Mingwei Zhang 0004

dblp:08/7638-4 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0001-8330-8884ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 first-authorSecurity and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2023 DDoS Mitigation Dilemma Exposed: A Two-Wave Attack with Collateral Damage of Millions
Lumin Shi, Jun Li 0001, Devkishen Sisodia, Mingwei Zhang 0004, Alberto Dainotti, Peter L. Reiher
SecureComm (2)4
2023 A Game Theoretical Analysis of Distributed Denial-of-Service Defense Incentive
Mingwei Zhang 0004, Jun Li 0001, Jiabin Wu, Peter L. Reiher
SecureComm (2)1
2022 On Capturing DDoS Traffic Footprints on the Internet
abstract
While distributed denial-of-service (DDoS) attacks are easy to launch and are becoming more damaging, the defense against DDoS attacks often suffers from the lack of relevant knowledge of the DDoS traffic, including the paths the DDoS traffic has used, the source addresses (spoofed or not) that appear along each path, and the amount of traffic per path or per source. Though IP traceback and path inference approaches could be considered, they are either expensive and hard to deploy or inaccurate. We propose PathFinder, a service that a DDoS defense system can use to obtain the footprints of the DDoS traffic to the victim. PathFinder employs an architecture that is easy to implement and deploy on today's Internet, a PFTrie data structure that introduces multiple design features to log traffic at line rate, and streaming and zooming mechanisms that facilitates the storage and transmission of DDoS footprints more efficiently. Our evaluation shows that PathFinder can significantly improve the efficacy of a DDoS defense system, its PFTrie data structure is fast and has a manageable overhead, and its streaming and zooming mechanisms significantly reduce the delay and overhead in transmitting DDoS footprints.
Lumin Shi, Jun Li 0001, Mingwei Zhang 0004, Peter L. Reiher
IEEE Trans. Dependable Secur. Comput.3
2019 On Multi-Point, In-Network Filtering of Distributed Denial-of-Service Traffic
Mingwei Zhang 0004, Lumin Shi, Devkishen Sisodia, Jun Li 0001, Peter L. Reiher
IM1
2017 I-Seismograph: Observing, Measuring, and Analyzing Internet Earthquakes
abstract
Disruptive events, such as large-scale power outages, undersea cable cuts, or security attacks, could have an impact on the Internet and cause the Internet to deviate from its normal state of operation, which we also refer to as an “Internet earthquake.” As the Internet is a large, complex moving target, unfortunately little research has been done to define, observe, quantify, and analyze such impact on the Internet, whether it is during a past event period or in real time. In this paper, we devise an Internet seismograph, orI-seismograph, to fill this gap. Since routing is the most basic function of the Internet and the Border Gateway Protocol (BGP) is thede factostandard inter-domain routing protocol, we focus on BGP to observe, measure, and analyze the Internet earthquakes. After defining what an impact to BGP entails, we describe how I-seismograph observes and measures the impact, exemplify its usage during both old and recent disruptive events, and further validate its accuracy and convergency. Finally, we show that I-seismograph can further be used to help analyze what happened to BGP while BGP experienced an impact, including which autonomous systems (AS) were affected most or which AS paths or path segments surged significantly in BGP updates during an Internet earthquake.
Mingwei Zhang 0004, Jun Li 0001, Scott Brooks
IEEE/ACM Trans. Netw.1
2014 Drawbridge: software-defined DDoS-resistant traffic engineering
abstract
End hosts in today's Internet have the best knowledge of the type of traffic they should receive, but they play no active role in traffic engineering. Traffic engineering is conducted by ISPs, which unfortunately are blind to specific user needs. End hosts are therefore subject to unwanted traffic, particularly from Distributed Denial of Service (DDoS) attacks. This research proposes a new system called DrawBridge to address this traffic engineering dilemma. By realizing the potential of software-defined networking (SDN), in this research we investigate a solution that enables end hosts to use their knowledge of desired traffic to improve traffic engineering during DDoS attacks.
Jun Li 0001, Skyler Berg, Mingwei Zhang 0004, Peter L. Reiher, Tao Wei 0002
SIGCOMM3