EDBT 2026 Demo / reviewers in the wild / expert
Yu Zhang 0036
dblp:50/671-36
· DBLP profile ↗
39ranked-venue papers
6as first author
24since 2021 · last 2026
0000-0003-2040-5059ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 22 · 3 first-author · 13 since 2021Security and privacy · 7 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A distributed, scalable cross-chain state channel scheme based on recursive state synchronizationabstractAs cross-chain technology continues to advance, the scale of cross-chain transactions is experiencing significant expansion. To improve scalability, researchers have turned to the study of cross-chain state channels. However, most of the existing schemes rely on trusted parties to support channel operations. To address this issue, we present Interpipe: a distributed cross-chain state channel scheme. Specifically, we propose a real-time cross-chain synchronization scheme to ensure consistent operations between two blockchains to a cross-chain state channel. Moreover, we propose a batch transaction proof scheme based on recursive SNARK to meet the cross-chain verification needs of large-scale users. Based on the above designs, Interpipe offers protocols for opening, updating, closing, and disputing operations to cross-chain state channels. Security analysis shows that Interpipe has consistency and resistance, and experimental results demonstrate that a cross-chain state channel can be nearly as efficient as an existing intra-chain state channel. Ruiying Du, Jing Chen 0003, Yu Zhang 0036, Shuangxi Cao, Yufeng Wei, Shixiong Yao |
Blockchain Res. Appl. | 4 |
| 2026 | NeuroSketch: Bloom Filter-Based Sketch for Accurate Network Measurement via Neural NetworksabstractIn network measurement, learning-based sketch is a hot topic recently, which combines traditional sketches with machine learning techniques to improve the accuracy of sketches, while reducing the deployment overhead on switches. So far, most learning-based sketches estimate the sizes of either error-prone flows or all flows using machine learning models. These models take the sketch counter values of flows as features and their real sizes as labels for training. However, the flow size distribution is highly skewed, resulting in the effect that the flow sizes estimated by models are biased toward the sizes of mouse flows, severely underestimating elephant flows. To this end, a network measurement framework via back propagation neural network (BPNN) called NeuroSketch is proposed, which can directly estimate flow sizes and flow cardinality without identifying error-prone flows. Meanwhile, in order to provide effective features for BPNNs, a novel bloom filter-based sketch named BF-Sketch is proposed in this paper. BF-Sketch not only records the count values, but also the number of hash collisions in counters as a new feature, which can efficiently reduce the underestimation of elephant flows by machine learning models. The experimental results show that NeuroSketch reduces the average absolute error (AAE) of flow size estimation by 65%, and relative errors of flow cardinality estimation by 72.23%, compared with learning-based sketches. Moreover, BF-Sketch is implemented on OVS platform and P4-programmable switch to justify its feasible deployment in commodity software and hardware switches. Jindian Liu, Zhuo Li 0009, Hao Xun, Yu Zhang 0036, Peng Luo 0004, Qiang Li 0048 |
IEEE Trans. Netw. | 4 |
| 2025 | Compact Lifting for NTT-Unfriendly Modulus
Ying Liu 0078, Xianhui Lu, Yu Zhang 0036, Ruida Wang, Ziyao Liu, Kunpeng Wang 0001 |
ACISP (2) | 3 |
| 2025 | DAWN: Smaller and Faster NTRU Encryption via Double Encoding
Yu Zhang 0036, Xianhui Lu, Yongjian Yin |
ASIACRYPT (3) | 2 |
| 2025 | Smartreco: Detecting Read-Only Reentrancy via Fine-Grained Cross-DApp AnalysisabstractDespite the increasing popularity of Decentralized Applications (DApps), they are suffering from various vulnerabilities that can be exploited by adversaries for profits. Among such vulnerabilities, Read-Only Reentrancy (called ROR in this paper), is an emerging type of vulnerability that arises from the complex interactions between DApps. In the recent three years, attack incidents of ROR have already caused around 30M USD losses to the DApp ecosystem. Existing techniques for vulnerability detection in smart contracts can hardly detect Read-Only Reentrancy attacks, due to the lack of tracking and analyzing the complex interactions between multiple DApps. In this paper, we propose SmartReco, a new framework for detecting Read-Only Reentrancy vulnerability in DApps through a novel combination of static and dynamic analysis (i.e., fuzzing) over smart contracts. The key design behind SmartReco is threefold: (1) SmartReco identifies the boundary between different DApps from the heavy-coupled cross-contract interactions. (2) SmartReco performs fine-grained static analysis to locate points of interest (i.e., entry functions) that may lead to ROR. (3) SmartReco utilizes the on-chain transaction data and performs multi-function fuzzing (i.e., the entry function and victim function) across different DApps to verify the existence of ROR. Our evaluation of a manual-labeled dataset with 45 RORs shows that SmartReco achieves a precision of 88.64 % and a recall of 86.67 %. In addition, SmartReco successfully detects 43 new RORs from 123 popular DApps. The total assets affected by such RORs reach around 520,000 USD. Zibin Zheng, Yuhong Nan, Mingxi Ye, Kaiwen Ning, Yu Zhang 0036, Weizhe Zhang |
ICSE | 6 |
| 2025 | Leading Attackers Astray: Mitigating Link Flooding Attacks through Stub Node Relocation and InsertionabstractLink Flooding Attacks (LFA) exploit network topology knowledge to disrupt connectivity by targeting critical links and nodes. Existing defenses often presuppose an attacker with complete topological awareness and overlook the concentration of attack traffic on specific routers. Furthermore, many countermeasures rely on SDN, which can suffer from performance degradation due to the limited packet processing capabilities of switches. To address these issues, we introduce the GateLFA attacker model, which assumes that attackers lack complete topology knowledge and guide their attacks based on traffic density analysis. We propose the EqualFlow algorithm, which utilizes stub node relocation and insertion to minimize adversarial impact, balance attack traffic, and reduce defense costs. Additionally, we present the Network Topology Obfuscation System, leveraging XDP for high-speed packet processing at the network boundary to overcome the performance challenges of SDN-based solutions. Our experimental results demonstrate that EqualFlow computes high-quality virtual topologies, outperforming existing algorithms across small, medium, and large-scale networks. Moreover, the Network Topology Obfuscation System effectively disrupts prominent topology probing tools through explicit information interference at a 10 Gbps line rate. For implicit interference, the system increases the packet rate of typical traceroute probes by approximately 17% compared to traffic control methods. This research provides an efficient and practical solution for defending against LFA. Bin Wang 0098, Kehong Liu, Yu Zhang 0036, Guopu Zhu, Binxing Fang |
SMC | 3 |
| 2025 | When Translators Refuse to Translate: A Novel Attack to Speech Translation Systems
Haolin Wu 0001, Chang Liu 0089, Jing Chen 0003, Ruiying Du, Kun He 0008, Yu Zhang 0036, Cong Wu 0003, Tianwei Zhang 0004, Qing Guo 0005, Jie Zhang 0073 |
USENIX Security Symposium | 6 |
| 2025 | TuplePick: A High Stability Packet Classification based on Neural NetworkabstractPacket classification is one of the crucial components of networking. With the advent of Software Defined Network (SDN), packet classification has become more challenging. So far, the proposed schemes have shown good performance. However, packet classification has different application scenarios, such as access control and firewalls. The distribution characteristics of rulesets vary in different application scenarios, which affects packet classification throughput. To this end, a tuple selection model named Picking Model (PM) is designed in this paper to perform packet matching via a neural network. Moreover, based on PM, a packet classification scheme called TuplePick (TP) is proposed, which enables to pick a possible good tuple rather than an exhaustive search in the tuple space. The experimental results indicate that its throughput variances of different rulesets are less than state-of-the-art schemes, which means it outperforms current schemes on stability of throughput in different application scenarios. Zhuo Li 0009, Jindian Liu, Yu Zhang 0036, Tianxiang Ma |
WoWMoM | 4 |
| 2025 | AR: An Efficient Alliance Root Service with Decentralized Trust
Bin Zhang 0048, Yu Zhang 0036, Yuming Feng 0002, Wei-Zhe Zhang, Dongcen Ji, Fan Nie |
J. Comput. Sci. Technol. | 2 |
| 2025 | Paths in the cloud: Geolocation mapping of Amazon's cross-border connectivity
Yu Zhang 0036, Yunan Wang, Hongli Zhang 0001, Binxing Fang |
Peer Peer Netw. Appl. | 2 |
| 2025 | Unity is Strength: Enhancing Precision in Reentrancy Vulnerability Detection of Smart Contract Analysis ToolsabstractReentrancy is one of the most notorious vulnerabilities in smart contracts, resulting in significant digital asset losses. However, many previous works indicate that current Reentrancy detection tools suffer from high false positive rates. Even worse, recent years have witnessed the emergence of new Reentrancy attack patterns fueled by intricate and diverse vulnerability exploit mechanisms. Unfortunately, current tools face a significant limitation in their capacity to adapt and detect these evolving Reentrancy patterns. Consequently, ensuring precise and highly extensible Reentrancy vulnerability detection remains critical challenges for existing tools. To address this issue, we propose a tool named ReEP, designed to reduce the false positives for Reentrancy vulnerability detection. Additionally, ReEP can integrate multiple tools, expanding its capacity for vulnerability detection. It evaluates results from existing tools to verify vulnerability likelihood and reduce false positives. ReEP also offers excellent extensibility, enabling the integration of different detection tools to enhance precision and cover different vulnerability attack patterns. We perform ReEP to eight existing state-of-the-art Reentrancy detection tools. The average precision of these eight tools increased from the original 0.5% to 73% without sacrificing recall. Furthermore, ReEP exhibits robust extensibility. By integrating multiple tools, the precision further improved to a maximum of 83.6%. These results demonstrate that ReEP effectively unites the strengths of existing works, enhances the precision of Reentrancy vulnerability detection tools. Zexu Wang, Jiachi Chen, Peilin Zheng, Yu Zhang 0036, Weizhe Zhang, Zibin Zheng |
IEEE Trans. Software Eng. | 4 |
| 2025 | Toward accurate weight-based measurement and periodic edge measurement in graph stream
Zhuo Li 0009, YuXuan Zhao, Jindian Liu, Yu Zhang 0036 |
World Wide Web (WWW) | 4 |
| 2024 | Escape Cache Traps by Rate Feedback for Ndn Real-Time Video StreamingabstractIn-network caching is one of the most important characteristic of Named Data Networking (NDN). However, while replacing producers in responding to interest requests, caching data packets also shields consumers from perceiving the bottleneck bandwidth of the transmission path between the producer and the consumer. Therefore, when the content source switches from the cache node to the producer due to data exhaustion, the consumer can not adjust the requesting rate accordingly, and may lead to the serious bufferbloat or packet loss - we call it as Cache Trap. We found that Cache Trap occurs commonly in streaming services and the state-of-art NDN congestion control schemes cannot achieve efficient and stable quality of service when it happens. To escape Cache Trap, this paper proposes an explicit rate feedback congestion control algorithm, named as RFCC. RFCC leverages NDN routers' ability of encapsulating customized information in data packets to send link state information to consumers. Specifically, when responding to interest packets, RFCC nodes estimate data throughput received from the producer and insert this information into the returned data packets. The consumer perceives the change of content source according to the hopcount tag in data packet, and then adjusts the sending rate of interest packet based on the explicit rate information. We have implemented RFCC in both real-world NDN live video streaming and NDNsim simulation platforms, and compared it with the state-of-arts congestion control algorithms in a variety of scenarios. The experimental results show that when Cache Trap occurs, RFCC maintains a stable QoE in live video streaming, reduces 50% delay jitters compared with DPCCP and achieves$2.4 \times$throughput compared with PCON. Zhaohua Zhu, Yongrui Chen 0001, Linggang Li, Zhijun Li 0002, Weizhe Zhang, Yu Zhang 0036 |
ICNP | 6 |
| 2024 | SIM: A fast real-time graph stream summarization with improved memory efficiency and accuracy
Zhuo Li 0009, Jindian Liu, Yu Zhang 0036, Teng Liang |
Comput. Networks | 4 |
| 2024 | LearningTuple: A packet classification scheme with high classification and high update
Zhuo Li 0009, Hao Xun, Jindian Liu, Peng Luo 0004, Yu Zhang 0036, Teng Liang, Wanli Zhao 0005 |
Comput. Networks | 6 |
| 2024 | An effective and accurate flow size measurement using funnel-shaped sketch
Jindian Liu, Zhuo Li 0009, Huipeng Du, Haodong Zhou, Leyang Li, Yi An, Yu Zhang 0036, Qiang Li 0048 |
Comput. Networks | 7 |
| 2024 | AGC Sketch: An effective and accurate per-flow measurement to adapt flow size distribution
Zhuo Li 0009, Jindian Liu, Yu Zhang 0036, Teng Liang |
Comput. Commun. | 4 |
| 2024 | An efficient cheating-detectable secret image sharing scheme with smaller share sizes
Zuquan Liu, Guopu Zhu, Yu Zhang 0036, Hongli Zhang 0001, Sam Kwong |
J. Inf. Secur. Appl. | 3 |
| 2024 | An IoT Device Identification Method Using Extracted Fingerprint From Sequence of Traffic Grayscale ImagesabstractWith the widespread deployment and application of various types of IoT devices, preventing illegal intrusion and impersonation attacks of IoT devices has become an important security challenge. Device identification helps to limit the behavior of suspicious devices and enhances the security of the device access process. In this paper, we propose a novel deep learning-based automatic fingerprint extraction model that addresses low efficiency and complexity of traditional feature engineering process, which are often rely on expert experience. The proposed model integrates advanced modules such as Depthwise Separable Convolution (DSC) and Gated Recurrent Unit (GRU), as well as architectures of inverted residuals and linear bottlenecks to enhance the performance of fingerprint extraction. After converting the raw device traffic into the sequence of traffic grayscale images, the model can analyze spatial and temporal features from them to generate highly distinguishable device fingerprints automatically. Additionally, we also achieve fast fingerprint search based on Hierarchical Navigable Small World (HNSW) to support device identification. Our proposed method can not only indicate deviations in device behavior from expected specifications, but also identify unknown and unreliable IoT devices. The experimental results show that our method has excellent performance and more comprehensive identification capabilities in multiple dimensions. Yuming Feng 0002, Yu Zhang 0036, Weizhe Zhang, Desheng Wang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | A Collaborative Stealthy DDoS Detection Method Based on Reinforcement Learning at the Edge of Internet of ThingsabstractThe weaknesses of Internet of Things (IoT) devices leads to vulnerabilities easily, which can be exploited by criminals to launch Distributed Denial-of-Service (DDoS) attacks, becoming a major security hazard. Nowadays, the rapid development of the IoT makes the IoT-based DDoS attacks have the characteristics of wide distribution, large scale, and more stealthy that brings greater challenges for the DDoS detection. In this article, we conduct our research based on the edge side of IoT for providing earlier detection capability and more efficient resource utilization. We propose a novel reinforcement learning-based collaborative DDoS detection method and design a lightweight unsupervised classifier based on statistics. We deploy the classifiers in IoT edge gateways to detect anomalies by analyzing network traffic features in time. In order to deal with the dynamic changes of the IoT environment, we use the soft actor–critic (SAC) reinforcement learning model deployed on the edge server to adjust the parameter configuration of the underlying unsupervised classifier dynamically, which can ensure excellent detection effect for different types of IoT devices. In addition, a collaborative aggregation module is designed in the edge server to share the observation state and historical experience, which has a unique collaborative reward mechanism for the reinforcement learning model to fully mobilize the collaborative work capability. The experiments on public data set and constructed real-world testbed demonstrate that our proposed method has excellent detection performance and especially it can also discover stealthy IoT-based DDoS attacks accurately. Yuming Feng 0002, Weizhe Zhang, Shujun Yin, Yang Xiang 0001, Yu Zhang 0036 |
IEEE Internet Things J. | 6 |
| 2022 | DWBFT: A Weighted Byzantine Fault Tolerant Protocol with Decentralized TrustabstractThe surprising wave of blockchain has led to rapid progress of Byzantine fault tolerant protocol. However, most researches concentrate on the centralized trust such as PBFT, in which all participants trust each other equally. This paper presents DWBFT, a weighted Byzantine fault tolerant protocol with decentralized trust under the weak synchrony assumption. In DWBFT, the nodes can assign weights to each other depending on their decentralized trust relationship, which are adopted to make decisions. DWBFT can achieve safety under the condition that the weight of Byzantine nodes is less than 1/5 of the total weight of all nodes under any weight assignment. The experimental results show that DWBFT can achieve a throughput of nearly 13,000 tps under 32 nodes, and has no significant performance degradation compared with PBFT. Chuanwang Ma, Yu Zhang 0036, Binxing Fang, Hongli Zhang 0001 |
ICC | 2 |
| 2022 | Exploiting Knowledge for Better Mobility Support in the Future Internet
Zhongda Xia, Yu Zhang 0036, Binxing Fang |
Mob. Networks Appl. | 2 |
| 2021 | Adapting Named Data Networking (NDN) for Better Consumer Mobility Support in LEO Satellite NetworksabstractLarge low Earth orbit (LEO) satellite constellations provide low-latency and high-bandwidth Internet connectivity at the global scale. One major challenge is to handle frequent satellite handovers. Named Data Networking (NDN) adopts a pull-based communication model, which allows users to retrieve data that fail to come back because of satellite handovers by retransmitting the corresponding requests, hence simplifying mobility management when retrieving data. However, we find that relying on such retransmissions alone can be highly inefficient in typical LEO satellite constellations. Specifically, typical inter-satellite topologies and satellite handover strategies may produce bad cases for retransmissions, generating a significant amount of additional traffic. Motivated by this observation, this paper attempts to consolidate NDN's advantage in mobility management with the Data Recovery Link Service (DRLS), a shim layer service operating between the network and link layer in the NDN protocol stack. DRLS hides recurring satellite handovers from forwarding by recovering data from the previously connected satellite via alternative paths, thus ensuring the bidirectional request-response exchange of NDN without retransmitting requests. A prototype of DRLS is implemented in the reference NDN software forwarder and evaluated through simulations. Results prove the efficacy of the proposed mechanism at reducing the overall traffic volume. Zhongda Xia, Yu Zhang 0036, Teng Liang, Xinggong Zhang, Binxing Fang |
MSWiM | 2 |
| 2021 | Blockchain-Based DNS Root Zone Management Decentralization for Internet of ThingsabstractDomain Name System (DNS) is a widely used infrastructure for remote control and batch management of IoT devices. As a critical Internet infrastructure, DNS is structured as a tree‐like hierarchy with single root zone authority at the top, which puts the operation of DNS at risk from single point of failure. The current root zone management is lack of transparency and accountability, since only the root zone file is published as the final outcome of operations inside the root zone authority. Towards distributed root zone operation in DNS, this paper presents a blockchain‐based root operation architecture—RootChain, composed of multiple root servers. On the basis of maintaining the single root authority for top‐level domain (TLD), RootChain decentralizes TLD data publication by empowering delegated TLD authorities to publish authenticated data directly. The transparency and accountability of root zone operation are attained by smart‐contracting the whole life cycle of TLD operation and logging all operations on the chain. RootChain is transparent to recursive/stub resolver and DNS/DNSSEC‐compatible. A proof‐of‐concept prototype of RootChain has been implemented with Hyperledger Fabric and evaluated by experiments. Yu Zhang 0036, Zhongda Xia, Zhongze Wang, Weizhe Zhang, Hongli Zhang 0001, Binxing Fang |
Wirel. Commun. Mob. Comput. | 1 |
| 2020 | A secure domain name resolution and management architecture based on blockchainabstractThe domain name system (DNS) is the infrastructure of many services and applications, thus the availability and consistency of the domain name resolution process are crucial but have long troubled DNS. The availability problem is caused by a denial-of-service (DoS) attack or a single point of failure (SPOF). The consistency problem originates from the lack of a forced data synchronization mechanism between authoritative server replicas or between parent/child authoritative servers. We proposed a novel blockchain-based domain name resolution and management architecture named FI-DNS to solve the above problems fundamentally. FI-DNS solves availability and consistency problems in the name resolution process from the mechanism level and guarantees the authenticity and integrity of name resolution results by using public-key cryptography. FIDNS also supports root zone collaborative management based on smart contracts, which is compatible with the current governance model led by Internet Corporation for Assigned Names and Numbers (ICANN). We implemented the prototype system to prove the feasibility and effectiveness of the FI-DNS architecture. We built an experimental environment with real domain name data, evaluated the name resolution performance and stability of the FI-DNS prototype system, and compared the prototype system with DNS. Yu Zhang 0036, Hongli Zhang 0001, Binxing Fang |
ISCC | 2 |
| 2019 | Modeling, Measuring, and Analyzing the Resolution Process of Popular DomainsabstractThe DNS system is gradually becoming the infrastructure of many services and applications. The availability and security of the domain name resolution process must be guaranteed. We propose a graph-based formal model and a general analysis method for quantifying the name resolution process. We define metrics to quantify the availability and security of resolution process for a domain name. We conducted four measurements of the top 1 million popular domains within a one-year period. Our survey shows that for more than 50% of domains, if the most critical authoritative server of the domain name becomes unavailable or compromised, the probability of resolution failure or insecure answer is over 50%. Yu Zhang 0036, Yongyue Li, Binxing Fang |
ICC | 2 |
| 2018 | Multi-objective network optimization combining topology and routing algorithms in multi-layered satellite networks
Zhuoming Li, Huiyun Xia, Yu Zhang 0036, Junqing Qi, Shaohua Wu 0002, Shushi Gu |
Sci. China Inf. Sci. | 3 |
| 2017 | Succinct and practical greedy embedding for geometric routing
Yanbin Sun, Yu Zhang 0036, Binxing Fang, Hongli Zhang 0001 |
Comput. Commun. | 2 |
| 2017 | MBSA: a lightweight and flexible storage architecture for virtual machinesabstractSummary With the advantages of extremely high access speed, low energy consumption, nonvolatility, and byte addressability, nonvolatile memory (NVM) device has already been setting off a revolution in storage field. Conventional storage architecture needs to be optimized or even redesigned from scratch to fully explore the performance potential of NVM device. However, most previous NVM‐related works only explore its low access latency and low energy consumption. Few works have been done to explore the appropriate way to use NVM device for improving virtual machine's storage performance. In this paper, we comprehensively evaluate and analyze conventional virtual machine's storage architecture. We find that, even with cutting‐edge optimization technologies, virtual machine can only achieve 30% of NVM device's original performance. Based on this observation, we propose a memory bus–based storage architecture, which we named MBSA. Memory bus–based storage architecture can greatly shorten the length of virtual machine's storage input/output stack and improve NVM device's use flexibility. In addition, an efficient wear‐leveling algorithm is proposed to prolong NVM device's lifespan. To evaluate the new architecture, we implement it as well as the wear‐leveling algorithm on real hardware and software platform. Experimental results show that MBSA can provide a big performance improvement, about 2.55X, and the wear‐leveling algorithm can efficiently balance write operations on NVM device with a negligible performance overhead (no more than 3%). Wenzhi Chen, Zhongyong Lu, Yu Zhang 0036, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi, Yang Xiang 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2017 | Secure independent-update concise-expression access control for video on demand in cloud
Kun He 0008, Jing Chen 0003, Yu Zhang 0036, Ruiying Du, Yang Xiang 0001, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi |
Inf. Sci. | 3 |
| 2015 | Geometric Routing on Flat Names for ICNabstractThis paper presents Griffin, a scheme of geometric routing on flat names to conduct massive content distribution and retrieval. A tree-based metric space T is proposed according to the concept of hierarchical division of symbol space. In Griffin, the network topology is embedded into the T-space, and content names are mapped to the T-space. Content publication and retrieval are supported by geometric routing in the T-space. Different from previous embedding schemes, Griffin constructs the T-space according to the network topology before embedding. In contrast to prior name resolution schemes, Griffin operates directly on the network topology without establishing an overlay. The correctness of Griffin is proved by the greediness of geometric routing. The experiments by simulation demonstrate that Griffin is efficient and scalable. Yanbin Sun, Yu Zhang 0036, Hongli Zhang 0001, Binxing Fang, Xiaojiang Du |
GLOBECOM | 2 |
| 2014 | FEACS: A Flexible and Efficient Access Control Scheme for Cloud ComputingabstractIn the past few years, cloud computing has emerged as one of the most influential paradigms in the IT industry. As promising as it is, this paradigm brings forth many new challenges for data security because users have to outsource sensitive data on untrusted cloud servers for sharing. In this paper, to guarantee the confidentiality and security of data sharing in cloud environment, we propose a Flexible and Efficient Access Control Scheme (FEACS) based on Attribute-Based Encryption, which is suitable for fine-grained access control. Compared with existing state-of-the-art schemes, FEACS is more practical by following functions. First of all, considering the factor that the user membership may change frequently in cloud environment, FEACS has the capability of coping with dynamic membership efficiently. Secondly, full logic expression is supported to make the access policy described accurately and efficiently. Besides, we prove in the standard model that FEACS is secure based on the Decisional Bilinear Diffie-Hellman assumption. To evaluate the practicality of FEACS, we provide a detailed theoretical performance analysis and a simulation comparison with existing schemes. Both the theoretical analysis and the experimental results prove that our scheme is efficient and effective for cloud environment. Yu Zhang 0036, Jing Chen 0003, Ruiying Du, Lan Deng, Yang Xiang 0001 |
TrustCom | 1 |
| 2013 | Refining IP-to-AS Mappings for AS-Level TracerouteabstractIt is of great significance for network operators and researchers to obtain accurate AS-level traceroute paths, for which mapping IP addresses to correct AS numbers is critical. Thus, there have been a lot of efforts to improve the original IP-to-AS mapping table, which was extracted from BGP routing tables. One of these efforts is called pair matching, which refines the original mapping table by maximizing the number of matched pairs of traceroute and BGP AS paths. However, the existing pair-matching-based methods refine the original IP-to-AS mapping table only with the prefix granularity, i.e., IP addresses in the same /24 prefix are mapped to the same AS or the same set of ASes, which does not fit reality. In this paper, we attempt to refine the IP-to-AS mapping table with the IP address granularity, i.e., allowing IP addresses in the same prefix to be mapped to different ASes. The results show that our fine-grained method can produce a more accurate IP-to-AS mapping table. In addition, this paper also provides a better understanding for the pair-matching-based methods. Baobao Zhang, Jun Bi, Yangyang Wang 0001, Yu Zhang 0036 |
ICCCN | 4 |
| 2012 | Feature selection for optimizing traffic classification
Hongli Zhang 0001, Mahmoud T. Qassrawi, Yu Zhang 0036, Xiangzhan Yu |
Comput. Commun. | 4 |
| 2011 | Parallelizing weighted frequency counting in high-speed network monitoring
Yu Zhang 0036, Binxing Fang, Yongzheng Zhang 0002 |
Comput. Commun. | 1 |
| 2011 | A Framework to Quantify the Pitfalls of Using Traceroute in AS-Level Topology MeasurementabstractAlthough traceroute has the potential to discover AS links that are invisible to existing BGP monitors, it is well known that the common approach for mapping router IP addresses to AS numbers based on BGP routing tables is highly error-prone. We develop a systematic framework to quantify the potential errors of traceroute measurement in AS-level topology inference. In comparing traceroute-derived AS paths with BGP AS paths, we take a novel approach to identifying mismatched path segments and then inferring the causes of these mismatches through a set of tests. Our results show that about 60% of mismatches are due to routers using IP addresses belonging to peering neighbors. This result helps settle a debate in previous works regarding the major cause of errors in traceroute measurement. With the approximate ground truth of the ASes with BGP monitors inside, we identify the inaccuracy of publicly available traceroute-derived topology datasets and find that between 8% and 42% of AS adjacencies on the monitored ASes are false. With a new method to characterize AS links, we show that the derived (false) links between Tier-1/large ISPs and their customers' customers appear more frequently than real links do. Yu Zhang 0036, Ricardo V. Oliveira, Yangyang Wang 0001, Shen Su, Baobao Zhang, Jun Bi, Hongli Zhang 0001, Lixia Zhang 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2010 | Quantifying the Pitfalls of Traceroute in AS Connectivity Inference
Yu Zhang 0036, Ricardo V. Oliveira, Hongli Zhang 0001, Lixia Zhang 0001 |
PAM | 1 |
| 2010 | Identifying heavy hitters in high-speed network monitoring
Yu Zhang 0036, Binxing Fang, Yongzheng Zhang 0002 |
Sci. China Inf. Sci. | 1 |
| 2001 | Understanding end-to-end performance: testbed and primary resultsabstractAs the Internet infrastructure evolves to include quality of service (QoS), a lot of work has been done on how to allocate network resources to satisfy the QoS requirements of IP flows. Less attention is being paid to mapping the network QoS specifications, e.g., network delay and loss rate, to the (perceived) end-to-end performance of user applications, e.g., the latency of retrieving a Web page. We study the impact of the network QoS on the perceived end-to-end performance of user applications. We first propose a generic testbed using a combination of simulation and emulation techniques. It can be used to evaluate the end-to-end performance of user applications in different network environments. Next, we use this testbed to study the effect of network QoS metrics on the perceptual quality of various user applications. We focus on estimating the latency of Web retrieval under given packet delay and loss rate and derive an accurate and efficient TCP short connection performance model. Yu Zhang 0036, Srinivasan Keshav |
GLOBECOM | 2 |