Jinshu Su

dblp:15/2098 · DBLP profile ↗
← Back
156ranked-venue papers
5as first author
53since 2021 · last 2026
0000-0001-9273-616XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 68 · 2 first-author · 24 since 2021Security and privacy · 30 · 1 first-author · 12 since 2021Systems, architecture and hardware · 23 · 1 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 15 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 7 · 3 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LLMs Unleashed: Generating Protocol Code from RFC Specifications
abstract
RFC (Request for Comments) documents constitute the foundation of network protocol standardization. However, they are expressed in natural language, they tend to be lengthy and ambiguous, forcing protocol implementers to rely on extensive manual parsing and coding—a process that is both labor-intensive and prone to errors. This makes the automated parsing and comprehension of RFC documents a major challenge in network protocol research. To address this gap, we introduce large language models (LLMs) into the task of automatic network protocol code generation from RFC documents (RFC2Code) and propose a comprehensive evaluation framework to quantitatively assess LLM performance. We develop an end-to-end automated protocol generation system, APG (Automated Protocol-Generation), which supports implementations of ICMP, IGMP, NTP, and TCP. Compared to prior NLP (Natural language processing) methods, APG achieves a fully automated workflow with approximately 3.17× faster processing, 95% compile success and behavioral correctness for stateless protocols like ICMP, and 90% interoperability for complex stateful protocols such as TCP, requiring only minimal manual intervention.
Junfeng Long, Jinshu Su, Biao Han 0003
AAAI2
2026 ReMu: Bridging Fidelity and Flexibility in High-Mobility Network Emulation at Microsecond Scale
Mingtai Lv, Xuyan Jiang, Huan Zhou 0006, Gaofeng Lv, Jinshu Su, Xiangrui Yang 0002
IWQoS6
2026 DTCC: Decision Transformer-driven framework for adaptive network congestion control
abstract
Existing learning-based congestion control methods suffer from myopic decision-making due to their reliance on single-timestep states and fail to model long-term dependencies due to architectural constraints (e.g., recurrent networks’ vanishing gradients). To address these issues, we propose a Decision Transformer-based network congestion control framework named DTCC. DTCC is the first to unify long-context modeling and real-time decision-making within a 4-layer autoregressive Transformer, replacing traditional Markov decision paradigms with sequence-to-action mapping. With enhancement learning strategy such as stochasticity-aware training, DTCC achieves efficient and generalizable performance from heterogeneous dataset. Extensive experiments demonstrate DTCC’s supremacy: it achieves 16.67–29.55% higher winning rate compared to state-of-the-art baselines (e.g., Sage) across diverse network scenarios and 8.33%–29.17% higher winning rate under unseen highly variable network. Leveraging a lightweight Transformer, DTCC enables real-time deployment with approximately 2.8 ms inference per step on general CPU devices. To the best of our knowledge, this is the first work to employ Decision Transformer for training an intelligent congestion control mechanism. Our work, therefore, showcases the potential of combining reinforcement learning with advanced Transformer architectures in real-time network control.
Xiaolan Ji, Biao Han 0003, Xiaoliang Wang 0001, Ruidong Li 0001, Jinshu Su
Comput. Networks5
2026 Towards sustainable smart agriculture: Autonomous UAV deployment and task scheduling in a cloud-Fog-Edge synergy
abstract
With the development of smart agriculture, the Agricultural Artificial Intelligence Internet of Things (Agri-AIoT) has shown great potential in fields such as farmland monitoring and precision pesticide application. However, the computationally intensive tasks generated by massive heterogeneous agricultural sensing devices pose serious challenges to real-time and sustainability. To address this issue, this paper proposes a Cloud-Fog-Edge based collaborative computing framework, decoupling the problem into unmanned aerial vehicles (UAVs) deployment and task scheduling two sequential problems. Specifically, a hierarchical optimization framework is proposed with the goal of optimizing system latency and energy consumption. In network deployment stage, a semi-supervised K-Means based UAV deployment algorithm (SKm-UD) is designed, while an improved multi-agent deterministic policy gradient (MTD 3 PG) strategy is proposed in the distributed task offloading phase, which integrates dual delay network, a lightweight local policy update mechanism, and an adaptive learning rate adjustment strategy based on zebra optimization (ZOA-L) to support efficient computation offloading decisions in partially observable environments. Simulation results show that our proposed method can quickly converge to the optimal strategy, with network energy consumption decreases by at most 30.1%. In addition, the scalability of the mechanism in large-scale Agri-AIoT scenarios is also validated.
Xingchen Wei, Jinshu Su, Congxi Song, Yusheng Xia
Comput. Networks2
2026 Semantic-Oriented Image Transmission and Resource Allocation for UAV Networks
Jianchao Zheng, Weilu Wang, Xiancai Yao, Huadong Dai, Jinshu Su
IEEE Trans. Commun.8
2026 ICCP: Toward Congestion Control Agent via Controlling Logic Decoupling and Algorithm Integration
Xiaolan Ji, Biao Han 0003, Yuedong Xu 0001, Jinshu Su
IEEE Trans. Netw. Serv. Manag.4
2025 Universally Composable Subversion-Resilient Authenticated Key Exchange
Yi Wang 0055, Rongmao Chen, Xinyi Huang 0001, Jinshu Su, Moti Yung
ASIACRYPT (2)5
2025 Can LLMs only talk? Experimental studies on task scheduling with Large Language Models
abstract
Large Language Models (LLMs) have emerged as a disruptive technology for Natural Language Processing (NLP), achieving success in NLP-related generative applications. However, the potential capability of LLMs in other domains remains largely unexplored. To explore the potential of task scheduling with LLMs, we model a typical task scheduling scenario in cloud computing and transfer scheduling problems as natural language prompts. Afterward, the knowledge and reasoning abilities of LLMs are enabled to generate scheduling decisions. Six well-known and open-source LLMs are integrated into our framework to perform experimental studies, and the results are evaluated from multiple perspectives and compared with each other. Besides, traditional heuristic algorithms and a basic Reinforcement Learning (RL) method are all performed for comparison. Our results demonstrate: 1) compared to most heuristic methods, the decisions made by LLMs achieve better scheduling performance; 2) compared to the basic RL method, LLMs exhibit better generalization on various workload patterns; 3) the larger parameter size of the LLMs has, the better scheduling performance it achieves. To the best of our knowledge, our experimental study is the first exploration to apply LLMs in task scheduling. Our findings highlight the promising potential of LLMs as a novel approach to task scheduling, offering new avenues for research and practice.
Mengjuan Li, Zhengguang Chen, Huan Zhou 0006, Yingwen Chen 0001, Baokang Zhao, Xue Ouyang 0003, Jinshu Su
ICCCN8
2025 Cellular-Snooper: A General and Real-Time Mobile Application Fingerprinting Attack in LTE Networks
Wenao Zhang, Shuhui Chen, Ziling Wei, Qianqian Xing, Jinshu Su
ICIC (4)6
2025 TrafficBM: A Dual-Modality Pre-Training Framework for Network Traffic Classification
abstract
Network traffic classification is critical for ensuring network quality, security, and stability. However, the increasing complexity of network environments and the growth of encrypted traffic bring significant challenges. Traditional rule-based, machine learning-based, and deep learning-based approaches are limited by the scarcity of plaintext, reliance on handcrafted features, and the need for large labeled datasets. Pre-training methods have alleviated these issues, but existing models mainly focus on payload semantics and lack dedicated learning of traffic behavior patterns essential for encrypted traffic characterization. Motivated by this, we propose TrafficBM, a dual-modality pre-training framework that jointly models semantic features and traffic behavior patterns. Our approach extracts dualmodality features from network traffic and applies modalityspecific data augmentation to mitigate data imbalance and scarcity. During pre-training, BERT leverages masked bigram modeling (MBM) to capture semantic information, while Mamba uses a masked autoencoder (MAE) architecture to learn traffic behavior patterns. An adaptive gating network, together with a parameter-preserving warm-up strategy, fuses features from both pre-trained models during fine-tuning to improve downstream classification performance. TrafficBM achieves state-of-the-art results on six tasks across eight datasets, including over 0.99 accuracy on five datasets and a 10 % improvement over the best baseline on Datacon2021 Part 2, demonstrating strong generalization and robustness in network traffic classification.
Minxin Wang, Junhong Liao, Jinshu Su, Ziling Wei, Shuhui Chen, Zhengpeng Li, Biying Wang
IPCCC3
2025 ROVReco: An ROV deployment recommendation approach with GNN based on routing betweenness
Jinshu Su, Bo Yu 0008
Comput. Networks3
2025 SMCCA: A sharded multi-task collaborative consensus algorithm for unmanned vehicle networks
Yongming Fu, Yingwen Chen 0001, Mengyuan Zhu, Huan Zhou 0006, Jiachao Wang, Jinshu Su
J. Syst. Archit.7
2025 Bubble-Swap Flow Control
abstract
Deadlock-free adaptive routing is extensively adopted in both on-chip and off-chip interconnection networks to improve communication bandwidth and reduce latency. Introducing virtual channels (VCs), also known as virtual lanes (VLs). This is the mainstream technique to handle deadlocks incurred by adaptive routing and also provides VC preemption for higher priority traffic. However, existing deadlock-free flow control schemes either underutilize memory resources due to inefficient buffer management to simplify hardware implementation, or rely on complicated global coordination and synchronization with very high hardware complexity. Most hardware-friendly schemes use more VCs and memory resources to enable ease of implementation of deadlock-free flow control. In contrast, sophisticated schemes achieve deadlock freedom with minimum VC cost, even eliminating additional buffer requirement through the complicated control mechanisms. In this work, we rethink the root cause of the deadlock problem from a different perspective by considering it as a lack of credit, which makes us find an efficient solution to the deadlock problem. With minor modification of credit accumulation and return, our proposed bubble-swap flow control (BSFC) ensures atomic buffer swap between two adjacent routers only based on local credit status while making full use of the buffer space. BSFC achieves a better tradeoff between implementation complexity and memory overhead and can be easily integrated in the industrial router with no modification on buffer allocation or port arbitration. The simulation results demonstrate BSFC outperforms existing bubble-based deadlock-free methods by average 64% higher throughput. We further propose a credit reservation strategy to eliminate the escape virtual channel (VC) cost for fully adaptive routing implementation. The synthesizing results demonstrate that BSFC along with credit reservation (BSFC-CR) can reduce the area and power consumption by respectively 29% and 26% in contrast to the traditional critical bubble scheme (CBS).
Kai Lu 0001, Sheng Ma, Jinshu Su, Dongsheng Li 0001
ACM Trans. Archit. Code Optim.4
2025 srTLS: Secure TLS Handshake on Corrupted Machines
abstract
TLS 1.3 is widely used to realize secure communication over the Internet. Existing security analyses of TLS 1.3 primarily focus on its handshake protocol which is indeed an authenticated key exchange (AKE) protocol, and implicitly neglect the so-called subversion attacks (e.g., breaking TLS via Dual EC) in the real world. Reverse firewall (RF) is a prevalent approach to defend against subversion attack. To the best of our knowledge, the only two subversion-resilient AKE protocols with RFs are proposed by Dodis et al. (CRYPTO'16) and Bossuat et al. (ESORICS'20). The security of both protocols is proved under game-based model which is insufficient for the concurrent execution of multiple TLS instances in practice. In this paper, we propose$\mathsf {srTLS}$, a variant of the TLS 1.3 full one round-trip time (1-RTT) handshake protocol with RFs under the universally composable (UC) model. In particular, we first present the ideal functionality of unilateral AKE$\mathcal {F}_{\mathsf {uaKE}}$. Then, we use RFs with outer transparency to circumvent the difficulty in sanitizing the messages of handshake protocol, and prove that$\mathsf {srTLS}$UC-realizes$\mathcal {F}_{\mathsf {uaKE}}$in the presence of subversion attacks. Finally, we integrate$\mathsf {srTLS}$and existing subversion-resilient AKE protocols into TLS 1.3. The evaluation result demonstrates that$\mathsf {srTLS}$achieves at least a 44.86% efficiency improvement over other subversion-resilient AKE protocols.
Yi Wang 0055, Xincheng Tang, Rongmao Chen, Xinyi Huang 0001, Jinshu Su
IEEE Trans. Dependable Secur. Comput.6
2025 Toward an Effective Few-Shot Website Fingerprinting Attack With Quadruplet Networks and Deep Local Fingerprinting Features
abstract
Website fingerprinting (WF) attacks can reveal the users' online privacy by the traffic analysis technique, even with the protection of the Tor anonymity network. Recent WF attacks tend to leverage the deep learning (DL) models, which require a large number of traffic samples for training. In this case, it is impractical for low-resource adversaries in reality. Thus, we propose a lightweight WF attack to tackle this challenge, i.e., Deep Quadruplet Fingerprinting (DQF), which only needs one training sample to obtain an accuracy of 87.1%. Regarding the overall design, DQF first combines the metric learning and meta-learning schemes. To improve the generalization ability of the trained model, DQF leverages the quadruplet networks as the architecture and modifies the quadruplet loss function. Besides, by taking the deep local fingerprinting features (DLFFs), DQF avoids losing a lot of discriminative information, which is a problem with previous attacks. To evaluate DQF, we use multiple typical datasets and conduct 11 different experiments. In closed-world settings, the accuracy of DQF can exceed the best baseline attack by 10%. In open-world settings, DQF steadily performs the best even in the most challenging scenario, namely, 1-shot learning, where previous attacks significantly degrade the performance or even fail.
Hongcheng Zou, Jinshu Su, Ziling Wei, Shuhui Chen, Chunfang Yang, Mantun Chen
IEEE Trans. Dependable Secur. Comput.2
2025 Jump Routing: Toward Scalable and Lightweight Anonymous Network
abstract
Including TOR, most of the anonymous communication systems adopt source routing, that the source has to share the globally consistent view of all relays and maintain the up-to-date information. To increase the scalability of TOR, researchers mainly utilize hop-by-hop routing during circuit extension. However, hop-by-hop routing has not been widely deployed since it suffers from route capture attacks, and most of the countermeasures require the source participate in the route extension indirectly, help verify the selection of next hop by intermediate nodes, thus introduces communication overhead. In this paper, we introduce a novel routing scheme called Jump Routing. In jump routing, the route extension follows the jumping way, that each relay chooses the successor of the next hop rather than the next hop itself. In particular, to the best of our knowledge, we are the first to route in the jumping way. In addition, to defend route capture attacks, enhance data privacy, and defend collusion attacks, we propose multiple schemes including jump verification, jump encryption, and corporative jump verification. Different from previous measures on route capture attacks, jump routingdoes not need the participation of the source, but deals with the attack by intermediate nodes only. We manage to realize the full jump routing prototype, and the evaluation results show that our jump routing is scalable, lightweight, and resilient.
Yusheng Xia, Jinshu Su, Rongmao Chen, Congxi Song
IEEE Trans. Inf. Forensics Secur.2
2025 Robustness Matters: Pre-Training Can Enhance the Performance of Encrypted Traffic Analysis
abstract
Models with large-scale parameters and pre-training have been leveraged for encrypted traffic analysis. However, existing researches primarily focused on accuracy, often overlooking the role of large-scale pre-trained parameters in enhancing robustness. While machine learning (ML) and deep learning (DL) models trained from scratch can achieve high accuracy, they exhibit limited robustness. When subjected to network noise in real-world, their identification results can fluctuate significantly, which is unacceptable. Unfortunately, current robustness evaluation methods neglect samples diversity and employ unreasonable noise settings. This field still lacks a reasonable quantitative description of models robustness. In this paper, we propose the PA-curve to display the distribution of sample’s correct-decision stability, which can simultaneously reflect the model’s accuracy and robustness. By calculating the area under the PA-curve, called PA-area, we enable the quantitative assessment of robustness for encrypted traffic analysis. Furthermore, we design a pre-trained model based on packet length sequence, and pre-trained it on TB-scale traffic. By fine-tuning on limited labeled training data, it can achieve downstream analysis tasks. We conduct experiments on five encrypted traffic datasets with different tasks. Besides accuracy, we analyzed the robustness of the pre-trained model and existing methods under common network disturbances, including packet loss, retransmission, and disorder. Experimental results demonstrated that, compared to ML-based and DL-based models trained from scratch, the pre-trained model can not only achieve high accuracy, but also exhibit greater resilience to network noise. The source code is available at https://anonymous.4open.science/r/BERT-ps-4630.
Luming Yang, Lin Liu 0018, Junjie Huang 0001, Jiangyong Shi, Shaojing Fu, Jinshu Su
IEEE Trans. Inf. Forensics Secur.7
2024 WeMu: A design of wireless network emulator
Mingtai Lv, Xiangrui Yang 0002, Huan Zhou 0006, Wenfei Wu, Yusheng Xia, Jinshu Su
APNet6
2024 srCPace: Universally Composable PAKE with Subversion-Resilience
Yi Wang 0055, Rongmao Chen, Xincheng Tang, Jinshu Su
Inscrypt (1)5
2024 Aquilas: Adaptive QoS-Oriented Multipath Packet Scheduler with Hierarchical Intelligence for QUIC
abstract
Multipath packet scheduler is responsible for deliv-ering each packet to an appropriate path. However, rules-based schedulers struggle to adapt to varying network conditions and diverse Quality of Service (QoS) requirements. Despite learning- based scheduler can adapt to various network conditions, reacting quickly to network changes is still challenging. Moreover, for diverse QoS requirements, learning-based schedulers often neces-sitates training from scratch. To solve the above challenges, we propose a multi-head mapping model that selects an optimal sub- scheduler based on the current state. It works with a shared state encoder, a multi-head Q-value decoder, and QoS-oriented reward decomposition. Furthermore, we propose Aquilas, an adaptive multi path packet scheduler with hierarchical intelligence for the Quick UDP Internet Connection (QUIC) protocol. Aquilas adopts a learning-based scheduler selector, thereby enabling selection of an optimal policy from a pool of sub-schedulers. This sub- scheduler pool encompasses a wide range of knowledge for handling various network conditions. In coarse time intervals, the learning-based scheduler selector operates, while during fine- grained time intervals, the selected sub-scheduler delivers each packet to the corresponding path. Aquilas has been evaluated in both controlled emulation and real-world networks. Compared with the state-of-the-art schedulers, Aquilas improves transmis-sion performance in various network conditions and diverse traffic types.
Congxi Song, Biao Han 0003, Ruidong Li 0001, Xueqiang Han, Jinshu Su
ICDCS6
2024 KP-WF: Cross-Domain Few-Shot Website Fingerprinting
Lin Liu 0018, Ziling Wei, Shuhui Chen, Jinshu Su
ICDF2C (2)4
2024 FingerMamba: Mamba-based Efficient Multi-tab Website Fingerprinting
abstract
Nowadays, protecting user privacy on the Internet is paramount, especially with the increasing use of the Tor network to anonymize online activities. However, Tor is vulnerable to website fingerprinting (WF), where patterns in encrypted traffic are analyzed to infer visited websites. It can be utilized to monitor and investigate illegal activities on the dark web. Existing website fingerprinting techniques typically assume single-tab browsing, which is unrealistic as users often open multiple tabs consecutively or within a short period due to Tor’s slow loading speeds and typical user habits. Moreover, current multi-tab approaches face challenges in classification speed, which is crucial for high-throughput networks. FingerMamba, our proposed model, addresses these gaps by efficiently extracting local information and establishing long-range dependencies using a Mamba-based structured state-space model. It significantly enhances the accuracy and speed of multi-tab website fingerprinting. Extensive experiments on the largest real-world multi-tab dataset demonstrate that FingerMamba effectively improves classification accuracy in both closed-world and open-world settings. Furthermore, with maintaining similar accuracy performance, FingerMamba can increase inference speed by up to four times compared to the existing methods. To our knowledge, FingerMamba is the first model to tailor the Mamba architecture for website fingerprinting.
Lin Liu 0018, Ziling Wei, Shuhui Chen, Zixuan Dong, Jinshu Su
IPCCC5
2024 AST-Trans: Detecting Web Tracking using Transformer-based Deep Learning with Abstract Syntax Tree
abstract
Web tracking has become a key tool for service providers to collect online data and analyze user behaviors, raising concerns about the privacy of Internet users. In this paper, we propose a new web tracking detection method, namely AST-Trans, which detects and removes web tracking behavior using Transformer-based deep learning with abstract syntax trees. In the method, the abstract syntax tree is built for the detected website codes. Then, a sequence generation algorithm is proposed to convert tree-like code structures into one-dimensional sequences for deep models. To enhance training efficiency, we devise a reduction strategy to simplify the code tree structure by introducing equivalent nodes. After that, a Transformer-based deep learning algorithm is introduced to realize web tracking detection. By the proposed method, the exact tracking code blocks can be identified, and thus, we can implement the tracking code removal with minimum website breakage. To verify the effectiveness of the proposed method, an HTTPS proxy with AST-Trans on it is implemented to detect and remove tracking codes. We evaluate AST-Trans with the TrackSign-labeled dataset. The results show that the proposed method can detect the tracking behavior with high precision. In addition, we validate the feasibility of the method by measuring the website page breakage.
Ziling Wei, Lin Liu 0018, Shuhui Chen, Jinshu Su
IPCCC5
2024 Subversion-Resilient Authenticated Key Exchange with Reverse Firewalls
Rongmao Chen, Yi Wang 0055, Xincheng Tang, Jinshu Su
ProvSec (2)5
2024 ConfigKG: Identify Routing Security Issues from Configurations Based on Knowledge Graph
abstract
Inadequate network configurations can lead to serious security issues. Current research, however, overlooks the integrity of the network in identifying security issues from configurations. Specifically, it lacks sufficient integration of multi-level information and lacks a certain level of scalability when facing different network situations. This paper introduces ConfigKG, a general, extensible, and comprehensible framework for identifying security issues from configurations in a network. ConfigKG utilizes configuration files to create a knowledge graph, which assists in reasoning and mining network information. Through this process, ConfigKG models networks in knowledge graphs. Drawing from properly configured routing protocol scenarios, this study translates the standard network state into a series of graph-based rules that are applied across network planes. By evaluating these rules, ConfigKG can determine the network state and find errors in configurations. This article focuses solely on identifying security issues in the configuration of routing protocols, as routing security is the primary concern related to configuration problems. An experimental scenario was conducted to assess ConfigKG, which successfully constructs a knowledge graph and accurately models the network, enabling finding security issues through rule set checks. During the experiment, ConfigKG effectively identifies misconfigurations in OSPF and BGP, as well as prefix hijacking. Additionally, ConfigKG demonstrates scalability by accommodating additional mining algorithms and rule sets, allowing for customized adjustments based on detailed requirements.
Jinshu Su, Bo Yu 0008
TrustCom3
2024 Relation-CNN: Enhancing website fingerprinting attack with relation features and NFS-CNN
Hongcheng Zou, Ziling Wei, Jinshu Su, Shuhui Chen
Expert Syst. Appl.3
2024 Blockchain and trusted reputation assessment-based incentive mechanism for healthcare services
abstract
Blockchain-based healthcare IoT technology research enhances security for smart healthcare services such as real-time monitoring and remote disease diagnosis. To incentivize positive behavior among participants within a blockchain-based smart healthcare system, existing efforts employ benefit distribution and reputation assessment methods to enhance performance. Yet, there remains a significant gap in multidimensional assessment strategies and consensus improvements in addressing complex healthcare scenarios. In this paper, we propose a blockchain and trusted reputation assessment-based incentive mechanism for healthcare services (BtRaI). BtRaI provides a realistic and comprehensive reputation assessment with feedback to motivate blockchain consensus node participation, thus effectively defending against malicious behavior in the healthcare service system. Specifically, BtRaI first introduces multiple moderation factors for comprehensive multidimensional reputation assessment and credibly records the assessment results on the blockchain. Then, we propose an improved PBFT algorithm, grounded in the reputation assessment, to augment blockchain consensus efficiency. Finally, BtRaI designs a token-based reward and punishment mechanism to motivate honest participation in the blockchain, inhibit potential misbehavior, and promote enhanced service quality in the healthcare system. Theoretical analysis and simulation experiments conducted across various scenarios demonstrate that BtRaI effectively suppresses malicious attacks in healthcare services , improves blockchain node fault tolerance rates, and achieves blockchain transaction processing efficiency within 0.5 s in a 100-node consortium chain. BtRaI’s reputation assessment and token incentive mechanism, characterized by realistic differentiation granularity and change curves, are well-suited for dynamic and complex healthcare service environments.
Zhihuang Liu, Qiu Zhang, Jinshu Su, Zhiping Cai
Future Gener. Comput. Syst.4
2024 4D-MAP: Multipath Adaptive Packet Scheduling for Live Streaming over QUIC
Congxi Song, Biao Han 0003, Jinshu Su
J. Comput. Sci. Technol.3
2024 A multi-agent collaboration scheme for energy-efficient task scheduling in a 3D UAV-MEC space
abstract
Multi-access edge computing (MEC) presents computing services at the edge of networks to address the enormous processing requirements of intelligent applications. Due to the maneuverability of unmanned aerial vehicles (UAVs), they can be used as temporal aerial edge nodes for providing edge services to ground users in MEC. However, MEC environment is usually dynamic and complicated. It is a challenge for multiple UAVs to select appropriate service strategies. Besides, most of existing works study UAV-MEC with the assumption that the flight heights of UAVs are fixed; i.e., the flying is considered to occur with reference to a two-dimensional plane, which neglects the importance of the height. In this paper, with consideration of the co-channel interference, an optimization problem of energy efficiency is investigated to maximize the number of fulfilled tasks, where multiple UAVs in a three-dimensional space collaboratively fulfill the task computation of ground users. In the formulated problem, we try to obtain the optimal flight and sub-channel selection strategies for UAVs and schedule strategies for tasks. Based on the multi-agent deep deterministic policy gradient (MADDPG) algorithm, we propose a curiosity-driven and twin-networks-structured MADDPG (CTMADDPG) algorithm to solve the formulated problem. It uses the inner reward to facilitate the state exploration of agents, avoiding convergence at the sub-optimal strategy. Furthermore, we adopt the twin critic networks for update stabilization to reduce the probability of Q value overestimation. The simulation results show that CTMADDPG is outstanding in maximizing the energy efficiency of the whole system and outperforms the other benchmarks.
Yang Li 0052, Ziling Wei, Jinshu Su, Baokang Zhao
Frontiers Inf. Technol. Electron. Eng.3
2023 Adaptive QoS-aware multipath congestion control for live streaming
Xiaolan Ji, Biao Han 0003, Cao Xu, Congxi Song, Jinshu Su
Comput. Networks5
2023 Automatic discovery of stateful variables in network protocol software based on replay analysis
abstract
Network protocol software is usually characterized by complicated functions and a vast state space. In this type of program, a massive number of stateful variables that are used to represent the evolution of the states and store some information about the sessions are prone to potential flaws caused by violations of protocol specification requirements and program logic. Discovering such variables is significant in discovering and exploiting vulnerabilities in protocol software, and still needs massive manual verifications. In this paper, we propose a novel method that could automatically discover the use of stateful variables in network protocol software. The core idea is that a stateful variable features information of the communication entities and the software states, so it will exist in the form of a global or static variable during program execution. Based on recording and replaying a protocol program’s execution, varieties of variables in the life cycle can be tracked with the technique of dynamic instrument. We draw up some rules from multiple dimensions by taking full advantage of the existing vulnerability knowledge to determine whether the data stored in critical memory areas have stateful characteristics. We also implement a prototype system that can discover stateful variables automatically and then perform it on nine programs in ProFuzzBench and two complex real-world software programs. With the help of available open-source code, the evaluation results show that the average true positive rate (TPR) can reach 82% and the average precision can be approximately up to 96%.
Bo Yu 0008, Runhao Liu 0001, Jinshu Su
Frontiers Inf. Technol. Electron. Eng.4
2023 Towards Strong Privacy Protection for Association Rule Mining and Query in the Cloud
abstract
Efficiently mining frequent itemsets and association rules on the encrypted outsourced data remains a great challenge for the time-consuming ciphertext computations. Nowadays, it has been not well addressed for privacy-preserving frequent itemsets and association rule mining schemes with mining efficiency, dataset, and query confidentiality simultaneously. In this paper, we investigate the study of privacy issues on frequent itemset mining and association rule mining on outsourced data in a two-cloud model, where the data are encrypted and outsourced by multiple owners holding different public keys. We develop several secure computation protocols based on additively homomorphic cryptosystem and additive secret sharing, which enable the clouds could securely mine the frequent itemsets and association rules. Furthermore, we also design two kinds of frequent itemset and association rule query service models, i.e., service customers query the cloud-mined results, and service customers query with their own decided threshold. The proposed scheme not only supports the mining process on the data encrypted by multiple public keys without compromising the security of the datasets, query data and query results, but also offline users. In addition, the experimental results show that our query scheme is much more efficient than the state-of-the-art work.
Lin Liu 0018, Jinshu Su, Ximeng Liu, Rongmao Chen, Xinyi Huang 0001, Guang Kou, Shaojing Fu
IEEE Trans. Cloud Comput.2
2023 In Pursuit of Beauty: Aesthetic-Aware and Context-Adaptive Photo Selection in Crowdsensing
abstract
The pervasive view of the mobile crowd bridges various real-world scenes and people's perceptions with the gathering of distributed crowdsensing photos. To elaborate informative visuals for viewers, existing techniques introduce photo selection as an essential step in crowdsensing. Yet, the aesthetic preference of viewers, at the very heart of their experiences under various crowdsensing contexts (e.g., travel planning), is seldom considered and hardly guaranteed. We propose CrowdPicker, a novel photo selection framework with adaptive aesthetic awareness for crowdsensing. With the observations on aesthetic uncertainty and bias in different crowdsensing contexts, we exploit a joint effort of mobile crowdsourcing and domain adaptation to actively learn contextual knowledge for dynamically tailoring the aesthetic predictor. Concretely, an aesthetic utility measure is invented based on the probabilistic balance formalization to quantify the benefit of photos in improving the adaptation performance. We prove the NP-hardness of sampling the best-utility photos for crowdsourcing annotation and present a (1-1/e) approximate solution. Furthermore, a two-stage distillation-based adaptation architecture is designed based on fusing contextual and common aesthetic preferences. Extensive experiments on three datasets and four raw models demonstrate the performance superiority of CrowdPicker over four photo selection baselines and four typical sampling strategies. Cross-dataset evaluation illustrates the impacts of aesthetic bias on selection.
Tongqing Zhou, Zhiping Cai, Fang Liu 0002, Jinshu Su
IEEE Trans. Knowl. Data Eng.4
2023 A Multivariate KPIs Anomaly Detection Framework With Dynamic Balancing Loss Training
abstract
Anomaly detection on multivariate KPIs (Key Performance Indicators, such as CPU utilization, sockets status, and HTTP requests per second) is of utmost importance to the systems’ reliability. Unsupervised methods have been of considerable interests and have significantly progressed due to their superior effectiveness. However, the state-of-art unsupervised anomaly detection methods still suffer from high false or missed alarm rates. To this end, in this paper, we propose MM, a practicalMultivariate KPIs anomaly detection framework following the principles ofMulti-task learning with the proposed dynamic balancing loss function. To capture KPIs’ characteristics to the most extent, we simultaneously train multiple sequential autoencoders with different connections based on a designed semi-Random Connection Recurrent Neural Network (sRC-RNN). These autoencoders can be treated as different reconstruction tasks while training. Furthermore, we propose a dynamic loss function to adaptively balance the tasks’ weights. Extensive experiments show that MM outperforms the state-of-art unsupervised multivariate KPIs anomaly detection algorithms and achieves an average F1-score of 0.95 on two public machine-level KPIs datasets and 0.96 on an internal container-level KPIs dataset.
Biao Han 0003, Ruidong Li 0001, Jinshu Su
IEEE Trans. Netw. Serv. Manag.4
2023 Realizing Fine-Grained Inference of AS Path With a Generative Measurable Process
abstract
In the global Internet, the paths between two autonomous systems (ASes), which are used for the exchange of traffic, are essential for understanding the behavior of the Internet routing system and they can help improve the performance of many applications of the Internet. Popular approaches to obtain the AS path between an AS pair (AP) are measurement based (e.g., Traceroute), but considering the size of the modern Internet and the limitations of measurement resources, only paths between a very small portion of APs can be measured. In recent years, a large body of path inference approaches has been proposed to bridge the gap in measurement resources. However, as we show with experiments, they perform poorly in accuracy and coverage. We propose a generative measurable path inference (GMPI) framework for AS-level path measurement, which performs well in accuracy and coverage. GMPI addresses two limitations of previous approaches: 1) Information incompleteness due to unrevealed real-world AS-level routing policies and insufficient measuring resources. 2) Knowledge isolation caused by distributed AS knowledge with different sources and inconsistent forms. To overcome these challenges, the data-driven GMPI framework invents heuristic path generation to address incompleteness and a dual-attention network to integrate the isolated knowledge. GMPI does not perform any measurement or impose any burden on the network. Our performance evaluation shows that our framework GMPI outperforms state-of-the-art approaches in terms of accuracy and coverage. In particular, compared to the state-of-the-art stitching-based baseline, GMPI provides a 42.45% improvement in coverage and a 39.97% improvement in accuracy. The experimental results demonstrate that GMPI can accurately infer paths for nearly arbitrary APs.
Xionglve Li, Tongqing Zhou, Zhiping Cai, Jinshu Su
IEEE/ACM Trans. Netw.4
2022 Multi-Level Text Importance Classification Architecture Based on Deep Learning
abstract
In the era of information explosion, the Internet is full of spam and false information, making it more difficult for people to obtain effective information. Since text data is the main carrier for disseminating information and knowledge, we propose a multi-level text importance classification architecture based on deep learning to enable Internet users to quickly and accurately access text content of interest. Experiments demonstrate that the proposed architecture can achieve a good performance.
Meizhen Huang, Jinshu Su, Zhong Liao, Shuhui Chen, Ziling Wei
APNet2
2022 The Extreme Counts: Modeling the Performance Uncertainty of Cloud Resources with Extreme Value Theory
Mengjuan Li, Jinshu Su, Hongyun Liu, Zhiming Zhao, Xue Ouyang 0003, Huan Zhou 0006
ICSOC2
2022 ACCeSS: Adaptive QoS-aware Congestion Control for Multipath TCP
abstract
Multipath TCP (MPTCP) enables multi-home devices to establish multiple paths for simultaneous data transmission. However, due to diverse Quality of Service (QoS) requirements in real network, existing multipath congestion control algorithms (CCAs) fail to fast adapt to dynamic traffic, which leads to performance degradation, especially in heterogeneous network environments. To tackle these problems, in this paper, we first observe the performance limitations of current multipath CCAs by conducting extensive experiments. Then we propose ACCeSS, an adaptive QoS-aware multipath congestion control framework, which is able to promptly adapt to network changes and QoS requirements with a novel control policy optimization phase. In order to adjust and stimulate improvement of the preferred performance metric, ACCeSS exploits Random Forest Regressing (RFR) method to perform QoS-specific utility function optimization. ACCeSS is implemented and compared with other multipath CCAs in Linux kernel. Performances of ACCeSS are evaluated in both emulated and real-world networks, which reveal that ACCeSS outperforms classic multipath CCAs and the state-of-the-art learning based multipath CCA with better adaptive capability of QoS.
Xiaolan Ji, Biao Han 0003, Ruidong Li 0001, Cao Xu, Jinshu Su
IWQoS6
2022 An efficient cross-domain few-shot website fingerprinting attack with Brownian distance covariance
Hongcheng Zou, Jinshu Su, Ziling Wei, Shuhui Chen, Baokang Zhao
Comput. Networks2
2022 Moving direction-based adaptive task migration in MEC
abstract
Abstract Edge computing is expected to be a promising paradigm to provide low‐latency services. Tasks from resource‐limited users can be offloaded to edge servers for efficient execution within a limit time. This innovative technique has attracted widespread attention. Task migration is one of the important problems in mobile edge computing (MEC). Taking vehicle network as an example, during the moving process, a vehicle passes through multiple edge servers and decisions about where to migrate the task need to be made. The moving direction should be emphasized since it directly determines a vehicle's trajectory. Nevertheless, few existing works take the moving direction into consideration. In this paper, task migration issue during the vehicle's mobility process is investigated and the moving direction is specifically considered. The direction helps exclude meaningless selections. The moving process can be formulated as a Markov decision process (MDP) and effort is made to design an adaptive algorithm with direction consideration, aiming at minimizing the total communication time while satisfying the deadline of each task. Based on deep Q network (DQN), we devise a Soft update and parameter Noise applied algorithm DQN‐SN, trying to enlarge action exploration space and stabilize the target network's parameter placement in training process. Besides, with the goal of building credible MEC, a credit‐based scheme is also introduced to establish a trusted edge environment. Extensive experiments are conducted to evaluate the performance of our proposed algorithm. Compared to Greedy algorithm and DQN, the total consumed task communication time of DQN‐SN shows 10–20% reduction. Furthermore, the algorithms with the direction factor always outperform the algorithms without direction consideration.
Yang Li 0052, Ziling Wei, Jinshu Su
IET Commun.3
2022 Technology trends in large-scale high-efficiency network computing
abstract
Network technology is the basis for large-scale high-efficiency network computing, such as supercomputing, cloud computing, big data processing, and artificial intelligence computing. The network technologies of network computing systems in different fields not only learn from each other but also have targeted design and optimization. Considering it comprehensively, three development trends, i.e., integration, differentiation, and optimization, are summarized in this paper for network technologies in different fields. Integration reflects that there are no clear boundaries for network technologies in different fields, differentiation reflects that there are some unique solutions in different application fields or innovative solutions under new application requirements, and optimization reflects that there are some optimizations for specific scenarios. This paper can help academic researchers consider what should be done in the future and industry personnel consider how to build efficient practical network systems.
Jinshu Su, Baokang Zhao, Jijun Cao, Ziling Wei, Congxi Song, Yusheng Xia
Frontiers Inf. Technol. Electron. Eng.1
2022 Event-Driven Computation Offloading in IoT With Edge Computing
abstract
Edge computing, which provides computation services at the edge of networks, has become a promising method to meet the massive computation demands of Internet of Things (IoT). To make full use of resources, a computation offloading scheme is needed in edge computing system. In this work, we propose an event-driven computation offloading scheme for the first time. Compared with the existing time-driven schemes, the proposed scheme has a smaller implementation complexity in some scenarios with computation-intensive task computing. In the proposed scheme, the priority of different tasks is jointly considered. To decide the optimal offloading action of the scheme, we formulate the offloading problem as a semi-Markov decision process (SMDP). Then, a model-based method is proposed to derive the optimal offloading policy under fully explored system by addressing the challengs of modeling. On the other hand, considering partially explored system, we propose an online double deep Q-network algorithm, which can deal with the poor scalability of the standard Q-learning algorithm, to derive the optimal offloading policy. In addition, we also introduce some tricks to accelerate the learning procedure. The simulation results show the superior performance of our proposed scheme.
Ziling Wei, Baokang Zhao, Jinshu Su
IEEE Trans. Wirel. Commun.3
2021 A Novel 3D Intelligent Cluster Method for Malicious Traffic Fine-Grained Classification
Baokang Zhao, Murao Lin, Ziling Wei, Qin Xin 0001, Jinshu Su
ICA3PP (1)5
2021 6Hit: A Reinforcement Learning-based Approach to Target Generation for Internet-wide IPv6 Scanning
abstract
Fast Internet-wide network measurement plays an important role in cybersecurity analysis and network asset detection. The vast address space of IPv6, however, makes it infeasible to apply a brute-force approach for scanning the entire network. Even worse, the extremely uneven distribution of IPv6 active addresses results in a low hit rate for active scanning. To address the problem, we propose 6Hit, a reinforcement learning-based target generation method for active address discovery in the IPv6 address space. It first divides the IPv6 address space into different regions according to the structural information of a set of known seed addresses. Then, it allocates exploration resources according to the reward of the scanning on each region. Based on the evaluative feedback from existing scanning results, 6Hit optimizes the subsequent search direction to regions that have a higher density of activity addresses. Compared with other state-of-the-art target generation methods, 6Hit achieves better performance on hit rate. Our experiments over real-world networks show that 6Hit achieves 3.5% - 11.5% hit rate for the eight candidate datasets, which is 7.7% - 630% improvement over the state-of-the-art methods.
Bingnan Hou, Zhiping Cai, Kui Wu 0001, Jinshu Su, Yinqiao Xiong
INFOCOM4
2021 ModelCoder: A Fault Model based Automatic Root Cause Localization Framework for Microservice Systems
abstract
Microservice system is an architectural style to develop a single application as a suite of small services running in its process and communicating with lightweight message mechanisms. Although microservice architecture enables rapid, frequent and reliable delivery of large, complex applications, it is increasingly challenging for operational staffs to locate the root cause of a microservice fault, which usually occurs on a service node and propagates to affect the entire system. To this end, in this paper, we first introduce the concept of deployment graph and service dependency graph to depict the deployment status and calling relationship between service nodes. Then we formulate the root cause localization problem in microservice systems based on the constructed graphs, in which fault model is defined to capture the characteristics of a fault’s root cause. A fault model based automatic root cause localization framework called ModelCoder is later developed to figure out the root cause of unknown faults by comparing with the predefined fault models. We evaluate ModelCoder on a real-world microservice system monitoring data set spanning 15 days. Through extensive experiments, it is revealed that ModelCoder can localize the fault root cause nodes within 80 seconds on average and improve the root cause localization accuracy (to 93%) by 12% compared with the state-of-the-art root cause localization algorithm.
Biao Han 0003, Jie Li 0002, Jinshu Su
IWQoS5
2021 SeqAD: An Unsupervised and Sequential Autoencoder Ensembles based Anomaly Detection Framework for KPI
abstract
Key Performance Indicator (KPI), a kind of time-series data, its anomalies are the most intuitive characteristics when failures occurred in IT systems. KPI anomaly detection is increasingly critical to provide reliable and stable services for IT systems. Unsupervised learning is a promising method because of lacking labels and the unbalance in KPI samples. However, existing unsupervised KPI anomaly detection methods suffer from high false alarm rates. They handle KPI sequence as non-sequential data and ignore the time information, which is an essential KPI character. To this end, in this paper, we propose an unsupervised and sequential autoencoder ensembles based anomaly detection framework called SeqAD. SeqAD inherits the advantages both from the sequence-to-sequence model and autoencoder ensembles. SeqAD reduces the KPI over-fitting problem effectively by introducing autoencoder ensembles. In order to better capture the time information of KPI, we propose a random step connection based recurrent neural network (RSC-RNN) to train the KPI sequence, which can provide random connections to construct autoencoders with different structures and retain time information to the most extent. Extensive experiments are conducted on two public KPI data-sets from real-world deployed systems to evaluate the efficiency and robustness of our proposed SeqAD framework. Results show that SeqAD is able to smoothly capture most of the characteristics in all KPI data-sets, as well as to achieve a high F1 score between 0.93 and 0.98, which is better than the state-of-art unsupervised KPI anomaly detection methods.
Biao Han 0003, Jinshu Su
IWQoS4
2021 TraceModel: An Automatic Anomaly Detection and Root Cause Localization Framework for Microservice Systems
abstract
Microservice system is a web application architecture that divides a single application into a suite of service nodes running as separate processes and communicating with lightweight message mechanisms. Although microservice can improve the abstraction, modularity and extensibility of web applications, it makes the anomaly detection and fault root cause localization more challenging for operational staff. To this end, in this paper, we first introduce the concept of service dependency graph (SDG) to depict the complex calling relationship between nodes and then develop an anomaly detection and root cause localization framework called TraceModel which consists of TraceVAE and ModelCoder. TraceVAE divides user requests into different request classes according to well-constructed trace and analysis them separately with variational autoencoder(VAE) to figures out abnormal requests. Based on the anomaly detection results of TraceVAE, ModelCoder localizes the root cause of unknown faults by comparing their fault features with the predefined fault models. By evaluating TraceModel on a realworld microservice system monitoring data set spanning 15 days, it is revealed that TraceModel can detect the anomaly and localize the fault root cause nodes within 110 seconds on average. Furthermore, it improves the root cause localization accuracy (to 97%) by 17.5% compared with the state-of-the-art root cause localization algorithm.
Biao Han 0003, Jinshu Su, Xiaoyan Wang 0003
MSN3
2021 A Probabilistic Resilient Routing Scheme for Low-Earth-Orbit Satellite Constellations
Ziling Wei, Baokang Zhao, Jinshu Su, Qin Xin 0001
WASA (3)4
2021 Balancing anonymity and resilience in anonymous communication networks
Yusheng Xia, Rongmao Chen, Jinshu Su, Hongcheng Zou
Comput. Secur.3
2021 Enforcing trustworthy cloud SLA with witnesses: A game theory-based model using smart contracts
abstract
There lacks trust between the cloud customer and provider to enforce traditional cloud SLA (Service Level Agreement) where the blockchain technique seems a promising solution. However, current explorations still face challenges to prove that the off-chain SLO (Service Level Objective) violations really happen before recorded into the on-chain transactions. In this paper, a witness model is proposed implemented with smart contracts to solve this trust issue. The introduced role, "Witness", gains rewards as an incentive for performing the SLO violation report, and the payoff function is carefully designed in a way that the witness has to tell the truth, for maximizing the rewards. This fact that the witness has to be honest is analyzed and proved using the Nash Equilibrium principle of game theory. For ensuring the chosen witnesses are random and independent, an unbiased selection algorithm is proposed to avoid possible collusions. An auditing mechanism is also introduced to detect potential malicious witnesses. Specifically, we define three types of malicious behaviors and propose quantitative indicators to audit and detect these behaviors. Moreover, experimental studies based on Ethereum blockchain demonstrate the proposed model is feasible, and indicate that the performance, ie, transaction fee, of each interface follows the design expectations.
Huan Zhou 0006, Xue Ouyang 0003, Jinshu Su, Cees T. A. M. de Laat, Zhiming Zhao
Concurr. Comput. Pract. Exp.3
2021 A novel blockchain-based privacy-preserving framework for online social networks
abstract
Online social networks (OSNs) are nowadays an important field of applications thanks to the recent surge in online interaction. However, the illegal disclosure of user's private data can cause damaging consequences and even threaten the safety of users' life. The privacy issues of OSNs have become a matter of great concern for many people. In recent years, there are some research works to address this privacy issue, yet they do not always focus on providing the normal social network services for users, such as data sharing, data retrieval and data access services. Therefore, it is a challenge to ensure the security of sensitive data while providing efficient and privacy-preserving social network services for users. In this paper, we propose a novel blockchain-based privacy-preserving framework for online social networks, called BPP. Combined blockchain and public-key cryptography technique, the BPP framework can achieve secure data sharing, data retrieving, and data accessing with fairness and without worrying about potential damage to users' interest. Specifically, based on blockchain and public key encryption with keyword search technique, a secure, fair and efficient keyword search algorithm is proposed, with which the BBP framework realises privacy preservation of user's query and then obtain accurate query results with assurance and without needing for any further verification operation in online social network. Finally, we implement a prototype of our framework and deploy it to a locally simulated network. The extensive experiments and security analysis demonstrate the security, efficacy and efficiency of our proposed framework.
Shiwen Zhang 0004, Arthur Sandor Voundi Koe, Tien-Hsiung Weng, Wei Liang 0005, Jinshu Su
Connect. Sci.6
2021 DIIA: Blockchain-Based Decentralized Infrastructure for Internet Accountability
abstract
The Internet lacking accountability suffers from IP address spoofing, prefix hijacking, and DDoS attacks. Global PKI-based accountable network involves harmful centralized authority abuse and complex certificate management. The inherently accountable network with self-certifying addresses is incompatible with the current Internet and faces the difficulty of revoking and updating keys. This study presents DIIA, a blockchain-based decentralized infrastructure to provide accountability for the current Internet. Specifically, DIIA designs a public-permissioned blockchain called TIPchain to act as a decentralized trust anchor, allowing cryptographic authentication of IP addresses without any global trusted authority. DIIA also proposes the revocable trustworthy IP address bound to the cryptographic key, which supports automatic key renewal and efficient key revocation and eliminates complexity certificate management. We present several security mechanisms based on DIIA to show how DIIA can help to enhance network layer security. We also implement a prototype system and experiment with real-world data. The results demonstrate the feasibility and suitability of our work in practice.
Pengkun Li, Jinshu Su, Xiaofeng Wang 0002, Qianqian Xing
Secur. Commun. Networks2
2021 APGS: An Efficient Source-Accountable and Metadata-Private Protocol in the Network Layer
abstract
Due to the revelations of global-scale pervasive surveillance programs, Internet users have an increasing demand for privacy. However, this is usually undesirable for network service providers because attackers would be able to anonymize themselves and avoid regulation while conducting network attacks. Therefore, network service providers want to hold users accountable and it has been widely considered as a tussle to find a good balance point between the accountability and privacy for the Internet. In this work, we first show that existing representative approaches mainly suffer from narrow-range accountability, low efficiency or risky key management. Motivated by these observations, we propose an efficient network layer protocol called APGS to balance the accountability and privacy. At the core of our APGS is the group signature which, however, is not trivial to apply for the network layer mainly due to the efficiency, revocation, and privacy issues. We manage to overcome these challenges via proposing some novel approaches, including challenge-based cache strategy, scalable verifier-local revocation strategy, and Onion-then-Case strategy. We then evaluate the efficiency of APGS and conclude that in our environment, APGS can generate packets up to 20k pkts/s on a desktop and achieve approximately 80% of IP's goodput at most on a software router.
Yusheng Xia, Jinshu Su, Rongmao Chen, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.2
2020 Hybrid Routing: Towards Resilient Routing in Anonymous Communication Networks
abstract
Anonymous communication networks (ACNs) are intended to protect the metadata during communication. As classic ACNs, onion mix-nets are famous for strong anonymity, in which the source defines a static path and wraps the message multi-times with the public keys of nodes on the path, through which the message is relayed to the destination. However, onion mix-nets lacks in resilience when the static on-path mixes fail. Mix failure easily results in message loss, communication failure, and even specific attacks. Therefore, it is desirable to achieve resilient routing in onion mix-nets, providing persistent routing capability even though node failure. The state-of-theart solutions mainly adopt mix groups and thus need to share secret keys among all the group members which may cause single point of failure. To address this problem, in this work we propose a hybrid routing approach, which embeds the onion mix-net with hop-by-hop routing to increase routing resilience. Furthermore, we propose the threshold hybrid routing to achieve better key management and avoid single point of failure. As for experimental evaluations, we conduct quantitative analysis of the resilience and realize a local T-hybrid routing prototype to test performance. The experimental results show that our proposed routing strategy increases routing resilience effectively, at the expense of acceptable latency.
Yusheng Xia, Rongmao Chen, Jinshu Su
ICC3
2020 ME-TLS: Middlebox-Enhanced TLS for Internet-of-Things Devices
abstract
In-network middleboxes are vital for the Internet-of-Things (IoT) system security, but the widely adopted transport layer security (TLS) protocol blinds application-level middleboxes due to the encryption of traffic data. To resolve this problem, many solutions have been proposed to date. Among them, SplitTLS is widely adopted in the industry by proxy manufacturers. It requires TLS client to install customized root certificates and incurs additional security flaws, e.g., disabling server authentication and using weak cipher suites. Another approach is to customize the TLS protocol where middleboxes are enabled via either performing handshake directly with TLS endpoints or receiving session key materials in an out-of-band manner. Overall, current solutions would either jeopardize the original TLS handshake procedure or incur additional overheads on the endpoints. In this article, we design a new middlebox-enhanced TLS (ME-TLS), which enables endpoints to introduce authenticated middleboxes into a TLS session while control middleboxes' access permission and processing order of traffic data. Particularly, in our proposed ME-TLS, the handshake structure of TLS keeps unchanged and middleboxes work in a passive manner. That is, middleboxes in the ME-TLS could recover session key materials by monitoring handshake messages passively instead of interacting with endpoints; secondary secure channels for key transmission are also not needed in our ME-TLS. We implement our ME-TLS based on the TLS 1.3 protocol and evaluate its performances. The experimental results demonstrate that our proposal is practical and deployable for real-world IoT scenarios.
Jie Li 0041, Rongmao Chen, Jinshu Su, Xinyi Huang 0001, Xiaofeng Wang 0002
IEEE Internet Things J.3
2020 iTLS: Lightweight Transport-Layer Security Protocol for IoT With Minimal Latency and Perfect Forward Secrecy
abstract
Enabling end-to-end secure communication is essential for many Internet-of-Things (IoT) application scenarios. Transport-layer security (TLS) and datagram TLS (DTLS) are the de-facto protocols for communication security in the IP-based IoT. However, the current authentication approaches of TLS are confronted with the heavy overhead and security issues in the resource-constrained IoT scenario. On the other hand, the identity-based cryptography (IBC) becomes an attractive cryptographic solution for the IoT. Unfortunately, the current IBC-based proposals exist the problem of either high communication latency or low level of security. In this article, we propose the first lightweight secure transport protocol called iTLS, which delivers protected data in the first flight with perfect forward secrecy, and provides implicit mutual authentication without certificates. iTLS dynamically generates identity-based early keys before receiving a server response, allowing clients to send the encrypted data without additional round trips. Furthermore, it employs the ephemeral secret ticket to obtain an ephemeral server key in the previous connection. Therefore, the early key established afterward can provide full forward secrecy. Design and implementation in the form of extension make iTLS fully compatible with TLS 1.3 and easy to be converted to a DTLS version. Our evaluation shows that iTLS reduces the network traffic overhead by at least 61.2%, and handshake latency on an ideal network by at least 60% compared to the certificate-based TLS. The results demonstrate iTLS achieves strong adaptability on the low-power and lossy IoT networks.
Pengkun Li, Jinshu Su, Xiaofeng Wang 0002
IEEE Internet Things J.2
2020 Towards Practical Privacy-Preserving Decision Tree Training and Evaluation in the Cloud
abstract
Due to the capacity of storing massive data and providing huge computing resources, cloud computing has been a desirable platform for doing machine learning. However, the issue of data privacy is far from being well solved and thus has been a general concern in the cloud-aided machine learning. In this work, we investigate the study of how to efficiently do decision tree training and evaluation in the cloud and meanwhile achieve privacy preservation. Unlike existing cloud server-assisted model training approaches, in our proposed solution, the whole training process is mostly done by the cloud service provider who owns the machine learning model. Since the cloud cannot directly divide the encrypted dataset according to the best attributes selected, we propose a new method for decision tree training without dataset splitting. Precisely, we design three methods for decision tree training with the different tradeoff between privacy and efficiency. In all of these methods, the outsourced data are not revealed to the cloud service provider. We also propose a privacy-preserving decision tree evaluation scheme where the cloud service provider learns nothing about the user's input and the classification result while the trained model is kept secret to the user who could only learn the classification result. Compared with previous decision tree evaluation work, our scheme achieves desirable privacy preservation against both the user and the cloud service provider, and also minimizes the user's computation and communication costs. Moreover, besides protecting the data confidentiality, our proposed scheme also supports off-line users and thus has good scalability. The real-world dataset-based experimental results demonstrate that our system is of desirable utility and efficiency.
Lin Liu 0018, Rongmao Chen, Ximeng Liu, Jinshu Su, Linbo Qiao
IEEE Trans. Inf. Forensics Secur.4
2020 Distributed Opportunistic Scheduling in Cooperative Networks With RF Energy Harvesting
abstract
In this paper, the problem of distributed opportunistic channel access in wireless cooperative networks is investigated. To cope with the energy limitation problem of relay nodes, radio-frequency (RF) energy harvesting is considered, and thus, no external energy is needed for each relay node. Then, a novel distributed opportunistic scheduling (DOS) scheme is proposed. In the scheme, users contend for the channel access opportunity by random access, and then, the user with a successful contention makes a decision whether to give up the opportunity after probing the source-to-relay link and relay-to-destination link by following a strategy. To maximize the average throughput of the network, the optimal strategy of the proposed scheme, which is to help the user to decide whether to give up the transmission opportunity, is derived by optimal stopping theory. The obtained optimal strategy has a threshold-based structure, and thus, it is easy to implement in practice. In addition, the threshold can be calculated off-line by a proposed low-complexity algorithm. Simulation results are provided to demonstrate the superior performance of the proposed DOS scheme.
Ziling Wei, Jinshu Su, Baokang Zhao, Xicheng Lu
IEEE/ACM Trans. Netw.2
2020 Real Network Traffic Collection and Deep Learning for Mobile App Identification
abstract
The proliferation of mobile devices over recent years has led to a dramatic increase in mobile traffic. Demand for enabling accurate mobile app identification is coming as it is an essential step to improve a multitude of network services: accounting, security monitoring, traffic forecasting, and quality-of-service. However, traditional traffic classification techniques do not work well for mobile traffic. Besides, multiple machine learning solutions developed in this field are severely restricted by their handcrafted features as well as unreliable datasets. In this paper, we propose a framework for real network traffic collection and labeling in a scalable way. A dedicated Android traffic capture tool is developed to build datasets with perfect ground truth. Using our established dataset, we make an empirical exploration on deep learning methods for the task of mobile app identification, which can automate the feature engineering process in an end-to-end fashion. We introduce three of the most representative deep learning models and design and evaluate our dedicated classifiers, namely, a SDAE, a 1D CNN, and a bidirectional LSTM network, respectively. In comparison with two other baseline solutions, our CNN and RNN models with raw traffic inputs are capable of achieving state-of-the-art results regardless of TLS encryption. Specifically, the 1D CNN classifier obtains the best performance with an accuracy of 91.8% and macroaverage F-measure of 90.1%. To further understand the trained model, sample-specific interpretations are performed, showing how it can automatically learn important and advanced features from the uppermost bytes of an app’s raw flows.
Xin Wang 0076, Shuhui Chen, Jinshu Su
Wirel. Commun. Mob. Comput.3
2019 Cooperative Sensing in Cognitive Radio Ad Hoc Networks
abstract
Cognitive radio technology can largely enhance spectrum utilization efficiency by dynamic spectrum access. In cognitive radio, spectrum sensing is essential to protect the transmission of primary users (PUs). To improve the sensing accuracy, cooperative sensing has been introduced in the literature. However, there are still some challenges on cooperative sensing, especially in Cognitive Radio Ad Hoc Networks (CRAHNs) in which a centralized coordinator does not exist. In this paper, we deal with the challenges of cooperative sensing in CRAHNs, with focus on sensing data fusion and security. An overview of existing research efforts is given first, and thus, the research challenges are identified and discussed in details. To solve those challenges, we propose a cooperative sensing scheme for CRAHNs. In order to reduce the communication overhead, we partition the secondary users (SUs) to several clusters, and in each cluster, a cluster head is selected to serve as the representative for the cluster. An efficient consensus-based method with security consideration is proposed to obtain the accurate final sensing result. Extensive simulation is conducted based on real scenarios to evaluate the performance of the proposed scheme.
Ziling Wei, Baokang Zhao, Jinshu Su
ICC3
2019 A Heterogeneous Parallel Packet Processing Architecture for NFV Acceleration
abstract
Network function virtualization (NFV) offers a new way to design, deploy and manage networking services. It is of vital importance to exploit heterogeneous parallelism between hardware and software, in order to improve virtulization performance and quality of virtualized network services. In this poster, we propose a novel heterogeneous parallel architecture that highly exploits the parallelism inside packet processing, and implementation efficacy with hardware processing engines and software threads. We present two packet processing pipelines with three implemented VNF instances to better demonstrate the efficiency of heterogeneous parallelism in accelerating NFV. We show the performance of our proposed architecture with various virtualized requirements and traffics in a well-deployed network environment. Experimental results reveal that it can achieve accelerated NFV performance, as well as provide a wide class of VNFs to improve the quality of virtualized network services.
Jinshu Su, Biao Han 0003, Gaofeng Lv, Tao Li 0008, Zhigang Sun 0002
ICNP1
2019 A Blockchain based Witness Model for Trustworthy Cloud Service Level Agreement Enforcement
abstract
Traditional cloud Service Level Agreement (SLA) suffers from lacking a trustworthy platform for automatic enforcement. The emerging blockchain technique brings in an immutable solution for tracking transactions among business partners. However, it is still very challenging to prove the credibility of possible violations in the SLA before recording them onto the blockchain. To tackle this challenge, we propose a witness model using game theory and the smart contract techniques. The proposed model extends the existing service model with a new role called “witness” for detecting and reporting service violations. Witnesses gain revenue as an incentive for performing these duties, and the payoff function is carefully designed in a way that trustworthiness is guaranteed: in order to get the maximum profit, the witness has to always tell the truth. This is analyzed and proved through game theory using the Nash equilibrium principle. In addition, an unbiased sortition algorithm is proposed to ensure the randomness of the independent witnesses selection from the decentralized witness pool, to avoid possible unfairness or collusion. An auditing mechanism is also introduced in the paper to detect potential irrational or malicious witnesses. We have prototyped the system leveraging the smart contracts of Ethereum blockchain. Experimental results demonstrate the feasibility of the proposed model and indicate good performance in accordance with the design expectations.
Huan Zhou 0006, Xue Ouyang 0003, Zhijie Ren, Jinshu Su, Cees T. A. M. de Laat, Zhiming Zhao
INFOCOM4
2019 Practical privacy-preserving deep packet inspection outsourcing
abstract
Summary Hardware‐based middleboxes are ubiquitous in computer networks, which usually incur high deployment and management expenses. A recently arising trend aims to address those problems by outsourcing the functions of traditional hardware‐based middleboxes to high volume servers in a cloud. This technology is promising but still faces a few challenges from different aspects, including privacy concerns, middlebox functionality, and performance. In this paper, we propose two practical approaches to implementing a cloud‐based DPI middlebox. The outsourced DPI middlebox performs payload inspection over encrypted traffic while preserving the privacy of both communication data and inspection rules. Our first approach employs a modified reversible sketch structure, which is used for efficient error‐free membership testing, and our second approach extends the famous AC pattern matching algorithm to the cipher text domain. We utilize unkeyed one‐way hash functions instead of complex cryptographic protocols to achieve the privacy preservation requirements. Our system supports a wide range of real‐world inspection rules. We conduct evaluations on the ClamAV rule set, and the experiment results demonstrate the effectiveness of our proposals.
Jie Li 0041, Jinshu Su, Rongmao Chen, Xiaofeng Wang 0002, Shuhui Chen
Concurr. Comput. Pract. Exp.2
2019 Toward Highly Secure Yet Efficient KNN Classification Scheme on Outsourced Cloud Data
abstract
Nowadays, outsourcing data and machine learning tasks, e.g.,$k$-nearest neighbor (KNN) classification, to clouds has become a scalable and cost-effective way for large scale data storage, management, and processing. However, data security and privacy issue have been a serious concern in outsourcing data to clouds. In this article, we propose a privacy-preserving KNN classification scheme on cloud data in a twin-cloud model based on an additively homomorphic cryptosystem and secret sharing. Compared with existing works, we redesign a set of lightweight building blocks, such as secure square Euclidean distance, secure comparison, secure sorting, secure minimum, and maximum number finding, and secure frequency calculating, which achieve the same security level but with higher efficiency. In our scheme, data owners stay offline, which is different from secure-multiparty computation-based solutions which require data owners’ stay online during computation. In addition, query users do not interact with the cloud except sending query data and receiving the query results. Our security analysis shows that the scheme protects outsourced data security and query privacy, and hides access patterns. The experiments on real-world dataset indicate that our scheme is significantly more efficient than existing schemes.
Lin Liu 0018, Jinshu Su, Ximeng Liu, Rongmao Chen, Robert H. Deng, Xiaofeng Wang 0002
IEEE Internet Things J.2
2019 Dynamic Edge Computation Offloading for Internet of Things With Energy Harvesting: A Learning Method
abstract
Mobile edge computing (MEC) has recently emerged as a promising paradigm to meet the increasing computation demands in Internet of Things (IoT). However, due to the limited computation capacity of the MEC server, an efficient computation offloading scheme, which means the IoT device decides whether to offload the generated data to the MEC server, is needed. Considering the limited battery capacity of IoT devices, energy harvesting (EH) is introduced to enhance the lifetime of the IoT systems. However, due to the unpredictability nature of the generated data and the harvested energy, it is a challenging problem when designing an effective computation offloading scheme for the EH MEC system. To cope with this problem, we model the computation offloading process as a Markov decision process (MDP) so that no prior statistic information is needed. Then, reinforcement learning algorithms can be adopted to derive the optimal offloading policy. To address the large time complexity challenge of learning algorithms, we first introduce an after-state for each state-action pair so that the number of states in the formulated MDP is largely decreased. Then, to deal with the continuous state space challenge, a polynomial value function approximation method is introduced to accelerate the learning process. Thus, an after-state reinforcement learning algorithm for the formulated MDP is proposed to obtain the optimal offloading policy. To provide efficient instructions for real MEC systems, several analytical properties of the offloading policy are also presented. Our simulation results validate the great performance of our proposed algorithm, which significantly improves the achieved system reward under a reasonable complexity.
Ziling Wei, Baokang Zhao, Jinshu Su, Xicheng Lu
IEEE Internet Things J.3
2019 Identifying Known and Unknown Mobile Application Traffic Using a Multilevel Classifier
abstract
Due to the proliferation of mobile applications, mobile traffic identification plays a crucial role in understanding the network traffic. However, the pervasive unconcerned apps and the emerging apps pose great challenges to the mobile traffic identification method based on supervised machine learning, since such method merely identifies and discriminates several apps of interest. In this paper we propose a three-layer classifier using machine learning to identify mobile traffic in open-world settings. The proposed method has the capability of identifying traffic generated by unconcerned apps and zero-day apps; thus it can be applied in the real world. A self-collected dataset that contains 160 apps is used to validate the proposed method. The experimental results show that our classifier achieves over 98% precision and produces a much smaller number of false positives than that of the state of the art.
Shuhui Chen, Yipin Sun, Zhiping Cai, Jinshu Su
Secur. Commun. Networks5
2019 CloudsStorm: A framework for seamlessly programming and controlling virtual infrastructure functions during the DevOps lifecycle of cloud applications
abstract
Summary The infrastructure‐as‐a‐service (IaaS) model of cloud computing provides virtual infrastructure functions (VIFs), which allow application developers to flexibly provision suitable virtual machines' (VM) types and locations, and even configure the network connection for each VM. Because of the pay‐as‐you‐go business model, IaaS provides an elastic way to operate applications on demand. However, in current cloud applications DevOps (software development and operations) lifecycle, the VM provisioning steps mainly rely on manually leveraging these VIFs. Moreover, these functions cannot be programmatically embedded into the application logic to control the infrastructure at runtime. Especially, the vendor lock‐in issue, which different clouds provide different VIFs, also enlarges this gap between the cloud infrastructure management and application operation. To mitigate this gap, we designed and implemented a framework, CloudsStorm, which enables developers to easily leverage VIFs of different clouds and program them into their cloud applications. To be specific, CloudsStorm empowers applications with infrastructure programmability at design‐level, infrastructure‐level, and application‐level. CloudsStorm also provides two infrastructure controlling modes, ie, active and passive mode, for applications at runtime. Besides, case studies about operating task‐based and big data applications on clouds show that the monetary cost is significantly reduced through the seamless and on‐demand infrastructure management provided by CloudsStorm. Finally, the scaling and recovery operation evaluations of CloudsStorm are performed to show its controlling performance. Compared with other tools, ie, “jcloud” and “cloudinit.d”, the scaling and provisioning performance evaluations demonstrate that CloudsStorm can achieve at least 10% efficiency improvement in our experiment settings.
Huan Zhou 0006, Yang Hu 0013, Xue Ouyang 0003, Jinshu Su, Spiros Koulouzis, Cees T. A. M. de Laat, Zhiming Zhao
Softw. Pract. Exp.4
2019 A Cost-Efficient Router Architecture for HPC Inter-Connection Networks: Design and Implementation
abstract
High-radix routers with lower latency and higher bandwidth play an increasingly important role in constructing large-scale interconnection networks such as those used in super-computers and datacenters. The tile-based crossbar approach partitions a single large crossbar into many small tiles and can considerably reduce the complexity of arbitration while providing higher throughput than the conventional switch implementation. However, it is not scalable due to power consumption, placement, and routing problems. Inspired by non-saturated throughput theory, this paper proposes a scalable router microarchitecture, termed Multiport Binding Tile-based Router (MBTR). By aggregating multiple physical ports into a single tile a high-radix router can be flexibly organized into different tile arrays, thus the number of tiles and hardware overhead can be considerably reduced. For a radix-64 router MBTR achieves up to$50 \sim 75\%$reduction in memory consumption as well as wire area compared with a hierarchical switch. We theoretically deduce the sufficient and necessary conditions for the asymmetrical crossbar to achieve un-saturated relative 100 percent throughput. Based on this observation we analyze the MBTR throughput and derive the condition that should be satisfied by the MBTR design parameters to yield 100 percent throughput. We further discuss how to make a trade-off between MBTR parameters based on the constraints of performance, power and area. The simulation results demonstrate MBTR is indistinguishable from the YARC router in terms of throughput and delay, and can even outperform it by reducing potential contention for output ports. We have fabricated a 36-port MBTR chip at 28 nm, providing 100 Gb/s bidirectional bandwidth per port, with a fall-through latency of just 30 ns. Internally it runs at 9.6 Tb/s, thus offering a speedup of$1.34\times$.
Kai Lu 0001, Liquan Xiao, Jinshu Su
IEEE Trans. Parallel Distributed Syst.4
2018 Empowering Dynamic Task-Based Applications with Agile Virtual Infrastructure Programmability
abstract
The IaaS (Infrastructure-as-a-Service) offered by Clouds provides applications with the capability of customizing VMs and configuring their network. Compared to traditional service-based IaaS applications such as persistent web services, most task-based applications have a relatively short duration but are triggered on demand. A typical way to support such kinds of application is to provision a shared and fixed virtual infrastructure based on pre-estimated size in advance, and then perform all the processing tasks. However, due to unpredictable workloads, this solution can lead to either cost inefficiency caused by over-provisioning, or failure to deliver the performance required by applications. CloudsStorm is a dynamic control framework proposed to provide applications with agile programmability and flexibility in controlling the virtual infrastructure. With its front end, applications can design their networked infrastructure and program that infrastructure with our interpreted infrastructure code language. With the back-end engine, the infrastructure code can be executed to provision the networked infrastructure, deploy and execute the application to obtain results, and release resources. Moreover, we adopt multi-threading to support parallel operation. Finally, we conduct experiments in an assumed scenario to demonstrate functionalities of CloudsStorm. The evaluation results prove CloudsStorm is efficient for task-based applications that need to exploit Clouds but reduce the monetary cost.
Huan Zhou 0006, Yang Hu 0013, Jinshu Su, Mingmin Chi, Cees T. A. M. de Laat, Zhiming Zhao
IEEE CLOUD3
2018 Privacy-Preserving Mining of Association Rule on Outsourced Cloud Data from Multiple Parties
Lin Liu 0018, Jinshu Su, Rongmao Chen, Ximeng Liu, Xiaofeng Wang 0002, Shuhui Chen, Ho-fung Leung
ACISP2
2018 OverWatch: A Cross-Plane DDoS Attack Defense Framework with Collaborative Intelligence in SDN
abstract
Distributed Denial of Service (DDoS) attacks are one of the biggest concerns for security professionals. Traditional middle-box based DDoS attack defense is lack of network-wide monitoring flexibility. With the development of software-defined networking (SDN), it becomes prevalent to exploit centralized controllers to defend against DDoS attacks. However, current solutions suffer with serious southbound communication overhead and detection delay. In this paper, we propose a cross-plane DDoS attack defense framework in SDN, called OverWatch, which exploits collaborative intelligence between data plane and control plane with high defense efficiency. Attack detection and reaction are two key procedures of the proposed framework. We develop a collaborative DDoS attack detection mechanism, which consists of a coarse-grained flow monitoring algorithm on the data plane and a fine-grained machine learning based attack classification algorithm on the control plane. We propose a novel defense strategy offloading mechanism to dynamically deploy defense applications across the controller and switches, by which rapid attack reaction and accurate botnet location can be achieved. We conduct extensive experiments on a real-world SDN network. Experimental results validate the efficiency of our proposed OverWatch framework with high detection accuracy and real-time DDoS attack reaction, as well as reduced communication overhead on SDN southbound interface.
Biao Han 0003, Xiangrui Yang 0002, Zhigang Sun 0002, Jinshu Su
Secur. Commun. Networks5
2018 CSR: Classified Source Routing in Distributed Networks
abstract
In recent years cloud computing provides a new way to address the constraints of limited energy, capabilities, and resources. Distributed hash table (DHT) based distributed networks have become increasingly important for efficient communication in large-scale cloud systems. Previous studies mainly focus on improving the performance such as latency, scalability and robustness, but seldom consider the security demands on the routing paths, for example, bypassing untrusted intermediate nodes. Inspired by Internet source routing, in which the source nodes specify the routing paths taken by their packets, this paper presents CSR, a tag-based, Classified Source Routing scheme in distributed networks to satisfy the security demands on the routing paths. Different from Internet source routing which requires some map of the overall network, CSR operates in a distributed manner where nodes with certain security level are tagged with a label and routing messages requiring that level of security are forwarded only to the qualified next-hops. We show how this can be achieved efficiently, by simple extensions of the traditional routing structures, and safely, so that the routing is uniformly convergent. The effectiveness of our proposals is demonstrated through theoretical analysis and extensive simulations.
Yiming Zhang 0003, Dongsheng Li 0001, Zhigang Sun 0002, Feng Zhao 0012, Jinshu Su, Xicheng Lu
IEEE Trans. Cloud Comput.5
2017 PriMal: Cloud-Based Privacy-Preserving Malware Detection
Hao Sun 0004, Jinshu Su, Xiaofeng Wang 0002, Rongmao Chen, Qiaolin Hu
ACISP (2)2
2017 EffiEye: Application-aware Large Flow Detection in Data Center
abstract
With the rapid development of cloud computing, thousands of servers and various cloud applications are involved in data center. These changes result in more and more complex flows in data center, which motivates the need for faster, lower overhead, more scalable large flow detection technology. This paper firstly shows the shortcomings of the traditional large flow detection technologies. Then it proposes a new method named EffiEye, which efficiently realizes application-aware large flow detection in the controller. EffiEye mainly replies on two different mechanisms: one is the flow classification based on the pre-classification of cloud applications in App Info module, which can ensure the fast detecting speed, the other is the flow-stat triggering supported by OpenFlow 1.5, which can ensure the high detecting accuracy.
Binfeng Wang, Jinshu Su, Jinsheng Deng
CCGrid2
2017 Automatic privacy leakage detection for massive android apps via a novel hybrid approach
abstract
Android apps frequently leak private data off the device with or without intentions. Researchers have proposed a large number of methods, for example, static and dynamic analysis methods, to pick out the apps which tend to leak private data. However, they are only able to identify part of private data leakage vulnerabilities, due to the dynamic features in codes or code coverage problem. This paper presents a novel hybrid approach that can find out more private data leakages than the existing static or dynamic methods. The approach, realized in a tool, called HybriDroid, which employs both static and dynamic analysis methods to extract the models of each apps, and then refines the behavior model to a more adequate one according to the dynamic analysis result. As a consequence, HybriDroid inherits the advantages of both static and dynamic analysis methods, which not only achieves a high code coverage, but also can deal with the dynamic features in codes. The evaluation results show that HybriDroid is effective in detecting privacy leakages for both inter- and intra-app communication. Comparing with the existing methods, it can achieve considerable improvements in data leakage detection performance with a 97.8% precision and 90% recall on the selected apps from DroidBench 3.0 test suite.
Ho-fung Leung, Biao Han 0003, Jinshu Su
ICC4
2017 Enhancing the effectiveness of traffic engineering in hybrid SDN
abstract
A lot of researches exploit the flexibility of Software-Defined Networking (SDN) to conduct traffic engineering in order to improve network performance and enhance robustness to failures. As the upgrade of a traditional network to a full SDN deployment is an incremental process, the coexistence of SDN switches and legacy switches forms a hybrid SDN. Due to the different forwarding characteristics of these switches, it is essential to coordinate the forwarding of SDN control and distributed routing to avoid inconsistency and achieve high network utilization. In this paper, we note that the effectiveness of traffic engineering in hybrid SDN strongly depends on both the structures of forwarding graphs and traffic distribution, while existing approaches mainly focus on the latter. We first define the consistent forwarding graph, and then construct forwarding graphs with potential high throughput for effective traffic engineering, while maintaining forwarding consistency. The evaluation results show that the proposed forwarding graph construction approach improves network throughput and achieves better load balancing compared with existing simple forwarding path constructing approaches, especially with more fraction of SDN deployment.
Wen Wang 0018, Wenbo He 0003, Jinshu Su
ICC3
2017 Boosting The Benefits of Hybrid SDN
abstract
The upgrade of a legacy network to a full software-defined networking (SDN) deployment is usually an incremental process, during which SDN switches and legacy switches coexist in the hybrid network. However, with inappropriate deployment of SDN switches and design of hybrid control, the advantages of SDN control could not exert, and it even results in performance degradation or inconsistency (e.g., loops, black-holes). Therefore, the hybrid SDN requires considerable coordination of the centralized control and distributed routing. In this paper, we propose a solution to handle the heterogeneity caused by distinct forwarding characteristics of SDN and legacy switches, therefore boosting the benefits of hybrid SDN. We plan SDN placement to enhance the SDN controllability over the hybrid network, and conduct traffic engineering considering both the forwarding characteristics of SDN and legacy switches. The experiments with various topologies show that the SDN placement planning and hybrid forwarding yield better network performance especially in the early 70% SDN deployment.
Wen Wang 0018, Wenbo He 0003, Jinshu Su
ICDCS3
2017 Real-time pre-processing system with hardware accelerator for mobile core networks
abstract
With the rapidly increasing number of mobile devices being used as essential terminals or platforms for communication, security threats now target the whole telecommunication infrastructure and become increasingly serious. Network probing tools, which are deployed as a bypass device at a mobile core network gateway, can collect and analyze all the traffic for security detection. However, due to the ever-increasing link speed, it is of vital importance to offload the processing pressure of the detection system. In this paper, we design and evaluate a real-time pre-processing system, which includes a hardware accelerator and a multi-core processor. The implemented prototype can quickly restore each encapsulated packet and effectively distribute traffic to multiple back-end detection systems. We demonstrate the prototype in a well-deployed network environment with large volumes of real data. Experimental results show that our system can achieve at least 18 Gb/s with no packet loss with all kinds of communication protocols.
Mian Cheng, Jinshu Su
Frontiers Inf. Technol. Electron. Eng.2
2017 A systematic review of structured sparse learning
abstract
High dimensional data arising from diverse scientific research fields and industrial development have led to increased interest in sparse learning due to model parsimony and computational advantage. With the assumption of sparsity, many computational problems can be handled efficiently in practice. Structured sparse learning encodes the structural information of the variables and has been quite successful in numerous research fields. With various types of structures discovered, sorts of structured regularizations have been proposed. These regularizations have greatly improved the efficacy of sparse learning algorithms through the use of specific structural information. In this article, we present a systematic review of structured sparse learning including ideas, formulations, algorithms, and applications. We present these algorithms in the unified framework of minimizing the sum of loss and penalty functions, summarize publicly accessible software implementations, and compare the computational complexity of typical optimization methods to solve structured sparse learning problems. In experiments, we present applications in unsupervised learning, for structured signal recovery and hierarchical image reconstruction, and in supervised learning in the context of a novel graph-guided logistic regression.
Linbo Qiao, Bo-Feng Zhang, Jinshu Su, Xicheng Lu
Frontiers Inf. Technol. Electron. Eng.3
2017 CloudEyes: Cloud-based malware detection with reversible sketch for resource-constrained internet of things (IoT) devices
abstract
Summary Because of the rapid increasing of malware attacks on the Internet of Things in recent years, it is critical for resource‐constrained devices to guard against potential risks. The traditional host‐based security solution becomes puffy and inapplicable with the development of malware attacks. Moreover, it is hard for the cloud‐based security solution to achieve both the high performance detection and the data privacy protection simultaneously. This paper proposes a cloud‐based anti‐malware system, called CloudEyes, which provides efficient and trusted security services for resource‐constrained devices. For the cloud server, CloudEyes presents suspicious bucket cross‐filtering, a novel signature detection mechanism based on the reversible sketch structure, which provides retrospective and accurate orientations of malicious signature fragments. For the client, CloudEyes implements a lightweight scanning agent which utilizes the digest of signature fragments to dramatically reduce the range of accurate matching. Furthermore, by transmitting sketch coordinates and the modular hashing, CloudEyes guarantees both the data privacy and low‐cost communications. Finally, we evaluate the performance of CloudEyes by utilizing both the campus suspicious traffic and normal files. The results demonstrate that the mechanisms in CloudEyes are effective and practical, and our system can outperform other existing systems with less time and communication consumption. Copyright © 2016 John Wiley & Sons, Ltd.
Hao Sun 0004, Xiaofeng Wang 0002, Rajkumar Buyya, Jinshu Su
Softw. Pract. Exp.4
2016 Fast Resource Co-provisioning for Time Critical Applications Based on Networked Infrastructures
abstract
Resource provisioning is a key step in the deployment of applications onto clouds. When some datacenter is not accessible or some part of the infrastructure is crashed, the provisioning mechanism is therefore essential for these applications to recover quickly from sudden failures, especially for time critical applications. However, most current solutions focus on the cloud provider's hardware to achieve the fast provisioning of cloud resources. This paper proposes a co-provisioning mechanism to partition the customer's cloud resource requests while preserving their connectivity. This mechanism uses a brokering approach that is totally transparent to both the customer and the cloud provider, specifically considering the network topology. We carry out experiments on an NIaaS (networked infrastructure-as-a-service) platform, called ExoGENI. Experimental results and data analysis show that this mechanism is feasible and can dramatically improve the speed of resource provisioning.
Huan Zhou 0006, Yang Hu 0013, Jinshu Su, Paul Martin 0002, Cees T. A. M. de Laat, Zhiming Zhao
CLOUD4
2016 Linearized Alternating Direction Method of Multipliers for Constrained Nonconvex Regularized Optimization
abstract
In this paper, we consider a class of constrained nonconvex regularized minimization problems, where the constraints is linearly constrained. It was reported in the literature that nonconvex regularization usually yields a solution with more desirable sparse structural properties beyond convex ones. However, it is not easy to obtain the proximal mapping associated with nonconvex regularization, due to the imposed linearly constraints. In this paper, the optimization problem with linear constraints is solved by the Linearized Alternating Direction Method of Multipliers (LADMM). Moreover, we present a detailed convergence analysis of the LADMM algorithm for solving nonconvex compositely regularized optimization with a large class of nonconvex penalties. Experimental results on several real-world datasets validate the efficacy of the proposed algorithm.
Linbo Qiao, Bofeng Zhang, Jinshu Su, Xicheng Lu
ACML3
2016 An Event Grouping Approach for Infinite Stream with Differential Privacy
Mian Cheng, Yipin Sun, Baokang Zhao, Jinshu Su
APSCC4
2016 Redactor: Reconcile network control with declarative control programs In SDN
abstract
With SDN control programs from multi-domains configuring the network, it is inevitable that control programs make conflicting control decisions, which probably lead to misconfiguration or performance degradation. Existing control coordination approaches either compose control programs to derive consistent solutions jointly or examine the generated rules of each control program to ensure they are consistent. However, the former is usually of great complexity and hard to be conducted automatically, and the latter probably results in suboptimal solutions due to the independent execution of control programs. Moreover, these approaches all fail to consider the control utility of control programs. In this paper, we propose Redactor to optimize the consistency and utility of network control in an automatic and dynamic manner. To make network control consistent, we implement SDN control programs with declarative language Prolog, and compose control programs automatically to execute together to make consistent decisions. When conflicts occur, we use a heuristic approach to compromise a subset of control programs to maximize the control utility. We compare Redactor with the static priority mechanism and Athens [1], and the results show that Redactor always satisfies more control objectives to achieve better control consistency and utility.
Wen Wang 0018, Wenbo He 0003, Jinshu Su
ICNP3
2016 Cupid: Congestion-free consistent data plane update in software defined networks
abstract
With the popular applications of SDN in load balancing and failure recovery, the controller schedules affected flows to redundant paths to avoid network congestions and failures by updating flow tables in data plane. However, inconsistent flow table updating may lead to transient incorrect network behaviors or undesired performance degradation. Therefore, the consistency imposes dependencies among updates, so that the order of updates must be carefully considered to keep the consistency. To update flow tables consistently and efficiently, in this paper, we propose an update ordering approach — Cupid. To avoid high overhead in update ordering, we divide the global dependencies among updates into local restrictions by: 1) partitioning a new routing path into several independent segments, 2) identifying critical nodes controlling traffic shifting between the old path and new path, and 3) constructing a dependency graph among critical nodes for potential congested links. We then design a heuristic algorithm to resolve the dependency graph. To save the flow table space, a switch keeps only one flow entry with multiple ports for a flow during updating. Our simulation shows that Cupid schedules updates at least 2 times faster and has less throughput losses than the state-of-the-art approaches in both fat-tree and mesh networks.
Wen Wang 0018, Wenbo He 0003, Jinshu Su, Yixin Chen 0004
INFOCOM3
2016 A 60Gbps DPI Prototype based on Memory-Centric FPGA
abstract
Deep packet inspection (DPI) is widely used in content-aware network applications to detect string features. It is of vital importance to improve the DPI performance due to the ever-increasing link speed. In this demo, we propose a novel DPI architecture with a hierarchy memory structure and parallel matching engines based on memory-centric FPGA. The implemented DPI prototype is able to provide up to 60Gbps full-text string matching throughput and fast rules update speed.
Jinshu Su, Shuhui Chen, Biao Han 0003, Xin Wang 0076
SIGCOMM1
2016 Achieving Consistent SDN Control With Declarative Applications
abstract
Software-defined networking enables applications act as blackboxes independently to control the network flexibly. However, these independent applications may generate conflicting control decisions. To reconcile applications automatically and dynamically, we implement control applications with Prolog, which enables applications to execute jointly to make consistent control decisions. When conflicts occur, we design a compromise algorithm by sacrificing a subset of applications to maximize the desired control objectives.
Wen Wang 0018, Jinshu Su, Wenbo He 0003
SIGCOMM3
2016 BufferBank storage: an economic, scalable and universally usable in-network storage model for streaming data applications
Zhigang Sun 0002, Fei Yi, Jinshu Su
Sci. China Inf. Sci.4
2016 An escrow-free online/offline HIBS scheme for privacy protection of people-centric sensing
abstract
Abstract People‐centric sensing (PCS), which collects information closely related to human activity and interactions in societies, is stepping into a flourishing time. Along with its great benefits, PCS poses new security challenges such as data integrity and participant privacy. Hierarchical identity‐based signature (HIBS) scheme can efficiently provide high‐integrity messaging, secure communication, and privacy protection to PCS. However, key escrow problem and low computation efficiency primarily hinder the adoption of HIBS scheme. In this paper, we propose an escrow‐free online/offline HIBS scheme for securing PCS. By utilizing user‐selected‐secret signing algorithm and splitting the signing phase into online and offline procedures, our scheme solves the key escrow problem and achieves high scheme performance. Copyright © 2016 John Wiley & Sons, Ltd.
Peixin Chen, Jinshu Su, Baokang Zhao, Xiaofeng Wang 0002, Ilsun You
Secur. Commun. Networks2
2015 Keyword Search over Shared Cloud Data without Secure Channel or Authority
abstract
Storage services play an important role in a public cloud. By outsourcing data to the remote cloud, users do not need to maintain a local storage infrastructure and can significantly lower the storage cost. To protect the privacy, documents must be encrypted before outsourcing. This raises a new challenge for the document owner: how should the encrypted documents be securely searched in a public cloud? While many mechanisms have been proposed to support secure search over the encrypted documents, most of these mechanisms require secure channels to transmit the secret information, such as the secret keys and trapdoors, and is difficult to deploy in cloud systems. Moreover, some existing mechanisms require an authority to control the access requests of users, which inevitably increases the complexity of cloud infrastructure. This paper considers a more stringent security model where an eavesdropper exists in the cloud and can eavesdrop on all transmission channels. We propose a novel mechanism that supports multi-user keyword search over the encrypted data without relying on any secure channel or authority. The eavesdropper can neither forge valid trapdoors from the intercepted information nor can it directly use the intercepted trapdoors to complete the keyword search. Security analysis shows that the proposed mechanism is secure.
Jinshu Su, Baochun Li
CLOUD2
2015 POSTER: iPKI: Identity-based Private Key Infrastructure for Securing BGP Protocol
abstract
For Securing BGP Protocol, this paper proposes an identity-based private key infrastructure (iPKI) for managing self-attested IP (sIP) addresses. An sIP address endows the current IP address self-attested characteristic, which does not rely on any credential based PKI. Based on the sIP address, we design the In-Band Self Origin Verification (IBSOV) protocol and self Route Origin Authorization (sROA) to provide a lightweight origin verification for the BGP protocol, which has a much lower overhead than the existing works.
Peixin Chen, Xiaofeng Wang 0002, Jinshu Su, Huan Zhou 0006
CCS4
2015 Network intrusion detection and prevention middlebox management in SDN
abstract
In traditional networks, it is difficult to manage the distributed detection and prevention nodes of IDS and IPS due to the laborious manual deployment and independent configuration. Software defined networking (SDN) provides a flexible approach to control the underlying network infrastructures efficiently. However, the OpenFlow flow table is too simple to provide complex functions with the match-action style processing. To support more functionalities, in this paper, we propose a middlebox management architecture with SDN - OpenMiddlebox, by extending OpenFlow to support middleboxes with ClickOS virtual machines (VM), so that programmable middleboxes could be deployed and managed in switches with fast booted ClickOS VMs flexibly. We then design automatic deployment and update schemes of network intrusion detection and prevention middleboxes with the centralized controller. The evaluation results show that OpenMiddlebox could manage the distributed middleboxes efficiently and is scalable to large networks, and the centralized control also improves the network intrusion detection and prevention accuracy.
Wen Wang 0018, Wenbo He 0003, Jinshu Su
IPCCC3
2015 M2SDN: Achieving multipath and multihoming in data centers with software defined networking
abstract
The increasing virtualization in data centers brings growing inter-node communication by running various applications on virtual machines located physically separated. Meanwhile, the virtual machines on a physical server also compete for limited Ethernet interface I/O resources. Load balancing with multipath and multihoming is usually the key to address the bandwidth and Ethernet I/O bottlenecks. Even though various variants of equal cost multipath (ECMP) schemes have been widely applied for load balancing, the equal and fairness assumption of ECMP results in imbalance and underutilization in asymmetric networks without considering network topology and traffic situation. The multihoming solutions usually require protocol modification and peer's support. In this paper, we propose a utilization & topology-aware multipath routing and multihoming scheduling with Software Defined Networking (SDN) in data centers to address these bottlenecks. The utilization & topology-aware multipath routing takes global network situation to avoid congestions and balances utilization of multiple paths. At a multi-homed server end, the multihoming scheduler balances the traffic among multiple Ethernet interfaces and ensures QoS guarantees when accessing the network without changing network stack. We compared our approach with traditional single path and equal cost multipath schemes, and the results showed that the utilization & topology-aware multipath routing and multihoming scheduling achieved much higher network utilization and better load balancing, especially for asymmetric networks.
Wen Wang 0018, Wenbo He 0003, Jinshu Su
IWQoS3
2015 Providing adaptive quality of security in quantum networks
Baokang Zhao, Ziling Wei, Bo Liu 0013, Jinshu Su, Ilsun You
QSHINE4
2015 RScam: Cloud-Based Anti-Malware via Reversible Sketch
Hao Sun 0004, Xiaofeng Wang 0002, Jinshu Su, Peixin Chen
SecureComm3
2015 A Novel Location Privacy Mining Threat in Vehicular Internet Access Service
Yipin Sun, Shuhui Chen, Biao Han 0003, Bofeng Zhang, Jinshu Su
WASA5
2015 Trust Description and Propagation System: Semantics and axiomatization
Xiaofeng Wang 0002, Jinshu Su, Ho-fung Leung
Knowl. Based Syst.2
2015 Mix-zones optimal deployment for protecting location privacy in VANET
Yipin Sun, Bofeng Zhang, Baokang Zhao, Xiangyu Su, Jinshu Su
Peer-to-Peer Netw. Appl.5
2015 Security, trust, and resilience of distributed networks and systems
abstract
The rapid growth of distributed and networking technologies has made our information system more vulnerable to attack threats, malicious behaviors, and unpredictable failures. As the emergence of botnets and advanced persistent threat attacks, the traditional defense technology cannot cope well with the new large-scale and obfuscated malwares. In distributed and virtualized environments, the trust risk of applications has been increased considerably, which made it vital to propose new trust access control technologies. In addition, the complicated system usually comprises a large number of components that are susceptible to unpredictable failures. We need new designs of resilient infrastructure and dependable services. The papers in this special issue focus on the security, trust, and resilience management for distributed and networking computing paradigms, such as wireless sensor network, P2P network, ad hoc networks, virtualized network, and software-defined network. The contributions of these papers are outlined next. To locate the real source of the Internet attacks, existing work is easy to be evaded by attackers and difficult to justify the stepping stones. Sheng Wen et al. introduce the consistent causality probability to detect the stepping stones. They formulate the ranges of abnormal causality probabilities according to the different network conditions and further implement self-adaptive methods to capture stepping stones. To extract signatures for malwares, most existing string-based signatures extracting methods have the problem of inaccuracy and time consuming. Sun Hao et al. present a system for automatically extracting signatures from large-scale malwares, named AutoMal. The system can extract both byte signatures and hashed signatures from the malware network flows with high accuracy. Multi-interface multi-channel can reduce the channel interference and improve the network capacity for multi-hop wireless ad hoc networks. Tong Zhao et al. design a dynamic channel assignment algorithm that can dynamically switch the channels to the less busy ones by monitoring the channel usages. Moreover, the algorithm is designed in a fully distributed way with low overhead For the task allocation in wireless sensor networks (WSNs), traditional solutions for high-performance computing cannot be directly used in WSNs because of limitations of resource availability and shared communication medium. Wenzhong Guo et al. design a discrete particle swarm optimization to generate a structure of the parallel coalitions, and then introduce the game theory and redesigned fitness function to find the Nash equilibrium point for the purpose of improving the effectiveness of scheduling and the reliability of the network. Clustering approach has been considered one of the most effective measures for wireless sensor networks. Xiao-Hui Kuang et al. propose a novel energy-efficient clustering approach based on convergence degree chain, which is named ECACD. ECACD can improve the stability of topology, reduce the energy consumption, and decrease the communication cost. The distributed hash table (DHT) technology is widely used, which needs to take into account the real-time response and dynamic network maintenance for distributed communication systems. Kai Shuang et al. propose a hierarchical DHT lookup service named Comb, which is organized as a two-layered architecture; workload is distributed evenly among nodes, and most queries can be routed in no more than two hops. Few access control models have been proposed for security issues of multi-domain and virtualized network management. Yang Luo et al. enhance the classic role-based access control model through two concepts: domain and virtual machine. They define the virtualized role based access control (VRBAC) model in which authorized users can migrate or copy virtual machines from one domain to another without causing a conflict. In software-defined networks, network operating systems (NOSes) are required to share or exchange reachability and topological information. Pingping Lin et al. proposes a west–east bridge mechanism for distributed heterogeneous NOSes to cooperate in enterprise/data center/intra-autonomous system networks. Monitoring Border Gateway Protocol (BGP) is an effective way to improve the security of inter-domain routing. Ning Hu et al. present a cooperative BGP monitoring method called the cooperative information sharing model (CoISM). CoISM can provide a more comprehensive information view by introducing information diffuse reflection based on initiative inquiry and making use of the relativity of monitoring information. Securing mobile devices such as smart phones is inherently difficult. René Mayrhofer et al. review recent research results, systematically analyze the technical issues of securing mobile device platforms against different threats, and suggest potential approaches to create human-verifiable secure communication with components or services within partially untrusted devices. We would like to thank the editor-in-chief, Professor Hsiao-Hwa Chen, and co-editor-in-chief, Professor Hamid R. Sharif, for providing us the opportunity to host this special issue. We thank Prof. Guojun Wang for his great help in the organization of the special issue. We also thank all the authors who contributed their papers. Last but not least, we appreciate the work of many reviewers for this special issue.
Jinshu Su, Xiaofeng Wang 0002, Weisong Shi, Indrakshi Ray
Secur. Commun. Networks1
2015 Truncated differential cryptanalysis of PRINCE
abstract
Abstract PRINCE is a lightweight block cipher whose block size and key size are 64‐bit and 128‐bit, respectively. The core component of PRINCE is PRINCE which is wrapped by the initial and final key whitening. PRINCEcore adopts a 12‐round SPN structure. This paper exploits some new vulnerabilities of PRINCE from an aspect different from previous results, and applies truncated differential cryptanalysis to PRINCE. The result demonstrates that for several reduced versions of PRINCE, there exist 5‐round and 6‐round (out of 12 rounds) truncated differential distinguishers. We introduce a key‐recovery attack on 7‐round PRINCEcore using two 5‐round distinguishers, the data complexity is 250 chosen plaintexts and the time complexity is 248.2 7‐round encryptions, with a storage of about 222.6 counters. Both the distinguishers and key‐recovery attacks are not related to the value of α. Copyright © 2015 John Wiley & Sons, Ltd.
Guangyao Zhao, Bing Sun 0001, Chao Li 0002, Jinshu Su
Secur. Commun. Networks4
2015 Latency-aware DVFS for efficient power state transitions on many-core architectures
Zhiquan Lai, King Tin Lam, Cho-Li Wang, Jinshu Su
J. Supercomput.4
2015 Secrecy Capacity Optimization via Cooperative Relaying and Jamming for WANETs
abstract
Cooperative wireless networking, which is promising in improving the system operation efficiency and reliability by acquiring more accurate and timely information, has attracted considerable attentions to support many services in practice. However, the problem of secure cooperative communication has not been well investigated yet. In this paper, we exploit physical layer security to provide secure cooperative communication for wireless ad hoc networks (WANETs) where involve multiple source-destination pairs and malicious eavesdroppers. By characterizing the security performance of the system by secrecy capacity, we study the secrecy capacity optimization problem in which security enhancement is achieved via cooperative relaying and cooperative jamming. Specifically, we propose a system model where a set of relay nodes can be exploited by multiple source-destination pairs to achieve physical layer security. We theoretically present a corresponding formulation for the relay assignment problem and develop an optimal algorithm to solve it in polynomial time. To further increase the system secrecy capacity, we exploit the cooperative jamming technique and propose a smart jamming algorithm to interfere the eavesdropping channels. Through extensive experiments, we validate that our proposed algorithms significantly increase the system secrecy capacity under various network settings.
Biao Han 0003, Jie Li 0002, Jinshu Su, Minyi Guo, Baokang Zhao
IEEE Trans. Parallel Distributed Syst.3
2014 POSTER: T-IP: A Self-Trustworthy and Secure Internet Protocol with Full Compliance to TCP/IP
abstract
In this demo, we propose the self-trustworthy and secure Internet protocol (T-IP) for authenticated and encrypted network layer communications. T-IP has the following advantages: 1) Self-Trustworthy IP address. 2) Low connection latency and transmission overhead. 3) Reserving to be stateless (an important merit of IP). 4) Compatible with the existing TCP/IP architecture. We have implemented the protocol and deployed it in our campus network. Compared with IPsec, the evaluation shows that T-IP has a much lower transmission overhead and connection latency.
Xiaofeng Wang 0002, Huan Zhou 0006, Jinshu Su, Bofeng Zhang
CCS3
2014 SPS: A Novel Semantics-Aware Scheme for Location Privacy in People-Centric Sensing Network
Ziling Wei, Jinshu Su, Baokang Zhao
WASA2
2014 ePASS: An expressive attribute-based signature scheme with privacy and an unforgeability guarantee for the Internet of Things
Jinshu Su, Dan Cao, Baokang Zhao, Xiaofeng Wang 0002, Ilsun You
Future Gener. Comput. Syst.1
2014 A study of IP prefix hijacking in cloud computing networks
abstract
ABSTRACT IP prefix hijacking remains a serious security threat to the traditional services in the Internet. It also harms the confidentiality and integrity of user data in Internet‐enabled cloud services because of its great dependence on Internet routing infrastructure. In addition, collaborations between networks in the cloud environment, especially in cross‐domain deployment, bring about new types of prefix hijacking attack, which may cause greater impact due to side‐effect of the cooperation of victim and infected autonomous systems. It is important to understand what impact a prefix hijacking attack can cause and how the number and locations of participants can affect the attacking results. In this paper, we model this problem as an attack planning task and solve it by applying a genetic algorithm. By analyzing the best solution to the problem, we find that the type of victims plays a more important role in IP prefix hijacking than that of attackers. Attackers can gain great impact even when the prefixes of a small number of victims are hijacked. For attack planning, the degree of an autonomous system is a major criterion to be considered. These findings are useful for securing cloud computing networks by preventing and eliminating IP prefix hijacking attacks. Copyright © 2013 John Wiley & Sons, Ltd.
Wei Peng 0005, Jinshu Su
Secur. Commun. Networks3
2014 A Random Road Network Model and Its Effects on Topological Characteristics of Mobile Delay-Tolerant Networks
abstract
Road networks have significant impact on mobility and network characteristics of wireless ad hoc networks. Discovering their characteristics and effects on mobility and network performance in urban environments is a fundamental research task. In this paper, we firstly study the graph attributes of road networks by sampling real road networks in main cities of Europe and USA. We propose a new graph metric, called characteristic central length, in order to estimate the average shortest-path length of a large-scale spatial network. We find that real road networks from Europe and USA have different patterns with regard to some graph attributes and a simple grid model is inadequate to describe them. Considering the diverse patterns of urban road networks caused by obstacles and shortcuts, we propose a random road network model, called the GRE model. The model is validated through fitting it to real road network samples using a genetic algorithm and simulation of delay-tolerant networks. The simulation results have shown that by extending the grid model with new probabilistic parameters, the GRE model has better capability on approximating real road networks. The simulation results have also shown that delay-tolerant networks operating on road networks may have better performance than scenarios without road networks.
Wei Peng 0005, Guohua Dong, Kun Yang 0001, Jinshu Su
IEEE Trans. Mob. Comput.4
2013 Optimal relay assignment for secrecy capacity maximization in cooperative ad-hoc networks
abstract
Physical layer security has emerged as a key technique for providing trustworthy and reliable future wireless networks and has witnessed a significant growth in the past few years. In this paper, we aim to improve the physical layer security and provide secure cooperative communication through cooperative relay assignment. By characterizing the security performance of the system by secrecy capacity, we study the secrecy capacity maximization problem in cooperative ad hoc networks with the involvement of multiple malicious eavesdroppers. Specifically, we propose a system model where a set of relay nodes can be exploited by multiple source-destination pairs to achieve physical layer security. We theoretically present a corresponding formulation for the secrecy capacity maximization problem. Then we develop an optimal relay assignment algorithm to solve the problem in polynomial time. The basic idea behind our proposed algorithm is to boost the capacity of the primary channel by simultaneously decreasing the capacity of the eavesdropping channel. Through extensive experiments, we validate that our proposed relay assignment algorithm significantly increase the system secrecy capacity under various network settings.
Biao Han 0003, Jie Li 0002, Jinshu Su
ICC3
2013 Detect and identify blocker tags in tree-based RFID systems
abstract
Blocker tags are initially introduced to protect regular tags in certain ID ranges, called blocking ranges, from unwanted scanning in RFID systems. But if misused, blocker tags can cause blocking attacks that corrupt the communication between interfered regular tags and readers. Previous approaches can only detect blocking behavior. However, they cannot distinguish malicious blocking from legitimate blocking that can be perfectly allowed to protect customer's privacy. To solve the problem, we carry out the first attempt in the paper to detect real blocking attacks by identifying malicious blocking ranges from authorized ones in a system. We present two pioneer probe-based protocols that can accurately identify malicious blocking ranges in popular tree-based RFID systems, and get rid of their impact before performing RFID applications. We validate the efficacy of the two protocols through theoretical analysis and simulation experiments. The results show that our protocols can identify blocking ranges very fast even when the blocker tag percentage is very low, for example, dozens of blocker tags among tens of thousands of regular tags. Our protocols deliver also a faster blocker tag detection than previous detection methods; our best protocol reduces detection time by over 90% compared with the state-of-the-art detection method.
Fei Wang 0007, Bin Xiao 0001, Kai Bu, Jinshu Su
ICC4
2013 Qphone: a quantum security VoIP phone
abstract
This work presents a novel quantum security VoIP phone, called Qphone. Qphone integrates quantum key distribution (QKD) and VoIP steganography, and achieves peer-to-peer communication with information-theoretical security (ITS) guaranteeing. Qphone consists of three parts, a real-time QKD system, RT-QKD, a steganography software, VS-Phone, and an audio encryption and authentication hardware, AE-KEY. RT-QKD explores QKD technologies, and is able establish a shared key between two peers ensuring ITS. VS-Phone utilizes VoIP steganography to protect transmission channels of sensitive information. Qphone can provide efficient and real-time security protections to meet different security demands.
Bo Liu 0013, Baokang Zhao, Ziling Wei, Chunqing Wu, Jinshu Su, Wanrong Yu, Fei Wang 0007, Shihai Sun
SIGCOMM5
2013 Optimal relay node placement for multi-pair cooperative communication in wireless networks
abstract
Relaying and cooperation have emerged as important research topics in wireless communication over the past half-decade. During cooperative communication, spatial diversity can be achieved by exploiting the relaying capabilities of the involved relay nodes, which may vastly enhance the achieved system capacity. The potential gains largely depend on the location of relay nodes. In this paper, we study the relay node placement problem for multi-pair cooperative communication in wireless networks, where a finite number of candidate relay nodes can be placed to help the transmission of multiple source-destination pairs. Our objective is to maximize the system capacity. After formulating the relay node placement problem, we comprehensively study the effect of relay location on cooperative link capacity and show several attractive properties of the considered problem. As the main contribution, we develop a geographic aware relay node placement algorithm which optimally solves the relay node placement problem in polynomial time. The basic idea is to place a set of relay nodes to the optimum locations so as to maximize the system capacity. The efficiency of our proposed algorithm is evaluated by the results of series experimental studies.
Biao Han 0003, Jie Li 0002, Jinshu Su
WCNC3
2013 Characterizing Inter-Domain Rerouting by Betweenness Centrality after Disruptive Events
abstract
Rerouting is not uncommon in nowadays Internet because it can be triggered by many root causes, such as network faults, routing attacks, etc. However, few methods effectively characterize rerouting in the whole Internet. In this paper, inspired by a well known network science metric - betweenness centrality, we propose a new approach to characterize inter-domain reroutings. By defining and analysing the variation of AS betweenness centrality for neighbouring-destination routes and global routes separately, our method empowers users to identify the temporal, topological, and relational characteristics of route changes. We apply our method to investigate the Internet's reactions to four different disruptive events, including Japan earthquake in March 2011, SEA-ME-WE 4 cable fault in April 2010, routing attack on YouTube in February 2008, and AS4761 hijacking event in January 2011. This examination reveals many new insights. For example, the route flapping and the congestion caused by the side-effect of rerouting after cable faults significantly degraded path quality. Moreover, direct providers of attackers and victims are the most critical positions for amplifying impact of prefix hijacking attacks. Such results shed light on how to implement effective reactions to network faults and how to deploy efficient defense mechanisms against routing attacks.
Xiapu Luo, Rocky K. C. Chang, Jinshu Su
IEEE J. Sel. Areas Commun.4
2012 A Random Road Network Model for Mobility Modeling in Mobile Delay-Tolerant Networks
abstract
Mobility is an important issue in the research of mobile delay-tolerant networks (DTNs). A simple grid model has been frequently used to simulate urban road networks in geographical restricted mobility models. However, by analyzing graph attributes of some urban road networks in main cities of Europe and USA, we discovered the discrepancy between real road network samples and the grid model. Based on the finding, we proposed a random graph-based road network model, called the Grid Model with Random Edges (GRE). The GRE model extends the basic grid model with new probabilistic parameters and thus has better capabilities to approximate real-world road networks. The model was validated through optimizing model parameter values using a genetic algorithm and comparing graph attributes of road networks generated by the model. It was demonstrated that the GRE model has better capability on approximating real road networks than the grid model, thus providing a better foundation for mobility modeling in mobile DTNs.
Wei Peng 0005, Guohua Dong, Kun Yang 0001, Jinshu Su, Jun Wu 0004
MSN4
2012 Characterizing Inter-domain Rerouting after Japan Earthquake
Xiapu Luo, Rocky K. C. Chang, Jinshu Su
Networking (2)4
2012 VicSifter: A Collaborative DDoS Detection System with Lightweight Victim Identification
abstract
Flooding based Distributed Denial of Service (DDoS) attacks can cause very serious security problem by exhausting computing and bandwidth resources of victims. To mitigate these destructive attacks, it is crucially important to detect the occurrence of DDoS attacks and identify their targets as early as possible. In this paper, we propose a collaborative DDoS detection system, called VicSifter, which can detect ongoing DDoS attacks and identify victims at an early stage with good scalability and low overhead. VicSifter is deployed over multiple nodes with two kinds of functions: local anomaly detection and collaborative victim identification. The anomaly detection method is performed locally and is lightweight to save computation by measuring passing packets in a sketch. The collaborative victim identification is triggered only when a local anomaly is detected by employing our distinctive elimination mechanism. The mechanism can significantly reduce the number of packets to be processed by each node, making our system scalable for high-speed network links. We evaluate the performance of VicSifter by using real-world data traffic, mixing the real DDoS attack traces with captured campus gateway traffic. The results show that our system has high accuracy in the early detection of DDoS attacks and timely identification of targeted victims. Our system can outperform other existing methods with less space requirement, and thus achieving good system scalability.
Fei Wang 0007, Xiaofeng Wang 0002, Jinshu Su, Bin Xiao 0001
TrustCom3
2012 Privacy aware publishing of successive location information in sensor networks
Baokang Zhao, Dan Wang 0002, Zili Shao, Jiannong Cao 0001, Jinshu Su
Future Gener. Comput. Syst.5
2012 Self-Supported Cooperative Networking for Emergency Services in Multi-Hop Wireless Networks
abstract
One of the challenging issues for supporting emergency services in wireless networks is coordinating the network under emergent situations. Cooperative communication (CC) is a promising approach which can offer significant enhancements in multi-hop wireless networks. This paper investigates the potential issues in using this communication paradigm to support emergency services. We focus on promoting energy-efficient and congestion-aware cooperative networking for emergency services based on the idea of Do-It-Yourself. We propose a novel cross-layer design which jointly considers the problems of route selection in network layer, congestion and non-cooperation avoidance among multiple links in MAC layer under cooperative multi-hop wireless environments. We formulate the multi-hop cooperative flow routing and relay node selection process as an optimization problem. Based on the formulations and models, we propose a self-supported networking scheme including three novel components that make the solution procedure highly efficient. Analysis and simulation results show that our approaches significantly achieve better network performance and typically satisfy the requirements for emergency services in multi-hop wireless networks.
Biao Han 0003, Jie Li 0002, Jinshu Su, Jiannong Cao 0001
IEEE J. Sel. Areas Commun.3
2012 A complete first-order temporal BDI logic for forest multi-agent systems
Lijun Wu 0001, Kaile Su, Abdul Sattar 0001, Qingliang Chen, Jinshu Su, Wei Wu 0042
Knowl. Based Syst.5
2012 An efficient distributed key management scheme for group-signature based anonymous authentication in VANET
abstract
ABSTRACT Group signature is one of the well‐known cryptographic primitives for anonymous authentication which is the fundamental requirement for securing vehicular ad hoc networks (VANETs), but it is prone to cause huge revocation overhead in VANETs with millions of nodes and serious security risk. To solve this problem, we develop an efficient distributed key management scheme (DKM) where the whole domain of VANET is divided into several sub‐regions, and any vehicle has to update its group secret key periodically from the regional group manager who manages the region where the vehicle stays. Unlike the previously reported works, DKM prevents vehicles from leaking the value of the updated group secret key to the regional group manager during the group key updating process. Subsequently, it is capable of identifying either the compromised regional authorities or the malicious vehicles. Moreover, performance analysis demonstrates that DKM can reduce the revocation cost significantly while the communication cost for key updating is small. Copyright © 2011 John Wiley & Sons, Ltd.
Yipin Sun, Zhenqian Feng, Qiaolin Hu, Jinshu Su
Secur. Commun. Networks4
2012 RLM: A General Model for Trust Representation and Aggregation
abstract
Reputation-based trust systems provide important capability in open and service-oriented computing environments. Most existing trust models fail to assess the variance of a reputation prediction. Moreover, the summation method, widely used for reputation feedback aggregation, is vulnerable to malicious feedbacks. This paper presents a general trust model, called RLM, for a more comprehensive and robust reputation evaluation. Concretely, we define a comprehensive reputation evaluation method based on two attributes: reputation value and reputation prediction variance. The reputation predication variance serves as a quality measure of the reputation value computed based on aggregation of feedbacks. For feedback aggregation, we propose the novel Kalman aggregation method, which can inherently support robust trust evaluation. To defend against malicious and coordinated feedbacks, we design the Expectation Maximization algorithm to autonomously mitigate the influence of a malicious feedback, and further apply the hypothesis test method to resist malicious feedbacks precisely. Through theoretical analysis, we demonstrate the robustness of the RLM design against adulating and defaming attacks, two popular types of feedback attacks. Our experiments show that the RLM model can effectively capture the reputation's evolution and outperform the popular summation-based trust models in terms of both accuracy and attack resilience. Concretely, under the attack of collusive malicious feedbacks, RLM offers higher robustness for the reputation prediction and a lower false positive rate for the malicious feedback detection.
Xiaofeng Wang 0002, Ling Liu 0001, Jinshu Su
IEEE Trans. Serv. Comput.3
2011 Evaluation of Topological Vulnerability of the Internet under Regional Failures
Wei Peng 0005, Zimu Li, Jinshu Su, Muwei Dong
ARES3
2011 SDBGP: A scalable, distributed BGP routing protocol implementation
abstract
Traditional BGP implementation is based on single process or single thread model and not fit for cluster architecture of future core router. We have developed SDBGP, a distributed BGP implementation for future core router that provides excellent performance, reliability and scalability. SDBGP is designed on a fully distributed architecture, which gives equal chance for router nodes to participate in BGP routes computing and storage. SDBGP distributes BGP neighbors among cluster router nodes in a balanced way and improves BGP's performance by parallel processing of BGP neighbors. We deploy SDBGP on a software cluster router with four nodes. Performance testing shows that SDBGP can achieve great scalability in neighbor number and routes computation. It can get almost linear speedup with the increasing of cluster route size.
Xiaozhe Zhang, Xicheng Lu, Jinshu Su
HPSR3
2011 How Can Multipath Dissemination Help to Detect Prefix Hijacking?
abstract
Multiple path dissemination is recognized as an important feature to improve the reliability and efficiency of networks. However, most multipath routing proposals focus only on disseminating additional routes to increase the reliability of the Internet, and do not concern the security issues that the additional routes bring to the table. In this paper, we attempt to understand the feasibility of utilizing multipath dissemination to detect prefix hijacking attacks. We investigate the minimum level of security enhancement that would be achieved by multipath dissemination. We systematically analyze the effectiveness of two types of multipath advertisements, advertising the most disjoint path advertisement or the second best path advertisement with the best path, on detecting prefix hijacking. Our analysis and measurement results show that advertising the second best route with the best route is an efficient and effective way to disseminate multipath information with respect to inter-domain routing security.
Feng Wang 0017, Bin Dai 0001, Jinshu Su
ICCCN3
2011 Self-supported congestion-aware networking for emergency services in WANETs
abstract
One of the challenging issues for supporting emergency services in wireless ad hoc networks (WANETs) is coordinating the network under emergency situations. It may lead to inefficient use of the network resources by increasing congestion, as well as affect the network connectivity due to the non-cooperation behaviors of some selfish users. In this paper, we focus on promoting self-supported and congestion-aware networking for emergency services in WANETs based on the idea of Do-It-Yourself1. We model network congestion and non-cooperation behaviors according to the relations between nodes in the constructed dependency graph. Then we propose an energy-efficient and congestion-aware routing protocol for the emergency services of WANETs. Based on the proposed model and routing protocol, we design two novel movement schemes, called Direct Movement to potential selfish/busy Relays (DMR) scheme and Iterative Movement to potential selfish/busy Relays (IMR) scheme for urgent sources to support themselves and to avoid congestion and non-cooperation. Analysis and simulation results show that our approaches significantly achieve better network performance and typically satisfy the requirements for emergency services in WANETs.
Biao Han 0003, Jie Li 0002, Jinshu Su
INFOCOM3
2011 One Leader at One Time: OLOT Routing in Delay Tolerant Networks
abstract
Routing is a challenge problem in Delay-tolerant networks (DTNs) due to the intermittent connectivity environment. To cope with it, both single-copy and multi-copy routing protocols have been proposed. The difference between them is how to handle with the messages that have been forwarded to the next hop. These messages will be removed from buffer immediately in the single-copy protocols, while be kept and forwarded to other relays in the multi-copy cases. However, there is a gap between the two protocols. In our previous work, we have indicated it and proposed a Snail Crawling(SC) method to fill the gap. In this paper, we indicate that the SC method is just an enhanced method but not a routing protocol. By adopting heuristic strategies in messages distribution of SC, we get a new routing protocol One Leader at One Time(OLOT), in which only one node can forward message to another relay at the same time. Simulation results show that both the delivery rate and the overhead of OLOT are better than the SC method.
Zhenqian Feng, Baokang Zhao, Jinshu Su
MSN4
2011 Shrew Attack in Cloud Data Center Networks
abstract
Multi-tenancy and lack of network performance isolation among tenants together make the public cloud vulnerable to attacks. This paper studies one of the potential attacks, namely, low-rate denial-of-service (DoS) attack (or \textit{Shrew} attack for short), in cloud data center networks (DCNs). To explore the feasibility of launching Shrew attack from the perspective of a normal external tenant, we first leverage a loss-based probe to identify the locations and capabilities of the underlying bottlenecks, and then make use of the low-latency feature of DCNs to synchronize the participating attack flows. Moreover, we quantitatively analyze the necessary and sufficient traffic for an effective attack. Using a combination of analytical modeling and extensive experiments, we demonstrate that a tenant could initiate an efficient Shrew attack with extremely little traffic, e.g., milliseconds-long burst traffic, which imposes significant difficulty for the switching boxes and counter-DoS mechanisms to detect. We identify that both the conventional protocol assumption and new features of DCNs enable such Shrew attack, and new techniques are required to thwart it in the DCNs.
Zhenqian Feng, Baokang Zhao, Jinshu Su
MSN4
2011 Protecting Router Forwarding Table in Space
abstract
SRAM-based FPGA is more sensitive to multiple bit upset, and the possibility of accumulation of memory's upset is high. In order to improve the ability that SRAM-based FPGA is more stable to multiple upset, this paper presents a new type design of multiple errors correction. The design combines BCH(15,7) code which can correct two errors and the improved TMR technology and achieves detecting and correcting multiple bit upset. Compared with the classical Hamming codes and extended Hamming codes, it has the advantage of correcting multiple bit upset. And compared with the traditional TMR, it can effectively determine the validity of the data after voting. Meanwhile, the design writes back the right data when error happens to avoid the accumulation of errors.
Xiangyu Su, Jinzhen Bao, Baokang Zhao, Jinshu Su
MSN4
2011 VISOR: A Pratical VoIP Steganography Platform
abstract
Recently, streaming steganography has attracted a lot of research efforts, however, since multimedia processing requires high performance hardware and software, most literatures in the streaming steganography community focus on simulations due to lack of a practical streaming steganography platform. Towards this issue, we design and develop VISOR, a novel VoIP Steganography Oriented platfoRm. VISOR consists of both hardware(named "VISOR-Key") and software(named "VISORPhone"). In general, VISOR provides an open, high performance and portable platform to the streaming steganography community.
Ziling Wei, Bo Liu 0012, Erci Xu, Baokang Zhao, Jinshu Su
MSN6
2011 Analysis of prefix hijacking based on AS hierarchical model
abstract
BGP prefix hijacking is one of the main threatens for the Internet. It is important to identify the impact factors for prefix hijacking. This paper studies the problem from the view of AS logical topology by analysis of the data from the snapshots of CAIDA. We propose a hierarchical model based on AS relationship to classify the AS nodes into different level and define core size of each node to prioritize them in each level. Two metrics named infected number and infected diameter are introduced to analyze the relationship between the logical structural characters of AS node and the impact of prefix hijacking. The results show that core size, which reflects the relation of an AS node with Tier-1 AS nodes, and AS level are two main important factors. AS nodes in higher level or with bigger core size are able to infect more nodes. However, AS node in lower level has longer infected diameters. This phenomenon indicates that the prefix hijacking with attacker in lower level is harder to detect.
Bofeng Zhang, Yuan Li 0011, Jinshu Su
NSS4
2011 Study on IP Prefix Hijacking in Cloud Computing Networks Based on Attack Planning
abstract
Due to the great dependence on Internet routing infrastructure, cloud services are vulnerable to IP prefix hijacking attacks which can destroy the confidentiality and integrity of user data. It is important to understand what impact a prefix hijacking attack can cause and how the number and locations of participants can affect the attacking results. In this paper, considering both attacking and detecting, we innovatively model this problem as an attack planning task, and solve it by applying a genetic algorithm. By analyzing the best solution to the problem, we find that the type of victims plays a more important role in IP prefix hijacking than that of attackers. We also find that attackers can gain great impact even when the prefixes of a small number of victims are hijacked. For attack planning, the degree of an AS is a major criterion to be considered. These findings are useful for securing cloud computing networks by preventing and eliminating IP prefix hijacking.
Wei Peng 0005, Jinshu Su
TrustCom3
2011 Optimizing the makespan and reliability for workflow applications with reputation and a look-ahead genetic algorithm
Xiaofeng Wang 0002, Chee Shin Yeo, Rajkumar Buyya, Jinshu Su
Future Gener. Comput. Syst.4
2011 The TianHe-1A Supercomputer: Its Hardware and Software
Xuejun Yang, Xiangke Liao, Kai Lu 0001, Qingfeng Hu, Junqiang Song, Jinshu Su
J. Comput. Sci. Technol.6
2010 A Secure and Efficient Revocation Scheme for Anonymous Vehicular Communications
abstract
In this paper, we propose a secure and efficient revocation scheme for anonymous vehicular communications, named SEA. SEA is a pseudonymous authentication scheme, but unlike traditional pseudonymous schemes, its CRL size is linear in terms of the number of revoked vehicles and unrelated to the size of vehicle pseudonymous certificate set. SEA supports certificate regional management and keeps the service overhead of RSUs very low. Furthermore, SEA provides strong privacy preservation against the RSUs so that the adversaries can not trace any vehicle even all RSUs have been compromised. Extensive analysis demonstrates that the proposed scheme outperforms previously reported ones in terms of the revocation cost and the RSUs service overhead.
Yipin Sun, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen, Jinshu Su
ICC5
2010 Roadside Units Deployment for Efficient Short-Time Certificate Updating in VANETs
abstract
Roadside Units (RSUs) aided distributed certificate service is a promising approach for ensuring security and privacy preservation in vehicular ad hoc networks (VANETs), where the existence of RSUs is critical for such a scheme in order to allow On-Board Units (OBUs) to update their short-time certificates on time. However, RSUs may only be deployed at some critical points along roads due to the cost. In this paper, we propose a cost-efficient RSUs deployment scheme to guarantee that OBUs at any place could communicate with RSUs in certain driving time (DT), and the extra overhead time (ET) of adjusting routes to update short-time certificate is small. Based on a real-world map, several deployment examples are given illustrating the influence of key factors in RSUs deployment such as wireless communication range, DT and ET. Furthermore, extensive analysis demonstrates that our RSUs deployment scheme can meet the required design goals.
Yipin Sun, Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Jinshu Su
ICC5
2010 A Simple Effective Scheme to Enhance the Capability of Web Servers Using P2P Networks
abstract
Nowadays, web servers are suffering from flash crowds and application layer DDoS attacks that can severely degrade the availability of services. It is difficult to prevent them because they comply with the communication protocol. Peer-to-peer (P2P) networks have been exploited to amplify DDoS attacks, but we believe their available resource, such as distributed storage and network bandwidth, can be used to mitigate both flash crowds and DDoS attacks. In this paper, we propose a server initiated approach to employ deployed P2P networks as distributed web caches, so that the workload directed to web servers can be reduced. In experiments, we use Kad as the particular P2P network for the realization of a large-scale distributed web cache. We performed comprehensive evaluation on the feasibility, efficiency and robustness of our scheme, through experiments and simulations on the prototype we implemented. The evaluation results show that our scheme can increase the capacity of the protected web servers at least 10 times at the same cost of connection and bandwidth consumption. The web contents cached in Kad remain reachable even under churn of peers and targeted DoS attack, and the access latency is comparable to normal direct access to web servers. It also achieves good load balancing under the heavy-tailed distribution of object popularity.
Jie Yu 0008, Zhoujun Li 0001, Xiaofeng Wang 0002, Jinshu Su
ICPP5
2010 TH-1: China's first petaflop supercomputer
Xuejun Yang, Xiangke Liao, Weixia Xu 0001, Junqiang Song, Qingfeng Hu, Jinshu Su, Liquan Xiao, Kai Lu 0001, Qiang Dou, Juping Jiang, Canqun Yang
Frontiers Comput. Sci. China6
2010 A concurrent dynamic logic of knowledge, belief and certainty for multi-agent systems
Lijun Wu 0001, Jinshu Su, Kaile Su, Zhihua Yang
Knowl. Based Syst.2
2009 Reliability-Driven Reputation Based Scheduling for Public-Resource Computing Using GA
abstract
For an application in public-resource computing environments, providing reliable scheduling based on resource reliability evaluation is becoming increasingly important. Most existing reputation models used for reliability evaluation ignore the time influence. And very few works use a robust genetic algorithm to optimize both time and reliability for a workflow application. Hence, in this paper, we propose the reliability-driven (RD) reputation, which is time dependent and can be used to evaluate a taskpsilas reliability directly using the exponential failure model. Based on the RD reputation, we also propose knowledge-based genetic algorithm (KBGA) to optimize both time and reliability for a workflow application. KBGA uses heuristics to accelerate the evolution process without giving invalid solutions. Our experiments show that the RD reputation can improve the reliability of a workflow application with more accurate reputation, while the KBGA can evolve to better scheduling solutions more quickly than traditional genetic algorithms.
Xiaofeng Wang 0002, Chee Shin Yeo, Rajkumar Buyya, Jinshu Su
AINA4
2009 Reliability-Oriented Genetic Algorithm for Workflow Applications Using Max-Min Strategy
abstract
To optimize makespan and reliability for workflow applications, most existing works use list heuristics rather than genetic algorithms (GAs) which can usually give better solutions. In addition, most existing GAs evolve a scheduling solution randomly, which may give invalid solutions or lead to slow convergence of the algorithm. In this paper, we define three heuristics for GAs to decide the priorities for a resource and a task dynamically. We propose look-ahead genetic algorithm (LAGA) to optimize both makespan and reliability for workflow applications. It uses a novel evolution and evaluation mechanism: the genetic operators evolve the task-resource mapping for a scheduling solution, while the solutionpsilas task order is determined in the evaluation step using our new max-min strategy, which is specifically proposed for GAs. Our experiments show that LAGA can provide better solutions than existing list heuristics and evolve to better solutions more quickly than a traditional genetic algorithm.
Xiaofeng Wang 0002, Rajkumar Buyya, Jinshu Su
CCGRID3
2009 A new broadcast-Key Management Scheme for Distributed Wireless Sensor Networks
abstract
The management of broadcast-key is one of the most important security problems in the distributed wireless sensor networks. Firstly, the broadcast-key should be calculated and used by each node. Secondly, the broadcast-key should also be updated according to the variation of security condition. In this paper, we propose a new broadcast-key management scheme which has many advantages over the famous μTESLA protocol. The analysis in this paper demonstrates its feasibility, efficiency and security for broadcast-key establishment and renewing in distributed Wireless Sensor Networks.
YingZhi Zeng, Xia Yan, Jinshu Su
MASS3
2009 A new Group Key Management Scheme based on DMST for Wireless Sensor Networks
abstract
Communication via self-organization is a practical and most common model for wireless sensor network. Its security, efficiency and cost and corresponding key management are one of the key research topics on WSN security. This paper proposes a group key management scheme for WSN based on an original self-organized structure, grid-loop. The group which we called Grid-loop is constructed on distributed Minimum Spanning Tree. Our group key management scheme has many advantages over cluster-based scheme. The analysis and comparison demonstrates its feasibility, efficiency and security for key establishment and maintenance in Wireless Sensor Networks.
YingZhi Zeng, Xia Yan, Jinshu Su
MASS3
2009 MORT: A Technique to Improve Routing Efficiency in Fault-Tolerant Multipath Routing
abstract
Multipath routing is thought of as a promising direction of the current routing system as it can improve the network performance in terms of reliability and throughput. However, there are some challenging problems to solve towards Internet-wide multipath routing. One of them is the dramatically increasing control message overhead caused by network dynamics. More message overhead will consume more computing resources and more storage. Meanwhile, more message overhead will lead to slower convergence process for routing protocols due to longer processing time. In this paper, we present MORT to solve the above problem. MORT is based on a technique called ¿information hiding¿. The ¿information hiding¿ technique allows routers in network to hide some routing information such as link failures and link cost changes to other routers without introducing any serious bad effect to the routing protocols. Multipath routing protocols embedded with MORT will have fewer routing message overhead and shorter routing convergence time when facing network events such as link failures and link recoveries. In the simulations, we apply MORT to a newly presented multipath protocol to show that MORT can reduce message overhead significantly as well as shortening the routing convergence time.
Bin Dai 0001, Huabiao Lu, Zhigang Sun 0002, Ziming Song, Yanpeng Ma, Jinshu Su
MSN6
2009 Network Access Control Mechanism Based on Locator/Identifier Split
abstract
Legacy IP address-based access control has met many challenges, because the network nodes cannot be identified accurately based on their variable IP addresses. ldquolocator/identifier splitrdquo has made it possible to build a network access control mechanism based on the permanent identifier. With the support of ldquolocator/identifier splitrdquo routing and addressing concept, the identifier-based access control (IBAC) makes network access control more accurate and efficient, and fits for mobile nodespsila access control quite well. Moreover, Self-verifying Identifier makes it possible for the receiver to verify the packet senderpsilas identity without the third part authentication, which greatly reduces the probability of ldquoidentifier spoofingrdquo.
Rui Tu, Jinshu Su, Feng Chen 0015
NAS2
2008 An Efficient Approach to Minimum-Cost Network Hardening Using Attack Graphs
abstract
Attack graphs can reveal the threat of sophisticated multi-step attacks by enumerating possible sequences of exploits leading to the compromise of given critical resources. Finding a solution to remove such threats by hands is tedious and error prone, particularly for larger and poorly secured networks. Existing automated approaches for hardening a network has an exponential complexity and is not scalable to large networks. This paper proposes a novel approach of applying the Reduced Ordered Binary Decision Diagram (ROBDD) method to network hardening. Existing mature optimization techniques in ROBDD makes the proposed approach an efficient solution that can potentially be applied to large networks.
Feng Chen 0015, Lingyu Wang 0001, Jinshu Su
IAS3
2008 Modeling and Analyzing the Instantaneous Stability for Application Layer Multicast
abstract
Both IP multicast and application layer multicast (ALM) are always using tree structure as data delivery path, but the adaptiveness to the dynamic behaviors of member nodes in ALM trees is weaker than that of IP multicast trees. In ALM tree, when a parent node leaves or fails, all its descendent nodes must adjust their positions in the ALM tree, which causes the interruption of multicast data transmission seriously. This phenomenon is called stability problem of ALM trees. Firstly, this paper analyzes the stability problem of ALM trees and proposes the instantaneous stability degree model (ISDM). Secondly, an approach that takes advantage of the statistical properties of memberpsilas join-leave behaviors is proposed to estimate the Leave Probabilities of member nodes for the model. Thirdly, the various factors related to the instantaneous stability of ALM trees are analyzed through simulations. The modeling and analyzing the instantaneous stability of ALM trees have established a theoretical basis for constructing stable ALM trees, and therefore some possible directions for the future work are discussed finally.
Jijun Cao, Jinshu Su, Chunqing Wu
APSCC2
2008 Analysis of Reverse Traffic in Delay-Based Congestion Control
abstract
Previous theory and experiments show that delay- based algorithm, e.g. TCP Vegas, outperforms other congestion control algorithms with loss-based events. Unfortunately, previous analytic models of TCP Vegas always omit the impact of traffic in reverse path. To address this problem, we develop a simple analytic model in the presence of traffic in reverse path. This model captures the key innovative mechanisms that TCP Vegas employs during congestion avoidance and studies the relations between equilibrium window size and round trip time (RTT). In order to do this, We split RTT to two parts: forward trip time and reverse trip time. Results show that the delay time in reverse path has the same importance as forward data path in determining equilibrium window size and throughput of delay- based algorithm in congestion control.
Jinshu Su
ICDS2
2008 Analysis and Enhancement of Delay-Based Congestion Control
abstract
Previous delay-based congestion control algorithms always omit the impact of traffic in reverse path, e.g. TCP Vegas. To address this problem, we analyze the relation between TCP performance and reverse traffic and describe a novel approach, unidirectional trip aware TCP, UTA TCP, for congestion control in high-speed long-latency networks, from design to implementation. Results of our experiments show that UTA TCP outperforms those conventional delay-based congestion control algorithms.
Jinshu Su
ICDS2
2008 Route recovery in vertex-disjoint multipath routing for many-to-one sensor networks
abstract
Multipath routing is attractive for load-balancing, fault-tolerance, and security enhancement. However, constructing and maintaining a set of node-disjoint paths between the data source and sink is non-trivial in a dynamic environment. In this paper, we study the problem of route recovery in vertex-disjoint multipath routing for sensor networks with many-to-one traffic patterns. We identify the sufficient conditions for multipaths to be recovered when the existing node-disjoint paths are broken, and provide a simple framework for multipath maintenance. This framework is very efficient in time when multipath source routing is employed. Our findings can help to conserve network resource by not launching any route discovery when the data source realizes that a new route may not exist, to guide mobile data sources to relocate themselves in order to reconstruct the new multipaths, and to help newly-deployed data sources quickly determine whether the required number of multipaths exist for sure or not and then compute them. The technique proposed in this paper is a good complement to the classic max-flow algorithm when node-disjoint multipaths are needed.
Wei Cheng 0001, Xiuzhen Cheng, Xicheng Lu, Jinshu Su, Yujun Liu 0002
MobiHoc6
2008 Topology Aware Task Allocation and Scheduling for Real-Time Data Fusion Applications in Networked Embedded Sensor Systems
abstract
In networked embedded sensor systems, data fusion is a viable solution to significantly reduce energy consumption while achieving real-time guarantee. Emerging data fusion applications demand efficient task allocation and scheduling techniques. However, existing approaches can not be effectively applied concerning both network topology and wireless communications. In this paper, we formally model TATAS, the topology-aware task allocation and scheduling problem for real-time data fusion applications, and show it is NP-complete. We also propose an efficient three-phase heuristic to solve the TATAS problem. We implement our technique and conduct experiments based on a simulation environment. Experimental results show that, as compared with traditional approaches, our technique can achieve significant energy saving and effectively meet the real-time requirements as well.
Baokang Zhao, Meng Wang 0005, Zili Shao, Jiannong Cao 0001, Keith C. C. Chan, Jinshu Su
RTCSA6
2007 Efficient Congestion Control Based on Awareness of Multistage Resources (CC-AMR)
Jijun Cao, Xiangquan Shi, Chunqing Wu, Jinshu Su, Zhaowei Meng
APNOMS4
2007 Using NIC-Based Multicast Scheme to Improve Forwarding Rate for Application Layer Multicast
abstract
Recently, application layer multicast (ALM) has become an effective alternative to IP multicast across the Internet. By deeply analyzing the characteristics of traditional packet forwarding in end host, this paper proposes a high performance multicast scheme, in which a NIC-based multicast mechanism is used to send multiple replicas of a ALM packet to different destinations with less CPU intermediation compared to the traditional host- based multicast scheme. By adopting the NIC-based multicast scheme, the CPU overhead and the number of times data packets are copied from host memory to NIC buffer are reduced. Theoretical analysis indicates that the new scheme can notably decrease the multicast delay and enhance the service capability of ALM proxies. We have modified the NIC driver and added some corresponding APIs to network protocol stack in order to implement the proposed scheme. Experimental results illustrate that the NIC-based multicast scheme can greatly improve forwarding rate for ALM.
Jijun Cao, Jinshu Su, Chunqing Wu
APSCC2
2007 A Uniform Fine-Grain Frame Spreading Algorithm for Avoiding Packet Reordering in Load-Balanced Switches
abstract
Network operators need high capacity router architectures that can offer scalability, provide throughput guarantees, and maintain packet ordering. However, current centralized crossbar-based architectures cannot scale to fast line rates and high port counts. On the other hand, while load-balanced switch architectures that rely on two identical stages of fixed configuration meshes appear to be an effective way to scale Internet routers to very high capacities, they incur a large worst-case packet reordering that is at best quadratic to the switch size. In this paper, we propose a Uniform Fine-grain Frame Spreading (UFFS) algorithm to avoid packet reordering throughout the load-balanced switch by assigning cells of the same flow to the fixed successive intermediate inputs. In order to distribute traffic equally among the intermediate inputs, a rotation mapping algorithm is used to construct a fixed mapping relationship between flows of different inputs and intermediate inputs in a round-robin fashion. The UFFS algorithm is distributed and can operate independently in each input. It spreads each flow to intermediate inputs according to the mapping relationship that is precomputed by the rotation mapping algorithm. We show that the UFFS algorithm can enforce packet ordering and achieve 100 % throughput with no additional communication of information among linecards.
Jinshu Su, Zhigang Sun 0002, Jianbo Guan
APSCC2
2007 LBKERS: A New Efficient Key Management Scheme for Wireless Sensor Networks
YingZhi Zeng, Jinshu Su, Xia Yan, Baokang Zhao, QingYuan Huang
MSN2
2006 Delay-Bounded Range Queries in DHT-based Peer-to-Peer Systems
abstract
Many general range query schemes for DHT-based peer-to-peer (P2P) systems have been proposed, which do not need to modify the underlying DHTs. However, most existing works have the query delay depending on both the scale of the system and the size of the query space or the specific query, and thus cannot guarantee to return the query results in a bounded delay. In this paper, we propose Armada, an efficient general range query scheme to support single-attribute and multipleattribute range queries. Armada is the first delaybounded range query scheme over constant-degree DHTs, and can return the results for any range query within 2logN hops in a P2P system with N peers. Results of analysis and simulations show that the average delay of Armada is less than logN, and the average message cost of single-attribute range queries is about logN+2n..2 (n is the number of peers that intersect with the query). These results are very close to the lower bounds on delay and message cost of range queries over constant-degree DHTs.
Dongsheng Li 0001, Xicheng Lu, Jinshu Su, Jiannong Cao 0001, Keith C. C. Chan, Hong Va Leong
ICDCS4
2004 A Clustering-Based Data Replication Algorithm in Mobile Ad Hoc Networks for Improving Data Availability
Jinshu Su, Xicheng Lu
ISPA2
2004 Graph-Theoretic Analysis of Kautz Topology and DHT Schemes
Dongsheng Li 0001, Xicheng Lu, Jinshu Su
NPC3