Hongda Li 0002

dblp:49/6722-2 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
4since 2021 · last 2023
0000-0001-5589-4759ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2023 xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
Hongda Li 0002, Ziming Zhao 0001, Hongxin Hu
USENIX Security Symposium2
2023 SysFlow: Toward a Programmable Zero Trust Framework for System Security
abstract
Zero Trust, as an emerging trend of cybersecurity paradigms in modern infrastructure (e.g., enterprise, cloud, edge, IoT, and 5G), is moving security defenses from static and perimeter-based control systems to focus on users and resources with no assumption of implicit trust. However, the current Zero Trust Architecture (ZTA) mainly focuses on the network security and lacks in-depth considerations on system-level security policies and abstractions, which leaves the realization of the principle incomplete. To bridge the gap, we propose an innovativeprogrammablesystem security framework called SYSFLOW to enable unified, dynamic, and fine-grained Zero Trust security control for system resources. SYSFLOW introduces a novelsystem flowabstraction to modelsystem activitiesacross the entire infrastructure, and provides a system-level data plane and control plane separation and abstraction. The new logically centralized controller accommodates a unifiedprogrammablePolicy Decision Point (PDP) that acquires a holistic view of system behaviors for controlling system resource accesses by translated programmable security policies into system flow rules. The SYSFLOW data plane, acting as Policy Enforcement Point (PEP), enforces translated system flow rules, which can be updated dynamically and facilitate fine-grained responsive actions. Our extensive evaluations demonstrate the effectiveness and scalability of SYSFLOW, which addresses the security issues in various scenarios with a minor performance overhead.
Sungmin Hong, Lei Xu 0024, Hongda Li 0002, Hongxin Hu, Guofei Gu
IEEE Trans. Inf. Forensics Secur.4
2022 Understanding and Detecting Remote Infection on Linux-based IoT Devices
abstract
The rocketed population, poor security, and 24/7 online properties make Linux-based Internet of Things (IoT) devices ideal targets for attackers. However, due to the budget constraints and an enormous number of vulnerabilities on such devices, protecting them against attacks is very challenging. Therefore, understanding and detecting IoT malware remote infection, which is before the compromised IoT devices are monetized by adversaries, is crucial to mitigate damages and financial loss caused by IoT malware. In this paper, we conduct an empirical study on a large-scale dataset covering 403,464 samples collected from VirusShare and a large group of IoT honeypots to gain a deep insight into the characteristics of IoT malware remote infection. We share detailed statistics of shell commands found in our dataset, highlight malicious behaviors performed through those commands, investigate current states of fingerprinting methods of those commands, and offer a taxonomy of shell commands by introducing the notion of infection capability. To demonstrate the usefulness of the knowledge gained from our study, we develop an approach to detect ongoing remote infection activities based on infection capabilities. Our evaluation shows that our detection approach can achieve a 99.22% detection rate for remote infections in the wild and introduce small performance overhead.
Hongda Li 0002, Qiqing Huang, Hongxin Hu, Long Cheng 0005, Guofei Gu, Ziming Zhao 0001
AsiaCCS1
2022 S-Blocks: Lightweight and Trusted Virtual Security Function With SGX
abstract
Despite the advantages of scalability and flexibility, Security Function Virtualization (SFV) raises concerns about its own security. To enhance the security of SFV, a promising approach is to run critical components of off-the-shelf security software inside Software Guard Extensions (SGX) enclaves. This idea, however, is hardly practical due to the difficulty of detaching components from the monolithic security function and the unacceptable cost of executing them inside enclaves. In this article, we propose S-Blocks, an architecture to modularize virtual security functions (VSFs) and protect crucial modules with SGX in an efficient manner. S-Blocks decomposes VSFs into trusted and untrusted modules and provides dedicated APIs systematically. Only crucial VSF modules are hardened with enclaves. Furthermore, aiming at addressing state consistency and secure migration issues of security function scaling, we design a fine-grained state synchronization and migration mechanism to ensure loss-free, order-preserving, and state security for VSFs. To demonstrate the effectiveness of our approach, we prototype S-Blocks using Fast-Click on a real Skylake platform and implement three critical types of virtual security functions based on the S-Blocks architecture. Our evaluation results show that S-Blocks only imposes a manageable performance overhead, and low latency and resource consumption when protecting VSFs.
Juan Wang 0006, Shirong Hao, Hongxin Hu, Bo Zhao 0023, Hongda Li 0002, Jun Xu 0024, Peng Liu 0005
IEEE Trans. Cloud Comput.5
2020 DeepPower: Non-intrusive and Deep Learning-based Detection of IoT Malware Using Power Side Channels
abstract
The vulnerability of Internet of Things (IoT) devices to malware attacks poses huge challenges to current Internet security. The IoT malware attacks are usually composed of three stages: intrusion, infection and monetization. Existing approaches for IoT malware detection cannot effectively identify the executed malicious activities at intrusion and infection stages, and thus cannot help stop potential attacks timely. In this paper, we present DeepPower, a non-intrusive approach to infer malicious activities of IoT malware via analyzing power side-channel signals using deep learning. DeepPower first filters raw power signals of IoT devices to obtain suspicious signals, and then performs a fine-grained analysis on these signals to infer corresponding executed activities inside the devices. DeepPower determines whether there exists an ongoing malware infection by conducting a correlation analysis on these identified activities. We implement a prototype of DeepPower leveraging low-cost sensors and devices and evaluate the effectiveness of DeepPower against real-world IoT malware using commodity IoT devices. Our experimental results demonstrate that DeepPower is able to detect infection activities of different IoT malware with a high accuracy without any changes to the monitored devices.
Hongda Li 0002, Feng Luo 0001, Hongxin Hu, Long Cheng 0005, Hai Xiao, Rong Ge 0002
AsiaCCS2
2019 When NFV Meets ANN: Rethinking Elastic Scaling for ANN-based NFs
abstract
Network Function Virtualization (NFV) provides middleboxes with substantial elasticity from a system level, and Artificial Neural Network (ANN) empowers middleboxes with great intelligence from an algorithm-level perspective. However, when ANN-based Network Functions (NFs) want to take advantage of the elasticity of NFV, our study finds that huge gaps exist between the existing approaches and the ideal goals for the elasticity control of ANN-based NFs. By revealing the key differences between ANN-based NFs and traditional NFs, we propose LEGO, an innovative framework that provides systematic mechanisms for traffic splitting, instance partition and runtime management to enable correct and efficient scaling of ANN-based NFs. Preliminary implementation and evaluation demonstrate the feasibility and effectiveness of the LEGO system. The major purpose of this paper is to highlight these challenges and sketch out a new roadmap towards ANN-based NFV paradigm.
Menghao Zhang 0001, Jiasong Bai, Zili Meng, Hongda Li 0002, Hongxin Hu, Mingwei Xu 0001
ICNP5
2019 Towards a reliable firewall for software-defined networks
Hongxin Hu, Wonkyu Han, Sukwha Kyung, Juan Wang 0006, Gail-Joon Ahn, Ziming Zhao 0001, Hongda Li 0002
Comput. Secur.7
2018 vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection Systems
abstract
Traditional Network Intrusion Detection Systems (NIDSes) are generally implemented on vendor proprietary appliances or middleboxes with poor versatility and flexibility. Emerging Network Function Virtualization (NFV) and Software-Defined Networking (SDN) technologies can virtualize NIDSes and elastically scale them to deal with attack traffic variations. However, such an elasticity feature must not come at the cost of decreased detection effectiveness and expensive provisioning. In this paper, we propose an innovative NIDS architecture, vNIDS, to enable safe and efficient virtualization of NIDSes. vNIDS addresses two key challenges with respect to effective intrusion detection and non-monolithic NIDS provisioning in virtualizing NIDSes. The former challenge is addressed by detection state sharing while minimizing the sharing overhead in virtualized environments. In particular, static program analysis is employed to determine which detection states need to be shared. vNIDS addresses the latter challenge by provisioning virtual NIDSes as microservices and employing program slicing to partition the detection logic programs so that they can be executed by each microservice separately. We implement a prototype of vNIDS to demonstrate the feasibility of our approach. Our evaluation results show that vNIDS could offer both effective intrusion detection and efficient provisioning for NIDS virtualization.
Hongda Li 0002, Hongxin Hu, Guofei Gu, Gail-Joon Ahn
CCS1
2018 Enhancing Security Education Through Designing SDN Security Labs in CloudLab
abstract
Software-Defined Networking (SDN) represents a major shift from ossified hardware-based networks to programmable software-based networks. It introduces significant granularity, visibility, and flexibility into networking, but at the same time brings new security challenges. Although the research community is making progress in addressing both the opportunities in SDN and the accompanying security challenges, very few educational materials have been designed to incorporate the latest research results and engage students in learning about SDN security. In this paper, we presents our newly designed SDN security education materials, which can be used to meet the ever-increasing demand for high quality cybersecurity professionals with expertise in SDN security. The designed security education materials incorporate the latest research results in SDN security and are integrated into CloudLab, an open cloud platform, for effective hands-on learning. Through a user study, we demonstrate that students have a better understanding of SDN security after participating in these well-designed CloudLab-based security labs, and they also acquired strong research interests in SDN security.
Younghee Park, Hongxin Hu, Xiaohong Yuan, Hongda Li 0002
SIGCSE4
2017 On the Safety and Efficiency of Virtual Firewall Elasticity Control
Juan Deng, Hongda Li 0002, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao 0001, Wonkyu Han
NDSS2
2017 Poster: On the Safety and Efficiency of Virtual Firewall Elasticity Control
abstract
Firewalls have been typically used to enforce network access control. Network Functions Virtualization (NFV) envisions to implement firewall function as software instance (a.k.a virtual firewall). Virtual firewall provides great flexibility and elasticity, which are necessary to protect virtualized environments. In this poster, we propose an innovative virtual firewall controller, VFW Controller, which enables safe, efficient and cost-effective virtual firewall elasticity control. In addition, we implement the core components of VFW Controller on top of NFV and SDN environments. Our experimental results demonstrate that VFW Controller is efficient to provide safe elasticity control of virtual firewalls.
Hongda Li 0002, Juan Deng, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao 0001, Wonkyu Han
SACMAT1