EDBT 2026 Demo / reviewers in the wild / expert
Mingming Chen 0001
dblp:26/9777-1
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0001-9595-770XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Lightweight Coordinated Sampling for Dynamic Flows: Theory and ImplementationabstractAs cyber-attacks on networks become stealthier, monitoring techniques relying on low-rate packet sampling may prove insufficient to detect attacks. While various methods, such as truncating packets, flow-based sampling, and adaptive sampling rates, have been proposed to enhance detection rates and ease capability limitations, it remains challenging to perform sufficient sampling at line speed and high rates at a single sampling point due to limited CPU or bandwidth capacity and fluctuating network traffic. To address these challenges, we propose CoordSamp, a system that distributes the sampling workload across multiple sampling points and coordinates their actions to avoid duplicate sampling of the same packet. This design enables scalable, resource-aware monitoring—particularly suited for dynamic, agentless cloud-based environments—relying solely on network-level deployment that can be dynamically assigned and adjusted by the provider. We develop a coordinated sampling algorithm on multiple P4-programmable switches and show that the algorithm ensures coordination among multiple sampling points for each flow, preventing duplicate samples, with negligible network overhead and real-time configurability. At its core, CoordSamp separatesoffline placement—the budgeted selection of sampling points—fromonline allocation—the capacity-aware assignment of sampling tasks—allowing practical deployment in hybrid networks that combine programmable and legacy switches. We formulate sampling point placement as budgeted maximum multi-coverage problems, solving them optimally in pseudo-polynomial time. Our system far outperforms those based on greedy placement along many key dimensions. Mingming Chen 0001, Thomas La Porta, Trent Jaeger, Srikanth V. Krishnamurthy |
IEEE Trans. Netw. | 1 |
| 2024 | Evolving Network Security in the Era of Network ProgrammabilityabstractSoftware-defined networking (SDN) is a centralized network architecture enabling dynamic, programmable, and flexible network management, which advances technologies like network security.However, it also introduces new vulnerabilities due to the segregation of data, control, and application planes, creating additional attack surfaces and security gaps from the increased complexity of programmability, flexibility, and scalability.To empower network security with SDN, we develop a coordinated sampling strategy using P4 programming for adaptive network monitoring.Additionally, we uncover a flow entry-induced topology poisoning attack to highlight security gaps from unplanned module integration.Finally, we propose to fortify the SDN control plane by generalizing SDN security policies and fuzzing it to uncover unknown vulnerabilities. Mingming Chen 0001 |
CCS | 1 |
| 2024 | Manipulating OpenFlow Link Discovery Packet Forwarding for Topology PoisoningabstractSoftware-defined networking (SDN) is a centralized, dynamic, and programmable network management technology that enables flexible traffic control and scalability. SDN facilitates network administration through a centralized view of the underlying physical topology; tampering with this topology view can result in catastrophic damage to network management and security. To underscore this issue, we introduce Marionette, a new topology poisoning technique that manipulates OpenFlow link discovery packet forwarding to alter topology information. Our approach exposes an overlooked yet widespread attack vector, distinguishing itself from traditional link fabrication attacks that tamper, spoof, or relay discovery packets at the data plane. Unlike localized attacks observed in existing methods, our technique introduces a globalized topology poisoning attack that leverages control privileges. Marionette implements a reinforcement learning algorithm to compute a poisoned topology target, and injects flow entries to achieve a long-lived stealthy attack. Our evaluation shows that Marionette successfully attacks five open-source controllers and nine OpenFlow-based discovery protocols. Marionette overcomes the state-of-the-art topology poisoning defenses, showcasing a new class of topology poisoning that initiates on the control plane. This security vulnerability was ethically disclosed to OpenDaylight, and CVE-2024-37018 has been assigned. Mingming Chen 0001, Thomas La Porta, Teryl Taylor, Frederico Araujo, Trent Jaeger |
CCS | 1 |
| 2024 | Lightweight Coordinated Sampling for Dynamic Flows under Budget ConstraintsabstractAs cyber-attacks on networks become more stealthy, monitoring techniques relying on low-rate packet sampling may prove insufficient to detect attacks. While various sampling methods have been proposed to address capacity limitations and enhance detection rates, achieving sampling at line speed at a single point remains challenging due to limited CPU or bandwidth capacity at sampling points. In this paper, we propose harnessing coordinating sampling across switches to create a unified system that can dynamically activate sampling points to meet sampling rate needs. We introduce and implement a coordinated sampling algorithm on multiple P4-programmable switches and show that the algorithm ensures coordination among multiple sampling points for each flow, preventing duplicate samples, with negligible network overhead and real-time configurability. We formulate sampling point placement as budgeted maximum multi-coverage problems, solving them optimally in pseudo-polynomial time. We show our system far outperforms those based on greedy algorithms along many key dimensions. Mingming Chen 0001, Thomas La Porta, Trent Jaeger, Srikanth V. Krishnamurthy |
ICCCN | 1 |
| 2024 | OPTISAN: Using Multiple Spatial Error Defenses to Optimize Stack Memory Protection within a Budget
Rahul George, Mingming Chen 0001, Kaiming Huang, Zhiyun Qian, Thomas La Porta, Trent Jaeger |
USENIX Security Symposium | 2 |