EDBT 2026 Demo / reviewers in the wild / expert
An Wang 0002
dblp:06/4924-2
· DBLP profile ↗
32ranked-venue papers
11as first author
12since 2021 · last 2026
0000-0002-1701-9176ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 4 first-author · 5 since 2021Security and privacy · 11 · 4 first-author · 3 since 2021Systems, architecture and hardware · 7 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EASE: Practical and Efficient Safety Alignment for Small Language ModelsabstractSmall language models (SLMs) are increasingly deployed on edge devices, making their safety alignment crucial yet challenging. Current shallow alignment methods that rely on direct refusal of malicious queries fail to provide robust protection, particularly against adversarial jailbreaks. While deliberative safety reasoning alignment offers deeper alignment for defending against sophisticated attacks, effectively implanting such reasoning capability in SLMs with limited capabilities remains an open challenge. Moreover, safety reasoning incurs significant computational overhead as models apply reasoning to nearly all queries, making it impractical for resource-constrained edge deployment scenarios that demand rapid responses. We propose EASE, a novel framework that enables practical and Efficient safety Alignment for Small languagE models. Our approach first identifies the optimal safety reasoning teacher that can effectively distill safety reasoning capabilities to SLMs. We then align models to selectively activate safety reasoning for dangerous adversarial jailbreak queries while providing direct responses to straightforward malicious queries and general helpful tasks. This selective mechanism enables small models to maintain robust safety guarantees against sophisticated attacks while preserving computational efficiency for benign interactions. Experimental results demonstrate that EASE reduces jailbreak attack success rates by up to 17% compared to shallow alignment methods while reducing inference overhead by up to 90% compared to deliberative safety reasoning alignment, making it practical for SLMs real-world edge deployments. Haonan Shi 0002, Tu Ouyang, An Wang 0002 |
AAAI | 4 |
| 2026 | Blockchain Security and Privacy: Threats, Challenges, Applications, and ToolsabstractBlockchain technology has heralded a new era in digital innovation, revolutionizing our approach to designing and building distributed applications in the digital sphere. Blockchain technology operates as an immutable digital ledger, where each entry representing a digital transaction is indelible and cannot be altered once established. Initially designed as the fundamental framework for cryptocurrencies, blockchain has outgrown its original purpose, demonstrating significant potential in various industries and offering a variety of security and privacy features. Our study provides a thorough and current survey of blockchain applications, security, privacy concepts, primitives, and threat models. It stands out by concentrating on how blockchain technology intersects with emerging fields like IoT, EVs, FinTech, and healthcare systems in a single framework. To provide security and privacy features, blockchain systems employ different foundational notions and primitives while tackling diverse adversarial scenarios with various capabilities and goals. This study presents a fresh examination of the current state of applications, security and privacy notions and primitives, and threat models in blockchain systems. Additionally, this work highlights existing gaps in knowledge and outlines open questions, aiming to stimulate interest in further advancements in the field. Ahod Alghuried, Mohammed Alkinoon, Manar Mohaisen, An Wang 0002, Cliff C. Zou, David Mohaisen |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2025 | Poster: Measuring Algorithmic Systems' Resilience Against Generative AI-Powered Attacks - Case Study on Exploiting a Code Search PlatformabstractGenerative AI applications have boomed since the GPT-3-powered ChatGPT release in 2022. Miscreants also see the opportunities of leveraging these frontier GenAI technologies to facilitate cyberattacks, from planning to execution. Nathaniel Hahn, Tu Ouyang, An Wang 0002 |
IMC | 3 |
| 2025 | Tree Embedding Based Mapping System for Low-Latency Mobile Applications in Multi-Access Networks
Yu Mi, Randeep Bhatia, Fang Hao, An Wang 0002, Steven A. Benno, T. V. Lakshman |
INFOCOM | 4 |
| 2025 | Unveiling Client Privacy Leakage from Public Dataset Usage in Federated DistillationabstractFederated Distillation (FD) has emerged as a popular federated training framework, enabling clients to collaboratively train models without sharing private data. Public Dataset-Assisted Federated Distillation (PDA-FD), which leverages public datasets for knowledge sharing, has become widely adopted. Although PDA-FD enhances privacy compared to traditional Federated Learning, we demonstrate that the use of public datasets still poses significant privacy risks to clients' private training data. This paper presents the first comprehensive privacy analysis of PDA-FD in the presence of an honest-but-curious server. We show that the server can exploit clients' inference results on public datasets to extract two critical types of private information: label distributions and membership information of the private training dataset. To quantify these vulnerabilities, we introduce two novel attacks specifically designed for the PDA-FD setting: a label distribution inference attack and innovative membership inference methods based on Likelihood Ratio Attack (LiRA). Through extensive evaluation of three representative PDA-FD frameworks (FedMD, DS-FL, and Cronus), our attacks achieve state-of-the-art performance, with label distribution attacks reaching minimal KL-divergence and membership inference attacks maintaining high True Positive Rates under low False Positive Rate constraints. Our findings reveal significant privacy risks in current PDA-FD frameworks and emphasize the need for more robust privacy protection mechanisms in collaborative learning systems. Haonan Shi 0002, Tu Ouyang, An Wang 0002 |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Learning-Based Difficulty Calibration for Enhanced Membership Inference AttacksabstractMachine learning models, in particular deep neural networks, are currently an integral part of various applications, from healthcare to finance. However, using sensitive data to train these models raises concerns about privacy and security. One method that has emerged to verify if the trained models are privacy-preserving is Membership Inference Attacks (MIA), which allows adversaries to determine whether a specific data point was part of a model's training dataset. While a series of MIAs have been proposed in the literature, only a few can achieve high True Positive Rates (TPR) in the low False Positive Rate (FPR) region (0.01% ~ 1%). This is a crucial factor to consider for an MIA to be practically useful in real-world settings. In this paper, we present a novel approach to MIA that is aimed at significantly improving TPR at low FPRs. Our method, named learning-based difficulty calibration for MIA (LDC-MIA), characterizes data records by their hardness levels using a neural network classifier to determine membership. The experiment results show that LDC-MIA can improve TPR at low FPR by up to 4x compared to the other difficulty calibration-based MIAs. It also has the highest Area Under ROC curve (AUC) across all datasets. Our method's cost is comparable with most of the existing MIAs, but is orders of magnitude more efficient than one of the state-of-the-art methods, LiRA, while achieving similar performance. Haonan Shi 0002, Tu Ouyang, An Wang 0002 |
EuroS&P | 3 |
| 2023 | DNN Architecture Attacks via Network and Power Side Channels
Yuanjun Dai, Qingzhe Guo, An Wang 0002 |
SecureComm (1) | 3 |
| 2023 | Towards Software Defined Measurement in Data Centers: A Comparative Study of Designs, Implementation, and EvaluationabstractCloud data centers are increasingly adopting the Software-Defined Networking (SDN) technologies for their underlying connection and communications. However, as a critical part of daily operations and management of such data centers, the network measurement is essential but has often been constrained by the available resources in the traditional network devices. Thus, how to properly balance the resource consumption while maintain timely and accurate measurement remains a challenge to data center systems. Recent advances in Software-Defined Networking (SDN) have enabled flexible and programmable network measurement, which is referred to as Software Defined Measurement (SDM). A promising trend for SDM is to conduct network traffic measurement on widely deployed Open vSwitches (OVS) in data centers. However, little attention has been paid to the design options for conducting traffic measurement on the OVS. In this study, we set to explore different designs and investigate the corresponding trade-offs among resource consumption, measurement accuracy, implementation complexity, and impact on switching speed. Through extensive experiments and comparisons, we quantitatively show the various trade-offs that the different schemes strike to balance, and demonstrate the feasibility of instrumenting OVS with monitoring capabilities. These results provide valuable insights into which design will best serve different measurement and monitoring needs. Zili Zha, An Wang 0002, Yang Guo 0001, Songqing Chen |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | Elastically Augmenting the Control-path Throughput in SDN to Deal with Internet DDoS AttacksabstractDistributed denial of service (DDoS) attacks have been prevalent on the Internet for decades. Albeit various defenses, they keep growing in size, frequency, and duration. The new network paradigm, Software-defined networking (SDN), is also vulnerable to DDoS attacks. SDN uses logically centralized control, bringing the advantages in maintaining a global network view and simplifying programmability. When attacks happen, the control path between the switches and their associated controllers may become congested due to their limited capacity. However, the data plane visibility of SDN provides new opportunities to defend against DDoS attacks in the cloud computing environment. To this end, we conduct measurements to evaluate the throughput of the software control agents on some of the hardware switches when they are under attacks. Then, we design a new mechanism, called Scotch , to enable the network to scale up its capability and handle the DDoS attack traffic. In our design, the congestion works as an indicator to trigger the mitigation mechanism. Scotch elastically scales up the control plane capacity by using an Open vSwitch-based overlay. Scotch takes advantage of both the high control plane capacity of a large number of vSwitches and the high data plane capacity of commodity physical switches to increase the SDN network scalability and resiliency under abnormal (e.g., DDoS attacks) traffic surges. We have implemented a prototype and experimentally evaluated Scotch . Our experiments in the small-scale lab environment and large-scale GENI testbed demonstrate that Scotch can elastically scale up the control channel bandwidth upon attacks. Yuanjun Dai, An Wang 0002, Yang Guo 0001, Songqing Chen |
ACM Trans. Internet Techn. | 2 |
| 2022 | Understanding Internet of Things malware by analyzing endpoints in their static artifacts
Jinchun Choi, Afsah Anwar, Abdulrahman Alabduljabbar, Hisham Alasmary, Jeffrey Spaulding, An Wang 0002, Songqing Chen, DaeHun Nyang, Amro Awad, David Mohaisen |
Comput. Networks | 6 |
| 2022 | ShellCore: Automating Malicious IoT Software Detection Using Shell Commands RepresentationabstractThe Linux shell is a command-line interpreter that provides users with a command interface to the operating system, allowing them to perform various functions. Although very useful in building capabilities at the edge, the Linux shell can be exploited, giving adversaries a prime opportunity to use them for malicious activities. With access to Internet of Things (IoT) devices, malware authors can abuse the Linux shell of those devices to propagate infections and launch large-scale attacks, e.g., Distributed Denial of Service. In this work, we provide a first look at the tasks managed by shell commands in Linux-based IoT malware toward detection. We analyze malicious shell commands found in IoT malware and build a neural network-based model, ShellCore, to detect malicious shell commands. Namely, we collected a large data set of shell commands, including malicious commands extracted from 2891 IoT malware samples and benign commands collected from real-world network traffic analysis and volunteered data from Linux users. Using conventional machine and deep learning-based approaches trained with a term- and character-level features, ShellCore is shown to achieve an accuracy of more than 99% in detecting malicious shell commands and files (i.e., binaries). Hisham Alasmary, Afsah Anwar, Ahmed Abusnaina, Abdulrahman Alabduljabbar, Mohammed Abuhamad, An Wang 0002, DaeHun Nyang, Amro Awad, David Mohaisen |
IEEE Internet Things J. | 6 |
| 2021 | Mind the Gap: Broken Promises of CPU Reservations in Containerized Multi-tenant CloudsabstractContainerization is becoming increasingly popular, but unfortunately, containers often fail to deliver the anticipated performance with the allocated resources. In this paper, we first demonstrate the performance variance and degradation are significant (by up to 5x) in a multi-tenant environment where containers are co-located. We then investigate the root cause of such performance degradation. Contrary to the common belief that such degradation is caused by resource contention and interference, we find that there is a gap between the amount of CPU a container reserves and actually gets. The root cause lies in the design choices of today's Linux scheduling mechanism, which we call Forced Runqueue Sharing and Phantom CPU Time. In fact, there are fundamental conflicts between the need to reserve CPU resources and Completely Fair Scheduler's work-conserving nature, and this contradiction prevents a container from fully utilizing its requested CPU resources. As a proof-of-concept, we implement a new resource configuration mechanism atop the widely used Kubernetes and Linux to demonstrate its potential benefits and shed light on future scheduler redesign. Our proof-of-concept, compared to the existing scheduler, improves the performance of both batch and interactive containerized apps by up to 5.6x and 13.7x. Li Liu 0045, An Wang 0002, Mengbai Xiao, Yue Cheng 0001, Songqing Chen |
SoCC | 3 |
| 2020 | Statically Dissecting Internet of Things Malware: Analysis, Characterization, and Detection
Afsah Anwar, Hisham Alasmary, Jeman Park 0001, An Wang 0002, Songqing Chen, David Mohaisen |
ICICS | 4 |
| 2020 | SmartMon: Misbehavior Detection via Monitoring Smart Home AutomationsabstractThe rapid expansion of Internet of Things (IoT) has brought unprecedented changes to our daily life. Among all, smart home technologies are the most widely adopted. They leverage various devices in home environment to build a connected network, over which automation is implemented for enhancing device interoperability. Such automations usually execute on platforms that are provided by device vendors, such as Samgsung, Google and Amazon. However, back-end cloud may not always be trustworthy due to malware, unknown third-party applications and possible side-channel attacks. Specifically for the IoT platforms, we identify two security threats that may gain unauthorized control of smart home devices: over-privilege issue and spooking events. In this thesis, we presents SmartMon, a framework that is designed to detect such security violations by statically analyzing automation application (SmartApp) control logic and comparing them with dynamic execution patterns. Through evaluations, we demonstrate that SmartMon could achieve high precision (> 95%) in detecting both violations. We also evaluate its detection capability in more complex settings, where multiple SmartApps execute simultaneously, resulting in potential dependencies. The evaluation results show that SmartMon remains high accuracy in this scenario as well. Pengfei Peng, An Wang 0002 |
SEC | 2 |
| 2020 | AccuPIPE: Accurate Heavy Flow Detection in the Data Plane Using Programmable SwitchesabstractIdentifying heavy flows, i.e., flows with large packet counts during a pre-defined time window, is vital for many network applications. The task of real-time heavy flow detection in data plane is challenging due to high switching speed (100 Gbps), a large number of concurrent flows (millions of concurrent flows), and small memory footprint requirement. In this paper, we dissect the key factors that affect the existing detection scheme’s accuracy, and propose AccuPipe, a new detection scheme with intelligent flow entry replacement strategies. The simulation results show that the new scheme is able to efficiently utilize all flow entries in the detection pipeline, and detects more than 850 heavy flows (out of top 1,000) using a small amount of memory (1,000 flow entries, roughly equivalently to 18KB memory) with reasonable reporting overhead. This represents a 76% improvement over HashPIPE scheme, which detects on average 484 heavy flows (out of top 1,000) in the same setting. In addition, we investigate the performance of different flow entry replacement strategies, and report their pros and cons. Yang Guo 0001, Franklin Liu, An Wang 0002, Hang Liu 0003 |
NOMS | 3 |
| 2020 | A Data-Driven Study of DDoS Attacks and Their DynamicsabstractDespite continuous defense efforts, DDoS attacks are still very prevalent on the Internet. In such arms races, attackers are becoming more agile and their strategies are more sophisticated to escape from detection. Effective defenses demand in-depth understanding of such strategies. In this paper, we set to investigate the DDoS landscape from the perspective of the attackers. We focus on the dynamics of the attacking force, aiming to explore the strategies behind the scenes, if any. Our study is based on 50,704 different Internet DDoS attacks across the globe in a seven-month period. Our results indicate that attackers deliberately schedule their controlled bots in a dynamic fashion, and such dynamics can be well captured by statistical distributions. Furthermore, different botnet families exhibit similar scheduling patterns, strongly suggesting their close relationship and potential collaborations. Such collaborations are further confirmed by bots rotating in multiple families, and such rotation patterns are examined and confirmed at various levels. These findings lay a promising foundation for predicting DDoS attacks in the future and aid mitigation efforts. An Wang 0002, Wentao Chang, Songqing Chen, David Mohaisen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | XLF: A Cross-layer Framework to Secure the Internet of Things (IoT)abstractThe burgeoning Internet of Things (IoT) has offered unprecedented opportunities for innovations and applications that are continuously changing our life. At the same time, the large amount of pervasive IoT applications have posed paramount threats to the user's security and privacy. While a lot of efforts have been dedicated to deal with such threats from the hardware, the software, and the applications, in this paper, we argue and envision that more effective and comprehensive protection for IoT systems can only be achieved via a cross-layer approach. As such, we present our initial design of XLF, a cross-layer framework towards this goal. XLF can secure the IoT systems not only from each individual layer of device, network, and service, but also through the information aggregation and correlation of different layers. An Wang 0002, David Mohaisen, Songqing Chen |
ICDCS | 1 |
| 2019 | vCPU as a container: towards accurate CPU allocation for VMsabstractWith our increasing reliance on cloud computing, accurate resource allocation of virtual machines (or domains) in the cloud have become more and more important. However, the current design of hypervisors (or virtual machine monitors) fails to accurately allocate resources to the domains in the virtualized environment. In this paper, we claim the root cause is that the protection scope is erroneously used as the resource scope for a domain in the current virtualization design. Such design flaw prevents the hypervisor from accurately accounting resource consumption of each domain. In this paper, using virtual CPUs as a container we propose to redefine the resource scope of a domain, so that the new resource scope is aligned with all the CPU consumption incurred by this domain. As a demonstration, we implement a novel system, called VASE (vCPU as a container), on top of the Xen hypervisor. Evaluations on our testbed have shown our proposed approach is effective in accounting system-wide CPU consumption incurred by domains, while introducing negligible overhead to the system. Li Liu 0045, An Wang 0002, Mengbai Xiao, Yue Cheng 0001, Songqing Chen |
VEE | 3 |
| 2019 | Software-Defined Networking Enhanced Edge Computing: A Network-Centric SurveyabstractEdge computing is burgeoning along with the rapidly increasing adoption of the Internet of Things (IoT). While there are studies on various aspects of edge computing, we find there is a lack of network perspective. In this paper, we, thus, first present an overview of how software-defined networking (SDN) and related technologies are being investigated in edge computing. Our purpose is to survey the state of the art and discuss the potential (remaining) challenges for future research. For this, we survey how SDN and related technologies are integrated to facilitate the management and operations of edge servers and various IoT devices. For the former, we review how SDN has been utilized in the access network, the core network, and the wide area network (WAN) between the edge and the cloud. For the latter, we focus on how SDN is leveraged to provide unified and programmable interfaces to manage devices. Through our discussion, we suggest that the SDN-related network support for edge computing deserves more in-depth investigations. We also identify several challenges and open issues to be addressed in the future. An Wang 0002, Zili Zha, Yang Guo 0001, Songqing Chen |
Proc. IEEE | 1 |
| 2018 | Empirical Evaluation of the Hypervisor Scheduling on Side Channel AttacksabstractAlong with the wide adoption of the cloud platform, various attacks also target clouds. Due to the sharing of the underlying physical resources among different virtual machines (VMs), various side-channel attacks have been demonstrated to be capable of stealing victim's secret information, such as encryption key, by monitoring the victim's access pattern to a shared hardware, such as CPU cache. Among various defense mechanisms proposed, the hypervisor scheduling based schemes shed some light on lightweight solutions that are more likely to be adopted in practice. However, scheduling is affected by several factors that have not been thoroughly investigated so far. In this study, we aim to study in-depth the impact of various factors affecting the hypervisor scheduling, with the objective to understand their impact on mitigating these side-channel attacks. Our results can not only deepen our understanding, but also provide some guidelines to design effective scheduling based defenses in the future. Li Liu 0045, An Wang 0002, Wanyu Zang, Meng Yu 0001, Songqing Chen |
ICC | 2 |
| 2018 | Shuffler: Mitigate Cross-VM Side-Channel Attacks via Hypervisor Scheduling
Li Liu 0045, An Wang 0002, Wanyu Zang, Meng Yu 0001, Menbai Xiao, Songqing Chen |
SecureComm (1) | 2 |
| 2018 | Delving Into Internet DDoS Attacks by Botnets: Characterization and AnalysisabstractInternet distributed denial of service (DDoS) attacks are prevalent but hard to defend against, partially due to the volatility of the attacking methods and patterns used by attackers. Understanding the latest DDoS attacks can provide new insights for effective defense. But most of existing understandings are based on indirect traffic measures (e.g., backscatters) or traffic seen locally. In this paper, we present an in-depth analysis based on 50 704 different Internet DDoS attacks directly observed in a seven-month period. These attacks were launched by 674 botnets from 23 different botnet families with a total of 9026 victim IPs belonging to 1074 organizations in 186 countries. Our analysis reveals several interesting findings about today's Internet DDoS attacks. Some highlights include: 1) geolocation analysis shows that the geospatial distribution of the attacking sources follows certain patterns, which enables very accurate source prediction of future attacks for most active botnet families; 2) from the target perspective, multiple attacks to the same target also exhibit strong patterns of inter-attack time interval, allowing accurate start time prediction of the next anticipated attacks from certain botnet families; and 3) there is a trend for different botnets to launch DDoS attacks targeting the same victim, simultaneously or in turn. These findings add to the existing literature on the understanding of today's Internet DDoS attacks and offer new insights for designing new defense schemes at different levels. An Wang 0002, Wentao Chang, Songqing Chen, David Mohaisen |
IEEE/ACM Trans. Netw. | 1 |
| 2017 | An Adversary-Centric Behavior Modeling of DDoS AttacksabstractDistributed Denial of Service (DDoS) attacks are some of the most persistent threats on the Internet today. The evolution of DDoS attacks calls for an in-depth analysis of those attacks. A better understanding of the attackers' behavior can provide insights to unveil patterns and strategies utilized by attackers. The prior art on the attackers' behavior analysis often falls in two aspects: it assumes that adversaries are static, and makes certain simplifying assumptions on their behavior, which often are not supported by real attack data. In this paper, we take a data-driven approach to designing and validating three DDoS attack models from temporal (e.g., attack magnitudes), spatial (e.g., attacker origin), and spatiotemporal (e.g., attack inter-launching time) perspectives. We design these models based on the analysis of traces consisting of more than 50,000 verified DDoS attacks from industrial mitigation operations. Each model is also validated by testing its effectiveness in accurately predicting future DDoS attacks. Comparisons against simple intuitive models further show that our models can more accurately capture the essential features of DDoS attacks. An Wang 0002, David Mohaisen, Songqing Chen |
ICDCS | 1 |
| 2017 | vPROM: VSwitch enhanced programmable measurement in SDNabstractWhile being critical to the network management, the current state of the art in network measurement is inadequate, providing surprisingly little visibility into detailed network behaviors and often requiring high level of manual intervention to operate. Such a practice becomes increasingly ineffective as the networks grow both in size and complexity. In this paper, we propose vPROM, a vSwitch enhanced SDN programmable measurement framework that automates the measurement process, minimizes the measurement resource usage, and addresses several significant technical challenges faced by early works. vPROM leverages the SDN programmability and extends the Pyretic runtime system and OpenFlow network interface to achieve the measurement automation. The required measurement resources are minimized by only acquiring the necessary statistics, made possible with instrumented Open vSwitches1with user defined monitoring capability. By decoupling monitoring from routing, vPROM reduces the interference between the measurement applications and other applications, and eliminates the frequent involvement of the controller. A vPROM prototype is implemented with DDoS and port-scan detection applications. The performance of vPROM is evaluated and the comparison results with other existing programmable measurement approaches are also presented. An Wang 0002, Yang Guo 0001, Songqing Chen, Fang Hao, T. V. Lakshman, Doug Montgomery, Kotikalapudi Sriram |
ICNP | 1 |
| 2017 | Understanding Adversarial Strategies from Bot Recruitment to Scheduling
Wentao Chang, David Mohaisen, An Wang 0002, Songqing Chen |
SecureComm | 3 |
| 2015 | Measuring Botnets in the Wild: Some New TrendsabstractToday, botnets are still responsible for most large scale attacks on the Internet. Botnets are versatile, they remain the most powerful attack platform by constantly and continuously adopting new techniques and strategies in the arms race against various detection schemes. Thus, it is essential to understand the latest of the botnets in a timely manner so that the insights can be utilized in developing more efficient defenses. In this work, we conduct a measurement study on some of the most active botnets on the Internet based on a public dataset collected over a period of seven months by a monitoring entity. We first examine and compare the attacking capabilities of different families of today's active botnets. Our analysis clearly shows that different botnets start to collaborate when launching DDoS attacks. Wentao Chang, David Mohaisen, An Wang 0002, Songqing Chen |
AsiaCCS | 3 |
| 2015 | UMON: flexible and fine grained traffic monitoring in open vSwitchabstractWe study how to provide fine-grained, flexible traffic monitoring in the Open vSwitch (OVS). We argue that the existing OVS monitoring tools are neither flexible nor sufficient for supporting many monitoring applications. We propose UMON, a mechanism that decouples monitoring from forwarding, and offers flexible and fine-grained traffic stats. We describe a prototype implementation of UMON that integrates well with the OVS architecture. Finally, we evaluate the performance using the prototype, and illustrate UMON's efficiency with the example use cases such as detecting port scans. An Wang 0002, Yang Guo 0001, Fang Hao, T. V. Lakshman, Songqing Chen |
CoNEXT | 1 |
| 2015 | Capturing DDoS Attack Dynamics Behind the Scenes
An Wang 0002, David Mohaisen, Wentao Chang, Songqing Chen |
DIMVA | 1 |
| 2015 | Delving into Internet DDoS Attacks by Botnets: Characterization and AnalysisabstractInternet Distributed Denial of Service (DDoS) at- tacks are prevalent but hard to defend against, partially due to the volatility of the attacking methods and patterns used by attackers. Understanding the latest DDoS attacks can provide new insights for effective defense. But most of existing understandings are based on indirect traffic measures (e.g., backscatters) or traffic seen locally. In this study, we present an in-depth analysis based on 50,704 different Internet DDoS attacks directly observed in a seven-month period. These attacks were launched by 674 botnets from 23 different botnet families with a total of 9,026 victim IPs belonging to 1,074 organizations in 186 countries. Our analysis reveals several interesting findings about today's Internet DDoS attacks. Some highlights include: (1) geolocation analysis shows that the geospatial distribution of the attacking sources follows certain patterns, which enables very accurate source prediction of future attacks for most active botnet families, (2) from the target perspective, multiple attacks to the same target also exhibit strong patterns of inter-attack time interval, allowing accurate start time prediction of the next anticipated attacks from certain botnet families, (3) there is a trend for different botnets to launch DDoS attacks targeting the same victim, simultaneously or in turn. These findings add to the existing literature on the understanding of today's Internet DDoS attacks, and offer new insights for designing new defense schemes at different levels. An Wang 0002, David Mohaisen, Wentao Chang, Songqing Chen |
DSN | 1 |
| 2014 | POSTER: How Distributed Are Today's DDoS Attacks?abstractToday botnets are responsible for most of the DDoS attacks on the Internet. Understanding the characteristics of such DDoS attacks is critical to develop effective DDoS mitigation schemes. In this poster, we present some preliminary findings, mainly concerning the distribution of the attackers, of today's DDoS attacks. Our investigation is based on 50,704 different Internet DDoS attacks collected within a seven-month period for activities across the globe. These attacks were launched by 674 botnet generations from 23 different bonet families with a total of 9026 victim IPs belonging to 1074 organizations that are collectively located in 186 countries. We find that different from the traditional widely distributed intuition, most of these DDoS attacks are not widely distributed as the attackers are mostly from the same region, i.e., highly regionalized. We also find that different botnet families have strong target preferences in the same area as well. These findings refresh our understanding on the modern DDoS attacks. An Wang 0002, Wentao Chang, David Mohaisen, Songqing Chen |
CCS | 1 |
| 2014 | Scotch: Elastically Scaling up SDN Control-Plane using vSwitch based OverlayabstractSoftware Defined Networks use logically centralized control due to its benefits in maintaining a global network view and in simplifying programmability. However, the use of centralized controllers can affect network performance if the control path between the switches and their associated controllers becomes a bottleneck. We find from measurements that the software control agents on some of the switches have very limited throughput. This can cause performance degradation if the switch has to handle a high traffic load, as for instance due to flash crowds or DDoS attacks. This degradation can occur even when the data plane capacity is under-utilized. The goal of our paper is to design new mechanisms to enable the network to scale up its ability to handle high control traffic loads. For this purpose, we design, implement, and experimentally evaluate Scotch, a solution that elastically scales up the control plane capacity by using a vSwitch based overlay. Scotch takes advantage of both the high control plane capacity of a large number of vSwitches and the high data plane capacity of commodity physical switches to increase the SDN network scalability and resiliency under normal (e.g., flash crowds) or abnormal (e.g., DDoS attacks) traffic surge. An Wang 0002, Yang Guo 0001, Fang Hao, T. V. Lakshman, Songqing Chen |
CoNEXT | 1 |
| 2014 | Characterizing botnets-as-a-serviceabstractNo abstract available. Wentao Chang, An Wang 0002, David Mohaisen, Songqing Chen |
SIGCOMM | 2 |