EDBT 2026 Demo / reviewers in the wild / expert
Yongning Tang
dblp:16/5813
· DBLP profile ↗
25ranked-venue papers
12as first author
5since 2021 · last 2026
0009-0003-5152-8841ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 7 first-author · 1 since 2021Systems, architecture and hardware · 3 · 2 first-authorSecurity and privacy · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 2FiA: Towards WiFi Sensing-Based Authentication with Unique Biometrics
Bofan Li, Zhankai Ye, Weikuan Yu, Yongning Tang, Liu Xiu |
SP | 4 |
| 2026 | Order-Preserving Pattern Matching: ReviewabstractOrder-preserving pattern matching (OPPM) is a specialized area within the domain of pattern recognition and string matching. This specialized area is dedicated to identifying patterns in sequences where the intrinsic order of elements is crucially important. This comprehensive review provides an in-depth analysis of diverse order-preserving pattern matching techniques, focusing on their algorithms and methodologies. Particular attention is paid to the challenges researchers face in preserving order during pattern matching. The review also evaluates the performance and scalability of various techniques to handle large-scale datasets. By discussing the current state of OPPM research, we identify gaps, opportunities, and potential avenues for future exploration. Through this exploration, we aim to contribute valuable insights that will guide researchers and practitioners in advancing the frontiers of OPPM research, shaping the trajectory of this field in the coming years. Feng Wang 0017, Yongning Tang |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2025 | Fusion-Based Traffic Prediction for 5G Slicing: a Hybrid Lstm-Transformer ModelabstractNetwork slicing in 5G enables flexible resource allocation but faces challenges in accurate traffic prediction due to dynamic variations, inter-slice dependencies, and real-time constraints. LSTM models capture temporal dependencies but struggle with cross-slice interactions, while Transformer models excel in inter-slice data fusion but have high computational costs and limited sequential modeling. This paper proposes a novel hybrid LSTM-Transformer model for multi-slice traffic prediction, integrating the strengths of both architectures. The LSTM component captures short- and longterm temporal dependencies, while the Transformer component models inter-slice relationships through self-attention mechanisms. The proposed approach enables fusion-aware forecasting, improving predictive accuracy and scalability in dynamic network environments. To validate the effectiveness of our model, we conduct experiments using two real-world datasets: the CRAWDAD umkc/networkslicing5g dataset and the Telecom Italia mobile network dataset. The evaluation considers three key performance metrics: prediction accuracy, scalability, and response time. Comparative analysis against baseline models, including ARIMA, LSTM, Transformer, and CNN-LSTM, demonstrates that the hybrid model achieves 7.8 % MAPE, outperforming all baselines while maintaining real-time feasibility with a response time of 24.6 ms per batch. Yongning Tang, Feng Wang 0017, Zutong Hu, Chung-Chih Li |
FUSION | 1 |
| 2023 | SINT: Toward a Blockchain-Based Secure In-Band Network Telemetry ArchitectureabstractThe foundation of network management is to timely, accurately, and flexibly monitor the status of a managed network. Recently, In-band Network Telemetry (INT) has presented its unique capabilities in acquiring the insights of a network and thus has been adopted in many production networks. However, less attention was put on the potential threats on INT (e.g., the man-in-the-middle attacks, Trojan horse injection) that may falsify network measurements resulting in catastrophic consequences. In this paper, we propose a secure INT architecture calledSINTthat can effectively mitigate INT vulnerabilities and can be implemented using ’chiplet’ based multi-modal network processors (MNP). SINT adopts blockchain technology into INT, in which a network status snapshot acquired via INT is viewed as a block and added into a network telemetry blockchain to prevent arbitrary access and malicious modification. To minimize the intrusiveness of the INT and blockchain operations, SINT is designed to be a lightweight protocol and uses improved RAFT consensus mechanisms to reduce its network and computing overhead. The design of the chiplet MNP system makes SINT highly flexible and adaptive to facilitate INT convergence and related blockchain updates. In the SINT architecture, INT tasks and blockchain operations are dispatched to different chips to achieve an optimal trade-off among measurement accuracy, security requirements, and computing resource on the data plane. Experiments and simulations show that SINT can alleviate most cyberattacks on INT and retain 97% of bandwidth utilization for other users’ normal traffic in a complex scenario with 500 nodes. Furthermore, SINT converges the INT results quickly and accurately with minor overhead compared to that of the state-of-art INT methods. Yuyu Zhao, Guang Cheng 0001, Yongning Tang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | The Diminished Importance of Connection-based Features in Intrusion DetectionabstractToday, more and more Machine Learning (ML) and Deep Learning (DL) techniques are adopted to attain efficient feature selection for intrusion detection. Previous efforts have demonstrated that the major challenge of creating efficient ML and DL-based intrusion detection is to determine appropriate features without negatively affecting classification accuracy. This paper explores the impact of connection-based features on performing intrusion detection models, precisely the effect of connection-based features on detecting DDoS attacks in the CICDDoS2019 dataset. We used ML methods where samples trained with Decision Tree (DT) and Random Forest (RF) classifiers with and without connection-based features, understanding the effect on performance, stability, and its diminishing sensitivity with more samples. Our analysis shows that performing connection-based features depends on the available training sample size. Thus, connection-based features significantly impact classification accuracy concerning small training samples, how its importance is diminished along with increased sample size, and their strong effect on imbalanced malicious attacks. Jessil Fuhr, Isaac Hanna, Feng Wang 0017, Yongning Tang |
IPCCC | 4 |
| 2020 | A practical design of hash functions for IPv6 using multi-objective genetic programming
Ying Hu 0007, Guang Cheng 0001, Yongning Tang, Feng Wang 0017 |
Comput. Commun. | 3 |
| 2019 | Intelligence Enabled SDN Fault Localization via Programmable In-band Network TelemetryabstractIntelligent Fault localization for SDN becomes one of the most critical but difficult tasks. This paper proposes a new approach called Policy-Aware In-band Network Telemetry (PAINT) to tackle SDN fault localization. In the PAINT system, network operators define and deploy network services using a high-level Service Provisioning Language (SPL). Then, PAINT automatically parses the service policy to infer the causal relationship between service related network components and (end-to-end) service-level observable symptoms. Based on the causality model, PAINT deploys monitoring instruments for the symptoms. PAINT utilizes a dynamically created Symptom-Fault-Telemetry model to incorporate In-band Network Telemetry (INT) actions systematically into the fault reasoning process to improve the efficiency and accuracy of fault localization for SDN. PAINT has been extensively evaluated in a simulation environment for its accuracy and scalability with very positive results. Yongning Tang, Yangxuan Wu, Guang Cheng 0001, Zhiwei Xu 0001 |
HPSR | 1 |
| 2017 | eOpenFlow: Software defined sampling via a highly adoptable OpenFlow extensionabstractSampling is highly demanded in software defined networking (SDN) by the need to control the consumption of network measurement resources and by the need of detailed measurements from applications and service providers. Open-Flow, as the standard control protocol between SDN controller and switches, is not equipped with traffic sampling function. In this paper, we proposes a software defined sampling measurement scheme via an adoptable extension to OpenFlow called eOpenFlow. In the data plane of SDN switch, the sampling action OFPAT_OUTPUT_SAMPLING is added to sample user defined specific traffic flows. We present two different sampling rules, which are based on multi-level flow table and group-based table mechanisms, respectively. In SDN control plane, collected network samples are analyzed to realize various measurement functions. eOpenFlow has been implemented, and further evaluated via carefully designed experiments in order to verify its different sampling functions. Guang Cheng 0001, Yongning Tang |
ICC | 2 |
| 2016 | Service Oriented Verification Integrated Fault Reasoning for SDNsabstractFault localization is a core element in SDN networkmanagement. Many SDN fault reasoning and verificationtechniques assist operators focus on either analyzing the controlplane configuration or checking the data plane network behavior. These solutions are limited in that they cannot correlate networksymptoms between the control and the data planes, and areharder to generalize across protocols since they have to modelcomplex configuration languages and dynamic protocol behavior. This paper proposes a new approach called Service OrientedVerification Integrated Reasoning (SOVIR) to tackle SDN faultreasoning. In the SOVIR system, a network user can request oneor multiple network services via a high level Service ProvisioningLanguage (SPL). SOVIR automatically parses each provisionedservice and presents it as a logical Service View, which consistsof a pair of logical end nodes, a service specification, and alist of required network functions (e.g., load balancer). Afterprovisioned in an SDN network, SOVIR queries the controllerabout the network topology and flow rules from all SDN switches. Based on the flow rules and the configuration of end nodesand network function nodes, SOVIR maps the Service View toan Implementation View, in which all the logical componentsin the Service View are mapped to the actual system componentsalong with the actual network topology. SOVIR usesan extended Symptom-Fault-Verification model to incorporatevarious verification techniques systematically into fault reasoningprocess to localize the faults in SDN. SOVIR has been evaluatedin a simulation environment for its accuracy and efficiency. The evaluation shows that with SOVIR, both performance andaccuracy of fault reasoning in the simulated SDN networks canbe greatly improved by taking properly selected verification toolson specific network entities. Yongning Tang, Guang Cheng 0001, Zhiwei Xu 0001, Feng Chen 0025 |
AINA | 1 |
| 2016 | Towards QoE assessment of encrypted YouTube adaptive video streaming in mobile networksabstractVideo streaming has become one of the most prevalent mobile applications, and takes a huge portion of the traffic on mobile networks today. YouTube is one of the most popular and volume-dominant video content providers. Understanding the user perception on the quality (i.e., Quality of Experience or QoE) of YouTube video streaming services is thus paramount for the content provider as well as its content delivery network (CDN) providers. Although various video QoE assessment approaches proposed to use different Key Performance Indicators (KPIs), they are all essentially related to a common parameter: Bitrate. However, after YouTube adopted HTTPS as its adaptive video streaming method to better protect user privacy and network security, bitrate cannot be obtained anymore from encrypted video traffic via typical deep packet inspection (DPI) method. In this paper, we tackle this challenge by proposing a machine learning based bitrate estimation (MBE) approach to parse bitrate information from IP packet level measurement. For evaluating the effectiveness of MBE, we have chosen video Mean Opinion Score (vMOS) proposed by a leading telecom vendor, as the QoE assessment framework, and have conducted comprehensive experiments to study the impact of bitrate estimation accuracy on its KPIs for HTTPS YouTube video streaming service. Experimental results show that MBE is a feasible and highly effective approach to obtain in real time the bitrate information from encrypted video streaming traffic. Wubin Pan, Gaung Cheng, Hua Wu 0004, Yongning Tang |
IWQoS | 4 |
| 2013 | Line speed accurate superspreader identification using dynamic error compensation
Guang Cheng 0001, Yongning Tang |
Comput. Commun. | 2 |
| 2012 | Towards an efficient verification approach on network configuration
Khalid Elbadawi, Yongning Tang, James T. Yu |
CNSM | 2 |
| 2012 | Reasoning under Uncertainty for Overlay Fault DiagnosisabstractThe performance and reliability of overlay services rely on the underlying overlay network's ability to effectively diagnose and recover from faults such as link failures and overlay node outages. However, overlay networks bring to fault diagnosis new challenges such as large-scale deployment, inaccessible underlay network information, dynamic symptom-fault causality relationship, and multi-layer complexity. In this paper, we develop an evidential overlay fault diagnosis framework called DigOver to tackle these challenges. Firstly, DigOver identifies a set of potential faulty components based on shared end-user observed negative symptoms. Then, each potential faulty component is evaluated to quantify its fault likelihood and the corresponding evaluation uncertainty. Finally, DigOver dynamically constructs a plausible fault graph to locate the root causes of end-user observed negative symptoms. Both simulation and Internet experiments demonstrate that DigOver can effectively and accurately diagnose overlay faults based on end-user observed negative symptoms. Yongning Tang, Ehab Al-Shaer, Kaustubh R. Joshi |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2011 | Probabilistic and reactive fault diagnosis for dynamic overlay networks
Yongning Tang, Guang Cheng 0001, Zhiwei Xu 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2009 | Sharing end-user negative symptoms for improving overlay network dependabilityabstractThe dependability of overlay services rely on the overlay network's capabilities to effectively diagnose and recover faults (e.g., link failures, overlay node outages). However, overlay applications bring to overlay fault diagnosis new challenges, which include large-scale deployment, inaccessible underlying network information, dynamic symptom-fault causality relationship, and multi-layer complexity. In this paper, we develop an evidential overlay fault diagnosis framework (called DigOver) to tackle these challenges. Firstly, the DigOver identifies a set of potential faulty components based on shared end-user observed negative symptoms. Then, each potential faulty component is evaluated to quantify its fault likelihood and the corresponding evaluation uncertainty. Finally, the DigOver dynamically constructs a plausible fault graph to locate the root causes of end-user observed negative symptoms. Yongning Tang, Ehab Al-Shaer |
DSN | 1 |
| 2009 | Overlay Fault Diagnosis Based on Evidential ReasoningabstractThe attractive characteristics of overlay networks bring to overlay fault diagnosis new challenges, which include inaccessible underlying network information, incomplete and inaccurate network status observations, dynamic symptom-fault causality relationship, and multi-layer complexity. To address these challenges, we propose a novel evidential reasoning based overlay fault diagnosis technique called ERD. Firstly, by analyzing end-user observed network symptoms, ERD narrows down suspicious components, and investigates their status (i.e., good or bad) with likelihood measurement and uncertainty evaluation using a novel evidence-driven belief function. Next, ERD adapts to the changes in highly dynamic overlay networks by dynamically constructing plausible fault diagnosis graph based on belief evaluation. Finally, ERD conducts plausible fault reasoning to locate the root causes of observed network symptoms. Yongning Tang, Ehab Al-Shaer |
INFOCOM | 1 |
| 2009 | A Trace Measurement and Analysis System for the Multi-Links CERNET BackboneabstractCurrently, researchers study the traffic difference of various Internet applications, and analyze the impacts on network performance and quality of service, mainly through network measuring, to explore the unknown behaviors performed by this huge complex nonlinear system. Passive measurement can get the measurement data which most truly reflect network behavior, so it is widely used in the network measurement. However, in the high-speed network, it is difficult to measure, process, storage and analyze the measured massive data. Under the background of passive measurement for the large-scale high-speed network, this paper focuses on measurement, collation, storage and analysis of the massive data, which was closely related to the measurement and behavior analysis. This paper will design and implement a Trace Measurement and Analysis System for the Multi-links CERNET Backbone (TMASM), and it would test TMASM using a JSERNET trace. In this paper, first, we design and implement TMASM, then discuss the features of the data captured by Watcher measurement subsystem. We study the strategy of processing the parallel links packet data collected from Jiangsu Province border multi-links of CERNET backbone. The Architecture of TMASM supports scalability in order to expand the analysis functions only through a simple approach. Finally, TMASM is tested, and a Trace collected from Jiangsu Province border channel of CERNET is analyzed using TMASM. Guang Cheng 0001, Yongning Tang, Jiexin Jiang, Wei Ding 0001 |
NAS | 2 |
| 2009 | Community-base Fault Diagnosis Using Incremental Belief RevisionabstractOverlay networks have emerged as a powerful and flexible platform for developing new disruptive network applications. The attractive characteristics of overlay networks such as planetary-scale distributions, user-level flexibility (e.g., overlay routing) and manageability bring to overlay fault diagnosis new challenges, which include inaccessible underlying network information, incomplete and inaccurate network status observations; dynamic symptom-fault causality relationships, and multi-layer complexity. To address these challenges, we propose a distributed user-level Belief Revision based overlay fault diagnosis technique called EUDiag. EUDiag can passively use observed overlay symptoms as reported by overlay monitoring agents to correlate and diagnose faults, and select the least-costly appropriate probing actions whenever necessary to enhance the passive fault reasoning results. EUDiag adapts to the changes in highly dynamic overlay networks by incrementally revising user beliefs based on new observed overlay symptoms. EUDiag can diagnose faults without relying on underlying network fault probabilistic quantifications (e.g. prior fault probability).Simulations and experimental studies show that EUDiag can efficiently (e.g. low latency) and accurately localize root causes of overlay faults/problems, even when the observed symptoms are incomplete. Yongning Tang, Guang Cheng 0001, Zhiwei Xu 0001, Ehab Al-Shaer |
NAS | 1 |
| 2008 | Towards Collaborative User-Level Overlay Fault DiagnosisabstractOverlay networks have emerged as a powerful and flexible platform for developing new disruptive network applications. The attractive characteristics of overlay networks such as planetary-scale distributions, user-level flexibility (e.g. overlay routing) and manageability bring to overlay fault diagnosis new challenges, which include inaccessible underlying network information, incomplete and inaccurate network status observations; dynamic symptom-fault causality relationships, and multi-layer complexity. To address these challenges, we propose a collaborative overlayUserObservationbased fault diagnosis technique called OUD. OUD can passively use observed overlay symptoms as reported by overlay monitoring agents to correlate multiple users' observations to diagnose faults. OUD can diagnose faults without relying on underlying network fault probabilistic quantifications (e.g. prior fault probability). Simulations and experimental studies show that OUD can efficiently (e.g. low latency) and accurately localize root causes of overlay faults/problems, even when the observed symptoms are incomplete. Yongning Tang, Ehab Al-Shaer |
INFOCOM | 1 |
| 2008 | Efficient fault diagnosis using incremental alarm correlation and active investigation for internet and overlay networksabstractFault localization is the core element in fault management. Symptom-fault map is commonly used to describe the symptom-fault causality in fault reasoning. For Internet service networks, a well-designed monitoring system can effectively correlate the observable symptoms (i.e., alarms) with the critical network faults (e.g., link failure). However, the lost and spurious symptoms can significantly degrade the performance and accuracy of a passive fault localization system. For overlay networks, due to limited underlying network accessibility, as well as the overlay scalability and dynamics, it is impractical to build a static overlay symptom-fault map. In this paper, we firstly propose a novel active integrated fault reasoning (AIR) framework to incrementally incorporate active investigation actions into the passive fault reasoning process based on an extended symptom-fault-action (SFA) model. Secondly, we propose an overlay network profile (ONP) to facilitate the dynamic creation of an overlay symptom-fault-action (called O-SFA) model, such that the AIR framework can be applied seamlessly to overlay networks (called O-AIR). As a result, the corresponding fault reasoning and action selection algorithms are elaborated. Extensive simulations and Internet experiments show that AIR and O-AIR can significantly improve both accuracy and performance in the fault reasoning for Internet and overlay service networks, especially when the ratio of the lost and spurious symptoms is high. Yongning Tang, Ehab Al-Shaer, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2007 | Toward Globally Optimal Event Monitoring & Aggregation For Large-scale Overlay NetworksabstractOverlay networks have emerged as a powerful and flexible platform for developing new disruptive network applications. The performance and reliability of overlay applications depend on the capability of overlay networks to dynamically adapt to various factors such as link/node failures, overlay link quality, and overlay node characteristics. In order to achieve this, the overlay applications require scalable and open overlay monitoring services to monitor, aggregate globally distributed events and take appropriate control actions. In this paper, we propose the techniques and algorithms to create an optimal event monitoring and aggregation infrastructure (called MOON) that minimizes the monitoring latency (i.e., event retrival/detection time) and event aggregation cost (i.e., intrusiveness) considering the large-scale geographical and network distribution of overlay nodes. The proposed monitoring infrastructure, MOON, clusters and organizes overlay nodes efficiently such that overlay applications can globally monitor and query correlated events in an overlay network with minimum latency and monitoring cost. Our simulations and experimental studies show the evaluation of MOON under many various topological structures, network sizes, and event aggregation volumes. Yongning Tang, Ehab Al-Shaer, Bin Zhang 0007 |
Integrated Network Management | 1 |
| 2005 | Active integrated fault localization in communication networksabstractFault localization is a core element in fault management. Many fault reasoning techniques use deterministic or probabilistic symptom-fault causality model for fault diagnoses and localization. Symptom-fault map is commonly used to describe symptom-fault causality in fault reasoning. However, due to lost and spurious symptoms in fault reasoning systems that passively collect symptoms, the performance and accuracy of the fault localization can be significantly degraded. In this paper, we propose an extended symptom-fault-action model to incorporate actions into fault reasoning process to tackle the above problem. This technique is called active integrated fault reasoning (AIR), which contains three modules: fault reasoning, fidelity evaluation and action selection. Corresponding fault reasoning and action selection algorithms are elaborated. Simulation study shows both performance and accuracy of fault reasoning can be greatly improved by taking actions, especially when the rate of spurious and lost symptoms is high. Yongning Tang, Ehab Al-Shaer, Raouf Boutaba |
Integrated Network Management | 1 |
| 2004 | MRMON: remote multicast monitoringabstractAlthough IP multicasting has been deployed for more than a decade, management of multicast networks and services is still a challenging problem. The fact that IP multicast is a receiver-oriented and stateless protocol makes end-to-end multicast monitoring an intractable task. Important multicast information such as join/leave status, group membership, tree information, path/traffic characteristics, and session status is either unrevealed or distributed in various locations on the network. In this paper, we present a new remote passive multicast monitoring infrastructure, called MRMON, to capture, analyze and present multicast session, traffic and membership information in real time. The MRMON probes inhabit a well-organized multicast information structure (MIB) that provides a comprehensive view of multicast network activities in remote subnets. We show how information can be collected from different MRMON probes and then correlated to diagnose multicast session problems. MRMON is a crucial step toward effective multicast management, and our goal is to promote MRMON as a standard MIB in multicast management. Ehab Al-Shaer, Yongning Tang |
NOMS (1) | 2 |
| 2002 | SMRM: SNMP-based multicast reachability monitoringabstractOne of the main challenges of deploying multicast services in the Internet is the lack of active monitoring tools that can detect and isolate multicast reachability problems in real-time. Existing multicast monitoring tools are either not scalable or use proprietary protocols which limit their deployment in enterprise networks. This paper presents SNMP-based multicast reachability monitoring (SMRM), a framework for monitoring the health and the quality of multicast delivery paths (or forwarding tree) in real-time. SMRM addresses these limitations by using SNMP as a core component, which significantly facilitates the wide deployment of SMRM in existing networks. The SMRM framework combines distributed monitoring and centralized control, which offers a scalable, easy-to-use and easy-to-deploy multicast monitoring service. Ehab Al-Shaer, Yongning Tang |
NOMS | 2 |
| 2001 | Toward integrating IP multicasting in internet network management protocols
Ehab Al-Shaer, Yongning Tang |
Comput. Commun. | 2 |