Guangxi Yu

dblp:236/3253 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
5since 2021 · last 2024
0009-0009-3633-5607ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 5GC-SDP: Security Enhancement of 5G Core Networks With Zero Trust
abstract
The 5G core network (5GC) architecture based on Service-Based Architecture (SBA) has brought unprecedented flexibility and innovation. However, this architecture also comes with potential security challenges. The integration of different signaling protocols and the complexity of virtualization in 5GC have increased security risks within the core network. The concept of zero trust is considered a new solution, and Software-Defined Perimeter (SDP) represents a best practice for zero trust. In this paper, we propose a 5GC-SDP architecture that provides secure communication within the core network through authentication-based methods. Single Package Authorization (SPA) is the key technology of this study. Only Network Functions (NF) that have been authenticated and authorized by SPA can access each other. To the best of our knowledge, this is the first study to combine SDP with StandAlone (SA) 5GC. At the same time, we fully consider that although SPA technology can withstand most DoS attacks, DoS attacks caused by SPA packets will still become a problem. Therefore, we design a SPA enhancement module, and machine learning algorithms are used for SPA-DoS detection. We have conducted practical exploration on the proposed 5GC-SDP architecture and implemented testing on port scanning, DoS, and DDoS attacks. The experiments have shown that 5GC-SDP achieves enhanced protection of the core network by limiting network exposure and implementing fine-grained access control.
Zeqing Yan, Guangxi Yu, Mengqi Zhan, Yan Zhang 0014, Jiaxi Hu
CSCWD2
2023 GuardBox: A High-Performance Middlebox Providing Confidentiality and Integrity for Packets
abstract
The deepening of digital transformation has led to an increasing amount of data from industries being transmitted over the Internet. However, packets in plaintext originally designed for transmission in private networks suffer from significant security threats on the Internet. Unfortunately, existing encryption schemes, such as the representative TLS, are difficult to be applied to these industrial protocols due to their specific requirements and conditions such as low latency requirements and restricted operating environments. In this paper, we present a high-performance encryption/decryption middlebox called GuardBox to provide confidentiality and integrity for packets. GuardBox is expected to transparently encrypt/decrypt packets sent/received by protected industrial equipment with low latency and supports almost any application-layer protocol. To do that, we design a high-performance packet I/O framework and an optimized encryption/decryption scheme for GuardBox. More importantly, we use commodity trusted hardware, Intel SGX, to ensure the security of keys and the encryption/decryption process. Our extensive evaluation demonstrates that GuardBox can provide confidentiality and integrity for packets transmitted over the Internet with low latency and a near-native throughput.
Mengqi Zhan, Yang Li 0192, Guangxi Yu, Yan Zhang 0014, Bo Li 0063, Weiping Wang 0005
IEEE Trans. Inf. Forensics Secur.3
2023 Website-Aware Protocol Confusion Network for Emergent HTTP/3 Website Fingerprinting
abstract
Website fingerprinting is exploited to analyze encrypted traffic traces and infer the visited website. Existing website fingerprinting methods can achieve satisfying performance for the HTTP traffic visiting websites over TCP. Recently, a new protocol QUIC has been proposed, and HTTP-over-QUIC has been formalized as the next generation HTTP, named HTTP/3. Thus, it is necessary to classify HTTP/3 traces. However, since HTTP/3 is newly proposed and is being deployed, it is difficult to collect a large number of HTTP/3 traces. Intuitively, we can use sufficient TCP traces to improve the performance of the QUIC trace classifier. Unfortunately, the protocol discrepancy exists between TCP and QUIC traces, which undermines the generalization ability of the classifier. In this paper, for practical website fingerprinting of HTTP/3, we propose a Website-Aware Protocol Confusion Network (WAPCN), which exploits only a few QUIC traces to train a website classifier with the help of lots of available TCP traces. It consists of four main parts: a feature extractor, a website classifier, a protocol discriminator, and a website-aware adaptor. The feature extractor aims to extract trace representations from both TCP and QUIC traces. It cooperates with the website classifier to learn the discriminative representation for the website classification. The role of the protocol discriminator is to confuse protocols and guide the feature extractor to learn protocol-invariant representations. The website-aware adaptor can enhance protocol-invariant representations to be aware of the website classification boundary. Extensive experiments are conducted on various tasks to demonstrate the effectiveness of WAPCN.
Mengqi Zhan, Yang Li 0192, Yongchun Zhu, Guangxi Yu, Yan Zhang 0014, Bo Li 0063, Weiping Wang 0005
IEEE Trans. Inf. Forensics Secur.4
2023 Coda: Runtime Detection of Application-Layer CPU-Exhaustion DoS Attacks in Containers
abstract
Denial of service (DoS) attacks have increasingly exploited vulnerabilities in algorithms or implementation methods in application-layer programs. In this type of attack, called CPU-exhaustion DoS attack, a few well-crafted requests may consume a lot of server resources, which is essentially different from traditional volumetric DoS attacks. Due to the lack of recognizable patterns, the traditional network-layer defense mechanism is usually unable to detect such sophisticated DoS attacks. In this paper, we proposeCoda, a framework for detecting application-layer CPU-exhaustion DoS attacks in containers.Codamonitors the CPU time consumed by each connection and uses statistical methods to detect attacks. It traces system calls and other related information from the container based on Linux eBPF at the host level. Some specific system calls are used to indicate the establishment and closure of the connection, which in turn indicate the start/end of the request processing. After triggering these specific system calls,Codastarts/ends monitoring the CPU time consumed by a connection. An attack can be detected when the CPU time consumed by an attack connection is statistically different from that consumed by a legitimate connection.Codahas the following key advantages. First, it works with programs built in different programming languages. Second, it remains agnostic to the source code of protected programs. Third, it supports monitoring the container and is transparent to the container. Through evaluation of real-world attacks, we demonstrate thatCodacan accurately detect ongoing application-layer CPU-exhaustion DoS attacks with low additional overhead.
Mengqi Zhan, Yang Li 0192, Huiran Yang, Guangxi Yu, Bo Li 0063, Weiping Wang 0005
IEEE Trans. Serv. Comput.4
2022 Detecting DNS over HTTPS based data exfiltration
Mengqi Zhan, Yang Li 0192, Guangxi Yu, Bo Li 0063, Weiping Wang 0005
Comput. Networks3
2019 Towards Homograph-Confusable Domain Name Detection Using Dual-Channel CNN
Guangxi Yu, Xinghua Yang, Yan Zhang 0014, Huajun Cui, Huiran Yang, Yang Li 0192
ICICS1
2019 Mitigating Negative Impacts on DNS Caches Caused by Disposable Domain Names
abstract
DNS caches play an important role in DNS querying. However, the performance of DNS caches will be remarkably influenced by disposable domain names, which are generated by services of cloud storage, social networks, etc., and belong to a new class of misused case of DNS. In this paper, we proposed a novel solution named DC3(Domain Classification and Cascade Cache) to mitigate the negative impact. Domain Classification adopts a classifier which is based on a long short-term memory (LSTM) network to prevent disposable domains from being cached. Cascade Cache is a refined cascade LRU policy considering cache size allocation to process the remaining disposable domains. By querying the real DNS traces collected from a large ISP network, experiment results show that this solution can detect disposable domain names and mitigate their negative impacts on DNS caches effectively. Specifically, in our dataset, 67.4% of all distinct domain names are detected as disposable domain names. Correspondingly, when getting rid of them by using this solution, we can raise the cache hit rate more than double.
Guangxi Yu, Yan Zhang 0014, Huajun Cui, Xinghua Yang, Yang Li 0192
ISCC1
2018 Virtualized Security Function Placement for Security Service Chaining in Cloud
abstract
Security Service Chaining (SSC) has recently shown great potential to address cloud security problems. A key point to implement SSC is Virtualized Security Functions (VSF) placement, which is a special kind of VNF placement. However, the existing solutions of VNF placement have not considered traffic reachability problem and policy conflict problem, which should be addressed for SSC. In this paper, we study the issue of VSF placement for SSC in cloud, and propose a solution named MCE (Map, Check reachability, and Eliminate conflict). In the framework of MCE, we first formulate an optimization model for VSF and VL mapping, which is NP-hard and can be solved by existing mapping algorithms. Next, we propose to use HSA method to find and delete some improper mapping results where traffic reachability can't be satisfied. Finally, we propose a scheme named BSIS-RC (Bit Sequence Intersection and Subtraction based Rule Computation), which is based on our work on the formula expression of security policies, the definition of policy spaces, bit sequence subtraction rule and the definition of policy relationships. BSIS-RC can check and eliminate policy conflicts quickly and effectively. We combine MCE with three existing mapping algorithms and compare the performance of six solutions through simulations. Results show that, compared with three solutions not considering the problems of traffic reachability and policy conflict, MCE can improve 38% of the SSC request success rate on average and reduce 15% of the total bandwidth consumption per SSC request on average. Moreover, among the three MCE solutions with three different mapping algorithms, MCE with Genetic algorithm has the best performance.
Hongjing Wu, Yan Zhang 0014, Huiran Yang, Guangxi Yu, Jiuyue Cao
ICPADS4