Huancheng Zhou

dblp:243/6488 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Computer networks · 2Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 On the Security Risks of Memory Adaptation and Augmentation in Data-plane DoS Mitigation
Hocheol Nam 0001, Daehyun Lim, Huancheng Zhou, Guofei Gu, Min Suk Kang
NDSS3
2024 WIRE: Web3 Integrated Reputation Engine
abstract
Distributed Applications (DApps), powered by smart contracts, have sparked a significant transformation in the Web3 ecosystem by enabling the execution of real-world contracts on decentralized networks. However, the growing popularity of DApps has also led to an increase in malicious activities exploiting smart contracts, thereby exposing users to greater financial risks. Inspired by the FICO score system in traditional finance, we introduce WIRE, a reputation engine designed to evaluate the trustworthiness of deployed DApps. WIRE first derives diverse properties from contract activities, rather than relying solely on potentially irrelevant or unavailable source code. Based on selected properties, WIRE trains a machine learning model for assessing the trustworthiness of individual contracts. Further-more, WIRE utilizes a bytecode disassembler to identify related contracts of a DApp, thus determining its overall trustworthiness score. Moreover, WIRE's dashboard offers explainable and detailed reports that are accessible to users without professional knowledge. The evaluation results show that WIRE can provide a reliable and explainable reputation score for DApps. As a result, WIRE's users can distinguish between benign and malicious DApps or contracts with a high confidence.
Suraj Shamsundar Jain, Huancheng Zhou, Guofei Gu
ICDCS2
2024 Cerberus: Enabling Efficient and Effective In-Network Monitoring on Programmable Switches
abstract
With the increasing volume of network traffic and the emergence of new types of attacks, traditional network monitoring is facing significant challenges in ensuring network security and performance. In-network monitoring (INM) systems based on programmable switches, e.g., P4-based INM systems, have emerged as a more promising approach for high-performance and real-time network monitoring. However, existing P4-based INM systems have resource limitations in handling diverse and high-volume INM tasks such as multi-vector DDoS defenses. Worse still, attackers may try to dynamically change attack vectors to disrupt inadaptable systems and even lead to denial-of-service (DoS) attacks against INM.To address these challenges, we present Cerberus, an efficient and effective in-network security monitoring system. To support various INM tasks, we abstract them into key-feature (K-F) pairs and design a novel memory slicing mechanism to share memory among multiple K-F pairs. To handle high-volume traffic, we propose a new co-monitoring mechanism that complements the data and control planes, thereby greatly enhancing the efficiency of Cerberus. To adapt to changing network conditions, we design a new resource manager that dynamically reallocates resources for INM tasks and adjusts loads for the data and control planes without interrupting running services. We design a series of INM modules, including DDoS defenses, and develop a prototype of Cerberus. We conduct extensive evaluations to demonstrate that Cerberus can enhance the concurrency and capacity of programmable switches by an order of magnitude. Moreover, Cerberus is more adaptable in handling various INM tasks.
Huancheng Zhou, Guofei Gu
SP1
2024 You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology Obfuscation
Xuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai, Huancheng Zhou, Bo Luo, Guofei Gu, Qibin Sun
USENIX Security Symposium5
2023 Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable Switches
abstract
Link-flooding attacks (LFAs) can cut off the Internet connection to selected server targets and are hard to mitigate because adversaries use normal-looking and low-rate flows and can dynamically adjust the attack strategy. Traditional centralized defense systems cannot locally and efficiently suppress malicious traffic. Though emerging programmable switches offer an opportunity to bring defense systems closer to targeted links, their limited resource and lack of support for runtime reconfiguration limit their usage for link-flooding defenses.We present Mew1, a resource-efficient and runtime adaptable link-flooding defense system. Mew can counter various LFAs even when a massive number of flows are concentrated on a link, or when the attack strategy changes quickly. We design a distributed storage mechanism and a lossless state migration mechanism to reduce the storage bottleneck of programmable networks. We develop cooperative defense APIs to support multi-grained co-detection and co-mitigation without excessive overhead. Mew's dynamic defense mechanism can constantly analyze network conditions and activate corresponding defenses without rebooting devices or interrupting other running functions. We develop a prototype of Mew by using real-world programmable switches, which are located in five cities. Our experiments show that the real-world prototype can defend against large-scale and dynamic LFAs effectively.
Huancheng Zhou, Sungmin Hong, Xiapu Luo, Weichao Li 0001, Guofei Gu
SP1
2020 A Lightweight and Secure Group Key Based Handover Authentication Protocol for the Software-Defined Space Information Network
abstract
With rapid advances in satellite technology, space information network (SIN) has been proposed to meet the increasing demands of ubiquitous mobile communication due to its advantages in providing extensive access services. However, due to satellites' resource constraint and SIN's highly dynamic topology, it poses a challenge on management and resource utilization in the development of SIN. There have been some works integrating the software defined network (SDN) into SIN, defined as software defined space information network (SD-SIN), so as to simplify the management and improve resource utilization in SIN. However, these works ignore the security issue in SD-SIN. Meanwhile, the existing security mechanisms in SDN are still unable to cope with the uniqueness of satellite network, and some other critical security issues still haven't yet been well addressed. In this paper, based on (t,n) secret sharing, an SIN-specific lightweight group key agreement protocol is proposed for SD-SIN to ensure both the security and applicability. Moreover, considering the highly dynamic network topology, we also design a group key-based secure handover authentication scheme to reduce the overhead of handover authentication. Security analysis shows that the handover authentication protocol can resist to various known attacks. In addition, further performance evaluation shows its efficiency in terms of computation and communication overheads. Finally, the simulation results of computing overhead to the network entities demonstrate that our protocol is feasible in practical implementation.
Kaiping Xue, Huancheng Zhou, David S. L. Wei, Mohsen Guizani
IEEE Trans. Wirel. Commun.3
2019 A Secure and Efficient Access and Handover Authentication Protocol for Internet of Things in Space Information Networks
abstract
Space information network (SIN) makes it possible for any object to be connected to the Internet anywhere, even in the areas with extreme conditions, where a cellular network is not easy to deploy. Access authentication is the key to secure users' access control in SIN, mainly to prevent illegal adversaries from getting access to SIN services. However, the highly complicated communication environment of SIN (e.g., exposed links, higher signal delay, etc.) poses a challenging issue in the design of a secure and efficient authentication scheme. Although some authentication schemes have been proposed for SIN, they are unsuitable for Internet of Things (IoT) in SIN due to the high signaling overhead and insufficient security properties. Therefore, in this paper, we design a provably secure and efficient authentication protocol, along with an efficient handover mechanism, for IoT in SIN. In our design, we introduce a new authentication system model, where the satellites are given the ability to authenticate users to avoid the online involvement of the network control center (NCC) when authenticating users, thereby reducing long authentication delay and avoiding a single point of bottleneck in NCC. Furthermore, the support of batch verification in our design can significantly enhance handover efficiency when a group of users switch to another satellite. Our further analysis shows that our scheme is secure against various attacks and can meet a variety of security requirements. In addition, performance evaluation shows the superiority of our scheme on both delay and handover efficiency compared with existing schemes.
Kaiping Xue, Shaohua Li 0002, David S. L. Wei, Huancheng Zhou, Nenghai Yu
IEEE Internet Things J.5