EDBT 2026 Demo / reviewers in the wild / expert
Vrizlynn L. L. Thing
dblp:37/5092
· DBLP profile ↗
69ranked-venue papers
15as first author
18since 2021 · last 2026
0000-0003-4424-8596ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 7 first-author · 15 since 2021Graphics, computer vision, multimedia, augmented reality and games · 11 · 1 first-author · 2 since 2021Computer networks · 10 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 7 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CoSPED: Consistent Soft Prompt Targeted Data Extraction and DefenseabstractLarge language models have gained widespread attention recently, but their potential security vulnerabilities, especially privacy leakage, are also becoming apparent. To test and evaluate for data extraction risks in LLMs, we propose CoSPED, short for Consistent Soft Prompt Targeted Data Extraction and Defense. We introduce several innovative components, including Dynamic Loss, Additive Loss, Common Loss, and Self Consistency Decoding Strategy, and tested to enhance the consistency of the soft prompt tuning process. Through extensive experimentation with various combinations, we achieved an extraction rate of 65.2% at a 50-token prefix comparison. Our comparisons of CoSPED with other reference works confirm our superior extraction rates. We evaluate CoSPED on more scenarios, achieving Pythia model extraction rate of 51.7% and introducing cross-model comparison. Finally, we explore defense through Rank-One Model Editing and achieve a reduction in the extraction rate to 1.6%, which proves that our analysis of extraction mechanisms can directly inform effective mitigation strategies against soft prompt-based attacks. Zhuochen Yang, Kar-Wai Fok, Vrizlynn L. L. Thing |
AAAI | 3 |
| 2026 | Enhanced Consistency Bi-directional GAN (CBiGAN) for malware anomaly detectionabstractAbstract Static malware analysis remains a core technique in cybersecurity due to its ability to assess potentially malicious software without execution. Nevertheless, many existing static approaches rely on handcrafted features or curated datasets that may not generalize well to evolving malware distributions. In this work, we investigate an alternative representation that operates directly on raw binary content. Executable files are transformed into visual encodings that preserve local structural relationships, enabling the use of deep learning models without requiring semantic disassembly or dynamic behavior profiling. This study explores the use of a Consistency Bi-directional Generative Adversarial Network (CBiGAN) as an anomaly detection framework rather than as a generative model. The method enforces consistency between latent encodings and reconstructions, allowing deviations from learned benign structure to be quantified through reconstruction discrepancies. Importantly, the approach does not introduce a new generative architecture, instead, it evaluates how consistency based generative modeling can be applied at scale to heterogeneous malware data. The proposed framework is evaluated across multiple datasets comprising both Portable Executable (PE) and Object Linking and Embedding (OLE) files, including a large self-collected corpus spanning 214 malware families. Results demonstrate stable detection performance in terms of Area Under the Curve (AUC) while maintaining a unified and computationally lightweight processing pipeline. These findings suggest that consistency based generative modeling provides a practical and scalable direction for malware anomaly detection across diverse file formats and threat families. Thesath Wijayasiri, Kar-Wai Fok, Vrizlynn L. L. Thing |
Cybersecur. | 3 |
| 2026 | Threshold-free network anomaly detection via comparative reconstruction error learning with parallel GANs
Xinxing Zhao, Kar-Wai Fok, Vrizlynn L. L. Thing |
J. Inf. Secur. Appl. | 3 |
| 2024 | CPE-Identifier: Automated CPE Identification and CVE Summaries Annotation with Deep Learning and NLP
Wanyu Hu, Vrizlynn L. L. Thing |
ICISSP | 2 |
| 2024 | An adversarial attack approach for eXplainable AI evaluation on deepfake detection models
Balachandar Gowrisankar, Vrizlynn L. L. Thing |
Comput. Secur. | 2 |
| 2024 | Enhancing network intrusion detection performance using generative adversarial networks
Xinxing Zhao, Kar-Wai Fok, Vrizlynn L. L. Thing |
Comput. Secur. | 3 |
| 2023 | FaceLivePlus: A Unified System for Face Liveness Detection and Face VerificationabstractFace verification is a trending way to verify someone’s identity in broad applications. But such systems are vulnerable to face spoofing attacks via, for example, a fraudulent copy of a photo, making it necessary to include face liveness detection as an additional safeguard. Among most existing studies, the face liveness detection is realized in a separate machine learning model in addition to the model for face verification. Such a two-model configuration may face challenges when deployed onto platforms with limited computation power and storage (e.g. mobile phone, IoT devices), especially considering each model may have millions of parameters. Inspired by the fact that humans can verify a person’s identity and liveness at a single glance from a face, we develop a novel system, named FaceLivePlus, to learn a single and universal face descriptor for the two tasks (face verification and liveness detection) so that the computational workload and storage space can be halved. To achieve this, we formulate the underlying relationship between the two tasks, and seamlessly embed this relationship in a distance ranking deep model. The model directly works on features rather than classification labels, which makes the system well generalized on unseen data. Extensive experiments show that our average half total error rate (HTER) has at least 15% and 8% improvement from the state-of-the-arts on two benchmark datasets. We anticipate this approach could become a new direction for face authentication. Ying Zhang 0047, Lilei Zheng, Vrizlynn L. L. Thing, Roger Zimmermann, Bin Guo 0001, Zhiwen Yu 0001 |
ICMR | 3 |
| 2023 | RAPTOR: Advanced Persistent Threat Detection in Industrial IoT via Attack Stage CorrelationabstractPast Advanced Persistent Threat (APT) attacks on Industrial Internet-of-Things (IIoT), such as the 2016 Ukrainian power grid attack and the 2017 Saudi petrochemical plant attack, have shown the disruptive effects of APT campaigns while new IIoT malware continue to be developed by APT groups. Existing APT detection systems have been designed using cyberattack TTPs modelled for enterprise IT networks and leverage specific data sources (e.g., Linux audit logs, Windows event logs) which are not found on ICS devices. In this work, we propose RAPTOR, a system to detect APT campaigns in IIoT. Using cyberattack TTPs modelled for ICS/OT environments and focusing on ‘invariant’ attack phases, RAPTOR detects and correlates various APT attack stages in IIoT leveraging data which can be readily collected from ICS devices/networks (packet traffic traces, IDS alerts). Subsequently, it constructs a high-level APT campaign graph which can be used by cybersecurity analysts towards attack analysis and mitigation. A performance evaluation of RAPTOR’s APT attack-stage detection modules shows high precision and low false positive/negative rates. We also show that RAPTOR is able to construct the APT campaign graph for APT attacks (modelled after real-world attacks on ICS/OT infrastructure) executed on our IIoT testbed. Ayush Kumar 0001, Vrizlynn L. L. Thing |
PST | 2 |
| 2023 | A Public Key Infrastructure for 5G Service-Based ArchitectureabstractThe 3GPP 5G Service-based Architecture (SBA) security specifications leave several details on how to setup an appropriate Public Key Infrastructure (PKI) for 5G SBA, unspecified. In this work, we propose 5G-SBA-PKI, a public key infrastructure for secure inter-NF communication in 5G SBA core networks, where NF refers to Network Functions. 5G-SBA-PKI is designed to include multiple certificate authorities (with different scopes of operation and capabilities) at different PLMN levels for certification operations and key exchange between communicating NFs, where PLMN refers to a Public Land Mobile Network. We conduct a formal analysis of 5G-SBA-PKI with respect to the desired security properties using TAMARIN prover. Finally, we evaluate 5G-SBA-PKI’s performance with "pre-quantum" as well as quantum-safe cryptographic algorithms. Ayush Kumar 0001, Vrizlynn L. L. Thing |
TrustCom | 2 |
| 2023 | Few-shot weakly-supervised cybersecurity anomaly detectionabstractWith increased reliance on Internet based technologies, cyberattacks compromising users’ sensitive data are becoming more prevalent. The scale and frequency of these attacks are escalating rapidly, affecting systems and devices connected to the Internet. The traditional defense mechanisms may not be sufficiently equipped to handle the complex and ever-changing new threats. The significant breakthroughs in the machine learning methods including deep learning , had attracted interests from the cybersecurity research community for further enhancements in the existing anomaly detection methods. Unfortunately, collecting labelled anomaly data for all new evolving and sophisticated attacks is not practical. Training and tuning the machine learning model for anomaly detection using only a handful of labelled data samples is a pragmatic approach. Therefore, few-shot weakly supervised anomaly detection is an encouraging research direction. In this paper, we propose an enhancement to an existing few-shot weakly-supervised deep learning anomaly detection framework. This framework incorporates data augmentation , representation learning and ordinal regression. We then evaluated and showed the performance of our implemented framework on three benchmark datasets: NSL-KDD, CIC-IDS2018, and TON_IoT. Rahul Kale, Vrizlynn L. L. Thing |
Comput. Secur. | 2 |
| 2023 | Feature mining for encrypted malicious traffic detection with deep learning and other machine learning algorithms
Vrizlynn L. L. Thing |
Comput. Secur. | 2 |
| 2022 | IEEE Big Data Cup 2022: Privacy Preserving Matching of Encrypted Images with Deep LearningabstractSmart sensors, devices and systems deployed in smart cities have brought improved physical protections to their citizens. Enhanced crime prevention, and fire and life safety protection are achieved through these technologies that perform motion detection, threat and actors profiling, and real-time alerts. However, an important requirement in these increasingly prevalent deployments is the preservation of privacy and enforcement of protection of personal identifiable information. Thus, strong encryption and anonymization techniques should be applied to the collected data. In this IEEE Big Data Cup 2022 challenge, different masking, encoding and homomorphic encryption techniques were applied to the images to protect the privacy of their contents. Participants are required to develop detection solutions to perform privacy preserving matching of these images. In this paper, we describe our solution which is based on state-of-the-art deep convolutional neural networks and various data augmentation techniques. Our solution achieved 1stplace at the IEEE Big Data Cup 2022: Privacy Preserving Matching of Encrypted Images Challenge. Vrizlynn L. L. Thing |
IEEE Big Data | 1 |
| 2022 | PhilaeX: Explaining the Failure and Success of AI Models in Malware DetectionabstractThe explanation to an AI model's prediction used to support decision making in cyber security, is of critical importance. It is especially so when the model's incorrect prediction can lead to severe damages or even losses to lives and critical assets. However, most existing AI models lack the ability to provide explanations on their prediction results, despite their strong performance in most scenarios. In this work, we propose a novel explainable AI method, called PhilaeX, that provides the heuristic means to identify the optimized subset of features to form the complete explanations of AI models' predictions. It identifies the features that lead to the model's borderline prediction, and those with positive individual contributions are extracted. The feature attributions are then quantified through the optimization of a Ridge regression model. We verify the explanation fidelity through two experiments. First, we assess our method's capability in correctly identifying the activated features in the adversarial samples of Android malwares, through the features attribution values from PhilaeX. Second, the deduction and augmentation tests, are used to assess the fidelity of the explanations. The results show that PhilaeX is able to explain different types of classifiers correctly, with higher fidelity explanations, compared to the state-of-the-arts methods such as LIME and SHAP. Vrizlynn L. L. Thing |
IoTBDS | 2 |
| 2022 | Machine learning for encrypted malicious traffic detection: Approaches, datasets and comparative study
Kar-Wai Fok, Vrizlynn L. L. Thing |
Comput. Secur. | 3 |
| 2021 | Intrusion Detection in Internet of Things using Convolutional Neural NetworksabstractInternet of Things (IoT) has become a popular paradigm to fulfil needs of the industry such as asset tracking, resource monitoring and automation. As security mechanisms are often neglected during the deployment of IoT devices, they are more easily attacked by complicated and large volume intrusion attacks using advanced techniques. Artificial Intelligence (AI) has been used by the cyber security community in the past decade to automatically identify such attacks. However, deep learning methods have yet to be extensively explored for Intrusion Detection Systems (IDS) specifically for IoT. Most recent works are based on time sequential models like LSTM and there is short of research in CNNs as they are not naturally suited for this problem. In this article, we propose a novel solution to the intrusion attacks against IoT devices using CNNs. The data is encoded as the convolutional operations to capture the patterns from the sensors data along time that are useful for attacks detection by CNNs. The proposed method is integrated with two classical CNNs: ResNet and EfficientNet, where the detection performance is evaluated. The experimental results show significant improvement in both true positive rate and false positive rate compared to the baseline using LSTM. Martin Kodys, Kar-Wai Fok, Vrizlynn L. L. Thing |
PST | 4 |
| 2021 | Data Privacy in Multi-Cloud: An Enhanced Data Fragmentation FrameworkabstractData splitting preserves privacy by partitioning data into various fragments to be stored remotely and shared. It supports most data operations because data can be stored in clear as opposed to methods that rely on cryptography. However, majority of existing data splitting techniques do not consider data already in the multi-cloud. This leads to unnecessary use of resources to re-split data into fragments. This work proposes a data splitting framework that leverages on existing data in the multi-cloud. It improves data splitting mechanisms by reducing the number of splitting operations and resulting fragments. Therefore, decreasing the number of storage locations a data owner manages. Broadcasts queries locate third-party data fragments to avoid costly operations when splitting data. This work examines considerations for the use of third-party fragments and application to existing data splitting techniques. The proposed framework was also applied to an existing data splitting mechanism to complement its capabilities. Randolph Loh, Vrizlynn L. L. Thing |
PST | 2 |
| 2021 | Clustering based opcode graph generation for malware variant detectionabstractMalwares are the key means leveraged by threat actors in the cyber space for their attacks. There is a large array of commercial solutions in the market and significant scientific research to tackle the challenge of the detection and defense against malwares. At the same time, attackers also advance their capabilities in creating polymorphic and metamorphic malwares to make it increasingly challenging for existing solutions. To tackle this issue, we propose a methodology to perform malware detection and family attribution. The proposed methodology first performs the extraction of opcodes from malwares in each family and constructs their respective opcode graphs. We explore the use of clustering algorithms on the opcode graphs to detect clusters of malwares within the same malware family. Such clusters can be seen as belonging to different sub-family groups. Opcode graph signatures are built from each detected cluster. Hence, for each malware family, a group of signatures is generated to represent the family. These signatures are used to classify an unknown sample as benign or belonging to one the malware families. We evaluate our methodology by performing experiments on a dataset consisting of both benign files and malware samples belonging to a number of different malware families and comparing the results to existing approach. Kar-Wai Fok, Vrizlynn L. L. Thing |
PST | 2 |
| 2021 | Three decades of deception techniques in active cyber defense - Retrospect and outlook
Vrizlynn L. L. Thing |
Comput. Secur. | 2 |
| 2019 | Coverless Image Steganography Framework with Increased Payload CapacityabstractThis paper proposes a coverless image steganog- raphy framework with increased payload hiding capacity for confidential information transmission. This is superior to existing coverless schemes which require transmitting a stream of stego images in sequence due to the issue of small hiding capacity per stego image. In addition, by directly linking the secret with existing or generated images, coverless schemes are proven to be more secure as compared to traditional image steganography which embeds confidential message by modifying pixel values of a given image (known as cover). Specifically, we build a dictionary- based encoding scheme using images of the MNIST handwritten digit dataset to generate the stego image. In this dataset, thousands of images carry the same digit but have variance in their shapes and pixel depth. Thus it serves as a good codebook to represent information. The proposed coverless steganography scheme holds necessary resistance to image processing operations like JPEG compression, image binarization, image scaling and image noise, i.e., the hidden message can be successfully decoded from the processed stego images. Ying Zhang 0047, Lilei Zheng, Yew Yi Lu, Vrizlynn L. L. Thing, Roger Zimmermann |
ISM | 4 |
| 2019 | A scalable and extensible framework for android malware detection and family attribution
Vrizlynn L. L. Thing |
Comput. Secur. | 2 |
| 2019 | A survey on image tampering and its detection in real-world photos
Lilei Zheng, Ying Zhang 0047, Vrizlynn L. L. Thing |
J. Vis. Commun. Image Represent. | 3 |
| 2018 | BIFF: A Blockchain-based IoT Forensics Framework with Identity PrivacyabstractThe ubiquitous deployment of Internet of Things (IoT) devices enhances connectivity and communication, and benefits almost every aspect of our lives from manufacturing to retail to smart homes. However, low levels of security protection in these devices due to their limited resources open opportunities for malicious users. An IoT forensics system collecting, processing, analyzing and reporting evidence of attack is required to mitigate the IoT security issues. Although such system has been studied over the past decade and solutions such as cloud-based IoT forensic were proposed, limitation still exist. In this paper, leveraging on the blockchain technology, we propose a per-missioned blockchain-based IoT forensics framework to enhance the integrity, authenticity and non-repudiation properties for the collected evidence. We formally define the system architecture, provide framework details, and propose a cryptographic-based approach to mitigate identity privacy concern. Duc-Phong Le, Mark Huasong Meng, Le Su, Sze Ling Yeo, Vrizlynn L. L. Thing |
TENCON | 5 |
| 2018 | Towards Building a Remote Anti-spoofing Face Authentication SystemabstractThe ability to offer remote access to services or data through various platforms has become a public expectation of many applications and systems nowadays. Recently, we can see the growth in trend where wide range of service providers offer the option to use biometric as a form of authentication, replacing conventional password system. While we gradually migrate towards such authentication method, it is important not to overlook the vulnerabilities of such systems to spoof attack. In fact, spoof attack must be prevented as a mandatory prerequisite in all biometric systems. In this paper, we present a systematic approach for face authentication that incorporates state-of-the-art liveness detection and face verification algorithms to safeguard a system against such attack. We explore and examine the feasibility of the application of such approach on generic devices and systems without incurring hardware dependencies or requiring extensive user-cooperation. Chien Eao Lee, Lilei Zheng, Ying Zhang 0047, Vrizlynn L. L. Thing, Ying Yu Chu |
TENCON | 4 |
| 2018 | Automated Botnet Traffic Detection via Machine LearningabstractConnected machines become more vulnerable to malware infections which potentially cause them to be controlled as part of a botnet for cybercrime activities. Prompt detection of infected machines is required for protecting local networks and infrastructure as well as reducing the impact of botnets. In this paper, we propose the use of machine learning techniques involving multi-layer perceptrons and decision trees on network traffic analysis for the detection of botnet traffic. We enhance components of an existing detection framework with these techniques to automate its processes and improve performance at the same time. Our experiments indicate that the modifications successfully improved the overall performance of botnet traffic detection in both supervised and semi-supervised manners. Kar-Wai Fok, Lilei Zheng, Watt Kwong Wai, Le Su, Vrizlynn L. L. Thing |
TENCON | 5 |
| 2018 | Face Spoofing Video Detection Using Spatio-Temporal Statistical Binary PatternabstractFace has been used as a popular biometric trait to identify a person. However, attacking such face recognition system is not challenging today by using for example a fake face photo or video in front of a camera. In this paper, we present a novel feature, namely, SBP-TOP, to effectively identify such spoofings. SBP-TOP presents the texture information for the face region from both spatial and temporal perspectives. We have tested the proposed feature on two well-known face spoofing datasets: new Michigan State University mobile face spoofing database (MSU MFSD) and CASIA Face Anti-Spoofing Database (CASIA). The results indicate an accuracy over 95% on both datasets and there is an improvement over the state-of-the-art feature by around 10% and 3.2%, respectively. Ying Zhang 0047, Rohit Kumar Dubey, Guang Hua 0001, Vrizlynn L. L. Thing |
TENCON | 4 |
| 2018 | Progressive Control Flow Obfuscation for Android ApplicationsabstractAndroid bytecode is easy to reverse engineer. It has been a common practice for Android application developers to protect their applications with obfuscation techniques. Control flow obfuscation aims to make it more difficult to determine the actual application control flows and thereby impede the understanding of the application logic by the attacker. Despite of the strong potency (i.e., high complexity increment), control flow obfuscation usually incurs a large overhead due to the call and return instructions inserted, which makes the application developer reluctant to use it in practice. In this paper, we present a pragmatic control-flow obfuscation approach where the application developer has more freedom to customize the trade-off between the achieved complexity and overhead. A new subset of application methods will be obfuscated by using a combination of packed-switch and try-catch constructs in different rounds, and larger methods are obfuscated by creating more code fragments in earlier rounds. After each round, the complexity increment will be automatically calculated using our implemented cyclomatic complexity based metric and checked against the target complexity increment. In other words, the obfuscation is conducted in a progressive manner until the target complexity increment is reached. The experimental results show that our method incurs averaged area overhead of 4.07% while achieving almost double complexity increment than the existing method when the same number of application methods are obfuscated. Mark Huasong Meng, Vrizlynn L. L. Thing |
TENCON | 3 |
| 2018 | Assisting Vulnerability Detection by Prioritizing Crashes with Incremental LearningabstractThe proliferation of Internet of Things (IoT) devices is accompanied by the tremendous increase of the attack surface of the networked embedded systems. Software vulnerabilities in these systems become easier than ever to be exploited by cybercriminals. Although fuzz testing is an effective technique to detect memory corruption induced vulnerabilities, it requires in-depth analysis of the typically massive crashes, which impedes the in-time identification and patching of potentially disastrous vulnerabilities. In this paper, we present a new approach that can efficiently classify crashes based on their exploitability, which facilitates the human analysts to prioritize the crashes to be examined and hence accelerate the discovery of vulnerabilities. A compact fingerprint for the dynamic execution trace of each crashing input is firstly generated based on n-gram analysis and feature hashing. The fingerprints are then fed to an online classifier to build the distinguishing model. The incremental learning enabled by the online classifier makes the built model scale well even for a large amount of crashes and at the same time easy to be updated for new crashes. Experiments on 4,392 exploitable crashes and 33,934 non-exploitable crashes show that our method can achieve an F1-score of 95% in detecting the exploitable crashes and significantly better accuracy than the popular crash classification tool !exploitable. Vrizlynn L. L. Thing |
TENCON | 2 |
| 2018 | A survey of Android exploits in the wild
Mark Huasong Meng, Vrizlynn L. L. Thing, Zhongmin Dai |
Comput. Secur. | 2 |
| 2018 | A semi-feature learning approach for tampered region localization across multi-format images
Ying Zhang 0047, Vrizlynn L. L. Thing |
Multim. Tools Appl. | 2 |
| 2018 | Anomaly Detection and Attribution in Networks With Temporally Correlated TrafficabstractAnomaly detection in communication networks is the first step in the challenging task of securing a network, as anomalies may indicate suspicious behaviors, attacks, network malfunctions, or failures. In this paper, we address the problem of not only detecting the anomalous events but also of attributing the anomaly to the flows causing it. To this end, we develop a new statistical decision theoretic framework for temporally correlated traffic in networks via Markov chain modeling. We first formulate the optimal anomaly detection problem via the generalized likelihood ratio test (GLRT) for our composite model. This results in a combinatorial optimization problem which is prohibitively expensive. We then develop two low-complexity anomaly detection algorithms. The first is based on the cross entropy (CE) method, which detects anomalies as well as attributes anomalies to flows. The second algorithm performs anomaly detection via GLRT on the aggregated flows transformation - a compact low-dimensional representation of the raw traffic flows. The two algorithms complement each other and allow the network operator to first activate the flow aggregation algorithm in order to quickly detect anomalies in the system. Once an anomaly has been detected, the operator can further investigate which specific flows are anomalous by running the CE-based algorithm. We perform extensive performance evaluations and experiment our algorithms on synthetic and semi-synthetic data, as well as on real Internet traffic data obtained from the MAWI archive, and finally make recommendations regarding their usability. Ido Nevat, Dinil Mon Divakaran, Sai Ganesh Nagarajan, Pengfei Zhang 0001, Le Su, Li Ling Ko, Vrizlynn L. L. Thing |
IEEE/ACM Trans. Netw. | 7 |
| 2017 | PowerLSTM: Power Demand Forecasting Using Long Short-Term Memory Neural Network
Chang Xu 0003, Daisuke Mashima, Vrizlynn L. L. Thing, Yongdong Wu |
ADMA | 4 |
| 2017 | An Empirical Study on Collective Online Behaviors of Extremist Supporters
Jung-Jae Kim 0001, Yong Liu 0020, Wee-Yong Lim, Vrizlynn L. L. Thing |
ADMA | 4 |
| 2017 | IEEE 802.11 Network Anomaly Detection and Attack Classification: A Deep Learning ApproachabstractDespite the significant advancement in wireless technologies over the years, IEEE 802.11 still emerges as the de-facto standard to achieve the required short to medium range wireless device connectivity in anywhere from offices to homes. With it being ranked the highest among all deployed wireless technologies in terms of market adoption, vulnerability exploitation and attacks targeting it have also been commonly observed. IEEE 802.11 security has thus become a key concern over the years. In this paper, we analysed the threats and attacks targeting the IEEE 802.11 network and also identified the challenges of achieving accurate threat and attack classification, especially in situations where the attacks are novel and have never been encountered by the detection and classification system before. We then proposed a solution based on anomaly detection and classification using a deep learning approach. The deep learning approach self-learns the features necessary to detect network anomalies and is able to perform attack classification accurately. In our experiments, we considered the classification as a multi-class problem (that is, legitimate traffic, flooding type attacks, injection type attacks and impersonation type attacks), and achieved an overall accuracy of 98.6688% in classifying the attacks through the proposed solution. Vrizlynn L. L. Thing |
WCNC | 1 |
| 2017 | REX: Resilient and efficient data structure for tracking network flows
Dinil Mon Divakaran, Li Ling Ko, Le Su, Vrizlynn L. L. Thing |
Comput. Networks | 4 |
| 2017 | FACT: A Framework for Authentication in Cloud-Based IP TracebackabstractIP traceback plays an important role in cyber investigation processes, where the sources and the traversed paths of packets need to be identified. It has a wide range of applications, including network forensics, security auditing, network fault diagnosis, and performance testing. Despite a plethora of research on IP traceback, the Internet is yet to see a large-scale practical deployment of traceback. Some of the major challenges that still impede an Internet-scale traceback solution are, concern of disclosing Internet Service Provider (ISP's) internal network topologies (in other words, concern of privacy leak), poor incremental deployment, and lack of incentives for ISPs to provide traceback services. In this paper, we argue that cloud services offer better options for the practical deployment of an IP traceback system. We first present a novel cloud-based traceback architecture, which possesses several favorable properties encouraging ISPs to deploy traceback services on their networks. While this makes the traceback service more accessible, regulating access to traceback service in a cloud-based architecture becomes an important issue. Consequently, we address the access control problem in cloud-based traceback. Our design objective is to prevent illegitimate users from requesting traceback information for malicious intentions (such as ISPs topology discovery). To this end, we propose a temporal token-based authentication framework, called FACT, for authenticating traceback service queries. FACT embeds temporal access tokens in traffic flows, and then delivers them to end-hosts in an efficient manner. The proposed solution ensures that the entity requesting for traceback service is an actual recipient of the packets to be traced. Finally, we analyze and validate the proposed design using real-world Internet data sets. Long Cheng 0005, Dinil Mon Divakaran, Aloysius Wooi Kiak Ang, Wee-Yong Lim, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2016 | Control flow obfuscation for Android applications
Vivek Balachandran, Sufatrio, Darell J. J. Tan, Vrizlynn L. L. Thing |
Comput. Secur. | 4 |
| 2016 | Twenty years of digital audio watermarking - a comprehensive reviewabstractDigital audio watermarking is an important technique to secure and authenticate audio media. This paper provides a comprehensive review of the twenty years’ research and development works for digital audio watermarking, based on an exhaustive literature survey and careful selections of representative solutions. We generally classify the existing designs into time domain and transform domain methods , and relate all the reviewed works using two generic watermark embedding equations in the two domains. The most important designing criteria, i.e., imperceptibility and robustness, are thoroughly reviewed. For imperceptibility , the existing measurement and control approaches are classified into heuristic and analytical types, followed by intensive analysis and discussions. Then, we investigate the robustness of the existing solutions against a wide range of critical attacks categorized into basic, desynchronization, and replacement attacks, respectively. This reveals current challenges in developing a global solution robust against all the attacks considered in this paper. Some remaining problems as well as research potentials for better system designs are also discussed. In addition, audio watermarking applications in terms of US patents and commercialized solutions are reviewed. This paper serves as a comprehensive tutorial for interested readers to gain a historical, technical, and also commercial view of digital audio watermarking. Guang Hua 0001, Jiwu Huang, Yun Q. Shi 0001, Jonathan Goh, Vrizlynn L. L. Thing |
Signal Process. | 5 |
| 2016 | Opportunistic Piggyback Marking for IP TracebackabstractIP traceback is a solution for attributing cyber attacks, and it is also useful for accounting user traffic and network diagnosis. Marking-based traceback (MBT) has been considered a promising traceback approach, and has received considerable attention. However, we find that the traceback message delivery problem in MBT, which is important to the successful completion of a traceback, has not been adequately studied in the literature. To address this issue, we present the design, analysis, and evaluation of opportunistic piggyback marking (OPM) for IP traceback in this paper. The OPM distinguishes itself from the existing works by decoupling the traceback message content encoding and delivery functions in MBT, and efficiently achieves expedited and robust traceback message delivery by exploiting piggyback marking opportunities. Based on the proposed OPM scheme, we then present the flexible marking-based traceback framework, which is a novel design paradigm for IP traceback and has several favorable features for practical deployment of IP traceback. Through the numerical analysis and the comprehensive simulation evaluations, we demonstrate that our design effectively reduces the traceback completion delay and router processing overhead, and increases the message delivery ratio compared with other baseline approaches. Long Cheng 0005, Dinil Mon Divakaran, Wee-Yong Lim, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Fingerprint Liveness Detection From Single Image Using Low-Level Features and Shape AnalysisabstractFingerprint-based authentication systems have developed rapidly in the recent years. However, current fingerprint-based biometric systems are vulnerable to spoofing attacks. Moreover, single feature-based static approach does not perform equally over different fingerprint sensors and spoofing materials. In this paper, we propose a static software approach. We propose to combine low-level gradient features from speeded-up robust features, pyramid extension of the histograms of oriented gradient and texture features from Gabor wavelet using dynamic score level integration. We extract these features from a single fingerprint image to overcome the issues faced in dynamic software approaches, which require user cooperation and longer computational time. A experimental analysis done on LivDet 2011 data produced an average equal error rate (EER) of 3.95% over four databases. The result outperforms the existing best average EER of 9.625%. We also performed experiments with LivDet 2013 database and achieved an average classification error rate of 2.27% in comparison with 12.87% obtained by the LivDet 2013 competition winner. Rohit Kumar Dubey, Jonathan Goh, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Audio Authentication by Exploring the Absolute-Error-Map of ENF SignalsabstractRecently, the electric network frequency (ENF), a natural signature embedded in many audio recordings, has been utilized as a criterion to examine the authenticity of audio recordings. ENF-based audio authentication system involves extraction of the ENF signal from a questioned audio recording, and matching it with the reference signal stored in an ENF database. This establishes a popular application of audio timestamp verification. In this paper, we explore another important application, i.e., ENF-based audio tampering detection, which has received less research attention. Specifically, we introduce the absolute-error-map (AEM) between the ENF signals obtained from the testing audio recording and the database. The AEM serves as an ensemble of the raw data associated with the ENF matching process. Through intensive analysis of the AEM, we propose two algorithms to jointly deal with timestamp verification and tampering detection, including insertion, deletion, and splicing attacks, respectively. The first algorithm is based on exhaustive point search and measurement, while the second algorithm leverages the image erosion technique to achieve fast detection of tampering type and tampered region, thus the second algorithm sacrifices some accuracy for speed. The authentication mechanism is that the system first determines if the testing data have been tampered with, and then outputs the timestamp information if no tampering is detected. Otherwise, it outputs the tampering type and tampered region. We demonstrate the effectiveness of the proposed solution via both synthetic and practical examples from our practically deployed audio authentication system. Guang Hua 0001, Ying Zhang 0047, Jonathan Goh, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | Accurate Specification for Robust Detection of Malicious Behavior in Mobile Environments
Sufatrio, Tong-Wei Chua, Darell J. J. Tan, Vrizlynn L. L. Thing |
ESORICS (2) | 4 |
| 2015 | SLIC: Self-Learning Intelligent Classifier for network traffic
Dinil Mon Divakaran, Le Su, Yung Siang Liau, Vrizlynn L. L. Thing |
Comput. Networks | 4 |
| 2015 | Time-Spread Echo-Based Audio Watermarking With Optimized Imperceptibility and RobustnessabstractWe present a time-spread echo-based audio watermarking scheme with optimized imperceptibility and robustness. Specifically, convex optimization based finite-impulse-response (FIR) filter design is utilized to obtain the optimal echo filter coefficients. The desired power spectrum of the echo filter is shaped by the proposed maximum power spectral margin (MPSM) and the absolute threshold of hearing (ATH) of human auditory system (HAS) to ensure the optimal imperceptibility. Meanwhile, the auto-correlation function of the echo filter coefficients is specified as the constraint in the problem formulation, which controls the robustness in terms of watermark detection. In this way, a joint optimization of imperceptibility and robustness can be quantitatively performed. As a result, the proposed watermarking scheme is superior to existing solutions such as the ones based on pseudo noise (PN) sequence or modified pseudo noise (MPN) sequence. Note that the designed echo kernel is also highly secure in that only with the same filter coefficients can one successfully detect the watermark. Experimental results are provided to evaluate the imperceptibility and robustness of the proposed watermarking scheme. Guang Hua 0001, Jonathan Goh, Vrizlynn L. L. Thing |
IEEE ACM Trans. Audio Speech Lang. Process. | 3 |
| 2015 | Cepstral Analysis for the Application of Echo-Based Audio Watermark DetectionabstractCepstral analysis is an important signal processing procedure for audio watermark detection in echo-based audio watermarking systems. However, with the use of two common versions, i.e., complex and real cepstra, this procedure is usually treated as a very standard routine. This paper starts from noting inappropriate cepstral analysis from existing works, and provides rigorous derivations to reveal the advantages of using real cepstrum than complex cepstrum in echo-based audio watermark detection. Furthermore, we introduce two alternatives, termed as real part and imaginary part cepstrum, respectively, based on which a joint detection scheme is proposed. This is achieved by noting that both real part and imaginary part cepstra contain a full version of the echo kernel coefficients, which can be appropriately combined to obtain a composite cepstrum to further suppress the interferences. The advantages of the joint detection scheme over conventional approach using real cepstrum are illustrated via both performance analysis and experimental results. The accuracies of the mathematical approximations for each version of cepstrum are evaluated by normalized misalignment. The detection robustness is evaluated using the peak-to-average power ratio. The relationships among echo length, echo delays, and scaling factor, during watermark detection phase, are also discussed. Experimental results of watermark detection rate are provided to compare the performance of complex, real, and composite cepstra, respectively. Guang Hua 0001, Jonathan Goh, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Conditional Weighted Transaction Aggregation for Credit Card Fraud Detection
Wee-Yong Lim, Amit Sachan, Vrizlynn L. L. Thing |
IFIP Int. Conf. Digital Forensics | 3 |
| 2014 | A Dynamic Matching Algorithm for Audio Timestamp Identification Using the ENF CriterionabstractThe electric network frequency (ENF) criterion is a recently developed technique for audio timestamp identification, which involves the matching between extracted ENF signal and reference data. For nearly a decade, conventional matching criterion has been based on the minimum mean squared error (MMSE) or maximum correlation coefficient. However, the corresponding performance is highly limited by low signal-to-noise ratio, short recording durations, frequency resolution problems, and so on. This paper presents a threshold-based dynamic matching algorithm (DMA), which is capable of autocorrecting the noise affected frequency estimates. The threshold is chosen according to the frequency resolution determined by the short-time Fourier transform (STFT) window size. A penalty coefficient is introduced to monitor the autocorrection process and finally determine the estimated timestamp. It is then shown that the DMA generalizes the conventional MMSE method. By considering the mainlobe width in the STFT caused by limited frequency resolution, the DMA achieves improved identification accuracy and robustness against higher levels of noise and the offset problem. Synthetic performance analysis and practical experimental results are provided to illustrate the advantages of the DMA. Guang Hua 0001, Jonathan Goh, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2013 | Smartphone Volatile Memory Acquisition for Security Analysis and Forensics Investigation
Vrizlynn L. L. Thing, Zheng Leong Chua |
SEC | 1 |
| 2013 | A Lightweight Algorithm for Automated Forum Information ProcessingabstractThe vast variety of information on Web forums makes them a valuable resource for various purposes such as scam detection, national security protection and sentiment analysis. However, it is challenging to extract useful information from Web forums accurately and efficiently. First, several page types exist in Web forums and content is presented in different formats in these pages. Second, the content on the forum pages is stored in the form of data blocks. For the information to be meaningful, it is necessary to extract the relevant data blocks separately. The main problem with generic content extraction systems is that they cannot distinguish among various pages nor extract information with the required granularity. Although, several content extraction methods exist for Web forums, these methods either do not satisfy the above requirements or use heuristics based approaches (such as assumptions on standard visual appearances, etc., resulting in limited applicability to different varieties of forum). In this paper, we propose a general and efficient content extraction method using the properties of links present in forum pages. The effectiveness of our proposed method is shown through our experimental results. Wee-Yong Lim, Amit Sachan, Vrizlynn L. L. Thing |
Web Intelligence | 3 |
| 2013 | Image content analysis for sector-wise JPEG fragment classification
Vrizlynn L. L. Thing |
J. Vis. Commun. Image Represent. | 2 |
| 2012 | An enhanced intelligent forum crawlerabstractAs online forums contain a vast amount of information that can aid in the early detection of fraud cases and extremist activities, accurate and efficient forum crawlers are very important in the field of digital forensics to acquire useful information and knowledge. In this paper, we conduct an analysis on an existing work, iRobot, which is an intelligent forum crawler. We identify the drawbacks of iRobot in its vertex-based traversal path selection, edge-based traversal path seletion, informativeness estimation and detection of duplicate pages. We also propose algorithms which are better suited for these tasks and present the proofs that they can achieve a much higher accuracy and efficiency. Finally, we conduct an empirical evaluation on the “scam.com” and “fraudwatchers.org” forum sites to demonstrate the actual accuracy improvement of our proposed informativeness estimation. Hwei-Ming Ying, Vrizlynn L. L. Thing |
CISDA | 2 |
| 2012 | Symbian Smartphone Forensics and Security: Recovery of Privacy-Protected Deleted Data
Vrizlynn L. L. Thing, Darell J. J. Tan |
ICICS | 1 |
| 2012 | Using Low Level Gradient Channels for Computationally Efficient Object Detection and Its Application in Logo DetectionabstractWe propose a logo detection approach which utilizes the Haar (Haar-like) features computed directly from the gradient orientation, gradient magnitude channels and the gray intensity channel to effectively and efficiently extract discriminating features for a variety of logo images. The major contributions of this work are two-fold: 1) we explicitly demonstrate that, with an optimized design and implementation, the considerable discrimination can be obtained from the simple features like the Haar features which are extracted directly from the low level gradient orientation and magnitude channels, 2) we proposed an effective and efficient logo detection approach by using the Haar features obtained directly from gradient orientation, magnitude, and gray image channels. The experimental results on the collected merchandise images of Louis Vuitton (LV) and Polo Ralph Lauren (PRL) products show promising applicabilities of our approach. Vrizlynn L. L. Thing |
ISM | 2 |
| 2012 | Logo Classification with Edge-Based DAISY DescriptorabstractFor the classification of logo images, there are significant challenges in the classification of merchandise logos such that only a few key points can be found in the relatively small logo images due to large variations in texture, poor illumination and generally, lack of discriminative features. This paper addresses these difficulties by introducing an integrated approach to classify merchandise logos with the combination of local edge-based descriptor-DAISY, spatial histogram and salient region detection. During the training phase, after carrying out the edge extraction, merchandise logos are described with a set of SIFT-like DAISY descriptors which is computed efficiently and densely along edge pixels. Visual word vocabulary generation and spatial histogram are used for describing the images/regions. Saliency map for object detection is adopted to narrow down and localize the logos. The feature map for approximating a non-linear kernel is also used to facilitate the classification by a linear SVM classifier. The experimental results demonstrate that the Edge-based DAISY (EDAISY) descriptor outperforms the state-of-the-art SIFT and DSIFT descriptors in terms of classification accuracy on a set of collected logo image dataset. Bai Ying Lei, Vrizlynn L. L. Thing, Wee-Yong Lim |
ISM | 2 |
| 2012 | An Improved Double Compression Detection Method for JPEG Image ForensicsabstractDouble JPEG image compression detection, or more specifically, double quantization detection, is an important digital image forensic method to detect the presence of image forgery or tampering. In this paper, we introduce an improved double quantization detection method to improve the accuracy of JPEG image tampering detection. We evaluate our detection method using the publicly available CASIA authentic and tampered image data set of 9501 JPEG images. We carry out 20 rounds of experiments with stringent parameter setting placed on our detection method to demonstrate its robustness. Each round of classifier is generated from a unique, non-overlapping and small subset composing of 1/20 of the tampered and 1/72 of the authentic images, to obtain a training data set of about 100 images per class, with the rest of the 19/20 of the tampered and 71/72 of the authentic images used for testing. Through the experiments, we show an average improvement of 40.31% and 44.85% in the true negative (TN) rate and true positive (TP) rate, respectively, when compared with the current state-of-the-art method. The average TN and TP rates obtained from 20 rounds of experiments carried out using our detection method, are 90.81% and 76.95%, respectively. The experimental results show that our JPEG image forensics method can support a reliable large-scale digital image evidence authenticity verification with consistent good accuracy. The low training to testing data ratio also indicates that our method is robust in practical applications even with a relatively limited or small training data set available. Vrizlynn L. L. Thing, Carmen Cheh |
ISM | 1 |
| 2012 | Enhanced Dictionary Based Rainbow Table
Vrizlynn L. L. Thing, Hwei-Ming Ying |
SEC | 1 |
| 2012 | A Generalized Links and Text Properties Based Forum CrawlerabstractWeb forums have become a major source of information gathering/mining due to a large amount of user generated content. Crawling of Web forums is necessary to gather/mine the information from them. However, a generic Web crawler is unable to efficiently and effectively crawl the Web forums because of the existence of many redundant and duplicate pages. In addition, there exists a crawling relationship among the useful pages that need to be considered. So, for efficient crawling, we need to intelligently crawl the Web forums by eliminating redundant and duplicate pages, and understanding the crawling relationship. Existing works in forum crawling use visual pattern recognition based methods, which make them extremely computational expensive. In this paper, we propose a novel light-weight crawling method using text and links properties of the pages in Web forums. Theoretical analysis and experimental results show the effectiveness and efficiency of the proposed method. Amit Sachan, Wee-Yong Lim, Vrizlynn L. L. Thing |
Web Intelligence | 3 |
| 2011 | Content based JPEG fragmentation point detectionabstractIn the forensics analysis of raw evidence data, fragmentation point detection is crucial to differentiate fragments of evidence and identify potentially corrupted data. This need is even more prominent for JPEG images since the chance is high that an erroneous data block passes a normal JPEG decoder without triggering any errors. Therefore, it is important to verify the content of the decoded image data to determine if fragmentation and/or corruption has occurred. In this paper, we propose three different techniques for the detection of fragmentation point based on the image contents, as well as a detector built by combining these methods. We evaluate the effectiveness of these techniques and the combined detector by implementing them on a standard JPEG decoder and testing them on more than 2000 fragmented images generated from over 1200 JPEG photos. Bilgehan Sahin, Ee-Chien Chang, Vrizlynn L. L. Thing |
ICME | 4 |
| 2010 | Virtual Expansion of Rainbow Tables
Vrizlynn L. L. Thing |
IFIP Int. Conf. Digital Forensics | 1 |
| 2009 | Adaptive response system for distributed denial-of-service attacksabstractThis dissertation presents a distributed denial-of-service adaptive response (DARE) system, capable of executing appropriate detection and mitigation responses automatically and adaptively according to the attacks. It supports easy integration of distributed modules for both signature-based and anomaly-based detection. Additionally, the innovative design of DARE's individual components takes into consideration the strengths and weaknesses of existing defence mechanisms, and the characteristics and possible future mutations of DDoS attacks. The distributed components work together interactively to adapt detection and response according to the attack types. Experiments on DARE show that the attack detection and mitigation were successfully completed within seconds, with about 60% to 86% of the attack traffic being dropped, while availability for legitimate and new legitimate requests was maintained. DARE is able to detect and trigger appropriate responses in accordance to the attacks being launched with high accuracy, effectiveness and efficiency. The dissertation is available at http://pubs.doc.ic.ac.uk/VrizlynnThing-PhD-Thesis-2008/VrizlynnThing-PhD-Thesis-2008.pdf. Vrizlynn L. L. Thing, Morris Sloman, Naranker Dulay |
Integrated Network Management | 1 |
| 2009 | Locating network domain entry and exit point/path for DDoS attack trafficabstractA method to determine entry and exit points or paths of DDoS attack traffic flows into and out of network domains is proposed. We observe valid source addresses seen by routers from sampled traffic under non-attack conditions. Under attack conditions, we detect route anomalies by determining which routers have been used for unknown source addresses, to construct the attack paths. We consider deployment issues and show results from simulations to prove the feasibility of our scheme. We then implement our Traceback mechanism in C++ and more realistic experiments are conducted. The experiments show that accurate results, with high traceback speed of a few seconds, are achieved. Compared to existing techniques, our approach is non-intrusive, not requiring any changes to the Internet routers and data packets. Precise information regarding the attack is not required allowing a wide variety of DDoS attack detection techniques to be used. The victim is also relieved from the traceback task during an attack. The scheme is simple and efficient, allowing for a fast traceback, and scalable due to the distribution of processing workload. Vrizlynn L. L. Thing, Morris Sloman, Naranker Dulay |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2008 | Network domain entrypoint/path determination for DDoS attacksabstractA method to determine entry points and paths of DDoS attack traffic flows into network domains is proposed. We determine valid source addresses seen by routers from sampled traffic under non-attack conditions. Under attack conditions, we detect route anomalies by determining which routers have been used for unknown source addresses to construct the attack paths. We show results from simulations to detect the routers carrying attack traffic in the victim's network domain. Our approach is non-intrusive, not requiring any changes to the Internet routers and data packets. Precise information regarding the attack is not required allowing a wide variety of DDoS attack detection techniques to be used. The victim is also relieved from the traceback task during an attack. Our algorithm is simple and efficient, allowing for a fast traceback and the method is scalable due to the distribution of processing workload. Vrizlynn L. L. Thing, Morris Sloman, Naranker Dulay |
NOMS | 1 |
| 2007 | Non-intrusive IP traceback for DDoS attacksabstractThe paper describes a Non-Intrusive IP traceback scheme which uses sampled traffic under non-attack conditions to build and maintains caches of the valid source addresses transiting network routers. Under attack conditions, route anomalies are detected by determining which routers have been used for unknown source addresses, in order to construct the attack graph. Results of simulation studies are presented. Our approach does not require changes to the Internet routers or protocols. Precise information regarding the attack is not required allowing a wide variety of DDoS attack detection techniques to be used. Our algorithm is simple and efficient, allowing for a fast traceback and the scheme is scalable due to the distribution of processing workload. Vrizlynn L. L. Thing, Morris Sloman, Naranker Dulay |
AsiaCCS | 1 |
| 2007 | A Survey of Bots Used for Distributed Denial of Service Attacks
Vrizlynn L. L. Thing, Morris Sloman, Naranker Dulay |
SEC | 1 |
| 2005 | Traffic Redirection Attack Protection System (TRAPS) - A Full-Fledged Adaptive DoS/DDoS Attack Mitigation Scheme
Vrizlynn L. L. Thing, Henry C. J. Lee, Morris Sloman |
SEC | 1 |
| 2004 | Bandwidth-efficient WDM channel allocation for four-wave mixing-effect minimizationabstractA novel channel-allocation method that allows reduction of the four-wave mixing (FWM) effect while maintaining bandwidth efficiency is presented. It is composed of a fractional bandwidth-allocation algorithm, taking into consideration the use of parameters with distinct differences. This proposed technique allows the computation of an optimal channel-allocation set, where degradation caused by interchannel interference and FWM is minimal. Simulation is carried out to show significant performance improvement, such as an average bit-error rate improvement factor of 1.336 for an eight-channel wavelength-division multiplexing system, without the requirement of increased bandwidth, unlike existing channel-allocation methods. Vrizlynn L. L. Thing, Perry Ping Shum, M. K. Rao |
IEEE Trans. Commun. | 1 |
| 2003 | A local mobility agent selection algorithm for mobile networksabstractThe mobile IP protocol has been designed to address the problem of roaming between IP networks. However, as mobile nodes moves between networks, the signaling overhead causes significant disruption to real time data traffic. The localized mobility management (LMM) has been proposed to enhance the handoff performance between networks within the same domain. By introducing the concept of local mobility agent (LMA), a mobile node visiting a foreign domain is exempted from sending frequent address update to its home agent and correspondent nodes, when its movement is limited to the visited domain. As multiple LMAs are configured in a domain for redundancy, scalability and load sharing concerns, LMA selection becomes an issue. This paper proposed a new LMA selection algorithm, mobile controlled movement tracking (MCMT). The objective of this new algorithm is to discover the optimal LMA in terms of selection stability and load balancing, by taking into consideration the mobility characteristics of the mobile node. Our analysis shows that this proposal can provide good support for low latency handoff and load sharing among LMAs. Henry C. J. Lee, Vrizlynn L. L. Thing |
ICC | 3 |
| 2003 | ICMP Traceback with Cumulative Path, an Efficient Solution for IP Traceback
Henry C. J. Lee, Vrizlynn L. L. Thing, Miao Ma |
ICICS | 2 |
| 2003 | On the Issues of IP Traceback for IPv6 and Mobile IPv6abstractAs the Internet becomes pervasive, the vulnerability of some fundamental design aspects of the Internet has also become significant. Among which, denial-of-service (DoS) and distributed DoS (DDoS) pose significant problems, as they are disruptive to the useful traffics and are hard to prevent. One solution consists in instituting accountability, which hold the attackers accountable for the attack. The key issue is to identify the real sources of the attacks and attackers use spoofed IP address to hide their actual network location. However, the Internet architecture does not provide intrinsic support for identifying the real sources of IP packets. Numerous mechanisms have been proposed to traceback the real sources. Most of such networks have been addressing the IP version 4. In this paper, we address the issues of IP traceback in the context of IPv6 and mobile IPv6. This paper provides a detailed analysis of these issues and problems. The main problem lies with the transformations that are introduced by IPv6 and mobile IPv6 protocols, namely tunneling and addresses manipulation. We then propose a solution, including new ICMPv6 messages for traceback co-ordination, to facilitate the traceback mechanism. Henry C. J. Lee, Miao Ma, Vrizlynn L. L. Thing |
ISCC | 3 |
| 2003 | Performance Evaluation of Hop-by-Hop Local Mobility Agents Probing for Mobile IPv6abstractMobile Ipv6 (MIPv6) and fast handover (FHO) have been developed by the Internet Engineering Task Force (IETF) to address the IP mobility issues of roaming mobile devices, and to reduce handover latency due to link switching delay, movement detection and IP address configuration during MIPv6 operation, respectively. In an attempt to enhance the performance of MIPv6, the hop-by-hop local mobility management (HbH-LMAsP) localized mobility management (LMM) scheme was devised and proposed to IETF as an Internet draft. In this paper, simulations that were performed on MIPv6 and subsequently, on MIPv6 with the addition of the HbH-LMAsP functionality, were described. The results obtained based on registration delay, packet loss and the overhead computation, were analyzed and discussed. The improvements contributed by the HbH-LMAsP LMM scheme over the basic mobile IPv6 were shown to be significant. The discussion on load balancing was also covered. Vrizlynn L. L. Thing, Henry C. J. Lee |
ISCC | 1 |