EDBT 2026 Demo / reviewers in the wild / expert
Jiahao Cao 0001
dblp:218/8811-1
· DBLP profile ↗
43ranked-venue papers
6as first author
31since 2021 · last 2026
0000-0001-7139-376XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 5 first-author · 14 since 2021Computer networks · 20 · 1 first-author · 16 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Janus: Enabling Expressive and Efficient ACLs in High-speed RDMA Clouds
Ziteng Chen, Menghao Zhang 0001, Jiahao Cao 0001, Xuzheng Chen, Qiyang Peng |
NDSS | 3 |
| 2026 | DDoS Detection at the Scale of One Hundred Tbps
Yunming Xiao, Xijun Luo, Youliang Jiang, Aike Wang, Heng Yu 0005, Jiahao Cao 0001, Yong Jiang 0001, Jilong Wang 0001, Mingwei Xu 0001, Congcong Miao |
NSDI | 8 |
| 2026 | A large-scale measurement study of region-based web access restrictions: The case of China
Yuying Du, Jiahao Cao 0001, Junrui Xu, Yangyang Wang 0001, Renjie Xie, Changliyun Liu, Mingwei Xu 0001 |
Comput. Secur. | 2 |
| 2025 | Assessing the Impact of ISP de-peering: A case study of Cogent's Disconnection from Russian Networks in Routing Perspective
Yuanyuan Zhang 0006, Meijia Hou, Mingwei Xu 0001, Jiahao Cao 0001, Yonghong Fu |
APNet | 6 |
| 2025 | Poster: Uncovering Hidden ASes in ROV Deployment via Temporal FingerprintingabstractBGP, the Internet’s inter-domain routing protocol, is vulnerable to prefix hijacks due to tamperable prefix–origin bindings. RPKI addresses this by cryptographically binding prefixes to authorized ASes, enabling Route Origin Validation (ROV). Given RPKI’s critical role in Internet security, identifying the proportion of ASes that deploy ROV is a key research question. However, measuring ROV deployment is difficult due to limited visibility into private AS configurations. Existing methods suffer from low accuracy, restricted coverage, and the inability to detect hidden ASes whose behavior is masked by upstream ROV deployment. To address these limitations, we propose RIFT, a novel inference method based on temporal fingerprinting. RIFT leverages the insight that periodic ROA retrieval creates distinctive temporal patterns in the routing behavior of ROV-deployed ASes. Experiments show that RIFT achieves 94% accuracy and an F1 score of 0.88 in identifying ROV deployment. Shucan Yang, Jiahao Cao 0001, Mingwei Xu 0001, Renjie Xie, Yangyang Wang 0001 |
ICNP | 5 |
| 2025 | Undermining Delay-based QUIC Congestion Control: A Receiver-driven Attack via Crafted Host DelaysabstractQUIC gains significant attention due to its superior transmission performance, achieving widespread adoption in both academia and industry. To improve round-trip time (RTT) estimation, QUIC introduces the Host Delay field, enabling senders to exclude receiver-induced delays. Many delay-based congestion control algorithms (CCAs) rely on these RTT estimates to detect congestion and regulate sending rates. However, we find that malicious Host Delay values can distort RTT measurements, causing inappropriate rate adjustments by CCAs.In this paper, we investigate a new class of attacks leveraging maliciously crafted Host Delay values. To our knowledge, we are the first to analyze the vulnerability of Host Delay and present QUDIT, a universal receiver-driven attack targeting delay-based QUIC CCAs. Unlike prior attacks that presume full network queuing delays visibility and undetected injection capabilities, our attacker model only grants the adversary access as a standard QUIC receiver with limited knowledge of bottleneck conditions. We minimally modify the QUIC receiver to infer bottleneck queuing behavior in real time. Based on these inferences, we design dynamic Host Delay crafting strategies tailored to the specific behavior of various delay-based CCAs and accounting for random network fluctuations. Our attack prompts the sender to overshoot its rate, leading to excessive bandwidth consumption at the bottleneck and degradation of competing flows. Results demonstrate the throughput degradation of victim flow achieves up to 60% within 0.3 s and amplification gains between 200× and 600×. We propose defenses mitigating QUDIT, with vulnerabilities reported to IETF and QUIC maintainers. Shaorui Ren, Jia Zhang 0010, Enhuan Dong, Mingwei Xu 0001, Jiahao Cao 0001 |
ICNP | 6 |
| 2025 | GM-BFD: A Generalizable Multi-View Framework for Botnet Flow Detection
Xuejiao Luo, Pengcheng Wei, Wenyin Liu, Jiahao Cao 0001 |
INFOCOM | 4 |
| 2025 | GeoWatch: Measuring Geoblocking Practices Towards China at ScaleabstractThis paper presents GeoWatch to conduct the first large-scale measurement study of geoblocking practices towards China. Although prior studies have examined geoblocking in specific contexts as well as China's censorship, GeoWatch focuses on identifying which websites proactively block users from China. It employs advanced domain mining techniques and globally distributed vantage points to identify geoblocking websites, analyzing a total of 97.78 million domains worldwide and identifying 4.54 million geoblocking domains. Yuying Du, Jiahao Cao 0001, Junrui Xu, Yangyang Wang 0001, Changliyun Liu |
IWQoS | 2 |
| 2025 | HeavyFinder: Efficient and Fine-Grained Heavy Hitters Detection with Instantaneous Flow RateabstractThe detection of Heavy Hitters (HH) of flows in a network plays a crucial role in a variety of critical applications, including network topology optimization, congestion control, and network security (e.g., DDoS mitigation). In high-performance data centers, tasks such as optimizing model training and detecting anomalies require microsecond-level granularity for burst and congestion detection, demanding higher accuracy and fine granularity in HH detection. However, existing HH detection schemes primarily focus on traffic accumulation over longer periods and ignore instantaneous flow rates, making them incapable of detecting short-duration heavy hitters (at the granularity of milliseconds to microseconds) that can significantly affect network performance. This paper proposes a rate-sensitive definition of HHs and introduces HeavyFinder, a framework for enabling efficient HH detection of flows at microsecond granularity and accurately describing their traffic changes. It detects HHs based on inherent characteristics of both traffic volume and instantaneous flow rates, and improves the existing elephant flow filtering mechanism. Furthermore, this framework provides an efficient information aggregation method for reporting HH information, which can reduce overhead further. We deployed and tested HeavyFinder on x86 CPUs and evaluated its performance by using real network trace data. Results show that HeavyFinder achieves sub-$\mathbf{1 0}$-microsecond accuracy in detection for the start and end times of HHs, with$3-10 \times$lower reporting overhead compared to existing frameworks. Yangyang Wang 0001, Jiahao Cao 0001, Qilong Shi, Mingwei Xu 0001, Lihua Miao |
IWQoS | 4 |
| 2025 | Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection
Qiyang Song, Heqing Huang 0001, Xiaoqi Jia, Yuanbo Xie, Jiahao Cao 0001 |
NDSS | 5 |
| 2025 | VPGFuzz: Vulnerable Path-Guided Greybox FuzzingabstractFuzzing is a prevalent technology for identifying software vulnerabilities. Existing fuzzing techniques predominantly focus on maximizing code coverage to unearth potential security issues. However, the mere expansion of explored code does not necessarily correlate with an increased discovery of vulnerabilities. Additionally, existing fuzzers often neglect comprehensive execution path information in code exploration. Consequently, potential vulnerabilities may be delayed or overlooked in the fuzzing process. To address this, we propose VPGFUZZ, a vulnerable path-guided fuzzer that can not only explore new code but also exploit known vulnerability path knowledge for vulnerability discovery. It employs a vulnerable path recognition model to identify test cases with potentially vulnerable paths. This model is trained with various execution paths derived from real-world vulnerability PoCs (Proof of Concepts). Based on this model, VPGFUZZ applies an explore-exploit seed selection strategy to effectively choose test cases for testing. Unlike traditional seed selection methods that maintain a single queue for exploring new code, this strategy includes a separate queue for retaining test cases identified as potentially vulnerable, allowing for more thorough testing. Experimental results demonstrate that VPGFUZZ discovers 24 zero-day vulnerabilities, with 18 receiving vulnerability identifiers from third-party organizations such as CVE. Our evaluation also shows VPGFUZZ’s superior efficiency by uncovering the first vulnerability approximately 1.2 to 70 times faster than popular fuzzers in most programs. Zhechao Lin, Jiahao Cao 0001, Xinda Wang 0001, Renjie Xie, Yuxi Zhu, Xiao Li 0044, Qi Li 0002, Yangyang Wang 0001, Mingwei Xu 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Constructing SDN Covert Timing Channels Between Hosts With Unprivileged AttackersabstractSoftware-defined networking (SDN) has been widely deployed due to its centralization and programmable features. However, these new features bring new threats at the same time. Previous studies have shown that SDN covert channels can be built with a privileged adversary that controls SDN key components, such as controller applications or SDN switches. In this paper, we propose new SDN covert timing channels between hosts without controlling applications, controllers, or having access to switches. Experiments in a real SDN testbed demonstrate the feasibility and effectiveness of our covert channels. To defend against the covert timing channels, we design a defense system named CovertGuard, which utilizes the timing characteristics of the covert channels’ delays to detect and eliminate covert channels effectively. Yixiong Ji, Jiahao Cao 0001, Qi Li 0002, Yan Liu 0069, Tao Wei 0002, Ke Xu 0002 |
IEEE Trans. Netw. | 2 |
| 2024 | Poster: Few-Shot Inter-Domain Routing Threat Detection with Large-Scale Multi-Modal Pre-TrainingabstractBorder Gateway Protocol (BGP) plays a pivotal role as the de facto inter-domain routing protocol on the Internet. However, BGP threats continually emerge and undermine the Internet reliability. Existing BGP threat detection methods based on machine learning require substantial labeled data and expert involvement, making them costly and labor-intensive. Moreover, they fail to learn rich information from massive unlabeled BGP data consistently generated on the Internet. In this paper, we propose FIRE that enables few-shot inter-domain routing threat detection with large-scale multi-modal pre-training. FIRE conducts domain-specific pre-training tasks to acquire rich BGP implicit knowledge from massive unlabeled BGP data for few-shot learning. Our experiments show that FIRE can be fine-tuned to precisely identify BGP threats with only a few labeled samples, e.g., a 93.2% precision in route leak detection with merely 8 events for fine-tuning. Jiahao Cao 0001, Renjie Xie, Yangyang Wang 0001, Mingwei Xu 0001 |
CCS | 3 |
| 2024 | Paraleon: Automatic and Adaptive Tuning for DCQCN Parameters in RDMA NetworksabstractRDMA is a kernel-bypass and transport-offload technology that provides high throughput and low delay for datacenter networks, and DCQCN is the default and most widely used congestion control algorithm in large-scale RDMA networks. DCQCN involves over 10 parameters at RNICs and switches, and their settings significantly affect network performance, currently relying heavily on exhaustive manual tuning. Although some automatic methods are proposed to tune a subset of DCQCN parameters, none of them comprehensively address all parameters at both RNICs and switches, resulting in compromised network performance. In this paper, we propose Paraleon, an automatic and adaptive system to tune DCQCN parameters comprehensively. We design a millisecond-level sketch-based monitoring mechanism for accurate network-wide measurement, which collects runtime metrics as feedback to guide the tuning process. We also analyze the complicated parameter impacts on network performance, and leverage an improved heuristic searching algorithm for timely performance optimization with better efficiency and convergence. We implement Paraleon and conduct extensive experiments in both NS3 simulations and a real-world testbed. The results show that Paraleon achieves$3.8 \% \sim 61.4 \%$higher performance than existing tuning schemes. Ziteng Chen, Menghao Zhang 0001, Jiahao Cao 0001, Yang Jing, Mingwei Xu 0001, Renjie Xie, Fangzheng Jiao, Xiaohe Hu |
ICNP | 4 |
| 2024 | Poster: Automatic Network Protocol Fingerprint Discovery with Difference-Guided FuzzingabstractNetwork protocol fingerprinting is a critical technique for identifying various implementations of network protocols, which is essential for vulnerability assessment and security management. However, current fingerprinting methods such as Nmap still heavily rely on manual probe crafting, requiring experts with domain knowledge and leading to inefficiencies and potential oversights. This paper introduces pFuzz, an automatic network protocol fingerprint discovery system utilizing difference-guided fuzzing, to address the challenge of the vast search space inherent in fingerprinting. We propose a difference tree to model the nested recursive condition structure of network protocols and a packet oracle map to capture and utilize multifield relationships revealed by value co-occurrence. Our evaluation of pFuzz on the widely used TCP/IP protocol demonstrates its effectiveness and efficiency on discovering fingerprints. Yuxi Zhu, Hanyi Peng, Jiahao Cao 0001, Renjie Xie, Xinda Wang 0001, Mingwei Xu 0001 |
ICNP | 3 |
| 2024 | Enhancing Pre-trained Language Models for Vulnerability Detection via Semantic-Preserving Data Augmentation
Weiliang Qi, Jiahao Cao 0001, Darsh Poddar, Sophia Li, Xinda Wang 0001 |
SecureComm (4) | 2 |
| 2024 | Cactus: Obfuscating Bidirectional Encrypted TCP Traffic at Client SideabstractAs the mainstream encrypted protocols adopt TCP protocol to ensure lossless data transmissions, the privacy of encrypted TCP traffic becomes a significant focus for adversaries. They can leverage Deep Learning (DL) models to infer the sensitive information from encrypted TCP traffic by analyzing its packet size, direction, and timing information. To defend against such DL-based traffic analysis attacks, recent advances reshape the encrypted traffic and achieve desired results. However, they typically require deploying cooperative modules on both communication endpoints and only support specific applications, such as browsers. In this paper, we propose Cactus, a client-side plug-in to obfuscate bidirectional encrypted TCP traffic for a wide range of applications transparently using the inherent TCP semantics and the emerging eBPF technique. In particular, Cactus provides four effective operations to enable bidirectional traffic obfuscation while preserving communication semantics of applications. Besides, Cactus empowers users to specify which applications to conduct traffic obfuscation and what obfuscation level for each application. We conduct comprehensive experiments to demonstrate that Cactus can effectively obfuscate encrypted TCP traffic with low overhead to hinder the traffic analysis efforts in website fingerprinting and application identification. Renjie Xie, Jiahao Cao 0001, Yuxi Zhu, Yi He 0020, Hanyi Peng, Mingwei Xu 0001, Kun Sun 0001, Enhuan Dong, Qi Li 0002, Menghao Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | RoLL+: Real-Time and Accurate Route Leak Locating With AS Triplet Features at ScaleabstractBorder Gateway Protocol (BGP) is the only inter-domain routing protocol that plays an important role on the Internet. However, BGP suffers from route leaks, which can cause serious security threats. To mitigate the effects of route leaks, accurate and timely route leak locating is of great importance. Prior studies leverage AS business relationships to locate route leaks in real time. However, they fail to achieve high locating accuracy. Recent studies apply machine learning to accurately detect route leaks from statistical features of massive BGP messages. Nevertheless, they have high detection latency and cannot further locate route leaks. In this paper, we propose a real-time and accurate route leak locating system named RoLL+. It leverages distinctive AS triplet features to accurately locate AS triplets with route leaks from each BGP message in real time. Considering that RoLL+ may receive a substantial volume of BGP update messages per second, we integrate a cache-like design and a lazy update mechanism into the system to effectively identify route leaks at scale. Our experimental results on real-world BGP route leak data demonstrate that it can achieve 92% locating accuracy with less than 1 ms locating latency. Furthermore, the results show that RoLL+ can process over 7,000 AS triplets per second, meeting real-world throughput requirements. Jiahao Cao 0001, Zili Meng, Renjie Xie, Qi Li 0002, Yuan Yang 0001, Mingwei Xu 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | RoLL: Real-Time and Accurate Route Leak Location with AS Triplet FeaturesabstractBGP is the only inter-domain routing protocol that plays an important role on the Internet. However, BGP suffers from route leak, which can cause serious security threats. To mitigate the effects of route leak, accurate and timely route leak location is of great importance. Prior studies leverage AS business relationships to locate route leak in real time. However, they fail to achieve high location accuracy. Recent studies apply machine learning to accurately detect route leak from statistical features of massive BGP messages. Nevertheless, they have high detection latency and cannot further locate route leak. In this paper, we propose a real-time and accurate route leak location system named RoLL. It leverages distinctive AS triplet features to accurately locate AS triplets with route leak from each BGP update message in real time. Our experimental results on real-world BGP route leak data demonstrate that RoLL can achieve 91% location accuracy with less than 10 ms location latency. Jiahao Cao 0001, Zili Meng, Renjie Xie, Mingwei Xu 0001 |
ICC | 2 |
| 2023 | Unsupervised and Adaptive Tor Website Fingerprinting
Jiahao Cao 0001, Mingwei Xu 0001, Xinhao Deng 0001 |
SecureComm (2) | 2 |
| 2023 | Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic Augmentation
Renjie Xie, Jiahao Cao 0001, Enhuan Dong, Kun Sun 0001, Qi Li 0002, Licheng Shen, Menghao Zhang 0001 |
USENIX Security Symposium | 2 |
| 2023 | The LOFT Attack: Overflowing SDN Flow Tables at a Low RateabstractThe emerging Software-Defined Networking (SDN) is being adopted by data centers and cloud service providers to enable flexible control. Meanwhile, the current SDN design brings new vulnerabilities. In this paper, we explore a stealthy attack that uses a minimum rate of attack packets to disrupt SDN data plane. To achieve this, we propose the LOFT attack that computes the lower bound of attack rate to overflow flow tables based on the inferred network configurations. Particularly, each attack packet always triggers or maintains consumption of one flow rule. LOFT can ensure the attack effect under various network configurations while reducing the possibility of being captured. We demonstrate its feasibility and effectiveness in a real SDN testbed consisting of commercial hardware switches. The experimental results show that LOFT incurs significant network performance degradation and potential network DoS at an attack rate of only tens of Kbps. To defeat the attack, we develop a data-to-control plane collaborative defense system named LOFTGuard, which is lightweight and transparent to SDN applications. Evaluations show that LOFTGuard effectively protects SDN against the attack and introduces a small overhead. Jiahao Cao 0001, Mingwei Xu 0001, Qi Li 0002, Kun Sun 0001, Yuan Yang 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2022 | Consistency is All I Ask: Attacks and Countermeasures on the Network Context of Distributed Honeypots
Pengbin Feng, Jiahao Cao 0001, Tommy Chin, Kun Sun 0001, Qi Li 0002 |
DIMVA | 3 |
| 2022 | Auter: Automatically Tuning Multi-layer Network Buffers in Long-Distance Shadowsocks NetworksabstractTo bypass network censorship, Shadowsocks is often deployed on long-distance transnational networks; however, such proxy networks are usually plagued by high latency, high packet loss rate, and unstable bandwidth. Most existing tuning solutions rely on hand-tuned heuristics, which cannot work well in the volatile Shadowsocks networks due to the labor intensive and time-consuming properties. In this paper, we propose Auter, which automatically tunes multi-layer buffer parameters with reinforcement learning (RL) to improve the performance of Shadowsocks in long-distance networks. The key insight behind Auter is that different network environments require different sizes of buffers to achieve sufficiently good performance. Hence, Auter continuously learns a tuning policy from volatile network states and dynamically alter sizes of multi-buffers for high network performance. We prototype Auter and evaluate its effectiveness under various real networks. Our experimental results show that Auter can effectively improve network performance, up to 40.5% throughput increase in real networks. Besides, we demonstrate that Auter outperforms all the existing tuning schemes. Jiahao Cao 0001, Shu Wang 0004, Kun Sun 0001, Lisong Xu, Qi Li 0002 |
INFOCOM | 2 |
| 2022 | Enhancing malware analysis sandboxes with emulated user behavior
Pengbin Feng, Shu Wang 0004, Kun Sun 0001, Jiahao Cao 0001 |
Comput. Secur. | 5 |
| 2022 | The devil is in the detail: Generating system call whitelist for Linux seccomp
Yunlong Xing, Jiahao Cao 0001, Kun Sun 0001, Fei Yan 0008, Shengye Wan |
Future Gener. Comput. Syst. | 2 |
| 2022 | Good Learning, Bad Performance: A Novel Attack Against RL-Based Congestion Control SystemsabstractReinforcement Learning (RL) has been applied to solve decision-making problems in computer network designs, especially in TCP congestion control. As RL-based congestion control methods enable powerful learning abilities, it achieves competitive performance and adaptiveness advantages over the traditional methods. However, RL-based systems suffer from adversarial attacks that generate perturbations to significantly degrade the performance. In this paper, we conduct a comprehensive study of adversarial attacks against RL-based congestion control systems. Unlike the state-of-the-art adversarial attacks on images where an attacker can easily obtain the input states to introduce perturbations, the attacker cannot directly obtain the input states in congestion control settings that are only available to the agents. It is challenging to add effective perturbations without knowing the input states for RL-based congestion control models. To solve the challenge, we develop an adversarial attack to estimate states of the target agent, craft adversarial perturbations, and apply the generated perturbations in an automated fashion. We evaluate how our adversarial attack affects the target agent’s decision-making process. Our experiments illustrate that our attack can effectively reduce about 50% average throughput while increasing more than 36x latency and 45% packet loss rate. Zijie Yang, Jiahao Cao 0001, Zhuotao Liu, Xiaoli Zhang 0003, Kun Sun 0001, Qi Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Disrupting the SDN Control Channel via Shared Links: Attacks and CountermeasuresabstractSoftware-Defined Networking (SDN). SDN enables network innovations with a centralized controller controlling the whole network through the control channel. Because the control channel delivers all network control traffic, its security and reliability are of great importance. For the first time in the literature, we propose the CrossPath attack that disrupts the SDN control channel by exploiting the shared links in paths of control traffic and data traffic. In this attack, crafted data traffic can implicitly disrupt the forwarding of control traffic in the shared links. As the data traffic does not enter the control channel, the attack is stealthy and cannot be easily perceived by the controller. In order to identify the target paths containing the shared links to attack, we develop a novel technique called adversarial path reconnaissance. Our experimental results show its feasibility and efficiency of identifying the target path. We systematically study the impacts of the attack on various network applications in a real SDN testbed. Experiments show the attack significantly degrades the performance of existing network applications and causes serious network anomalies, e.g., routing blackhole, flow table resetting, and even network-wide DoS. To defeat the CrossPath attack, we design a lightweight defense system named CrossGuard. Experiments demonstrate that it can effectively protect the control channel and quickly locate the attack flow with 98% accuracy while introducing a small overhead. Renjie Xie, Jiahao Cao 0001, Qi Li 0002, Kun Sun 0001, Guofei Gu, Mingwei Xu 0001, Yuan Yang 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2021 | Try before You Buy: Privacy-preserving Data Evaluation on Cloud-based Machine Learning Data MarketplaceabstractA cloud-based data marketplace provides a service to match data shoppers with appropriate data sellers, so that data shoppers can augment their internal data sets with external data to improve their machine learning (ML) models. Since data may contain diverse values, it is critical for a shopper to evaluate the most valuable data before making the final trade. However, evaluating ML data typically requires the cloud to access a shopper’s ML model and sellers’ data, which are both sensitive. None of the existing cloud-based data marketplaces enable ML data evaluation while preserving both model privacy and data privacy. In this paper, we develop a privacy-preserving ML data evaluation framework on a cloud-based data marketplace to protect shoppers’ ML models and sellers’ data. First, we provide a privacy-preserving framework that allows shoppers and sellers to encrypt their models and data, respectively, while preserving data functionality and model functionality in the cloud. We then develop a privacy-preserving data selection protocol that enables the cloud to help shoppers select the most valuable ML data. Also, we develop a privacy-preserving data validation protocol that allows shoppers to further check the quality of the selected data. Compared to random data selection, the experimental results show that our solution can reduce 60% prediction errors. Qiyang Song, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002, Ke Xu 0002 |
ACSAC | 2 |
| 2021 | Hopping on Spectrum: Measuring and Boosting a Large-scale Dual-band Wireless NetworkabstractIn recent years, more and more wireless networks support both 2.4GHz and 5GHz bands. However, in large-scale dual-band wireless networks, lack of understanding on the behavior and performance makes the network diagnosis and optimization extremely challenging. In this paper, we conduct a comprehensive measurement to characterize the behavior and performance in a large-scale dual-band wireless network (TD WLAN). We make several meaningful observations. (1) Although the 5GHz band outperforms the 2.4GHz band, 60% of devices tend to be associated with the 2.4GHz band. The device association behavior has a large impact on the performance. (2) Rogue and non-WiFi devices are prevalent, wherein hidden terminal interference increases the average loss rate by 8%, carrier sense interference increases the average WiFi latency by 45%, and RF interference further aggravates both packet loss and channel contention. (3) The dynamic channel assignment strategy is not always effective. On this basis, we propose a novel and easy-to-implement strategy to improve the wireless performance by intelligent band navigation and heuristic channel optimization. The actual deployment in TD WLAN shows the packet loss reduces by 40% on average and the WiFi latency for more than 60% of devices is below 5ms. Haibo Wang 0004, Weizhen Dang, Jing'an Xue, Jiahao Cao 0001, Jilong Wang 0001 |
ICNP | 5 |
| 2021 | SAP-SSE: Protecting Search Patterns and Access Patterns in Searchable Symmetric EncryptionabstractSearchable symmetric encryption (SSE) enables users to search over encrypted documents in untrusted clouds without leaking the search keywords to the clouds. Existing SSE schemes achieve high search efficiency at the expense of leaking access patterns and search patterns, where clouds can recover a large percentage of queried keywords using the leaked access patterns and search patterns. To prevent clouds from recovering users' keywords, researchers have proposed a number of solutions to protect either search patterns or access patterns. However, none of them can protect both access patterns and search patterns. Moreover, existing SSE schemes cannot work in the generic database setting that allows multiple users to write or read over encrypted documents. In this paper, we propose an efficient searchable symmetric encryption scheme, called SAP-SSE, which protects both access patterns and search patterns in the generic database setting. The main idea of protecting search patterns is to leverage re-encryption cryptosystems to shuffle index entries over multiple clouds. To protect access patterns, we distribute secure indexes to multiple clouds and then propose an index redistribution protocol that allows users to renew index entries in clouds. Furthermore, SAP-SSE provides a configurable security policy to balance security and efficiency. Formal security analysis and experimental evaluation show that SAP-SSE can prevent pattern leakage with low overhead. Qiyang Song, Zhuotao Liu, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002, Cong Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | When the Differences in Frequency Domain are Compensated: Understanding and Defeating Modulated Replay Attacks on Automatic Speech RecognitionabstractAutomatic speech recognition (ASR) systems have been widely deployed in modern smart devices to provide convenient and diverse voice-controlled services. Since ASR systems are vulnerable to audio replay attacks that can spoof and mislead ASR systems, a number of defense systems have been proposed to identify replayed audio signals based on the speakers' unique acoustic features in the frequency domain. In this paper, we uncover a new type of replay attack called modulated replay attack, which can bypass the existing frequency domain based defense systems. The basic idea is to compensate for the frequency distortion of a given electronic speaker using an inverse filter that is customized to the speaker's transform characteristics. Our experiments on real smart devices confirm the modulated replay attacks can successfully escape the existing detection mechanisms that rely on identifying suspicious features in the frequency domain. To defeat modulated replay attacks, we design and implement a countermeasure named DualGuard. We discover and formally prove that no matter how the replay audio signals could be modulated, the replay attacks will either leave ringing artifacts in the time domain or cause spectrum distortion in the frequency domain. Therefore, by jointly checking suspicious features in both frequency and time domains, DualGuard~can successfully detect various replay attacks including the modulated replay attacks. We implement a prototype of DualGuard~on a popular voice interactive platform, ReSpeaker Core v2. The experimental results show DualGuard~can achieve 98% accuracy on detecting modulated replay attacks. Shu Wang 0004, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002 |
CCS | 2 |
| 2020 | SEC: Secure, Efficient, and Compatible Source Address Validation with Packet TagsabstractSpoofed traffic has been a great threat to the Internet. Tag-based inter-AS source address validation solutions show great effectiveness and high deployment incentives on filtering spoofed traffic. However, they fail to consider secure key negotiation for tags, efficient tag generation for network devices, and compatible tag placement for network functionalities. In this paper, we present SEC, a secure, efficient, and compatible source address validation scheme based on packet tags. We provide a secure key negotiation method and a lightweight tag generation algorithm for SEC considering hardware limitations of network devices. They can be easily implemented in network devices to filter spoofed packets while forwarding packets at approximately line rate. We also carefully place all tags into appropriate option fields in packet headers to guarantee the compatibility of network functionalities. We implement SEC in real programmable switches. Both theoretical analysis and experimental results show SEC can verify source addresses of packets in a secure, efficient, and compatible way. Jiahao Cao 0001, Mingwei Xu 0001 |
IPCCC | 2 |
| 2020 | When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDN
Jiahao Cao 0001, Renjie Xie, Kun Sun 0001, Qi Li 0002, Guofei Gu, Mingwei Xu 0001 |
NDSS | 1 |
| 2020 | SIEVE: Secure In-Vehicle Automatic Speech Recognition Systems
Shu Wang 0004, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002 |
RAID | 2 |
| 2019 | cSFC: Building Credible Service Function Chain on the CloudabstractTo reduce the management costs, outsourcing network function (NF) to the cloud becomes prevalent in enterprises. This trend is increasing with the advent of network function virtualization (NFV). However, such outsourcing cannot guarantee the order and security of service function chains(SFCs) as the cloud is susceptible to attacks. In this paper, we introduce credible SFC (cSFC), a practical scheme to build secure service function chains on the untrusted cloud, cooperating with encrypted transport protocols. cSFC simultaneously shields NFs from an untrusted cloud and preserves the order of SFC sequence. Meanwhile, this scheme supports a wide range of NF functionalities and preserves the privacy of session data. We implement the cSFC prototype, and the evaluation result shows that it is practical with acceptable performance. Shengsheng Yao, Qi Li 0002, Jiahao Cao 0001, Qiyang Song |
GLOBECOM | 4 |
| 2019 | SoftGuard: Defend Against the Low-Rate TCP Attack in SDNabstractThe low-rate TCP attack is essentially a great threat to the Internet. It causes significant throughput degradation of TCP flows by generating periodical pulsing flows. Due to its low rate, the attack is difficult to be detected and throttled. Recently, Software-Defined Networking (SDN) has emerged as a promising network paradigm. Several SDN-based defense systems have been proposed to deal with various Denial of Service (DoS) attacks. However, they fail to consider the low-rate TCP attack. In this paper, we propose SoftGuard, which is an SDN-based defense that effectively detects and mitigates the low-rate TCP attack. SoftGuard detects the attack by installing crafted flow rules to monitor the degradation of aggregated TCP throughput in ports of switches. It confirms the attack by judging whether there is periodicity for aggregated TCP throughput with adaptive Fast Fourier Transform, and accurately identifies attack flows with Mean Euclidean Distance. Identified attack flows will be effectively throttled by installing mitigation rules in ingress switches. We implement SoftGuard in the Floodlight controller. Experiments in a real SDN testbed demonstrate its effectiveness on defending against the low-rate TCP attack. Renjie Xie, Jiahao Cao 0001, Qi Li 0002 |
ICC | 3 |
| 2019 | Fingerprinting SDN Applications via Encrypted Control Traffic
Jiahao Cao 0001, Zijie Yang, Kun Sun 0001, Qi Li 0002, Peiyi Han |
RAID | 1 |
| 2019 | Covert Channels in SDN: Leaking Out Information from Controllers to End Hosts
Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002, Zijie Yang, Kyung Joon Kwak, Jason H. Li |
SecureComm (1) | 1 |
| 2019 | The CrossPath Attack: Disrupting the SDN Control Channel via Shared Links
Jiahao Cao 0001, Qi Li 0002, Renjie Xie, Kun Sun 0001, Guofei Gu, Mingwei Xu 0001, Yuan Yang 0001 |
USENIX Security Symposium | 1 |
| 2018 | Realtime DDoS Defense Using COTS SDN Switches via Adaptive Correlation AnalysisabstractDistributed denial-of-service (DDoS) defense is still a difficult problem though it has been extensively studied. The existing approaches are not capable of detecting various types of DDoS attacks. In particular, new emerging sophisticated DDoS attacks (e.g., Crossfire) constructed by low-rate and short-lived benign traffic are even more challenging to capture. Moreover, it is difficult to enforce realtime defense to throttle these detected attacks since the attack traffic can be concealed in benign traffic. Software defined networking (SDN) opens a new door to address these issues. In this paper, we propose Reinforcing Anti-DDoS Actions in Realtime (RADAR) to detect and throttle DDoS attacks via adaptive correlation analysis built upon unmodified commercial off-the-shelf SDN switches. It is a practical system to defend against a wide range of flooding-based DDoS attacks, e.g., link flooding (including Crossfire), SYN flooding, and UDP-based amplification attacks, while requiring neither modifications in SDN switches/protocols nor extra appliances. It accurately detects attacks by identifying attack features in suspicious flows, and locates attackers (or victims) to throttle the attack traffic by adaptive correlation analysis. We implement RADAR prototype using open source Floodlight controller, and evaluate its performance under various DDoS attacks by real hardware testbed based experiments. We observe that our scheme can successfully detect and effectively defend against various DDoS attacks with acceptable overhead. Qi Li 0002, Guofei Gu, Jiahao Cao 0001, David K. Y. Yau |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | TSA: A Two-Phase Scheme Against Amplification DDoS Attack in SDN
Jiahao Cao 0001, Qi Li 0002 |
MSN | 3 |
| 2017 | Disrupting SDN via the Data Plane: A Low-Rate Flow Table Overflow Attack
Jiahao Cao 0001, Mingwei Xu 0001, Qi Li 0002, Kun Sun 0001, Yuan Yang 0001 |
SecureComm | 1 |