad-hoc adjust DL-based networking systems. Zili Meng, Minhu Wang, Jiasong Bai, Mingwei Xu 0001, Hongzi Mao, Hongxin Hu |
SIGCOMM | 6 |
| 2019 | When NFV Meets ANN: Rethinking Elastic Scaling for ANN-based NFsabstractNetwork Function Virtualization (NFV) provides middleboxes with substantial elasticity from a system level, and Artificial Neural Network (ANN) empowers middleboxes with great intelligence from an algorithm-level perspective. However, when ANN-based Network Functions (NFs) want to take advantage of the elasticity of NFV, our study finds that huge gaps exist between the existing approaches and the ideal goals for the elasticity control of ANN-based NFs. By revealing the key differences between ANN-based NFs and traditional NFs, we propose LEGO, an innovative framework that provides systematic mechanisms for traffic splitting, instance partition and runtime management to enable correct and efficient scaling of ANN-based NFs. Preliminary implementation and evaluation demonstrate the feasibility and effectiveness of the LEGO system. The major purpose of this paper is to highlight these challenges and sketch out a new roadmap towards ANN-based NFV paradigm. Menghao Zhang 0001, Jiasong Bai, Zili Meng, Hongda Li 0002, Hongxin Hu, Mingwei Xu 0001 |
ICNP | 6 |
| 2019 | Octans: Optimal Placement of Service Function Chains in Many-Core SystemsabstractNetwork Function Virtualization (NFV) has the potential to offer service delivery flexibility and reduce overall costs by running service function chains (SFCs) on commodity servers with many cores. Existing solutions for placing SFCs in one server treat all CPU cores as equal and allocate isolated CPU cores to different network functions (NFs). However, advanced servers often adopt Non-Uniform Memory Access (NUMA) architecture to improve the scalability of many-core systems. CPU cores are grouped into nodes, incurring performance bottleneck due to cross-node memory access and intra-node resource contention. Our evaluation shows that randomly selecting cores to place NFs in an SFC could suffer from 39.2% lower throughput comparing to an optimal placement solution. In this paper, we propose Octans, an NFV orchestrator to achieve maximum aggregate throughput of all SFCs in many-core systems. Octans first formulates the optimization problem as a Non-Linear Integer Programming (NLIP) model. Then we identify the key factor for problem solving as evaluating the throughput drop of an NF caused by other NFs in the same SFC or different SFCs, i.e. performance drop index, and propose a formal and precise prediction model based on system level performance metrics. Finally, we propose an efficient heuristic algorithm to quickly find near-optimal placement solutions. We have implemented a prototype of Octans. Extensive evaluation shows that Octans significantly improves the aggregate throughput comparing to two state-of the-art placement mechanisms by 26.7%~51.8%, with very low prediction errors of SFC performance (an average deviation of 2.6%). Moreover, Octans could quickly find a near-optimal placement solution with tiny optimality gap (1.2%~3.5%). Zhilong Zheng, Jun Bi, Heng Yu 0005, Haiping Wang 0002, Chen Sun 0005, Hongxin Hu |
INFOCOM | 6 |
| 2019 | PiTree: Practical Implementation of ABR Algorithms Using Decision TreesabstractMajor commercial client-side video players employ adaptive bitrate (ABR) algorithms to improve user quality of experience (QoE). With the evolvement of ABR algorithms, increasingly complex methods such as neural networks have been adopted to pursue better performance. However, these complex methods are too heavyweight to be directly implemented in client devices, especially mobile phones with very limited resources. Existing solutions suffer from a trade-off between algorithm performance and deployment overhead. To make the implementation of sophisticated ABR algorithms practical, we propose PiTree, a general, high-performance and scalable framework that can faithfully convert sophisticated ABR algorithms into lightweight decision trees to reduce deployment overhead. We also provide a theoretical upper bound on the optimization loss during the conversion. Evaluation results on three representative ABR algorithms demonstrate that PiTree could faithfully convert ABR algorithms into decision trees with <3% average performance degradation. Moreover, comparing to original implementation solutions, PiTree could save operating expenses for large content providers. Zili Meng, Yaning Guo, Chen Sun 0005, Hongxin Hu, Mingwei Xu 0001 |
ACM Multimedia | 5 |
| 2019 | Security Labs for Software Defined Networks in CloudLababstractSoftware-Defined Networking (SDN) has been changing inflexible networks in software-based programmable networks for more flexibility, scalability, and visibility into networking. At the same time, it brings many new security challenges, but there are very few educational materials for students in learning about SDN security. In this workshop, we present our newly designed SDN security education materials, which can be used to meet the ever-increasing demand for high-quality cybersecurity professionals with expertise in SDN security. For effective hands-on learning, the security labs are designed in CloudLab, a free open cloud platform supported by NSF. Participants receive handouts describing security problems, lab instructions, techniques to use CloudLab, and worksheets for Q&A, which can be directly used for their networking classes at their home institutions. The workshop proceeds in three sessions in which we: present the way to use CloudLab and to understand SDN; practice in simulating three networking attacks in SDN on CloudLab; and discussion and critique in small groups for new SDN security labs. Younghee Park, Hongxin Hu, Xiaohong Yuan |
SIGCSE | 2 |
| 2019 | Towards a reliable firewall for software-defined networks
Hongxin Hu, Wonkyu Han, Sukwha Kyung, Juan Wang 0006, Gail-Joon Ahn, Ziming Zhao 0001, Hongda Li 0002 |
Comput. Secur. | 1 |
| 2019 | MicroNF: An Efficient Framework for Enabling Modularized Service Chains in NFVabstractThe modularization of service function chains (SFCs) in network function virtualization (NFV) could introduce significant performance overhead and resource efficiency degradation due to introducing frequent packet transfer and consuming much more hardware resources. In response, we exploit the reusability, lightweightness, and individual scalability features of elements in modularized SFCs (MSFCs) and propose MicroNF, an efficient framework for MSFC in NFV. MicroNF addresses the performance overhead and resource efficiency problems in three ways. First, MicroNF graph constructor reuses the processing results of elements from different NFs and reconstructs the MSFC after modularization to shorten the chain latency. Second, optimized placer pays attention to the problem of which elements to consolidate and provides a performance-aware placement algorithm to place MSFCs compactly and optimize the global packet transfer cost. Third, MicroNF individual scaler innovatively introduces a push-aside scaling up strategy to avoid degrading performance and taking up new CPU cores. To support MSFC reusing and consolidation, MicroNF also designs a high-performance infrastructure to efficiently forwarding packets with consistency ensured and to automatically scheduling elements with fairness ensured when the elements are consolidated on the CPU core. Our evaluation results show that MicroNF achieves significant performance improvement and efficient resource utilization on several metrics. Zili Meng, Jun Bi, Haiping Wang 0002, Chen Sun 0005, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 5 |
| 2019 | Tripod: Towards a Scalable, Efficient and Resilient Cloud GatewayabstractCloud gateways are fundamental components of a cloud platform, where various network functions (e.g., L4/L7 load balancing, network address translation, stateful firewall, and SYN proxy) are deployed to process millions of connections and billions of packets. Providing high-performance and failure-resilient packet processing with a scalable traffic management mechanism is crucial to ensuring the quality of service of a cloud provider, and hence is of great importance. Many network functions nowadays are implemented in software with commodity servers for low cost and high flexibility. However, existing software-based network function frameworks oftentimes provide part of these features, while cannot satisfy all three requirements above simultaneously. To address these issues, in this paper, we introduce TRIPOD, a novel network function framework specialized for cloud gateways. Having identified the fundamental limitations of loosely coupling traffic, processing logic and state, TRIPOD jointly manages these three elements with the unique characteristics of cloud gateways, which is enabled by a simple, efficient traffic processing mechanism, and a high performance state management service. Adopting several effective techniques and optimizations, TRIPOD is able to achieve scalable traffic management (<;100 flow rules for even ~Tbps traffic), high performance (reducing 40% of latency compared with state of the art) and failure resilience (similar packet/connection loss rate compared to state of the art), with reasonable overheads (less than 10% of the workload traffic) even under an extremely heavy traffic, making it a good fit for cloud gateways. Menghao Zhang 0001, Jun Bi, Kai Gao 0001, Yi Qiao, Zhaogeng Li, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 8 |
| 2019 | Guest Editors' Introduction: Special Section on Security in Emerging Networking TechnologiesabstractThe papers in this special section examine security in emerging networking technologies. Network infrastructure is undergoing a major shift away from ossified hardware-based networks to programmable software-based networks. One compelling example of this paradigm shift is the advent of Software- Defined Networking (SDN). A traditional network mixes control and traffic processing logic in single hardware devices, making the network more complex and harder to manage. SDN has addressed this issue by decoupling the control plane in network devices from the data plane to simplify production networks. On the other hand, enterprise networks are populated with a large number of proprietary and expensive hardware-based middleboxes, such as firewall, IDS/IPS, and load balancing. Hardware-based middleboxes present significant drawbacks such as high costs, management complexity, slow time to market, and unscalability. Network Function Virtualization (NFV) was proposed as another new network paradigm to address those drawbacks by replacing hardware-based network functions with virtualized software systems running on generic and inexpensive commodity hardware. Given their benefits, SDN and NFV have recently attracted significant attention from both academia and industry. Gail-Joon Ahn, Guofei Gu, Hongxin Hu, Seungwon Shin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | GEN: A GPU-Accelerated Elastic Framework for NFVabstractNetwork Function Virtualization (NFV) has the potential to enhance service delivery flexibility and reduce overall costs by provisioning software-based service function chains (SFCs) on commodity hardware. However, we observe that existing CPU-based SFC solutions cannot achieve both high performance and high elasticity simultaneously. To address such a critical challenge, we seek beyond CPU and exploit the capability of Graphics Processing Unit (GPU) to support NFV. We propose GEN, a GPU-based high performance and elastic framework for NFV. As opposed to pipeline-based SFCs in existing GPU-based NFV systems, GEN proposes to support RTC-based SFCs to improve processing performance. Meanwhile, GEN offers great elasticity of network function (NF) scaling up and down by allocating a different number of fine-grained GPU threads to an NF during runtime. We have implemented a prototype of GEN. Preliminary evaluation results demonstrate that GEN improves performance with RTC-based SFCs, and supports adaptive, precise, and fast NF scaling for NFV. Zhilong Zheng, Jun Bi, Chen Sun 0005, Heng Yu 0005, Hongxin Hu, Zili Meng, Shuhe Wang, Kai Gao 0001 |
APNet | 5 |
| 2018 | On the Safety of IoT Device Physical Interaction ControlabstractEmerging Internet of Things (IoT) platforms provide increased functionality to enable human interaction with the physical world in an autonomous manner. The physical interaction features of IoT platforms allow IoT devices to make an impact on the physical environment. However, such features also bring new safety challenges, where attackers can leverage stealthy physical interactions to launch attacks against IoT systems. In this paper, we propose a framework called IoTMon that discovers any possible physical interactions and generates all potential interaction chains across applications in the IoT environment. IoTMon also includes an assessment of the safety risk of each discovered inter-app interaction chain based on its physical influence. To demonstrate the feasibility of our approach, we provide a proof-of-concept implementation of IoTMon and present a comprehensive system evaluation on the Samsung SmartThings platform. We study 185 official SmartThings applications and find they can form 162 hidden inter-app interaction chains through physical surroundings. In particular, our experiment reveals that 37 interaction chains are highly risky and could be potentially exploited to impact the safety of the IoT~environment. Wenbo Ding 0003, Hongxin Hu |
CCS | 2 |
| 2018 | vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection SystemsabstractTraditional Network Intrusion Detection Systems (NIDSes) are generally implemented on vendor proprietary appliances or middleboxes with poor versatility and flexibility. Emerging Network Function Virtualization (NFV) and Software-Defined Networking (SDN) technologies can virtualize NIDSes and elastically scale them to deal with attack traffic variations. However, such an elasticity feature must not come at the cost of decreased detection effectiveness and expensive provisioning. In this paper, we propose an innovative NIDS architecture, vNIDS, to enable safe and efficient virtualization of NIDSes. vNIDS addresses two key challenges with respect to effective intrusion detection and non-monolithic NIDS provisioning in virtualizing NIDSes. The former challenge is addressed by detection state sharing while minimizing the sharing overhead in virtualized environments. In particular, static program analysis is employed to determine which detection states need to be shared. vNIDS addresses the latter challenge by provisioning virtual NIDSes as microservices and employing program slicing to partition the detection logic programs so that they can be executed by each microservice separately. We implement a prototype of vNIDS to demonstrate the feasibility of our approach. Our evaluation results show that vNIDS could offer both effective intrusion detection and efficient provisioning for NIDS virtualization. Hongda Li 0002, Hongxin Hu, Guofei Gu, Gail-Joon Ahn |
CCS | 2 |
| 2018 | CoCo: Compact and Optimized Consolidation of Modularized Service Function Chains in NFVabstractThe modularization of Service Function Chains (SFCs) in Network Function Virtualization (NFV) could introduce significant performance overhead and resource efficiency degradation due to introducing frequent packet transfer and consuming much more hardware resources. In response, we exploit the lightweight and individually scalable features of elements in Modularized SFCs (MSFCs) and propose CoCo, a compact and optimized consolidation framework for MSFC in NFV. CoCo addresses the above problems in two ways. First, CoCo Optimized Placer pays attention to the problem of which elements to consolidate and provides a performance-aware placement algorithm to place MSFCs compactly and optimize the global packet transfer cost. Second, CoCo Individual Scaler innovatively introduces a push-aside scaling up strategy to avoid degrading performance and taking up new CPU cores. To support MSFC consolidation, CoCo also provides an automatic runtime scheduler to ensure fairness when elements are consolidated on CPU core. Our evaluation results show that CoCo achieves significant performance improvement and efficient resource utilization. Zili Meng, Jun Bi, Haiping Wang 0002, Chen Sun 0005, Hongxin Hu |
ICC | 5 |
| 2018 | Improving Integrated LTE-WiFi Network Performance with SDN Based Flow SchedulingabstractDue to the explosive growth of data demand from mobile devices, cellular operators have been exploring the use of WiFi to offload traffic from the LTE network. Such an integration opens the door for exploiting the network usage diversity for further overall network performance improvement, by intelligently and dynamically scheduling flows over the most appropriate network. However, how such a function can be efficiently and systematically realize, is missing from the current standard specifications, especially on the network infrastructure side. In this paper, we aim to solve such a challenge by proposing a Software-Defined Networking (SDN) based flow scheduling system that is compatible to the 3GPP LTE-WiFi integration framework. The global view provided by SDN makes it easy to collect necessary flow information, and the flexible control of SDN enables efficient flow scheduling. We view the flow scheduling problem as an overall network utility maximization problem. We prove its hardness and propose an approximation algorithm for solving the problem. The proposed system can be incrementally deployed over existing wireless network infrastructure. With extensive simulations in NS3 and demo implementation, we prove the feasibility and effectiveness of both the framework and the scheduling algorithm. Kang Chen 0002, Jim Martin 0001, Kuang-Ching Wang, Hongxin Hu |
ICCCN | 5 |
| 2018 | CrescendoNet: A New Deep Convolutional Neural Network with Ensemble BehaviorabstractWe introduce a new deep convolutional neural network, CrescendoNet, by stacking simple building blocks without residual connections. Each Crescendo block contains independent convolution paths with increased depths. The numbers of convolution layers and parameters are only increased linearly in Crescendo blocks. In experiments, CrescendoNet with only 15 layers outperforms almost all networks without residual connections on benchmark datasets, CIFAR10, CIFAR100, and SVHN. Given sufficient amount of data as in SVHN dataset, CrescendoNet with 15 layers and 4.1M parameters can match the performance of DenseNet-BC with 250 layers and 15.3M parameters. CrescendoNet provides a new way to construct high performance deep convolutional neural networks with simple network architecture. Moreover, by investigating a various combination of subnetworks in CrescendoNet, we note that the high performance of CrescendoNet may come from its implicit ensemble behavior, which gives CrescendoNet an anytime classification property. Furthermore, the independence between paths in CrescendoNet allows us to introduce a new path-wise training procedure, which can reduce the memory needed for training. Nishant Vishwamitra, Hongxin Hu, Feng Luo 0001 |
ICMLA | 3 |
| 2018 | Grus: Enabling Latency SLOs for GPU-Accelerated NFV SystemsabstractGraphics Processing Unit (GPU) has been recently exploited as a hardware accelerator to improve the performance of Network Function Virtualization (NFV). However, GPU-accelerated NFV systems suffer from significant latency variation when multiple network functions (NFs) are co-located in the same machine, which prevents operators from supporting latency Service Level Objectives (SLOs). Existing research efforts to address this problem can only guarantee a limited number of SLOs with very low resource utilization efficiency. In this paper, we present the Grus framework to support latency SLOs in GPU-accelerated NFV systems. Grus thoroughly analyzes the sources of latency variation and proposes three design principles: (1) dynamic batch size setting is needed to bound packet batching latency in CPU; (2) a reordering mechanism for data transfer over PCI-E is required to guarantee the stalling time; and (3) maximizing concurrency in GPU is necessary to avoid NF execution waiting time. Guided by the principles, Grus consists of two logical layers including an infrastructure layer and a scheduling layer. The infrastructure layer is equipped with an in-CPU Reorder-able Worker Pool that could adjust batching size and packet transfer order, and in-GPU Controllable Concurrent Executors to provide maximized concurrency. The scheduling layer runs a heuristic algorithm to perform accurate and fast scheduling to guarantee SLOs based on our prediction models. We have implemented a prototype of Grus. Extensive evaluations demonstrate that Grus can significantly reduce latency variation and satisfy 4.5 × more SLO terms than state-of-the-art solutions. Zhilong Zheng, Jun Bi, Haiping Wang 0002, Chen Sun 0005, Heng Yu 0005, Hongxin Hu, Kai Gao 0001 |
ICNP | 6 |
| 2018 | OFM: Optimized Flow Migration for NFV Elasticity ControlabstractNetwork Function Virtualization (NFV) together with Software Defined Networking (SDN) offers the potential for enhancing service delivery flexibility and reducing overall costs. Based on the capability of dynamic creation and destruction of network function (NF) instances, NFV provides great elasticity in NF control, such as NF scaling out, scaling in, load balancing, etc. To realize NFV elasticity control, network traffic flows need to be redistributed across NF instances. However, deciding which flows are suitable for migration is a critical problem for efficient NFV elasticity control. In this paper, we propose to build an innovative flow migration controller, OFM Controller, to achieve optimized flow migration for NFV elasticity control. We identify the trigger conditions and control goals for different situations, and carefully design models and algorithms to address three major challenges including buffer overflow avoidance, migration cost calculation, and effective flow selection for migration. We implement the OFM Controller on top of NFV and SDN environments. Our evaluation results show that OFM Controller is efficient to support optimized flow migration in NFV elasticity control. Chen Sun 0005, Jun Bi, Zili Meng, Hongxin Hu |
IWQoS | 5 |
| 2018 | Enhancing Security Education Through Designing SDN Security Labs in CloudLababstractSoftware-Defined Networking (SDN) represents a major shift from ossified hardware-based networks to programmable software-based networks. It introduces significant granularity, visibility, and flexibility into networking, but at the same time brings new security challenges. Although the research community is making progress in addressing both the opportunities in SDN and the accompanying security challenges, very few educational materials have been designed to incorporate the latest research results and engage students in learning about SDN security. In this paper, we presents our newly designed SDN security education materials, which can be used to meet the ever-increasing demand for high quality cybersecurity professionals with expertise in SDN security. The designed security education materials incorporate the latest research results in SDN security and are integrated into CloudLab, an open cloud platform, for effective hands-on learning. Through a user study, we demonstrate that students have a better understanding of SDN security after participating in these well-designed CloudLab-based security labs, and they also acquired strong research interests in SDN security. Younghee Park, Hongxin Hu, Xiaohong Yuan, Hongda Li 0002 |
SIGCSE | 2 |
| 2018 | Enabling NFV Elasticity Control With Optimized Flow MigrationabstractNetwork function virtualization (NFV) together with software defined networking (SDN) offers the potential for enhancing service delivery flexibility and reducing overall costs. Based on the capability of dynamic creation and destruction of network function (NF) instances, NFV provides great elasticity in NF control, such as NF scaling out, scaling in, and load balancing. To realize NFV elasticity control, network traffic flows need to be redistributed across NF instances. However, deciding which flows are suitable for migration is a critical problem for efficient NFV elasticity control. In this paper, we propose to build an innovative flow migration controller, OFM controller, to achieve optimized flow migration for NFV elasticity control. We identify the trigger conditions and control goals for different situations, and carefully design models and algorithms to address three major challenges including buffer overflow avoidance, migration cost calculation, and effective flow selection for migration. We implement the OFM controller on top of NFV and SDN environments. Our evaluation results show that OFM controller is efficient to support optimized flow migration in NFV elasticity control. Chen Sun 0005, Jun Bi, Zili Meng, Tong Yang 0003, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 6 |
| 2017 | On the Safety and Efficiency of Virtual Firewall Elasticity Control
Juan Deng, Hongda Li 0002, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao 0001, Wonkyu Han |
NDSS | 3 |
| 2017 | Poster: On the Safety and Efficiency of Virtual Firewall Elasticity ControlabstractFirewalls have been typically used to enforce network access control. Network Functions Virtualization (NFV) envisions to implement firewall function as software instance (a.k.a virtual firewall). Virtual firewall provides great flexibility and elasticity, which are necessary to protect virtualized environments. In this poster, we propose an innovative virtual firewall controller, VFW Controller, which enables safe, efficient and cost-effective virtual firewall elasticity control. In addition, we implement the core components of VFW Controller on top of NFV and SDN environments. Our experimental results demonstrate that VFW Controller is efficient to provide safe elasticity control of virtual firewalls. Hongda Li 0002, Juan Deng, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao 0001, Wonkyu Han |
SACMAT | 3 |
| 2017 | Towards PII-based Multiparty Access Control for Photo Sharing in Online Social NetworksabstractThe privacy control models of current Online Social Networks (OSNs) are biased towards the content owners' policy settings. Additionally, those privacy policy settings are too coarse-grained to allow users to control access to individual portions of information that is related to them. Especially, in a shared photo in OSNs, there can exist multiple Personally Identifiable Information (PII) items belonging to a user appearing in the photo, which can compromise the privacy of the user if viewed by others. However, current OSNs do not provide users any means to control access to their individual PII items. As a result, there exists a gap between the level of control that current OSNs can provide to their users and the privacy expectations of the users. In this paper, we propose an approach to facilitate collaborative control of individual PII items for photo sharing over OSNs, where we shift our focus from entire photo level control to the control of individual PII items within shared photos. We formulate a PII-based multiparty access control model to fulfill the need for collaborative access control of PII items, along with a policy specification scheme and a policy enforcement mechanism. We also discuss a proof-of-concept prototype of our approach as part of an application in Facebook and provide system evaluation and usability study of our methodology. Nishant Vishwamitra, Yifang Li, Hongxin Hu, Kelly Caine, Gail-Joon Ahn |
SACMAT | 4 |
| 2017 | NFP: Enabling Network Function Parallelism in NFVabstractSoftware-based sequential service chains in Network Function Virtualization (NFV) could introduce significant performance overhead. Current acceleration efforts for NFV mainly target on optimizing each component of the sequential service chain. However, based on the statistics from real world enterprise networks, we observe that 53.8% network function (NF) pairs can work in parallel. In particular, 41.5% NF pairs can be parallelized without causing extra resource overhead. In this paper, we present NFP, a high performance framework, that innovatively enables network function parallelism to improve NFV performance. NFP consists of three logical components. First, NFP provides a policy specification scheme for operators to intuitively describe sequential or parallel NF chaining intents. Second, NFP orchestrator intelligently identifies NF dependency and automatically compiles the policies into high performance service graphs. Third, NFP infrastructure performs light-weight packet copying, distributed parallel packet delivery, and load-balanced merging of packet copies to support NF parallelism. We implement an NFP prototype based on DPDK in Linux containers. Our evaluation results show that NFP achieves significant latency reduction for real world service chains. Chen Sun 0005, Jun Bi, Zhilong Zheng, Heng Yu 0005, Hongxin Hu |
SIGCOMM | 5 |
| 2017 | ThinGs In a Fog: System Illustration with Connected VehiclesabstractThis paper presents ThinGs In a Fog (TGIF)- a system designed to support interdisciplinary research that fall under the broad context of the Internet of Things. The framework is based on an Edge Computing system design that distributes application processing to system compute nodes leveraging geographic compute location diversity of a Cloud-to-the-edge to support machine-to- machine interactions that potentially have real- time constraints. To provide further insight, we focus on Connected Vehicle as an exemplar application domain. This paper provides a summary of work-to-date, including results from a small prototype of the system deployed at Clemson University. We illustrate the system be presenting work-to-date on the design, implementation and evaluation of a Queue Warning which is an application that has been studied thoroughly by the transportation community. This particular application is nicely suited for illustrating the additional benefits and complexities associated with implementing well understood applications in emerging distributed computing environments expected to be supported by the IoT. Anjan Rayamajhi, Manveen Kaur, Mashrur Chowdhury, Hongxin Hu, Jerome McClendon, Kuang-Ching Wang, Abhimanyu Gosain, Jim Martin 0001 |
VTC Spring | 6 |
| 2017 | HYPER: A Hybrid High-Performance Framework for Network Function VirtualizationabstractNetwork function virtualization (NFV) offers the potential for both enhancing service delivery flexibility and reducing overall costs by virtualizing network functions that are traditionally implemented in dedicated hardware. However, the flexibility of NFV comes with considerable compromises since virtual machine carried functions could introduce significant performance overhead. In this paper, we present a novel high-performance framework called HYPER, which combines programmable hardware infrastructure and traditional software infrastructure in NFV to achieve both high performance and flexibility for supporting virtualized network functions (VNFs). In HYPER, we design a mediator layer to hide underlying infrastructure heterogeneity from the NFV orchestrator to simplify VNF management. In addition, we design a SLA-aware service chaining algorithm in HYPER to leverage the benefits of the hybrid infrastructure to fulfill both functional and performance requirements from service subscribers (or tenants). To optimize resource utilization efficiency, we also introduce a performance-aware VNF placement algorithm in HYPER, which accommodates both resource and performance requirements in placing VNFs. We implement HYPER in a testbed based on OpenStack and ONetCard. Experimental results show that HYPER reduces the forwarding latency of a service chain by 40% to 67% compared with data plane development kit -based implementation, while maintaining the flexibility of VNF management. Chen Sun 0005, Jun Bi, Zhilong Zheng, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 4 |
| 2017 | Effectiveness and Users' Experience of Obfuscation as a Privacy-Enhancing Technology for Sharing PhotosabstractCurrent collaborative photo privacy protection solutions can be categorized into two approaches: controlling the recipient, which restricts certain viewers' access to the photo, and controlling the content, which protects all or part of the photo from being viewed. Focusing on the latter approach, we introduce privacy-enhancing obfuscations for photos and conduct an online experiment with 271 participants to evaluate their effectiveness against human recognition and how they affect the viewing experience. Results indicate the two most common obfuscations, blurring and pixelating, are ineffective. On the other hand, inpainting, which removes an object or person entirely, and avatar, which replaces content with a graphical representation are effective. From a viewer experience perspective, blurring, pixelating, inpainting, and avatar are preferable. Based on these results, we suggest inpainting and avatar may be useful as privacy-enhancing technologies for photos, because they are both effective at increasing privacy for elements of a photo and provide a good viewer experience. Yifang Li, Nishant Vishwamitra, Bart P. Knijnenburg, Hongxin Hu, Kelly Caine |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2017 | CHAOS: An SDN-Based Moving Target Defense SystemabstractMoving target defense (MTD) has provided a dynamic and proactive network defense to reduce or move the attack surface that is available for exploitation. However, traditional network is difficult to realize dynamic and active security defense effectively and comprehensively. Software-defined networking (SDN) points out a brand-new path for building dynamic and proactive defense system. In this paper, we propose CHAOS, an SDN-based MTD system. Utilizing the programmability and flexibility of SDN, CHAOS obfuscates the attack surface including host mutation obfuscation, ports obfuscation, and obfuscation based on decoy servers, thereby enhancing the unpredictability of the networking environment. We propose the Chaos Tower Obfuscation (CTO) method, which uses the Chaos Tower Structure (CTS) to depict the hierarchy of all the hosts in an intranet and define expected connection and unexpected connection. Moreover, we develop fast CTO algorithms to achieve a different degree of obfuscation for the hosts in each layer. We design and implement CHAOS as an application of SDN controller. Our approach makes it very easy to realize moving target defense in networks. Our experimental results show that a network protected by CHAOS is capable of decreasing the percentage of information disclosure effectively to guarantee the normal flow of traffic. Huanguo Zhang, Juan Wang 0006, Daochen Zha, Hongxin Hu, Fei Yan 0008, Bo Zhao 0023 |
Secur. Commun. Networks | 7 |
| 2017 | SDPA: Toward a Stateful Data Plane in Software-Defined NetworkingabstractAs the prevailing technique of software-defined networking (SDN), open flow introduces significant programmability, granularity, and flexibility for many network applications to effectively manage and process network flows. However, open flow only provides a simple “match-action” paradigm and lacks the functionality of stateful forwarding for the SDN data plane, which limits its ability to support advanced network applications. Heavily relying on SDN controllers for all state maintenance incurs both scalability and performance issues. In this paper, we propose a novel stateful data plane architecture (SDPA) for the SDN data plane. A co-processing unit, forwarding processor (FP), is designed for SDN switches to manage state information through new instructions and state tables. We design and implement an extended open flow protocol to support the communication between the controller and FP. To demonstrate the practicality and feasibility of our approach, we implement both software and hardware prototypes of SDPA switches, and develop a sample network function chain with stateful firewall, domain name system (DNS) reflection defense, and heavy hitter detection applications in one SDPA-based switch. Experimental results show that the SDPA architecture can effectively improve the forwarding efficiency with manageable processing overhead for those applications that need stateful forwarding in SDN-based networks. Chen Sun 0005, Jun Bi, Haoxian Chen 0001, Hongxin Hu, Zhilong Zheng, Shuyong Zhu, Chenghui Wu |
IEEE/ACM Trans. Netw. | 4 |
| 2016 | Cyberbullying Detection with a Pronunciation Based Convolutional Neural NetworkabstractCyberbullying can have a deep and long lasting impact on its victims, who are often adolescents. Accurately detecting cyberbullying helps prevent it. However, the noise and errors in social media posts and messages make detecting cyberbullying very challenging. In this paper, we propose a novel pronunciation based convolutional neural network (PCNN) to address this challenge. Upon observing that the pronunciation of misspelled words in informal online conversations is often unchanged, we used the phoneme codes of the text as the features for a convolutional neural network. This procedure corrects spelling errors that did not alter the pronunciation, thereby alleviating the problem of noise and bullying data sparsity. To overcome class imbalance, a common problem in cyberbullying datasets, we implement three techniques that include threshold-moving, cost function adjusting, and a hybrid solution in our model. We evaluate the performance of our models using two cyberbullying datasets collected from Twitter and Formspring.me. The results of our experiment show that PCNN can achieve improved recall and precision compared to baseline convolutional neural networks. Jonathan Tong, Nishant Vishwamitra, Elizabeth Whittaker, Joseph P. Mazer, Robin M. Kowalski, Hongxin Hu, Feng Luo 0001, Edward Dillon 0002 |
ICMLA | 7 |
| 2016 | NeSMA: Enabling network-level state-aware applications in SDNabstractAs the de facto data plane technique of Software-Defined Networking (SDN), OpenFlow introduces significant programmability to enable innovative network applications. However, the simple OpenFlow data plane only maintains flow-level counters and lacks an efficient mechanism to manage network-level states, which limits its support for advanced state-aware applications. Regularly pulling whole state information from the data plane to the controller might incur untimely response to important network-level states such as CPU exhaustion, switch overload, etc and cause unnecessary traffic. To address above challenges, we introduce a novel Network-level State Management Architecture (NeSMA) to efficiently support advanced network-level state-aware applications by exploiting the opportunity of SDN central control. The data plane could be configured to check state regularly and report to the controller when triggered by state transitions. We design both sequential and parallel composition methods to deal with complex network-level states in NeSMA. To demonstrate the feasibility of our approach, we implement a software prototype of NeSMA, based on which we develop a data-center flow scheduling application. Experimental results show that NeSMA can process network-level states with low network resource consumption and high scalability without compromising packet forwarding efficiency. Chen Sun 0005, Jun Bi, Hongxin Hu, Zhilong Zheng |
ICNP | 3 |
| 2016 | HetSDN: Exploiting SDN for intelligent network usage in heterogeneous wireless networksabstractMobile devices nowadays can find multiple wireless networks, such as WiFi, 4G/LTE and relay through devices. These networks have different characteristics in terms of coverage, data rate, and price. Meanwhile, mobile applications (and even different TCP/UDP connections) often have diverse and time-variant network needs. Thus, to better use all wireless network resources, it would be ideal to enable a TCP/UDP connection to 1) select the most appropriate network dynamically and 2) migrate between networks transparently. However, existing methods fail to provide both functions in a systematic and efficient way at the TCP/UDP connection level. In this paper, we adopt Software-Defined Networking (SDN) to realize such a feature. We use the features of SDN to realize intelligent network selection that is adaptive to time-variant application needs, network availability, and scheduling commands. To support transparent migration, an intelligent home agent (HA) is designed with the SDN to anchor packets from the mobile device. It can intelligently determine which wireless network a TCP/UDP connection is running over. Finally, our implementation demonstrates the effectiveness and efficiency of the proposed system. Kang Chen 0002, Ryan Izard, Hongxin Hu, Kuang-Ching Wang, Jim Martin 0001, Juan Deng |
IWQoS | 3 |
| 2016 | State-aware Network Access Management for Software-Defined NetworksabstractOpenFlow, as the prevailing technique for Software-Defined Networks (SDNs), introduces significant programmability, granularity, and flexibility for many network applications to effectively manage and process network flows. However, because OpenFlow attempts to keep the SDN data plane simple and efficient, it focuses solely on L2/L3 network transport and consequently lacks the fundamental ability of stateful forwarding for the data plane. Also, OpenFlow provides a very limited access to connection-level information in the SDN controller. In particular, for any network access management applications on SDNs that require comprehensive network state information, these inherent limitations of OpenFlow pose significant challenges in supporting network services. To address these challenges, we propose an innovative connection tracking framework called STATEMON that introduces a global state-awareness to provide better access control in SDNs. STATEMON is based on a lightweight extension of OpenFlow for programming the stateful SDN data plane, while keeping the underlying network devices as simple as possible. To demonstrate the practicality and feasibility of STATEMON, we implement and evaluate a stateful network firewall and port knocking applications for SDNs, using the APIs provided by STATEMON. Our evaluations show that STATEMON introduces minimal message exchanges for monitoring active connections in SDNs with manageable overhead (3.27% throughput degradation). Wonkyu Han, Hongxin Hu, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn, Kuang-Ching Wang, Juan Deng |
SACMAT | 2 |
| 2016 | Enabling Dynamic Access Control for Controller Applications in Software-Defined NetworksabstractRecent findings have shown that network and system attacks in Software-Defined Networks (SDNs) have been caused by malicious network applications that misuse APIs in an SDN controller. Such attacks can both crash the controller and change the internal data structure in the controller, causing serious damage to the infrastructure of SDN-based networks. To address this critical security issue, we introduce a security framework called AEGIS to prevent controller APIs from being misused by malicious network applications. Through the run-time verification of API calls, AEGIS performs a fine-grained access control for important controller APIs that can be misused by malicious applications. The usage of API calls is verified in real time by sophisticated security access rules that are defined based on the relationships between applications and data in the SDN controller. We also present a prototypical implementation of AEGIS and demonstrate its effectiveness and efficiency by performing six different controller attacks including new attacks we have recently discovered. Hitesh Padekar, Younghee Park, Hongxin Hu, Sang-Yoon Chang |
SACMAT | 3 |
| 2016 | SLA-NFV: an SLA-aware High Performance Framework for Network Function VirtualizationabstractWe propose SLA-NFV, a Service Level Agreement (SLA) aware framework, for building high-performance NFV, focusing on fulfilling SLAs of service subscribers (or tenants). SLA-NFV leverages a hybrid infrastructure with both software and programmable hardware to enhance NFV’s capability with respect to various SLAs. Evaluations show that a hybrid service chain could reduce latency by up to 60% compared with a pure soft- ware service chain. Chen Sun 0005, Jun Bi, Zhilong Zheng, Hongxin Hu |
SIGCOMM | 4 |
| 2016 | TripleMon: A multi-layer security framework for mediating inter-process communication on AndroidabstractAs smartphones have become an indispensable part of daily life, mobile users are increasingly relying on them to process personal information with feature-rich applications. This situation requires robust security mechanisms for protecting sensitive applications and data on mobile devices. Android, as one the most popular smartphone operating systems, provides two core security mechanisms, application sandboxing and a permission system. However, recent studies show that these mechanisms are vulnerable to be passed by a variety of attacks. In this paper, we argue for the need of designing and implementing more comprehensive security mechanisms for Android. We realize that mediating Inter-Process Communication (IPC) channels used by Android applications can mitigate prominent attacks effectively and efficiently. Based on this observation, we propose a practical multi-layer security framework called TripleMon to support policy-based mediation on Android IPC. We also discuss and evaluate a proof-of-concept prototype of TripleMon along with the experimental results derived from real malware samples and synthetic attacks. Yiming Jing, Gail-Joon Ahn, Hongxin Hu, Haehyun Cho, Ziming Zhao 0001 |
J. Comput. Secur. | 3 |
| 2015 | SDPA: Enhancing Stateful Forwarding for Software-Defined NetworkingabstractAs the prevailing technique of Software-Defined Networking (SDN), OpenFlow introduces significant programmability, granularity and flexibility for many network applications to effectively manage and process network flows. However, OpenFlow only provides a simple "match-action" paradigm and lacks the function of stateful forwarding for SDN data plane, which limits it to support advanced network applications. Heavily relying on SDN controllers for all state maintenance incurs both scalability and performance issues. In this paper, we propose a novel Stateful Data Plane Architecture (SDPA) for SDN data plane. A co-processing unit, Forwarding Processor (FP), is designed for SDN switches to manage state information through new instructions and state tables. We design and implement an extended OpenFlow protocol to implement the communication between the controller and FP. To demonstrate the practicality and feasibility of our approach, we implement both software and hardware prototypes of SDPA switches, and develop a sample network function chain with stateful firewall, DNS reflection attack defense and NAT applications in one SDPA-based switch. Experimental results show that the SDPA architecture can effectively improve the forwarding efficiency with manageable processing overhead for those applications that need stateful forwarding in SDN-based networks. Shuyong Zhu, Jun Bi, Chen Sun 0005, Chenhui Wu, Hongxin Hu |
ICNP | 5 |
| 2015 | Towards Automated Risk Assessment and Mitigation of Mobile ApplicationsabstractMobile operating systems, such as Apple's iOS and Google's Android, have supported a ballooning market of feature-rich mobile applications. However, helping users understand and mitigate security risks of mobile applications is still an ongoing challenge. While recent work has developed various techniques to reveal suspicious behaviors of mobile applications, there exists little work to answer the following question: are those behaviors necessarily inappropriate? In this paper, we seek an approach to cope with such a challenge and present a continuous and automated risk assessment framework called RiskMon that uses machine-learned ranking to assess risks incurred by users' mobile applications, especially Android applications. RiskMon combines users' coarse expectations and runtime behaviors of trusted applications to generate a risk assessment baseline that captures appropriate behaviors of applications. With the baseline, RiskMon assigns a risk score on every access attempt on sensitive information and ranks applications by their cumulative risk scores. Furthermore, we demonstrate how RiskMon supports risk mitigation with automated permission revocation. We also discuss a proof-of-concept implementation of RiskMon as an extension of the Android mobile platform and provide both system evaluation and usability study of our methodology. Yiming Jing, Gail-Joon Ahn, Ziming Zhao 0001, Hongxin Hu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2015 | Picture Gesture Authentication: Empirical Analysis, Automated Attacks, and Scheme EvaluationabstractPicture gesture authentication has been recently introduced as an alternative login experience to text-based password on touch-screen devices. In particular, the newly on market Microsoft Windows 8™ operating system adopts such an alternative authentication to complement its traditional text-based authentication. We present an empirical analysis of picture gesture authentication on more than 10,000 picture passwords collected from more than 800 subjects through online user studies. Based on the findings of our user studies, we propose a novel attack framework that is capable of cracking passwords on previously unseen pictures in a picture gesture authentication system. Our approach is based on the concept of selection function that models users’ thought processes in selecting picture passwords. Our evaluation results show the proposed approach could crack a considerable portion of picture passwords under different settings. Based on the empirical analysis and attack results, we comparatively evaluate picture gesture authentication using a set of criteria for a better understanding of its advantages and limitations. Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2014 | Morpheus: automatically generating heuristics to detect Android emulatorsabstractEmulator-based dynamic analysis has been widely deployed in Android application stores. While it has been proven effective in vetting applications on a large scale, it can be detected and evaded by recent Android malware strains that carry detection heuristics. Using such heuristics, an application can check the presence or contents of certain artifacts and infer the presence of emulators. However, there exists little work that systematically discovers those heuristics that would be eventually helpful to prevent malicious applications from bypassing emulator-based analysis. To cope with this challenge, we propose a framework called Morpheus that automatically generates such heuristics. Morpheus leverages our insight that an effective detection heuristic must exploit discrepancies observable by an application. To this end, Morpheus analyzes the application sandbox and retrieves observable artifacts from both Android emulators and real devices. Afterwards, Morpheus further analyzes the retrieved artifacts to extract and rank detection heuristics. The evaluation of our proof-of-concept implementation of Morpheus reveals more than 10,000 novel detection heuristics that can be utilized to detect existing emulator-based malware analysis tools. We also discuss the discrepancies in Android emulators and potential countermeasures. Yiming Jing, Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu |
ACSAC | 4 |
| 2014 | POSTER: An E2E Trusted Cloud InfrastructureabstractIn this paper, a framework of end to end (E2E) trusted cloud infrastructure is proposed. On one end of the cloud provider, the trusted chain is extended to VMM and VM by trusted measurement and remote attestation, which can assure the trust of VMM and VM. On another end of the cloud terminal, the trusted mechanism is used to protect the terminal security. For the trust of cloud network, trusted network connect (TNC) is leveraged to protect the security of communication between the loud provider and the cloud terminal. The E2E trusted cloud infrastructure provides an E2E trusted protection for cloud computing. In addition, it can support the Chinese cryptographic algorithm (SMx) based on TPM 2.0. Juan Wang 0006, Bo Zhao 0023, Huanguo Zhang, Fei Yan 0008, Fajiang Yu, Hongxin Hu |
CCS | 7 |
| 2014 | RiskMon: continuous and automated risk assessment of mobile applicationsabstractMobile operating systems, such as Apple's iOS and Google's Android, have supported a ballooning market of feature-rich mobile applications. However, helping users understand security risks of mobile applications is still an ongoing challenge. While recent work has developed various techniques to reveal suspicious behaviors of mobile applications, there exists little work to answer the following question: are those behaviors necessarily inappropriate? In this paper, we seek an approach to cope with such a challenge and present a continuous and automated risk assessment framework called RiskMon that uses machine-learned ranking to assess risks incurred by users' mobile applications, especially Android applications. RiskMon combines users' coarse expectations and runtime behaviors of trusted applications to generate a risk assessment baseline that captures appropriate behaviors of applications. With the baseline, RiskMon assigns a risk score on every access attempt on sensitive information and ranks applications by their cumulative risk scores. We also discuss a proof-of-concept implementation of RiskMon as an extension of the Android mobile platform and provide both system evaluation and usability study of our methodology. Yiming Jing, Gail-Joon Ahn, Ziming Zhao 0001, Hongxin Hu |
CODASPY | 4 |
| 2014 | Defensive maneuver cyber platform modeling with Stochastic Petri NetsabstractDistributed and parallel applications are critical information technology systems in multiple industries, including academia, military, government, financial, medical, and transportation. These applications present target rich environments for malicious attackers seeking to disrupt the confidentiali William Clay Moody, Hongxin Hu, Amy W. Apon |
CollaborateCom | 2 |
| 2014 | LPM: Layered Policy Management for Software-Defined Networks
Wonkyu Han, Hongxin Hu, Gail-Joon Ahn |
DBSec | 2 |
| 2014 | Game theoretic analysis of multiparty access control in online social networksabstractExisting online social networks (OSNs) only allow a single user to restrict access to her/his data but cannot provide any mechanism to enforce privacy concerns over data associated with multiple users. This situation leaves privacy conflicts largely unresolved and leads to the potential disclosure of users' sensitive information. To address such an issue, a MultiParty Access Control (MPAC) model was recently proposed, including a systematic approach to identify and resolve privacy conflicts for collaborative data sharing in OSNs. In this paper, we take another step to further study the problem of analyzing the strategic behavior of rational controllers in multiparty access control, where each controller aims to maximize her/his own benefit by adjusting her/his privacy setting in collaborative data sharing in OSNs. We first formulate this problem as a multiparty control game and show the existence of unique Nash Equilibrium (NE) which is critical because at an NE, no controller has any incentive to change her/his privacy setting. We then present algorithms to compute the NE and prove that the system can converge to the NE in only a few iterations. A numerical analysis is also provided for different scenarios that illustrate the interplay of controllers in the multiparty control game. In addition, we conduct user studies of the multiparty control game to explore the gap between game theoretic approaches and real human behaviors. Hongxin Hu, Gail-Joon Ahn, Ziming Zhao 0001, Dejun Yang |
SACMAT | 1 |
| 2014 | Secure and efficient random functions with variable-length output
Yan Zhu 0010, Di Ma 0001, Changjun Hu, Gail-Joon Ahn, Hongxin Hu |
J. Netw. Comput. Appl. | 5 |
| 2013 | On the Security of Picture Gesture Authentication
Ziming Zhao 0001, Gail-Joon Ahn, Jeong-Jin Seo, Hongxin Hu |
USENIX Security Symposium | 4 |
| 2013 | Discovery and Resolution of Anomalies in Web Access Control PoliciesabstractEmerging computing technologies such as web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing web access control policies are often error-prone due to the lack of effective analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly analysis approach for web access control policies, focusing on extensible access control markup language policy. We introduce a policy-based segmentation technique to accurately identify policy anomalies and derive effective anomaly resolutions, along with an intuitive visualization representation of analysis results. We also discuss a proof-of-concept implementation of our method called XAnalyzer and demonstrate how our approach can efficiently discover and resolve policy anomalies. Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2013 | Role-Based Cryptosystem: A New Cryptographic RBAC System Based on Role-Key HierarchyabstractEven though role-based access control (RBAC) can tremendously help us to minimize the complexity in administering users, it still needs to realize the notion of roles at the resource level. In this paper, we propose a practical cryptographic RBAC model, called role-key hierarchy model, to support various security features, including signature, identification, and encryption on role-key hierarchy. In addition, several advanced features, such as role or user revocation, tracing, and anonymity, are implemented as well. With the help of rich algebraic structure of elliptic curves, we introduce a unified and complete construction of role-based cryptosystem to verify the rationality and validity of our proposed model. In addition, a proof-of-concept prototype implementation and performance evaluation is discussed to demonstrate the feasibility and efficiency of our mechanisms. Yan Zhu 0010, Gail-Joon Ahn, Hongxin Hu, Di Ma 0001, Shan-Biao Wang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2013 | Multiparty Access Control for Online Social Networks: Model and MechanismsabstractOnline social networks (OSNs) have experienced tremendous growth in recent years and become a de facto portal for hundreds of millions of Internet users. These OSNs offer attractive means for digital social interactions and information sharing, but also raise a number of security and privacy issues. While OSNs allow users to restrict access to shared data, they currently do not provide any mechanism to enforce privacy concerns over data associated with multiple users. To this end, we propose an approach to enable the protection of shared data associated with multiple users in OSNs. We formulate an access control model to capture the essence of multiparty authorization requirements, along with a multiparty policy specification scheme and a policy enforcement mechanism. Besides, we present a logical representation of our access control model that allows us to leverage the features of existing logic solvers to perform various analysis tasks on our model. We also discuss a proof-of-concept prototype of our approach as part of an application in Facebook and provide usability study and system evaluation of our method. Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2013 | Dynamic Audit Services for Outsourced Storages in CloudsabstractIn this paper, we propose a dynamic audit service for verifying the integrity of an untrusted and outsourced storage. Our audit service is constructed based on the techniques, fragment structure, random sampling, and index-hash table, supporting provable updates to outsourced data and timely anomaly detection. In addition, we propose a method based on probabilistic query and periodic verification for improving the performance of audit services. Our experimental results not only validate the effectiveness of our approaches, but also show our audit system verifies the integrity with lower computation overhead and requiring less extra storage for audit metadata. Yan Zhu 0010, Gail-Joon Ahn, Hongxin Hu, Stephen S. Yau, Ho G. An, Changjun Hu |
IEEE Trans. Serv. Comput. | 3 |
| 2012 | Comparison-based encryption for fine-grained access control in cloudsabstractAccess control is one of the most important security mechanisms in cloud computing. However, there has been little work that explores various comparison-based constraints for regulating data access in clouds. In this paper, we present an innovative comparison-based encryption scheme to facilitate fine-grained access control in cloud computing. By means of forward/backward derivation functions, we introduce comparison relation into attribute-based encryption to implement various range constraints on integer attributes, such as temporal and level attributes. Then, we present a new cryptosystem with dual decryption to reduce computational overheads on cloud clients, where the majority of decryption operations are executed in cloud servers. We also prove the security strength of our proposed scheme, and our experiment results demonstrate the efficiency of our methodology. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Mengyang Yu, Hong-Jia Zhao |
CODASPY | 2 |
| 2012 | Secure sharing of electronic health records in cloudsabstractIn modern healthcare environments, healthcare providers are more willing to shift their electronic medical record systems to clouds. Instead of building and maintaining dedicated data centers, this paradigm enables to achieve lower operational cost and better interoperability with other healthcare p Gail-Joon Ahn, Hongxin Hu |
CollaborateCom | 3 |
| 2012 | SocialImpact: Systematic Analysis of Underground Social Dynamics
Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu, Deepinder Mahi |
ESORICS | 3 |
| 2012 | Enabling Collaborative data sharing in Google+abstractMost of existing online social networks, such as Facebook and Twitter, are designed to bias towards information disclosure to a large audience. Google recently launched a new social network platform, Google+. By introducing the notion of `circles', Google+ enables users to selectively share data with specific groups within their personal network, rather than sharing with all of their social connections at once. Although Google+ can help mitigate the gap between the individuals' expectations and their actual privacy settings, it still only allows a single user to restrict access to her/his data but cannot provide any mechanism to enforce privacy concerns over data associated with multiple users. In this paper, we propose an approach to facilitate collaborative privacy management of shared data in Google+. We extend and formulate a multiparty access control model, named MPAC+, to capture the essence of collaborative authorization requirements in Google+, along with a multiparty policy specification scheme and a policy enforcement mechanism. We also discuss a proof-of-concept prototype of our approach and describe system evaluation and usability study of our prototype. Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
GLOBECOM | 1 |
| 2012 | Secure and efficient constructions of hash, MAC and PRF for mobile devicesabstractNumerous cryptographic techniques have been developed to be used on mobile devices for various security and privacy protections. However, these cryptographic primitives, working under different mathematical assumptions, tend to become more and more complex and intricate, which makes it increasingly more difficult for proper implementation and management. Thus, it is desired to simplify management and improve efficiency by means of designing a general function family to meet a variety of security requirements. In this paper, we present such a family of square functions, including SqHash, SqMAC and SqPRF, based on a specially truncated function (MSB or LSB). We further improve the efficiency of these algorithms by using “circular convolution with carry bits” which makes parallel processing possible. We prove the security of these functions based on the privacy in hidden number problem and hard-core predicate of one-way function. We also show that the proposed schemes achieve better performance with a complexity reduction from O(n2) to O(kn/w) for n-bit message, k-bit output and w-bit word size. Yan Zhu 0010, Shan-Biao Wang, Di Ma 0001, Hongxin Hu, Gail-Joon Ahn |
GLOBECOM | 4 |
| 2012 | Towards temporal access control in cloud computingabstractAbstract—Access control is one of the most important security mechanisms in cloud computing. Attribute-based access control provides a flexible approach that allows data owners to integrate data access policies within the encrypted data. However, little work has been done to explore temporal attributes in specifying and enforcing the data owner’s policy and the data user’s privileges in cloud-based environments. In this paper, we present an efficient temporal access control encryption scheme for cloud services with the help of crypto-graphic integer comparisons and a proxy-based re-encryption mechanism on the current time. We also provide a dual comparative expression of integer ranges to extend the power of attribute expression for implementing various temporal constraints. We prove the security strength of the proposed scheme and our experimental results not only validate the effectiveness of our scheme, but also show that the proposed integer comparison scheme performs significantly better than previous bitwise comparison scheme. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Dijiang Huang, Shan-Biao Wang |
INFOCOM | 2 |
| 2012 | Efficient construction of provably secure steganography under ordinary covert channels
Yan Zhu 0010, Mengyang Yu, Hongxin Hu, Gail-Joon Ahn, Hong-Jia Zhao |
Sci. China Inf. Sci. | 3 |
| 2012 | Secure Collaborative Integrity Verification for Hybrid Cloud EnvironmentsabstractA hybrid cloud is a cloud computing environment in which an organization provides and manages some internal resources and has others provided externally. However, this new environment could bring irretrievable losses to the clients due to a lack of integrity verification mechanism for distributed data outsourcing. To support scalable service and data migration, in this paper we address the construction of a collaborative integrity verification mechanism in hybrid clouds where we consider the existence of multiple cloud service providers to collaboratively store and maintain the clients' data. We propose a collaborative provable data possession scheme adopting the techniques of homomorphic verifiable responses and hash index hierarchy. In addition, we articulate the performance optimization mechanisms for our scheme and prove the security of our scheme based on multi-prover zero-knowledge proof system, which can satisfy the properties of completeness, knowledge soundness, and zero-knowledge. Our experiments also show that our proposed solution only incurs a small constant amount of communications overhead. Yan Zhu 0010, Shan-Biao Wang, Hongxin Hu, Gail-Joon Ahn, Di Ma 0001 |
Int. J. Cooperative Inf. Syst. | 3 |
| 2012 | Comprehensive two-level analysis of role-based delegation and revocation policies with UML and OCL
Karsten Sohr, Mirco Kuhlmann, Martin Gogolla, Hongxin Hu, Gail-Joon Ahn |
Inf. Softw. Technol. | 4 |
| 2012 | Efficient audit service outsourcing for data integrity in clouds
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Stephen S. Yau |
J. Syst. Softw. | 2 |
| 2012 | Detecting and Resolving Firewall Policy AnomaliesabstractThe advent of emerging computing technologies such as service-oriented architecture and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services. Firewalls are the most widely deployed security mechanism to ensure the security of private networks in most businesses and institutions. The effectiveness of security protection provided by a firewall mainly depends on the quality of policy configured in the firewall. Unfortunately, designing and managing firewall policies are often error prone due to the complex nature of firewall configurations as well as the lack of systematic analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly management framework for firewalls, adopting a rule-based segmentation technique to identify policy anomalies and derive effective anomaly resolutions. In particular, we articulate a grid-based representation technique, providing an intuitive cognitive sense about policy anomaly. We also discuss a proof-of-concept implementation of a visualization-based firewall policy analysis tool called Firewall Anomaly Management Environment (FAME). In addition, we demonstrate how efficiently our approach can discover and resolve anomalies in firewall policies through rigorous experiments. Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2012 | Remote Attestation with Domain-Based Integrity Model and Policy AnalysisabstractWe propose and implement an innovative remote attestation framework called DR@FT for efficiently measuring a target system based on an information flow-based integrity model. With this model, the high integrity processes of a system are first measured and verified, and these processes are then protected from accesses initiated by low integrity processes. Toward dynamic systems with frequently changed system states, our framework verifies the latest state changes of a target system instead of considering the entire system information. Our attestation evaluation adopts a graph-based method to represent integrity violations, and the graph-based policy analysis is further augmented with a ranked violation graph to support high semantic reasoning of attestation results. As a result, DR@FT provides efficient and effective attestation of a system's integrity status, and offers intuitive reasoning of attestation results for security administrators. Our experimental results demonstrate the feasibility and practicality of DR@FT. Wenjuan Xu, Xinwen Zhang, Hongxin Hu, Gail-Joon Ahn, Jean-Pierre Seifert |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2012 | Risk-Aware Mitigation for MANET Routing AttacksabstractMobile Ad hoc Networks (MANET) have been highly vulnerable to attacks due to the dynamic nature of its network infrastructure. Among these attacks, routing attacks have received considerable attention since it could cause the most devastating damage to MANET. Even though there exist several intrusion response techniques to mitigate such critical attacks, existing solutions typically attempt to isolate malicious nodes based on binary or naïve fuzzy response decisions. However, binary responses may result in the unexpected network partition, causing additional damages to the network infrastructure, and naïve fuzzy responses could lead to uncertainty in countering routing attacks in MANET. In this paper, we propose a risk-aware response mechanism to systematically cope with the identified routing attacks. Our risk-aware approach is based on an extended Dempster-Shafer mathematical theory of evidence introducing a notion of importance factors. In addition, our experiments demonstrate the effectiveness of our approach with the consideration of several performance metrics. Ziming Zhao 0001, Hongxin Hu, Gail-Joon Ahn |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2012 | Cooperative Provable Data Possession for Integrity Verification in Multicloud StorageabstractProvable data possession (PDP) is a technique for ensuring the integrity of data in storage outsourcing. In this paper, we address the construction of an efficient PDP scheme for distributed cloud storage to support the scalability of service and data migration, in which we consider the existence of multiple cloud service providers to cooperatively store and maintain the clients' data. We present a cooperative PDP (CPDP) scheme based on homomorphic verifiable response and hash index hierarchy. We prove the security of our scheme based on multiprover zero-knowledge proof system, which can satisfy completeness, knowledge soundness, and zero-knowledge properties. In addition, we articulate performance optimization mechanisms for our scheme, and in particular present an efficient method for selecting optimal parameter values to minimize the computation costs of clients and storage service providers. Our experiments show that our solution introduces lower computation and communication overheads in comparison with noncooperative approaches. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Mengyang Yu |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2011 | Detecting and resolving privacy conflicts for collaborative data sharing in online social networksabstractWe have seen tremendous growth in online social networks (OSNs) in recent years. These OSNs not only offer attractive means for virtual social interactions and information sharing, but also raise a number of security and privacy issues. Although OSNs allow a single user to govern access to her/his data, they currently do not provide any mechanism to enforce privacy concerns over data associated with multiple users, remaining privacy violations largely unresolved and leading to the potential disclosure of information that at least one user intended to keep private. In this paper, we propose an approach to enable collaborative privacy management of shared data in OSNs. In particular, we provide a systematic mechanism to identify and resolve privacy conflicts for collaborative data sharing. Our conflict resolution indicates a tradeoff between privacy protection and data sharing by quantifying privacy risk and sharing loss. We also discuss a proof-of-concept prototype implementation of our approach as part of an application in Facebook and provide system evaluation and usability study of our methodology. Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
ACSAC | 1 |
| 2011 | Poster: temporal attribute-based encryption in clouds
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Xiaorui Gong, Shimin Chen |
CCS | 2 |
| 2011 | Ontology-based policy anomaly management for autonomic computingabstractThe advent of emerging computing technologies such as service-oriented architecture and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services. Moreover, des Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
CollaborateCom | 1 |
| 2011 | Collaborative integrity verification in hybrid cloudsabstractA hybrid cloud is a cloud computing environment in which an organization provides and manages some internal resources and the others provided externally. However, this new environment could bring irretrievable losses to the clients due to a lack of integrity verification mechanism for distribute Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Yujing Han, Shimin Chen |
CollaborateCom | 2 |
| 2011 | Multiparty Authorization Framework for Data Sharing in Online Social Networks
Hongxin Hu, Gail-Joon Ahn |
DBSec | 1 |
| 2011 | Examining Social Dynamics for Countering Botnet AttacksabstractEven though promising results have been obtained from existing research on bots and associated command and control channels, there is little research in exploring the ways on how bots are created and distributed by adversaries. Consequently, innovative methods that help determine the linkage between the rogue programs and adversaries are imperative for mitigating and combating botnet attacks. Recent study discovers that rogue programs are sold in black markets in online social networks and adversaries use online social networks to coordinate attacks. Correlation of botnet attacks and activities in online underground social networks is crucial to tactically cope with net-centric threats. In this paper, we take the first step toward adversarial behavior identification by modeling social dynamics of underground adversarial communities and tracing the origin of certain malwares and attack events in underground communities. We also describe our evaluation to demonstrate the effectiveness of our approach. Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu |
GLOBECOM | 3 |
| 2011 | Anomaly discovery and resolution in web access control policiesabstractThe advent of emerging technologies such as Web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing Web access control policies are often error-prone due to the lack of effective analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly analysis approach for Web access control policies. We focus on XACML (eXtensible Access Control Markup Language) policy since XACML has become the de facto standard for specifying and enforcing access control policies for various Web-based applications and services. We introduce a policy-based segmentation technique to accurately identify policy anomalies and derive effective anomaly resolutions. We also discuss a proof-of-concept implementation of our method called XAnalyzer and demonstrate how efficiently our approach can discover and resolve policy anomalies. Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
SACMAT | 1 |
| 2011 | Zero-knowledge proofs of retrievability
Yan Zhu 0010, Huaixi Wang, Zexing Hu, Gail-Joon Ahn, Hongxin Hu |
Sci. China Inf. Sci. | 5 |
| 2011 | Patient-centric authorization framework for electronic healthcare services
Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
Comput. Secur. | 3 |
| 2011 | Provably Secure Role-Based Encryption with Revocation Mechanism
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Huaixi Wang, Shan-Biao Wang |
J. Comput. Sci. Technol. | 2 |
| 2010 | Cryptographic role-based security mechanisms based on role-key hierarchyabstractEven though role-based access control (RBAC) can tremendously help us minimize the complexity in administering users, it is still needed to realize the notion of roles at the resource level. In this paper, we propose a practical cryptographic RBAC model, called role-key hierarchy model, to support various security features including signature and encryption based on role-key hierarchy. With the help of rich algebraic structure of elliptic curve, we introduce a role-based cryptosystem construction to verify the rationality and validity of our proposed model. Also, a proof-of-concept prototype implementation and performance evaluation are discussed to demonstrate the feasibility and efficiency of our mechanisms. Yan Zhu 0010, Gail-Joon Ahn, Hongxin Hu, Huaixi Wang |
AsiaCCS | 3 |
| 2010 | Efficient provable data possession for hybrid cloudsabstractProvable data possession is a technique for ensuring the integrity of data in outsourcing storage service. In this paper, we propose a cooperative provable data possession scheme in hybrid clouds to support scalability of service and data migration, in which we consider the existence of multiple cloud service providers to cooperatively store and maintain the clients' data. Our experiments show that the verification of our scheme requires a small, constant amount of overhead, which minimizes communication complexity. Yan Zhu 0010, Huaixi Wang, Zexing Hu, Gail-Joon Ahn, Hongxin Hu, Stephen S. Yau |
CCS | 5 |
| 2010 | Information flow control in cloud computingabstractCloud computing is an emerging computing paradigm where computing resources are provided as services over Internet while residing in a large data center. Even though it enables us to dynamically provide servers with the ability to address a wide range of needs, this paradigm brings forth many new ch Gail-Joon Ahn, Hongxin Hu, Mukesh Singhal |
CollaborateCom | 3 |
| 2010 | A collaborative framework for privacy protection in online social networksabstractWith the wide use of online social networks (OSNs), the problem of data privacy has attracted much attention. Several approaches have been proposed to address this issue. One of privacy management approaches for OSN leverages a key management technique to enable a user to simply post encrypted conte Yan Zhu 0010, Zexing Hu, Huaixi Wang, Hongxin Hu, Gail-Joon Ahn |
CollaborateCom | 4 |
| 2010 | Representing and Reasoning about Web Access Control PoliciesabstractThe advent of emerging technologies such as Web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing Web access control policies are often error-prone due to the lack of logical and formal foundation. In this paper, we attempt to introduce a logic-based policy management approach for Web access control policies especially focusing on XACML (eXtensible Access Control Markup Language) policies, which have become the de facto standard for specifying and enforcing access control policies for various applications and services in current Web-based computing technologies. Our approach adopts Answer Set Programming (ASP) to formulate XACML that allows us to leverage the features of ASP solvers in performing various logical reasoning and analysis tasks such as policy verification, comparison and querying. In addition, we propose a policy analysis method that helps identify policy violations in XACML policies accommodating the notion of constraints in role-based access control (RBAC). We also discuss a proof-of-concept implementation of our method called XACMLl2ASP with the evaluation of several XACML policies from real-world software systems. Gail-Joon Ahn, Hongxin Hu, Joohyung Lee 0002, Yunsong Meng |
COMPSAC | 2 |
| 2010 | DR@FT: Efficient Remote Attestation Framework for Dynamic Systems
Wenjuan Xu, Gail-Joon Ahn, Hongxin Hu, Xinwen Zhang, Jean-Pierre Seifert |
ESORICS | 3 |
| 2010 | Risk-Aware Response for Mitigating MANET Routing AttacksabstractMobile Ad hoc Networks (MANET) have been highly vulnerable to attacks due to the dynamic nature of its network infrastructure. Among these attacks, routing attacks have received considerable attention since it could cause the most devastating damage to MANET. Even though there exist several intrusion response techniques to mitigate such critical attacks, existing solutions typically attempt to isolate malicious nodes based on binary or naive fuzzy response decisions. However, binary responses may result in the unexpected network partition, causing additional damages to the network infrastructure, and naive fuzzy responses could lead to uncertainty in countering routing attacks in MANET. In this paper, we propose a risk-aware response mechanism to systematically cope with the identified routing attacks. Our risk-aware approach is based on an extended Dempster-Shafer mathematical theory of evidence introducing a notion of importance factor. In addition, our experiments demonstrate the effectiveness of our approach with the consideration of the packet delivery ratio and routing cost. Ziming Zhao 0001, Hongxin Hu, Gail-Joon Ahn |
GLOBECOM | 2 |
| 2010 | Constructing Authorization Systems Using Assurance Management FrameworkabstractModel-driven approach has recently received much attention in developing secure software and systems. In addition, software developers have attempted to employ such an emerging approach in the early stage of software development life cycle. However, security concerns are rarely considered and practiced due to the lack of appropriate systematic mechanisms and tools. In this paper, we introduce a multilayered software development life cycle (SDLC), which is based on an assurance management framework (AMF), focusing on the development of authorization systems. AMF facilitates comprehensive realization of formal security model, security policy specification and verification, generation of security enforcement codes, and rigorous conformance testing. We also articulate our experience in analyzing role-based authorization requirements and realizing those requirements in constructing a role-based authorization system. Hongxin Hu, Gail-Joon Ahn |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2009 | Patient-centric authorization framework for sharing electronic health recordsabstractIn modern healthcare environments, a fundamental requirement for achieving continuity of care is the seamless access to distributed patient health records in an integrated and unified manner, directly at the point of care. However, Electronic Health Records (EHRs) contain a significant amount of sensitive information, and allowing data to be accessible at many different sources increases concerns related to patient privacy and data theft. Access control solutions must guarantee that only authorized users have access to such critical records for legitimate purposes, and access control policies from distributed EHR sources must be accurately reflected and enforced accordingly in the integrated EHRs. Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
SACMAT | 3 |
| 2009 | Security-Enhanced OSGi Service EnvironmentsabstractToday's home and local-area network environments consist of various types of personal equipments, network devices, and corresponding services. Since such prevalent home network environments frequently deal with private and sensitive information, it is crucial to legitimately provide access control for protecting such emerging environments. As a result, the open services gateway initiative (OSGi) attempted to address this critical issue. However, the current OSGi authorization mechanism is not rigorous enough to fulfill security requirements involved in dynamic OSGi environments. In this paper, we provide a systematic way to adopt a role-based access control (RBAC) approach in OSGi environments. We demonstrate how our authorization framework can achieve important RBAC features and enhance existing primitive access control modules in OSGi service environments. Also, we describe a proof-of-concept prototype of the proposed framework to discuss the feasibility of our approach using an open source implementation of OSGi framework known as Knopflerfish. Gail-Joon Ahn, Hongxin Hu |
IEEE Trans. Syst. Man Cybern. Part C | 2 |
| 2008 | Enabling verification and conformance testing for access control modelabstractVerification and testing are the important step for software assurance. However, such crucial and yet challenging tasks have not been widely adopted in building access control sys-tems. In this paper we propose a methodology to sup-port automatic analysis and conformance testing for ac-cess control systems, integrating those features to Assur-ance Management Framework (AMF). Our methodology at-tempts to verify formal specifications of a role-based access control model and corresponding policies with selected se-curity properties. Also, we systematically articulate testing cases from formal specifications and validate conformance to the system design and implementation using those cases. In addition, we demonstrate feasibility and effectiveness of our methodology using SAT and Alloy toolset. Hongxin Hu, Gail-Joon Ahn |
SACMAT | 1 |
| 2007 | Towards trust-aware access management for ad-hoc collaborationsabstractIn an ad-hoc collaborative sharing environment, attribute-based access control provides a promising approach in defining authorization over shared resources based on userspsila properties/attributes rather than their identities. While the userpsilas attributes are always asserted by different authorities in the form of credentials, these authorities may not be accepted by the resource owner with the same degree of trust. In this paper, we present a trust-aware role-based authorization framework, called RAMARS_TM, to address both the access control and the trust management issues in such environment. Central to our approach is the dynamic role assignment based on a userpsilas attributes, and trust management, as a special constraint, is in place to make trust decisions on a userpsilas attributes. Required components and functions are identified and specified in our trust and access management policies. An architecture of prototype system implementation is also discussed. Gail-Joon Ahn, Mohamed Shehab, Hongxin Hu |
CollaborateCom | 4 |
| 2007 | Towards realizing a formal RBAC model in real systemsabstractThere still exists an open question on how formal models can be fully realized in the system development phase. The Model Driven Development (MDD) approach has been recently introduced to deal with such a critical issue for building high assurance software systems. Gail-Joon Ahn, Hongxin Hu |
SACMAT | 2 |